← Regulations / New Zealand / Operating Models / Crypto ATM

Crypto ATM / kiosk operator in New Zealand

Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.

Conditional AI-Generated · Unreviewed

Crypto ATM is conditionally permitted in New Zealand with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Register with Department of Internal Affairs (DIA) as a reporting entity under the AML/CFT Act 2009 (nz.licensing.amlcft-registration-dia-most-crypto)
  • Conduct a comprehensive risk assessment covering business, customers, products, delivery channels, and jurisdictions (nz.aml.conduct-a-comprehensive-risk-assessment)
  • Establish and maintain an AML/CFT programme with policies, procedures, and controls (nz.aml.establish-and-maintain-an-amlcft)
  • Perform standard Customer Due Diligence (CDD): obtain and verify full name, date of birth, address using reliable independent sources (nz.aml.identity-verification-obtaining-and-verifying)
  • Perform Enhanced CDD (ECDD) for higher-risk situations including cash-intensive operations, PEPs, high-risk countries, complex/unusually large transactions (nz.aml.enhanced-cdd-ecdd-required-for)
  • Identify and verify beneficial ownership (natural persons with >25% ownership or control) (nz.aml.beneficial-ownership-identifying-and-verifying)
  • Screen customers and transactions against UN Security Council sanctions lists (nz.aml.sanctions-screening-screening-customers-and)
  • Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit (FIU) (nz.aml.obligation-to-report-vasps-must)
  • Ongoing monitoring of transactions and customer information (nz.aml.ongoing-monitoring-regularly-reviewing-transactions)
  • No tipping-off — prohibited from disclosing that a report has been made or an investigation is underway (nz.aml.no-tipping-off-reporting-entities)
  • Face-to-face vs non-face-to-face specific requirements apply; ATMs are non-face-to-face and must comply with Identity Verification Code of Practice (nz.aml.face-to-face-vs-non-face-to-face-specific-requirements)

Key Restrictions

  • Must register with DIA as a reporting entity under the AML/CFT Act 2009 — no separate 'kiosk-specific' license exists, but the ATM/kiosk model triggers reporting entity obligations (nz.licensing.amlcft-registration-dia-most-crypto)
  • No specific minimum capital requirements under the AML/CFT Act for reporting entities (nz.licensing.there-are-no-specific-minimum)
  • Cash transactions (in/out) will trigger ECDD obligations due to inherently higher risk profile of cash-based crypto transactions (nz.aml.enhanced-cdd-ecdd-required-for)
  • If the kiosk offers any derivatives, financial advice, or managed investment schemes, FSP registration and FMA licensing may also be required (nz.licensing.if-the-exchange-offers-derivatives)
  • Local incorporation is effectively required as registration as a New Zealand reporting entity with DIA requires a local presence and nexus

Key Risks

  • Enforcement precedent: Coinstash fined NZD $2.3 million for significant AML/CFT breaches including failures in customer due diligence and compliance programme (nz.enforcement.violation-type-significant-breaches-of)
  • Enforcement precedent: Dasset Limited fined and subsequently liquidated for AML/CFT breaches including CDD failures (nz.enforcement.entity-targeted-dasset-limited-now)
  • High-risk cash model: Crypto ATMs are inherently cash-intensive and high-risk, attracting intensive regulatory scrutiny and potential ECDD obligations
  • Non-face-to-face challenges: ATMs operate without direct staff supervision, making compliance with Identity Verification Code of Practice technically complex
  • No prescribed cash-transaction reporting threshold found in provided facts — reporting entity must rely on suspicion-based reporting to FIU rather than a fixed cash threshold

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

AML/CFT Registration (DIA): Most crypto businesses, including exchanges, custody providers, and payment processors dealing with VAs, are categorised as "reporting entities" under the AML/CFT Act. This requires them to register with the DIA as a reporting entity and comply with comprehensive AML/CFT obligations. This is not a "license" in the traditional sense of permitting operation, but a mandatory registration for AML/CFT compliance.

licensing 60% confidence

Businesses that exchange virtual assets for fiat currency, other virtual assets, or facilitate such exchanges are deemed "reporting entities" under the AML/CFT Act. This includes operating a trading platform.

