New Zealand KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in New Zealand.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 39 implementation checks
Last reviewed: 29 September 2026 · Version 1.0
Download the checklistDirect answer
What does the New Zealand compliance checklist cover?
The New Zealand checklist translates primary KYC, KYB and AML rules into 11 control areas and 39 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- AML/CFT supervisor
- Department of Internal Affairs (single supervisor since 1 July 2026)
- FIU and reporting route
- New Zealand Police FIU through goAML
- SAR timing
- As soon as practicable, but no later than 3 working days after forming suspicion
- Prescribed transactions
- Physical cash NZ$10,000 or more; international wire transfer NZ$1,000 or more
- AML retention
- Generally at least 5 years; the statutory start event depends on record type
- Privacy and biometrics
- Privacy Act 2020 and Biometric Processing Privacy Code 2025, including 2026 amendments
- Payments
- No standalone e-money or payment-service licence; FSPR, dispute-resolution and product-specific duties may apply
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
New Zealand compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and registrationClassify the actual service and New Zealand nexus before assigning controls.3 items+
Determine whether each activity makes the operator a reporting entity.
- Implementation action
- Map financial activities, casinos, specified legal, accounting, real-estate, trust-and-company, money-transfer and virtual-asset services to the current Act, regulations, rules, notices and exemptions.
- Evidence to retain
- Entity and service map, funds flows, customer locations, statutory analysis and counsel sign-off.
- Primary citation
- AML/CFT Act 2009, sections 5-6 and current regulations, rules, notices and exemptions
Apply the post-1 July 2026 single-supervisor model.
- Implementation action
- Register or enrol and communicate with DIA as the AML/CFT supervisor; preserve FIU reporting and law-enforcement channels separately.
- Evidence to retain
- DIA enrolment, supervisor correspondence, FIU registration and responsibility matrix.
- Primary citation
- AML/CFT Act 2009, sections 130-135 as amended; Ministry of Justice 2026 legislative-change guidance
Assess financial-service registration, licensing and dispute-resolution duties separately.
- Implementation action
- Map each service to the FSPR and Financial Markets Conduct Act; register and obtain any product-specific licence before service and join an approved dispute-resolution scheme where retail-service rules require it.
- Evidence to retain
- FSPR extract, licence analysis, approvals, scheme membership and conditions register.
- Primary citation
- Financial Service Providers (Registration and Dispute Resolution) Act 2008; FMA fintech guidance
02Governance and ML/TF risk assessmentThe risk assessment and programme must be specific, current and independently tested.4 items+
Maintain a documented ML/TF risk assessment.
- Implementation action
- Assess customers, countries, institutions, products, services, transactions, delivery channels, technology and other prescribed factors; update for material change and new risk information.
- Evidence to retain
- Methodology, current assessment, data sources, approvals, change log and residual-risk decisions.
- Primary citation
- AML/CFT Act 2009, section 58
Maintain an AML/CFT programme based on the risk assessment.
- Implementation action
- Document CDD, monitoring, reporting, record, vetting, training, agent, correspondent, review and escalation controls proportionate to the identified risks.
- Evidence to retain
- Approved programme, control map, procedures, training and issue register.
- Primary citation
- AML/CFT Act 2009, sections 56-57
Appoint an AML/CFT compliance officer with sufficient access and authority.
- Implementation action
- Appoint an eligible employee or senior person, document duties and resources, and ensure governing-body visibility of material risks and breaches.
- Evidence to retain
- Appointment, role description, reporting packs, minutes and escalation records.
- Primary citation
- AML/CFT Act 2009, section 56
Arrange independent audit at the required risk-based interval.
- Implementation action
- Use a suitably qualified person independent of programme establishment, test design and operation, and track findings to verified closure.
- Evidence to retain
- Independence assessment, audit plan, report, response and closure testing.
- Primary citation
- AML/CFT Act 2009, sections 59-59B
03Natural-person identificationCDD must cover the customer, beneficial owners and persons acting for the customer.4 items+
Apply standard CDD when the statutory circumstances arise.
- Implementation action
- Before establishing a business relationship or conducting a covered occasional transaction or activity, obtain required identity, address or registered-office, authority, nature-and-purpose and risk information unless an express timing exception applies.
- Evidence to retain
- CDD record, relationship purpose, risk rating, verification and completion timestamp.
