Southern Cross Property Group Limited · AML/CFT Compliance Documentation 2026-08-04
This is a sample pack for a fictional firm. Southern Cross Property Group Limited doesn't exist — every name, number and listing below is invented to show you exactly what the NZ$595 Compliance Pack looks like when it's generated for a real firm from their questionnaire answers. Get yours →

Real estate agency

Southern Cross Property Group Limited

AML/CFT Compliance Documentation · 2026-08-04

Prepared under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 for approval by the AML/CFT compliance officer, Mere Kingi.

5Documents
2026-08-31Annual report due

Contents

  1. 1AML/CFT Risk Assessment (s.58)
    1. 1.1Purpose and statutory basis
    2. 1.2Section 1 — Nature, size and complexity of the business
    3. 1.3Section 2 — Products and services
    4. 1.4Section 3 — Delivery channels
    5. 1.5Section 4 — Customer types
    6. 1.6Section 5 — Countries
    7. 1.7Section 6 — Institutions
    8. 1.8Section 7 — Supervisor guidance and rules
    9. 1.9Section 8 — Incorporation of the SRA 2026 and NRA 2024
    10. 1.10Section 9 — Risk indicators and red flags
    11. 1.11Section 10 — Determining the level of risk
    12. 1.12Section 11 — Keeping this assessment current
    13. 1.13Section 12 — Version control and approval
  2. 2AML/CFT Programme (s.57)
    1. 2.1Version control
    2. 2.2Statutory basis and standard
    3. 2.3The AML/CFT compliance officer
    4. 2.4s.57(1)(a) — Vetting
    5. 2.5s.57(1)(b) — Training
    6. 2.6s.57(1)(c) — Customer due diligence
    7. 2.7s.57(1)(d) — Reporting suspicious activities
    8. 2.8s.57(1)(da) — Reporting prescribed transactions
    9. 2.9s.57(1)(e) — Record keeping
    10. 2.10s.57(1)(f) — Managing and mitigating risk
    11. 2.11s.57(1)(g) — Examining and keeping written findings on unusual transactions
    12. 2.12s.57(1)(h) — Higher-risk countries
    13. 2.13s.57(1)(i) — Products and transactions favouring anonymity
    14. 2.14s.57(1)(j) — Enhanced and simplified due diligence
    15. 2.15s.57(1)(k) — Third-party customer due diligence
    16. 2.16s.57(1)(l) — Monitoring, communication and training in the programme
    17. 2.17Reviewing, auditing and reporting on this programme
    18. 2.18Approval
  3. 3Annual AML/CFT Report 2025–26 (Schedule 2A)
    1. 3.1Summary
    2. 3.2The report
    3. 3.3Part 6 — Declaration and signature
  4. 4Customer Due Diligence Register
    1. 4.1How this register works
  5. 5Working Tools — how the work gets done
    1. 5.11. Taking on a new customer
    2. 5.22. Red flags — desk card
    3. 5.33. Annual training refresher
    4. 5.44. Registering for goAML
    5. 5.5The Word documents that come with this pack

What changes when it’s your firm’s pack

  • Every paragraph is generated from your ~60 answers — your services, staff, customers and history decide what each document says, not a template.
  • Your customers are in the register — each one entered with its owners, directors and the people who act for it, and the same rows pre-filled in your Excel workbook.
  • Your dates drive the calendar — audit clock, review dates and filing deadlines calculated from your facts, as a .ics you can subscribe to.
  • The covering note is written about you — what you already had, what’s still needed from you, and what to do in order (section 00 below shows the fictional firm’s).
  • A human reads it before you do — every pack is checked before it’s sent; delivery within one working day.
Get yours — NZ$595 →

Or start with the free annual-report tool — ten minutes, your answers formatted for AML Online.

The pack

  1. 00Start here — the covering note
    1. 0.4The dates that matter
    2. 0.6Still needed from you
    3. 0.7Things to do
    4. 0.8Filing the report — how it works
  2. 01AML/CFT Risk Assessment (s.58)
    1. 1.1Purpose and statutory basis
    2. 1.2Section 1 — Nature, size and complexity of the business
    3. 1.3Section 2 — Products and services
    4. 1.4Section 3 — Delivery channels
    5. 1.5Section 4 — Customer types
    6. 1.6Section 5 — Countries
    7. 1.7Section 6 — Institutions
    8. 1.8Section 7 — Supervisor guidance and rules
    9. 1.9Section 8 — Incorporation of the SRA 2026 and NRA 2024
    10. 1.10Section 9 — Risk indicators and red flags
    11. 1.11Section 10 — Determining the level of risk
    12. 1.12Section 11 — Keeping this assessment current
    13. 1.13Section 12 — Version control and approval
  3. 02AML/CFT Programme (s.57)
    1. 2.1Version control
    2. 2.2Statutory basis and standard
    3. 2.3The AML/CFT compliance officer
    4. 2.4s.57(1)(a) — Vetting
    5. 2.5s.57(1)(b) — Training
    6. 2.6s.57(1)(c) — Customer due diligence
    7. 2.7s.57(1)(d) — Reporting suspicious activities
    8. 2.8s.57(1)(da) — Reporting prescribed transactions
    9. 2.9s.57(1)(e) — Record keeping
    10. 2.10s.57(1)(f) — Managing and mitigating risk
    11. 2.11s.57(1)(g) — Examining and keeping written findings on unusual transactions
    12. 2.12s.57(1)(h) — Higher-risk countries
    13. 2.13s.57(1)(i) — Products and transactions favouring anonymity
    14. 2.14s.57(1)(j) — Enhanced and simplified due diligence
    15. 2.15s.57(1)(k) — Third-party customer due diligence
    16. 2.16s.57(1)(l) — Monitoring, communication and training in the programme
    17. 2.17Reviewing, auditing and reporting on this programme
    18. 2.18Approval
  4. 03Annual AML/CFT Report 2025–26 (Schedule 2A)
    1. 3.1Summary
    2. 3.2The report
    3. 3.3Part 6 — Declaration and signature
  5. 04Customer Due Diligence Register
    1. 4.1How this register works
  6. 05Working Tools — how the work gets done
    1. 5.11. Taking on a new customer
    2. 5.22. Red flags — desk card
    3. 5.33. Annual training refresher
    4. 5.44. Registering for goAML
    5. 5.5The Word documents that come with this pack

0Start here — the covering note

Every pack opens with a letter like this one — written about your firm: what you already had, what the pack puts in place, what is still needed from you, and what to do, in order. This is the fictional firm’s letter, exactly as generated.

Southern Cross Property Group Limited · 4 August 2026

Dear Mere Kingi,

This is your AML/CFT compliance pack. It contains the two documents the Act requires you to have and did not — a written risk assessment and a written programme — together with every answer for this year’s annual report, covering 1 July 2025 to 30 June 2026.

Read the risk assessment and the programme, change anything that does not match how you actually work, and approve them. They are your documents, not ours: we prepare them, you adopt them, and they take effect on the date you approve them. Then file this year’s report — every answer is listed at the end of this note, in the order AML Online asks for them, so you can read straight down while you type.

The filing window closes 31 August 2026 and the Department grants no extensions. Nothing is sent to them until you have confirmed it — the attestation on the annual report is yours to make, not ours.

The rest of this page is the detail behind that.


0.1Where you stood

Written risk assessment (s.58) Held
Written programme (s.57) Held
Annual report filed before Yes
Independent audit Last report 15 September 2024

0.2What is now in place

Document What it is
AML/CFT Risk Assessment Required by s.58. Identifies the money laundering and terrorism financing risk this business faces, service by service, using the Department’s own sector risk assessment. This becomes your document once you approve it.
AML/CFT Programme Required by s.57. The procedures, policies and controls that manage those risks — all twelve limbs the Act requires, written for how this business actually operates. Also becomes your document.
Annual Report answers Every question on this year’s return, with the answer to enter and the reasoning behind it.
Customer Due Diligence Register Your customers, who ultimately owns each of them, how that was established, the risk rating and the reasoning. The programme says how due diligence is done; this is the record that it was.
Compliance Workbook (Excel) The registers the programme commits you to keep, started and ready to type into.

Both the risk assessment and the programme are supplied in Word so you can change anything you disagree with before approving them. They are yours, and Mere Kingi approves them as compliance officer — we prepare, you adopt.

0.3Your working tools

The documents above say what the business is. Two more things come with them: one for what you record, and one for how the work actually gets done.

The Compliance Workbook — what you record

The register in your compliance documentation is a photograph of where things stood on the day it was prepared. The workbook is the copy that keeps moving — one spreadsheet, one tab per register the programme commits you to keep:

Tab What goes in it
CDD Register One row per PARTY: the customer, then a row for each beneficial owner and anyone acting on the customer’s behalf. Record what you checked and what form it was in — an original, a properly certified copy or an electronic verification. A photocopy is none of those. Delete the Outstanding note once you have done what it says.
Training Register Every AML/CFT session, including your own. Attendance is not evidence of training — record how you confirmed it was understood.
Written Findings Register Complex, unusually large or unusual-pattern transactions must be examined and the findings written down (s.57(1)(g)) — whether or not they end in a report. An empty register is a fine answer if the year was quiet; a missing one is not.
EDD Register Every customer enhanced due diligence was applied to, why it was triggered, and what you found. Reviewed quarterly against the transactions of the quarter.
SAR & Escalation Register Everything raised as possibly suspicious, and the decision either way with the reasoning. A decision NOT to report is the entry that matters most — it is the one you will be asked to justify. Filed within 3 working days of forming the suspicion (s.40(1)). Never tell the customer (s.46).
Vetting Record Everyone carrying out AML/CFT-related duties, vetted before they start (s.57(1)(a)). Licence currency is re-checked every year.
Compliance Officer Checklist The year’s dated obligations, with the next date already worked out. Put the date in ‘Done’ when you have done it, and roll the ‘Due next’ forward.

Anything still outstanding is written into it as a note. You delete the note when you have done the thing — that is the whole mechanism, and it means the workbook always shows what is genuinely left rather than what was left in August 2026. Keep the one file; do not start a fresh copy each year, because an auditor asks to see the history.

Working Tools — how it gets done

A separate short document, plus 3 Word files and a calendar file. None of it adds an obligation; it is the same content arranged for the moment you need it rather than for an auditor.

Taking on a new customer Seven steps: when due diligence falls due for each type of transaction, what to collect for an individual, a company, an overseas company or a trust, how to verify, how to rate, and when to escalate.
Red flags — desk card The indicators from your risk assessment on one page. Print it and keep it where you take calls.
Annual training refresher A page to work through and sign. Each person signs their own; attendance alone is not evidence of understanding.
Registering for goAML The steps, in order, with the link. Do it before you need it — a report falls due within 3 working days of forming a suspicion.
CDD Request Letter (Word) What you send a customer asking for identity and ownership documents. Written to be sendable as it is.
Beneficial Ownership Declaration (Word) The form a director signs naming everyone over 25%. This is what a low-risk customer’s ownership is established on where no public register can answer it.
Compliance Officer Designation (Word) The letter designating your AML/CFT compliance officer under s.56, with an acceptance for them to sign. Keep both halves with the approved documents.
Calendar file (.ics) Double-click it. Your dates go into your own calendar with reminders — the review, the period end, the login check, the filing window opening and closing, training, and the FATF check.

0.4The dates that matter

When What
1 July 2026 – 31 August 2026 This year’s annual report window. OPEN NOW — the Department grants no extensions.
30 June each year Reporting period ends. Freeze the year’s figures.
By 30 June 2027, then before 30 June each year Internal review of the risk assessment and programme. Section 59(1) says at least annually and sets no date; finishing before 30 June means every reporting year contains a review and each report you file describes documents you have just been through.
At least yearly AML/CFT training (s.57(1)(b)).
Every 3 years from your last audit report Independent audit (s.59(2)). You have never been audited, so no clock is running yet — but the Department’s position is to audit earlier rather than later.
Before using any new product, service or channel Update the risk assessment first (reg 13E).

0.5What to do next

  1. Read the risk assessment and the programme. Change anything that does not match how you actually work, and tell us what you changed.
  2. Approve them. They take effect on the date you approve them, and that date is what goes in your records.
  3. Log in to AML Online and type in this year’s answers, reading down the list at the end of this note. Each one is set out in full, with the question and the basis for the answer, in your Annual AML/CFT Report.
  4. File before the window closes.
  5. Open the workbook and keep it open. Your customers are already in it; everything the programme commits you to record has a tab waiting for it.

0.6Still needed from you

1 item — listed in full where it belongs in the documents:

  • Annual report 6.1 (Part 2) — Does your programme meet s.57 — Meets all / Meets some / Meets none

What is on your list now is compliance work rather than paperwork for us: 5 actions, set out in full under Things to do below. The customer ones also sit in the CDD Register tab of your workbook, and the dated ones on the Compliance Officer Checklist, as notes you delete once they are done — so the workbook always shows what is genuinely left.


0.7Things to do

In order. The first two are what make the documents yours; the rest is the catch-up work the programme now commits the business to.

1. Read the risk assessment and the programme

Change anything that does not match how the business actually works. They are yours to amend before you adopt them.

2. Approve them, and date the approval

Sign the version table at the end of the programme. That date is when they take effect, and it is the date an auditor will ask for.

3. File the annual report by 31 August 2026

Type the answers into AML Online from the list at the end of this note.

4. Book the first independent audit

Deplexify prepared these documents and so cannot audit them (s.59B(3)). No statutory deadline applies to a first audit, but the Department’s position is to audit earlier rather than later.

5. Diary the next internal review to complete by 30 June 2027

Section 59(1) requires a review of both documents at least annually. The date is set to 30 June — the last day of the reporting period — so the report filed from 1 July covers a year that contains a review, and describes documents just reviewed. Mere Kingi owns it, and it is already listed on the Compliance Officer Checklist tab of the workbook.


0.8Filing the report — how it works

Window 1 July 2026 to 31 August 2026 — OPEN NOW
Where AML Online, https://aml.dia.govt.nz/
Login Your RealMe login with two-factor authentication. A verified RealMe identity is no longer required.
Extensions None. The Department: “The Department is unable to grant any extensions.”
Stuck amlcft@dia.govt.nz, or 0800 257 887 — before the deadline, not after.

Three things worth knowing before you start.

There is no way to amend a report once it is filed. The Department publishes no procedure for correcting or resubmitting one — the User Guide, the AML Online page and the FAQ are all silent on it. So do not file an answer you are unsure of on the assumption it can be fixed later. Email them before the window closes instead.

The screen will say five parts; your report says six. The Department’s web page describes the form as five parts, while Schedule 2A and the User Guide use six. The substance is identical — the web page is describing the portal’s own labelling.

goAML is a separate system and you are not registered. It is where suspicious activity reports and prescribed transaction reports go. It is not needed for the annual report, but it is better to have it before you need it than to discover the gap when something arises.


0.9Filling in the annual report — the short version

The report is filed by typing answers into AML Online; nothing is uploaded. Every answer is below in full, in the order the form asks for them, so you can read straight down while you type. The question each one answers, and the working behind it, are in your Annual AML/CFT Report.

