- New Zealand
- Resources
- Compliance checklist
New Zealand AML/CFT Compliance Checklist
Use this free on-page checklist to see which core AML/CFT duties have been dealt with and what may still need work.
How this guide was researched and reviewedOn this page
Short answer
A reporting entity needs a written risk assessment and programme that are used in day-to-day work. Customer checks, reporting, records, training, annual reporting and audit must also be managed.
This checklist covers the main duties. Extra duties can apply to a sector, activity, designated business group or transaction.
At a glance
Start With These Four Questions
Is the scope written down?
The reporting-entity category, activities and New Zealand link should be recorded.
Does the programme match the risk?
The controls should flow from the business’s own risk assessment.
Can each decision be shown?
Records should show CDD, customer risk, monitoring, reporting and review.
Are dates under control?
Annual reporting, audit, record keeping and review dates should be tracked.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- AML/CFT
- Rules that help stop money laundering and terrorism financing.
- Reporting entity
- A business or person that must follow the AML/CFT Act for an activity it carries on.
- CDD
- Customer due diligence. These are checks used to know the customer, owners and people acting for them.
- Beneficial owner
- The real person who owns or controls a customer, or for whom a transaction is done.
- SAR
- Suspicious activity report. This is sent through goAML when the legal test for suspicion is met.
- Independent audit
- A check by a suitable independent person to see whether the risk assessment and programme meet the rules and work.
Part 1
Work Through the Core Duties
Tick an item only when it has been completed and evidence can be shown. Your progress stays in this browser and is not saved.
Nothing has been marked complete yet.
Part 2
How to Use This Checklist
Start with the legal scope. A business may have no AML/CFT duties for one service but be covered for another.
Ask for evidence for each tick. The programme should describe the process, and the customer or system records should show that the process is followed.
- Step 1
Mark what is complete
Tick an item only when it is in use and the record can be found.
- Step 2
Record each gap
Name what is missing, who will fix it and the date by which it will be fixed.
- Step 3
Deal with higher risk first
Missed CDD, missed reports and weak controls over higher-risk customers should be dealt with first.
A policy statement is not enough on its own. The control should be seen working in a file, report or system.
Part 3
Evidence That Should Be Easy to Find
A clear evidence set makes oversight, a DIA request and an independent audit easier to manage.
- The current risk assessment, programme and version history.
- The compliance officer appointment and senior manager reporting records.
- A scope note for each captured activity.
- Customer files, beneficial ownership checks and customer risk ratings.
- Ongoing CDD, account monitoring and written findings.
- SAR and prescribed transaction escalation and filing records.
- Staff vetting, training and attendance records.
- Annual reports, audit reports and action logs.
Part 4
Key Timing Rules
A calendar should be kept because several duties run on different dates.
- Step 1
Before CDD and the programme
The written risk assessment must be completed first. The programme must then be based on it.
- Step 2
Before new technology or a new product is used
The risk assessment must be reviewed and updated for the new risk before the change is used.
- Step 3
Each year
An annual AML/CFT report must be prepared and filed when required by DIA.
- Step 4
Usually every three years
The risk assessment and programme must be independently audited. A four-year period can apply if DIA gives notice, and DIA can ask for another time.
- Step 5
For at least five years
Risk assessment, programme and audit records must be kept for at least five years after they stop being used on a regular basis. Other record periods also apply.
Part 5
Common Mistakes
- A programme is copied from another business and does not match the risk assessment.
- The latest National Risk Assessment or Sector Risk Assessment is not considered.
- A customer risk rating is saved without reasons.
- CDD is done at onboarding but ongoing CDD and account monitoring are missed.
- A strange transaction is noted but no written finding is kept.
- The annual report is prepared from memory because data was not collected during the year.
- New software or a new service starts before the risk assessment is updated.
- The audit date is measured from the wrong starting point.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every reporting entity need a written risk assessment?
Yes. It must be completed before CDD is carried out or the AML/CFT programme is established.
Does every reporting entity need an AML/CFT programme?
Yes. It must be written, based on the risk assessment and used to manage the risks and duties that apply to the business.
How often is a New Zealand independent audit required?
The default period is every three years. DIA can notify a business that a four-year period applies, and an audit can be requested at another time.
Does an annual AML/CFT report need to be filed?
Reporting entities must prepare an annual report. DIA sets the form and filing period. The current dates should be checked each year.
How long must risk assessment and programme records be kept?
They must be kept for at least five years after they stop being used on a regular basis. Other records have their own retention rules.
Is a completed checklist proof of compliance?
No. Evidence must show that each duty has been met and that each control works. Sector, activity and transaction rules may add more duties.
Reference
Official Sources
This guide cites the following sources.
- Regulator guidanceDepartment of Internal AffairsAML/CFT information for businesses
Current DIA guidance and resources for New Zealand reporting entities.
- Regulator guidanceDepartment of Internal AffairsAML/CFT annual report
Current filing window, access details and annual-report support.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
The current Act, including programme, risk, reporting, records and audit duties.
- Primary lawNew Zealand LegislationRequirements and Compliance Regulations 2011
Current detailed requirements, including the default independent-audit period.