New Zealand’s proposed Anti-Money Laundering and Countering Financing of Terrorism (Omnibus) Amendment Bill seeks to reshape the country’s anti-financial-crime framework, combining greater flexibility for businesses with expanded supervisory, intelligence and enforcement powers.
The omnibus legislation would amend the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, alongside other legislation administered by the Ministry of Justice. It was introduced under Standing Order 267(1)(c), which permits an omnibus Bill amending more than one Act to be introduced where the Business Committee has agreed to its introduction in that form.
The Bill has three broad objectives: reducing unnecessary regulatory burdens on businesses, bringing New Zealand’s domestic framework closer to international expectations and standards, and strengthening the tools available to combat organised crime.
Greater flexibility in customer due diligence
One of the Bill’s central themes is giving reporting entities greater discretion over how they conduct customer due diligence.
The proposed changes would provide reporting entities with greater autonomy to apply simplified or enhanced customer due diligence, depending on the risks they face. They would also have more discretion to determine the information they need to collect to address their particular business risks.
The approach represents a shift towards a more explicitly risk-based compliance model, allowing businesses to tailor their AML/CFT controls to the risks associated with their customers, products, services and operations rather than relying solely on prescriptive information requirements.
For reporting entities, the practical implication would be greater responsibility for determining what information is proportionate and necessary to mitigate their specific risks.
Sanctions compliance becomes a formal part of the framework
A major component of the Bill is its proposed framework for supervising compliance with United Nations Security Council targeted financial sanctions.
The legislation is intended to close what the Bill identifies as a gap in New Zealand’s ability to meet its international obligations by creating a legal framework for supervision of reporting entities’ compliance with these sanctions.
Under the proposed system, reporting entities would have mandatory obligations to assess and mitigate relevant sanctions risks.
The Bill would also expand the roles of both AML/CFT supervisors and the Financial Intelligence Unit (FIU) of New Zealand Police in supporting implementation and supervision of these sanctions-related requirements.
For compliance teams, this would place sanctions-risk management more firmly within the regulated financial-crime control environment, alongside existing AML/CFT responsibilities.
Group-wide AML/CFT oversight to replace designated business groups
Another significant structural change would be the replacement of the existing designated business group model with mandatory and voluntary reporting frameworks.
Under the proposed mandatory framework, groups would be required to establish a group-wide AML/CFT programme designed to create a consistent and aligned approach to compliance across related entities.
The intention is to help groups identify risks arising from their common interests while reducing inconsistencies between related businesses that could potentially be exploited by criminals.
Both the mandatory and voluntary frameworks would require reporting entities to designate a lead entity responsible for overseeing shared AML/CFT risk assessments and policies.
This would place greater emphasis on coordinated group-level governance rather than treating AML/CFT compliance solely as an entity-by-entity responsibility.
Wider supervisory and enforcement powers
The Bill also proposes a substantial expansion of the powers available to supervisors and intelligence agencies.
Among the proposed measures are:
- enhanced supervisory powers;
- expanded intelligence functions;
- new offences;
- an infringement-offence regime for minor non-compliance;
- higher maximum penalties for civil liability acts and offences; and
- limitation periods aligned with record-keeping requirements.
The combination of these measures would give regulators a broader range of responses to non-compliance, distinguishing between minor breaches and more serious conduct while increasing the potential consequences for significant violations.
Expanded powers for the Financial Intelligence Unit
The Bill would also strengthen the intelligence and harm-prevention functions of the FIU.
Under the proposed changes, the FIU would gain powers to gather information from non-reporting entities, extending its ability to obtain intelligence beyond organisations already subject to AML/CFT reporting obligations.
The FIU would also be able to seek orders requiring the ongoing production of data by reporting entities.
Another proposed power would allow the FIU to seek rapid freezes on high-risk accounts and transactions.
Together, these measures are intended to strengthen the system’s ability to identify emerging financial-crime risks and intervene before potentially harmful activity can progress.
A greater emphasis on risk-based compliance
Taken together, the proposed reforms point towards a model in which reporting entities would have more flexibility but also greater accountability for the effectiveness of their own AML/CFT frameworks.
The Bill would give businesses more discretion over the information they collect and the way they apply simplified or enhanced due diligence. At the same time, it would strengthen supervisory and enforcement mechanisms and introduce additional obligations around targeted financial sanctions.
This combination effectively places greater importance on the quality of a reporting entity’s risk assessment, governance, controls and decision-making.
Rather than simply determining whether a prescribed compliance step has been completed, the framework would place greater emphasis on whether the organisation has appropriately identified and mitigated the risks relevant to its business.
Regulatory impact assessments underpin the reforms
The Ministry of Justice prepared regulatory impact statements on 18 June 2025 and 22 June 2026 to inform the Government’s principal policy decisions relating to the Bill.
The documents are intended to provide the analysis supporting the policy choices reflected in the proposed legislation and are available through the Ministry of Justice and New Zealand’s regulatory analysis resources.
The Ministry also prepared documentation relating to the Bill’s consistency with the principles of responsible regulation under the Regulatory Standards Act 2025.
This included a consistency accountability statement dated 19 June 2026 and a summary of underpinning analysis prepared on the same date.
The Ministry has stated that it considers a statement from the responsible Minister under section 11(b) of the Regulatory Standards Act 2025 is not required for the Bill.
What the proposed changes could mean for compliance teams
For reporting entities, the Bill would bring together several developments that could materially affect AML/CFT operating models.
First, organisations would have greater discretion to determine the customer information and due-diligence measures appropriate to their individual risk profiles.
Second, sanctions compliance would become subject to a dedicated supervisory framework, accompanied by mandatory risk-assessment and mitigation obligations.
Third, organisations operating within wider corporate groups could face stronger expectations around group-wide AML/CFT programmes, shared risk assessments and common policies, supported by a designated lead entity.
Finally, the expansion of FIU and supervisory powers would increase the importance of maintaining robust records, defensible risk assessments and effective controls capable of demonstrating compliance to regulators.
A dual message: flexibility and accountability
The proposed Omnibus Bill sends two parallel messages to New Zealand’s AML/CFT sector.
The first is regulatory flexibility. Businesses would receive greater autonomy to determine how they apply customer due diligence and what information they need to collect, allowing controls to be better aligned with their specific risks.
The second is greater accountability. Reporting entities would face new sanctions-related obligations, while regulators and the FIU would receive expanded powers to obtain information, supervise compliance, investigate risks and intervene in potentially harmful activity.
The result would be a framework that seeks to reduce unnecessary compliance burdens without reducing the system’s ability to respond to money laundering, terrorist financing, sanctions risks and organised crime.
For compliance functions, the direction of travel is therefore not simply towards less regulation, but towards more risk-based discretion accompanied by stronger expectations around governance, intelligence, oversight and demonstrable risk management.
By FCCT Editorial Team