licensing 60% confidence

Department of Internal Affairs (DIA): The primary supervisor for most VASPs under the AML/CFT Act 2009. This includes businesses involved in exchanging, transferring, holding, or safekeeping virtual assets.

licensing 60% confidence

Businesses that transmit money or value using virtual assets, or facilitate payments in VAs, are typically classified as "money or value transfer services" under the AML/CFT Act and must register with the DIA.

licensing 60% confidence

There are no specific minimum capital requirements under the AML/CFT Act for VASPs solely registered as reporting entities.

aml 20% confidence

Exchange virtual assets for fiat currency (and vice versa).

aml 20% confidence

Conduct a comprehensive risk assessment: This identifies and assesses the money laundering and terrorism financing risks specific to their business, customers, products, services, delivery channels, and jurisdictions they operate in. Risks associated with the inherent characteristics of virtual assets (e.g., pseudo-anonymity, speed of transfer, global reach) must be specifically addressed.

aml 20% confidence

Establish and maintain an AML/CFT Programme: This is a documented programme that outlines the policies, procedures, and controls the VASP has in place to mitigate the risks identified in their risk assessment. It must include measures to:

aml 20% confidence

Identity Verification: Obtaining and verifying the customer's full name, date of birth, and address using reliable and independent sources (e.g., passport, driver's license, national ID, proof of address utility bills). For legal entities, verifying the entity's name, legal form, proof of existence, registered address, and articles of association.

aml 20% confidence

Enhanced CDD (ECDD): Required for higher-risk situations, such as:

aml 20% confidence

Beneficial Ownership: Identifying and verifying the identity of the natural person(s) who ultimately own or control a customer (typically those with more than 25% ownership or control for legal entities).

aml 20% confidence

Sanctions Screening: Screening customers and transactions against relevant sanctions lists (e.g., UN Security Council sanctions lists).

aml 20% confidence

Obligation to Report: VASPs must report any transaction or activity they suspect is related to money laundering, terrorism financing, or other criminal activity to the New Zealand Police Financial Intelligence Unit (FIU).

aml 20% confidence

Ongoing Monitoring: Regularly reviewing transactions and customer information to ensure it is consistent with the VASP's knowledge of the customer, their business, and risk profile. This is crucial for VASPs given the dynamic nature of virtual assets.

aml 20% confidence

No Tipping Off: Reporting entities are prohibited from disclosing to the customer or any third party that a report has been made or that an investigation is underway.

aml 20% confidence

Face-to-Face vs. Non-Face-to-Face: Specific requirements apply to non-face-to-face onboarding to mitigate higher risks. Technologies like video conferencing or biometric verification can be used if they meet the standards set out in the Identity Verification Code of Practice.

aml 20% confidence

Identity Verification Code of Practice 2013 (or current version): Issued by the supervisors, this code provides practical guidance on how to meet customer identity verification requirements.

enforcement 70% confidence

Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, suspicious transaction reporting, and compliance programme. Penalty Amount: NZD $2.3 million. Outcome: Coinstash admitted to the breaches and agreed to pay the penalty. The DIA noted this was the largest financial penalty issued under the AML/CFT Act for a single infringement notice.

enforcement 70% confidence

Entity Targeted: Dasset Limited (now in liquidation). Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, record-keeping, and the overall compliance programme. Penalty Amount: NZD $1 million. Outcome: Dasset admitted to the breaches and agreed to pay the penalty. The company subsequently went into liquidation in October 2023, though the DIA noted the penalty was not the direct cause.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — Crypto ATM/kiosk operators are permitted in New Zealand but must register with the Department of Internal Affairs as a reporting entity under the AML/CFT Act 2009, comply with full AML/CFT obligations including ECDD for cash transactions, and face significant enforcement risk (up to NZD $2.3M+ penalties) as demonstrated by the Coinstash and Dasset cases.

Questions this verdict aims to answer

  • What money-transmitter / kiosk-specific license is required?
  • What cash-transaction reporting thresholds apply?
  • What enhanced-KYC obligations attach to cash-in / cash-out?