Compliance Hub

Fraud Prevention in New Zealand: What Banks and Financial Institutions Need to Know in 2026

Site Logo
Tookitaki
31 Aug 2026
5 min
read

New Zealand's scam-prevention framework changed materially at the end of 2025. Banks now operate under five specific protection commitments and a conditional compensation scheme, while the country's wider anti-scam response remains based largely on voluntary, cross-sector action.

Gross scam losses reported through New Zealand bank accounts reached approximately NZD 265 million in the 12 months reported in November 2025. That figure demonstrates the scale of the problem, but it is not a complete estimate of nationwide harm: it reflects losses visible through participating financial institutions and does not capture every unreported or non-bank scam.

The cost to individual victims can be severe. In its 2023-24 annual report, the Banking Ombudsman Scheme said the average reported scam loss was about NZD 80,000, up from NZD 57,000 a year earlier. The Scheme also reported that investment scams produced the greatest losses among the scam complaints it received.

The industry's principal response took effect on 30 November 2025, when the New Zealand Banking Association (NZBA) updated its Code of Banking Practice. The Code introduced five scam-protection commitments and a compensation process for eligible consumers affected by authorised payment scams. The framework is significant, but it is not a blanket guarantee that every scam victim will be reimbursed.

Talk to an Expert

The fraud types New Zealand institutions face

Investment scams. Fraudsters use fake trading platforms, deepfake or impersonation advertising, social-media groups and direct messaging to promote false investment opportunities. Some schemes build trust over weeks or months and encourage victims to make a series of increasingly large payments. For a bank, the individual payments may initially resemble legitimate customer-authorised transfers; the risk becomes clearer when the sequence, beneficiary and wider network are analysed together.

Authorised payment scams. In an authorised payment scam, the customer is deceived into approving a payment to a criminal. Examples include bank-impersonation scams, romance scams, investment scams and false-invoice schemes. Controls designed mainly to detect stolen credentials or an unfamiliar device may miss these cases because the genuine customer is initiating the payment. Effective prevention therefore also considers the payment purpose, beneficiary risk, the customer's normal behaviour and relevant scam indicators.

Bank impersonation. Criminals may pose as a bank's fraud team through calls, text messages or email, sometimes using spoofed caller information or personal details obtained elsewhere. The victim may be pressured to disclose credentials or move money to a supposedly safe account. The National Cyber Security Centre (NCSC) has specifically warned New Zealanders about criminals impersonating banks and using urgency to overcome normal caution.

Phishing, credential theft and account takeover. Phishing links and fraudulent login pages can enable criminals to access accounts, change payment details or initiate unauthorised transfers. These cases differ from authorised payment scams because the criminal, rather than the customer, executes the transaction. Banks need controls for both attack paths and a clear way to distinguish them during investigation and compensation decisions.

Business email compromise. Business email compromise redirects legitimate supplier, payroll or settlement payments by altering payment instructions or impersonating an authorised employee. Relevant indicators can include an unexpected beneficiary change, an unusual approval pattern, new payment instructions or a mismatch between the stated purpose and the receiving account.

Money mule activity. Scam proceeds often move through accounts controlled by complicit or unwitting money mules. Rapid pass-through behaviour, multiple unrelated incoming payments, shared devices or contact details, and connections to known high-risk beneficiaries can all be relevant. Cross-bank intelligence adds context that a single institution may not possess, but useful mule indicators can also be detected within an institution's own customer and transaction data.

The regulatory and industry framework

AML/CFT Act 2009

Fraud and AML/CFT obligations overlap, but they are not identical. Fraud is a common source of criminal proceeds, so an account receiving and moving scam funds can create money-laundering risk and may trigger suspicious-activity reporting obligations. Section 58 of the AML/CFT Act requires a reporting entity to assess the money-laundering and terrorism-financing risks it may reasonably expect to face. It does not, by itself, create a general fraud-risk assessment obligation. Fraud typologies should be incorporated where they are relevant to the institution's assessed ML/TF exposure.

The supervisory structure also changed during 2026. From 1 July 2026, the Department of Internal Affairs (DIA) became New Zealand's sole AML/CFT supervisor, taking over the AML/CFT supervisory responsibilities previously divided among DIA, the Reserve Bank of New Zealand and the Financial Markets Authority. RBNZ and the FMA continue to perform their separate prudential, market-conduct and enforcement functions.

FMA's role in investment scams

The Financial Markets Authority regulates New Zealand's financial markets and publishes warnings about suspicious, unregistered or impersonating investment businesses. It can investigate conduct within its statutory remit and work with domestic and international agencies, but it is not the sole agency responsible for every investment scam. Depending on the conduct, New Zealand Police, the Serious Fraud Office, the Commerce Commission, the NCSC and overseas authorities may also be involved. Financial institutions should use FMA warnings as one source of risk intelligence rather than as a complete list of fraudulent operators.