- Primary citation
- AML/CFT Act 2009, sections 14-17 and 37
Identify and verify individuals using reliable, independent evidence.
- Implementation action
- Obtain full name and date of birth and take reasonable risk-based steps to verify identity; use the 2026 Identity Verification Code of Practice as a safe-harbour method only when its conditions are met.
- Evidence to retain
- Identity attributes, source provenance, verification result, exception rationale and fraud checks.
- Primary citation
- AML/CFT Act 2009, sections 13, 15-16 and 67; DIA Identity Verification Code of Practice 2026
Identify persons acting on behalf and verify authority.
- Implementation action
- Identify the representative, establish the relationship to the customer, take risk-based verification steps and validate the mandate before accepting instructions.
- Evidence to retain
- Representative KYC, mandate, authority checks, scope limits and instruction log.
- Primary citation
- AML/CFT Act 2009, sections 15-16
Do not proceed where required CDD cannot be completed.
- Implementation action
- Do not establish the relationship or conduct the transaction or activity; terminate an existing relationship when section 37 requires it and consider a suspicious activity report without tipping off.
- Evidence to retain
- Failure record, restriction or exit decision, SAR assessment and communications review.
- Primary citation
- AML/CFT Act 2009, section 37
04KYB, registries, and beneficial ownershipRegistry information is an input, not a substitute for understanding natural-person ownership and control.4 items+
Verify the legal person or arrangement and its authority structure.
- Implementation action
- Collect current name, legal form, identifier, registered office, governing documents, directors, trustees or partners and reliable registry evidence appropriate to the customer type.
- Evidence to retain
- Companies Register or other extract, constitutional documents, officer list and discrepancy resolution.
- Primary citation
- AML/CFT Act 2009, sections 15-17; DIA customer-due-diligence guidance
Identify and risk-appropriately verify every beneficial owner.
- Implementation action
- Determine the natural persons with effective control or who own a prescribed threshold or more; trace layered, nominee and trust arrangements and apply current DIA beneficial-ownership guidance rather than relying on the register alone.
- Evidence to retain
- Ownership chart, control analysis, source documents, verified identities and rationale.
- Primary citation
- AML/CFT Act 2009, sections 5, 15-16; DIA Beneficial Ownership Guidance, July 2026
Identify trust and legal-arrangement parties under the applicable CDD level.
- Implementation action
- Record trustees, settlors, beneficiaries or classes, protectors, appointors and other controllers required by law and risk; obtain source-of-funds or wealth information where enhanced CDD applies.
- Evidence to retain
- Trust deed, party schedule, powers analysis, verification and source evidence.
- Primary citation
- AML/CFT Act 2009, sections 22-25; DIA trust and enhanced-CDD guidance
Reconcile company records without treating them as a complete AML ownership register.
- Implementation action
- Check directors, shareholders, share parcels and ultimate holding company information; account for the public register's limits and independently resolve ultimate ownership and control.
- Evidence to retain
- Register extracts, company share register, declarations, independent corroboration and discrepancy log.
- Primary citation
- Companies Act 1993; Companies Office register and annual-return guidance
05PEPs, enhanced due diligence, and remote onboardingApply enhanced measures to statutory triggers and higher-risk relationships.3 items+
Determine whether relevant persons are politically exposed persons.
- Implementation action
- Use reasonable risk-based steps to identify applicable foreign PEPs, family members and close associates; obtain senior management approval and source-of-wealth or funds measures where the Act requires them.
- Evidence to retain
- Screening, relationship map, approval, source corroboration and review history.
- Primary citation
- AML/CFT Act 2009, section 26
Apply enhanced CDD to each statutory trigger.
- Implementation action
- For trusts, companies with nominee shareholders or bearer shares, qualifying PEPs, higher-risk countries, unusual activity and other section 22 or 22A cases, obtain and verify the additional information required by the relevant trigger.
- Evidence to retain
- Trigger, additional CDD, source evidence, approval and enhanced monitoring plan.
- Primary citation
- AML/CFT Act 2009, sections 22-25
Control remote verification and biometric processing.
- Implementation action
- Assess impersonation, document authenticity and liveness; before biometric processing document lawful purpose, necessity, effectiveness, safeguards and proportionality, provide required notices and offer alternatives where the Code requires them.