Item Answer
1.1 1 July 2025 to 30 June 2026
2.1 Southern Cross Property Group Limited · Company · 9429030000000 · SX Property
2.2 Level 6, 88 The Terrace, Wellington 6011
2.3 PO Box 5521, Wellington 6140
2.4 Mere Kingi · mere@sxproperty.co.nz · 04 555 0180 · www.sxproperty.co.nz
2.5 real estate agent
3.1 No
3.2 New Zealand
3.3 34
3.4 Three offices — Wellington CBD, Lower Hutt, Porirua
3.5 None
3.6 None
3.7 None
4.1 No
4.2 Not applicable — not a DBG member
5.1 Meets some — the existing risk assessment predates s.58(3)(ba) and does not incorporate the SRA 2026 or the NRA 2024.
5.2 See 5.1 — s.58(3)(ba) until the NRA 2024 incorporation is completed.
5.3 1 June 2025
5.4 Yes
5.5 15 September 2024
5.6 Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally.
5.7 Not yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established.
5.8 No
6.1 Needed from you
6.2 Reported at engagement as partly compliant. The written programme covers vetting, training, CDD and record keeping but has no documented procedures for s.57(1)(g) written findings, s.57(1)(h) higher-risk countries, or s.57(1)(j) enhanced due diligence triggers.
6.3 1 June 2025
6.4 Yes
6.5 15 September 2024
6.6 Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally.
6.7 Not yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established.
6.8 Yes — s.57(1)(c) of the AML/CFT Programme addresses all three.
6.9 Yes — s.57(1)(c) of the AML/CFT Programme: where CDD cannot be completed the business does not establish or continue the relationship or carry out the transaction, and the compliance officer considers whether a SAR is required. The programme follows the Identity Verification Code of Practice 2026, which commenced on 1 July 2026. Schedule 2A and the Department’s FAQ still cite the Amended Identity Verification Code of Practice 2013 by name; the answer is the same either way.
6.10 No — all customer due diligence is conducted by the agency itself
6.11 No
7.1 Not applicable — the agency does not form companies, trusts, partnerships or charities
7.2 No nominee director, nominee shareholder or trustee roles held
7.3 Not applicable — no registered office or address services provided
7.4 Yes — $10m–$49.99m
7.5 Yes
7.6 REAA transactions (real estate agency work to bring about a transaction)
7.7 $50m+
7.8 Optional under Schedule 2A — leave blank unless the business carries on one of the listed financial activities (deposit-taking through to life insurance). No answer is required of a real estate agency that does not.
7.9 No
7.10 No · 0 · Residential property sales; commercial property sales; property management
8.1 366
8.2 PEPs (including PEP-owned or PEP-controlled): 1 · Trusts or other personal-asset-holding vehicles: 25 · Overseas government bodies: 0 · NZ resident individuals: 300 · NZ resident entities: 0 · Non-resident individuals: 40 · Non-resident entities: 0
8.3 Face-to-face: 1 (most common) · Non face-to-face: 2 · Overseas intermediaries: 3 · Domestic intermediaries: 4 · Other: 5 (not used)
9.1 No
9.2 Not applicable
9.3 Yes
9.4 No
9.5 Not applicable
9.6 Unknown
9.7 No
9.8 No
9.9 Yes — two overseas buyer’s agents introduced purchasers during the period
9.10 Singapore; China
9.11 No cash received as part of a real estate transaction during the period
9.12 Yes — residential property sales and services
9.13 Yes — commercial property sales and services. Estimated split: 70% residential, 30% commercial
10.1 No
10.2 Not applicable — no ministerial exemption held

Prepared for Southern Cross Property Group Limited
Prepared 4 August 2026
Prepared by Deplexify
AML/CFT supervisor Department of Internal Affairs
Compliance officer Mere Kingi

1Money Laundering and Terrorism Financing Risk Assessment

Southern Cross Property Group Limited

Prepared under section 58 of the AML/CFT Act 2009 — real estate agency

DocumentAML/CFT Risk Assessment
Version1.0
Prepared4 August 2026
SectorReal estate agency
AML/CFT compliance officerMere Kingi
Next internal review due30 June 2027 — the review completes before 30 June each year, so the annual report is filed on freshly reviewed documents (s.59(1): at least annually)
SupervisorDepartment of Internal Affairs (sole AML/CFT supervisor from 1 July 2026)

1.1Purpose and statutory basis

Section 58(1) requires that, before conducting customer due diligence or establishing an AML/CFT programme, a reporting entity must first undertake an assessment of the risk of money laundering and the financing of terrorism that it may reasonably expect to face in the course of its business.

That ordering matters and is not a formality. The programme has to be based on this assessment (s.57(1)), so a control that does not answer a risk identified here has nothing holding it up. This document is therefore the foundation of the whole compliance framework, and it is the document DIA looks at first.

Section 58(3) requires the assessment to be in writing and to do four things. Each has its own section below, so an auditor can find them:

  • s.58(3)(a) — Identify the risks faced in the course of business.
  • s.58(3)(b) — Describe how the entity will ensure the risk assessment remains current.
  • s.58(3)(ba) — Incorporate all relevant risks identified by any risk assessments produced under sections 131 and 142.
  • s.58(3)(c) — Enable the entity to determine the level of risk involved in relation to its obligations under the Act, regulations and rules.

s.58(3)(ba) is new. It was inserted on 19 May 2026 by s.15 of the AML/CFT Amendment Act 2026. Any risk assessment written before mid-2026 that does not incorporate the relevant risks from the SRA 2026 and the NRA 2024 is non-compliant on its face, however good it was when it was written. Section 8 of this document exists specifically to satisfy it.


1.2Section 1 — Nature, size and complexity of the business

s.58(2)(a)

Legal nameSouthern Cross Property Group Limited
Entity typeCompany
Registration / NZBN9429030000000
Trading namesSX Property
Principal place of businessLevel 6, 88 The Terrace, Wellington 6011
Staff34
New Zealand officesThree offices — Wellington CBD, Lower Hutt, Porirua
New Zealand subsidiariesNone
Overseas officesNone
Overseas subsidiariesNone
Overseas parentNo
Country of largest beneficial ownerNew Zealand
Designated Business Group memberNo

What this means for risk. A three-office agency across the Wellington region with 34 staff, split between residential and commercial sales teams. A central compliance function sits in the Wellington office under the Head of Risk and Compliance, who reports to the Chief Executive. Deposits are received into a single agency trust account administered centrally. Because salespeople work across three sites, the compliance officer cannot personally review every transaction and relies on escalation and file sampling.

At this size the compliance officer cannot personally see every transaction, so the controls in the programme rely on sampling, escalation routes and training rather than direct oversight. That is a deliberate design choice and the sampling rates are stated in the programme so they can be audited.

Complexity. The business does not operate through a Designated Business Group, so it is responsible for its own risk assessment, programme and annual report in full.


1.3Section 2 — Products and services

s.58(2)(b)

Residential and commercial property sales across the Wellington region, carried out as licensed real estate agency work to bring about transactions. The agency operates a trust account into which sale deposits are received. It also runs a property management portfolio, whose regulatory scope is an open question recorded in the gap analysis.

Services the SRA 2026 requires this business to assess

A real estate agent that carries out one or more of the following services must incorporate assessment of the risks associated with the service in its risk assessment: Money laundering: Sale and purchase of land and/or property; Trust accounts.

— Real Estate Agent Sector Risk Assessment 2026, published 22 June 2026

This is not advisory. Section 58(3)(ba) requires the relevant risks from a sector risk assessment produced under s.131 to be incorporated, and DIA's Risk Assessment Guidance puts it plainly: "The Department's latest SRAs identify those services provided in the sector that are assessed as most vulnerable… Any reporting entity in the sector that provides these services must incorporate an assessment of them in its risk assessment."

ServiceProvided?Sector vulnerabilityAssessed below
Sale and purchase of land and/or property (mandatory)YesMedium-HighSR01
Trust accounts / managing client funds (mandatory)YesMedium-HighSR02
Commercial leasingNoLow-MediumSR03

SR01 — Sale and purchase of land and/or property

The SRA 2026 names this a service that must be assessed.

This is the agency's core regulated service and the one the SRA rates most vulnerable alongside trust accounts. Property is a durable, high-value store of value that launders a large sum in a single transaction, and the agency sits at the point where buyer, seller, funds and title meet. The vulnerability is structural rather than a reflection on any individual agency.

Why the risk arises here:

  • A single transaction can absorb a very large sum without appearing unusual for the asset class.
  • The agency's customer is normally the vendor, so the purchaser — whose funds are settling — is the party the agency knows least about.
  • A purchaser may nominate a different person to complete the sale, changing who ultimately acquires the property after the agency's due diligence is done.
  • Value is negotiable, so a sale materially above or below market can move value between parties without an obvious paper trail.
RatingBasis
Inherent riskMedium-HighAs rated for this service in the SRA 2026.
Proposed residual riskMediumProposed on the basis that the controls in the AML/CFT programme are implemented and operating. Not proposed below the sector residual risk of Medium, because claiming stronger-than-sector controls is a claim this business would have to evidence to an auditor.

Compliance officer to confirm: is the proposed residual rating right for this business? If the controls are not yet operating, the residual rating is the same as the inherent rating until they are.


SR02 — Trust accounts / managing client funds

The SRA 2026 names this a service that must be assessed.

Where the agency holds a deposit — or where a third-party trust account is used — it is handling the money itself rather than merely introducing the parties. The SRA is explicit that this is where the sector's risk is most direct, because the account can be used to give funds an appearance of legitimacy or to route them onward to a party who was never disclosed.

When a real estate agent receives funds in a trust account or when a third-party trust account is used, the money laundering risk is at its most direct.

— Real Estate Agent Sector Risk Assessment 2026

Why the risk arises here:

  • Receipts materially larger than the transaction requires, followed by a direction to pay the surplus onward.
  • A transaction that is aborted after funds are received, with a refund directed to a third party or a different account.
  • Deposits paid in cash, or paid in structured instalments that individually attract less attention.
  • Payment from, or refund to, a person who is not a party to the agreement.
RatingBasis
Inherent riskMedium-HighAs rated for this service in the SRA 2026.
Proposed residual riskMediumProposed on the basis that the controls in the AML/CFT programme are implemented and operating. Not proposed below the sector residual risk of Medium, because claiming stronger-than-sector controls is a claim this business would have to evidence to an auditor.

Compliance officer to confirm: is the proposed residual rating right for this business? If the controls are not yet operating, the residual rating is the same as the inherent rating until they are.


SR03 — Commercial leasing

Not provided by this business. Recorded as assessed and not applicable rather than omitted, so that an auditor can see the question was asked and answered. If the business begins providing this service, this assessment must be updated before it does so.


1.4Section 3 — Delivery channels

s.58(2)(c)

How customers reach the business determines how much of the customer the business can actually see. A customer met in person, whose identity documents are handled directly, presents a different risk from one onboarded entirely through a screen.

ChannelRanking / useRisk note
Face To Face1 (most common)Lowest channel risk — identity documents seen directly and behaviour observed.
Non Face To Face2Higher channel risk. Identity is verified remotely, so the verification method itself becomes a control that must be recorded.
Overseas Intermediaries3Highest channel risk of the four — distance, different regulatory standards, and limited ability to verify what the intermediary actually did.
Nz Intermediaries4Risk depends on the intermediary's own standards. Where the business relies on another party's due diligence, s.57(1)(k) applies.
Other5 (not used)

Technology and new channels. Regulation 13E of the AML/CFT (Requirements and Compliance) Regulations 2011 requires that where a reporting entity introduces new or developing technologies or new or developing products — including any new delivery mechanism — the risk assessment must be updated prior to their use. Section 11 sets out how that is done.


1.5Section 4 — Customer types

s.58(2)(d)

Customer categoryNumber this yearRisk weighting
PEPs (including PEP-owned or PEP-controlled)1Higher — enhanced due diligence always required.
Trusts or other personal-asset-holding vehicles25Higher — beneficial ownership is not apparent from the front of the structure.
Overseas government bodies0Higher — additional scrutiny of authority and source of funds.
NZ resident individuals300Baseline.
NZ resident entities0Baseline, rising with structural complexity.
Non-resident individuals40Higher — identity verification and source of funds are harder to establish.
Non-resident entities0Higher — combines non-residence with structural opacity.
Total customers366

Customer features this sector treats as higher risk:

  • Politically exposed persons, and customers beneficially owned or controlled by a PEP.
  • Trusts and other personal asset-holding vehicles, where the beneficial owner is not apparent from the front of the structure.
  • Companies with layered or overseas ownership, where identifying the beneficial owner takes more than a companies register search.
  • Non-resident purchasers and vendors, and customers whose funds originate overseas.
  • Customers introduced entirely remotely, with no face-to-face contact at any stage.
  • Cash-intensive businesses purchasing property, where the source of funds is the business's takings.

Where a customer has one of these features it is weighed in the customer's risk rating. Where the feature is one of the s.22 triggers, or the rating comes out High, enhanced customer due diligence follows — see s.57(1)(j) in the programme, which lists the mandatory triggers separately from the features that raise a rating. DIA names failure to apply enhanced due diligence where the risk requires it as a common sector deficiency, which is why the triggers are listed rather than left to judgement in the moment.


1.6Section 5 — Countries

s.58(2)(e)

Countries the business deals with, through customers, payments or structures: New Zealand; Singapore; China

Companies or trusts formed outside New Zealand: No — so no formation jurisdictions arise.

Funds sent or received internationally: No. Banded value: 0

Country risk is assessed using DIA's Assessing Country Risk Guidance together with the current FATF listings. Where a relationship or transaction involves a country with insufficient AML/CFT systems, the additional measures in s.57(1)(h) of the programme apply and a written finding is kept.


1.7Section 6 — Institutions

s.58(2)(f)

Banks and financial institutions the business deals with: BNZ (agency trust account and operating account). Purchaser funds arrive through the purchaser's conveyancing solicitor's trust account, and in some overseas-introduced transactions from offshore bank accounts.

New Zealand registered banks are themselves reporting entities with their own AML/CFT obligations, which reduces — but does not remove — the risk carried by funds arriving through them. Funds arriving from institutions outside that supervised perimeter carry more risk and are assessed under Section 5.


1.8Section 7 — Supervisor guidance and rules

s.58(2)(g) and (h)

In preparing this assessment, regard has been had to the DIA guidance listed under Sources at the end of this document, in particular the Risk Assessment Guidance (July 2026) and the Real Estate Agent Sector Risk Assessment 2026.

Watch item. Paragraphs (g) and (h) were amended on 1 July 2026 so that additional factors are prescribed by rules made under s.156B rather than by regulations. If DIA issues s.156B rules adding risk assessment factors, they take effect without the Act's text visibly changing. This is re-checked at each annual review.


1.9Section 8 — Incorporation of the SRA 2026 and NRA 2024

s.58(3)(ba) — mandatory since 19 May 2026

Section 58(3)(ba) requires this assessment to incorporate all relevant risks identified by risk assessments produced under ss.131 and 142 of the Act. In practice that means two documents: the Sector Risk Assessment produced by the Department under s.131, and the National Risk Assessment produced by the Financial Intelligence Unit under s.142.

Real Estate Agent Sector Risk Assessment 2026

Published 22 June 2026. Current. This is the sector risk assessment produced by the Department under s.131 of the Act, and s.58(3)(ba) makes incorporating its relevant risks mandatory.

