Compliance Hub

Sanctions Screening in New Zealand: Legal Requirements and Good Practices for Financial Institutions

Site Logo
Tookitaki
21 Aug 2026
6 min
read

For most of New Zealand's regulatory history, sanctions compliance centred on sanctions mandated by the United Nations Security Council (UNSC) and implemented domestically through regulations under the United Nations Act 1946.

That changed significantly in 2022.

The Russia Sanctions Act 2022 gave New Zealand the ability to impose autonomous sanctions in response to Russia's invasion of Ukraine, without requiring a corresponding UN Security Council resolution. This introduced an additional sanctions regime that New Zealand businesses and financial institutions needed to incorporate into their compliance frameworks.

Since then, New Zealand's Russia sanctions regime has expanded to cover hundreds of individuals, entities and other designated persons or assets. For compliance teams, this has increased the importance of maintaining current sanctions data and ensuring that customer, beneficial ownership and payment controls can identify exposure to newly designated parties.

This guide explains New Zealand's current sanctions framework, how sanctions obligations interact with the AML/CFT regime, and the practical controls financial institutions can adopt to manage sanctions risk effectively.

Talk to an Expert

The New Zealand Sanctions Framework

New Zealand sanctions obligations arise from several legislative regimes.

United Nations Act 1946 — UN-mandated sanctions

New Zealand implements sanctions mandated by the UN Security Council through regulations made under the United Nations Act 1946.

These regulations cover sanctions regimes relating to jurisdictions and groups including North Korea, ISIL and Al-Qaeda, Libya, Somalia, South Sudan and others.

Financial institutions therefore need processes capable of identifying persons and entities subject to applicable UN sanctions.

Russia Sanctions Act 2022 — autonomous sanctions

The Russia Sanctions Act 2022 established a standalone autonomous sanctions regime in response to Russia's invasion of Ukraine.

It enables the New Zealand government to impose sanctions independently of the UN Security Council, including restrictions involving designated individuals, entities, services and assets.

The Ministry of Foreign Affairs and Trade (MFAT) maintains the Russia Sanctions Register, which identifies sanctions imposed under the Act and is updated as new sanctions are introduced or existing sanctions are amended.

Terrorism Suppression Act 2002

New Zealand also maintains terrorist designations under the Terrorism Suppression Act 2002, including designations made domestically and those arising from relevant UN processes.

Financial institutions should therefore ensure that their controls account for applicable terrorist designations and associated restrictions.

There is no single list that covers every sanctions obligation

An important operational consideration is that New Zealand's sanctions framework should not be thought of as one single "MFAT consolidated sanctions list."

Depending on their activities and legal exposure, institutions may need to account for sources including:

  • the UN Security Council Consolidated List and relevant UN sanctions regimes;
  • New Zealand's Russia Sanctions Register; and
  • applicable terrorist designations.

Institutions with international operations, overseas parent companies, correspondent banking relationships or exposure to other jurisdictions may also need to consider sanctions imposed by authorities such as Australia's Department of Foreign Affairs and Trade (DFAT), the US Office of Foreign Assets Control (OFAC), the UK and the European Union.

These additional lists are not automatically New Zealand legal requirements simply because an institution operates in New Zealand. Their relevance depends on the institution's activities, legal exposure, counterparties and contractual or group-level requirements.

AML/CFT Supervision in New Zealand

New Zealand's AML/CFT supervisory structure changed materially in 2026.

From 1 July 2026, the Department of Internal Affairs (DIA) became New Zealand's sole AML/CFT supervisor.

Previously, supervisory responsibility had been divided between the Reserve Bank of New Zealand (RBNZ), Financial Markets Authority (FMA) and DIA.

DIA now oversees reporting entities under the AML/CFT framework.

The New Zealand Police Financial Intelligence Unit (NZ Police FIU) continues to receive suspicious activity reports and other financial intelligence. It is not the AML/CFT supervisor but plays an important role in receiving and analysing financial intelligence and sharing it with relevant domestic and international authorities.

Sanctions Compliance and the AML/CFT Act: An Important Distinction

Sanctions compliance and AML/CFT compliance are closely connected, but they are not the same legal obligation.

New Zealand sanctions legislation prohibits certain dealings with designated persons, entities, services or assets and can impose reporting and other obligations.