- Evidence to retain
- Method assessment, privacy impact record, notices, alternative path, vendor tests and exception review.
- Primary citation
- Biometric Processing Privacy Code 2025, rules 1-4; DIA Identity Verification Code of Practice 2026
06Monitoring and suspicious activity reportingOngoing scrutiny and documented suspicion timing drive FIU reporting.4 items+
Conduct ongoing CDD and account monitoring.
- Implementation action
- Regularly review relationship information, keep CDD current and examine transactions and activities for consistency with the customer's profile, purpose and risk.
- Evidence to retain
- Monitoring scenarios, alerts, case decisions, refresh records and quality testing.
- Primary citation
- AML/CFT Act 2009, section 31
Identify the moment reasonable grounds for suspicion arise.
- Implementation action
- Assess transactions, proposed transactions, services, attempted activity and other relevant information promptly; record the facts and timestamp without waiting for proof of an offence.
- Evidence to retain
- Alert chronology, information reviewed, suspicion decision and decision-maker.
- Primary citation
- AML/CFT Act 2009, sections 39A-41
Submit a suspicious activity report to the FIU on time.
- Implementation action
- File through goAML as soon as practicable and no later than three working days after forming suspicion; complete required fields and preserve the acknowledgement.
- Evidence to retain
- Suspicion timestamp, SAR, goAML receipt and any correction record.
- Primary citation
- AML/CFT Act 2009, sections 40-41; New Zealand Police FIU guidance
Protect SAR information and prevent tipping off.
- Implementation action
- Restrict SAR content and related information to authorised use and assess any disclosure against the statutory permissions before release.
- Evidence to retain
- Access controls, disclosure register, legal review, training and incident log.
- Primary citation
- AML/CFT Act 2009, sections 46-47
07Prescribed transactions, wires, and virtual assetsThresholds are report-specific and do not replace suspicious-activity assessment.4 items+
Report prescribed large cash transactions.
- Implementation action
- Report a transaction involving NZ$10,000 or more in physical currency, or foreign-currency equivalent, through goAML within the prescribed period and retain the submission trail.
- Evidence to retain
- Cash data, aggregation and conversion logic, PTR and receipt.
- Primary citation
- AML/CFT Act 2009, sections 48A-48B; Prescribed Transactions Reporting Regulations 2016; FIU PTR guidance
Report prescribed international wire transfers.
- Implementation action
- Report an international wire transfer of NZ$1,000 or more, or foreign-currency equivalent, through goAML within the prescribed period; distinguish ordering, intermediary and beneficiary roles.
- Evidence to retain
- Transfer fields, role analysis, currency conversion, PTR and receipt.
- Primary citation
- AML/CFT Act 2009, sections 48A-48B; Prescribed Transactions Reporting Regulations 2016; FIU PTR guidance
Carry and verify required wire-transfer information.
- Implementation action
- Collect, include, retain and review prescribed originator and beneficiary information and apply controls for missing or incomplete data.
- Evidence to retain
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Primary citation
- AML/CFT Act 2009, sections 27-28; current requirements regulations
Map virtual-asset services to AML and financial-service obligations.
- Implementation action
- Treat covered cryptoasset exchange, transfer, custody or related services as likely financial-institution activity; assess DIA supervision, FSPR registration, dispute resolution and any FMC licensing before launch.
- Evidence to retain
- Service and wallet-flow analysis, DIA position, FSPR record, licensing memo and monitoring tests.
- Primary citation
- AML/CFT Act 2009, section 5 definition of financial institution; FMA cryptoasset-service-provider guidance
08Targeted financial sanctionsSanctions and terrorist-property controls apply separately from AML screening.3 items+
Screen current United Nations, terrorist and New Zealand sanctions designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and on list changes; assess ownership and control rather than exact-name matches only.
- Evidence to retain
- List versions, update logs, configuration tests, match analysis and disposition.
- Primary citation
- United Nations Act 1946; Terrorism Suppression Act 2002; Russia Sanctions Act 2022
Stop prohibited dealings and report terrorist property.
- Implementation action
- Do not make property or financial services available contrary to applicable prohibitions; freeze or hold where legally required and promptly use the Police/FIU reporting route for suspicious property or sanctions-related reports.
- Evidence to retain
- Match analysis, restriction timestamp, report, authority correspondence and release approval.
