iGaming AML/KYC: What Regulators Actually Check (2026)
iGaming AML/KYC in 2026 — the MLRO, CDD/EDD tiers, source-of-funds checks, transaction monitoring, sanctions screening and SAR reporting regulators actually.
Contents
Most operators think the gambling licence is the finish line. It isn’t — it’s the entry ticket. What keeps a licence alive is the anti-money-laundering file behind it, and that is the thing regulators actually come back to inspect. An application is a snapshot; the AML programme is what they test in the years that follow, and it is where suspensions, fines and revocations come from.
In our practice building compliance frameworks across offshore and tier-1 regimes, the pattern is consistent: applications pass on paper, then operators get caught out because the programme they filed was never really run. This is the substance — what an AML/KYC programme for an online casino must contain, and what an inspector will genuinely check.
The MLRO: the person the whole file hangs on
Every serious regime requires a named Money Laundering Reporting Officer, and in most a regulator must approve them as a key person before they take the role. The MLRO owns the programme and files suspicious activity reports to the jurisdiction’s financial intelligence unit. The mistake we see most is treating this as a title rather than a function — appointing someone junior, offshore and disengaged. Regulators probe exactly this. The MLRO needs seniority to challenge the commercial side, genuine independence, and real access to customer and transaction data. When an inspector asks who decides to file a SAR and how that decision is documented, a name on an org chart with no evidence behind it is a finding.
The risk assessment nobody wants to write
Before a single customer is onboarded, a regulated operator must produce a documented business-wide risk assessment: which products, customer types, geographies and payment methods carry the most laundering risk, and how controls are calibrated against them. This is the foundation the rest of the programme is built on, and it is the document operators most often skip or copy. Everything downstream — where you set EDD thresholds, which countries you refuse, how hard your monitoring runs — has to trace back to it. An inspector who finds tiered controls with no risk assessment explaining why they are set where they are has found a programme built on sand.
CDD and EDD: the tiers regulators expect
Customer due diligence is not one gate applied equally. It is tiered by risk, and the tiering is exactly what an audit examines. The table below is the shape of a defensible model — the thresholds vary by jurisdiction and by your own risk appetite, but the logic is constant.
| Tier | What it requires | Typical trigger |
|---|---|---|
| Simplified (SDD) | Basic identity verification; light monitoring | Low-risk, low-value play within defined limits |
| Standard (CDD) | Verified identity, age and address; watchlist screening; ongoing monitoring | The default for every onboarded customer |
| Enhanced (EDD) | Source of funds and source of wealth, senior sign-off, closer monitoring | PEPs, high-risk geographies, deposits or losses over threshold |
| Prohibited | No onboarding; exit if discovered mid-relationship | Sanctioned persons, banned jurisdictions, unresolved red flags |
The decisive tier is EDD. It is triggered by a politically exposed person, a customer from a high-risk or sanctioned jurisdiction, unusual funding, or a player crossing a monetary threshold in deposits or losses. EDD means going past identity to establish where the money and the wealth come from — with senior sign-off to onboard or continue, and heightened monitoring for the life of the account. Get the trigger logic wrong and you either bleed good customers through friction or, far worse, let high-risk money through unchecked.
Source of funds and source of wealth: the most-tested section
If an inspector opens one part of your file at random, it is this. Source of funds explains where the specific money being staked came from — a salary, a property sale, a documented crypto disposal. Source of wealth explains how the customer built their overall net worth. Regulators do not accept the customer’s assertion; they expect evidence on record: payslips, bank statements, sale contracts, tax filings. The classic enforcement case is a high-spending player allowed to lose large sums with no SoF/SoW file behind them. This is where “responsible gaming” and AML overlap — affordability and source-of-funds checks protect the vulnerable customer and satisfy the money-laundering rulebook at the same time. Build the two as one workflow, not two.
Transaction monitoring, PEP and sanctions screening
A programme that verifies identity at onboarding and then stops watching is not a programme. Ongoing transaction monitoring — automated where volumes justify it — flags the patterns that matter: structuring deposits under thresholds, rapid deposit-and-withdraw with minimal play, chip-dumping between accounts, and funding that does not fit the customer’s established profile. Alerts have to be reviewed by a human, and that review has to be recorded. Alongside monitoring runs continuous screening: every customer checked against sanctions lists (OFAC, UN, EU, UK) and PEP databases, not once at signup but on an ongoing basis as lists change. Screening only at onboarding is a gap inspectors specifically look for, because sanctions designations happen after a customer is already through the door.
