- New Zealand
- Resources
- ML/TF risk assessment
How to Build a New Zealand ML/TF Risk Assessment
Learn what a New Zealand ML/TF risk assessment must cover, how to rate risk and when the assessment must be reviewed.
How this guide was researched and reviewedOn this page
Short answer
A risk assessment explains how the business could be used for money laundering or terrorism financing. It must be written and completed before CDD is carried out or the AML/CFT programme is established.
The programme must be based on the assessment. The business should be able to explain each risk rating and show which controls respond to it.
At a glance
The Four-Part Method
Identify
Find the risks in the business, its services, customers, delivery, countries and institutions.
Assess
Decide how open each area is to misuse before controls are applied.
Evaluate
Set clear ratings so the higher risks can be dealt with first.
Respond
Build the AML/CFT programme from the risks and ratings.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- ML/TF risk
- The chance that a service could be used for money laundering or terrorism financing.
- Inherent risk
- The risk that exists before the business applies its AML/CFT controls.
- Residual risk
- The risk that is left after the controls are applied. The Act does not require this rating.
- Risk factor
- A fact that can raise or lower risk, such as a service, customer type, country or delivery method.
- NRA and SRA
- The National Risk Assessment and Sector Risk Assessments. Relevant risks from them must be used.
- Control
- A step used to manage risk, such as CDD, approval, monitoring or a service limit.
Part 1
What the Assessment Must Cover
Section 58 lists the areas that must be considered. The depth of the work should match the nature, size and complexity of the business.
- Step 1
Nature, size and complexity
Consider branches, staff, systems, growth, transaction volume and how easy it would be for strange activity to be missed.
- Step 2
Products and services
Look at how money or assets can be raised, held, changed or moved. Check high values, third-party payments and hidden ownership.
- Step 3
Delivery methods
Assess in-person, remote, self-service and third-party delivery. Less staff contact can make identity and behaviour harder to check.
- Step 4
Customer types
Consider ownership, control, public office, source of funds, criminal links, cash use, overseas links and any reason enhanced CDD may apply.
- Step 5
Countries and institutions
Check the countries and other firms used in the service. Consider sanctions, corruption, crime, terrorism financing and weak AML/CFT systems.
- Step 6
Official risk information
Relevant risks in the National Risk Assessment and Sector Risk Assessments must be brought into the business’s own assessment.
The risk assessment must now include relevant risks identified by the supervisor and the Financial Intelligence Unit. A source register can show what was checked and how it was used.
Part 2
A Simple Method That Can Be Explained
DIA suggests identify, assess, evaluate and respond. A small business can use a short rating scale if the reasons are clear.
- Step 1
Map the business
List each product or service, customer group, delivery method, country and institution. Add the nature, size and complexity of the business.
- Step 2
Describe the misuse
Write how a criminal or terrorist financier could use each area. Say what could be hidden, moved or made to look lawful.
- Step 3
Rate inherent risk
Assess risk before AML/CFT controls are applied. A scale such as low, medium and high can work if each level is defined.
- Step 4
Record the reason
Use business data, DIA guidance, the National Risk Assessment, the relevant Sector Risk Assessment and known warning signs.
- Step 5
Set the response
Show how the programme will deal with each risk through CDD, customer risk rating, monitoring, approval, reporting or service limits.
- Step 6
Name the owner and review trigger
Record who watches the risk, what change will trigger review and how the document will be kept current.
DIA explains residual risk as the risk left after controls. The Act does not require a residual-risk rating, but one may be used if the method stays clear.
Part 3
Worked Example
This example shows the level of reasoning that should be visible. It is not a template and should not be copied without checking the facts.
| Field | Example |
|---|---|
| Service | Forming a New Zealand company and providing its registered office. |
| Possible misuse | A company may be used to hide who owns assets or to move funds through a business that looks lawful. |
| Risk factors | Remote customer, overseas owners, nominee requests, several companies and no clear business reason. |
| Inherent rating | High. The structure can hide control and can be formed without meeting the customer in person. |
| Controls | Beneficial ownership checks, source-of-funds or wealth checks where required, purpose checks, senior approval and ongoing review. |
| Review trigger | A new country, a new remote identity tool or a rise in nominee service requests. |
Part 4
When the Assessment Must Be Reviewed
The document must state how it will be kept current. Review should be linked to business change, new risk information and the audit cycle.
- A product, service, customer group, country or institution changes.
- A new or developing technology or delivery method is planned.
- DIA or the Financial Intelligence Unit releases relevant risk information.
- The National Risk Assessment or a Sector Risk Assessment changes.
- Monitoring, a SAR decision or a control failure shows a new risk.
- An independent audit finds that the assessment is missing, unclear or out of date.
Regulation 13E requires the assessment to be reviewed and updated before a new technology, product or delivery method is used.
Part 5
Records and Independent Audit
The current assessment, earlier versions and the records used to build it should be kept. Risk assessment, programme and audit records must be kept for at least five years after they stop being used on a regular basis.
The risk assessment and programme must be independently audited. The default period is every three years. A four-year period can apply if DIA gives notice, and DIA can ask for an audit at another time.
- Keep the method, definitions and rating scale.
- Keep source dates, links and notes on how each source was used.
- Keep data extracts, meeting notes, decisions and approvals.
- Keep each version and a clear record of what changed.
- Give the auditor enough evidence to test how the assessment works in practice.
Part 6
Common Mistakes
- A sector risk assessment is copied and treated as the business’s own assessment.
- The National Risk Assessment or relevant Sector Risk Assessment is not used.
- Controls are used to lower the rating before inherent risk is understood.
- Every service or customer type is given the same rating.
- The rating scale is not defined.
- A rating is stated without facts, sources or reasons.
- The programme does not show how each higher risk is managed.
- New technology is used before the assessment is updated.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
When must a New Zealand ML/TF risk assessment be completed?
It must be completed before the reporting entity carries out CDD or establishes its AML/CFT programme.
What factors must be covered?
The business, products and services, delivery methods, customers, countries, institutions, official guidance and any other factor set by rules must be considered.
Must the National Risk Assessment be used?
Yes, where its risks are relevant. Relevant risks in assessments produced by the supervisor and the Financial Intelligence Unit must be included.
Must residual risk be rated?
No. DIA explains residual risk, but the Act does not require a residual-risk rating. A business may still use one.
How often must the assessment be independently audited?
The default period is every three years. DIA can set a four-year period by notice or ask for an audit at another time.
Can a DIA guide be used as the business’s risk assessment?
No. DIA material should inform the work, but the assessment must be written for the services, customers, delivery, countries, institutions and facts of the business.
Reference
Official Sources
This guide cites the following sources.
- Regulator guidanceDepartment of Internal AffairsRisk Assessment Guidance
DIA’s current four-step method and links to the July 2026 guidance suite.
- Regulator guidanceDepartment of Internal AffairsNew era for AML/CFT regulation and guidance
The 1 July 2026 guidance release and DIA’s role as sole supervisor.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
Section 58 sets the written risk-assessment duty and required factors.
- Primary lawNew Zealand LegislationRequirements and Compliance Regulations 2011
Regulation 13E covers new technology, products and delivery methods.