- Primary citation
- Terrorism Suppression Act 2002, including sections 9-10 and 43; applicable sanctions regulations
Use exemptions, permits or releases only under verified authority.
- Implementation action
- Identify the governing sanctions regime, obtain written authority before activity, implement conditions and document expiry, reporting and release decisions.
- Evidence to retain
- Regime analysis, permit or exemption, conditions, monitoring and release record.
- Primary citation
- Applicable regulations under the United Nations Act 1946 and Russia Sanctions Act 2022
09Records and regulator accessApply the correct five-year trigger to each record class and preserve retrieval.3 items+
Retain transaction records for at least five years from completion.
- Implementation action
- Keep records sufficient to reconstruct covered transactions and identify the parties, amounts, dates and nature; apply longer legal holds where required.
- Evidence to retain
- Retention schedule, transaction sample, trigger calculation, legal hold and deletion log.
- Primary citation
- AML/CFT Act 2009, sections 49 and 52-55
Retain identity and verification records for the statutory period.
- Implementation action
- Keep CDD and verification records for at least five years after the end of the business relationship or completion of the occasional transaction or activity, as applicable.
- Evidence to retain
- Relationship-end or completion date, archive sample, retrieval test and deletion approval.
- Primary citation
- AML/CFT Act 2009, section 50 and sections 52-55
Preserve SAR, programme, risk and audit evidence.
- Implementation action
- Keep SAR and prescribed-report material, risk assessments, programmes, audits and supporting records for the applicable statutory periods in readily retrievable form.
- Evidence to retain
- Record-class matrix, access controls, sample case pack and DIA production test.
- Primary citation
- AML/CFT Act 2009, sections 49A and 51-55
10Privacy, biometrics, and transfersKYC processing must satisfy the Privacy Act and any applicable biometric rule.4 items+
Collect and use identity data for a lawful, necessary purpose.
- Implementation action
- Map each data element to a lawful function, collect no more than necessary, give required collection notice, maintain accuracy and restrict later use and disclosure.
- Evidence to retain
- Data inventory, purpose and authority map, notices, access controls and accuracy reviews.
- Primary citation
- Privacy Act 2020, information privacy principles 1-8 and IPP 3A
Comply with the Biometric Processing Privacy Code.
- Implementation action
- Before using automated biometric verification, assess necessity, effectiveness and proportionality, implement privacy safeguards, provide clear notice and control use, disclosure, security, retention and disposal under the Code.
- Evidence to retain
- Biometric assessment, safeguards, notices, alternatives, accuracy tests, vendor review and deletion controls.
- Primary citation
- Biometric Processing Privacy Code 2025, as amended in 2026
Assess and notify notifiable privacy breaches.
- Implementation action
- Contain and assess incidents promptly; notify the Privacy Commissioner and affected people as soon as practicable when serious harm has occurred or is likely, unless a statutory exception applies.
- Evidence to retain
- Incident chronology, harm assessment, notifications, exception analysis and remediation.
- Primary citation
- Privacy Act 2020, sections 112-122
Control overseas disclosures and processors.
- Implementation action
- Before disclosing personal information outside New Zealand, satisfy IPP 12 through comparable safeguards, qualifying recipient status or informed authorisation; contract for security, incidents, return and deletion.
- Evidence to retain
- Transfer map, IPP 12 analysis, contract, recipient diligence and monitoring.
- Primary citation
- Privacy Act 2020, information privacy principle 12
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP and sanctions results, purpose, risk, privacy records, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting AML/CFT Act 2009, sections 11-38 and 50
Maintain a reconstructable FIU and sanctions case pack.
- Implementation action
- Link activity, alert, suspicion chronology, threshold analysis, submission, acknowledgement, confidentiality, asset restrictions and authority communications.
- Evidence to retain
- Complete sampled case pack, timeline and controlled-access record.
- Primary citation
- Operational control supporting AML/CFT Act 2009, sections 40-55 and Terrorism Suppression Act 2002
Maintain a launch and change pack.
- Implementation action
- Record perimeter, DIA enrolment, FSPR or licensing, approved programme, reporting connectivity, sanctions, privacy, vendors, testing and unresolved uncertainty before launch or material change.
