- New Zealand
- Resources
- Customer due diligence
Customer Due Diligence in New Zealand
A clear guide to New Zealand standard, simplified, enhanced and ongoing customer due diligence, including beneficial owners and source checks.
How this guide was researched and reviewedOn this page
Short answer
CDD means identifying the customer, the people who own or control them and anyone acting for them, then checking that information and understanding the relationship. The level of work changes with the customer and the risk.
CDD is not finished when an identity document is copied. The information should help the business understand risk, monitor the relationship and recognise unusual activity.
At a glance
CDD Answers Four Questions
Who is the customer?
Identify the person or legal entity and verify the required identity information.
Who is behind them?
Identify beneficial owners and people acting on behalf of the customer.
Why are they here?
Understand the nature and purpose of the relationship or activity.
Has the risk changed?
Review the customer’s information, activity and risk rating over time.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Standard CDD
- The normal level of CDD used when simplified or enhanced CDD does not apply.
- Beneficial owner
- An individual who ultimately owns or controls a customer or on whose behalf a transaction or activity is carried out.
- Person acting on behalf
- A person authorised to act for the customer, such as a signatory, attorney, director or agent.
- Enhanced CDD
- Extra checks required for trusts and other listed or higher-risk situations.
- Source of funds or wealth
- Where transaction funds came from or how the customer built their overall wealth.
Part 1
The Core CDD Process
- Step 1
Identify the customer type
Decide whether the customer is an individual, company, trust, partnership, club, society or another structure.
- Step 2
Identify the relevant people
Find the beneficial owners and any person acting on behalf of the customer. Nominee directors or partners may require specific work.
- Step 3
Collect and verify information
Use reliable and independent material and the current Identity Verification Code of Practice or another lawful method.
- Step 4
Understand purpose and risk
Record the nature and purpose of the relationship, expected activity and customer risk rating.
- Step 5
Decide whether extra work is needed
Check for enhanced CDD triggers, PEPs, sanctions, reliance issues and any reason the activity should not proceed.
Part 2
Choose the Correct Level of CDD
| Level | When it applies | Main point |
|---|---|---|
| Simplified | Only for eligible customer types and circumstances | Reduced information is allowed by law, not merely because risk feels low. |
| Standard | The default where neither simplified nor enhanced CDD applies | Identify and verify the customer and relevant people, purpose and risk. |
| Enhanced | Trusts, higher risk and other listed triggers | Obtain and verify extra information, including source information when required. |
A customer’s address is generally collected as part of CDD, but the current rules do not require it to be verified in every case. Follow the current customer-type and risk guidance.
Part 3
When Enhanced CDD Is Needed
Enhanced CDD should be focused on the reason for the higher risk. Source of funds or wealth information should be specific enough to understand and, where required, verify how the money or wealth was obtained.
- The customer is a trust or another structure listed in the Act.
- The customer or activity is assessed as higher risk.
- A customer has a relevant link to a high-risk country.
- A nominee, bearer, complex or unusual structure creates extra risk.
- A customer or beneficial owner is a politically exposed person and the statutory conditions apply.
- The activity is unusually large, complex, has an unusual pattern or lacks an apparent lawful purpose.
Part 4
Ongoing CDD and Account Monitoring
- Keep CDD information and the customer risk rating current.
- Review activity against what is known about the customer and relationship.
- Examine complex, unusually large or unusual patterns and keep written findings.
- Escalate material changes and suspicious indicators promptly.
- Apply enhanced CDD when a trigger is found during the relationship.
- Record reviews, decisions, approvals and action taken.
Part 5
Common Mistakes
- The legal customer is confused with the person who sends instructions.
- Beneficial owners are accepted from a form without being checked.
- The nature and purpose answer is too vague to guide monitoring.
- A trust is treated as standard CDD rather than enhanced CDD.
- Source information is collected but not assessed or verified when required.
- The customer risk rating is never reviewed after onboarding.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Must every customer receive enhanced CDD?
No. Enhanced CDD applies when the Act or the customer’s risk triggers it. Standard CDD is the default in other cases, and simplified CDD is limited to eligible situations.
Must a residential address always be verified?
No blanket address-verification rule applies in every case under the current settings. The required information, customer type, risk and current guidance should be checked.
Can CDD be completed after work starts?
Verification can be delayed only in limited circumstances and when the legal conditions and safeguards are met. The exception should not become the normal process.
Can another reporting entity’s CDD be relied on?
Only where the statutory conditions are met. The relying business keeps responsibility and needs timely access to the information and verification records.
What if CDD cannot be completed?
The business may be prohibited from starting or continuing the relationship or activity. It should also consider whether a suspicious activity report is required.
Reference
Official Sources
This guide cites the following sources.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.
- Regulator guidanceDepartment of Internal AffairsCustomer due diligence guidance
DIA’s current collection of CDD, beneficial ownership, entity and identity-verification guidance.
- Regulator guidanceDepartment of Internal AffairsEnhanced Customer Due Diligence Guidance 2026
The current triggers and risk-based measures for enhanced CDD.
- Regulator guidanceDepartment of Internal AffairsAML/CFT Programme Guidance 2026
Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.