NZBA Code of Banking Practice

The Code amendment applies from 30 November 2025 to NZBA member banks. It establishes five commitments for protecting consumers from authorised payment scams:

  • Provide payment-purpose-based education warnings before certain payments, including warnings for known high-impact scam types where appropriate.
  • Offer Confirmation of Payee through consumer retail mobile and web-banking channels so customers can check whether the payee name matches the account name.
  • Maintain policies and processes to identify and respond to high-risk transactions, potentially using questions, warnings, delays or blocks.
  • Provide 24/7 options for customers to report scams and respond within a reasonable timeframe to protect accounts and seek recovery.
  • Share information with other NZBA member banks to help prevent scams, recover money and freeze or close scammer and mule accounts where appropriate.

The Code does not guarantee compensation merely because a scam occurred. An eligible consumer may receive all or part of the direct financial loss when the sending bank, or the NZBA member bank that received the payment, failed an applicable scam-protection commitment. Eligibility includes a domestic payment to a New Zealand bank account after 30 November 2025, reporting to both Police and the bank within the required time limits, cooperation with reasonable information requests, and other conditions. Payments made through a third-party payment service and purchases through social-media or equivalent online marketplaces are excluded.

The amount of compensation also depends on whether the consumer took reasonable care. APP-scam compensation is ordinarily limited to three claims during the banking relationship and a combined maximum of NZD 500,000, after which the bank has discretion. Once the bank has the information needed to assess the matter, it must pay any compensation determined to be due within 30 business days. These conditions are set out in the Code amendment.

Government and cross-sector activity

New Zealand does not currently have a single consolidated scam-prevention and reimbursement statute equivalent to Australia's Scams Prevention Framework Act 2025. The banking commitments remain part of an industry Code, although general criminal, consumer, financial-markets and AML/CFT laws continue to apply.

The New Zealand Anti-Scam Alliance brings together government agencies, banks, telecommunications providers, digital platforms and consumer organisations. Its 2026 programme continues to emphasise collaboration, disruption, education and voluntary sector codes. Planned work includes reviewing the banking commitments, expanding access to Confirmation of Payee, developing a wider scam-prevention code framework and researching appropriate cross-sector data sharing. The Government is also progressing a safe-harbour defence intended to let online service providers disrupt suspected scams when they act reasonably and in good faith.

NCSC reporting

For the first quarter of 2025, the NCSC recorded NZD 7.8 million in reported direct financial loss, 14.7% higher than the previous quarter. Scams and fraud accounted for NZD 6.5 million, including around NZD 5 million associated with unauthorised money transfers or business email compromise. These are reported losses, not an estimate of total fraud in New Zealand, and should not be extrapolated using an unsupported fixed reporting-rate assumption.

fraud_prevention_new_zealand_under_200kb

What effective fraud prevention requires

1. Layered controls for authorised payment scams

An effective APP-scam programme combines customer-facing warnings with behavioural monitoring and intervention. Relevant factors may include the customer's stated payment purpose, a new or recently changed beneficiary, an unusual amount, repeated or escalating transfers, the receiving account's risk profile, recent contact-centre activity and deviations from the customer's established behaviour. No single indicator proves a scam; the objective is to identify combinations that justify an additional warning, a question, a temporary delay or a block.

2. Confirmation of Payee embedded in the payment journey

Confirmation of Payee compares the entered payee name with the name associated with the receiving account and returns a match outcome. The result must be explained clearly so the customer understands the risk of proceeding after a mismatch or when a match cannot be confirmed. CoP is an important safeguard against misdirected and fraudulent payments, but it is not a standalone fraud-detection system: a scammer may persuade a victim to pay an account under its genuine name.

3. Investment-scam sequence detection

Investment scams often unfold through a sequence rather than a single obviously fraudulent transaction. Institutions should consider patterns such as escalating transfers to the same beneficiary, multiple unrelated customers paying the same receiving account, payments following a recent change in customer behaviour, or rapid movement of funds through the receiving account. FMA warnings and other threat intelligence can enrich these controls, but they should supplement behavioural detection rather than replace it.

4. Mule-account and beneficiary-risk analysis

Receiving-side controls are as important as sending-side warnings. Banks should assess rapid inflow-and-outflow patterns, concentration of unrelated senders, shared identity or device attributes, beneficiary relationships and links to previously reported accounts. Cross-bank sharing under the NZBA commitment can improve the timeliness of this analysis, subject to legal, privacy and operational controls.

5. Fraud and AML convergence

The same account can be the destination of a scam, a money-mule account and part of a laundering chain. Fraud and AML teams therefore benefit from shared customer context, consistent entity resolution and coordinated case management. This does not remove the distinction between fraud operations and statutory AML/CFT duties; it helps both functions investigate the same risk with fuller information. For more on this operating model, see Tookitaki's guide to FRAML.

Questions institutions should ask about their current controls

  • Do payment-purpose questions and scam warnings change according to the risk presented, or are they generic messages that customers routinely dismiss?
  • Can the institution detect a suspicious sequence across multiple customer-authorised transfers, rather than assessing each payment in isolation?
  • Are sending-side fraud signals, receiving-account risk and AML indicators available to the same investigation workflow?
  • Can customers report a scam at any time, and are payment recovery and receiving-bank escalation processes documented and tested?
  • Is Confirmation of Payee implemented in the relevant consumer channels with clear match, close-match, no-match and unavailable outcomes?
  • Can the institution receive, assess and act on scammer-account intelligence from other NZBA member banks within an appropriate timeframe?
  • Are compensation decisions evidenced against the Code's eligibility conditions, applicable bank commitments and reasonable-care test?