Separately, the AML/CFT Act requires reporting entities to conduct customer due diligence, identify and understand beneficial ownership, conduct ongoing monitoring, maintain required records and report suspicious activity.

Effective sanctions screening brings these obligations together operationally.

The important distinction is between what the law requires and the controls institutions commonly implement to manage the risk of breaching those requirements.

What the Law Requires

Depending on the applicable sanctions regime and circumstances, an institution may be prohibited from dealing with a sanctioned or designated person, providing certain services, dealing with restricted assets, or undertaking other prohibited activities.

Institutions must also comply with applicable reporting requirements.

Under the AML/CFT Act, reporting entities separately have obligations relating to customer due diligence, beneficial ownership, ongoing monitoring and suspicious activity reporting.

These underlying obligations are continuous. A customer that presented no sanctions concern when a relationship began may subsequently become subject to sanctions.

Good Practice: Customer and Beneficial Owner Screening

Although New Zealand law should not be characterised as prescribing one universal technological process for sanctions screening, screening is an important practical control for institutions seeking to avoid prohibited dealings.

A robust sanctions programme will typically consider screening:

  • customers as part of onboarding and customer due diligence;
  • beneficial owners and persons exercising control over legal entities;
  • relevant counterparties and payment participants;
  • existing customers when relevant sanctions designations change; and
  • customers when material information or risk circumstances change.

This is particularly important for corporate structures.

The AML/CFT framework requires institutions to understand beneficial ownership as part of customer due diligence. From a sanctions perspective, checking only a company's legal name may be insufficient where a designated individual owns or controls the entity.

Good Practice: Ongoing and Event-Driven Re-screening

Sanctions exposure does not end after onboarding.

New designations can be introduced and existing sanctions can be amended. Institutions therefore need controls capable of identifying whether an existing customer or relevant party has subsequently become subject to sanctions.

New Zealand law does not prescribe a single universal re-screening frequency for every institution.

The appropriate approach should reflect the institution's risk profile, customer base, products, payment activity and sanctions exposure.

For institutions with meaningful customer or transaction volumes, automated or event-driven re-screening following relevant list updates is a strong compliance practice because it reduces the period during which a newly designated party could remain undetected.

Weekly or monthly batch screening may create exposure where relevant sanctions designations change between screening cycles.

Good Practice: Payment Screening Before Execution

Financial institutions processing domestic and international payments face a particular challenge: once a prohibited payment has been executed, the institution may already have engaged in a prohibited dealing.

Screening relevant payment participants before execution is therefore an important control for institutions exposed to sanctions risk.

This should be distinguished from saying that the AML/CFT Act universally mandates a particular "real-time sanctions screening" technology.

The compliance objective is to prevent prohibited dealings. For institutions processing high volumes of payments, real-time or near-real-time screening before execution is often the most effective way to achieve that objective.

What Happens When a Potential Match Is Identified?

A sanctions-screening alert is not automatically a confirmed sanctions match.

The institution should first determine whether the person or entity identified in the transaction or customer relationship is actually the designated party.

This requires considering available identifiers such as:

  • full name and aliases;
  • date of birth;
  • nationality;
  • address;
  • identification numbers;
  • ownership information; and
  • other identifying information available in the relevant sanctions designation.

Where the identity is confirmed, the institution should determine the restrictions applying to that particular designation and ensure it does not undertake a prohibited dealing.

Depending on the applicable regime and circumstances, additional reporting obligations may arise.

The institution should also assess whether the circumstances give rise to suspicion under the AML/CFT Act. Where the statutory threshold for suspicious activity reporting is met, a suspicious activity report should be filed with the NZ Police FIU within the applicable timeframe.

This distinction between a potential screening hit, a confirmed sanctions match and suspicious activity is important for avoiding both sanctions breaches and unnecessary disruption to legitimate customers.

Penalties Under the Russia Sanctions Act 2022

Breaching New Zealand's autonomous Russia sanctions can result in significant criminal penalties.

For knowingly or recklessly breaching a sanction, the Russia Sanctions Act provides for penalties of up to:

  • 7 years' imprisonment and/or a fine of NZD 100,000 for an individual; and
  • a fine of NZD 1 million for an entity.

Where an offence results in commercial gain, the court may also order payment of an amount of up to three times the value of that commercial gain.

Separate penalties can apply for failures to comply with reporting and other requirements under the Act.

These penalties make effective sanctions controls an important component of financial crime risk management rather than simply an administrative screening exercise.

