KYC Requirements in New Zealand: AML/CFT Act Obligations for Banks and Reporting Entities
New Zealand's AML/CFT framework has continued to evolve, including the customer risk-rating requirement effective 1 June 2025 and major 2026 legislative and supervisory changes. From 1 June 2025, reporting entities must keep a record of a customer's risk rating, review it during ongoing customer due diligence and account monitoring, and update it where appropriate. From 1 July 2026, the Department of Internal Affairs (DIA) became the sole AML/CFT supervisor.
This guide covers who the AML/CFT Act applies to, what CDD requires at each level, what the customer risk-rating requirement means operationally, how reporting works, and where programmes commonly need strengthening.

Who the AML/CFT Act covers
The AML/CFT Act uses the term "reporting entity" for organisations with KYC and CDD obligations. The scope of covered organisations expanded in two stages beyond the original 2009 Act.
The original group of reporting entities included financial institutions, casinos and other businesses captured by the Act. The regime was later extended to additional sectors, including lawyers, conveyancers, accountants, real estate agents and high-value dealers, with sector-specific commencement dates and requirements.
Phase 2 entities are subject to the AML/CFT Act once their sector is captured, but the detailed obligations can vary by business model, service and applicable exemptions. It is therefore more accurate to say that they share the Act's core CDD, risk-assessment, programme, record-keeping and reporting framework, rather than that every obligation is identical to that of a bank.
Supervision and guidance: DIA, RBNZ, FMA and the 2026 transition
Before 1 July 2026, AML/CFT supervision was divided among RBNZ, FMA and DIA. From 1 July 2026, DIA became the sole AML/CFT supervisor. RBNZ and FMA continue to perform their wider prudential and conduct functions, but reporting entities should update AML/CFT programmes, policies and regulatory references to reflect the single-supervisor model.
Before the transition, RBNZ supervised banks, non-bank deposit takers and certain insurers for AML/CFT purposes. Those AML/CFT supervisory responsibilities now sit with DIA, while RBNZ retains its broader prudential mandate.
Before the transition, FMA supervised relevant financial-markets reporting entities for AML/CFT purposes. Those AML/CFT supervisory responsibilities now sit with DIA, while FMA retains its wider financial-markets conduct and licensing functions.
DIA supervised the remaining reporting entities before the transition and became the sole AML/CFT supervisor on 1 July 2026. The article should not attribute current examination findings to a three-supervisor structure without an as-of date and a supporting source.
The New Zealand Police Financial Intelligence Unit remains the recipient of SARs and prescribed transaction reports. It is not the AML/CFT supervisor; it receives, analyses and disseminates financial intelligence to Police, domestic agencies, overseas FIUs and other law-enforcement partners.
When CDD must be performed
The AML/CFT Act requires CDD when establishing a business relationship, when conducting an occasional transaction or activity that falls within the Act, when suspicion arises, and in other circumstances specified by the Act, such as doubts about previously obtained identity information.
- Before establishing a business relationship — CDD should generally be completed before the relationship is established, subject to the limited, risk-managed circumstances permitted by the Act and guidance.
- Occasional transactions and prescribed transactions should not be conflated. NZD 10,000 or more in domestic physical cash and NZD 1,000 or more in an international funds transfer are prescribed-transaction reporting thresholds. There is not a universal rule that every wire transfer to a high-risk country automatically triggers a new CDD process; the applicable CDD requirements depend on the transaction, customer and statutory provisions.
- When suspicion arises — CDD and reporting obligations apply regardless of transaction value, subject to the Act's provisions on not proceeding where CDD cannot be completed and on avoiding tipping off.
The inability to complete CDD to the required standard is grounds for declining to establish or continue the relationship, or for not proceeding with the relevant activity, and the entity should consider whether a SAR is required.

Three tiers of CDD
Reduced or simplified CDD may be available for prescribed customer categories and circumstances under the Act and regulations, such as certain government entities, listed issuers and regulated financial institutions. The entity must confirm that the customer fits the relevant category and apply the conditions of the applicable provision; low perceived risk alone is not enough.
