Regulation Name: Anti-Money Laundering and Countering Financing of Terrorism (Omnibus) Amendment Bill 2026
Date of Publication: 01 Sep 2026
Region: New Zealand
Agency: NZ Parliament
New Zealand has introduced the Anti-Money Laundering and Countering Financing of Terrorism (Omnibus) Amendment Bill 2026, proposing a broad set of changes to the AML/CFT Act 2009 and related legislation.
The Bill has three central objectives: provide regulatory relief to businesses, align New Zealand’s AML/CFT framework with international expectations, and strengthen intelligence and enforcement tools against organised crime. It also brings compliance with specified UN-related financial sanctions into the AML/CFT framework.
The following is a practical overview for AML/CFT compliance leaders and professionals.
1. AML/CFT will explicitly include sanctions compliance
One of the most significant changes is the expansion of the AML/CFT framework to cover non-compliance with specified sanctions.
The Bill introduces the concept of a specified sanction, covering New Zealand legislation implementing relevant UN Security Council resolutions that require assets to be frozen or prohibit funds, financial services or related services from being made available to designated persons or entities.
Reporting entities will need to incorporate sanctions-related risks into their AML/CFT:
risk assessments;
AML/CFT programmes;
policies and controls;
customer and transaction monitoring; and
suspicious activity reporting.
The AML/CFT supervisor will also be able to establish rules covering how and when sanctions checks must be performed, who must be checked, the methodology used and what happens when a potential match is identified. (New Zealand Legislation)
This effectively makes sanctions screening a more formal part of New Zealand’s AML/CFT compliance architecture.
2. A more risk-based approach to customer due diligence
The Bill gives reporting entities considerably more flexibility to apply customer due diligence according to risk.
Simplified CDD
A reporting entity will be able to apply simplified CDD where it has reasonable grounds to assess the circumstances as low risk, based on its section 58 risk assessment.
Importantly, the entity will determine what identity information is necessary for that low-risk scenario rather than following a single prescribed information set.
The risk assessment itself can document the circumstances that qualify as low risk.
Standard CDD must be applied if those circumstances subsequently cease to apply. (New Zealand Legislation)
Enhanced CDD
The Bill also changes when EDD is required.
The existing broad references to jurisdictions with insufficient AML/CFT systems are replaced with a more specific reference to jurisdictions identified by the FATF as high-risk jurisdictions subject to a call for action.
EDD will also become more risk-responsive. Reporting entities must collect the standard information plus whatever additional information is necessary to mitigate the relevant ML/TF risk, and verification should reflect the level of risk.
There is also an important exception: where an entity has determined that it must file a suspicious activity report and reasonably believes that completing EDD could alert the customer to that fact, it will not be required to complete that EDD.
3. New CDD requirements for trusts
The Bill changes identity requirements for trusts.
For discretionary trusts, charitable trusts and trusts with more than 10 beneficiaries, reporting entities will need information describing beneficiary classes or types, with charitable trusts also requiring information about their objects.
For other trusts, the Bill requires the name and date of birth of each beneficiary. (New Zealand Legislation)
This should prompt compliance teams to review trust onboarding processes, data fields and supporting documentation.
4. Replacement of designated business groups
The existing designated business group model is replaced by two new structures:
Mandatory reporting groups
Voluntary reporting groups
A mandatory reporting group generally covers related reporting entities and certain overseas AML/CFT-regulated entities. It must appoint a lead entity responsible for the group-wide AML/CFT programme and annual reporting.
The Bill also permits members of a mandatory group to rely on another member for CDD, share customer information, share parts of risk assessments or AML/CFT programmes, and make certain reports on behalf of other members—while the individual reporting entity retains responsibility for its own compliance. (New Zealand Legislation)
Voluntary reporting groups provide a similar framework for eligible related professional and other reporting entities.
For multinational groups, this could make group-wide AML/CFT governance more practical, but it will also increase the importance of data-sharing controls, governance, accountability and privacy safeguards.
5. AML/CFT programmes and risk assessments are expanded
AML/CFT programmes and risk assessments will need to address sanctions risk alongside money laundering and terrorism-financing risk.
Mandatory reporting groups must maintain a group AML/CFT programme covering group-level risk management, information sharing, customer and transaction information sharing where necessary, and protection of personal information.
The Bill also changes the existing audit model to independent evaluations. Evaluations must be performed by an appropriately qualified independent person who was not involved in establishing or maintaining the AML/CFT programme or conducting the risk assessment. The evaluator does not have to be a chartered accountant or financial auditor. (New Zealand Legislation)
6. New controls for cash-based virtual-asset transactions
The Bill introduces new restrictions on cash transactions involving virtual assets.
A person in trade will be prohibited from buying or selling virtual assets through cash transactions where the applicable threshold is reached, where prescribed transaction patterns exceed the threshold, where the asset is designated as a restricted virtual asset, or where regulations prohibit the activity.