Record Keeping and Auditability

AML/CFT reporting entities are subject to record-keeping requirements under the AML/CFT Act.

The general statutory retention period for relevant AML/CFT records is at least five years, although particular sanctions regimes or other legal requirements may impose different record-keeping obligations.

From a sanctions-screening perspective, good practice is to maintain an auditable record showing:

  • when screening occurred;
  • which customer, beneficial owner or transaction party was screened;
  • which sanctions data or list version was used;
  • potential matches generated by the screening process;
  • how alerts were investigated;
  • the evidence considered by analysts; and
  • the final disposition and approvals.

Maintaining this information allows an institution to demonstrate not merely that screening occurred, but how a particular decision was reached.

What Effective Sanctions Screening Looks Like

Comprehensive list coverage

Institutions should first determine which sanctions regimes are legally or operationally relevant to their business.

For a New Zealand institution, this starts with applicable New Zealand sanctions obligations, including relevant UN sanctions implemented in New Zealand and autonomous sanctions under the Russia Sanctions Act.

Depending on the institution's international exposure, additional sanctions regimes such as OFAC, DFAT, UK or EU sanctions may also need to be considered.

Timely list updates

Sanctions designations change.

Reliance on manual downloading and uploading of sanctions data creates the risk that screening will be conducted against outdated information.

Automated sanctions-data ingestion and event-driven screening are therefore good practices for institutions operating at meaningful scale.

Fuzzy name and alias matching

Sanctions screening cannot rely solely on exact name matching.

Individuals may have multiple aliases, alternative spellings or transliterations. This is particularly relevant for names transliterated from scripts such as Cyrillic into Roman characters.

Effective screening systems should therefore be capable of considering aliases and spelling variations while allowing institutions to configure matching thresholds to manage false positives.

Beneficial ownership

Sanctions exposure may exist behind a corporate customer even where the company's own name does not appear on a sanctions list.

Combining customer due diligence and beneficial ownership information with sanctions screening can help institutions identify circumstances in which a designated individual owns or controls an apparently non-designated entity.

Explainable alert resolution

Generating an alert is only the beginning of the process.

Compliance teams should be able to understand why a match occurred, compare relevant identifiers, document their investigation and demonstrate why an alert was confirmed or dismissed.

This becomes particularly important when institutions need to explain their decisions to auditors, regulators or law enforcement.

sanctions_screening_in_new_zealand_under_200kb

Common Sanctions-Screening Gaps

Rather than assuming that particular gaps have been identified as recurring findings by New Zealand regulators without published evidence, institutions should assess their own programmes for weaknesses commonly associated with sanctions screening.

These can include:

Incomplete list coverage. Screening against only one source may leave relevant sanctions regimes outside the institution's controls.

Infrequent re-screening. Long intervals between screening cycles can leave newly designated customers undetected.

Weak alias and transliteration coverage. Exact-name matching may fail to identify alternative spellings or known aliases.

Beneficial owners not included in screening. Screening only the legal entity can miss sanctions exposure through ownership or control.

Outdated sanctions data. Manual list-management processes can create a gap between a designation becoming effective and being incorporated into screening.

Insufficient audit trail. Institutions may be unable to reconstruct which sanctions data was used, why an alert was generated or why an analyst dismissed it.

Disconnected screening and AML investigations. Where sanctions screening, transaction monitoring and case management operate independently, investigators may need to manually reconstruct the customer's broader financial crime risk profile.

New Zealand's Pacific and International Payment Exposure

New Zealand has significant economic and community links with Pacific Island countries and substantial cross-border payment and remittance activity.

Financial institutions and money service businesses operating across these corridors should ensure that their sanctions controls reflect their actual payment flows, counterparties, correspondent relationships and geographic exposure.

This does not mean Pacific corridors inherently present sanctions concerns. Rather, sanctions-screening programmes should be calibrated to the institution's specific cross-border activity and risk exposure.

How Tookitaki's FinCense Supports New Zealand Institutions

Effective sanctions screening requires more than checking names against a list.

Financial institutions need to identify potential matches, investigate them efficiently, document analyst decisions and connect sanctions alerts with the customer's broader AML and transaction-monitoring context.

FinCense supports sanctions screening as part of an integrated financial crime compliance platform.

Screening events can capture information such as match scores, identifiers and analyst decisions, creating an auditable record of how alerts were investigated and resolved.

