The updated Identity Verification Code of Practice (IVCOP) has now been released, with changes coming into effect on 1 July 2026.
While legislative change can sometimes feel disruptive, these amendments offer a more effective balance between operational costs and money laundering risk management.
It represents a move towards a more risk-based approach (something we shouldn’t be surprised at), which if implemented effectively could provide a more flexible approach to identity verification.
Here’s our breakdown of what’s changed, what it means in practice, and what you need to do next.
The key changes
1. Documentary verification streamlined
- Documentary verification applies only when meeting clients in-person, so you can compare the identity documentation to the individual.
- The existing list of identity documents (or combination of documents) for identity verification remains, with the addition of the Kiwi Access card, alongside an 18+ card becoming acceptable secondary or supporting forms of photographic identification.
- The signature page of overseas passports is no longer required.
- Signature requirements for bank documents have been removed.
- The requirement for a New Zealand birth certificate to be a full birth certificate has also been removed.
In our view, these are sensible, practical changes that help to reduce unnecessary friction without compromising the integrity of the in-person verification process but should be supported with robust risk assessment processes.
2. Certification changes
- The photograph on the certified copy must be clearly visible.
- Trusted referees are only required to certify the copy matches the original. However, you must separately demonstrate the robustness of the process to bind the person being dealt with to that identity.
- Overseas referees must be equivalent to NZ referees.
- Certification validity has extended from three to 12 months.
If you’ve been reliant on using certified copies for identification purposes, your onboarding workflows will need to be reconsidered and changes documented.
On the plus side the extension of certification validity is a welcome change for many businesses, making onboarding easier without exponentially increasing risk.
3. Simpler electronic identity verification
- Where a customer’s name is verified using a government agency source such as the DIA Confirmation Service, only one matching data source is now required. The old requirement to obtain a second corroborating electronic source has been removed.
- Embedded e-passport microchips in NZ and overseas passports are now accepted as reliable sources.
This will simplify the EIV process while still adhering to a risk-based approach, recognising that government sourced data is inherently reliable and doesn’t need to be corroborated in the same way that commercial data sources do.
It also allows reporting entities to take advantage of advances in technology to help reduce the regulatory burden.
4. A fourth verification pathway is introduced (DISTF accredited providers)
The Digital Identity Services Trust Framework (DISTF) enables New Zealanders to share their personal information safely and securely, and for reporting entities who need this information to rely on it.
- Verification of a customer’s name and date of birth through an accredited DISTF provider may be conducted in person or online.
For reporting entities, this opens up a new route to compliance, in addition to existing routes – original documents, certified copies, and electronic sources.
5. IVCOP now applies to high-risk customers
Previously, the IVCOP applied only to customers assessed as low to medium risk. The updated code extends the same framework to high-risk customers.
- The verification of name and date of birth is required for customers rated high-risk.
We believe this is a positive development, helping to ensure a consistent approach to compliance is taken across the whole customer base.
6. Reduced verification requirements on beneficial owners and persons acting on behalf
A risk-based tiered approach to verify beneficial owners and persons acting on behalf is being introduced. This means the extent of verification steps required depends on the level of risk you have associated with your client.
Beneficial owners and/or persons acting on behalf of customers rated as high-risk are subject to the IVCOP in full. However, for a customer rated low or medium risk, a lesser verification requirement applies.
This seems to be a sensible solution, balancing the need to protect against money laundering with the impacts to reporting entities. However, it requires a robust risk rating process which is consistently applied by all relevant staff members.
7. Wire transfer simplification
Reporting entities are no longer required to re-verify the name and date of birth of a wire transfer originator if they have already conducted customer due diligence (CDD) on that person as a customer — unless there are reasonable grounds to doubt the adequacy of the earlier verification.
This removes a layer of duplication that has frustrated many compliance teams and has no real risk-reduction benefit when the customer is already known.
8. Expanded exception handling
- Exception handling procedures include customers whose name and date of birth is being verified through any part of the IVCOP.
- Reporting entities must consider whether there are legitimate reasons a customer has not been able to meet verification requirements and may, in appropriate circumstances, waive those requirements.
This reflects a more mature, risk-based approach to compliance which recognises that rigid application of rules can sometimes create barriers for vulnerable or marginalised customers without materially improving AML outcomes.
What you should do now
The updated IVCOP will be in force from 1 July 2026. Here’s a practical checklist to get ready:
Review and update your AML/CFT programme and risk assessment
Your policies, procedures and controls must reflect the new IVCOP. This isn’t optional, if your programme still references the old code after 1 July 2026, it needs updating. Consider whether your identity verification and onboarding processes will change and if you will be using new technology.
Keep a clear record of what is changing, when it changed, who approved it, and why the change was made. That record will help with audits, reporting, and supervisor questions later.
Revise your certification processes
Certification allows you to accept copies of identity documents certified by a trusted referee. However, you must have appropriate procedures in place to provide identity assurance.
The DIA states that:
“A reporting entity must incorporate procedures, policies and controls that provide enhanced assurance that the person being dealt with is the genuine holder of claimed identity where there are reasonable grounds for a concern that a copy may not be genuine.”
Review your approach to beneficial owners and persons acting on behalf
The new guidance provides more flexibility, but also requires more deliberate, risk-based thinking. Make sure your processes reflect the updated requirements.
Ensure your exception handling procedures are fit for purpose
Exception handling now applies across all IVCOP parts. Your programme should include clear, documented processes for how exceptions are identified, assessed and handled.
Update your staff guidance and training
With an increasingly risk-based regime, your team needs to be consistent in their approach to identifying risk. Make sure they understand what information needs to be collected and recorded, and how to identify red flags. Consider how you approach risk in your business, and the controls that need to be applied.
Ensure your team understands the new rules and how to apply them correctly in your day-to-day operations.
Below is an overview of verification pathways and when to use them.
Final thoughts
The updated IVCOP doesn’t exist in isolation. It sits alongside a broader programme of AML/CFT reform in New Zealand. These include amendments to the AML/CFT Act that came into force in late 2025 such as the introduction of customer risk ratings, and the removal of proof of address requirements for low-medium risk clients.
These reforms represent an attempt to modernise New Zealand’s AML/CFT framework, making it more efficient, increasingly risk-based, and signals the regulator’s confidence in trusted digital identity sources.
At tic, we work with reporting entities every day to navigate exactly these kinds of changes. If you’d like to talk through what the updated IVCOP means for your business, or assess what changes you need to make to your compliance framework, we’re here to help
About the author
Joel Meiklejohn
Joel is a Compliance Officer at tic, specialising in AML/CFT operations, customer risk assessment, and practical compliance delivery.
He brings hands-on experience across onboarding, transaction monitoring, and case analysis, with a strong focus on applying regulatory requirements in real-world operational environments. Prior to joining tic, Joel worked in merchant services, making risk-based decisions on customer applications, which adds a valuable commercial lens to his compliance approach.