- New Zealand
- Resources
- Compliance officer
New Zealand AML/CFT Compliance Officer Responsibilities
A clear guide to who can be a New Zealand AML/CFT compliance officer, what the role covers and the support and evidence it needs.
How this guide was researched and reviewedOn this page
Short answer
The compliance officer administers and maintains the AML/CFT programme. The person should have direct access to senior managers, enough authority and time, and a clear view of CDD, monitoring, reporting, training, records and change.
The role usually must be held by an employee who reports to a senior manager. An external person may be appointed where the reporting entity has no employees.
At a glance
Four Things the Role Needs
Correct appointment
The person should meet the employee and reporting-line requirements in section 56.
Real authority
They need access to leaders, information, systems and enough resources.
Clear oversight
The role should cover daily controls, issues, reporting and programme maintenance.
Visible evidence
Reports, reviews, decisions and action logs should show what has been overseen.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Compliance officer
- The person designated to administer and maintain the reporting entity’s AML/CFT programme.
- Senior manager
- A senior person to whom the compliance officer reports, or who may hold the compliance officer role.
- Administer
- Coordinate the processes, information, decisions and records needed to operate the programme.
- Maintain
- Keep the programme current, adequate, effective and connected with the risk assessment.
- DBG
- Designated business group. Some obligations may be shared when the legal conditions are met.
Part 1
Who Can Hold the Role
- An employee should be designated and should report to a senior manager.
- A senior manager may also be the compliance officer.
- A sole practitioner will usually hold the role personally.
- An external person may be appointed where the reporting entity has no employees.
- The appointment, reporting line and responsibilities should be recorded.
- DIA and AML Online contact details should be kept current.
The person needs the authority, access, time and knowledge to administer and maintain the programme in real life.
Part 2
What the Officer Should Oversee
| Area | Oversight | Useful evidence |
|---|---|---|
| Risk and programme | Keep the documents connected and current | Review log, versions and approvals |
| CDD | Oversee quality, exceptions, risk ratings and overdue work | File reviews and issue records |
| Monitoring and reporting | Ensure unusual activity is examined and reports are filed on time | Alerts, decisions and goAML receipts |
| People | Coordinate vetting, training and practical support | Role, training and competency records |
| Assurance | Track internal checks, audit findings and remediation | Reports, action logs and retesting |
Part 3
A Simple Operating Rhythm
- Step 1
Deal with urgent work
Prioritise suspicious activity, high-risk customers, prohibited work, missed deadlines and serious control failures.
- Step 2
Review monthly information
Track overdue CDD, customer risk, monitoring, reporting, training, exceptions and open actions.
- Step 3
Check change
Assess new services, technology, countries, customer types, outsourcing and guidance before they create a control gap.
- Step 4
Report to senior management
Explain risk, compliance, incidents, resource needs and remediation in a form that supports decisions.
Part 4
Support the Role Needs
- Direct access to senior managers and important business decisions.
- Access to customer, transaction, case, staff and system information.
- Time and budget that match the size and risk of the business.
- Authority to challenge, pause or escalate work.
- A backup route for leave and urgent reporting.
- Independent legal or technical advice for difficult matters.
Part 5
Common Mistakes
- The officer is isolated from customer and operational teams.
- The role is added to a full workload without protected time.
- Management receives counts but not the risk or cause of problems.
- Outsourced work is accepted without quality checks.
- Changes are made without updating the risk assessment and programme.
- No one covers the role during leave or a conflict.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Can a sole practitioner be the compliance officer?
Yes. DIA generally expects the sole practitioner to hold the role unless there is a reason they cannot.
Can the role be outsourced?
An external compliance officer may be used where the reporting entity has no employees. Other specialist support can be outsourced, but responsibility stays with the reporting entity.
Can one person be the officer for several businesses?
Special arrangements or exemptions may apply to a designated business group. The current law, exemption and DIA guidance should be checked before relying on a shared officer.
Does the officer make every AML/CFT decision?
No. Tasks and decisions may be shared across trained staff and senior managers. The programme should say who is accountable and how the officer oversees the work.
What should be reported to senior managers?
Material risks, control failures, reporting issues, overdue work, audit findings, legal changes, resources and the progress of important fixes should be made clear.
Reference
Official Sources
This guide cites the following sources.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.
- Regulator guidanceDepartment of Internal AffairsAML/CFT programme guidance: compliance officer
The current programme guidance, including the role of the compliance officer in Part 7.
- Regulator guidanceDepartment of Internal AffairsAML/CFT Programme Guidance 2026
Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.