Nouvelle-Zélande KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Nouvelle-Zélande.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 39 contrôles d’implémentation
Dernière revue: 29 September 2026 · Version 1.0
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Nouvelle-Zélande ?
La checklist pour Nouvelle-Zélande traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 39 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- AML/CFT supervisor
- Department of Internal Affairs (single supervisor since 1 July 2026)
- FIU and reporting route
- New Zealand Police FIU through goAML
- SAR timing
- As soon as practicable, but no later than 3 working days after forming suspicion
- Prescribed transactions
- Physical cash NZ$10,000 or more; international wire transfer NZ$1,000 or more
- AML retention
- Generally at least 5 years; the statutory start event depends on record type
- Privacy and biometrics
- Privacy Act 2020 and Biometric Processing Privacy Code 2025, including 2026 amendments
- Payments
- No standalone e-money or payment-service licence; FSPR, dispute-resolution and product-specific duties may apply
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Nouvelle-Zélande
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and registrationClassify the actual service and New Zealand nexus before assigning controls.3 éléments+
Determine whether each activity makes the operator a reporting entity.
- Action d’implémentation
- Map financial activities, casinos, specified legal, accounting, real-estate, trust-and-company, money-transfer and virtual-asset services to the current Act, regulations, rules, notices and exemptions.
- Preuves à conserver
- Entity and service map, funds flows, customer locations, statutory analysis and counsel sign-off.
- Source primaire
- AML/CFT Act 2009, sections 5-6 and current regulations, rules, notices and exemptions
Apply the post-1 July 2026 single-supervisor model.
- Action d’implémentation
- Register or enrol and communicate with DIA as the AML/CFT supervisor; preserve FIU reporting and law-enforcement channels separately.
- Preuves à conserver
- DIA enrolment, supervisor correspondence, FIU registration and responsibility matrix.
- Source primaire
- AML/CFT Act 2009, sections 130-135 as amended; Ministry of Justice 2026 legislative-change guidance
Assess financial-service registration, licensing and dispute-resolution duties separately.
- Action d’implémentation
- Map each service to the FSPR and Financial Markets Conduct Act; register and obtain any product-specific licence before service and join an approved dispute-resolution scheme where retail-service rules require it.
- Preuves à conserver
- FSPR extract, licence analysis, approvals, scheme membership and conditions register.
- Source primaire
- Financial Service Providers (Registration and Dispute Resolution) Act 2008; FMA fintech guidance
02Governance and ML/TF risk assessmentThe risk assessment and programme must be specific, current and independently tested.4 éléments+
Maintain a documented ML/TF risk assessment.
- Action d’implémentation
- Assess customers, countries, institutions, products, services, transactions, delivery channels, technology and other prescribed factors; update for material change and new risk information.
- Preuves à conserver
- Methodology, current assessment, data sources, approvals, change log and residual-risk decisions.
- Source primaire
- AML/CFT Act 2009, section 58
Maintain an AML/CFT programme based on the risk assessment.
- Action d’implémentation
- Document CDD, monitoring, reporting, record, vetting, training, agent, correspondent, review and escalation controls proportionate to the identified risks.
- Preuves à conserver
- Approved programme, control map, procedures, training and issue register.
- Source primaire
- AML/CFT Act 2009, sections 56-57
Appoint an AML/CFT compliance officer with sufficient access and authority.
- Action d’implémentation
- Appoint an eligible employee or senior person, document duties and resources, and ensure governing-body visibility of material risks and breaches.
- Preuves à conserver
- Appointment, role description, reporting packs, minutes and escalation records.
- Source primaire
- AML/CFT Act 2009, section 56
Arrange independent audit at the required risk-based interval.
- Action d’implémentation
- Use a suitably qualified person independent of programme establishment, test design and operation, and track findings to verified closure.
- Preuves à conserver
- Independence assessment, audit plan, report, response and closure testing.
- Source primaire
- AML/CFT Act 2009, sections 59-59B
03Natural-person identificationCDD must cover the customer, beneficial owners and persons acting for the customer.4 éléments+
Apply standard CDD when the statutory circumstances arise.
- Action d’implémentation
- Before establishing a business relationship or conducting a covered occasional transaction or activity, obtain required identity, address or registered-office, authority, nature-and-purpose and risk information unless an express timing exception applies.
- Preuves à conserver
- CDD record, relationship purpose, risk rating, verification and completion timestamp.