Sector ratingLevel
Inherent money laundering vulnerabilityMedium-High
Terrorism financing vulnerabilityLow
Proliferation financing vulnerabilityLow
Strength of controlsModerate
Residual money laundering riskMedium

Sector population: 925 known real estate agent reporting entities in New Zealand.

Mandatory services — assessed in Section 2 above:

  • Sale and purchase of land and/or property
  • Trust accounts

The deficiency DIA names in this sector:

There are common deficiencies relating to requirements to monitor, examine and keep written findings for high-risk clients, activities, or transactions, and to conduct enhanced customer due diligence in all situations where the level of risk requires it.

DIA says it sees this across many DNFBPs, not only real estate. It maps directly onto s.57(1)(g) and s.57(1)(j), which is why those two sections of the programme are written in more operational detail than the others.

Structural gap in this sector:

Customer due diligence obligations usually attach to the agency's client — the vendor — and not to the purchaser, who may in turn nominate a different person to complete the sale. The agency therefore has the least information about the party whose funds are actually settling the transaction.

suspicious activity reporting obligations do not just apply in respect of an agent's client, but also to any counterparty.

Sector reporting rates. Between 1 January 2019 and 31 December 2025 the sector produced 709 suspicious activity reports (about 9% of agents filed at least one) and 747 prescribed transaction reports (about 6%).

DIA publishes these figures in the SRA itself, which shows it is watching sector-wide reporting volumes. An agency that has never filed a SAR is not thereby non-compliant, but it should be able to explain why.

New Zealand National Risk Assessment 2024 on Money Laundering, Terrorism Financing and Proliferation Financing

Produced by the New Zealand Police Financial Intelligence Unit. Produced under s.142 of the Act. s.58(3)(ba) makes incorporating its relevant risks mandatory for every reporting entity in every sector. Released 17 March 2025. The first update since the 2019 NRA.

Extracted from the primary PDF (96 pages, 13.7 MB), downloaded from police.govt.nz and read directly. Page numbers below are the NRA's own printed page numbers. No secondary summary was used.

The NRA identifies fraud-related crime, drug crime and transnational money laundering as currently exposing New Zealand's AML/CFT system to the highest threat (Foreword; Chapter 1).

The sector, as the FIU measures it:

Reporting entities923 active reporting entities in the real estate sector (p.46, and Table 2 p.12).
Gross transaction value$17,564,000,000 self-reported gross value of transactions for 2022–2023 (Table 2, p.12).
Money movement per $1m of banking$297.91 per $1 million transacted through the banking sector (Table 2, p.12).
SupervisorDIA (Table 2, p.12).

The NRA 2024 counts 923 reporting entities; the SRA 2026 counts 925. The figures are eighteen months apart and are not in conflict — cite whichever document is being quoted rather than reconciling them.

The 11 NRA 2024 findings relevant to this business

Section 58(3)(ba) requires the relevant risks to be incorporated, not merely acknowledged. Each finding below is therefore given with the FIU's own words, the page it comes from, what it means for this business specifically, and where in this pack it is addressed. A finding with no corresponding control is an incorporation that has not happened.

NRA01 — Real estate agents are named among the sectors identified as being misused by criminals to launder proceeds of crime

Trust and company service providers (TCSPs), lawyers, real estate agents, high-value dealers, NBDTs and casinos were all identified as being misused by criminals to launder proceeds of crime.

— NRA 2024, p.11 (Executive Summary — Sectoral vulnerabilities in New Zealand)

What it means here. The sector is not merely theoretically exposed. The FIU places it in the group of sectors it has evidence of criminals actually using. An agency cannot treat its ML risk as hypothetical.

Addressed in. Risk Assessment Section 2 (service-level risk); AML/CFT Programme s.57(1)(f)

NRA02 — The sector's risk level is unchanged since the 2019 NRA

Real estate, law firms, accountancy firms and high-value dealers all feature in investigations and therefore the level of risk remains unchanged.

— NRA 2024, p.17 (Key changes from last NRA — UNCHANGED RISK)

What it means here. Five years of AML/CFT supervision has not moved the sector's risk. Controls that merely match what the sector was already doing in 2019 are, on the FIU's own evidence, not enough to shift the position.

Addressed in. Risk Assessment Section 8; AML/CFT Programme s.57(1)(l) monitoring

NRA03 — Customer due diligence reaches the vendor, but reporting obligations reach both parties

In the real estate sector, CDD obligations generally extend only to the vendor (the seller) not the purchaser. However, reporting obligations apply in relation to either party.

— NRA 2024, p.46 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. This is the sector's defining structural gap, and the FIU states it independently of the SRA 2026. The agency knows least about the party whose funds settle the transaction, yet must still report suspicion about them.

Addressed in. AML/CFT Programme s.57(1)(c) and s.57(1)(d)

NRA04 — Suspicious activity reporting obligations apply to purchasers as well as vendors, even where the conduct sits outside the agent's normal view

Although CDD obligations generally only involve establishing the identity and monitoring transactions of the seller, and some of the described activities may be outside of the purview of real estate professionals, suspicious activity reporting obligations still apply in relation to both the vendors and purchasers of real estate.

— NRA 2024, p.46 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. 'The agency did not act for the purchaser' is not an answer to a reporting obligation. Staff must be trained to escalate what they observe about a purchaser, not only about the client.

Addressed in. AML/CFT Programme s.57(1)(b) training and s.57(1)(d) reporting

NRA05 — How real estate is actually used to launder money — the FIU's named methods

Real estate as a property type can be used for money laundering, primarily during layering and integration of the proceeds of crime. This includes renovating with illicit cash; repaying mortgage debt with illicit cash; manipulating purchase price between a complicit vendor and purchaser; and using legal structures to conceal beneficial ownership. Nominee ownership may also occur to navigate foreign buyer rules.

— NRA 2024, p.46 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. These five methods are the sector's primary-source red flags. Price manipulation between a complicit vendor and purchaser, and nominee ownership used to navigate foreign buyer rules, are both visible to an agency in a way they are not visible to a bank.

Addressed in. Risk Assessment Section 9 (indicators); AML/CFT Programme s.57(1)(g) written findings

NRA06 — The sector under-reports relative to its transaction volume

Real Estate Institute data identifies that 63,361 residential properties were sold in 2023. This was a slight increase on 2022. In contrast to these sale volumes, sector reporting averages 100 SARs per year. This indicates an opportunity to improve the number and quality of SAR from this sector.

— NRA 2024, p.47 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. The FIU has said in terms that it wants more, and better, suspicious activity reports from this sector. An agency with no SARs is not thereby non-compliant, but it should be able to show that the question was considered and the reasoning recorded.

Addressed in. AML/CFT Programme s.57(1)(d) — including the requirement to record a decision NOT to report

NRA07 — Only about a tenth of the sector has ever filed a suspicious activity report

Slightly more than 10% of the sector has reported a SAR. 25% were sampled and reviewed. The most common reason for reporting was the vendor's avoidance to complete CDD/EDD. The second most common reason was concern that the property was purchased and sold within a short timeframe.

— NRA 2024, p.46 and Table 10, p.46 — 555 SARs from 107 real estate agencies, 1 January 2018 to 31 December 2023

What it means here. The two most common reporting triggers are both things an agency sees directly: a vendor dodging due diligence, and a fast resale. Both belong in staff training as the first things to escalate.

Addressed in. Risk Assessment Section 9; AML/CFT Programme s.57(1)(b) and s.57(1)(g)

NRA08 — CDD timing is a named compliance failure in this sector, and enforcement has followed

Non-compliance has been identified in more complex AML/CFT obligations such as the exact timing of when verification must be completed. In these instances, entities were requested to remediate issues. Between January 2018 and December 2023, there were five enforcement actions undertaken in the real estate sector related to deficiencies in AML programmes. Five formal warnings were given: three public and two non-publicised.

— NRA 2024, p.47 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. Doing the right due diligence at the wrong time is itself a breach the regulator has acted on. This is why the programme fixes the completion point against reg 16 by transaction type — before the lease agreement is presented to the landlord on a commercial lease, and on a fully signed agency agreement for a sale — rather than leaving it at 'before settlement'.

Addressed in. AML/CFT Programme s.57(1)(c) — timing is stated explicitly

NRA09 — Real estate is the third most commonly restrained asset in New Zealand

Between January 2018 and December 2023, real estate was the third most commonly restrained asset in New Zealand (after cash and vehicles). During this time, Police restrained 339 residential properties; the total restrained properties (when including commercial property, farms/orchards, and lifestyle blocks) was 418.

— NRA 2024, p.46 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. Residential property — the core of most agencies' business — accounts for the large majority of restrained property. The risk sits in ordinary residential work, not in exotic transactions.

Addressed in. Risk Assessment Section 2, SR01

NRA10 — The specific criminal threats that reach property, from FIU investigations

Drug offenders integrated their criminal proceeds into property. They also renovated properties by using illicitly obtained cash. Drug offenders also used criminal proceeds to service mortgages. Drug offenders placed properties into the names of relatives and associates when purchasing property, presumably to conceal and disguise their beneficial ownership. […] Tax offenders integrated proceeds of their offending into property in New Zealand; property had been bought and sold – with multiple purchases on the same day. […] Individuals involved in international money laundering integrated the proceeds of global frauds into real estate that included land and residential property. To facilitate such purchases, funds were transferred from offshore bank accounts into trust accounts of lawyers in New Zealand.

— NRA 2024, p.47 (Chapter 3 — Vulnerabilities: Real estate agents, 'Threats'). The NRA notes real estate purchases feature across almost half the threats profiled for this NRA.

What it means here. Three concrete patterns for staff to recognise: property bought in the name of a relative or associate; multiple purchases on the same day, or rapid buy-and-sell; and purchase funds arriving from an offshore bank account through a New Zealand lawyer's trust account.

Addressed in. Risk Assessment Section 9; AML/CFT Programme s.57(1)(g) and s.57(1)(h)

NRA11 — Lawyers' property SARs show purchasers refusing to evidence source of wealth

44% of SARs reported by lawyers relate to property transactions where individuals want to purchase real estate without providing source of wealth documentation, reflecting that the legal sector is also a critical gatekeeper for the purchaser.

— NRA 2024, p.46 (Chapter 3 — Vulnerabilities: Real estate agents)

What it means here. The behaviour the conveyancer eventually reports usually starts at the agency. A purchaser evasive about the source of their money is an indicator the agency sees first, even though the agency does not hold the CDD obligation for them.

Addressed in. AML/CFT Programme s.57(1)(d) counterparty reporting; s.57(1)(j) enhanced due diligence triggers

A scope finding that may affect what this assessment has to cover

While the buying of property for rental purposes is subject to AML/CFT regulation, the subsequent renting or leasing activities fall outside the regulations' scope and provide a potential regulatory and awareness gap for the DPRK to exploit.

— NRA 2024, p.92 (Chapter 6 — Proliferation Financing, 'International research – typologies')

The agency's property management and residential rentals work sits outside the AML/CFT Act, and this assessment records why. The Act captures a real estate agent for 'real estate agency work' as defined in the Real Estate Agents Act 2008 — that is, work done to bring about a 'transaction'. Section 4(1) of that Act defines a transaction to exclude 'a tenancy to which the Residential Tenancies Act 1986 applies'. Arranging a residential tenancy is therefore not real estate agency work for these purposes. Separately, once a property is leased, ongoing property management is excluded by regulation 21B of the AML/CFT (Definitions) Regulations 2011, and rent collected as part of that management does not trigger obligations. Commercial lease listings are a different matter and are captured. One thing to watch: a long leasehold interest that is not a Residential Tenancies Act tenancy — a ground lease, for example — remains a captured transaction.

The National Risk Assessment 2024 presents its sector ratings in Table 1 (p.11) as a colour-shaded matrix with no rating words printed, so no NRA rating level is quoted for this sector anywhere in this assessment — there is none to quote. What the table and the surrounding text do support is recorded instead: real estate agents appear among the sectors considered most vulnerable in New Zealand; the sector sits below banking, remittance and virtual-asset providers on inherent risk, alongside the other professional sectors; its strength-of-control-measures shading is comparatively light; and its risk level is unchanged since 2019 (p.17). Named rating language in this assessment is taken from the Sector Risk Assessment 2026, which does print it.


1.10Section 9 — Risk indicators and red flags

s.58(3)(a) — identifying the risks faced

These are the behaviours that, in this sector, indicate the risks assessed above may be materialising. They are the working content of staff training, and an indicator seen and examined produces a written finding under s.57(1)(g) whether or not it results in a suspicious activity report.

The indicators below are the ones that bear on the services this business actually provides. A further 1 group of published indicators covers real estate services this business does not provide, and is not reproduced here; if the business starts one of those services, this assessment is updated before it does so.

Real estate transaction red flags (sale and purchase)

Source: Department of Internal Affairs, Real Estate Agent Sector Risk Assessment 2026 (published 22 June 2026), pp.28–29 — 'Red flags for real estate transactions (sale and purchase) include'.

  • Transfer of real estate between parties in an unusually short time period.
  • The vendor and purchaser are known to each other or connected in some way without explanation.
  • There are unexplained changes in instructions, such as just before a settlement.
  • Client appears to be acting on somebody else's instructions without disclosing the identity of that person.
  • Property 'flipping' with back-to-back property transactions with rapidly increasing value and/or sales to related parties.
  • Client has unexplained wealth that appears inconsistent with their socio-economic profile.
  • A 'sight unseen' property purchase where the purchaser has not seen the property in person without a logical explanation.
  • Client is buying or selling property from overseas without a logical explanation – for example, they have dealings in New Zealand but no indication of being in New Zealand or intention to come to New Zealand.
  • Funding is provided by or to be repaid to a lender other than a bank or credit institution without logical explanation or economic justification.

Reproduced verbatim from the sector's own risk assessment. These are the indicators DIA expects a real estate agent to be trained on and to act upon.

Additional red flags specific to vendors

Source: Department of Internal Affairs, Real Estate Agent Sector Risk Assessment 2026 (published 22 June 2026), p.29 — 'Additional red flags specific to vendors'.

  • Client is willing to accept offer well below current market prices and/or appears disinterested in obtaining a better price.
  • Property is unencumbered, without explanation for this (including where a mortgage has been paid off rapidly).
  • Property is re-sold after significant renovation (without evidence of source of funding of the renovation project).

The vendor is usually the agent's customer, so these sit closest to the customer due diligence the business actually performs.

Additional red flags specific to purchasers

Source: Department of Internal Affairs, Real Estate Agent Sector Risk Assessment 2026 (published 22 June 2026), p.29 — 'Additional red flags specific to purchasers'.

  • Payments of deposits or funds from unknown third parties.
  • Purchaser offers to pay real estate agent an unusually large deposit (or settlement payment) that is not necessary to secure the purchase.
  • The property being purchased is inconsistent with the socio-economic profile of the purchaser, including if the purchase appears to involve a disproportionate amount of private funding.
  • Use of nominees or complex structures for purchase of property.

A purchaser is not normally the agent's customer and so is not normally subject to customer due diligence, but these behaviours are still reportable under s.40 and still require a written finding under s.57(1)(g) when seen.

Additional red flags for sale of commercial property or a business

Source: Department of Internal Affairs, Real Estate Agent Sector Risk Assessment 2026 (published 22 June 2026), p.29 — 'Additional red flags for sale of commercial property or a business'.