Screening alerts feed into case management, enabling investigators to examine sanctions concerns alongside relevant customer and transaction-monitoring information rather than reconstructing that context manually across disconnected systems.

For institutions operating at scale, capabilities such as automated list updates, configurable matching, alias handling, alert investigation and auditable decision-making can help translate sanctions obligations into effective operational controls.

Book a demo to see how FinCense's Screening module can support your sanctions and broader financial crime compliance programme.

Frequently Asked Questions

What sanctions lists should New Zealand financial institutions screen against?

There is no single "MFAT consolidated sanctions list" covering every New Zealand sanctions obligation.

Institutions need to identify the sanctions regimes applicable to their activities. Relevant sources can include the UN Security Council Consolidated List and regime-specific UN designations implemented in New Zealand, New Zealand's Russia Sanctions Register and applicable terrorist designations.

Institutions with international legal, payment, correspondent banking or group exposure may also need to consider sanctions imposed by jurisdictions such as Australia, the United States, the UK and EU.

What is the Russia Sanctions Act 2022?

The Russia Sanctions Act 2022 allows New Zealand to impose autonomous sanctions in response to Russia's invasion of Ukraine without requiring corresponding UN Security Council sanctions.

It created a separate New Zealand sanctions regime covering designated individuals, entities, services and assets. MFAT maintains the Russia Sanctions Register containing sanctions imposed under the Act.

Who supervises AML/CFT compliance in New Zealand?

From 1 July 2026, the Department of Internal Affairs is New Zealand's sole AML/CFT supervisor.

Previously, responsibility was divided between DIA, the Reserve Bank of New Zealand and the Financial Markets Authority.

The NZ Police Financial Intelligence Unit continues to receive suspicious activity reports and other financial intelligence.

How often should existing customers be re-screened?

New Zealand law does not prescribe one universal sanctions re-screening interval for every institution.

Institutions should adopt an approach proportionate to their sanctions exposure, customers, products and transaction activity.

For institutions operating at scale, automated or event-driven re-screening when relevant sanctions designations change is a strong compliance practice because it reduces the risk of continuing to deal with a party that has become subject to sanctions.

Do New Zealand financial institutions have to screen payments in real time?

New Zealand law should not be interpreted as universally prescribing a particular real-time screening technology.

However, institutions must avoid prohibited dealings. For payment providers and financial institutions exposed to sanctions risk, screening relevant payment participants before execution can therefore be an important control.

Real-time or near-real-time screening is often the practical approach for institutions processing significant transaction volumes.

How long should sanctions-screening records be retained?

The AML/CFT Act generally requires relevant records to be retained for at least five years. Specific sanctions regimes or other legislation may impose additional or different requirements.

As good practice, institutions should maintain sufficient screening records to demonstrate which data was used, what alerts were generated, how they were investigated and why particular decisions were made.

What are the penalties for breaching the Russia Sanctions Act?

For knowingly or recklessly breaching a sanction, an individual can face up to 7 years' imprisonment and/or a NZD 100,000 fine, while an entity can face a fine of up to NZD 1 million.

A court may additionally impose an amount of up to three times the value of any commercial gain resulting from the offence.

Separate penalties apply to certain reporting and other breaches under the Act.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
21 Aug 2026
7 min
read

Sanctions Screening in the Philippines: BSP and AMLC Requirements

Understand sanctions screening requirements in the Philippines, including BSP and AMLC rules, targeted financial sanctions, re-screening, freeze obligations, reporting, and good practices for financial institutions.

Sanctions Screening in the Philippines: BSP and AMLC Requirements
Blogs
17 Aug 2026
5 min
read

From Phone Scam to Gold Bars: How Thailand’s Call-Centre Gang Broke the Money Trail

Explore AML lessons from Thailand’s call-centre scam case, where victim funds moved through mule accounts and were converted into gold bars and smartphones.

From Phone Scam to Gold Bars: How Thailand’s Call-Centre Gang Broke the Money Trail
Blogs
15 Aug 2026
6 min
read

Real-Time Transaction Monitoring: How It Works and What APAC Banks Need

Real-time transaction monitoring is now table stakes for APAC banks — but most implementations fall short. This guide covers how it works, what regulators expect, and the NPP and instant payment implications.

Real-Time Transaction Monitoring: How It Works and What APAC Banks Need