- New Zealand
- Resources
- Independent audit
Independent AML/CFT Audits in New Zealand
A practical guide to New Zealand AML/CFT audit timing, auditor independence, scope, testing, reports and remediation.
How this guide was researched and reviewedOn this page
Short answer
An independent audit checks whether the risk assessment and AML/CFT programme meet the law and work in practice. The usual period is every three years, unless DIA gives a four-year timeframe or requests another time.
High-value dealers have a different rule and are audited when DIA requests it. The current due date and the reporting entity’s status should be confirmed before planning.
At a glance
A Useful Audit Does Four Things
Checks the law
The risk assessment and programme are compared with current duties and guidance.
Tests real work
Customer files, monitoring, reports, people and records are sampled.
Explains the gap
Findings show the evidence, impact, cause and practical correction.
Supports repair
Actions are prioritised, owned and tested after completion.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Independent auditor
- A suitably qualified person who has not established, implemented or maintained the work they are auditing.
- Adequate
- The risk assessment or programme covers what it needs to cover.
- Effective
- The controls work in practice and achieve their intended purpose.
- Finding
- A gap or weakness supported by evidence and measured against a clear requirement.
- Remediation
- Work used to correct a finding and deal with its cause and impact.
Part 1
Confirm Timing and Independence
- Check the last audit date, the current statutory period and any DIA notice.
- Use the three-year period unless DIA has notified a four-year period or another timing applies.
- Treat a DIA-requested audit as separate from the ordinary cycle.
- Choose an auditor with suitable AML/CFT, audit and sector knowledge.
- Confirm the auditor did not establish, implement or maintain the risk assessment or programme.
- Record conflicts, safeguards, scope, access and reporting lines before work starts.
Part 2
Set a Useful Audit Scope
- Step 1
Understand the entity
Map covered activities, locations, products, systems, customers, changes, prior findings and material incidents.
- Step 2
Assess the risk assessment
Check whether it identifies and assesses required risk factors, uses current source material and supports the controls.
- Step 3
Assess the programme
Check whether every required area is covered and whether the procedures, policies and controls are adequate and effective.
- Step 4
Test evidence
Sample CDD, customer risk, monitoring, written findings, reporting, records, training, vetting and changes.
- Step 5
Follow serious issues
Expand testing where a failure may be widespread, affect a report or expose the business to unmanaged higher risk.
Part 3
Write Findings That Can Be Fixed
| Element | What to include | Purpose |
|---|---|---|
| Requirement | The Act, regulation, programme or expected control | Shows the benchmark |
| Evidence | The sample and facts found | Makes the conclusion traceable |
| Risk | The compliance and ML/TF impact | Supports priority |
| Cause | Why the issue occurred | Prevents a surface-only fix |
| Action | A practical response, owner and due date | Turns assurance into improvement |
Part 4
Respond and Follow Up
- Give leaders the report and explain serious findings promptly.
- Prioritise possible missed reporting, failed CDD and unmanaged higher-risk customers.
- Assess whether older files, customers or reports need a look-back.
- Update the risk assessment, programme, systems, forms and training together.
- Record an owner, due date, status and evidence for each action.
- Retest important fixes before they are closed.
Part 5
Common Mistakes
- The audit date is calculated from an old two-year rule.
- The auditor helped maintain the programme and then audits the same work.
- Only policy wording is checked.
- Samples avoid higher-risk or failed files.
- Findings do not identify the legal or programme requirement.
- Actions are closed without checking whether they work.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
How often is an independent audit required?
The default period is every three years. DIA may notify a four-year period or require an audit at another time.
Do high-value dealers follow the same cycle?
No. High-value dealers are subject to audit when DIA requests it. Their exact status and duties should be checked.
Can the person who maintains the programme audit it?
No. The auditor must not have established, implemented or maintained the risk assessment or programme being audited.
Must an external auditor be used?
The law focuses on qualification and independence. An internal person would need to meet the same requirements, which can be difficult in a small business.
Is the audit report sent to DIA automatically?
Not in every case, but it must be kept and may need to be provided. DIA can also direct the timing or scope of an audit.
Reference
Official Sources
This guide cites the following sources.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.
- Regulator guidanceDepartment of Internal AffairsAudit Guidance for Risk Assessment and AML/CFT Programme
Current guidance on audit timing, independence, scope, evidence and reporting.
- Regulator guidanceDepartment of Internal AffairsAML/CFT Programme Guidance 2026
Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.
- Regulator guidanceDepartment of Internal AffairsAML/CFT information and guidance
DIA’s current AML/CFT homepage, including guidance for reporting entities and its consolidated supervision role from 1 July 2026.