- New Zealand
- Resources
- Virtual Asset Service Providers
AML/CFT Guide for Virtual Asset Service Providers in New Zealand
DIA is New Zealand’s sole AML/CFT supervisor from 1 July 2026. Whether a virtual-asset business is a reporting entity depends on the financial activity it carries on in the ordinary course of business. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.
How this guide was researched and reviewedOn this page
Short answer
DIA is New Zealand’s sole AML/CFT supervisor from 1 July 2026. Whether a virtual-asset business is a reporting entity depends on the financial activity it carries on in the ordinary course of business.
Scope is based on the listed activity, the ordinary-course test and the New Zealand connection. Check current regulations, exemptions and DIA guidance before relying on a result.
At a glance
Start With These Four Checks
Map the activity
Write down exactly what the business does and match it to section 5.
Know the customer
Identify the customer, beneficial owners, people acting for them and the purpose of the work.
Follow the sector risk
Build controls around how money, property, structures, products and instructions move in this sector.
Keep the evidence
Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Captured activity
- An activity that brings a person or business within section 5 of the New Zealand AML/CFT Act.
- Reporting entity
- A person or business that must meet AML obligations for the covered service or activity.
- Beneficial owner
- The individual who ultimately owns or controls the customer or on whose behalf the work is done.
- Enhanced CDD
- Extra customer and source checks used when the law or higher risk requires them.
- SAR
- A suspicious activity report submitted to the New Zealand FIU through goAML when reasonable grounds for suspicion exist.
Part 1
When AML/CFT May Apply
The function performed for the customer matters more than the technology label. Control of assets, transaction authority and the New Zealand connection should be clear.
- Exchanging virtual assets for money or other virtual assets.
- Transferring virtual assets for customers.
- Providing hosted wallet or safekeeping services.
- Broking or arranging virtual-asset transactions.
- Issuing virtual assets or providing related investment services.
- Another captured financial activity involving virtual assets.
Software, validation, analytics, self-custody tools and other technical activity are not automatically captured. The actual service, control and customer relationship should be checked.
Part 2
Main Risks in This Sector
These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.
- Virtual assets can move across borders quickly and through pseudonymous addresses.
- Mixers, chain hopping and privacy tools can obscure source and destination.
- Scams, stolen identity and account takeover can make the apparent customer misleading.
- Hosted and unhosted wallets create different visibility and counterparty risks.
- Sanctions and high-risk service exposure can arise through wallet activity.
Part 3
A Practical Control Plan
- Step 1
Confirm scope
Map every function, legal entity, wallet model and New Zealand connection.
- Step 2
Build the customer process
Confirm the section 5 activity and DIA supervision position.
- Step 3
Set the risk controls
Connect KYC, wallet screening, sanctions, transaction monitoring and cases.
- Step 4
Train and connect people
Set risk rules for assets, products, counterparties, countries and unhosted wallets.
- Step 5
Test and improve
Test deposits, withdrawals, transfers, account takeover and goAML reporting.
Part 4
Worked Examples
These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.
| Situation | Why it matters | Practical response |
|---|---|---|
| A customer receives assets from a mixer and withdraws immediately. | The source may be hidden and the rapid movement may reduce recovery options. | Investigate the chain and customer profile, apply enhanced CDD and assess a SAR or STR. |
| A developer supplies non-custodial wallet software. | The VASP label may be used as a shortcut instead of analysing the service. | Map control, authority, customer interaction and every section 5 activity. |
| A customer’s device and wallet behaviour change suddenly. | The account may have been taken over or sold. | Re-establish identity and control, review linked activity and assess suspicion. |
Part 5
Evidence That Should Be Easy to Find
- The section 5, ordinary-course and New Zealand connection analysis.
- The current sector risk assessment and the official sources used.
- A function and wallet-control map tied to section 5.
- Asset, product and risk-acceptance decisions.
- Wallet-screening results linked to customer and transaction cases.
- Testing of data coverage, sanctions, alerts and withdrawal controls.
- Customer, beneficial ownership, risk, monitoring and reporting records.
- Training, internal review, independent assurance and remediation records.
Part 6
Common Mistakes
- Using the words exchange or wallet as the scope decision.
- Screening the customer but not the wallet or transaction path.
- Treating analytics scores as final decisions.
- Ignoring scam and account-takeover indicators because they look like fraud.
- Adding a new asset or service without updating the risk assessment.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every business in this sector have AML/CFT duties?
No. The exact activity, ordinary-course facts and New Zealand connection decide the answer. A business may carry out both captured and uncaptured work.
What should the business do first?
Map every function, legal entity, wallet model and New Zealand connection.
Can the sector risk assessment replace our own?
No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.
Can a generic AML/CFT template be used?
A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.
Is every crypto business a reporting entity?
No. The exact financial activity, control, customer relationship, ordinary-course facts and New Zealand connection should be analysed.
Is blockchain analytics enough for AML/CFT?
No. It can support risk and monitoring, but identity, beneficial ownership, purpose, source, reporting and other duties still apply.
Reference
Official Sources
This guide cites the following sources.
- Primary lawNew Zealand LegislationAnti-Money Laundering and Countering Financing of Terrorism Act 2009
The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.
- Regulator guidanceDepartment of Internal AffairsVirtual asset service providers
Current DIA guidance and resources for virtual asset exchanges, wallet, transfer and related providers.
- Regulator guidanceDepartment of Internal AffairsAML/CFT Programme Guidance 2026
Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.
- Regulator guidanceNew Zealand Police Financial Intelligence UnitNational Risk Assessment
The March 2025 national assessment of New Zealand money laundering and terrorism financing risk.
- Regulator guidanceDepartment of Internal AffairsAML/CFT information and guidance
DIA’s current AML/CFT homepage, including guidance for reporting entities and its consolidated supervision role from 1 July 2026.