  • Illegal activity being conducted (or suspected) on premises.
  • Appearance of manipulation of the appraisal or valuation of the commercial property or business.
  • Purchase and use of commercial property inconsistent with business purpose.
  • Suspicious behaviour of potential purchaser when shown property or business, including evasive when asked questions around intended use.
  • Use of complex loan structures or credit finance (such as loan back schemes).
  • Other gatekeepers or unknown persons appear to have full control of activity.

Commercial prices are high and financing is often layered across multiple streams, which conceals the true source of funds; and because commercial property is usually held by a legal person or arrangement, beneficial ownership is easier to hide (paras 108–109).

Trust account red flags

Source: Department of Internal Affairs, Real Estate Agent Sector Risk Assessment 2026 (published 22 June 2026), pp.33–34 — 'Red flags for trust accounts include'.

  • Funds received into trust account are not expected or more than expected (for example an overpayment of a deposit), with subsequent directions for their use or payment.
  • Funds paid into a trust account by a third party on behalf of the purchaser/non-client without legitimate explanation.
  • Payments into a trust account by cash deposit (at the real estate agent or third-party trust account provider's bank).
  • Unexplained or late changes in payment arrangements.
  • Requests to hold funds in a trust account for a longer time than is required by the conditions of the sale, with further instructions received subsequently.
  • Transaction occurs through a trust account of another gatekeeper in circumstances that are not expected.
  • Use of trust account for transactions that are more appropriately conducted directly from a client's bank account.
  • Funds received from or sent to high-risk countries, or other countries where there is no apparent connection to the client.

The SRA 2026 replaces the law firm trust account list previously carried here — this one is written for real estate trust accounts specifically. DIA singles out overpayment by a non-client as a known money laundering typology warranting enhanced customer due diligence.

Behavioural red flags

Source: Department of Internal Affairs, Real Estate Agent Sector Risk Assessment 2026 (published 22 June 2026), p.53 — 'Behavioural red flags by clients include'.

  • Client is involved in a type of business not normally cash intensive but appear to have substantial amounts of cash.
  • Client whose instructions are unusual and/or with no apparent visible or economic purpose.
  • Client who appears to avoid face-to-face meetings.
  • Client is reluctant to provide identification or behaves nervously.
  • Client who appears to be acting on somebody else's instructions without disclosing the identity of that person.
  • Client asks for shortcuts or unexplained speed in completing a transaction or activity.
  • Identity or other verification documents provided are or look fraudulent.
  • Client enquiring into whether a service would be considered suspicious or require reporting to authorities.
  • An absence of documentation to support the client's stated reason for engaging the real estate agent, their previous transactions, or business activities.
  • Client who offers to pay extraordinary fees for services that would not warrant such a premium.
  • Client using a small or non-specialised real estate agent to provide specialised real estate agency work (for example commercial property or sale of a business).

These apply to every service and are not tied to a transaction type: DIA's position is that staying alert to behaviour, even where no other higher-risk indicator is present, is a key part of running an effective programme (para 192). Two related warnings sit alongside them. A client who is a friend, a family member or a referral from a trusted associate does not become low risk by being known — assumptions must be challenged and verification from reliable and independent sources still applies (paras 193–194). And an employee who knows how the programme works can bypass or manipulate it, which DIA calls the insider threat (para 195).

Indicators the FIU has evidence of in this sector

Source: New Zealand Police Financial Intelligence Unit, National Risk Assessment 2024, pp.46–47 (Chapter 3 — Vulnerabilities: Real estate agents).

  • A vendor avoiding or delaying customer due diligence, or declining to complete enhanced due diligence. This was the single most common reason real estate agencies filed a suspicious activity report (NRA 2024, p.46).
  • A property purchased and sold again within a short timeframe. The second most common reporting trigger (p.46), and separately observed in tax-offender investigations as 'multiple purchases on the same day' (p.47).
  • The purchase price appears manipulated between a vendor and purchaser who are acting in concert (p.46).
  • A legal structure — company, trust or nominee — used in a way that conceals who ultimately benefits, including nominee ownership used to navigate foreign buyer rules (p.46).
  • Property being bought in the name of a relative or associate of the person actually providing the funds (p.47, drug-offender investigations).
  • Purchase funds arriving from an offshore bank account, routed through a New Zealand lawyer's trust account (p.47, international money laundering investigations).
  • Renovation, or mortgage servicing, apparently funded with cash (p.46, p.47).
  • A client using a trust, where the reason for the arrangement is not explained (p.46, reported SAR reasons).
  • Offshore source of funds for the initial property purchase (p.46, reported SAR reasons).
  • Adverse media about the client; property sold below value; unusual or evasive behaviour; or a vendor with gang links (p.46, less frequent but recorded SAR reasons).
  • A client who may themselves be the victim of a scam or fraud (p.46, reported SAR reasons) — the obligation is to report the suspicion, not to judge who is at fault.

These are the strongest indicators in this document because they are real-estate-specific and drawn from what the FIU has actually seen in New Zealand investigations and in six years of suspicious activity reports from this sector — not carried across from another profession. The first two are the two most common reasons agencies filed a SAR between 2018 and 2023.

Property transaction red flags seen from the conveyancing side

Source: DIA, Law Firms Money Laundering and Terrorism Financing Risk Summary (2023) — conveyancing section.

  • A purchase made sight unseen, where the purchaser has not inspected and shows no interest in inspecting the property.
  • Back-to-back transactions in which the value rises rapidly between sales without any improvement to the property.
  • A vendor knowingly selling materially below market value.
  • Payment made by, or on behalf of, a third party with no explained connection to the transaction.
  • Vendor and purchaser are connected and the connection is not explained.
  • Instructions change unexpectedly shortly before settlement — a change of purchaser, of nominee, or of payment direction.
  • An unencumbered purchase with no bank finance, or funded by private lending, where the source of funds is not clear.

DIA published these in the law-firm risk summary rather than the real estate SRA, because conveyancing is where they surface in that sector. They are kept as a secondary list because the underlying transaction is the same one the agency brings about, and an agency often sees the behaviour before the conveyancer does — the NRA 2024 makes the same point, recording that 44% of lawyers' SARs concern purchasers who will not evidence their source of wealth (p.46). The SRA 2026 does publish its own distinct real estate red-flag lists — confirmed 30 July 2026 and reproduced above — so this list is corroboration rather than a substitute, and the overlap between the two is itself the point.

Sight unseen purchases

Source: Department of Internal Affairs, 'Sight unseen property purchases' AML/CFT advisory, dia.govt.nz — read in full 30 July 2026. DIA lists these as higher risk indicators.

  • The customer shows interest in purchasing property without normal levels of interest in price, characteristics of the property, or other details.
  • A third party is acting on behalf of the customer, and the customer or beneficial owner is added to the sale and purchase agreement at the last minute.
  • The transaction does not match the customer's business or personal profile.
  • A property is bought and sold quickly.
  • The customer is reluctant to provide identity, or source of funds/wealth information and documentation.
  • Verification documentation is, or looks, fraudulent.
  • Unusual or complex ownership structure where beneficial ownership is hidden.
  • The customer is based in a country with a higher level of assessed ML/FT risk.
  • Payments received from bank accounts belonging to third parties who have no clear link to the customer.
  • Sale and purchase price are significantly undervalued or well above market price.
  • The customer intends to complete the sale without the use of a mortgage.

DIA publishes a standalone advisory on this one behaviour for the real estate sector, which is a strong signal it wants agencies alert to it specifically. Its instruction is explicit: if the business is involved in sight unseen purchases, the transaction type must be addressed in the risk assessment and in the AML/CFT programme. The SRA 2026 carries the same behaviour in its own sale-and-purchase list, qualified as being without a logical explanation.


1.11Section 10 — Determining the level of risk

s.58(3)(c)

This assessment enables the business to determine the level of risk involved in relation to its obligations. Every customer is risk-rated at onboarding using the factors in Sections 3 to 5, and the rating determines the level of customer due diligence applied.

Customer risk ratingWhen it appliesDue diligence applied
LowCustomer type for which the Act expressly permits simplified due diligence, and no higher-risk feature presentSimplified CDD, with the basis recorded in each case
MediumStandard customer, standard channel, no higher-risk featureStandard CDD
HighAny s.22 trigger — a politically exposed person or a customer with a PEP beneficial owner; a trust or other vehicle for holding personal assets; a company with nominee shareholders or shares in bearer form; a non-resident customer from a country with insufficient AML/CFT systems or measures — any country from Section 5 with insufficient AML/CFT systems or measures, or any unresolved indicator from Section 9. The other higher-weighted features in Section 4 raise the assessment and may result in High: that is a conclusion reached on assessment, with the reasons recorded, not an automatic ratingEnhanced CDD, including source of funds and source of wealth, and senior manager approval to proceed

A rating is a decision with reasons, not a category. The reasoning is recorded on the customer file so that the compliance officer's quarterly sampling can test whether ratings are being applied consistently — and so an auditor can see the same.

When the due diligence has to be done. When customer due diligence falls due depends on the type of transaction. For a commercial lease it must be completed before the lease agreement is presented to the landlord; for an assignment of lease, before the assignment is presented to the assignee; for a sublease, before the sublease agreement is presented to the outgoing tenant. For every other real estate transaction — a sale, most obviously — it falls due once there is a fully signed agency agreement, and before any further agency work is carried out for that customer. A conjunctional agent is outside this regulation.

Despite subsections (1) and (2), a real estate agent must conduct standard customer due diligence at the times, and with any other modifications, specified in rules made under section 156B.

— AML/CFT Act 2009, s.14(3)

For the purpose of sections 14(3), 18(3A), and 22(6) of the Act, a real estate agent must conduct customer due diligence,— (a) in relation to a commercial lease transaction, before the real estate agent presents a lease agreement to the landlord: (b) in relation to an assignment to lease transaction, before the real estate agent presents an assignment of lease to the assignee: (c) in relation to a sublease transaction, before the real estate agent presents a sublease agreement to the outgoing tenant: (d) in relation to any other real estate transaction, once there is a fully signed agency agreement and before carrying out any further real estate agency work for the customer.

— AML/CFT (Requirements and Compliance) Regulations 2011, reg 16(1)

Nothing in subclause (1) applies to an agent who is a conjunctional agent.

— AML/CFT (Requirements and Compliance) Regulations 2011, reg 16(2)

Listing and arranging a commercial lease by real estate agents is a captured activity under the AML/CFT Act… customer due diligence obligations apply in relation to the real estate agent's client.

— Real Estate Agent Sector Risk Assessment 2026, para 119

On a sale, a live listing with a signed agency agreement and no customer due diligence completed is an obligation already outstanding — the trigger has passed. On a commercial lease listing it has not: the obligation attaches before the lease agreement is presented to the landlord, so a listing still on the market has not yet reached its trigger. Establish which limb applies before describing anything as overdue.

Guidance followed: DIA's Guidance on Customer Risk-Rating, and the Enhanced Customer Due Diligence Guidance (2026).


1.12Section 11 — Keeping this assessment current

s.58(3)(b)

Scheduled review — before 30 June each year. Section 59(1) requires the business to review the risk assessment at least annually, to ensure it remains current, to identify deficiencies, and to make any necessary changes. That is the statutory floor and it fixes no date. DIA suggests scheduling the review alongside the annual report, and this business does so by completing it before 30 June — the last day of the reporting period. Every reporting year therefore contains a review, and the report filed from 1 July describes documents that have just been reviewed rather than documents last looked at during the previous year. The next review is due by 30 June 2027.

Out-of-cycle update — on a material change. The assessment is updated whenever the business changes materially, including:

  • a new product, service or delivery channel;
  • a change in business model, a merger or an acquisition;
  • dealing with a new country or a new type of customer;
  • opening a new office, or a significant change in size.

Out-of-cycle update — on a trigger event. Including:

  • an emerging threat or vulnerability affecting the sector;
  • new relevant risks identified by DIA under s.131 or the FIU under s.142 — a new Sector Risk Assessment or a new National Risk Assessment triggers a mandatory update under s.58(3)(ba);
  • an audit finding, or a deficiency identified in the internal review;
  • a suspicious activity report that reveals a risk this assessment did not anticipate.

Before use — new technology and new products. Under regulation 13E, where the business introduces new or developing technologies, or new or developing products including any new delivery mechanism, this assessment must be updated prior to their use. This is the one trigger that cannot be handled at the annual review, because the obligation bites before the thing is switched on.

TriggerWho actsWhen
Annual internal reviewMere KingiBefore 30 June each year — next by 30 June 2027
Material change to the businessCompliance officer, on becoming awareWithin 30 days (the window this business adopts — the Act requires the assessment be kept current, s.58(3)(b), without fixing a number of days)
New DIA Sector Risk Assessment or FIU National Risk AssessmentCompliance officerWithin 30 days of publication (the window this business adopts — s.58(3)(ba) makes incorporation mandatory without fixing a number of days)
New technology, product or delivery mechanism (reg 13E)Compliance officerBefore it is used
Audit findingCompliance officerPer the remediation plan

1.13Section 12 — Version control and approval

VersionDateAuthorApproved byChange and reason
1.04 August 2026Mere Kingi_________________ (sign and date on approval)First issue.

Approval. This risk assessment takes effect when approved below by the AML/CFT compliance officer. Until then it is a draft prepared for review.

Approved byMere Kingi
Position____________________________________
Signature____________________________________
Date____________________________________

Sources

Prepared from the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, the AML/CFT (Requirements and Compliance) Regulations 2011, the AML/CFT (Definitions) Regulations 2011, the Real Estate Agents Act 2008, and guidance published by the Department of Internal Affairs. DIA guidance and New Zealand legislation are Crown copyright and reproduced or paraphrased here for the client's compliance purposes.

  • Real Estate Sector Risk Assessment 2026
  • Risk Assessment Guidance (July 2026)
  • AML/CFT Programme Guidance (2026)
  • Audit Guidance for risk assessment and AML/CFT programme (July 2026)
  • A guide to complying with the AML/CFT Act
  • Guideline: Real Estate Agents — Complying with the AML/CFT Act 2009 (Dec 2018)
  • Guidance: Customer Risk-Rating
  • Enhanced Customer Due Diligence Guidance (2026)
  • Beneficial Ownership Guidance (July 2026)
  • Identity Verification Code of Practice 2026
  • Assessing Country Risk Guidance (July 2026)
  • Wire Transfers and Prescribed Transaction Reporting Guidance (July 2026)
  • Interpreting 'Ordinary Course of Business' Guidance (July 2026)
  • Sight unseen property purchases AML/CFT advisory
  • DNFBPs and Casinos Sector Risk Assessment (Dec 2019)
  • Annual AML/CFT Report User Guide for DNFBPs (June 2021)
  • AML/CFT Act 2009
  • AML/CFT (Requirements and Compliance) Regulations 2011
  • AML/CFT (Definitions) Regulations 2011
  • Real Estate Agents Act 2008

2AML/CFT Programme

Southern Cross Property Group Limited

Prepared under section 57 of the AML/CFT Act 2009 — real estate agency

DocumentAML/CFT Programme
Version1.0
Prepared4 August 2026
Based onAML/CFT Risk Assessment v1.0, 4 August 2026
AML/CFT compliance officerMere Kingi
Next internal review due30 June 2027 — the review completes before 30 June each year, so the annual report is filed on freshly reviewed documents (s.59(1): at least annually)
SupervisorDepartment of Internal Affairs

2.1Version control

VersionDateAuthorApproved byChange and reason
1.04 August 2026Mere Kingi_________________ (sign and date on approval)First issue.