- Source primaire
- AML/CFT Act 2009, sections 14-17 and 37
Identify and verify individuals using reliable, independent evidence.
- Action d’implémentation
- Obtain full name and date of birth and take reasonable risk-based steps to verify identity; use the 2026 Identity Verification Code of Practice as a safe-harbour method only when its conditions are met.
- Preuves à conserver
- Identity attributes, source provenance, verification result, exception rationale and fraud checks.
- Source primaire
- AML/CFT Act 2009, sections 13, 15-16 and 67; DIA Identity Verification Code of Practice 2026
Identify persons acting on behalf and verify authority.
- Action d’implémentation
- Identify the representative, establish the relationship to the customer, take risk-based verification steps and validate the mandate before accepting instructions.
- Preuves à conserver
- Representative KYC, mandate, authority checks, scope limits and instruction log.
- Source primaire
- AML/CFT Act 2009, sections 15-16
Do not proceed where required CDD cannot be completed.
- Action d’implémentation
- Do not establish the relationship or conduct the transaction or activity; terminate an existing relationship when section 37 requires it and consider a suspicious activity report without tipping off.
- Preuves à conserver
- Failure record, restriction or exit decision, SAR assessment and communications review.
- Source primaire
- AML/CFT Act 2009, section 37
04KYB, registries, and beneficial ownershipRegistry information is an input, not a substitute for understanding natural-person ownership and control.4 éléments+
Verify the legal person or arrangement and its authority structure.
- Action d’implémentation
- Collect current name, legal form, identifier, registered office, governing documents, directors, trustees or partners and reliable registry evidence appropriate to the customer type.
- Preuves à conserver
- Companies Register or other extract, constitutional documents, officer list and discrepancy resolution.
- Source primaire
- AML/CFT Act 2009, sections 15-17; DIA customer-due-diligence guidance
Identify and risk-appropriately verify every beneficial owner.
- Action d’implémentation
- Determine the natural persons with effective control or who own a prescribed threshold or more; trace layered, nominee and trust arrangements and apply current DIA beneficial-ownership guidance rather than relying on the register alone.
- Preuves à conserver
- Ownership chart, control analysis, source documents, verified identities and rationale.
- Source primaire
- AML/CFT Act 2009, sections 5, 15-16; DIA Beneficial Ownership Guidance, July 2026
Identify trust and legal-arrangement parties under the applicable CDD level.
- Action d’implémentation
- Record trustees, settlors, beneficiaries or classes, protectors, appointors and other controllers required by law and risk; obtain source-of-funds or wealth information where enhanced CDD applies.
- Preuves à conserver
- Trust deed, party schedule, powers analysis, verification and source evidence.
- Source primaire
- AML/CFT Act 2009, sections 22-25; DIA trust and enhanced-CDD guidance
Reconcile company records without treating them as a complete AML ownership register.
- Action d’implémentation
- Check directors, shareholders, share parcels and ultimate holding company information; account for the public register's limits and independently resolve ultimate ownership and control.
- Preuves à conserver
- Register extracts, company share register, declarations, independent corroboration and discrepancy log.
- Source primaire
- Companies Act 1993; Companies Office register and annual-return guidance
05PEPs, enhanced due diligence, and remote onboardingApply enhanced measures to statutory triggers and higher-risk relationships.3 éléments+
Determine whether relevant persons are politically exposed persons.
- Action d’implémentation
- Use reasonable risk-based steps to identify applicable foreign PEPs, family members and close associates; obtain senior management approval and source-of-wealth or funds measures where the Act requires them.
- Preuves à conserver
- Screening, relationship map, approval, source corroboration and review history.
- Source primaire
- AML/CFT Act 2009, section 26
Apply enhanced CDD to each statutory trigger.
- Action d’implémentation
- For trusts, companies with nominee shareholders or bearer shares, qualifying PEPs, higher-risk countries, unusual activity and other section 22 or 22A cases, obtain and verify the additional information required by the relevant trigger.
- Preuves à conserver
- Trigger, additional CDD, source evidence, approval and enhanced monitoring plan.
- Source primaire
- AML/CFT Act 2009, sections 22-25
Control remote verification and biometric processing.
- Action d’implémentation
- Assess impersonation, document authenticity and liveness; before biometric processing document lawful purpose, necessity, effectiveness, safeguards and proportionality, provide required notices and offer alternatives where the Code requires them.
