← Regulations / New Zealand / Operating Models / On-shore VASP

On-shore VASP in New Zealand

Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.

Conditional AI-Generated · Unreviewed

On-shore VASP is conditionally permitted in New Zealand with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Register as a reporting entity with the Department of Internal Affairs (DIA) under the AML/CFT Act 2009.
  • Conduct a comprehensive risk assessment covering business, customers, products, delivery channels, and jurisdictions.
  • Establish and maintain an AML/CFT Programme with written policies, procedures, and controls.
  • Perform Customer Due Diligence (CDD): verify customer name, date of birth, address via reliable independent sources (e.g. passport, driver's license). For legal entities, verify name, legal form, proof of existence, and beneficial ownership (>25% threshold).
  • Apply Enhanced CDD (ECDD) for Politically Exposed Persons (PEPs), high-risk countries, complex/unusually large transactions, and customers with complex ownership structures.
  • Conduct ongoing monitoring of transactions and customer information.
  • Screen customers and transactions against UN Security Council sanctions lists.
  • Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit (FIU).
  • Comply with 'no tipping-off' obligations — cannot disclose to the customer that a report has been made.
  • Maintain records for the required retention period under the AML/CFT Act.
  • Adhere to the Identity Verification Code of Practice 2013, including specific rules for non-face-to-face onboarding.

Key Restrictions

  • Must be incorporated in New Zealand and registered with the New Zealand Companies Office.
  • Must register as a reporting entity with the DIA under the AML/CFT Act 2009 — this is the primary licensing requirement for most VASPs.
  • If offering derivatives, managed investment schemes, or regulated financial advice, an FMA licence (e.g. Market Services Licence or Financial Advice Provider licence) is additionally required.
  • If the business involves deposit-taking from the public or e-money issuance redeemable for fiat, RBNZ Non-Bank Deposit Taker (NBDT) registration may be triggered, which carries significant capital requirements.
  • No specific minimum capital requirements for pure AML/CFT reporting entity registration, but FMA licensing (if triggered) imposes capital/solvency requirements.
  • Crypto gains from trading/investing are generally taxable as income under NZ law — the IRD treats most crypto trading activity as a profit-making scheme.

Key Risks

  • Enforcement precedent: DIA has imposed significant penalties — NZD $2.3 million on Coinstash and NZD $3.5 million on Dasset for AML/CFT breaches (customer due diligence, risk assessments, record-keeping failures).
  • Individual liability risk: FMA obtained High Court orders banning an individual and imposing penalties for operating unregistered financial services and misleading representations about crypto investments.
  • Regulatory boundary risk: Activities that stray into derivatives, managed investment schemes, or deposit-taking can trigger FMA or RBNZ oversight with much higher compliance burdens.
  • Tax ambiguity: IRD treats most crypto disposals as taxable income (not capital gains), and the bar for proving long-term holding without profit intention is high.
  • Liquidation risk: Dasset went into liquidation shortly after its penalty, illustrating that enforcement actions can compound financial stress on operators.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

AML/CFT Registration (DIA): Most crypto businesses, including exchanges, custody providers, and payment processors dealing with VAs, are categorised as "reporting entities" under the AML/CFT Act. This requires them to register with the DIA as a reporting entity and comply with comprehensive AML/CFT obligations. This is not a "license" in the traditional sense of permitting operation, but a mandatory registration for AML/CFT compliance.

licensing 60% confidence

Businesses that exchange virtual assets for fiat currency, other virtual assets, or facilitate such exchanges are deemed "reporting entities" under the AML/CFT Act. This includes operating a trading platform.

licensing 60% confidence

Businesses that offer safekeeping services for virtual assets on behalf of customers (i.e., holding private keys or managing custodial wallets) are considered "reporting entities" under the AML/CFT Act.

licensing 60% confidence

Businesses that transmit money or value using virtual assets, or facilitate payments in VAs, are typically classified as "money or value transfer services" under the AML/CFT Act and must register with the DIA.

licensing 60% confidence

If the exchange offers derivatives (e.g., futures, options on VAs), manages client funds in a structured investment product, or provides regulated financial advice, then FSP registration and potentially an FMA license (e.g., a Market Services Licence or a Financial Advice Provider (FAP) Licence) would be required.

licensing 60% confidence

If the custody service is part of a broader investment scheme (e.g., a managed investment scheme where the provider also makes investment decisions or offers investment products), then FMA licensing would be necessary. Merely providing technical custody without any active management or investment component is less likely to trigger FMA licensing, but full AML/CFT compliance remains critical.

licensing 60% confidence

If the payment processor also accepts deposits of fiat currency from the public or issues e-money that is redeemable for fiat, they might fall under the RBNZ's NBDT regime. This is less common for pure crypto payment processors but important to consider if they bridge significantly with traditional fiat payment systems. Similarly, if they offer payment-related financial products, FMA oversight might be triggered.