It also restricts money or value transfer services from accepting certain cash transactions intended to transfer money or value outside New Zealand. (New Zealand Legislation)
The actual thresholds and additional restrictions will be established through regulations. This means virtual-asset businesses should monitor the subsequent regulatory process rather than treating the Bill’s framework as the final operational threshold.
7. Stronger FIU and law-enforcement intelligence powers
The Bill substantially expands the information-gathering powers of the Commissioner and Police.
The Commissioner will be able to obtain records, documents and information from non-reporting entities where relevant to analysing information received under the AML/CFT Act.
The Bill also introduces ongoing production orders, allowing reporting entities to be required to continuously provide specified financial records for the period covered by an order. (New Zealand Legislation)
In addition, the investigative and intelligence branches of New Zealand Police will be able to access suspicious activity reports and prescribed transaction reports for law-enforcement purposes.
8. Temporary freezing orders
A new mechanism will allow the Commissioner to seek temporary freezing orders over transactions or financial facilities.
An issuing officer may grant an order for up to 7 days, with a High Court Judge able to extend it for up to a further 28 days. The framework includes provisions for reasonable living costs, business expenses and certain other expenses, as well as mechanisms for seeking further orders or lifting an extended order. (New Zealand Legislation)
For financial institutions, this creates a potentially significant new operational requirement: systems and response processes may need to support rapid implementation of legally binding transaction or account freezes.
9. New infringement offence regime
The Bill introduces infringement offences for specified instances of minor non-compliance.
These include failures involving:
reporting group notifications;
appointment of an AML/CFT compliance officer;
written risk assessments;
provision of required records;
annual reporting;
production of information requested by the supervisor; and
maintaining required AML/CFT programmes.
Infringement fees can be prescribed up to NZ$20,000, while certain maximum fines can reach NZ$40,000 under the regulation-making framework. (New Zealand Legislation)
This creates a more graduated enforcement model between regulatory remediation and prosecution.
10. Significantly higher penalties and longer prosecution periods
The Bill increases penalties across a wide range of AML/CFT offences.
For civil liability acts, the proposed maximum penalty is:
NZ$500,000 for an individual, or three times the resulting commercial gain where applicable; and
NZ$5 million for other persons, with potential alternatives based on three times commercial gain or 10% of turnover where gain cannot readily be established.
Several serious offences carry maximum penalties of up to four years’ imprisonment and/or NZ$500,000 for individuals, with corporate penalties potentially reaching NZ$5 million or turnover-based amounts. (New Zealand Legislation)
The Bill also:
extends several prosecution limitation periods from 3 years to 5 years;
introduces an offence for structuring a legal person or legal arrangement to avoid AML/CFT requirements;
increases penalties for existing structuring and reporting offences;
introduces offences for obstructing or misleading the Commissioner; and
increases penalties associated with cross-border cash reporting.
11. Money-laundering penalties under the Crimes Act increase
The Bill separately amends section 243 of the Crimes Act 1961.
The maximum imprisonment for knowingly or recklessly dealing with criminal proceeds through a money-laundering transaction increases from 7 years to 14 years.
For possessing or obtaining another person’s criminal proceeds with the relevant intent and knowledge, the maximum increases from 5 years to 10 years.
12. What AML compliance teams should prepare for
The Bill points toward a compliance model that is simultaneously more risk-based and more enforcement-focused.
Compliance leaders should begin reviewing:
CDD frameworks — particularly low-risk SDD and trust onboarding.
Sanctions screening — including governance, screening frequency, escalation and potential-match handling.
Risk assessments — to incorporate sanctions risk and formally document low-risk scenarios.
Group AML governance — particularly for multinational or related entities.
Data-sharing arrangements — including privacy and accountability controls.
Independent evaluation arrangements — including evaluator independence and scope.
Virtual-asset controls — especially cash transaction monitoring.
FIU response processes — including readiness to respond to production and freezing orders.
Record management — given the expanded information-production powers and longer limitation periods.
Regulatory change management — because several important operational requirements, including virtual-asset thresholds and infringement fees, will be determined through subsequent regulations.
Conclusion
The AML/CFT (Omnibus) Amendment Bill 2026 is not simply a collection of technical amendments. It proposes a shift toward greater proportionality in customer due diligence, formal sanctions compliance, stronger group-wide AML governance, expanded financial intelligence powers and a more graduated but significantly tougher enforcement framework.
For reporting entities, the key message is that regulatory relief will come primarily through risk-based flexibility, while expectations around financial intelligence, sanctions, information sharing and enforcement will become more structured.
The Bill provides the legislative framework; several important operational details will depend on regulations and rules made after the legislation progresses. The Bill itself proposes commencement one year after Royal assent.
Read about the laws; click here.
Read about the product: Transact Comply
Empower your organization with ZIGRAM’s integrated RegTech solutions – Book a Demo
- #AMLCompliance
- #AntiMoneyLaundering
- #AML
- #CFT
- #FinancialCrime
- #FinancialCrimeCompliance
- #omnibus
- #NewZealand