Contents
The Department of Internal Affairs (DIA) celebrated its promotion to sole regulator for the Anti-Money Laundering and Countering Financing of Terrorism Act (AML/CFT Act) by issuing what it describes as “one of the largest AML/CFT resource releases in recent years”.
The 23 guidance notes either updated or refreshed existing guidance, some with significant consequences. The changes are on top of two other guidance notes published in June and the new Identity Verification Code of Practice.
As the AML/CFT Act explicitly requires reporting entities to “have regard” to any applicable guidance produced by the DIA in relation to their risk assessment and compliance programme, we strongly encourage you to familiarise yourselves with the DIA’s new expectations, and consider whether your AML/CFT documents should be updated to reflect the changes. We expect that your next AML audit will focus on these new expectations, including the new risk assessment requirements.
To assist, we have provided a summary of the key changes.
Changes to risk assessment requirements
Effective from 19 May 2026, reporting entities must incorporate all relevant risks identified by either the DIA or the New Zealand Police Financial Intelligence Unit (for example, National Risk Assessments (NRA) and Sector Risk Assessments (SRAs)) in their risk assessment. Previously, reporting entities were required only to “have regard” to applicable guidance material.
In addition, the DIA emphasises that reporting entities must include each captured activity, relevant product or service in the risk assessment. In the new Audit Guidance for risk assessment and AML/CFT programme, the DIA also suggests that the scope of the audit is informed by the NRA and SRA.
All reporting entities will need to review their risk assessments to ensure that they comply with these, and other changes, to the guidance.
The DIA has also flagged that it will be updating, as needed, the remaining SRAs from mid-2026. We expect that, consistent with its approach to date, it will take a risk-based approach to the updates.
The new guidance emphasises that risk assessments must be reviewed or updated for material changes to your business, new products or services, new types of customers, or new threats, vulnerabilities or relevant risks identified by the DIA or FIU. Since 1 June 2024, risk assessments must be updated prior to the use of new or developing technologies or products (including new delivery mechanisms). DIA states that associated exposure to emerging or sudden risks should be carefully considered.
Wire transfer and prescribed transaction reporting (PTR) guidance
This guidance expands on earlier DIA guidance for money remitters in relation to regulatory changes which came into effect in 2023 and 2024.
The guidance also:
- clarifies that the new wire transfer and PTR requirements commence when the transfer of funds forms part of a broader service provided to the customer, accepting that in some circumstances, this may result in “complementary” PTR reporting of the same transaction by both the bank and the non-bank financial institution (NBFI); and
- states DIA’s view that, where the transfer of funds forms part of a broader service, an NBFI can be an “ordering”, “intermediary” or “beneficiary” institution, even when it does not itself control the account, hold the funds, or directly access the relevant payment system, making them subject to prescribed transaction reporting requirements.
The DIA has also published a practice note specifically for NBFIs, reflecting the greater impact these changes will have for them. NBFIs that have relied on the FMA’s differing prior PTR guidance, and complied with it, will have a transition implementation period from 1 July 2026 to 30 June 2027.
Identity Verification Code of Practice (IVCOP) 2026
The new IVCOP came into effect on 1 July 2026. It has been updated to:
- improve clarity and readability;
- also apply to high-risk customers;
- ensure that modern practices and technologies are supported (reflecting advances in technology and digital identity verification practices);
- explicitly allow additional evidence options (e.g., photographic and support documents) to improve usability;
- ease certification requirements (e.g., extending the timeframe for certified documents to 12 months); and
- in certain circumstances where the customer is a legal person rated as low or medium risk, allow for reduced verification steps for beneficial owners and persons “acting on behalf of” the customer.
See also the AML/CFT Programme Guidance which has been amended to reference the new code.
Guidance for offshore businesses
The updated Territorial Scope of the AML/CFT Act guidance introduces a new “three-step test” to help offshore businesses determine whether they are captured by New Zealand’s AML/CFT Act.