licensing 60% confidence

There are no specific minimum capital requirements under the AML/CFT Act for VASPs solely registered as reporting entities.

licensing 60% confidence

However, if an FMA license is triggered (e.g., Financial Advice Provider, Market Services Licence), then specific capital and solvency requirements will apply, often based on the nature and scale of the financial services provided. For example, FAPs must demonstrate adequate financial resources.

licensing 60% confidence

Financial Service Provider (FSP) Licensing (FMA): If a VASP provides services that meet the definition of a "financial service" under the Financial Service Providers (Registration and Dispute Resolution) Act 2008 (FSP Act) – for example, giving financial advice, operating a managed investment scheme involving VAs, or dealing in financial products like VA derivatives – then they will need to license with the FMA. This involves more stringent requirements than just AML/CFT registration.

aml 20% confidence

Conduct a comprehensive risk assessment: This identifies and assesses the money laundering and terrorism financing risks specific to their business, customers, products, services, delivery channels, and jurisdictions they operate in. Risks associated with the inherent characteristics of virtual assets (e.g., pseudo-anonymity, speed of transfer, global reach) must be specifically addressed.

aml 20% confidence

Establish and maintain an AML/CFT Programme: This is a documented programme that outlines the policies, procedures, and controls the VASP has in place to mitigate the risks identified in their risk assessment. It must include measures to:

aml 20% confidence

Identity Verification: Obtaining and verifying the customer's full name, date of birth, and address using reliable and independent sources (e.g., passport, driver's license, national ID, proof of address utility bills). For legal entities, verifying the entity's name, legal form, proof of existence, registered address, and articles of association.

aml 20% confidence

Enhanced CDD (ECDD): Required for higher-risk situations, such as:

aml 20% confidence

Beneficial Ownership: Identifying and verifying the identity of the natural person(s) who ultimately own or control a customer (typically those with more than 25% ownership or control for legal entities).

aml 20% confidence

Ongoing Monitoring: Regularly reviewing transactions and customer information to ensure it is consistent with the VASP's knowledge of the customer, their business, and risk profile. This is crucial for VASPs given the dynamic nature of virtual assets.

aml 20% confidence

Sanctions Screening: Screening customers and transactions against relevant sanctions lists (e.g., UN Security Council sanctions lists).

aml 20% confidence

Obligation to Report: VASPs must report any transaction or activity they suspect is related to money laundering, terrorism financing, or other criminal activity to the New Zealand Police Financial Intelligence Unit (FIU).

aml 20% confidence

No Tipping Off: Reporting entities are prohibited from disclosing to the customer or any third party that a report has been made or that an investigation is underway.

aml 20% confidence

Face-to-Face vs. Non-Face-to-Face: Specific requirements apply to non-face-to-face onboarding to mitigate higher risks. Technologies like video conferencing or biometric verification can be used if they meet the standards set out in the Identity Verification Code of Practice.

enforcement 70% confidence

Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, suspicious transaction reporting, and compliance programme. Penalty Amount: NZD $2.3 million. Outcome: Coinstash admitted to the breaches and agreed to pay the penalty. The DIA noted this was the largest financial penalty issued under the AML/CFT Act for a single infringement notice.

enforcement 70% confidence

Entity Targeted: Dasset Limited (now in liquidation). Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, record-keeping, and the overall compliance programme. Penalty Amount: NZD $1 million. Outcome: Dasset admitted to the breaches and agreed to pay the penalty. The company subsequently went into liquidation in October 2023, though the DIA noted the penalty was not the direct cause.

enforcement 70% confidence

Entity Targeted: James Malcolm Allan (individual). Violation Type: Operating an unregistered financial service provider, making misleading representations about financial products (including crypto-assets), and breaches of the Fair Trading Act 1986 and the Financial Service Providers (Registration and Dispute Resolution) Act 2008. Allan had been promoting investments via social media, purporting to offer high returns from trading shares and crypto-assets. Penalty Amount: Permanent ban from providing financial services and from acting as a director or manager of any financial service provider. A pecuniary penalty of NZD $50,000 was also ordered. Outcome: The FMA successfully obtained orders from the High Court against Allan, resulting in the ban and penalty. This was a significant action against an individual promoting crypto-related investments without proper registration or disclosure.

tax 60% confidence

Income Treatment: If you acquired the crypto with an intention to sell it for a profit, or if your activities constitute a business of dealing, any gain is taxable income. This includes short-term speculation, day trading, and most active trading strategies.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — an on-shore VASP may operate in New Zealand by incorporating locally, registering as a reporting entity with the DIA under the AML/CFT Act 2009, and complying with comprehensive AML/CFT obligations; if the VASP offers derivatives, managed investment schemes, or deposit-taking services, additional FMA or RBNZ licensing is triggered.

Questions this verdict aims to answer

  • What license(s) are required to operate locally?
  • What capital, governance, and reporting obligations apply?
  • What is the application process and timeline?