Country comparison • Australia & New Zealand

Australian and New Zealand AML Compliance Compared

A plain-English comparison of the AML/CTF rules in Australia and the AML/CFT rules in New Zealand.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. At a glance
  3. Part 1: The Main Differences Side by Side
  4. Part 2: What Can Be Shared—and What Must Stay Local
  5. Part 3: Five Cross-Border Mistakes
  6. Part 4: Choose the Country That Applies
  7. Common questions
  8. Official sources

Short answer

The two systems share the same goal, but they are not interchangeable. They use different laws, regulators, reporting terms and review requirements. A group operating in both countries needs a clear local view for each business.

This comparison gives you the main differences. It does not replace a country-specific scope assessment or the current legislation.

At a glance

What to Know First

  • Different words

    Australia uses AML/CTF, program and suspicious matter report. New Zealand uses AML/CFT, programme and suspicious activity report.

  • Different regulators

    AUSTRAC regulates and receives reports in Australia. DIA supervises New Zealand reporting entities, while the New Zealand FIU receives prescribed reports through goAML.

  • Different coverage tests

    Australia focuses on designated services and a geographical link. New Zealand uses reporting-entity categories, listed activities, ordinary course of business and territorial scope.

  • Local evidence matters

    A group policy can provide a base, but local risk, approvals, reports, records and testing must meet each country’s rules.

The Main Differences Side by Side

Australia and New Zealand AML compliance comparison
TopicAustraliaNew Zealand
Common termAML/CTFAML/CFT
Main lawAnti-Money Laundering and Counter-Terrorism Financing Act 2006Anti-Money Laundering and Countering Financing of Terrorism Act 2009
Main supervisorAUSTRACDepartment of Internal Affairs
Who is coveredA reporting entity that provides a designated service with the required geographical linkA reporting entity carrying on a covered activity in the ordinary course of business with the required New Zealand connection
Core frameworkML/TF risk assessment and AML/CTF programML/TF risk assessment and AML/CFT programme
Suspicious reportSuspicious matter report (SMR)Suspicious activity report (SAR)
Suspicious-report receiverAUSTRAC through AUSTRAC OnlineNew Zealand Police Financial Intelligence Unit through goAML
Independent assuranceIndependent evaluation, at least every three years, subject to transitional first deadlinesIndependent audit generally every three years unless DIA specifies a different period
Annual compliance reportingAnnual AUSTRAC compliance report for the financial-year reporting periodAnnual report information is provided through the process set by DIA

What Can Be Shared—and What Must Stay Local

A business group can use one governance approach, but it should not simply change ‘CTF’ to ‘CFT’ and reuse the same documents.

  • Shared: group risk appetite, escalation principles, staff standards, quality assurance and board reporting structure.
  • Local: legal scope, regulator references, report names, filing systems, deadlines and exemptions.
  • Local: customer-risk logic where the customer base, products, countries or delivery channels differ.
  • Local: compliance-officer responsibilities and senior-manager approvals required by the country rules.
  • Local: evidence showing the Australian controls work in Australia and the New Zealand controls work in New Zealand.

Five Cross-Border Mistakes

  1. Step 1

    One scope decision for the whole group

    The legal test should be applied to each entity, service and country connection.

  2. Step 2

    One risk assessment with country names swapped

    Local customers, services, countries, typologies and systems can produce different risks.

  3. Step 3

    Reports sent through the wrong process

    Australia and New Zealand use different report types, agencies and online systems.

  4. Step 4

    A global policy with no local owner

    Each business needs clear responsibility, escalation and evidence that the local controls are used.

  5. Step 5

    Independent testing that skips one country

    Testing should cover the local requirements and a reasonable sample from the operations being evaluated or audited.

Choose the Country That Applies

Common Questions

Short answers to the questions businesses ask most often.

Can one AML program cover Australia and New Zealand?

A group framework can share principles and controls, but each country’s legal scope, terminology, reporting, approvals and evidence need to be addressed. A copied document with country names changed is unlikely to be enough.

Is AUSTRAC the regulator in New Zealand?

No. AUSTRAC is the Australian regulator and financial intelligence unit. DIA supervises New Zealand reporting entities, and the New Zealand Police FIU receives prescribed reports through goAML.

Is an Australian SMR the same as a New Zealand SAR?

They serve a similar purpose, but they are reports under different laws, with different terminology, systems and legal requirements.

Which country’s law applies to an online business?

It depends on the entity, service or activity, where and how it is provided, and the business’s connection with each country. Online delivery does not by itself decide the answer.

Do both countries require independent review?

Yes. Australia requires an independent evaluation and New Zealand requires an independent audit. The detailed scope, timing and transitional rules are different.

Official Sources

This page cites the following sources.

  1. Primary lawFederal Register of Legislation
  2. Regulator guidanceAUSTRAC
    Key steps and support for your AML/CTF journey

    Current guidance on enrolment, building controls and maintaining an AML/CTF program.

  3. Primary lawNew Zealand Legislation
  4. Regulator guidanceDepartment of Internal Affairs
    AML/CFT guidance and resources

    Guidance and information for reporting entities supervised by DIA.

  5. Regulator guidanceNew Zealand Police Financial Intelligence Unit
    Suspicious Activity and Transaction Reports

    Current New Zealand guidance on suspicious activity reports and goAML.

This page provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Operating across both countries?

Keep the Group Approach Consistent Without Losing the Local Rules.

We can help map the Australian and New Zealand requirements, identify what can be shared and show where local controls are needed.

Talk through the two-country approach