Audit history. DIA expects this document to record when the last independent audit was carried out and how any deficiencies were remediated.

Audit report dateAuditorDeficiencies identifiedRemediationCompleted
15 September 2024Independent auditor — name to confirmYes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally.Not yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established.No

2.2Statutory basis and standard

Section 57(1) requires this programme to be in writing, to be based on the risk assessment undertaken in accordance with s.58, and to include adequate and effective procedures, policies and controls for each of the thirteen matters in s.57(1)(a) to (l) (the lettering runs (a) to (l) but includes (da), inserted in 2017 — thirteen limbs). Each has its own section below, lettered to match the statute.

The standard is two-part, and both halves are tested. DIA:

'Adequate' means your procedures, policies and controls must be adequately designed to meet all requirements of the Act. 'Effective' means that those procedures, policies and controls must manage and mitigate your ML/TF risks and operate effectively in practice.

A procedure that is well drafted but not followed fails the second half. That is why each section below states not only what the business does but where the record of it is kept — a control with no record cannot be shown to have operated.

Section 57(2) requires regard to be had to applicable guidance material produced by the supervisor or the Commissioner. The guidance relied on is listed under Sources.

On templates. DIA's Programme Guidance says:

Your programme should be specific to your business. The use of a template may be a good starting point to develop your programme. However, the Department considers that generic procedures, policies and controls not based on your risk assessment, and/or not tailored to your ML/TF risks, are unlikely to comply with the Act.


2.3The AML/CFT compliance officer

s.56

Section 56 requires the business to establish, implement and maintain this programme, and to designate an employee as AML/CFT compliance officer to administer and maintain it. Where the business has no employees, it must appoint an individual. The compliance officer must be a senior manager, or must report to a senior manager. A partnership may designate a partner irrespective of whether it has employees, and that partner must report to another partner designated to receive those reports.

(s.56(3) and (4) were amended on 19 May 2026 by s.14 of the AML/CFT Amendment Act 2026.)

AML/CFT compliance officerMere Kingi
PositionHead of Risk and Compliance
Reports toDaniel Whitcombe, Chief Executive
Contact for AML/CFT mattersmere@sxproperty.co.nz · 04 555 0180

Authority. The compliance officer has express authority to decline a customer or a transaction on AML/CFT grounds without seeking commercial sign-off, and to require that a transaction not proceed until due diligence is complete. That authority is stated here because a compliance officer who has to win an argument with a fee-earner before stopping a transaction does not, in practice, have it.

Independence of the audit. Under s.59B(3) the independent auditor must not have been involved in establishing, implementing or maintaining this programme or in undertaking the risk assessment. Anyone who assisted in preparing these documents is excluded on that basis, and the business appoints its independent auditor accordingly.


2.4s.57(1)(a) — Vetting

Statutory requirement. Adequate and effective procedures, policies and controls for: Vetting senior managers, the AML/CFT compliance officer, and any other employee engaged in AML/CFT related duties.

Vetting reaches everyone who can influence a transaction, not just the compliance officer.

Procedures, policies and controls

  1. Vetting is completed before a person starts AML/CFT-related duties, and covers the compliance officer, senior managers, licensed salespeople, branch managers, and any administrator with access to the trust account or to customer due diligence records.
  2. Vetting comprises: confirmation of identity; confirmation of a current REA licence where the role requires one; a criminal history check where the person consents and the check is lawfully available; verification of the employment history stated on application; and a reference from the most recent employer.
  3. Adverse findings are considered by the compliance officer against the role, recorded with the reasoning, and escalated to the senior manager to whom the compliance officer reports before any appointment proceeds.
  4. Vetting is repeated on a change of role that brings a person into AML/CFT duties for the first time, and licence currency is re-checked annually.

Specific to this business

  • Vetting covers all 34 people in the business who fall within the scope above.
  • At 34 staff across multiple sites, vetting is completed centrally by Mere Kingi before a start date is confirmed, rather than by each office. Branch managers cannot waive it for a hire they want to make quickly.

Records kept. Vetting file per person: checks completed, dates, outcome, decision-maker. Retained for the period the person holds the role and afterwards in line with the record-keeping policy.


2.5s.57(1)(b) — Training

Statutory requirement. Adequate and effective procedures, policies and controls for: Training on AML/CFT matters for senior managers, the AML/CFT compliance officer, and any other employee engaged in AML/CFT related duties.

Salespeople meet the customer and see the behaviour; they are the detection layer, so training is role-specific rather than a single all-staff session.

Procedures, policies and controls

  1. Every person within the vetting scope completes AML/CFT training at induction, before carrying out AML/CFT-related duties, and at least annually thereafter.
  2. Salesperson training covers: who the customer is and when customer due diligence must be completed; identifying beneficial owners of company and trust vendors; the red flags listed in the risk assessment; the counterparty suspicious activity reporting obligation; and the prohibition on tipping off.
  3. Trust account and administration staff receive additional training on receipting, third-party payment directions, aborted transactions and prescribed transaction reporting.
  4. Training is refreshed out of cycle when the risk assessment or programme changes materially, when DIA publishes a new sector risk assessment, and following any audit finding that relates to staff practice.
  5. Understanding is checked rather than assumed — attendance alone is not evidence of training under s.57(1)(b).

Specific to this business

  • The last AML/CFT training session was delivered on 12 November 2025. The next annual refresher is due by 12 November 2026.
  • All 34 staff are within scope for the induction and annual refresher.

Records kept. Training register: date, topic, delivered by, attendees, materials used, and how understanding was confirmed.


2.6s.57(1)(c) — Customer due diligence

Statutory requirement. Adequate and effective procedures, policies and controls for: Complying with customer due diligence requirements, including ongoing customer due diligence and account monitoring.

The vendor is the customer; the purchaser usually is not. This is the sector's structural gap and the programme has to name it rather than let it sit unaddressed.

When customer due diligence falls due. When customer due diligence falls due depends on the type of transaction. For a commercial lease it must be completed before the lease agreement is presented to the landlord; for an assignment of lease, before the assignment is presented to the assignee; for a sublease, before the sublease agreement is presented to the outgoing tenant. For every other real estate transaction — a sale, most obviously — it falls due once there is a fully signed agency agreement, and before any further agency work is carried out for that customer. A conjunctional agent is outside this regulation.

Despite subsections (1) and (2), a real estate agent must conduct standard customer due diligence at the times, and with any other modifications, specified in rules made under section 156B.

— AML/CFT Act 2009, s.14(3)

For the purpose of sections 14(3), 18(3A), and 22(6) of the Act, a real estate agent must conduct customer due diligence,— (a) in relation to a commercial lease transaction, before the real estate agent presents a lease agreement to the landlord: (b) in relation to an assignment to lease transaction, before the real estate agent presents an assignment of lease to the assignee: (c) in relation to a sublease transaction, before the real estate agent presents a sublease agreement to the outgoing tenant: (d) in relation to any other real estate transaction, once there is a fully signed agency agreement and before carrying out any further real estate agency work for the customer.

— AML/CFT (Requirements and Compliance) Regulations 2011, reg 16(1)

Nothing in subclause (1) applies to an agent who is a conjunctional agent.

— AML/CFT (Requirements and Compliance) Regulations 2011, reg 16(2)

Listing and arranging a commercial lease by real estate agents is a captured activity under the AML/CFT Act… customer due diligence obligations apply in relation to the real estate agent's client.

— Real Estate Agent Sector Risk Assessment 2026, para 119

On a sale, a live listing with a signed agency agreement and no customer due diligence completed is an obligation already outstanding — the trigger has passed. On a commercial lease listing it has not: the obligation attaches before the lease agreement is presented to the landlord, so a listing still on the market has not yet reached its trigger. Establish which limb applies before describing anything as overdue.

Procedures, policies and controls

  1. Customer due diligence is completed on the customer — the vendor on a sale, the landlord on a lease listing — by the point reg 16 requires for that transaction type: on a sale, once the agency agreement is fully signed and before any further agency work is carried out; on a commercial lease, before the lease agreement is presented to the landlord; on an assignment or sublease, before the assignment or sublease agreement is presented. Work does not proceed past that point until the due diligence is complete.
  2. Where the vendor is a company, trust, partnership or other legal arrangement, the agency identifies and verifies the beneficial owners and any person acting on the customer's behalf, using DIA's Beneficial Ownership Guidance and the relevant CDD guidance for that entity type.
  3. Identity verification follows the Identity Verification Code of Practice 2026, which took effect on 1 July 2026 and now covers high-risk customers as well as low and medium. Following the Code is not mandatory but provides a safe harbour, and the agency has chosen to rely on it.
  4. Although customer due diligence obligations normally attach to the vendor, the agency records what it knows about the purchaser and any nominee, because its suspicious activity reporting obligations extend to any counterparty. Where a purchaser nominates a different person to complete, that change is recorded and assessed.
  5. Ongoing customer due diligence and account monitoring are conducted for the duration of the business relationship, so that the agency's information stays current and transactions are checked against what it knows of the customer.
  6. Where there has been a material change in the nature or purpose of the relationship and the agency holds insufficient information, customer due diligence is conducted again before the relationship continues.
  7. Exception handling: where customer due diligence cannot be completed, the agency does not establish or continue the relationship and does not carry out the transaction, and the compliance officer considers whether a suspicious activity report is required.

Specific to this business

  • This business operates a trust account (Schedule 2A item 7.4 value band: $10m–$49.99m). Customer due diligence on the vendor must be complete before any deposit is receipted, not merely before settlement.
  • 25 of this year's customers were trusts or personal asset-holding vehicles. For each, the beneficial owners and any person acting on the customer's behalf are identified and verified — a trust deed and the trustee's identification alone do not satisfy this.
  • The Schedule 2A item 8.2 figures record 40 non-resident customers for reporting purposes. Verification for a non-resident cannot rely on a New Zealand document check, so the method used is recorded on each file. Non-residence is not itself a trigger for enhanced due diligence: enhanced measures apply where a s.22 trigger is met, and each customer's risk rating and the reasoning for it are recorded in the CDD register.
  • Schedule 2A item 8.1 records approximately 366 customers for the year. The compliance officer's quarterly sampling is sized against that volume.

Records kept. CDD file per customer: information obtained, verification method and evidence, beneficial ownership analysis, risk rating and reasoning, date, and who completed it.


2.7s.57(1)(d) — Reporting suspicious activities

Statutory requirement. Adequate and effective procedures, policies and controls for: Reporting suspicious activities.

The counterparty obligation is the point most agencies miss.

Procedures, policies and controls

  1. Any person in the agency who forms a suspicion reports it to the compliance officer immediately, using the internal escalation form, and does not discuss it with the customer or any other party.
  2. The compliance officer decides whether the suspicion meets the reporting threshold, records the decision and the reasoning either way, and where it does, files the suspicious activity report through goAML within three working days.
  3. A decision NOT to report is recorded with the same rigour as a decision to report. An unrecorded negative decision is indistinguishable from a failure to consider the matter.
  4. The obligation is not limited to the agency's own client. It applies to any counterparty to the transaction — purchasers, nominees and the parties directing payment included.
  5. Tipping off: no person discloses to the customer, the counterparty or anyone else that a report has been made, is being considered, or that an investigation is on foot.
  6. The agency registers with goAML, which is the channel through which suspicious activity reports are filed and is separate from enrolment as a reporting entity. Once registration is held, it is maintained together with the compliance officer's access to it, and that access is tested at least annually so it is not discovered to be broken at the moment it is needed.

Records kept. Suspicious activity register: every escalation received, the assessment, the decision, the reasoning, the date, and the goAML reference where filed.


2.8s.57(1)(da) — Reporting prescribed transactions

Statutory requirement. Adequate and effective procedures, policies and controls for: Reporting prescribed transactions.

Trust account receipts are where prescribed transactions surface for an agency.

Scaled to this business.

This business does not accept cash and does not send or receive funds internationally (Schedule 2A items 7.9 and 7.10). It does operate a trust account, so receipts still pass through it.

The obligation under s.57(1)(da) does not fall away because the activity is currently absent — it is dormant, not inapplicable, and the procedures below are proportionate rather than detailed. The full procedure is reactivated if the business begins accepting cash, or begins sending or receiving funds internationally. Where that change involves a new or developing technology, product or delivery mechanism, regulation 13E requires the risk assessment to be updated before it is used, and this section is rewritten at the same time.

Procedures, policies and controls

  1. The compliance officer confirms at each annual review that the business still does not accept cash and still does not send or receive funds internationally. The answer is recorded, because it is also the answer to Schedule 2A items 7.9 and 7.10. The thresholds that would make a transaction reportable are NZ$10,000 or more in physical cash domestically, and NZ$1,000 or more for an international wire transfer (AML/CFT (Prescribed Transactions Reporting) Regulations 2016).
  2. Trust account receipts are checked against the prescribed transaction criteria at the point of receipting. A cash deposit or an international transfer arriving unexpectedly is exactly the event this limb exists for, and it will arrive through the trust account if it arrives at all.
  3. Any staff member who is offered cash, or asked to accept funds from overseas, refers it to the compliance officer before accepting. Nobody accepts a first cash payment and reports it afterwards.
  4. If either activity begins, the full procedure is reinstated and goAML reporting arrangements are confirmed to be working before the first qualifying transaction — not after it.

Records kept. Prescribed transaction register with goAML references.


2.9s.57(1)(e) — Record keeping

Statutory requirement. Adequate and effective procedures, policies and controls for: Record keeping.

Records have to survive the transaction, the staff member and the software.

Procedures, policies and controls

  1. The agency keeps records of: customer due diligence information and verification evidence; agency agreements and transaction records; trust account receipts, payments and reconciliations; suspicious activity and prescribed transaction reports and the decisions behind them; training and vetting records; every version of the risk assessment and this programme; and audit reports and remediation.
  2. Records relating to the independent audit are kept for at least five years after they cease to be used on a regular basis, and are made available to DIA on request (ss.51(1)(b), 51(2) and 51(3)).
  3. Transaction records are kept for at least five years after the completion of the transaction (s.49), and identity and verification records for at least five years after the end of the business relationship — or, for an occasional transaction or activity, five years after its completion (s.50). These periods were confirmed against the Act on 29 July 2026.
  4. Records are held so that a specific customer's file can be produced to DIA promptly, in a form that is readable and complete, and they are backed up against loss of the practice management system.

Specific to this business

  • Trust account records are kept and reconciled separately from property files, and both must be retrievable for the same transaction on request.
  • With 34 staff across more than one office, records must be retrievable centrally rather than held on the file of the salesperson who acted. A departing salesperson must not take the only copy of a due diligence record.

Records kept. Record-keeping schedule listing each record type, where it is held, who is responsible, and its retention period.


2.10s.57(1)(f) — Managing and mitigating risk

Statutory requirement. Adequate and effective procedures, policies and controls for: Setting out what the reporting entity needs to do, or continue to do, to manage and mitigate the risk of money laundering and the financing of terrorism.

s.57(1)(f) asks what the agency does, and continues to do, to manage and mitigate the risks its own risk assessment identified. This is the limb that ties the programme back to the risk assessment.