Record-keeping and SAR reporting
Two obligations that sound administrative and are anything but. Records — identity documents, due-diligence files, transaction histories, the reasoning behind decisions — must be retained for a defined period (commonly five years after the relationship ends) and be producible on demand. And when a genuine suspicion arises, the MLRO must file a suspicious activity report to the financial intelligence unit, usually within a fixed window and without tipping off the customer. The absence of SARs is itself a red flag to a regulator: a live operator that has never filed one is either not looking or not reporting, and both are findings. Keep the decision trail even where you decide not to file — the reasoning is as important as the report.
Two obligations sit alongside these and are easy to overlook until an inspector asks for them. The first is training: staff who touch onboarding, payments or player accounts must be trained on the AML programme, and you must be able to show a dated record of who was trained on what. The second is independent testing — a periodic review of the programme by someone other than the people running it, whose findings feed back into the risk assessment. FATF-aligned regimes expect both, and their absence tells a regulator the programme is theoretical rather than lived.
Crypto casinos: the same duties, plus virtual-asset rules
A crypto casino inherits every obligation above and adds a layer specific to virtual assets. Wallet addresses must be screened with blockchain analytics against known illicit sources — mixers, sanctioned addresses, darknet markets — and against sanctions lists in their own right. And the FATF Travel Rule applies: for transfers above the threshold, originator and beneficiary information must be collected and transmitted. The on-chain ledger is traceable, which helps, but regulators want a documented programme, not a claim that “the blockchain is transparent.” The same AML backbone underpins crypto-native regimes too, from a crypto casino licence to the frameworks explained in VASP, CASP and MiCA compared. If you are structuring crypto play, plan the Travel Rule tooling into the build from day one.
How this connects to the rest of the launch
The AML programme does not sit in isolation. The regime you choose sets the intensity of every control above — an offshore permit and a tier-1 licence expect very different depth, which is the real subject of offshore vs onshore gambling licences. It ties directly to banking: EMIs and payment providers underwrite your AML maturity before they onboard you, which is why weak compliance is a leading reason high-risk banking fails and why the payment stack has to be planned alongside the file, not after. And it is inseparable from the licence itself — the programme is a core pillar of how you get the gambling licence in the first place. Get all four moving together and the launch holds.
An AML/KYC programme built to be genuinely operated — not to pass one review — is what separates operators who keep their licences from those who lose them. If you want the framework built right the first time, and matched to the gaming licence that fits your model, book a free consultation.
Frequently asked questions
What does an iGaming AML/KYC programme have to contain?
Six load-bearing parts: a named MLRO with real authority, a documented business-wide risk assessment, tiered customer due diligence (CDD and EDD), ongoing transaction monitoring, PEP and sanctions screening, and record-keeping plus suspicious-activity reporting. Regulators expect written policies, evidence they are actually operated day to day, and a training and audit trail — not a downloaded template that sits unused.
Who is the MLRO and does an online casino really need one?
The Money Laundering Reporting Officer is the named individual accountable for the AML programme and for filing suspicious activity reports to the financial intelligence unit. Yes — almost every regulated regime requires one, and many require they be approved as a key person. The MLRO must be senior enough to challenge the business and have genuine independence, resources and access to customer data.
When do I need to run enhanced due diligence (EDD)?
EDD is triggered by higher risk: politically exposed persons, customers from high-risk or sanctioned jurisdictions, unusual funding patterns, or players whose deposits or losses cross defined monetary thresholds. It means going beyond identity — establishing source of funds and source of wealth, senior sign-off to onboard or continue, and closer ongoing monitoring for the life of the relationship.
What are source-of-funds and source-of-wealth checks?
Source of funds explains where the specific money being wagered came from — salary, a property sale, a documented crypto disposal. Source of wealth explains how the customer accumulated their overall net worth. Regulators expect evidence, not the customer's word: payslips, bank statements, sale contracts. For high-spending players these checks are the single most tested part of an AML file.
How is AML/KYC different for a crypto casino?
A crypto casino carries everything a fiat operator does plus virtual-asset duties: blockchain analytics to screen wallet addresses against known illicit sources, sanctions screening of addresses, and the FATF Travel Rule — collecting and transmitting originator and beneficiary information on transfers above the threshold. On-chain traceability helps, but regulators expect a documented programme, not reliance on the ledger alone.
Can a weak AML programme cost me my gambling licence?
Yes — it is one of the most common reasons licences are suspended or revoked and fines are issued. Regulators audit the live programme, not just the application file. Missing SARs, no evidence of monitoring, an MLRO in name only, or CDD gaps found on inspection are enough to trigger enforcement. The AML file is what actually keeps a licence alive after issuance.
Sources
This article is for general informational purposes only and is not legal, tax or financial advice. Consult a qualified professional before acting.
Licence, done right.
300+ licences obtained across 40+ jurisdictions. Book a free consultation.
Book a free consultation