- Updated:
- Published:
Anti-money laundering (AML) policy
A player deposits €15,000 in prepaid vouchers across four bank accounts in sixteen days. Automated risk scoring never flags the pattern. Six months later, the regulator opens a case — real and documented in the Videoslots enforcement action.
An AML policy tells an operator how to identify customers, monitor money flows, escalate risk, and report suspicion. Without it, no licence clears and no regulator treats the operator as fit to hold a permit. KYC proves identity; AML adds monitoring, sanctions screening, and SAR obligations. This article covers policy components, regulatory pressure, and links to verification and registration.
What is an AML policy?
At its core, an AML policy translates legal obligation into daily procedure. The FATF classifies casinos and online gambling operators as Designated Non-Financial Businesses and Professions (DNFBPs). Member jurisdictions must apply customer due diligence, transaction monitoring, and suspicious activity reporting comparable to banks.

For an iGaming operator, the policy document typically covers eight interlocking components:
- Enterprise risk assessment — mapping products, geographies, payment rails, and player types to ML/TF exposure
- Customer identification and verification — the operational face of KYC
- Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) — ongoing profiling with step-up checks for high-risk players
- Transaction monitoring — automated and manual review of deposit, wager, and withdrawal patterns
- Sanctions and PEP screening — against OFAC, EU, UN, and domestic lists
- Suspicious Activity Reporting (SAR/STR) — filing to the Financial Intelligence Unit (FIU)
- Governance — MLRO appointment, staff training, independent audit
- Record-keeping — retention of KYC files, transaction logs, and investigation notes
Curaçao’s regulations, effective April 2025, require every licensed casino to publish a policy statement that “sets the tone for the organization” and references NOIS, NORUT, and sanctions ordinances by name. The bar is no longer offshore paperwork; it is auditable control design.
Why is AML policy important?
Regulators have moved from checkbox compliance to volume enforcement. The UKGC reported 9,700 compliance activities in 2024/25 — more than double 2023/24. It fined 24 operators £4.2M in the same period.

The fine total fell 68.6% from £13.4M in 2023/24. The Commission described that as a potentially positive sign. The activity count tells a different story: scrutiny intensified even as headline penalties dropped.
A Lexology review of 88 UKGC cases found AML breaches and social responsibility failures in the vast majority of actions.
Licensing makes the policy concrete. Every serious jurisdiction demands an AML/CTF policy at application stage — see the licensing guide. The UKGC has issued penalties exceeding £10M for AML failures.
Singapore’s 2023 case linked gambling to unlicensed lending and fraud. MAS imposed S$27.45M in composition penalties on nine financial institutions in July 2025. Operators who treat AML as a PDF in a data room inherit that reputational tail risk.
How does an AML policy work?
Risk-based approach
Every modern framework starts with proportionality: controls must match assessed risk. Spelinspektionen defines low-risk customers as those below SEK 20,000 in deposits or stakes over twelve months. Above that threshold, deeper scrutiny applies.

The EU’s AMLR introduces a harmonised €2,000 CDD threshold from 10 July 2027. A new EU-level AML Authority (AMLA) will supervise high-risk obliged entities. Multi-market operators should treat 2027 as a hard migration date.
KYC, CDD, and EDD
KYC establishes who the player is. CDD builds the risk profile from identity, behaviour, payment methods, and geography. EDD activates when risk rises: PEP status, high velocity, geographic mismatch, or inability to verify source of funds.
EDD almost always means source of funds (SoF) or source of wealth (SoW) verification. The Betfred penalty cited SoF thresholds of £15,000 in losses or £125,000 in stakes as too high to be risk-based. Thresholds set for convenience become enforcement exhibits.
Under UKGC rules, verification must complete before any gambling or deposit. MGA and certain offshore licences allow limited play first. Pre-play verification remains the safest default.
Transaction monitoring
Monitoring runs at deposit, during play, and at withdrawal — not only when the player asks for cash out. Swedish guidance explicitly requires measures at the point of deposit. A player who cannot explain where the money came from may need an STR even if they never reach the cashier withdrawal step.

