Foundation guide • New ZealandRead the Australia version

How to Build a New Zealand ML/TF Risk Assessment

Learn what a New Zealand ML/TF risk assessment must cover, how to rate risk and when the assessment must be reviewed.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. The Four-Part Method
  3. Key words explained
  4. Part 1: What the Assessment Must Cover
  5. Part 2: A Simple Method That Can Be Explained
  6. Part 3: Worked Example
  7. Part 4: When the Assessment Must Be Reviewed
  8. Part 5: Records and Independent Audit
  9. Part 6: Common Mistakes
  10. Common questions
  11. Official sources

Short answer

A risk assessment explains how the business could be used for money laundering or terrorism financing. It must be written and completed before CDD is carried out or the AML/CFT programme is established.

The programme must be based on the assessment. The business should be able to explain each risk rating and show which controls respond to it.

At a glance

The Four-Part Method

  • Identify

    Find the risks in the business, its services, customers, delivery, countries and institutions.

  • Assess

    Decide how open each area is to misuse before controls are applied.

  • Evaluate

    Set clear ratings so the higher risks can be dealt with first.

  • Respond

    Build the AML/CFT programme from the risks and ratings.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

ML/TF risk
The chance that a service could be used for money laundering or terrorism financing.
Inherent risk
The risk that exists before the business applies its AML/CFT controls.
Residual risk
The risk that is left after the controls are applied. The Act does not require this rating.
Risk factor
A fact that can raise or lower risk, such as a service, customer type, country or delivery method.
NRA and SRA
The National Risk Assessment and Sector Risk Assessments. Relevant risks from them must be used.
Control
A step used to manage risk, such as CDD, approval, monitoring or a service limit.

What the Assessment Must Cover

Section 58 lists the areas that must be considered. The depth of the work should match the nature, size and complexity of the business.

  1. Step 1

    Nature, size and complexity

    Consider branches, staff, systems, growth, transaction volume and how easy it would be for strange activity to be missed.

  2. Step 2

    Products and services

    Look at how money or assets can be raised, held, changed or moved. Check high values, third-party payments and hidden ownership.

  3. Step 3

    Delivery methods

    Assess in-person, remote, self-service and third-party delivery. Less staff contact can make identity and behaviour harder to check.

  4. Step 4

    Customer types

    Consider ownership, control, public office, source of funds, criminal links, cash use, overseas links and any reason enhanced CDD may apply.

  5. Step 5

    Countries and institutions

    Check the countries and other firms used in the service. Consider sanctions, corruption, crime, terrorism financing and weak AML/CFT systems.

  6. Step 6

    Official risk information

    Relevant risks in the National Risk Assessment and Sector Risk Assessments must be brought into the business’s own assessment.

A 2026 change

The risk assessment must now include relevant risks identified by the supervisor and the Financial Intelligence Unit. A source register can show what was checked and how it was used.

A Simple Method That Can Be Explained

DIA suggests identify, assess, evaluate and respond. A small business can use a short rating scale if the reasons are clear.

  1. Step 1

    Map the business

    List each product or service, customer group, delivery method, country and institution. Add the nature, size and complexity of the business.

  2. Step 2

    Describe the misuse

    Write how a criminal or terrorist financier could use each area. Say what could be hidden, moved or made to look lawful.

  3. Step 3

    Rate inherent risk

    Assess risk before AML/CFT controls are applied. A scale such as low, medium and high can work if each level is defined.

  4. Step 4

    Record the reason

    Use business data, DIA guidance, the National Risk Assessment, the relevant Sector Risk Assessment and known warning signs.

  5. Step 5

    Set the response

    Show how the programme will deal with each risk through CDD, customer risk rating, monitoring, approval, reporting or service limits.

  6. Step 6

    Name the owner and review trigger

    Record who watches the risk, what change will trigger review and how the document will be kept current.

Residual risk

DIA explains residual risk as the risk left after controls. The Act does not require a residual-risk rating, but one may be used if the method stays clear.

