← Regulations / New Zealand / Operating Models / Custodial SaaS

Custodial wallet / SaaS in New Zealand

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in New Zealand with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Register as a reporting entity with the Department of Internal Affairs (DIA) under the AML/CFT Act 2009 — this applies to businesses offering custodial services for virtual assets (holding private keys/managing custodial wallets).
  • Conduct a comprehensive AML/CFT risk assessment covering business, customers, products, services, delivery channels, and jurisdictions.
  • Establish and maintain a documented AML/CFT Programme with policies, procedures, and controls to mitigate identified risks.
  • Perform standard Customer Due Diligence (CDD): obtain and verify customer's full name, date of birth, and address using reliable independent sources (e.g. passport, driver's license). For legal entities, verify entity name, legal form, proof of existence.
  • Apply specific identity verification measures for non-face-to-face onboarding per the Identity Verification Code of Practice.
  • Conduct Enhanced Due Diligence (ECDD) for: PEPs, high-risk country customers, complex or unusually large transactions, customers with complex ownership structures.
  • Identify and verify beneficial owners (natural persons with >25% ownership or control).
  • Conduct ongoing transaction monitoring to ensure activity matches the customer's risk profile.
  • Screen customers and transactions against relevant sanctions lists (e.g. UN Security Council sanctions lists).
  • Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit (FIU).
  • Adhere to 'no tipping-off' rules — cannot disclose to customer or third party that a report has been made or an investigation is underway.
  • If the custody service is part of a broader managed investment scheme or involves financial advice, additional FMA licensing obligations (e.g. Market Services Licence, Financial Advice Provider licence) and associated capital/solvency requirements may apply.

Key Restrictions

  • The custodial wallet/SaaS provider must register as a reporting entity with the DIA — there is no separate 'custody license' or 'qualified custodian' designation under NZ law.
  • Merely providing technical custody without active management or investment discretion generally does not trigger FMA licensing — but if the service is bundled with investment decisions or structured as a managed investment scheme, FMA licensing (Market Services Licence or FAP) becomes required.
  • No specific minimum capital requirements exist under the AML/CFT Act for pure custody providers solely registered as reporting entities with the DIA.
  • If the SaaS provider white-labels to clients, both the SaaS provider (as the reporting entity holding keys) and potentially the white-label client (if engaging in financial services) must assess their own AML/CFT obligations.
  • If the service takes fiat deposits from the public or issues redeemable e-money, RBNZ Non-Bank Deposit Taker (NBDT) registration with significant capital requirements may be triggered.

Key Risks

  • Enforcement precedent: DIA has imposed significant penalties (NZD $2.3M on Coinstash, penalty on Dasset) for AML/CFT compliance failures — custodial providers face real enforcement exposure for inadequate CDD, risk assessments, and compliance programmes.
  • Regulatory ambiguity around the boundary between pure custody (DIA-supervised) vs. managed investment/financial advice (FMA-supervised) — getting this classification wrong exposes the operator to FMA enforcement.
  • Allan case (FMA) shows that unregistered financial service providers offering crypto-related services face High Court orders, bans, and penalties — operators must ensure FSP registration if their offering crosses into financial services.
  • Segregation, insurance, and proof-of-reserves rules are NOT addressed by NZ's current regulatory framework — operators have no statutory safe harbour and must rely on contractual arrangements with clients, creating potential gap in customer protection expectations.
  • Liquidation risk: Dasset went into liquidation after enforcement action — demonstrating that even if penalties are not the direct cause, reputational damage and compliance costs can threaten business viability.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Department of Internal Affairs (DIA): The primary supervisor for most VASPs under the AML/CFT Act 2009. This includes businesses involved in exchanging, transferring, holding, or safekeeping virtual assets.

licensing 60% confidence

AML/CFT Registration (DIA): Most crypto businesses, including exchanges, custody providers, and payment processors dealing with VAs, are categorised as "reporting entities" under the AML/CFT Act. This requires them to register with the DIA as a reporting entity and comply with comprehensive AML/CFT obligations. This is not a "license" in the traditional sense of permitting operation, but a mandatory registration for AML/CFT compliance.

licensing 60% confidence

Businesses that offer safekeeping services for virtual assets on behalf of customers (i.e., holding private keys or managing custodial wallets) are considered "reporting entities" under the AML/CFT Act.

licensing 60% confidence

If the custody service is part of a broader investment scheme (e.g., a managed investment scheme where the provider also makes investment decisions or offers investment products), then FMA licensing would be necessary. Merely providing technical custody without any active management or investment component is less likely to trigger FMA licensing, but full AML/CFT compliance remains critical.

