New DIA Sector Risk Assessment: Key findings for accounting practices
The Department of Internal Affairs (DIA) has issued a new Sector Risk Assessment (SRA) covering the accounting, trust and company service provider, and insolvency sectors.
The new SRA is substantially more detailed than the previous assessment and provides useful insight into the risks identified by the DIA, as well as some of the common compliance issues it has identified through its supervisory work.
Overall sector risk ratings
The new SRA assigns the following overall inherent risk ratings:
Accounting and insolvency sectors
Money laundering: Medium
Terrorism financing: Low
Proliferation financing: Low
Trust and company service providers
Money laundering: Medium
Terrorism financing: Medium-High
Proliferation financing: Medium-High
The higher terrorism financing and proliferation financing ratings for trust and company services reflect the potential for bad actors to use these services to establish opaque or complex legal structures in New Zealand, which can be used to facilitate or conceal their activities.
Risk ratings by service
One particularly useful aspect of the new SRA is its more granular assessment of the services provided by accounting practices.
The DIA provides inherent risk ratings and relevant risk information for services such as managing client funds, insolvency services, trust and company services and tax-related services. Each service is also accompanied by potential red flags that may help reporting entities identify circumstances requiring closer attention.
This is a useful resource for accounting practices when reviewing their own enterprise-wide risk assessment and their client risk rating.
Residual risk
The SRA also discusses residual risk, which is risk remaining after mitigation measures have been taken into account.
Accounting practices may find it useful to incorporate residual risk into their own risk assessment methodology. However, the AML/CFT Act does not require reporting entities to calculate or document residual risk as a separate risk rating.
What the DIA is seeing in practice
The SRA provides some interesting statistics from the DIA's supervisory work. Between 1 October 2018 and 31 December 2025, the DIA conducted 244 off-site desk-based reviews or on-site inspections of accounting practices. The DIA reports that:
Almost all accounting practices known to it have appointed a compliance officer and have a written risk assessment and AML/CFT programme.
Some, particularly larger practices, have established strong training, governance and compliance frameworks. In other practices, the DIA has identified less robust frameworks, including compliance officers with limited understanding of the relevant risks or insufficient commitment to AML/CFT obligations.
There are circumstances in which accounting services are subject to the AML/CFT Act that are not always understood. It is in these practices that the DIA has typically identified more significant AML/CFT non-compliance.
For the year ending 30 June 2025, approximately 89% of accounting practices known to the DIA that were required to submit an annual report did so. The annual reports generally indicate that risk assessments and AML/CFT programmes are being reviewed, independently audited and kept up to date. However, 35% of annual reports indicated that an independent audit had not been completed. Moreover, the DIA also identified situations where adverse findings from independent audits had not been remediated, as well as cases where annual report information was incomplete.
Accounting practices are not required to register with the DIA as their AML/CFT supervisor. As a result, the DIA must proactively identify accounting practices that do not make themselves known when they commence operations or become reporting entities. Given the size and diverse nature of the sector, it is likely that not all accounting practices are known to it or subject to active AML/CFT supervision.
What’s next?
Get in touch if you have any questions about the new SAR.