Practical guide • New ZealandRead the Australia version

New Zealand AML/CFT Compliance Checklist

Use this free on-page checklist to see which core AML/CFT duties have been dealt with and what may still need work.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. Start With These Four Questions
  3. Key words explained
  4. Part 1: Core checklist
  5. Part 2: How to Use This Checklist
  6. Part 3: Evidence That Should Be Easy to Find
  7. Part 4: Key Timing Rules
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

A reporting entity needs a written risk assessment and programme that are used in day-to-day work. Customer checks, reporting, records, training, annual reporting and audit must also be managed.

This checklist covers the main duties. Extra duties can apply to a sector, activity, designated business group or transaction.

At a glance

Start With These Four Questions

  • Is the scope written down?

    The reporting-entity category, activities and New Zealand link should be recorded.

  • Does the programme match the risk?

    The controls should flow from the business’s own risk assessment.

  • Can each decision be shown?

    Records should show CDD, customer risk, monitoring, reporting and review.

  • Are dates under control?

    Annual reporting, audit, record keeping and review dates should be tracked.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

AML/CFT
Rules that help stop money laundering and terrorism financing.
Reporting entity
A business or person that must follow the AML/CFT Act for an activity it carries on.
CDD
Customer due diligence. These are checks used to know the customer, owners and people acting for them.
Beneficial owner
The real person who owns or controls a customer, or for whom a transaction is done.
SAR
Suspicious activity report. This is sent through goAML when the legal test for suspicion is met.
Independent audit
A check by a suitable independent person to see whether the risk assessment and programme meet the rules and work.

Work Through the Core Duties

Tick an item only when it has been completed and evidence can be shown. Your progress stays in this browser and is not saved.

Progress0/14

Nothing has been marked complete yet.

How to Use This Checklist

Start with the legal scope. A business may have no AML/CFT duties for one service but be covered for another.

Ask for evidence for each tick. The programme should describe the process, and the customer or system records should show that the process is followed.

  1. Step 1

    Mark what is complete

    Tick an item only when it is in use and the record can be found.

  2. Step 2

    Record each gap

    Name what is missing, who will fix it and the date by which it will be fixed.

  3. Step 3

    Deal with higher risk first

    Missed CDD, missed reports and weak controls over higher-risk customers should be dealt with first.

A useful rule

A policy statement is not enough on its own. The control should be seen working in a file, report or system.

Evidence That Should Be Easy to Find

A clear evidence set makes oversight, a DIA request and an independent audit easier to manage.

  • The current risk assessment, programme and version history.
  • The compliance officer appointment and senior manager reporting records.
  • A scope note for each captured activity.
  • Customer files, beneficial ownership checks and customer risk ratings.
  • Ongoing CDD, account monitoring and written findings.
  • SAR and prescribed transaction escalation and filing records.
  • Staff vetting, training and attendance records.
  • Annual reports, audit reports and action logs.

Key Timing Rules

A calendar should be kept because several duties run on different dates.

  1. Step 1

    Before CDD and the programme

    The written risk assessment must be completed first. The programme must then be based on it.

  2. Step 2

    Before new technology or a new product is used

    The risk assessment must be reviewed and updated for the new risk before the change is used.

  3. Step 3

    Each year

    An annual AML/CFT report must be prepared and filed when required by DIA.

  4. Step 4

    Usually every three years

    The risk assessment and programme must be independently audited. A four-year period can apply if DIA gives notice, and DIA can ask for another time.

  5. Step 5

    For at least five years

    Risk assessment, programme and audit records must be kept for at least five years after they stop being used on a regular basis. Other record periods also apply.

Common Mistakes

  • A programme is copied from another business and does not match the risk assessment.
  • The latest National Risk Assessment or Sector Risk Assessment is not considered.
  • A customer risk rating is saved without reasons.
  • CDD is done at onboarding but ongoing CDD and account monitoring are missed.
  • A strange transaction is noted but no written finding is kept.
  • The annual report is prepared from memory because data was not collected during the year.
  • New software or a new service starts before the risk assessment is updated.
  • The audit date is measured from the wrong starting point.

Common Questions

Short answers to the questions businesses ask most often.

Does every reporting entity need a written risk assessment?

Yes. It must be completed before CDD is carried out or the AML/CFT programme is established.

Does every reporting entity need an AML/CFT programme?

Yes. It must be written, based on the risk assessment and used to manage the risks and duties that apply to the business.

How often is a New Zealand independent audit required?

The default period is every three years. DIA can notify a business that a four-year period applies, and an audit can be requested at another time.

Does an annual AML/CFT report need to be filed?

Reporting entities must prepare an annual report. DIA sets the form and filing period. The current dates should be checked each year.

How long must risk assessment and programme records be kept?

They must be kept for at least five years after they stop being used on a regular basis. Other records have their own retention rules.

Is a completed checklist proof of compliance?

No. Evidence must show that each duty has been met and that each control works. Sector, activity and transaction rules may add more duties.

Official Sources

This guide cites the following sources.

  1. Regulator guidanceDepartment of Internal Affairs
    AML/CFT information for businesses

    Current DIA guidance and resources for New Zealand reporting entities.

  2. Regulator guidanceDepartment of Internal Affairs
    AML/CFT annual report

    Current filing window, access details and annual-report support.

  3. Primary lawNew Zealand Legislation
    Anti-Money Laundering and Countering Financing of Terrorism Act 2009

    The current Act, including programme, risk, reporting, records and audit duties.

  4. Primary lawNew Zealand Legislation
    Requirements and Compliance Regulations 2011

    Current detailed requirements, including the default independent-audit period.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your New Zealand business does and where the uncertainty sits. We will help you work out the practical AML/CFT response.

Tell us about your situation