Centralized exchange in New Zealand
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in New Zealand with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register as a reporting entity with the Department of Internal Affairs (DIA) under the AML/CFT Act 2009
- Conduct a comprehensive AML/CFT risk assessment specific to the business, customers, products, and jurisdictions
- Establish and maintain a documented AML/CFT programme covering policies, procedures, and controls
- Customer Due Diligence (CDD): Obtain and verify customer full name, date of birth, and address from reliable independent sources
- Non-face-to-face onboarding must comply with the Identity Verification Code of Practice
- Beneficial ownership identification: Identify and verify natural persons with >25% ownership or control of legal entity customers
- Enhanced CDD (ECDD) required for PEPs, high-risk jurisdictions, complex/unusually large transactions, and complex ownership structures
- Ongoing monitoring of transactions and customer information relative to customer risk profile
- Sanctions screening against UN Security Council and relevant sanctions lists
- Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit (FIU)
- No tipping-off: prohibited from disclosing to customers that a report has been made
- Travel Rule (value transfer) obligations likely apply as a money or value transfer service under AML/CFT Act — NZ is a FATF member and follows FATF Recommendation 16 requirements for VASPs
- Record-keeping obligations for CDD information and transaction records
Key Restrictions
- Must be registered as a reporting entity with DIA under the AML/CFT Act 2009
- If the exchange offers derivatives (futures, options on VAs), manages client funds in a structured investment product, or provides regulated financial advice, then FSP registration and potentially an FMA license (Market Services Licence or Financial Advice Provider Licence) is required
- Must have a local registered entity to register as a reporting entity with DIA
- No specific minimum capital requirements under pure AML/CFT registration, but capital/solvency requirements apply if FMA licensing is triggered
- Custody services trigger reporting-entity obligations — assets must be held in compliance with AML/CFT programme requirements (though the AML/CFT Act itself does not prescribe specific segregation rules for virtual assets; prudent segregation is expected as a matter of compliance practice)
Key Risks
- Enforcement precedent: DIA fined Coinstash NZD $2.3 million and Dasset NZD $1.3 million for AML/CFT compliance failures (CDD, risk assessments, record-keeping)
- High regulatory scrutiny on non-face-to-face onboarding compliance with Identity Verification Code of Practice — video and biometric verification must meet specific standards
- Regulatory ambiguity on whether specific custody segregation rules apply to virtual assets — no explicit segregation framework; reliance on general AML/CFT programme expectations
- If the exchange offers derivatives or structured products, FMA licensing adds material cost, capital, and compliance overhead
- FMA has actively pursued individuals operating unregistered crypto-related financial services without proper disclosure (e.g., James Allan case)
- Travel rule compliance is complex — no domestic prescribing regulation yet, but FATF obligations apply and supervisors expect compliance
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Department of Internal Affairs (DIA): The primary supervisor for most VASPs under the AML/CFT Act 2009. This includes businesses involved in exchanging, transferring, holding, or safekeeping virtual assets.
AML/CFT Registration (DIA): Most crypto businesses, including exchanges, custody providers, and payment processors dealing with VAs, are categorised as "reporting entities" under the AML/CFT Act. This requires them to register with the DIA as a reporting entity and comply with comprehensive AML/CFT obligations. This is not a "license" in the traditional sense of permitting operation, but a mandatory registration for AML/CFT compliance.
Primary Requirement: AML/CFT Reporting Entity Registration (DIA)
Businesses that exchange virtual assets for fiat currency, other virtual assets, or facilitate such exchanges are deemed "reporting entities" under the AML/CFT Act. This includes operating a trading platform.
Businesses that offer safekeeping services for virtual assets on behalf of customers (i.e., holding private keys or managing custodial wallets) are considered "reporting entities" under the AML/CFT Act.
If the exchange offers derivatives (e.g., futures, options on VAs), manages client funds in a structured investment product, or provides regulated financial advice, then FSP registration and potentially an FMA license (e.g., a Market Services Licence or a Financial Advice Provider (FAP) Licence) would be required.
Potential Secondary Requirement: FSP Registration/Licensing (FMA)
Financial Service Provider (FSP) Licensing (FMA): If a VASP provides services that meet the definition of a "financial service" under the Financial Service Providers (Registration and Dispute Resolution) Act 2008 (FSP Act) – for example, giving financial advice, operating a managed investment scheme involving VAs, or dealing in financial products like VA derivatives – then they will need to license with the FMA. This involves more stringent requirements than just AML/CFT registration.
