Crypto ATM / kiosk operator in New Zealand
Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.
Crypto ATM is conditionally permitted in New Zealand with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register with Department of Internal Affairs (DIA) as a reporting entity under the AML/CFT Act 2009 (nz.licensing.amlcft-registration-dia-most-crypto)
- Conduct a comprehensive risk assessment covering business, customers, products, delivery channels, and jurisdictions (nz.aml.conduct-a-comprehensive-risk-assessment)
- Establish and maintain an AML/CFT programme with policies, procedures, and controls (nz.aml.establish-and-maintain-an-amlcft)
- Perform standard Customer Due Diligence (CDD): obtain and verify full name, date of birth, address using reliable independent sources (nz.aml.identity-verification-obtaining-and-verifying)
- Perform Enhanced CDD (ECDD) for higher-risk situations including cash-intensive operations, PEPs, high-risk countries, complex/unusually large transactions (nz.aml.enhanced-cdd-ecdd-required-for)
- Identify and verify beneficial ownership (natural persons with >25% ownership or control) (nz.aml.beneficial-ownership-identifying-and-verifying)
- Screen customers and transactions against UN Security Council sanctions lists (nz.aml.sanctions-screening-screening-customers-and)
- Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit (FIU) (nz.aml.obligation-to-report-vasps-must)
- Ongoing monitoring of transactions and customer information (nz.aml.ongoing-monitoring-regularly-reviewing-transactions)
- No tipping-off — prohibited from disclosing that a report has been made or an investigation is underway (nz.aml.no-tipping-off-reporting-entities)
- Face-to-face vs non-face-to-face specific requirements apply; ATMs are non-face-to-face and must comply with Identity Verification Code of Practice (nz.aml.face-to-face-vs-non-face-to-face-specific-requirements)
Key Restrictions
- Must register with DIA as a reporting entity under the AML/CFT Act 2009 — no separate 'kiosk-specific' license exists, but the ATM/kiosk model triggers reporting entity obligations (nz.licensing.amlcft-registration-dia-most-crypto)
- No specific minimum capital requirements under the AML/CFT Act for reporting entities (nz.licensing.there-are-no-specific-minimum)
- Cash transactions (in/out) will trigger ECDD obligations due to inherently higher risk profile of cash-based crypto transactions (nz.aml.enhanced-cdd-ecdd-required-for)
- If the kiosk offers any derivatives, financial advice, or managed investment schemes, FSP registration and FMA licensing may also be required (nz.licensing.if-the-exchange-offers-derivatives)
- Local incorporation is effectively required as registration as a New Zealand reporting entity with DIA requires a local presence and nexus
Key Risks
- Enforcement precedent: Coinstash fined NZD $2.3 million for significant AML/CFT breaches including failures in customer due diligence and compliance programme (nz.enforcement.violation-type-significant-breaches-of)
- Enforcement precedent: Dasset Limited fined and subsequently liquidated for AML/CFT breaches including CDD failures (nz.enforcement.entity-targeted-dasset-limited-now)
- High-risk cash model: Crypto ATMs are inherently cash-intensive and high-risk, attracting intensive regulatory scrutiny and potential ECDD obligations
- Non-face-to-face challenges: ATMs operate without direct staff supervision, making compliance with Identity Verification Code of Practice technically complex
- No prescribed cash-transaction reporting threshold found in provided facts — reporting entity must rely on suspicion-based reporting to FIU rather than a fixed cash threshold
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
AML/CFT Registration (DIA): Most crypto businesses, including exchanges, custody providers, and payment processors dealing with VAs, are categorised as "reporting entities" under the AML/CFT Act. This requires them to register with the DIA as a reporting entity and comply with comprehensive AML/CFT obligations. This is not a "license" in the traditional sense of permitting operation, but a mandatory registration for AML/CFT compliance.
Primary Requirement: AML/CFT Reporting Entity Registration (DIA)
Businesses that exchange virtual assets for fiat currency, other virtual assets, or facilitate such exchanges are deemed "reporting entities" under the AML/CFT Act. This includes operating a trading platform.
Department of Internal Affairs (DIA): The primary supervisor for most VASPs under the AML/CFT Act 2009. This includes businesses involved in exchanging, transferring, holding, or safekeeping virtual assets.
Businesses that transmit money or value using virtual assets, or facilitate payments in VAs, are typically classified as "money or value transfer services" under the AML/CFT Act and must register with the DIA.
There are no specific minimum capital requirements under the AML/CFT Act for VASPs solely registered as reporting entities.
Exchange virtual assets for fiat currency (and vice versa).
Conduct a comprehensive risk assessment: This identifies and assesses the money laundering and terrorism financing risks specific to their business, customers, products, services, delivery channels, and jurisdictions they operate in. Risks associated with the inherent characteristics of virtual assets (e.g., pseudo-anonymity, speed of transfer, global reach) must be specifically addressed.
Establish and maintain an AML/CFT Programme: This is a documented programme that outlines the policies, procedures, and controls the VASP has in place to mitigate the risks identified in their risk assessment. It must include measures to:
Identity Verification: Obtaining and verifying the customer's full name, date of birth, and address using reliable and independent sources (e.g., passport, driver's license, national ID, proof of address utility bills). For legal entities, verifying the entity's name, legal form, proof of existence, registered address, and articles of association.
Enhanced CDD (ECDD): Required for higher-risk situations, such as:
Beneficial Ownership: Identifying and verifying the identity of the natural person(s) who ultimately own or control a customer (typically those with more than 25% ownership or control for legal entities).
Sanctions Screening: Screening customers and transactions against relevant sanctions lists (e.g., UN Security Council sanctions lists).
Obligation to Report: VASPs must report any transaction or activity they suspect is related to money laundering, terrorism financing, or other criminal activity to the New Zealand Police Financial Intelligence Unit (FIU).
Ongoing Monitoring: Regularly reviewing transactions and customer information to ensure it is consistent with the VASP's knowledge of the customer, their business, and risk profile. This is crucial for VASPs given the dynamic nature of virtual assets.
No Tipping Off: Reporting entities are prohibited from disclosing to the customer or any third party that a report has been made or that an investigation is underway.
Face-to-Face vs. Non-Face-to-Face: Specific requirements apply to non-face-to-face onboarding to mitigate higher risks. Technologies like video conferencing or biometric verification can be used if they meet the standards set out in the Identity Verification Code of Practice.
Identity Verification Code of Practice 2013 (or current version): Issued by the supervisors, this code provides practical guidance on how to meet customer identity verification requirements.
Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, suspicious transaction reporting, and compliance programme. Penalty Amount: NZD $2.3 million. Outcome: Coinstash admitted to the breaches and agreed to pay the penalty. The DIA noted this was the largest financial penalty issued under the AML/CFT Act for a single infringement notice.
Entity Targeted: Dasset Limited (now in liquidation). Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, record-keeping, and the overall compliance programme. Penalty Amount: NZD $1 million. Outcome: Dasset admitted to the breaches and agreed to pay the penalty. The company subsequently went into liquidation in October 2023, though the DIA noted the penalty was not the direct cause.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Crypto ATM/kiosk operators are permitted in New Zealand but must register with the Department of Internal Affairs as a reporting entity under the AML/CFT Act 2009, comply with full AML/CFT obligations including ECDD for cash transactions, and face significant enforcement risk (up to NZD $2.3M+ penalties) as demonstrated by the Coinstash and Dasset cases.
Questions this verdict aims to answer
- What money-transmitter / kiosk-specific license is required?
- What cash-transaction reporting thresholds apply?
- What enhanced-KYC obligations attach to cash-in / cash-out?