licensing 60% confidence

Potential Secondary Requirement: Non-Bank Deposit Taker (NBDT) Registration (RBNZ) / FSP Licensing (FMA)

licensing 60% confidence

There are no specific minimum capital requirements under the AML/CFT Act for VASPs solely registered as reporting entities.

aml 20% confidence

Provide custodial services for virtual assets.

aml 20% confidence

Exchange virtual assets for fiat currency (and vice versa).

aml 20% confidence

Conduct a comprehensive risk assessment: This identifies and assesses the money laundering and terrorism financing risks specific to their business, customers, products, services, delivery channels, and jurisdictions they operate in. Risks associated with the inherent characteristics of virtual assets (e.g., pseudo-anonymity, speed of transfer, global reach) must be specifically addressed.

aml 20% confidence

Establish and maintain an AML/CFT Programme: This is a documented programme that outlines the policies, procedures, and controls the VASP has in place to mitigate the risks identified in their risk assessment. It must include measures to:

aml 20% confidence

Identity Verification: Obtaining and verifying the customer's full name, date of birth, and address using reliable and independent sources (e.g., passport, driver's license, national ID, proof of address utility bills). For legal entities, verifying the entity's name, legal form, proof of existence, registered address, and articles of association.

aml 20% confidence

Face-to-Face vs. Non-Face-to-Face: Specific requirements apply to non-face-to-face onboarding to mitigate higher risks. Technologies like video conferencing or biometric verification can be used if they meet the standards set out in the Identity Verification Code of Practice.

aml 20% confidence

Enhanced CDD (ECDD): Required for higher-risk situations, such as:

aml 20% confidence

Beneficial Ownership: Identifying and verifying the identity of the natural person(s) who ultimately own or control a customer (typically those with more than 25% ownership or control for legal entities).

aml 20% confidence

Ongoing Monitoring: Regularly reviewing transactions and customer information to ensure it is consistent with the VASP's knowledge of the customer, their business, and risk profile. This is crucial for VASPs given the dynamic nature of virtual assets.

aml 20% confidence

Sanctions Screening: Screening customers and transactions against relevant sanctions lists (e.g., UN Security Council sanctions lists).

aml 20% confidence

Obligation to Report: VASPs must report any transaction or activity they suspect is related to money laundering, terrorism financing, or other criminal activity to the New Zealand Police Financial Intelligence Unit (FIU).

aml 20% confidence

No Tipping Off: Reporting entities are prohibited from disclosing to the customer or any third party that a report has been made or that an investigation is underway.

aml 20% confidence

Identity Verification Code of Practice 2013 (or current version): Issued by the supervisors, this code provides practical guidance on how to meet customer identity verification requirements.

enforcement 70% confidence

Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, suspicious transaction reporting, and compliance programme. Penalty Amount: NZD $2.3 million. Outcome: Coinstash admitted to the breaches and agreed to pay the penalty. The DIA noted this was the largest financial penalty issued under the AML/CFT Act for a single infringement notice.

enforcement 70% confidence

Entity Targeted: Dasset Limited (now in liquidation). Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, record-keeping, and the overall compliance programme. Penalty Amount: NZD $1 million. Outcome: Dasset admitted to the breaches and agreed to pay the penalty. The company subsequently went into liquidation in October 2023, though the DIA noted the penalty was not the direct cause.

enforcement 70% confidence

Entity Targeted: James Malcolm Allan (individual). Violation Type: Operating an unregistered financial service provider, making misleading representations about financial products (including crypto-assets), and breaches of the Fair Trading Act 1986 and the Financial Service Providers (Registration and Dispute Resolution) Act 2008. Allan had been promoting investments via social media, purporting to offer high returns from trading shares and crypto-assets. Penalty Amount: Permanent ban from providing financial services and from acting as a director or manager of any financial service provider. A pecuniary penalty of NZD $50,000 was also ordered. Outcome: The FMA successfully obtained orders from the High Court against Allan, resulting in the ban and penalty. This was a significant action against an individual promoting crypto-related investments without proper registration or disclosure.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers are permitted in New Zealand as DIA-registered reporting entities under the AML/CFT Act 2009, with comprehensive AML/CFT obligations but no dedicated custody license regime, no statutory segregation/insurance/proof-of-reserves rules, and potential secondary FMA licensing if the service crosses into managed investments or financial advice.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?