Worked Example

This example shows the level of reasoning that should be visible. It is not a template and should not be copied without checking the facts.

Example risk entry for a trust and company service
FieldExample
ServiceForming a New Zealand company and providing its registered office.
Possible misuseA company may be used to hide who owns assets or to move funds through a business that looks lawful.
Risk factorsRemote customer, overseas owners, nominee requests, several companies and no clear business reason.
Inherent ratingHigh. The structure can hide control and can be formed without meeting the customer in person.
ControlsBeneficial ownership checks, source-of-funds or wealth checks where required, purpose checks, senior approval and ongoing review.
Review triggerA new country, a new remote identity tool or a rise in nominee service requests.

When the Assessment Must Be Reviewed

The document must state how it will be kept current. Review should be linked to business change, new risk information and the audit cycle.

  • A product, service, customer group, country or institution changes.
  • A new or developing technology or delivery method is planned.
  • DIA or the Financial Intelligence Unit releases relevant risk information.
  • The National Risk Assessment or a Sector Risk Assessment changes.
  • Monitoring, a SAR decision or a control failure shows a new risk.
  • An independent audit finds that the assessment is missing, unclear or out of date.
Before new technology is used

Regulation 13E requires the assessment to be reviewed and updated before a new technology, product or delivery method is used.

Records and Independent Audit

The current assessment, earlier versions and the records used to build it should be kept. Risk assessment, programme and audit records must be kept for at least five years after they stop being used on a regular basis.

The risk assessment and programme must be independently audited. The default period is every three years. A four-year period can apply if DIA gives notice, and DIA can ask for an audit at another time.

  • Keep the method, definitions and rating scale.
  • Keep source dates, links and notes on how each source was used.
  • Keep data extracts, meeting notes, decisions and approvals.
  • Keep each version and a clear record of what changed.
  • Give the auditor enough evidence to test how the assessment works in practice.

Common Mistakes

  • A sector risk assessment is copied and treated as the business’s own assessment.
  • The National Risk Assessment or relevant Sector Risk Assessment is not used.
  • Controls are used to lower the rating before inherent risk is understood.
  • Every service or customer type is given the same rating.
  • The rating scale is not defined.
  • A rating is stated without facts, sources or reasons.
  • The programme does not show how each higher risk is managed.
  • New technology is used before the assessment is updated.

Common Questions

Short answers to the questions businesses ask most often.

When must a New Zealand ML/TF risk assessment be completed?

It must be completed before the reporting entity carries out CDD or establishes its AML/CFT programme.

What factors must be covered?

The business, products and services, delivery methods, customers, countries, institutions, official guidance and any other factor set by rules must be considered.

Must the National Risk Assessment be used?

Yes, where its risks are relevant. Relevant risks in assessments produced by the supervisor and the Financial Intelligence Unit must be included.

Must residual risk be rated?

No. DIA explains residual risk, but the Act does not require a residual-risk rating. A business may still use one.

How often must the assessment be independently audited?

The default period is every three years. DIA can set a four-year period by notice or ask for an audit at another time.

Can a DIA guide be used as the business’s risk assessment?

No. DIA material should inform the work, but the assessment must be written for the services, customers, delivery, countries, institutions and facts of the business.

Official Sources

This guide cites the following sources.

  1. Regulator guidanceDepartment of Internal Affairs
    Risk Assessment Guidance

    DIA’s current four-step method and links to the July 2026 guidance suite.

  2. Regulator guidanceDepartment of Internal Affairs
    New era for AML/CFT regulation and guidance

    The 1 July 2026 guidance release and DIA’s role as sole supervisor.

  3. Primary lawNew Zealand Legislation
    Anti-Money Laundering and Countering Financing of Terrorism Act 2009

    Section 58 sets the written risk-assessment duty and required factors.

  4. Primary lawNew Zealand Legislation
    Requirements and Compliance Regulations 2011

    Regulation 13E covers new technology, products and delivery methods.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your New Zealand business does and where the uncertainty sits. We will help you work out the practical AML/CFT response.

Tell us about your situation