Which service do I need?+
Choose an independent audit when your AML/CFT framework needs an objective test. Choose risk assessment and programme support when your documents need to be built or refreshed. Remediation and advisory is for audit findings, DIA requests and operational issues. If you are unsure, start by telling us what has happened.
How often is an independent AML/CFT audit required?+
Most New Zealand reporting entities must have a final audit report issued every three years from the date of their previous final report. A four-year period applies only where DIA has told you it applies. DIA can also request an audit at another time. Different rules apply to high-value dealers.
What is the difference between a risk assessment and an AML/CFT programme?+
The risk assessment identifies the money laundering and terrorism financing risks your business can reasonably expect to face. The programme sets out the procedures, policies and controls used to manage those risks. The programme must be based on the risk assessment.
Can the same provider build our documents and audit them?+
Not where independence would be affected. An auditor must not have developed the risk assessment or established, implemented or maintained the AML/CFT programme being audited. The document work and independent audit must be kept separate.
When should our AML/CFT documents be updated?+
They should be reviewed regularly and kept current. An update may be needed when services, customers, countries, delivery methods, ownership or business processes change. Audit findings and new DIA guidance may also require changes.
What happens when an audit or DIA review finds problems?+
The findings should be turned into clear actions, priorities and timeframes. The affected documents and processes should be updated, and evidence of each completed action should be kept. This creates a clear record for DIA and the next independent audit.