Talk with our team

0221032760

GRC Consulting

Insight Brief · Trans-Tasman

The ML/TF risk assessment: comparing the New Zealand and Australian regimes

A practitioner comparison of the statutory risk assessment obligation under the AML/CFT Act 2009 (NZ) and the reformed AML/CTF Act 2006 (Cth) — current as at June 2026.

June 2026/ 8 min read/ NZAU

The risk assessment is the foundation of every AML/CFT compliance programme. In both New Zealand and Australia it is the document on which everything else is built: the customer due diligence model, the monitoring rules, the escalation pathways, and ultimately the defensibility of the entire framework. Yet the two regimes arrive at this common starting point from different statutory architectures, and the gap between them has widened in 2026 as Australia’s reformed regime takes effect.

This brief sets out, for compliance officers and advisers operating on both sides of the Tasman, how the risk assessment obligation is framed in each jurisdiction, where the requirements align, and where the practical differences matter. Throughout, we distinguish between what is a legal requirement, what is regulatory expectation, and what is supervisory guidance or best practice — a distinction that is easily lost but central to a defensible position.

01

The statutory obligation

New Zealand s 58, AML/CFT Act 2009

In New Zealand, the obligation sits in section 58 of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009. Before conducting customer due diligence or establishing an AML/CFT programme, a reporting entity must first assess the money laundering and terrorism financing risk it may reasonably expect to face in the course of its business. The risk assessment is, in the words of all three supervisors, the first step a business must take, and the AML/CFT programme required under s 56 must be based on it.

Section 58(2) directs the reporting entity to have regard to a defined set of factors — the nature, size and complexity of the business; the products and services it offers; the methods by which it delivers them; the types of customers it deals with; the countries it deals with; and the institutions it deals with. The Department of Internal Affairs has been explicit that a generic, sector-level template will not satisfy section 58: the assessment must engage with the entity’s own business.

New Zealand’s obligation addresses two risks — money laundering and terrorism financing. Proliferation financing is not a standalone limb of the section 58 assessment in the way it is in the reformed Australian regime.

Australia s 26C, AML/CTF Act 2006 (reformed)

Australia’s risk assessment obligation was, until recently, embedded in the Part A programme requirements rather than expressed as a freestanding duty. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) changed that. From 31 March 2026 for existing reporting entities, and 1 July 2026 for newly regulated “Tranche 2” entities (lawyers, accountants, real estate professionals and dealers in precious metals and stones), the reformed Act sets out a distinct ML/TF risk assessment obligation in section 26C.

Under section 26C, a reporting entity must assess the risks of money laundering, terrorism financing and proliferation financing (ML/TF/PF) that it may reasonably face in providing its designated services. The assessment must be documented and in place before the entity begins providing a designated service, and it must have regard to the nature, size and complexity of the business and a defined set of risk factors — designated services and the methods of delivery (including new and emerging technologies), customer types, and the foreign jurisdictions the entity deals with.

Crucially, the reform abolishes the old Part A / Part B split. The risk assessment and the AML/CTF policies together now constitute a single, outcomes-focused AML/CTF program under s 26B, with the risk assessment expressly the first component that shapes the policies.

02

Side-by-side comparison

The comparison below sets out the core features of the risk assessment obligation in each jurisdiction. Legal requirements are stated as such; where a point reflects supervisory expectation or guidance rather than the statute, this is flagged.

Risk assessment obligation · feature comparison

Feature
New Zealand
Australia (reformed)
Primary source
New ZealandSection 58, AML/CFT Act 2009
AustraliaSection 26C, AML/CTF Act 2006 (as amended by the 2024 Amendment Act), supported by the AML/CTF Rules 2025
Risks covered
New ZealandMoney laundering and terrorism financing (ML/TF). Although proliferation financing is not expressly included in section 58, sanctions exposure and proliferation-related risks may still be relevant where they influence ML/TF risk or other legal obligations (for example under sanctions legislation).
AustraliaMoney laundering, terrorism financing and proliferation financing (ML/TF/PF).
Sequencing
New ZealandMust precede CDD and the programme; programme must be based on the risk assessment.
AustraliaMust be documented and in place before providing any designated service; shapes the AML/CTF policies.
Programme structure
New ZealandRisk assessment + AML/CFT programme (s 56). No Part A/B split in NZ.
AustraliaSingle AML/CTF program (s 26B) = risk assessment + AML/CTF policies. Part A/B split abolished.
Prescribed factors
New ZealandNature / size / complexity; products; delivery methods; customer types; countries; institutions dealt with (s 58(2)).
AustraliaNature / size / complexity; designated services; delivery methods incl. new / emerging technologies; customer types; foreign jurisdictions.
Review trigger
New ZealandNo statutory review cycle. The assessment should be reviewed whenever it no longer accurately reflects the entity’s ML/TF risks, including following material changes to the business. Supervisory guidance expects regular review.
AustraliaStatutory: review on significant change to risk factors, AUSTRAC direction or Rules. AUSTRAC guidance currently recommends review at least every three years.
Safe harbour / codes
New ZealandApproved Codes of Practice (such as the Identity Verification Code of Practice) provide statutory safe harbour only for the matters covered by that Code, rather than the AML/CFT framework generally.
AustraliaNo deemed-compliance safe harbour for the risk assessment; AUSTRAC starter programs assist smaller entities.
Independent assurance
New ZealandIndependent audit every 3 years; unless the AML/CFT supervisor requires an earlier audit based on risk or supervisory concerns; or the reporting entity is specifically notified that a different audit cycle (such as four years in limited circumstances) applies.
AustraliaIndependent evaluation of the whole program conducted by an appropriately qualified independent reviewer (s 26F(4)(f)); replaces the old Part A independent review.