- Evidence to retain
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Primary citation
- Official sources listed below
Primary-source register
22 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering and Countering Financing of Terrorism Act 2009 - current versionNew Zealand Legislation · Primary legislation
- Anti-Money Laundering and Countering Financing of Terrorism (Requirements and Compliance) Regulations 2011New Zealand Legislation · Primary delegated legislation
- Anti-Money Laundering and Countering Financing of Terrorism (Prescribed Transactions Reporting) Regulations 2016New Zealand Legislation · Primary delegated legislation
- 2026 AML/CFT legislative changesMinistry of Justice · Official reform guidance
- AML/CFT guidance library for trust and company service providersDepartment of Internal Affairs · Official supervisor guidance
- AML/CFT frequently asked questionsDepartment of Internal Affairs · Official supervisor guidance
- Identity Verification Code of Practice 2026Department of Internal Affairs · Official code guidance
- New Zealand Financial Intelligence UnitNew Zealand Police · Official FIU guidance
- Prescribed Transactions ReportingNew Zealand Police · Official reporting guidance
- Companies Register search guidanceNew Zealand Companies Office · Official registry guidance
- Companies Register annual-return guidanceNew Zealand Companies Office · Official registry guidance
- Privacy Act 2020 - current versionNew Zealand Legislation · Primary legislation
- Biometric Processing Privacy Code 2025Office of the Privacy Commissioner · Official privacy code
- Terrorism Suppression Act 2002 - current versionNew Zealand Legislation · Primary legislation
- Russia Sanctions Act 2022 - current versionNew Zealand Legislation · Primary legislation
- Fintech regulatory and licensing requirementsFinancial Markets Authority · Official licensing guidance
- Cryptoasset service providersFinancial Markets Authority · Official sector guidance
- E-money and payment service providersFinancial Markets Authority · Official sector guidance
- FATF New Zealand country profile and 2024 follow-upFATF · Authoritative current assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- New Zealand flag - use in advertisingManatu Taonga Ministry for Culture and Heritage · Official national-symbol guidance
Direct answers
New Zealand KYC, KYB and AML questions
Who supervises AML/CFT compliance?+
Since 1 July 2026, the Department of Internal Affairs is New Zealand's single AML/CFT supervisor. The Police FIU separately receives and analyses reports.
When must a suspicious activity report be filed?+
As soon as practicable, and no later than three working days after the reporting entity forms the relevant suspicion, through the FIU's goAML route.
Which prescribed transactions are threshold-reportable?+
Large physical-cash transactions of NZ$10,000 or more and international wire transfers of NZ$1,000 or more, including foreign-currency equivalents, are prescribed categories. Apply the regulations and FIU filing specifications to the actual transaction.
Is there one universal CDD transaction threshold?+
No. CDD is triggered by the relationship, occasional transaction or activity and statutory risk circumstances. Prescribed-transaction thresholds are separate reporting rules.
How is beneficial ownership determined?+
Identify natural persons who ultimately own or exercise effective control under the Act and current DIA guidance. Companies Register shareholders and ultimate-holding-company fields are evidence inputs, not a complete AML beneficial-ownership determination.
How long are AML/CFT records retained?+
Generally at least five years, but the clock depends on the record: transaction completion, relationship end, occasional transaction or activity completion, or the relevant statutory event.
Do payment or e-money providers need a special licence?+
New Zealand has no standalone e-money or payment-service licence. FSPR registration, dispute-resolution membership, AML/CFT duties and product-specific FMC or prudential requirements may still apply.
Are virtual-asset service providers covered?+
A provider carrying on covered cryptoasset-related financial services will likely be a financial institution under the AML/CFT Act and may need FSPR registration, dispute-resolution membership and product-specific licensing.
What privacy rules apply to facial verification?+
The Privacy Act 2020 and Biometric Processing Privacy Code 2025 apply. The Code requires a documented lawful purpose, necessity, effectiveness, safeguards and proportionality, plus transparency and lifecycle controls.
Is New Zealand on a FATF public list?+
No. New Zealand was absent from both FATF public lists dated 19 June 2026. It remains subject to FATF follow-up and absence from a list is not a low-risk conclusion.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 29 September 2026. Confirm the reporting-entity perimeter, current rules and notices, any exemption, filing specifications, sector licensing, sanctions designation and privacy position with DIA, the FIU and qualified New Zealand counsel before launch.