Procedures, policies and controls

  1. Every risk rated Medium or above in the risk assessment has a named mitigation in this programme, an owner, and a means of knowing whether it is working.
  2. Mitigations for the two services the SRA 2026 requires the agency to assess — sale and purchase of land and/or property, and trust accounts — are set out in the risk assessment and cross-referenced here.
  3. The compliance officer reviews whether mitigations are operating effectively, not merely whether they exist, and reports to the senior manager on that question at least annually.
  4. Where a mitigation is found not to be working in practice, it is changed and the change is briefed to everyone affected before it takes effect. A control that is documented but not followed fails the 'effective' half of the statutory standard.

Specific to this business

  • The services this business actually provides, each of which must have a named mitigation below: Sale and purchase of land and/or property (inherent Medium-High); Trust accounts / managing client funds (inherent Medium-High).
  • Not provided, and therefore not mitigated here: Commercial leasing. If the business begins any of these, the risk assessment is updated first.
  • An unclosed audit finding is itself an unmitigated risk: Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally. It carries an owner and a date until closed.

Records kept. Risk-to-control mapping, reviewed annually alongside the risk assessment.


2.11s.57(1)(g) — Examining and keeping written findings on unusual transactions

Statutory requirement. Adequate and effective procedures, policies and controls for: Examining, and keeping written findings relating to, complex or unusually large transactions; unusual patterns of transactions that have no apparent economic or visible lawful purpose; and any other activity regarded as particularly likely by its nature to relate to money laundering or the financing of terrorism.

DIA names failure to keep written findings as a common deficiency across DNFBPs. This limb is therefore written operationally rather than restating the statute.

Procedures, policies and controls

  1. The agency examines, and keeps a written finding on: complex or unusually large transactions; unusual patterns of transactions with no apparent economic or visible lawful purpose; and any other activity particularly likely by its nature to relate to money laundering or terrorism financing.
  2. For this agency that includes, at minimum: sales materially above or below the assessed market value; back-to-back transactions where value rises without improvement to the property; deposits paid in cash or in structured instalments; payment or refund directions involving a person who is not a party to the agreement; a change of purchaser or nominee shortly before settlement; and any transaction aborted after funds have been received.
  3. The written finding records what was examined, what enquiries were made, what the customer said, and the conclusion reached — including where the conclusion is that the transaction is legitimate.
  4. Written findings are made at the time, not reconstructed later, and are retained whether or not the matter resulted in a suspicious activity report.
  5. The compliance officer samples the register quarterly to confirm findings are being made where they should be. Absence of entries is treated as a question to answer, not as evidence of a clean book.

Specific to this business

  • Because this business receipts deposits into a trust account, the trust account is the first place an unusual transaction shows up. Receipts materially larger than the transaction requires, aborted transactions where a refund is directed elsewhere, and payments from a person who is not a party to the agreement are each examined and a written finding kept.
  • Unclosed audit finding relevant here. Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally. Reported remediation: Not yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established. A written findings register that does not exist in practice cannot satisfy this limb, whatever this document says.

Records kept. Register of examinations and written findings, with dates, the examiner, and the conclusion.


2.12s.57(1)(h) — Higher-risk countries

Statutory requirement. Adequate and effective procedures, policies and controls for: Monitoring, examining and keeping written findings relating to business relationships and transactions from or in countries that do not have or have insufficient AML/CFT systems in place, and having additional measures for dealing with, or restricting dealings with, such countries.

Overseas purchasers and overseas funds are the realistic route by which country risk reaches a New Zealand agency.

Why this limb is live for this business. This business uses intermediaries or agents overseas (Yes — two overseas buyer's agents introduced purchasers during the period).

Procedures, policies and controls

  1. The agency monitors and examines business relationships and transactions involving countries with insufficient AML/CFT systems and measures, and keeps written findings on them.
  2. Country risk is assessed using DIA's Assessing Country Risk Guidance (July 2026) together with the current FATF listings, and the assessment is recorded rather than held informally.
  3. Additional measures for higher-risk countries: enhanced customer due diligence; establishing source of funds and source of wealth to the compliance officer's satisfaction; senior manager approval before proceeding; and closer scrutiny of the transaction through to settlement.
  4. The agency will decline or restrict dealings where the country risk cannot be adequately mitigated, and the compliance officer has express authority to decline without seeking commercial sign-off.

Specific to this business

  • The countries this business actually deals with: Singapore; China. A country risk assessment is completed and recorded for each of these before the next transaction involving them, and reviewed at least annually and on any change to the FATF listings.
  • Where a purchaser is introduced through an overseas intermediary, the agency records which country the introduction came from, what the intermediary did and did not verify, and what the agency itself established. An introduction is not due diligence.
  • 40 non-resident customers this year. Source of funds and source of wealth are established and recorded for each where the country risk assessment requires it, with Mere Kingi approving before the transaction proceeds.
  • The FIU records that in international money laundering investigations, purchase funds were transferred from offshore bank accounts into New Zealand lawyers' trust accounts (NRA 2024, p.47). Funds arriving from offshore for a purchase are examined and a written finding kept under s.57(1)(g).

Records kept. Country risk assessment, reviewed at least annually and on any change to FATF listings; written findings on relevant relationships and transactions.


2.13s.57(1)(i) — Products and transactions favouring anonymity

Statutory requirement. Adequate and effective procedures, policies and controls for: Preventing the use for money laundering or the financing of terrorism of products and transactions that might favour anonymity — for example the misuse of technology, or non-face-to-face business relationships.

Anonymity in this sector comes through nominees, remote onboarding and sight-unseen purchasing.

Why this limb is live for this business. This business onboards some customers without face-to-face contact.

Procedures, policies and controls

  1. The agency identifies where its products, services and delivery channels could favour anonymity, and controls them: non-face-to-face onboarding; nominee purchasers; purchases made sight unseen; and any digital identity or onboarding technology used.
  2. Where a customer is onboarded without face-to-face contact, the verification method used is recorded and the relationship is risk-rated with that fact taken into account.
  3. A purchase made sight unseen is treated as an indicator requiring examination and a written finding under s.57(1)(g), consistent with DIA's advisory on sight unseen property purchases.
  4. Nominee arrangements are recorded, and the agency establishes and records why the arrangement is required.
  5. Under regulation 13E, where the agency introduces a new or developing technology or product — including a new delivery mechanism — the risk assessment is updated BEFORE it is used, not afterwards.

Specific to this business

  • For each customer onboarded without face-to-face contact, the verification method used is recorded on the file and the relationship is risk-rated with that fact taken into account.

Records kept. Channel and technology risk log; record of the reg 13E assessment for each new technology or product.


2.14s.57(1)(j) — Enhanced and simplified due diligence

Statutory requirement. Adequate and effective procedures, policies and controls for: Determining when enhanced customer due diligence is required, and when simplified customer due diligence might be permitted.

DIA's named deficiency includes failing to conduct enhanced due diligence in all situations where the level of risk requires it. The triggers are therefore listed rather than left to judgement in the moment.

Procedures, policies and controls

  1. Enhanced customer due diligence is conducted whenever the level of risk requires it. It is mandatory, whatever rating the customer would otherwise carry, where the customer is: a politically exposed person, or has a beneficial owner who is one (s.22(2) and s.26); a trust or another vehicle for holding personal assets; a company with nominee shareholders or shares in bearer form; or a non-resident customer from a country that has insufficient anti-money laundering and countering financing of terrorism systems or measures in place (s.22(1)(a)). It is equally mandatory where a customer seeks to conduct a complex or unusually large transaction, or an unusual pattern of transactions, with no apparent or visible economic or lawful purpose (s.22(1)(c)).
  2. Other features raise a customer's rating without triggering enhanced measures automatically: layered or overseas ownership, non-residence where the customer's country is not one of those above, and any other connection to a higher-risk country. Each is weighed at onboarding and may produce a High rating, and where it does, enhanced measures follow because the level of risk requires them (s.22(1)(d)). The rating and the reasoning for it are recorded in the CDD register either way.
  3. Enhanced customer due diligence also applies where a written finding under s.57(1)(g) leaves a residual concern short of suspicion, and where the source of funds is not readily apparent from what the agency already knows.
  4. Enhanced measures comprise: obtaining and verifying source of funds and source of wealth; additional verification of identity and beneficial ownership; senior manager approval to proceed; and increased monitoring through to settlement.
  5. Simplified customer due diligence is applied only to the customer types for which the Act permits it, and the basis for applying it is recorded in each case rather than assumed by category.
  6. The compliance officer reviews the enhanced due diligence register quarterly against the transaction ledger, to confirm that risk ratings are actually driving the level of due diligence applied. This check exists specifically because DIA names the failure to do so as a common sector deficiency.
  7. Guidance followed: DIA's Enhanced Customer Due Diligence Guidance (2026) and Customer Risk-Rating Guidance.

Specific to this business

  • Customers for whom enhanced due diligence is mandatory, from the Schedule 2A item 8.2 figures: 1 politically exposed person; 25 trusts or personal asset-holding vehicles. Section 22 requires enhanced measures for each of these regardless of the risk rating otherwise assigned. The compliance officer's quarterly check is against these numbers — if the enhanced due diligence register holds fewer entries than there are customers in these categories, the gap is the finding.
  • The item 8.2 figures also record 40 non-resident customers. Non-residence is not an s.22 trigger and does not by itself require enhanced measures; it is a risk factor weighed in the customer's rating. On assessment no current customer meets an s.22 trigger, and each rating and the reasoning for it are recorded in the CDD register. The compliance officer's quarterly check confirms that the ratings are driving the level of due diligence actually applied.
  • Unclosed audit finding. The last independent audit found: Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally. Remediation status reported: Not yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established. Until closed, this is the first thing an auditor will look at under this limb, and it must be disclosed at Schedule 2A items 5.7 and 6.7.

Records kept. Enhanced due diligence register: customer, trigger, measures applied, source of funds finding, approver, date.


2.15s.57(1)(k) — Third-party customer due diligence

Statutory requirement. Adequate and effective procedures, policies and controls for: Providing for when a person who is not the reporting entity may conduct customer due diligence on its behalf, and the procedures for that person to follow.

Where someone else does the due diligence, the agency remains accountable for it.

Scaled to this business.

This business conducts all of its own customer due diligence and does not rely on another reporting entity or outsource to a third-party agent under ss.32–34 (Schedule 2A item 6.10). However, introductions are received from intermediaries or agents, who carry out no due diligence on the agency's behalf.

The obligation under s.57(1)(k) does not fall away because the activity is currently absent — it is dormant, not inapplicable, and the procedures below are proportionate rather than detailed. The full procedure is reactivated if the business begins relying on another reporting entity's due diligence, engages a third-party agent to conduct customer due diligence, or joins a Designated Business Group. Where that change involves a new or developing technology, product or delivery mechanism, regulation 13E requires the risk assessment to be updated before it is used, and this section is rewritten at the same time.

Procedures, policies and controls

  1. The business conducts its own customer due diligence and does not rely on another reporting entity or outsource to a third-party agent under ss.32-34.
  2. Before entering any such arrangement, it is documented in a written agreement following DIA's Reliance on Another Reporting Entity and Outsourcing to a Third-Party Agent guidance (both July 2026), and the compliance officer satisfies themselves that the third party's procedures meet the standard of this programme.
  3. Responsibility for compliance would remain with the business in any event. Another party's due diligence is never a reason to hold less information about the business's own customer.
  4. The distinction that matters here: receiving an introduction is not the same as relying on someone else's customer due diligence. Where a conveyancer, an intermediary or a buyer's agent is involved, the agency still holds its own obligations in full and does not treat their involvement as a reason to hold less information about its own customer.

Records kept. Third-party CDD agreements, annual reviews, and evidence obtained.


2.16s.57(1)(l) — Monitoring, communication and training in the programme

Statutory requirement. Adequate and effective procedures, policies and controls for: Monitoring and managing compliance with, and the internal communication of and training in, those procedures, policies and controls.

The limb that makes the other eleven real — monitoring that the programme is followed, and communicating it internally.

Procedures, policies and controls

  1. The compliance officer monitors compliance with these procedures, policies and controls through quarterly file sampling across customer due diligence files, the written findings register and the enhanced due diligence register, and reports the results to the senior manager to whom they report.
  2. Findings from monitoring are recorded, given an owner and a date, and followed to closure.
  3. This programme is communicated to all staff on issue and on every material change, and forms part of induction for every new starter.
  4. Staff are trained in these procedures specifically, not only in AML/CFT in general — s.57(1)(l) requires training in the procedures, policies and controls themselves.
  5. The programme and risk assessment are reviewed at least annually under s.59(1), and independently audited under s.59(2), with remediation recorded in the version control table at the front of this document.

Specific to this business

  • With 34 staff across multiple offices, Mere Kingi cannot review every transaction. Monitoring is quarterly file sampling across all offices, sized so that every salesperson's files are sampled at least annually, with results reported to Daniel Whitcombe, Chief Executive.
  • Remediation of the outstanding audit finding is tracked through this limb and reported until closed.

Records kept. Monitoring reports, sampling results, remediation log, and the version control table.


2.17Reviewing, auditing and reporting on this programme

These three obligations sit outside s.57 but govern the life of this document, and DIA lists them alongside the 'adequate and effective' standard as the programme's other legal requirements.

Internal review — s.59(1). The business reviews this programme and the risk assessment at least annually, to ensure they remain current, to identify deficiencies, and to make any necessary changes. Annually is the statutory floor; the review is scheduled to complete before 30 June each year, so that every reporting year contains one and the annual report is filed on documents that have just been reviewed. The next review is due by 30 June 2027. The review is recorded in the version control table.

Independent audit — s.59(2) and reg 13. The risk assessment and this programme must be audited by an appropriately qualified and independent person every three years, unless DIA notifies the business that a four-year period applies, or DIA requests an audit at another time. The auditor need not be a chartered accountant and need not be qualified to undertake financial audits, but must not have been involved in preparing the documents. The audit of the risk assessment is limited to whether it fulfils s.58(3). A copy of any audit must be provided to DIA on request.

The clock runs from the report, not the fieldwork. DIA's Guidance: Audit for risk assessment and AML/CFT programme (July 2026), p.4: "An audit is not complete unless the final audit report is issued by your auditor. You then have three years from the date of your last audit report, to have your next audit completed and the audit report issued." The next audit is diarised from the report date, not from the fieldwork or the engagement.

Annual report — s.60. The business prepares an annual report on the risk assessment and this programme, in the approved form, taking into account the results and implications of the audit. See the Annual AML/CFT Report.

Records of the audit are kept for at least five years after they cease to be used on a regular basis (ss.51(1)(b), 51(2) and 51(3)), and are made available to DIA on request.


2.18Approval

This programme takes effect when approved below. Until then it is a draft prepared for review.

Approved byMere Kingi
Position____________________________________
Signature____________________________________
Date____________________________________

Issued to and read by:

NameRoleDate readSignature

Sources

Prepared from the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, the AML/CFT (Requirements and Compliance) Regulations 2011, the AML/CFT (Definitions) Regulations 2011, the Real Estate Agents Act 2008, and guidance published by the Department of Internal Affairs. DIA guidance and New Zealand legislation are Crown copyright and reproduced or paraphrased here for the client's compliance purposes.