Standard CDD is the baseline for all other customers. It requires:
- Customer identification: full legal name, date of birth (individuals), business registration number and registered address (entities)
- Verification against reliable, independent sources — not simply collecting documents but confirming the identity presented is genuine
- Beneficial ownership identification for legal entity customers (see below for the 25% threshold)
- Nature and purpose of the business relationship documented
- Ongoing monitoring of the relationship for consistency with the customer's profile
- From 1 June 2025: the customer risk rating must be recorded and maintained as part of the CDD record. The rating should be based on the entity's defined, risk-based criteria and reviewed during ongoing CDD and account monitoring.
Enhanced customer due diligence applies where the Act requires it or where the entity's risk assessment determines that enhanced measures are warranted. Current DIA guidance, including the 2026 Enhanced CDD guidance, should be used alongside the Act and regulations.
- Politically Exposed Persons (PEPs): The Act requires enhanced measures for foreign PEPs and applies a risk-based approach to other PEP situations. Enhanced measures may include senior approval, source-of-wealth and source-of-funds work, and enhanced ongoing monitoring. The precise treatment should follow the Act and current DIA guidance rather than an outdated sector-specific guideline.
- Correspondent banking relationships: Before establishing one, the institution should assess the respondent's AML/CFT controls, confirm that it is not a shell bank, understand the nature of its business and obtain the required senior-management approval.
- Non-face-to-face business relationships: Where the customer is not physically present for identification, the entity must apply the additional or alternative verification and risk controls required by the Act, regulations, applicable identity-verification code and current guidance.
- High-risk countries: Connections to countries identified as higher risk should inform the risk assessment and may require enhanced CDD. The treatment should be risk-based and aligned with current DIA country-risk guidance, rather than described as an automatic rule for every connection.
- Complex or unusual structures and transactions: Arrangements with no apparent economic or legal purpose, unusual complexity, or features that obscure ownership or control should be investigated and may require enhanced CDD, refusal or restriction of the activity, and/or a SAR.
The June 2025 risk-rating change
The customer risk-rating requirement became effective on 1 June 2025. Reporting entities must keep a record of the customer's risk rating, review it when conducting ongoing CDD and account monitoring, and update it where appropriate. The requirement should be described as a statutory record-and-review obligation, not as a mandate to use one universal low/medium/high model.
From June 2025:
- A risk rating should be recorded when the entity conducts CDD for a new customer or relationship in the circumstances covered by the Act. The rating methodology and categories are for the entity to define, provided they are risk-based and sufficiently documented.
- The risk rating must be kept as a record in the CDD file
- The rating must be reviewed when conducting ongoing CDD and account monitoring, and updated where appropriate
The operational implication is that the CDD file should show the customer's risk rating, the factors supporting it, and subsequent review or change decisions. The Act does not prescribe one mandatory scoring scale; a low/medium/high model is only one possible implementation.
Beneficial ownership: the 25% threshold
The AML/CFT Act requires reporting entities to identify beneficial owners — natural persons who ultimately own or control the customer or on whose behalf an activity is conducted. A 25% ownership or voting-interest indicator is useful in practice, but it should not be presented as a universal statutory threshold that ends the analysis. Control through other means must also be considered.
Where no individual can be identified through ownership, the entity must consider effective control through other means and apply the relevant senior-managing-official approach. Layered companies, trusts and partnerships require a look-through analysis appropriate to the structure.
Current DIA guidance emphasises that company-register information may not by itself establish ultimate beneficial ownership where nominee arrangements, layered ownership or other control features create uncertainty. The entity should document the sources checked and the reasoning supporting its conclusion.
Record keeping and SAR filing
Record keeping: CDD, transaction and account records must generally be retained for at least five years, with the precise starting point depending on the record category and whether the relationship has ended or the activity was a one-off transaction. Records must permit transactions and decisions to be reconstructed and be produced promptly to the supervisor or FIU when required.
The customer risk rating is now part of the information that must be recorded and available for examination where the Act and guidance require it.
Suspicious Activity Reports are filed with the New Zealand Police FIU through GoAML Web. SAR is the umbrella term for suspicious activity and suspicious transaction reporting. There is no minimum transaction-value threshold: a report may be required regardless of amount when the statutory suspicion test is met.
A SAR must be submitted to the FIU no later than three working days after reasonable grounds for suspicion are formed, according to NZ Police guidance.