- Preuves à conserver
- Method assessment, privacy impact record, notices, alternative path, vendor tests and exception review.
- Source primaire
- Biometric Processing Privacy Code 2025, rules 1-4; DIA Identity Verification Code of Practice 2026
06Monitoring and suspicious activity reportingOngoing scrutiny and documented suspicion timing drive FIU reporting.4 éléments+
Conduct ongoing CDD and account monitoring.
- Action d’implémentation
- Regularly review relationship information, keep CDD current and examine transactions and activities for consistency with the customer's profile, purpose and risk.
- Preuves à conserver
- Monitoring scenarios, alerts, case decisions, refresh records and quality testing.
- Source primaire
- AML/CFT Act 2009, section 31
Identify the moment reasonable grounds for suspicion arise.
- Action d’implémentation
- Assess transactions, proposed transactions, services, attempted activity and other relevant information promptly; record the facts and timestamp without waiting for proof of an offence.
- Preuves à conserver
- Alert chronology, information reviewed, suspicion decision and decision-maker.
- Source primaire
- AML/CFT Act 2009, sections 39A-41
Submit a suspicious activity report to the FIU on time.
- Action d’implémentation
- File through goAML as soon as practicable and no later than three working days after forming suspicion; complete required fields and preserve the acknowledgement.
- Preuves à conserver
- Suspicion timestamp, SAR, goAML receipt and any correction record.
- Source primaire
- AML/CFT Act 2009, sections 40-41; New Zealand Police FIU guidance
Protect SAR information and prevent tipping off.
- Action d’implémentation
- Restrict SAR content and related information to authorised use and assess any disclosure against the statutory permissions before release.
- Preuves à conserver
- Access controls, disclosure register, legal review, training and incident log.
- Source primaire
- AML/CFT Act 2009, sections 46-47
07Prescribed transactions, wires, and virtual assetsThresholds are report-specific and do not replace suspicious-activity assessment.4 éléments+
Report prescribed large cash transactions.
- Action d’implémentation
- Report a transaction involving NZ$10,000 or more in physical currency, or foreign-currency equivalent, through goAML within the prescribed period and retain the submission trail.
- Preuves à conserver
- Cash data, aggregation and conversion logic, PTR and receipt.
- Source primaire
- AML/CFT Act 2009, sections 48A-48B; Prescribed Transactions Reporting Regulations 2016; FIU PTR guidance
Report prescribed international wire transfers.
- Action d’implémentation
- Report an international wire transfer of NZ$1,000 or more, or foreign-currency equivalent, through goAML within the prescribed period; distinguish ordering, intermediary and beneficiary roles.
- Preuves à conserver
- Transfer fields, role analysis, currency conversion, PTR and receipt.
- Source primaire
- AML/CFT Act 2009, sections 48A-48B; Prescribed Transactions Reporting Regulations 2016; FIU PTR guidance
Carry and verify required wire-transfer information.
- Action d’implémentation
- Collect, include, retain and review prescribed originator and beneficiary information and apply controls for missing or incomplete data.
- Preuves à conserver
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Source primaire
- AML/CFT Act 2009, sections 27-28; current requirements regulations
Map virtual-asset services to AML and financial-service obligations.
- Action d’implémentation
- Treat covered cryptoasset exchange, transfer, custody or related services as likely financial-institution activity; assess DIA supervision, FSPR registration, dispute resolution and any FMC licensing before launch.
- Preuves à conserver
- Service and wallet-flow analysis, DIA position, FSPR record, licensing memo and monitoring tests.
- Source primaire
- AML/CFT Act 2009, section 5 definition of financial institution; FMA cryptoasset-service-provider guidance
08Targeted financial sanctionsSanctions and terrorist-property controls apply separately from AML screening.3 éléments+
Screen current United Nations, terrorist and New Zealand sanctions designations.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and on list changes; assess ownership and control rather than exact-name matches only.
- Preuves à conserver
- List versions, update logs, configuration tests, match analysis and disposition.
- Source primaire
- United Nations Act 1946; Terrorism Suppression Act 2002; Russia Sanctions Act 2022
Stop prohibited dealings and report terrorist property.
- Action d’implémentation
- Do not make property or financial services available contrary to applicable prohibitions; freeze or hold where legally required and promptly use the Police/FIU reporting route for suspicious property or sanctions-related reports.
- Preuves à conserver
- Match analysis, restriction timestamp, report, authority correspondence and release approval.