How Tookitaki’s FinCense supports fraud prevention in New Zealand

FinCense brings fraud detection, AML transaction monitoring, customer risk context and case management into a unified financial-crime environment. This can help institutions assess fraud and AML indicators against the same underlying customer and transaction context, reduce duplicated investigations and maintain a more coherent audit trail.

FinCense also draws on the Anti-Financial Crime (AFC) Ecosystem, a community-driven repository of validated financial-crime typologies and scenarios contributed by financial institutions and experts. The model shares typology logic and risk patterns rather than customer records, transaction data or account information. A participating institution selects relevant scenarios, calibrates them to its own environment, tests their likely impact and governs their deployment.

For New Zealand institutions, this approach can support the Code commitment to identify and respond to high-risk transactions by improving coverage of APP-scam, investment-scam, business-email-compromise and mule-account behaviours. However, the AFC Ecosystem does not itself replace Confirmation of Payee or the operational bank-to-bank exchange of scammer-account information required under the NZBA Code. Those capabilities require the appropriate domestic payment, data-sharing and interbank arrangements.

FinCense case management can consolidate alerts, investigation evidence, decisions and SAR preparation. The exact connection to the New Zealand Police FIU's goAML channel depends on the institution's deployment and integration design; institutions should verify the required workflow, format and submission controls during implementation.

For broader platform evaluation criteria, see Tookitaki's AML software guide.

Book a demo to see how FinCense can support authorised payment-scam detection, investment-scam monitoring, mule-account analysis and coordinated fraud and AML investigations for New Zealand banks and financial institutions.

Frequently asked questions

How much is lost to scams in New Zealand?

The New Zealand Government cited approximately NZD 265 million in gross scam losses reported through New Zealand bank accounts over the 12-month period discussed in November 2025. This is an industry-reported measure, not a complete estimate of all scam harm in New Zealand, and it should be described with its reporting period and scope.

What does the NZBA Code require banks to do?

From 30 November 2025, NZBA member banks committed to targeted pre-payment warnings, Confirmation of Payee, identification and appropriate handling of high-risk transactions, 24/7 scam-reporting options, and information sharing with other member banks to prevent scams and freeze or recover funds where appropriate.

Are New Zealand banks legally required to reimburse every scam victim?

No. The compensation framework is contained in the voluntary NZBA Code rather than a general statutory reimbursement regime. Compensation is available only when the customer and payment meet the eligibility conditions and an applicable commitment was not met by the sending or receiving NZBA member bank. The amount can also depend on whether the consumer took reasonable care.

What is the difference between an authorised payment scam and unauthorised fraud?

In an authorised payment scam, the genuine customer is deceived into approving the transfer. In unauthorised fraud, another person accesses or uses the customer's banking without authority. The distinction affects detection, investigation and the applicable compensation test under the Code.

Who supervises AML/CFT compliance in New Zealand in 2026?

The Department of Internal Affairs has been the sole AML/CFT supervisor since 1 July 2026. The Reserve Bank continues its prudential role and the FMA continues its financial-markets and conduct functions, but they no longer divide AML/CFT supervision with DIA.

Can shared typologies satisfy the NZBA information-sharing commitment?

Shared typologies can strengthen an institution's detection controls, but they are not the same as exchanging scammer-account information and acting to freeze or recover funds. Institutions need both: privacy-preserving threat intelligence for better detection and the authorised operational channels needed for bank-to-bank scam response.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
28 Aug 2026
5 min
read

Fraud Prevention for Philippine Banks: AFASA, BSP Requirements and What They Mean in Practice

Understand how AFASA and BSP Circulars 1213-1215 reshape fraud prevention for Philippine banks, including real-time monitoring, stronger authentication, customer controls, disputed-fund holds and coordinated verification.

Fraud Prevention for Philippine Banks: AFASA, BSP Requirements and What They Mean in Practice
Blogs
24 Aug 2026
5 min
read

Pawned Condos, Hidden Money Trails: The AML Risk Behind Pasay’s Sangla-Kolekta Scam

Explore AML lessons from Pasay’s sangla-kolekta condo scam, where fake property claims exposed risks around victim funds, cash collection and mule accounts.

Pawned Condos, Hidden Money Trails: The AML Risk Behind Pasay’s Sangla-Kolekta Scam
Blogs
21 Aug 2026
6 min
read

Sanctions Screening in New Zealand: Legal Requirements and Good Practices for Financial Institutions

Understand sanctions screening requirements in New Zealand, including UN sanctions, the Russia Sanctions Act 2022, DIA supervision, screening obligations and good practices for financial institutions.

Sanctions Screening in New Zealand: Legal Requirements and Good Practices for Financial Institutions