- Does the business carry on, or carry out, one or more captured activities in the ordinary course of business?
- Is the captured activity carried on or carried out in New Zealand?
- Is there a sufficient New Zealand connection?
This replaces the “carrying on business in New Zealand” threshold (also used in the Companies Act 1993 for determining registration requirements for overseas companies).
Practical examples are provided of the sorts of offshore activities that might come within scope, including:
Offshore online services
- The DIA confirms that offshore businesses providing regulated services through digital channels are not within scope merely because its website or app can be accessed from New Zealand. However, offshore businesses can be within scope of the AML/CFT Act where the service is “deliberately directed” to New Zealand, and the captured activity is provided to persons in New Zealand in a manner that creates a “real New Zealand connection”. This new guidance expands the potential reach of New Zealand’s AML/CFT laws.
New Zealand entities serving offshore customers
- The DIA confirms that New Zealand companies that perform relevant functions (in relation to captured activities) in New Zealand will usually be “carrying on or carrying out” the activity in New Zealand, even if all customers are offshore.
Foreign businesses with no physical presence
- The DIA states that revenue from persons in New Zealand is relevant but not determinative. Foreign businesses will need to consider how the revenue is earned and how those New Zealand customers were attracted. The activities may be seen as “carried on or carried out” in New Zealand if there is sustained, deliberate provision of captured activities to persons in New Zealand, supported by New Zealand-facing marketing, onboarding, payment channels, support, contractual settings or other New Zealand-facing features (for example, New Zealand pricing).
Offshore businesses who were relying on the previous territorial scope guidance (from 2019) should consider whether their activities are now caught under the broader three-step test. In particular, offshore businesses with New Zealand customers that previously relied on the prior “carrying on business” guidance should consider whether their activities are now covered because they have a sufficient New Zealand connection.
New guidance for reporting entities relying on outsourcing
Outsourcing to a Third-Party Agent and Reliance on Another Reporting Entity recognise the growing reliance on outsourced providers and build on the fact sheet published by the DIA and the Financial Markets Authority (FMA) on outsourcing customer due diligence (CDD).
While the requirements remain similar, the DIA has emphasised that reporting entities must manage the associated risks and regularly assess the arrangement. Reporting entities who rely on other parties to perform AML/CFT functions should ensure they comply with the additional requirements covered in these revised guidance notes.
Broader regulatory environment
The updates also respond to broader regulatory and legislative developments, in particular the shift to the DIA as the single supervisor. Reporting entities should check that they have access to DIA’s “AML Online” portal.
Other regulatory changes, all currently in effect, include:
- removing the requirement to verify address information for standard CDD (although the information must still be collected). This was aimed at easing onboarding requirements for customers who did not have easy access to evidential documents (e.g., customers who were flatting);
- the new risk-based approach that relieves reporting entities from verifying Source of Wealth and Source of Funds information in relation to trusts where the entity is satisfied that any money laundering/terrorism financing (ML/TF) risks have been mitigated by other CDD steps. This is a significant relaxation of the verification requirement for lower-risk trusts, including domestic family trusts which are now defined. The DIA has provided further guidance on how the new approach should be applied in the Customer Due Diligence: Trusts Guidance, including the content required in AML/CFT programmes; and
- the more relaxed requirement that a reporting entity take reasonable steps “according to the level of risk involved” to determine whether a customer (or beneficial owner) is a politically exposed person (PEP). The DIA has provided Enhanced Customer Due Diligence Guidance to cover this scenario.
2027 levies for certain sectors
From 1 July 2027:
- banks/deposit takers will contribute 85% of total levy costs;
- the gambling sector (casinos, including online casinos) will contribute 9% of levy costs; and
- NBFIs and “Designated Non-Financial Businesses and Professions” will contribute the remaining 6% of levy costs.
Next steps
You can find links to all the new guidance here. If you need assistance working through these guidance changes and how they may impact your business, one of our experts will be available to assist.