- Source primaire
- Terrorism Suppression Act 2002, including sections 9-10 and 43; applicable sanctions regulations
Use exemptions, permits or releases only under verified authority.
- Action d’implémentation
- Identify the governing sanctions regime, obtain written authority before activity, implement conditions and document expiry, reporting and release decisions.
- Preuves à conserver
- Regime analysis, permit or exemption, conditions, monitoring and release record.
- Source primaire
- Applicable regulations under the United Nations Act 1946 and Russia Sanctions Act 2022
09Records and regulator accessApply the correct five-year trigger to each record class and preserve retrieval.3 éléments+
Retain transaction records for at least five years from completion.
- Action d’implémentation
- Keep records sufficient to reconstruct covered transactions and identify the parties, amounts, dates and nature; apply longer legal holds where required.
- Preuves à conserver
- Retention schedule, transaction sample, trigger calculation, legal hold and deletion log.
- Source primaire
- AML/CFT Act 2009, sections 49 and 52-55
Retain identity and verification records for the statutory period.
- Action d’implémentation
- Keep CDD and verification records for at least five years after the end of the business relationship or completion of the occasional transaction or activity, as applicable.
- Preuves à conserver
- Relationship-end or completion date, archive sample, retrieval test and deletion approval.
- Source primaire
- AML/CFT Act 2009, section 50 and sections 52-55
Preserve SAR, programme, risk and audit evidence.
- Action d’implémentation
- Keep SAR and prescribed-report material, risk assessments, programmes, audits and supporting records for the applicable statutory periods in readily retrievable form.
- Preuves à conserver
- Record-class matrix, access controls, sample case pack and DIA production test.
- Source primaire
- AML/CFT Act 2009, sections 49A and 51-55
10Privacy, biometrics, and transfersKYC processing must satisfy the Privacy Act and any applicable biometric rule.4 éléments+
Collect and use identity data for a lawful, necessary purpose.
- Action d’implémentation
- Map each data element to a lawful function, collect no more than necessary, give required collection notice, maintain accuracy and restrict later use and disclosure.
- Preuves à conserver
- Data inventory, purpose and authority map, notices, access controls and accuracy reviews.
- Source primaire
- Privacy Act 2020, information privacy principles 1-8 and IPP 3A
Comply with the Biometric Processing Privacy Code.
- Action d’implémentation
- Before using automated biometric verification, assess necessity, effectiveness and proportionality, implement privacy safeguards, provide clear notice and control use, disclosure, security, retention and disposal under the Code.
- Preuves à conserver
- Biometric assessment, safeguards, notices, alternatives, accuracy tests, vendor review and deletion controls.
- Source primaire
- Biometric Processing Privacy Code 2025, as amended in 2026
Assess and notify notifiable privacy breaches.
- Action d’implémentation
- Contain and assess incidents promptly; notify the Privacy Commissioner and affected people as soon as practicable when serious harm has occurred or is likely, unless a statutory exception applies.
- Preuves à conserver
- Incident chronology, harm assessment, notifications, exception analysis and remediation.
- Source primaire
- Privacy Act 2020, sections 112-122
Control overseas disclosures and processors.
- Action d’implémentation
- Before disclosing personal information outside New Zealand, satisfy IPP 12 through comparable safeguards, qualifying recipient status or informed authorisation; contract for security, incidents, return and deletion.
- Preuves à conserver
- Transfer map, IPP 12 analysis, contract, recipient diligence and monitoring.
- Source primaire
- Privacy Act 2020, information privacy principle 12
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, beneficial ownership, PEP and sanctions results, purpose, risk, privacy records, approvals and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack and retrieval result.
- Source primaire
- Operational control supporting AML/CFT Act 2009, sections 11-38 and 50
Maintain a reconstructable FIU and sanctions case pack.
- Action d’implémentation
- Link activity, alert, suspicion chronology, threshold analysis, submission, acknowledgement, confidentiality, asset restrictions and authority communications.
- Preuves à conserver
- Complete sampled case pack, timeline and controlled-access record.
- Source primaire
- Operational control supporting AML/CFT Act 2009, sections 40-55 and Terrorism Suppression Act 2002
Maintain a launch and change pack.
- Action d’implémentation
- Record perimeter, DIA enrolment, FSPR or licensing, approved programme, reporting connectivity, sanctions, privacy, vendors, testing and unresolved uncertainty before launch or material change.
