AML/CFT Guide for Virtual Asset Service Providers in New Zealand

DIA is New Zealand’s sole AML/CFT supervisor from 1 July 2026. Whether a virtual-asset business is a reporting entity depends on the financial activity it carries on in the ordinary course of business. This guide explains scope, sector risks, practical controls, examples and official sources in plain English.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. Start With These Four Checks
  3. Key words explained
  4. Part 1: When AML/CFT May Apply
  5. Part 2: Main Risks in This Sector
  6. Part 3: A Practical Control Plan
  7. Part 4: Worked Examples
  8. Part 5: Evidence That Should Be Easy to Find
  9. Part 6: Common Mistakes
  10. Common questions
  11. Official sources

Short answer

DIA is New Zealand’s sole AML/CFT supervisor from 1 July 2026. Whether a virtual-asset business is a reporting entity depends on the financial activity it carries on in the ordinary course of business.

Scope is based on the listed activity, the ordinary-course test and the New Zealand connection. Check current regulations, exemptions and DIA guidance before relying on a result.

At a glance

Start With These Four Checks

  • Map the activity

    Write down exactly what the business does and match it to section 5.

  • Know the customer

    Identify the customer, beneficial owners, people acting for them and the purpose of the work.

  • Follow the sector risk

    Build controls around how money, property, structures, products and instructions move in this sector.

  • Keep the evidence

    Scope, CDD, risk, monitoring, reports, training and review should be easy to prove.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

Captured activity
An activity that brings a person or business within section 5 of the New Zealand AML/CFT Act.
Reporting entity
A person or business that must meet AML obligations for the covered service or activity.
Beneficial owner
The individual who ultimately owns or controls the customer or on whose behalf the work is done.
Enhanced CDD
Extra customer and source checks used when the law or higher risk requires them.
SAR
A suspicious activity report submitted to the New Zealand FIU through goAML when reasonable grounds for suspicion exist.

When AML/CFT May Apply

The function performed for the customer matters more than the technology label. Control of assets, transaction authority and the New Zealand connection should be clear.

  • Exchanging virtual assets for money or other virtual assets.
  • Transferring virtual assets for customers.
  • Providing hosted wallet or safekeeping services.
  • Broking or arranging virtual-asset transactions.
  • Issuing virtual assets or providing related investment services.
  • Another captured financial activity involving virtual assets.
Check the boundary

Software, validation, analytics, self-custody tools and other technical activity are not automatically captured. The actual service, control and customer relationship should be checked.

Main Risks in This Sector

These are starting points, not a ready-made risk rating. The business still needs to assess its own customers, services, countries, channels, transactions and technology.

  • Virtual assets can move across borders quickly and through pseudonymous addresses.
  • Mixers, chain hopping and privacy tools can obscure source and destination.
  • Scams, stolen identity and account takeover can make the apparent customer misleading.
  • Hosted and unhosted wallets create different visibility and counterparty risks.
  • Sanctions and high-risk service exposure can arise through wallet activity.

A Practical Control Plan

  1. Step 1

    Confirm scope

    Map every function, legal entity, wallet model and New Zealand connection.

  2. Step 2

    Build the customer process

    Confirm the section 5 activity and DIA supervision position.

  3. Step 3

    Set the risk controls

    Connect KYC, wallet screening, sanctions, transaction monitoring and cases.

  4. Step 4

    Train and connect people

    Set risk rules for assets, products, counterparties, countries and unhosted wallets.

  5. Step 5

    Test and improve

    Test deposits, withdrawals, transfers, account takeover and goAML reporting.

Worked Examples

These examples show how the scope and risk questions can be joined. They do not replace the law or the facts of a real matter.

Virtual Asset Service Providers: common situations and responses
SituationWhy it mattersPractical response
A customer receives assets from a mixer and withdraws immediately.The source may be hidden and the rapid movement may reduce recovery options.Investigate the chain and customer profile, apply enhanced CDD and assess a SAR or STR.
A developer supplies non-custodial wallet software.The VASP label may be used as a shortcut instead of analysing the service.Map control, authority, customer interaction and every section 5 activity.
A customer’s device and wallet behaviour change suddenly.The account may have been taken over or sold.Re-establish identity and control, review linked activity and assess suspicion.

Evidence That Should Be Easy to Find

  • The section 5, ordinary-course and New Zealand connection analysis.
  • The current sector risk assessment and the official sources used.
  • A function and wallet-control map tied to section 5.
  • Asset, product and risk-acceptance decisions.
  • Wallet-screening results linked to customer and transaction cases.
  • Testing of data coverage, sanctions, alerts and withdrawal controls.
  • Customer, beneficial ownership, risk, monitoring and reporting records.
  • Training, internal review, independent assurance and remediation records.

Common Mistakes

  • Using the words exchange or wallet as the scope decision.
  • Screening the customer but not the wallet or transaction path.
  • Treating analytics scores as final decisions.
  • Ignoring scam and account-takeover indicators because they look like fraud.
  • Adding a new asset or service without updating the risk assessment.

Common Questions

Short answers to the questions businesses ask most often.

Does every business in this sector have AML/CFT duties?

No. The exact activity, ordinary-course facts and New Zealand connection decide the answer. A business may carry out both captured and uncaptured work.

What should the business do first?

Map every function, legal entity, wallet model and New Zealand connection.

Can the sector risk assessment replace our own?

No. Official national and sector assessments are important sources, but the reporting entity must assess the risks it reasonably expects to face in its own business.

Can a generic AML/CFT template be used?

A template can help with structure, but it must be matched to the business’s scope, risks, people, systems and evidence. A document that is not implemented is not enough.

Is every crypto business a reporting entity?

No. The exact financial activity, control, customer relationship, ordinary-course facts and New Zealand connection should be analysed.

Is blockchain analytics enough for AML/CFT?

No. It can support risk and monitoring, but identity, beneficial ownership, purpose, source, reporting and other duties still apply.

Official Sources

This guide cites the following sources.

  1. Primary lawNew Zealand Legislation
    Anti-Money Laundering and Countering Financing of Terrorism Act 2009

    The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.

  2. Regulator guidanceDepartment of Internal Affairs
    Virtual asset service providers

    Current DIA guidance and resources for virtual asset exchanges, wallet, transfer and related providers.

  3. Regulator guidanceDepartment of Internal Affairs
    AML/CFT Programme Guidance 2026

    Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.

  4. Regulator guidanceNew Zealand Police Financial Intelligence Unit
    National Risk Assessment

    The March 2025 national assessment of New Zealand money laundering and terrorism financing risk.

  5. Regulator guidanceDepartment of Internal Affairs
    AML/CFT information and guidance

    DIA’s current AML/CFT homepage, including guidance for reporting entities and its consolidated supervision role from 1 July 2026.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your New Zealand business does and where the uncertainty sits. We will help you work out the practical AML/CFT response.

Tell us about your situation