Test and improve • New ZealandRead the Australia version

Independent AML/CFT Audits in New Zealand

A practical guide to New Zealand AML/CFT audit timing, auditor independence, scope, testing, reports and remediation.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. A Useful Audit Does Four Things
  3. Key words explained
  4. Part 1: Confirm Timing and Independence
  5. Part 2: Set a Useful Audit Scope
  6. Part 3: Write Findings That Can Be Fixed
  7. Part 4: Respond and Follow Up
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

An independent audit checks whether the risk assessment and AML/CFT programme meet the law and work in practice. The usual period is every three years, unless DIA gives a four-year timeframe or requests another time.

High-value dealers have a different rule and are audited when DIA requests it. The current due date and the reporting entity’s status should be confirmed before planning.

At a glance

A Useful Audit Does Four Things

  • Checks the law

    The risk assessment and programme are compared with current duties and guidance.

  • Tests real work

    Customer files, monitoring, reports, people and records are sampled.

  • Explains the gap

    Findings show the evidence, impact, cause and practical correction.

  • Supports repair

    Actions are prioritised, owned and tested after completion.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

Independent auditor
A suitably qualified person who has not established, implemented or maintained the work they are auditing.
Adequate
The risk assessment or programme covers what it needs to cover.
Effective
The controls work in practice and achieve their intended purpose.
Finding
A gap or weakness supported by evidence and measured against a clear requirement.
Remediation
Work used to correct a finding and deal with its cause and impact.

Confirm Timing and Independence

  • Check the last audit date, the current statutory period and any DIA notice.
  • Use the three-year period unless DIA has notified a four-year period or another timing applies.
  • Treat a DIA-requested audit as separate from the ordinary cycle.
  • Choose an auditor with suitable AML/CFT, audit and sector knowledge.
  • Confirm the auditor did not establish, implement or maintain the risk assessment or programme.
  • Record conflicts, safeguards, scope, access and reporting lines before work starts.

Set a Useful Audit Scope

  1. Step 1

    Understand the entity

    Map covered activities, locations, products, systems, customers, changes, prior findings and material incidents.

  2. Step 2

    Assess the risk assessment

    Check whether it identifies and assesses required risk factors, uses current source material and supports the controls.

  3. Step 3

    Assess the programme

    Check whether every required area is covered and whether the procedures, policies and controls are adequate and effective.

  4. Step 4

    Test evidence

    Sample CDD, customer risk, monitoring, written findings, reporting, records, training, vetting and changes.

  5. Step 5

    Follow serious issues

    Expand testing where a failure may be widespread, affect a report or expose the business to unmanaged higher risk.

Write Findings That Can Be Fixed

A clear audit finding
ElementWhat to includePurpose
RequirementThe Act, regulation, programme or expected controlShows the benchmark
EvidenceThe sample and facts foundMakes the conclusion traceable
RiskThe compliance and ML/TF impactSupports priority
CauseWhy the issue occurredPrevents a surface-only fix
ActionA practical response, owner and due dateTurns assurance into improvement

Respond and Follow Up

  • Give leaders the report and explain serious findings promptly.
  • Prioritise possible missed reporting, failed CDD and unmanaged higher-risk customers.
  • Assess whether older files, customers or reports need a look-back.
  • Update the risk assessment, programme, systems, forms and training together.
  • Record an owner, due date, status and evidence for each action.
  • Retest important fixes before they are closed.

Common Mistakes

  • The audit date is calculated from an old two-year rule.
  • The auditor helped maintain the programme and then audits the same work.
  • Only policy wording is checked.
  • Samples avoid higher-risk or failed files.
  • Findings do not identify the legal or programme requirement.
  • Actions are closed without checking whether they work.

Common Questions

Short answers to the questions businesses ask most often.

How often is an independent audit required?

The default period is every three years. DIA may notify a four-year period or require an audit at another time.

Do high-value dealers follow the same cycle?

No. High-value dealers are subject to audit when DIA requests it. Their exact status and duties should be checked.

Can the person who maintains the programme audit it?

No. The auditor must not have established, implemented or maintained the risk assessment or programme being audited.

Must an external auditor be used?

The law focuses on qualification and independence. An internal person would need to meet the same requirements, which can be difficult in a small business.

Is the audit report sent to DIA automatically?

Not in every case, but it must be kept and may need to be provided. DIA can also direct the timing or scope of an audit.

Official Sources

This guide cites the following sources.

  1. Primary lawNew Zealand Legislation
    Anti-Money Laundering and Countering Financing of Terrorism Act 2009

    The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.

  2. Regulator guidanceDepartment of Internal Affairs
    Audit Guidance for Risk Assessment and AML/CFT Programme

    Current guidance on audit timing, independence, scope, evidence and reporting.

  3. Regulator guidanceDepartment of Internal Affairs
    AML/CFT Programme Guidance 2026

    Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.

  4. Regulator guidanceDepartment of Internal Affairs
    AML/CFT information and guidance

    DIA’s current AML/CFT homepage, including guidance for reporting entities and its consolidated supervision role from 1 July 2026.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your New Zealand business does and where the uncertainty sits. We will help you work out the practical AML/CFT response.

Tell us about your situation