Short answer: If your firm handles identity verification, make sure the technology trail is clean: where records are stored, who has access, how supplier portals are controlled, and how audit evidence can be found without relying on one person's inbox.

What this helps you check

Use this as a practical technology review, not as an AML/CFT compliance checklist.

  • Identity record storage, retention, and sharing settings
  • Supplier portal access, MFA, and administrator ownership
  • Audit evidence, exception notes, and process ownership

On 1 July 2026, the Department of Internal Affairs became New Zealand's sole AML/CFT supervisor. DIA also released a large suite of new and updated AML/CFT guidance, including material on customer due diligence, beneficial ownership, outsourcing, reliance on another reporting entity, audit guidance, and the Identity Verification Code of Practice 2026.

This article does not interpret the AML/CFT Act, the new Code, or any firm's obligations. That work belongs with the right legal, regulatory, or AML/CFT adviser. The EQIQ point is narrower: identity verification and audit readiness depend on everyday technology systems, and those systems need clear ownership.

For legal, financial, accounting, and advisory firms, the practical risk is rarely one dramatic system failure. It is more often a quiet mix of shared folders, email attachments, old exports, supplier portals, exception notes, former-staff access, and unclear retention habits.

The current NZ signal

DIA's 1 July 2026 release says the Department has released 23 pieces of AML/CFT guidance and supporting material as it becomes the sole AML/CFT supervisor. DIA's AML/CFT homepage also states that from 1 July 2026 it supervises all reporting entities under the Act.

DIA's sector pages list July 2026 updates across customer due diligence, beneficial ownership, outsourcing, reliance on another reporting entity, wire transfers, audit guidance, territorial scope, country risk, and designated business group material. The Identity Verification Code of Practice 2026 also commences on 1 July 2026.

Those are regulatory materials. The safe technology takeaway is simple: when guidance changes, the systems that hold identity records and evidence should be easy to understand, secure, and reviewable.

1. Find where identity evidence actually sits

Start with reality, not the policy. Identity material may sit in a practice-management system, onboarding platform, AML supplier portal, SharePoint library, Teams channel, scanned PDF folder, email thread, or a staff member's downloads folder.

Map the locations before changing anything. If records are scattered, decide which system is the source of truth and which copies are temporary working files. That makes access review, retention, and incident response much simpler.

2. Check access before adding more process

Identity records can be highly sensitive. Firms should know who can view, upload, export, delete, or share the material, and whether that access still matches current roles.

In Microsoft 365, check SharePoint permissions, Teams membership, guest users, broad sharing links, mailbox delegates, and any synchronised local folders. In supplier portals, check named administrators, former staff, MFA settings, and whether shared accounts are still being used.

3. Keep exception notes findable and controlled

Most firms have occasional exceptions: a client cannot provide the expected document, a beneficial-owner record needs follow-up, or an adviser needs to record why a process took a different path.

The technology question is where those notes live. If they sit only in email or handwritten notes, they may be hard to find later. A controlled case note, task, or document record is usually easier to review than a trail scattered across inboxes.

4. Review supplier and outsourcing access

DIA's July release includes updated material on outsourcing customer due diligence requirements and reliance on another reporting entity. Again, this article is not interpreting those documents. The technology issue is that supplier-supported workflows still need internal oversight.

Check who owns the supplier relationship, who can access the portal, who approves new users, how evidence is exported, how support requests are logged, and what happens if the supplier account is compromised or unavailable.

5. Make audit evidence practical to produce

Audit readiness should not depend on someone remembering the right folder name. A firm should be able to locate current process documents, system access lists, sample evidence, exception logs, supplier records, and previous review notes without a long search through personal mailboxes.

That does not require a heavy system. It does require sensible structure, consistent naming, limited access, and a clear owner for keeping the evidence pack current.

6. Treat AI summaries with care

AI tools can help summarise public guidance or draft internal questions. They should not be used casually with identity documents, client files, personal information, or AML/CFT evidence unless the firm has approved the tool and understands where the information goes.

For Microsoft 365 Copilot or similar tools, permissions matter. If old folders are too broadly shared, AI-connected tools may make that exposure easier to see. Clean access is the foundation for safer AI use.

What should firm leaders do this month?

A calm first step is to ask six technology questions:

  • Where do identity records and verification evidence live today?
  • Who can access, export, delete, or share those records?
  • Which supplier portals support the workflow, and who administers them?
  • Where are exception notes and review decisions recorded?
  • Can audit evidence be produced from a controlled location?
  • What would the firm do if a supplier portal, mailbox, or document store became unavailable?

If the answers are unclear, start with a focused records and access review. Keep legal, regulatory, and AML/CFT interpretation with the right advisers, and make the technology evidence trail easier for them to rely on.

Common questions

Is this article AML/CFT compliance advice?

No. It is general technology-risk information about systems, records, access, and supplier governance. Firms should take appropriate legal, regulatory, or AML/CFT advice for their own obligations.

Why does identity verification create a technology governance issue?

Identity verification often involves sensitive records, supplier portals, administrator access, evidence files, and retention decisions. Those are technology and information-governance issues even when the regulatory interpretation sits elsewhere.

What should firms check first?

Start with where identity records are stored, who can access them, which suppliers support the workflow, how evidence is retained, and whether audit material can be produced without relying on one person's inbox or desktop.

Source note

This article is based on official Department of Internal Affairs material: New Era for AML/CFT regulation as DIA Launches Comprehensive Guidance Suite (1 July 2026), the DIA AML/CFT homepage stating DIA became sole AML/CFT supervisor from 1 July 2026, and DIA sector guidance pages listing July 2026 updates including the Identity Verification Code of Practice 2026, customer due diligence, outsourcing, reliance, and audit guidance. Sources were checked on 13 July 2026.

Compliance note: This article is general information only. It is technology-risk and information-governance guidance, not legal advice, not financial advice, not regulatory advice, not AML/CFT advice, not privacy advice, and not compliance advice. Firms should take appropriate professional advice for their own obligations and circumstances.