Country-specific guidance Current
New Zealand AML/CFT Act client due diligence overview
This program's first New Zealand guide.
Customer due diligence under New Zealand's AML/CFT Act is not optional, and it isn't a single fixed check either. This guide sets out a practical overview. It is general information, not legal or compliance advice.
Action plan
1 Collect the required information, then actually verify it Collecting customer information is only the first half of customer due diligence.
Department of Internal Affairs guidance for AML/CFT reporting entities is explicit that for standard customer due diligence, once you've obtained the required customer information, you must then take reasonable steps to verify that information to be satisfied it's correct. Treat verification as its own distinct step, not something collection alone satisfies.
- Collect the customer information your firm's AML/CFT programme requires
- Separately take reasonable steps to verify that information is correct
- Don't treat collection alone as satisfying the due diligence obligation
Done when: Customer information has been both collected and separately verified
DIA: AML/CFT FAQ for reporting entities2 Verify beneficial owners and persons acting on the customer's behalf Due diligence extends beyond the named customer to who actually stands behind them.
The same due diligence obligation extends to identifying and, according to the level of risk involved, verifying beneficial owners of the customer and any person acting on the customer's behalf, not only the named customer itself.
- Identify beneficial owners standing behind the named customer
- Identify and verify anyone acting on the customer's behalf, according to risk
- Don't treat verifying the named customer alone as complete due diligence
Done when: Beneficial owners and any persons acting on the customer's behalf have been identified and verified according to risk
DIA: AML/CFT FAQ for reporting entities3 Apply a risk-based approach, not one fixed level of check New Zealand's AML/CFT framework is generally risk-based; treat that as the wider context, not a fixed rule confirmed for every check.
New Zealand's AML/CFT framework is generally understood to expect the depth of due diligence and verification to track the level of risk posed by the customer -- the beneficial-owner and agent verification obligation is explicitly risk-based in DIA's own guidance. Assess each customer relationship's risk and apply verification depth proportionate to it, and confirm the specific provisions your firm's own AML/CFT programme relies on, rather than applying a single standard check uniformly.
- Assess each customer's risk before deciding the depth of verification
- Apply more thorough verification for higher-risk customers
- Document the risk assessment behind the verification depth chosen
Done when: Verification depth is documented as proportionate to each customer's assessed risk
See New Zealand Companies Office identity verification for company clients