  • Real Estate Sector Risk Assessment 2026
  • Risk Assessment Guidance (July 2026)
  • AML/CFT Programme Guidance (2026)
  • Audit Guidance for risk assessment and AML/CFT programme (July 2026)
  • A guide to complying with the AML/CFT Act
  • Guideline: Real Estate Agents — Complying with the AML/CFT Act 2009 (Dec 2018)
  • Guidance: Customer Risk-Rating
  • Enhanced Customer Due Diligence Guidance (2026)
  • Beneficial Ownership Guidance (July 2026)
  • Identity Verification Code of Practice 2026
  • Assessing Country Risk Guidance (July 2026)
  • Wire Transfers and Prescribed Transaction Reporting Guidance (July 2026)
  • Interpreting 'Ordinary Course of Business' Guidance (July 2026)
  • Sight unseen property purchases AML/CFT advisory
  • DNFBPs and Casinos Sector Risk Assessment (Dec 2019)
  • Annual AML/CFT Report User Guide for DNFBPs (June 2021)
  • AML/CFT Act 2009
  • AML/CFT (Requirements and Compliance) Regulations 2011
  • AML/CFT (Definitions) Regulations 2011
  • Real Estate Agents Act 2008

3Annual AML/CFT Report

Southern Cross Property Group Limited

Prepared under section 60 of the AML/CFT Act 2009 for filing through AML Online

DocumentAnnual AML/CFT Report
Version1.0
Prepared4 August 2026
Reporting period1 July 2025 – 30 June 2026
Filing window1 July 2026 – 31 August 2026 (OPEN NOW)
FormSchedule 2A, AML/CFT (Requirements and Compliance) Regulations 2011
ChannelAML Online — https://aml.dia.govt.nz/

3.1Summary

The position this report records, in plain terms, before the detail.

  • The business is a real estate agency. The work the Act captures is sale and purchase of land and/or property, trust accounts / managing client funds; nothing else it does is in scope.
  • Across the year it brought about transactions worth $50m+ in total, excluding its own fees and commission.
  • It takes no cash, so none of the cash reporting applies.
  • It sends and receives no money internationally.
  • At 30 June the written risk assessment was in place and the written programme was in place. This report records the position as at that date.
  • The period covered is 1 July 2025 to 30 June 2026.

3.2The report

Every question in Schedule 2A, the answer given, and where the answer required a judgement the basis on which it was reached.

Part 1 — Contact details and organisation structure

ItemQuestionAnswer
1.1Period the report covers1 July 2025 to 30 June 2026
2.1Legal name; entity type; registration or incorporation number; trading namesSouthern Cross Property Group Limited · Company · 9429030000000 · SX Property
2.2Physical addressLevel 6, 88 The Terrace, Wellington 6011
2.3Postal addressPO Box 5521, Wellington 6140
2.4Compliance officer full name; AML/CFT contact email; phone; websiteMere Kingi · mere@sxproperty.co.nz · 04 555 0180 · www.sxproperty.co.nz
2.5Sector tick-listreal estate agent
3.1Branch or subsidiary of an offshore parent?No
3.2Country of largest owner (or largest beneficial owner)New Zealand
3.3Headcount34
3.4New Zealand office locationsThree offices — Wellington CBD, Lower Hutt, Porirua
3.5New Zealand subsidiariesNone
3.6Overseas office locationsNone
3.7Overseas subsidiariesNone

Part 2 — Designated Business Group, risk assessment and programme

ItemQuestionAnswer
4.1Designated Business Group member?No
4.2If yes, are you completing Part 2 on behalf of the DBG? If not, name the DBG entity doing so, leave the rest of Part 2 blank and go to Part 3Not applicable — not a DBG member
5.1Does your risk assessment meet s.58 — Meets all / Meets some / Meets noneMeets some — the existing risk assessment predates s.58(3)(ba) and does not incorporate the SRA 2026 or the NRA 2024.
5.2If 'meets some', list every non-compliant subsectionSee 5.1 — s.58(3)(ba) until the NRA 2024 incorporation is completed.
5.3Date of most recent internal review of the risk assessment1 June 2025
5.4Has the risk assessment been independently audited?Yes
5.5Date of most recent audit15 September 2024
5.6Did the audit highlight deficiencies?Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally.
5.7Have you made the changes — Yes, complete / Not yet complete, plus a detailed explanationNot yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established.
5.8Did you introduce a new regulated service, product or channel during the year that was not considered in your risk assessment?No
6.1Does your programme meet s.57 — Meets all / Meets some / Meets noneNeeded from you
6.2If 'meets some', list non-compliant paragraphs from s.57(1)(a)–(l)Reported at engagement as partly compliant. The written programme covers vetting, training, CDD and record keeping but has no documented procedures for s.57(1)(g) written findings, s.57(1)(h) higher-risk countries, or s.57(1)(j) enhanced due diligence triggers.
6.3Date of most recent internal review of the programme1 June 2025
6.4Has the programme been independently audited?Yes
6.5Date of most recent audit15 September 2024
6.6Did the audit highlight deficiencies?Yes — the 2024 audit found enhanced due diligence was not consistently applied to non-resident purchasers, and that written findings were not kept for transactions that had been escalated verbally.
6.7Have you made the changes?Not yet complete. An EDD checklist was introduced in early 2025; the written findings register has not yet been established.
6.8Do you have procedures to identify and verify (a) a new customer including beneficial owners and persons acting on their behalf, (b) a person conducting an occasional transaction or activity, (c) an existing customer where there has been a material change and you hold insufficient information?Yes — s.57(1)(c) of the AML/CFT Programme addresses all three.
6.9Exception handling procedures for CDD issuesYes — s.57(1)(c) of the AML/CFT Programme: where CDD cannot be completed the business does not establish or continue the relationship or carry out the transaction, and the compliance officer considers whether a SAR is required. The programme follows the Identity Verification Code of Practice 2026, which commenced on 1 July 2026. Schedule 2A and the Department's FAQ still cite the Amended Identity Verification Code of Practice 2013 by name; the answer is the same either way.
6.10Outside a DBG, do you outsource CDD to third parties under ss.32–34?No — all customer due diligence is conducted by the agency itself
6.11Do you use electronic processes for account monitoring under s.31?No

Part 3 — Products, services, customers and channels

ItemQuestionAnswer
7.1Formation agent of legal persons or arrangements — banded counts for companies, trusts, partnerships, charities, otherNot applicable — the agency does not form companies, trusts, partnerships or charities
7.2Nominee director / nominee shareholder / trustee roles heldNo nominee director, nominee shareholder or trustee roles held
7.3Registered office, business, correspondence or administrative address services — banded by entity typeNot applicable — no registered office or address services provided
7.4Managing client funds, accounts, securities or other assets — banded valueYes — $10m–$49.99m
7.5Real estate agency work to effect a transactionYes
7.6Which of the five specified activities do you engage in or instruct on — conveyancing; REAA transactions; transfer of beneficial interest in land; buying/transferring/selling a business or legal person; creating, operating or managing a legal person or arrangementREAA transactions (real estate agency work to bring about a transaction)
7.7Estimated total value of the 7.6 transactions for the last year, excluding your professional fees and any commission earned$50m+
7.8Section B — eleven-item list of financial activities (OPTIONAL)Optional under Schedule 2A — leave blank unless the business carries on one of the listed financial activities (deposit-taking through to life insurance). No answer is required of a real estate agency that does not.
7.9Do you accept cash, and what percentage of your business involves it?No
7.10Do you send or receive funds internationally — banded total value — plus your three most common products or servicesNo · 0 · Residential property sales; commercial property sales; property management
8.1Estimated number of customers you conducted CDD on this year366
8.2How many of those were PEPs (including customers beneficially owned or controlled by a PEP), trusts or personal-asset-holding vehicles, overseas government bodies, NZ resident individuals, NZ resident entities, non-resident individuals, non-resident entitiesPEPs (including PEP-owned or PEP-controlled): 1 · Trusts or other personal-asset-holding vehicles: 25 · Overseas government bodies: 0 · NZ resident individuals: 300 · NZ resident entities: 0 · Non-resident individuals: 40 · Non-resident entities: 0
8.3Rank 1–5 the methods used to meet new customers — face-to-face, non face-to-face, domestic intermediaries, overseas intermediaries, otherFace-to-face: 1 (most common) · Non face-to-face: 2 · Overseas intermediaries: 3 · Domestic intermediaries: 4 · Other: 5 (not used)

Part 4 — Sector-specific questions

ItemQuestionAnswer
9.1Do you incorporate companies or form trusts or structures outside New Zealand?No
9.2The three most common jurisdictionsNot applicable
9.3Do you handle receipt and transmission of client money?Yes
9.4Do you manage client bank accounts?No
9.5Bearer-share physical control policies for overseas corporationsNot applicable
9.6Do you provide regulated services to other DNFBPs in New Zealand? (Yes / No / Unknown)Unknown
9.7Do you provide regulated services to overseas equivalents? (Yes / No / Unknown)No
9.8Do you use intermediaries or agents in New Zealand?No
9.9Do you use intermediaries or agents overseas?Yes — two overseas buyer's agents introduced purchasers during the period
9.10List the overseas countriesSingapore; China
9.11Have you received cash as part of a real estate transaction? How often, and how much in NZ dollars?No cash received as part of a real estate transaction during the period
9.12Do you provide residential property sales or services?Yes — residential property sales and services
9.13Do you provide commercial property sales or services? If both residential and commercial, the estimated percentage split.Yes — commercial property sales and services. Estimated split: 70% residential, 30% commercial

Part 5 — Ministerial exemption

ItemQuestionAnswer
10.1Have you been granted a ministerial exemption subject to conditions?No
10.2Describe your compliance with all conditionsNot applicable — no ministerial exemption held

3.3Part 6 — Declaration and signature

The declaration

This part is completed by the person submitting the report and by nobody else. It is a personal statement, made on that person's own authority, and section 103 makes it an offence to provide information to an AML/CFT supervisor knowing it to be false or misleading in any material respect.

The declaration reads:

"I confirm that I have the authority to submit this form on behalf of the reporting entity. I have reviewed the answers and information and I confirm that I am satisfied that, to the best of my knowledge, after undertaking all reasonable inquiries, all answers are true and correct."

The form carries a reminder that section 103 of the Act makes it an offence to provide information to an AML/CFT supervisor knowing it to be false or misleading in any material respect.

Date____________________________________
Signature____________________________________
Full name____________________________________
Position____________________________________

Before signing, the compliance officer confirms three things:

  1. Every answer above has been read and is true of this business — not approximately true, and not the answer that would look best.
  2. The reasonable inquiries the declaration refers to have been made. Where an answer is an estimate, the estimate is a fair one and the basis for it can be explained.
  3. No answer above is left unresolved.

Sources

Prepared from the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, the AML/CFT (Requirements and Compliance) Regulations 2011, the AML/CFT (Definitions) Regulations 2011, the Real Estate Agents Act 2008, and guidance published by the Department of Internal Affairs. DIA guidance and New Zealand legislation are Crown copyright and reproduced or paraphrased here for the client's compliance purposes.

  • DIA — Annual AML/CFT Report
  • DIA — AML Online
  • Real Estate Sector Risk Assessment 2026
  • Risk Assessment Guidance (July 2026)
  • AML/CFT Programme Guidance (2026)
  • Audit Guidance for risk assessment and AML/CFT programme (July 2026)
  • A guide to complying with the AML/CFT Act
  • Guideline: Real Estate Agents — Complying with the AML/CFT Act 2009 (Dec 2018)
  • Guidance: Customer Risk-Rating
  • Enhanced Customer Due Diligence Guidance (2026)
  • Beneficial Ownership Guidance (July 2026)
  • Identity Verification Code of Practice 2026
  • Assessing Country Risk Guidance (July 2026)
  • Wire Transfers and Prescribed Transaction Reporting Guidance (July 2026)
  • Interpreting 'Ordinary Course of Business' Guidance (July 2026)
  • Sight unseen property purchases AML/CFT advisory
  • DNFBPs and Casinos Sector Risk Assessment (Dec 2019)
  • Annual AML/CFT Report User Guide for DNFBPs (June 2021)
  • AML/CFT Act 2009
  • AML/CFT (Requirements and Compliance) Regulations 2011
  • AML/CFT (Definitions) Regulations 2011
  • Real Estate Agents Act 2008

4Customer Due Diligence Register

Southern Cross Property Group Limited

Snapshot as at 4 August 2026 — the customers of the business, and what has been established about each

DocumentCDD Register — snapshot
Snapshot as at4 August 2026
Version1.0
Maintained byMere Kingi
Maintained inthe Compliance Workbook — the register is kept current there, and this snapshot is reissued at each internal review
Governed bys.57(1)(c) of the AML/CFT Programme

4.1How this register works

One entry per customer. Each records who the customer is, who ultimately owns or controls it, and the risk rating with the reasoning for it. The Programme sets out the procedure; this register is the evidence that it was followed.

Each entry then sets out the parties — the customer, every beneficial owner, and every director or other person acting on the customer's behalf — with the detail that identifies each: the capacity they act in, the shareholding they hold, the date they were appointed.

The verification records are kept in the Compliance Workbook. What identity document was sighted and in what form, the date it was checked, the address check and the date of birth — those are recorded there, against each party, and amended as the work is done. This document does not carry them: it is the register's membership as at 4 August 2026, and a verification status printed into a page is out of date the day after it is printed and cannot be corrected there.

This document is a snapshot. It states the position as at 4 August 2026. The register itself is maintained in the Compliance Workbook, where entries are added as customers are taken on and updated as what is known about them changes. Where the two differ, the workbook is the current record and this is the position on the date above.


No customers recorded as at the date of this snapshot.



Sources

Prepared from the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, the AML/CFT (Requirements and Compliance) Regulations 2011, the AML/CFT (Definitions) Regulations 2011, the Real Estate Agents Act 2008, and guidance published by the Department of Internal Affairs. DIA guidance and New Zealand legislation are Crown copyright and reproduced or paraphrased here for the client's compliance purposes.

  • Real Estate Sector Risk Assessment 2026
  • Risk Assessment Guidance (July 2026)
  • AML/CFT Programme Guidance (2026)
  • Audit Guidance for risk assessment and AML/CFT programme (July 2026)
  • A guide to complying with the AML/CFT Act
  • Guideline: Real Estate Agents — Complying with the AML/CFT Act 2009 (Dec 2018)
  • Guidance: Customer Risk-Rating
  • Enhanced Customer Due Diligence Guidance (2026)
  • Beneficial Ownership Guidance (July 2026)
  • Identity Verification Code of Practice 2026
  • Assessing Country Risk Guidance (July 2026)
  • Wire Transfers and Prescribed Transaction Reporting Guidance (July 2026)
  • Interpreting 'Ordinary Course of Business' Guidance (July 2026)
  • Sight unseen property purchases AML/CFT advisory
  • DNFBPs and Casinos Sector Risk Assessment (Dec 2019)
  • Annual AML/CFT Report User Guide for DNFBPs (June 2021)
  • AML/CFT Act 2009
  • AML/CFT (Requirements and Compliance) Regulations 2011
  • AML/CFT (Definitions) Regulations 2011
  • Real Estate Agents Act 2008

5Working Tools

Southern Cross Property Group Limited

How the work gets done — new customers, red flags, training, goAML

DocumentWorking Tools
Version1.0
Prepared4 August 2026
Companion tothe AML/CFT Risk Assessment and Programme — this adds no obligation, it sets out how to meet the ones already there
OwnerMere Kingi

5.11. Taking on a new customer

Seven steps, in order. Steps 1 and 2 are the ones that go wrong: due diligence started too late, or the right documents never asked for.