Common red flags that trigger review or SAR consideration:
- Structuring — multiple deposits just below reporting thresholds
- Minimal play — large inbound funds, few bets, rapid outbound transfer
- Deposit-withdrawal cycling — funds pass through the wallet without genuine gambling activity
- Payment rail mismatch — deposit via one method, withdrawal to another (mitigated by closed-loop policies)
- Geographic inconsistency — stated residence, IP, and document country diverge
The gambling sector accounted for 9% of all STRs filed in Sweden in 2023. Report quality matters as much as volume: the FIU rejects submissions missing basic data or failing to explain why behaviour looked suspicious under the goAML structure.
Sanctions, PEP screening, and reporting
The AGA requires operators to screen patrons against OFAC and SDN lists at onboarding and block account creation on a match. Screening continues throughout the relationship — not a one-time gate.
When suspicion crystallises, the operator files a SAR/STR with the national FIU. Tipping off — informing the subject that a report was or will be filed — is a criminal offence in the UK and most FATF-aligned jurisdictions. Internal escalation routes must keep front-line staff, VIP hosts, and affiliate managers away from the subject until the MLRO decides.
Governance, training, and records
Curaçao requires policies referencing specific statutes. Sweden requires training programmes scaled to the operator’s risk assessment, with MLRO and independent review functions mandatory once annual stakes before paid-out winnings exceed SEK 50M.
Records — KYC documents, transaction logs, alert dispositions, investigation notes — must survive regulatory inspection years later. Sumsub recommends independent AML audits to surface weaknesses before inspectors do.
Examples of AML policy in action
Large deposit escalation. A UK-licensed casino’s policy triggers SoF verification at £2,000 cumulative deposits within 24 hours — below the Betfred-criticised thresholds. The player submits employer payslips. Monitoring shows matched deposit-withdrawal cycles across three payment methods. The MLRO files a SAR with the National Crime Agency. The account stays open until law enforcement responds; the player is never told why withdrawals paused.
Closed-loop mitigation. An operator offering cards, e-wallets, and crypto requires withdrawals to the same rail used for deposit unless EDD clears an exception. Swedish guidance identifies closed-loop as a standard risk mitigation when multiple payout channels exist.
Crypto tightening. Regulators now expect KYC on crypto deposits, SoF checks, and blockchain analysis where operators accept digital assets. Pseudonymous wallets that bypassed traditional rails in 2020 are compliance dead ends in 2026.
Challenges and considerations
Security versus experience. Step-up verification at every €500 deposit kills conversion. Risk-based tiering — low friction for verified players, EDD for high-deposit profiles — aligns with FATF expectations and product KPIs.
Registration and auto-deposit flows must embed compliance without extra fields the regulator does not require. Open-banking auto-deposit can satisfy speed and AML in one step — when the policy defines limits, triggers, and monitoring for tokenised methods.
Regulatory velocity. EU AMLR, Curaçao’s 2025 ML/FT package, UKGC’s expanding metrics — policies need version control and named owners. UKGC, MGA, Spelinspektionen, and Curaçao GCB each set different CDD timing and reporting formats. Multi-market operators run a core policy with jurisdiction-specific annexes.
Data privacy. AML holds sensitive financial and identity data. GDPR requires lawful basis, retention limits, and breach response. ISO 27001-aligned ISMS, cited by Sumsub, reduces duplicate audit burden.
Best practices
- Document every trigger — what activates CDD refresh, EDD, SoF request, account restriction, SAR filing
- Automate monitoring, humanise decisions — rules flag; MLRO and investigators adjudicate with audit trails
- Train by role — CRM, VIP, payments, and affiliate teams see different red flags than compliance analysts
- Audit before the regulator audits — external AML reviews every 12–18 months on high-volume licences
- Unify with antifraud — bonus abuse rings and mule networks often precede laundering; see antifraud
AML vs KYC vs antifraud
| Measure | Primary purpose | Regulatory driver |
| AML policy | Prevent ML/TF through gambling | FATF, national AML acts, licence conditions |
| KYC | Verify identity and initial risk | Embedded in AML/CDD obligations |
| Antifraud | Stop revenue fraud (bonus abuse, chargebacks, ATO) | Licence adequacy + commercial necessity |
| Responsible gambling | Protect players from harm | Separate licence pillar, often co-enforced with AML |
Bottom line
An AML policy is not a compliance appendix. It connects registration, verification, payments, and regulatory reporting into one risk narrative.
Operators who stay ahead of 2027 EU harmonisation treat AML as a living programme — measured in STR quality, audit findings, and whether a €75,000 voucher pattern gets stopped at deposit, not at licence review.