The Single Supervisor Transition is not the only change arriving on 1 July. The Identity Verification Code of Practice 2026 (IVCOP), approved by notice in the New Zealand Gazette on 28 May 2026, replaces the 2013 code on the same date — and it applies to all reporting entities. If your customer due diligence procedures still reference the 2013 code, they will be out of date within weeks.
What the new code covers
The code sets out suggested best practice for verifying the full name and date of birth of customers who are natural persons, beneficial owners, and persons acting on behalf of customers. It establishes four verification pathways: face-to-face verification using physical documents, verification through the Digital Identity Services Trust Framework (DISTF), other electronic identity verification methods, and certified copies of identity documents.
What is new
The 2026 code modernises identity verification in several practical ways. It introduces a pathway for digital identity credentials accredited under the DISTF. It updates the electronic verification options — including a verified RealMe identity, the DIA Confirmation Service, validation of e-passport microchips, and the NZTA Driver Check combined with a second independent source. It also refreshes the lists of acceptable identity documents and updates the certified copy requirements, including that certification must have been carried out within the twelve months preceding presentation. Note that some certified copy provisions (paragraphs 1.4.3 to 1.4.5) do not commence until 1 July 2027.
A safe harbour, not a mandate
Complying with the code is not mandatory, but full compliance operates as a safe harbour. A reporting entity that opts out must verify identity by some other equally effective means and must notify its AML/CFT supervisor in writing. For most businesses, aligning with the code is the simpler and safer path.
What to do before 1 July
Review your CDD and onboarding procedures against the new pathways, update your AML/CFT programme documentation where it references the 2013 code, and make sure staff who conduct identity verification understand what has changed. This fits naturally within your SST preparation — both take effect on the same day.
If you would like help checking your identity verification procedures against the new code, this is exactly the kind of gap a Strategi compliance review is designed to identify before it becomes an audit finding.
Check your CDD against the new code — book a Strategi review.