Note: review-cycle and three-year points on the Australian side reflect the Act read with AUSTRAC guidance and the Rules; the statute expresses the trigger as significant change rather than a fixed clock. New Zealand’s three-yearly audit cadence is the supervisory default position, subject to direction.

03

Where the two regimes align

Despite the architectural differences, the underlying logic is shared. Both regimes:

  • Put risk first. The risk assessment is the precondition for everything else, and the compliance programme must flow from it rather than sit alongside it.
  • Adopt a risk-based approach. Both supervisors expect the depth of CDD, the intensity of monitoring and the frequency of review to be calibrated to assessed risk, not applied uniformly.
  • Reject generic templates. The DIA’s position that sector-level content alone will not satisfy section 58 mirrors AUSTRAC’s expectation that the assessment must reflect the entity’s actual designated services and customer base.
  • Are FATF-aligned. Both frameworks are built to meet the FATF Recommendations, and both jurisdictions face FATF mutual evaluation pressure — Australia’s reform timetable is driven in part by its 2026 evaluation.
  • Require documentation and governance. In each case the assessment must be written, kept current, and capable of withstanding regulatory scrutiny; senior management and board visibility is expected.
04

Where they diverge — and why it matters

Proliferation financing

The most consequential divergence is scope. Australia’s reformed assessment must address proliferation financing as a distinct risk, consistent with the updated FATF standards. New Zealand’s section 58 remains framed around money laundering and terrorism financing. A trans-Tasman group cannot simply lift its New Zealand risk assessment across the Tasman; the Australian document must explicitly engage with PF risk, sanctions-evasion typologies and the relevant designated services.

The designated-services lens

Australia anchors the assessment to designated services — a defined list of captured activities. A reporting entity assesses risk service by service, and an activity that is not a designated service falls outside the obligation. New Zealand’s section 58 is framed more around the business as a whole and the products and services it offers. For Tranche 2 entities in particular, the first analytical task is determining which of their activities are designated services at all — a threshold question that has no direct New Zealand analogue.

Review cadence and triggers

New Zealand does not fix a statutory review interval for the risk assessment itself; the discipline comes through the three-yearly independent audit under s 59A and supervisory expectation of regular review. Australia’s regime is more explicit about review triggers, supplemented by AUSTRAC guidance recommending periodic review (currently at least every three years). Entities operating in both jurisdictions should adopt the more conservative position and treat regular, triggered review as mandatory in both.

Programme architecture

The abolition of the Part A / Part B distinction in Australia brings its structure closer to New Zealand’s single-programme model, but the reform goes further by making non-compliance with an entity’s own AML/CTF policies a civil penalty matter. The practical effect is that a poorly drafted or aspirational policy is now a liability rather than a cushion.

A poorly drafted or aspirational policy is now a liability rather than a cushion — a point that argues against “zero-tolerance” drafting in favour of proportionate, achievable controls.

Transition risk in Australia

Finally, timing. Australia is mid-transition. Existing reporting entities are expected to have refreshed their enterprise-wide ML/TF/PF risk assessment by 31 March 2026; Tranche 2 entities by 1 July 2026. AUSTRAC has signalled that it expects documented implementation plans and sustained progress rather than perfect compliance from day one — but it has been equally clear that failing to manage ML/TF risk is a serious concern now and will remain so after commencement. For advisers, the live risk is treating an implementation plan as a substitute for the assessment rather than a bridge to it.

05

Practical takeaways for trans-Tasman practitioners

  • Do not port a risk assessment across the Tasman unchanged. The PF limb, the designated-services lens and the different prescribed factors mean each document must be purpose-built for its jurisdiction.
  • Adopt the more conservative review cadence in both. Treating the assessment as a living document — reviewed on every material change, and at least on a fixed cycle — satisfies both regimes and is defensible to either supervisor.
  • Mind the policy-liability shift in Australia. Because policy breaches are now civil penalty matters, risk-appetite and control commitments should be proportionate and operationally achievable.
  • Keep the requirement hierarchy visible. Distinguish in the document itself between statutory obligations, supervisory expectations and best practice, so a reviewer can see the basis for each control.
  • Verify against primary sources. Both regimes are in flux — the AML/CTF Rules 2025 and the 2026 amendment and transitional rules in Australia, and ongoing NZ guidance updates. Confirm the current text before finalising any deliverable.

In a defensible document, practitioners should distinguish between:

  • Statutory obligations (mandatory).
  • Subordinate legislation (Rules or Regulations).
  • Approved Codes of Practice (where applicable).
  • Supervisory guidance.
  • Regulatory expectations reflected in enforcement action and thematic reviews.

Work with us

Building or refreshing a risk assessment on either side of the Tasman?

We help reporting entities design risk assessments and AML/CFT programmes that hold up to supervisory scrutiny in both New Zealand and Australia.

Talk to our AML team