Common KYC failures in New Zealand examinations
Supervisory expectations include substantive beneficial-owner analysis, effective programme implementation, risk-based CDD, documented decisions, ongoing monitoring and timely reporting.
Beneficial ownership not looked through to natural persons. The entity-level identification is complete but the look-through to ultimate individual owners is not performed. Holding company structures and nominee arrangements are accepted at face value.
Programme maturity, risk-rating implementation and reporting processes should be assessed against the current Act, the 2026 amendments and DIA's updated guidance.
Risk-rating obligation not yet embedded. From 1 June 2025, entities should have a documented risk rating and review process. Whether a breach exists depends on the applicable statutory requirement and the entity's facts; avoid declaring every workflow gap automatically a breach without that assessment.
Reduced or simplified CDD should be used only where the customer and circumstances meet the relevant statutory or regulatory conditions. An entity should not apply it merely because a customer appears low risk.
Ongoing monitoring not connected to CDD record. Transaction monitoring alerts are generated in one system and CDD records are maintained in another. When a monitoring alert changes what is known about a customer, the CDD risk rating is not updated. The two records diverge over time.
No audit trail for CDD decisions. Current DIA guidance expects entities to be able to evidence the information obtained, sources used, verification performed, risk assessment and decisions made. A record that only says CDD was completed may be inadequate.
How Tookitaki’s FinCense supports New Zealand KYC compliance
The connection between CDD, customer risk rating and ongoing monitoring is important under the current framework. A rating should be reviewed when monitoring or other information changes the risk profile, subject to the entity's documented risk-based process.
FinCense connects customer risk profiling with transaction monitoring on a unified platform. Customer risk ratings are updated as monitoring alerts and case findings accumulate rather than remaining fixed at the initial assessment. The CDD record — including the June 2025 risk rating — lives in the same environment as the transaction monitoring history, so ongoing CDD reviews draw on the same data that the monitoring function is generating continuously.
For SAR filing via GoAML, FinCense case management can generate report-ready documentation from investigation records, with the filing decision and timeline visible at the case level. The reporting entity remains responsible for submitting the SAR through the prescribed FIU channel and meeting the three-working-day deadline.
Book a demo to see how FinCense handles KYC and CDD for New Zealand reporting entities — including risk-rating workflows and SAR preparation for submission through the NZ Police FIU's GoAML process.
Frequently asked questions
What did the June 2025 AML/CFT Act amendments change for KYC in New Zealand?
The customer risk-rating requirement became effective on 1 June 2025. Reporting entities must keep a record of the customer's risk rating, review it during ongoing CDD and account monitoring, and update it where appropriate. DIA published guidance to support implementation. The article should not state that a particular workflow is automatically in breach without assessing the entity's circumstances.
Who must comply with AML/CFT KYC requirements in New Zealand?
Reporting entities under the AML/CFT Act must comply with the applicable obligations. The sectors captured include financial institutions, casinos, lawyers, conveyancers, accountants, real estate agents, high-value dealers and other businesses specified by the Act and regulations. Since 1 July 2026, DIA is the sole AML/CFT supervisor, while NZ Police FIU receives SAR and prescribed-transaction reports.
What is the beneficial ownership threshold under New Zealand's AML/CFT Act?
The Act's core test is ultimate ownership or control. A 25% ownership or voting-interest indicator may guide the analysis, but it does not replace the requirement to consider control through other means, nominee arrangements and layered structures.
What is the difference between standard and enhanced CDD under the AML/CFT Act?
Standard CDD generally requires identity information and verification, beneficial-owner and acting-on-behalf-of checks, information about the nature and purpose of the relationship, ongoing CDD and the required customer risk-rating record. Enhanced CDD applies where the Act, regulations, risk assessment or current DIA guidance require it, including relevant PEP, correspondent-banking, non-face-to-face, trust and high-risk situations.
How are Suspicious Activity Reports filed in New Zealand?
SARs are submitted through GoAML Web to the NZ Police FIU. The SAR framework has no minimum transaction-value threshold, and NZ Police guidance states that a SAR must be submitted no later than three working days after reasonable grounds for suspicion are formed. SAR records should be retained in accordance with the Act's record-keeping requirements.
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Top AML Scenarios in ASEAN

The Role of AML Software in Compliance

The Role of AML Software in Compliance





