top of page

AML/CFT Audit in New Zealand: What Reporting Entities Need to Know in 2026

  • 1 day ago
  • 2 min read
AML/CFT audit folder for New Zealand reporting entity compliance review

An AML/CFT Audit in New Zealand is more than a check that your compliance documents exist. It assesses whether your Risk Assessment and AML/CFT Programme meet the relevant requirements, and whether your AML/CFT Programme is working effectively in practice. DIA released updated AML/CFT Audit Guidance in July 2026, providing further guidance on audit timing, auditor independence, testing and remediation.


AML/CFT Audit New Zealand: How Often Is an Audit Required?

For most reporting entities, an independent AML/CFT audit must be completed every three years, unless DIA advises that a four-year timeframe applies or requests an audit at another time. An audit is not complete until the final audit report has been issued. The next audit period is then calculated from the date of that report. High-value dealers have different audit requirements and generally need an audit when requested by DIA.


What Does an AML/CFT Audit in New Zealand Check?

An AML/CFT audit may consider whether:

  • the Risk Assessment meets applicable requirements and remains current;

  • the AML/CFT Programme reflects identified risks;

  • CDD and Enhanced CDD procedures are operating effectively;

  • beneficial ownership requirements are being followed;

  • customer risk-rating procedures are being applied;

  • PEP requirements are being followed;

  • ongoing CDD and monitoring are operating effectively; and

  • previous audit findings have been addressed.


The purpose is not only to review documentation, but also to assess how the AML/CFT Programme works in practice.


Customer File Testing During an AML/CFT Audit

Auditors commonly use sampling and testing to review how AML/CFT obligations are applied in practice. This may involve reviewing real customer or transaction records, including identity verification, beneficial ownership, customer risk ratings, Enhanced CDD and source of funds or source of wealth information where required. DIA states that sampling should be risk-based and proportionate to the size, scale and activities of the reporting entity.


AML/CFT Auditor Independence Requirements in New Zealand

The auditor must be independent and appropriately qualified. Importantly, the auditor must not have been involved in undertaking the entity's Risk Assessment or establishing, implementing or maintaining its AML/CFT Programme.


An AML/CFT auditor does not need to be a Chartered Accountant or qualified financial auditor. Relevant AML/CFT knowledge, audit capability, sector knowledge and independence are important considerations when selecting an auditor.


What Happens After an AML/CFT Audit?

If the audit identifies partial or non-compliance, those issues need to be addressed. DIA recommends a structured remediation programme with clear actions and timeframes. Reporting entities are also required to state in their annual AML/CFT report whether necessary changes have been made following audit findings.


How to Prepare for an AML/CFT Audit in New Zealand

Before your next audit, consider:

  • When was our last final audit report issued?

  • Is our Risk Assessment current?

  • Does our AML/CFT Programme reflect our actual operations?

  • Do our customer files support our written procedures?

  • Have previous audit findings been addressed?


Preparing early can help identify compliance gaps before the audit begins.

 
 
 

Comments


bottom of page