Step 1 — Work out when due diligence falls due

It depends on the transaction, and getting this wrong is the most common failure in the sector. It is not "when we take the listing" for every deal.

When customer due diligence falls due depends on the type of transaction. For a commercial lease it must be completed before the lease agreement is presented to the landlord; for an assignment of lease, before the assignment is presented to the assignee; for a sublease, before the sublease agreement is presented to the outgoing tenant. For every other real estate transaction — a sale, most obviously — it falls due once there is a fully signed agency agreement, and before any further agency work is carried out for that customer. A conjunctional agent is outside this regulation.

Write the date the trigger falls on the file the day the engagement starts. That is the whole of the discipline — everything downstream is just doing the work before a date you already know.

Step 2 — Collect, by what the customer is

The customer isCollect
An individualFull name, date of birth and residential address, and the documents that evidence them.
A New Zealand companyCompanies Office extract (company summary and shareholdings); then identity for each beneficial owner and for the person you actually deal with.
An overseas companyThe equivalent extract from its own register of incorporation. The New Zealand register holds no shareholder data for an overseas company, so it cannot answer beneficial ownership — see Step 4.
A trustThe trust deed, and identity for the trustees, the settlor and the beneficiaries or class of beneficiaries. A trust is a mandatory enhanced due diligence trigger under s.22 — go to Step 6 before you go any further.
A partnership or other arrangementThe constituting document, and identity for those who own or control it.

Anyone acting on the customer's behalf is identified too, and so is their authority to act — a signed authority, a power of attorney, a directors' resolution.

Step 3 — Verify identity

Verification follows the Identity Verification Code of Practice 2026, which took effect on 1 July 2026 and now covers high-risk customers as well as low and medium. Following the Code is not mandatory; it provides a safe harbour, and this business has chosen to rely on it.

Name, date of birth and address, evidenced from documents. Date of birth is the one that catches people out: a companies register gives you a name and an address and never a date of birth, so an extract alone never completes this step.

Step 4 — Establish who ultimately owns or controls the customer

Beneficial ownership means the natural persons behind the entity — as a working threshold, anyone holding more than 25%, plus anyone who controls it by other means. Follow it up through holding companies until you reach people.

How much evidence depends on the rating you are heading for:

Assessed riskWhat will do
LowA written declaration from a director naming everyone over 25%, held on file. Use the Beneficial Ownership Declaration template.
Above lowAn independent source — a company extract from the register of the country of incorporation. A declaration is not enough.

Step 5 — Rate the customer, and write down why

Rate on the scale the risk assessment uses: Low, Medium-Low, Medium, Medium-High, High. The reasoning is the part that matters — a rating with no reasoning is the finding an auditor writes up, because it cannot be tested. Two or three lines naming the actual features: what kind of entity, where it is, how the ownership was established, whether any cash is involved, whether you have met them.

Non-residence is a risk factor, weighed here. It is not by itself an enhanced due diligence trigger — see Step 6 for what is.

Step 6 — Escalate where you have to

Enhanced due diligence is mandatory, whatever rating the customer would otherwise carry, where the customer:

  • is a politically exposed person, or has a beneficial owner who is one (s.22(2), s.26);
  • is a trust or another vehicle for holding personal assets;
  • is a company with nominee shareholders or shares in bearer form;
  • is a non-resident from a country with insufficient AML/CFT systems.

It also applies where the level of risk requires it (s.22(1)(d)) — so a High rating pulls it in on its own — and where the source of funds is not apparent from what you already know.

Enhanced measures: establish and verify source of funds and source of wealth; verify identity and beneficial ownership to a higher standard; watch the transaction through to settlement. Record the decision and the reasoning in the EDD Register tab.

And the hard stop. Where due diligence cannot be completed, the business does not establish or continue the relationship and does not carry out the transaction, and the compliance officer considers whether a suspicious activity report is required.

Step 7 — Write it down

A row in the CDD Register tab of the workbook for the customer, and one for each of their beneficial owners and anyone acting for them. The customer's row carries Type, Property / address, Company / ID numbers, Relationship, Transaction & date, How established, Risk rating, Reasoning, EDD required? (basis); every row carries what identity document you saw, whether it was an original, a properly certified copy or an electronic verification, the date, and the same for the address and the date of birth. Anything still to finish goes in the Outstanding column of the row it belongs to, and you delete it when it is done.


5.22. Red flags — desk card

Print this page and keep it where you take calls. These are the indicators in your risk assessment, in one glance. One flag is not a suspicion — it is a reason to look harder and to write down what you found. Several together, or one with no innocent explanation, is where the written findings and the reporting decision start.

Real estate transaction red flags (sale and purchase)

  • Transfer of real estate between parties in an unusually short time period.
  • The vendor and purchaser are known to each other or connected in some way without explanation.
  • There are unexplained changes in instructions, such as just before a settlement.
  • Client appears to be acting on somebody else's instructions without disclosing the identity of that person.
  • Property 'flipping' with back-to-back property transactions with rapidly increasing value and/or sales to related parties.
  • Client has unexplained wealth that appears inconsistent with their socio-economic profile.
  • A 'sight unseen' property purchase where the purchaser has not seen the property in person without a logical explanation.
  • Client is buying or selling property from overseas without a logical explanation – for example, they have dealings in New Zealand but no indication of being in New Zealand or intention to come to New Zealand.
  • Funding is provided by or to be repaid to a lender other than a bank or credit institution without logical explanation or economic justification.

Additional red flags specific to vendors

  • Client is willing to accept offer well below current market prices and/or appears disinterested in obtaining a better price.
  • Property is unencumbered, without explanation for this (including where a mortgage has been paid off rapidly).
  • Property is re-sold after significant renovation (without evidence of source of funding of the renovation project).

Additional red flags specific to purchasers

  • Payments of deposits or funds from unknown third parties.
  • Purchaser offers to pay real estate agent an unusually large deposit (or settlement payment) that is not necessary to secure the purchase.
  • The property being purchased is inconsistent with the socio-economic profile of the purchaser, including if the purchase appears to involve a disproportionate amount of private funding.
  • Use of nominees or complex structures for purchase of property.

Additional red flags for sale of commercial property or a business

  • Illegal activity being conducted (or suspected) on premises.
  • Appearance of manipulation of the appraisal or valuation of the commercial property or business.
  • Purchase and use of commercial property inconsistent with business purpose.
  • Suspicious behaviour of potential purchaser when shown property or business, including evasive when asked questions around intended use.
  • Use of complex loan structures or credit finance (such as loan back schemes).
  • Other gatekeepers or unknown persons appear to have full control of activity.

Trust account red flags

  • Funds received into trust account are not expected or more than expected (for example an overpayment of a deposit), with subsequent directions for their use or payment.
  • Funds paid into a trust account by a third party on behalf of the purchaser/non-client without legitimate explanation.
  • Payments into a trust account by cash deposit (at the real estate agent or third-party trust account provider's bank).
  • Unexplained or late changes in payment arrangements.
  • Requests to hold funds in a trust account for a longer time than is required by the conditions of the sale, with further instructions received subsequently.
  • Transaction occurs through a trust account of another gatekeeper in circumstances that are not expected.
  • Use of trust account for transactions that are more appropriately conducted directly from a client's bank account.
  • Funds received from or sent to high-risk countries, or other countries where there is no apparent connection to the client.

Behavioural red flags

  • Client is involved in a type of business not normally cash intensive but appear to have substantial amounts of cash.
  • Client whose instructions are unusual and/or with no apparent visible or economic purpose.
  • Client who appears to avoid face-to-face meetings.
  • Client is reluctant to provide identification or behaves nervously.
  • Client who appears to be acting on somebody else's instructions without disclosing the identity of that person.
  • Client asks for shortcuts or unexplained speed in completing a transaction or activity.
  • Identity or other verification documents provided are or look fraudulent.
  • Client enquiring into whether a service would be considered suspicious or require reporting to authorities.
  • An absence of documentation to support the client's stated reason for engaging the real estate agent, their previous transactions, or business activities.
  • Client who offers to pay extraordinary fees for services that would not warrant such a premium.
  • Client using a small or non-specialised real estate agent to provide specialised real estate agency work (for example commercial property or sale of a business).

Indicators the FIU has evidence of in this sector

  • A vendor avoiding or delaying customer due diligence, or declining to complete enhanced due diligence. This was the single most common reason real estate agencies filed a suspicious activity report (NRA 2024, p.46).
  • A property purchased and sold again within a short timeframe. The second most common reporting trigger (p.46), and separately observed in tax-offender investigations as 'multiple purchases on the same day' (p.47).
  • The purchase price appears manipulated between a vendor and purchaser who are acting in concert (p.46).
  • A legal structure — company, trust or nominee — used in a way that conceals who ultimately benefits, including nominee ownership used to navigate foreign buyer rules (p.46).
  • Property being bought in the name of a relative or associate of the person actually providing the funds (p.47, drug-offender investigations).
  • Purchase funds arriving from an offshore bank account, routed through a New Zealand lawyer's trust account (p.47, international money laundering investigations).
  • Renovation, or mortgage servicing, apparently funded with cash (p.46, p.47).
  • A client using a trust, where the reason for the arrangement is not explained (p.46, reported SAR reasons).
  • Offshore source of funds for the initial property purchase (p.46, reported SAR reasons).
  • Adverse media about the client; property sold below value; unusual or evasive behaviour; or a vendor with gang links (p.46, less frequent but recorded SAR reasons).
  • A client who may themselves be the victim of a scam or fraud (p.46, reported SAR reasons) — the obligation is to report the suspicion, not to judge who is at fault.

Property transaction red flags seen from the conveyancing side

  • A purchase made sight unseen, where the purchaser has not inspected and shows no interest in inspecting the property.
  • Back-to-back transactions in which the value rises rapidly between sales without any improvement to the property.
  • A vendor knowingly selling materially below market value.
  • Payment made by, or on behalf of, a third party with no explained connection to the transaction.
  • Vendor and purchaser are connected and the connection is not explained.
  • Instructions change unexpectedly shortly before settlement — a change of purchaser, of nominee, or of payment direction.
  • An unencumbered purchase with no bank finance, or funded by private lending, where the source of funds is not clear.

Sight unseen purchases

  • The customer shows interest in purchasing property without normal levels of interest in price, characteristics of the property, or other details.
  • A third party is acting on behalf of the customer, and the customer or beneficial owner is added to the sale and purchase agreement at the last minute.
  • The transaction does not match the customer's business or personal profile.
  • A property is bought and sold quickly.
  • The customer is reluctant to provide identity, or source of funds/wealth information and documentation.
  • Verification documentation is, or looks, fraudulent.
  • Unusual or complex ownership structure where beneficial ownership is hidden.
  • The customer is based in a country with a higher level of assessed ML/FT risk.
  • Payments received from bank accounts belonging to third parties who have no clear link to the customer.
  • Sale and purchase price are significantly undervalued or well above market price.
  • The customer intends to complete the sale without the use of a mortgage.

What to do with one. Ask the question the flag raises, and record the answer. If it resolves, write down that it resolved and why — that record is the point. If it does not, it goes in the Written Findings Register, and if you form a suspicion, the report is due within 3 working days (s.40(1)) and you must not tell the customer (s.46).


5.33. Annual training refresher

Print, work through, sign, file.

Everyone within the vetting scope completes this at induction and at least annually. Attendance is not evidence of understanding under s.57(1)(b), so the confirmations below are signed by each person rather than recorded as a headcount.

Re-read these three things. They are the whole refresher.

  1. The red flags — section 2 of this document, and section 9 of your risk assessment. Not to memorise; to recognise.
  2. When due diligence falls due — step 1 of section 1 above. The trigger differs by transaction type, and it is the thing most often got wrong.
  3. Tipping off — you must not tell a customer, or anyone else, that a suspicious activity report has been made or is being considered (s.46). Not a hint, not a delay you explain, not a reason given for declining. This is a criminal offence, and it is the one rule that feels unnatural in a relationship business.

Then confirm, by signing below:

  • I know at what point customer due diligence falls due for each type of transaction this business does, and that it must be complete before that point, not alongside it.
  • I know how to identify the beneficial owners of a company or a trust customer, and that a companies register alone does not verify identity.
  • I know the red flags in section 2, and that the response to one is to ask and record, not to ignore and not to accuse.
  • I know that a suspicion must be reported through goAML within 3 working days, and that I must not tell the customer.
  • I know that where due diligence cannot be completed, the transaction does not proceed.
Name
Role
Date of this session
Materials usedThis page; the AML/CFT Risk Assessment; the AML/CFT Programme
Signature

File the signed page, and enter the session in the Training Register tab of your workbook — date, topic, delivered by, attendees, materials, how understanding was confirmed. The register is the index; this page is the evidence behind the entry.


5.44. Registering for goAML

goAML is the Police Financial Intelligence Unit's reporting system. It is separate from AML Online — AML Online is the Department's, for enrolment and the annual report; goAML is where suspicious activity reports and prescribed transaction reports go. Registration is not needed to file the annual report.

Do it before you need it. A suspicious activity report falls due within 3 working days of forming the suspicion. Registration is not instant — the FIU has to approve it — so the day a suspicion arises is the wrong day to start.

StepWhat to do
1Confirm your reporting obligations with your sector supervisor first. The FIU asks you to do this before registering; for this business the supervisor is the Department of Internal Affairs.
2Go to https://fiu.police.govt.nz and choose Register as an Organisation. The entity registers first — the FIU's own wording is that "in order to get access to the system, you first need to register as a reporting entity under 'Register as an Organisation'".
3Then register each person who will use it, as a user of that registered entity. The Help page carries two separate guides — one for registering a new reporting entity, one for registering a new user for an existing entity. Download both before you start.
4Wait for the FIU. They contact you once the set-up is complete and your access has been established. The FIU publishes no turnaround time, so do not plan around one — this is the step that makes "do it before you need it" the whole point.
5Log in with the credentials you set during registration, and check the Resource Library — the ? icon on the task bar inside goAML.

Stuck: goaml@police.govt.nz. There is an FAQ document on the Help page worth reading before you email.

Then put it on the checklist. Once you are registered, the annual job is simply to log in and confirm the access still works — it is already a row on your Compliance Officer Checklist, dated alongside the AML Online login check for the same reason.


5.5The Word documents that come with this pack

All editable — change anything you want to before you use them:

  • CDD Request Letter — what you send a customer to ask for identity and ownership documents. It mentions the legal requirement once and then gets on with the list, because a letter that reads like an accusation is the one that loses the listing.
  • Beneficial Ownership Declaration — the form a director signs naming everyone who holds more than 25%. This is the instrument that satisfies Step 4 for a low-risk customer; keep the signed original on the customer file.
  • Compliance Officer Designation — the letter designating the compliance officer under s.56, with an acceptance block they sign and return. Date it the day you approve the risk assessment and the programme — s.56 requires the designation, and this is the record that it was made and accepted.

Prepared under the AML/CFT Act 2009 for Southern Cross Property Group Limited, for approval by its AML/CFT compliance officer. Not legal advice.

New Zealand legislation and Department of Internal Affairs guidance are Crown copyright, reproduced or paraphrased here for the client's compliance purposes.