There are no specific minimum capital requirements under the AML/CFT Act for VASPs solely registered as reporting entities.
However, if an FMA license is triggered (e.g., Financial Advice Provider, Market Services Licence), then specific capital and solvency requirements will apply, often based on the nature and scale of the financial services provided. For example, FAPs must demonstrate adequate financial resources.
Exchange virtual assets for fiat currency (and vice versa).
Exchange one form of virtual asset for another.
Provide custodial services for virtual assets.
Conduct a comprehensive risk assessment: This identifies and assesses the money laundering and terrorism financing risks specific to their business, customers, products, services, delivery channels, and jurisdictions they operate in. Risks associated with the inherent characteristics of virtual assets (e.g., pseudo-anonymity, speed of transfer, global reach) must be specifically addressed.
Establish and maintain an AML/CFT Programme: This is a documented programme that outlines the policies, procedures, and controls the VASP has in place to mitigate the risks identified in their risk assessment. It must include measures to:
Identity Verification: Obtaining and verifying the customer's full name, date of birth, and address using reliable and independent sources (e.g., passport, driver's license, national ID, proof of address utility bills). For legal entities, verifying the entity's name, legal form, proof of existence, registered address, and articles of association.
Face-to-Face vs. Non-Face-to-Face: Specific requirements apply to non-face-to-face onboarding to mitigate higher risks. Technologies like video conferencing or biometric verification can be used if they meet the standards set out in the Identity Verification Code of Practice.
Enhanced CDD (ECDD): Required for higher-risk situations, such as:
Politically Exposed Persons (PEPs): Customers who are or have been entrusted with prominent public functions, their family members, and close associates. Requires senior management approval, source of funds/wealth verification, and ongoing monitoring.
High-risk countries: Customers from jurisdictions identified as having inadequate AML/CFT regimes.
Beneficial Ownership: Identifying and verifying the identity of the natural person(s) who ultimately own or control a customer (typically those with more than 25% ownership or control for legal entities).
Ongoing Monitoring: Regularly reviewing transactions and customer information to ensure it is consistent with the VASP's knowledge of the customer, their business, and risk profile. This is crucial for VASPs given the dynamic nature of virtual assets.
Sanctions Screening: Screening customers and transactions against relevant sanctions lists (e.g., UN Security Council sanctions lists).
Obligation to Report: VASPs must report any transaction or activity they suspect is related to money laundering, terrorism financing, or other criminal activity to the New Zealand Police Financial Intelligence Unit (FIU).
No Tipping Off: Reporting entities are prohibited from disclosing to the customer or any third party that a report has been made or that an investigation is underway.
Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, suspicious transaction reporting, and compliance programme. Penalty Amount: NZD $2.3 million. Outcome: Coinstash admitted to the breaches and agreed to pay the penalty. The DIA noted this was the largest financial penalty issued under the AML/CFT Act for a single infringement notice.
Entity Targeted: Dasset Limited (now in liquidation). Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, record-keeping, and the overall compliance programme. Penalty Amount: NZD $1 million. Outcome: Dasset admitted to the breaches and agreed to pay the penalty. The company subsequently went into liquidation in October 2023, though the DIA noted the penalty was not the direct cause.
Entity Targeted: James Malcolm Allan (individual). Violation Type: Operating an unregistered financial service provider, making misleading representations about financial products (including crypto-assets), and breaches of the Fair Trading Act 1986 and the Financial Service Providers (Registration and Dispute Resolution) Act 2008. Allan had been promoting investments via social media, purporting to offer high returns from trading shares and crypto-assets. Penalty Amount: Permanent ban from providing financial services and from acting as a director or manager of any financial service provider. A pecuniary penalty of NZD $50,000 was also ordered. Outcome: The FMA successfully obtained orders from the High Court against Allan, resulting in the ban and penalty. This was a significant action against an individual promoting crypto-related investments without proper registration or disclosure.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange offering order-book and custody services in New Zealand must register with the DIA as a reporting entity under the AML/CFT Act 2009, and if it offers derivatives or structured investment products, it also requires FSP registration and FMA licensing.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?