- Preuves à conserver
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Source primaire
- Official sources listed below
Registre des sources primaires
22 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Anti-Money Laundering and Countering Financing of Terrorism Act 2009 - current versionNew Zealand Legislation · Primary legislation
- Anti-Money Laundering and Countering Financing of Terrorism (Requirements and Compliance) Regulations 2011New Zealand Legislation · Primary delegated legislation
- Anti-Money Laundering and Countering Financing of Terrorism (Prescribed Transactions Reporting) Regulations 2016New Zealand Legislation · Primary delegated legislation
- 2026 AML/CFT legislative changesMinistry of Justice · Official reform guidance
- AML/CFT guidance library for trust and company service providersDepartment of Internal Affairs · Official supervisor guidance
- AML/CFT frequently asked questionsDepartment of Internal Affairs · Official supervisor guidance
- Identity Verification Code of Practice 2026Department of Internal Affairs · Official code guidance
- New Zealand Financial Intelligence UnitNew Zealand Police · Official FIU guidance
- Prescribed Transactions ReportingNew Zealand Police · Official reporting guidance
- Companies Register search guidanceNew Zealand Companies Office · Official registry guidance
- Companies Register annual-return guidanceNew Zealand Companies Office · Official registry guidance
- Privacy Act 2020 - current versionNew Zealand Legislation · Primary legislation
- Biometric Processing Privacy Code 2025Office of the Privacy Commissioner · Official privacy code
- Terrorism Suppression Act 2002 - current versionNew Zealand Legislation · Primary legislation
- Russia Sanctions Act 2022 - current versionNew Zealand Legislation · Primary legislation
- Fintech regulatory and licensing requirementsFinancial Markets Authority · Official licensing guidance
- Cryptoasset service providersFinancial Markets Authority · Official sector guidance
- E-money and payment service providersFinancial Markets Authority · Official sector guidance
- FATF New Zealand country profile and 2024 follow-upFATF · Authoritative current assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- New Zealand flag - use in advertisingManatu Taonga Ministry for Culture and Heritage · Official national-symbol guidance
Réponses directes
Questions KYC, KYB et AML pour Nouvelle-Zélande
Who supervises AML/CFT compliance?+
Since 1 July 2026, the Department of Internal Affairs is New Zealand's single AML/CFT supervisor. The Police FIU separately receives and analyses reports.
When must a suspicious activity report be filed?+
As soon as practicable, and no later than three working days after the reporting entity forms the relevant suspicion, through the FIU's goAML route.
Which prescribed transactions are threshold-reportable?+
Large physical-cash transactions of NZ$10,000 or more and international wire transfers of NZ$1,000 or more, including foreign-currency equivalents, are prescribed categories. Apply the regulations and FIU filing specifications to the actual transaction.
Is there one universal CDD transaction threshold?+
No. CDD is triggered by the relationship, occasional transaction or activity and statutory risk circumstances. Prescribed-transaction thresholds are separate reporting rules.
How is beneficial ownership determined?+
Identify natural persons who ultimately own or exercise effective control under the Act and current DIA guidance. Companies Register shareholders and ultimate-holding-company fields are evidence inputs, not a complete AML beneficial-ownership determination.
How long are AML/CFT records retained?+
Generally at least five years, but the clock depends on the record: transaction completion, relationship end, occasional transaction or activity completion, or the relevant statutory event.
Do payment or e-money providers need a special licence?+
New Zealand has no standalone e-money or payment-service licence. FSPR registration, dispute-resolution membership, AML/CFT duties and product-specific FMC or prudential requirements may still apply.
Are virtual-asset service providers covered?+
A provider carrying on covered cryptoasset-related financial services will likely be a financial institution under the AML/CFT Act and may need FSPR registration, dispute-resolution membership and product-specific licensing.
What privacy rules apply to facial verification?+
The Privacy Act 2020 and Biometric Processing Privacy Code 2025 apply. The Code requires a documented lawful purpose, necessity, effectiveness, safeguards and proportionality, plus transparency and lifecycle controls.
Is New Zealand on a FATF public list?+
No. New Zealand was absent from both FATF public lists dated 19 June 2026. It remains subject to FATF follow-up and absence from a list is not a low-risk conclusion.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 29 September 2026. Confirm the reporting-entity perimeter, current rules and notices, any exemption, filing specifications, sector licensing, sanctions designation and privacy position with DIA, the FIU and qualified New Zealand counsel before launch.