What due diligence is for
Customer due diligence establishes who the customer is, understands the nature of the relationship, and gives the operator a baseline against which later behaviour can be judged. Everything downstream depends on it: monitoring compares behaviour to an expectation, and there is no expectation without a baseline.
Most frameworks require the same core elements. Identify the customer and verify that identity from reliable, independent sources. For a corporate customer, identify the beneficial owners and take reasonable measures to verify them. Understand the purpose and intended nature of the relationship. Conduct ongoing monitoring, including keeping the information current.
That last element is the one treated as optional in practice. Customer due diligence is frequently run as an onboarding event, completed, and filed. It is a continuing obligation, and the gap between those two readings is where most findings live.
Identification and verification are different things
Identification is collecting the attributes: name, date of birth, address, and whatever else the framework requires. Verification is establishing that those attributes are genuine and belong to the person presenting them. Confusing the two produces a file that looks complete and proves nothing.
Electronic verification matches the customer's declared details against independent data sources such as credit reference, electoral or government databases. It resolves the majority of customers instantly, it produces an auditable match record, and its quality depends entirely on the coverage and independence of the underlying sources. A single source matching a single attribute is weak; multiple independent sources matching several attributes is strong, and frameworks frequently specify what counts.
Document verification examines an identity document, increasingly with automated authenticity checks on the security features, and increasingly paired with a liveness check that binds the document to the person presenting it. Document plus liveness is materially stronger than document alone, because a stolen or purchased document defeats document-only checks.
The thin-file problem is real and is where inexperienced teams cause harm. Young customers, recent arrivals in a country and people who are not on credit or electoral registers fail electronic verification through no fault of their own. Treating an electronic verification failure as a suspicion indicator rather than as a data coverage problem produces both discrimination and wasted alerts. The correct response is escalation to a different method, not an inference about the customer.
Timing. In mature online regimes, verification is expected before the customer can deposit or play, rather than at first withdrawal. The older model allowed a customer to lose money before anyone checked who they were, and it produced exactly the problems you would expect.
Beneficial ownership, and the point of it
Where the customer is a company, trust or other legal arrangement, the obligation runs through the entity to the natural persons behind it. Identify the beneficial owners, typically those holding or controlling more than a defined percentage of ownership or voting rights, and those otherwise exercising control.
Two points are worth internalising.
Structures exist to defeat this. Layered holding companies across several jurisdictions, nominee directors and shareholders, and bearer instruments where they persist are all methods of putting distance between the entity and the person. Reaching a name at the top of a chain is not the same as understanding who controls it, and a structure whose complexity has no commercial explanation is itself a risk indicator.
Registers are a starting point, not an answer. Public beneficial ownership registers vary enormously in coverage, verification and accessibility, and several have been restricted following litigation. A register entry is evidence, weighed with everything else, not a conclusion.
In online B2C gambling, corporate customers are rare and this work concentrates in B2B relationships, affiliate and agent arrangements, and payment partnerships. Those relationships receive far less scrutiny than customer accounts in most operators, which is the wrong way round given the value moving through them.
Politically exposed persons
A politically exposed person holds or has held a prominent public function, and the category extends to immediate family members and known close associates. The rationale is exposure to bribery and corruption risk by virtue of position, not an allegation about any individual.
Several points are routinely misunderstood.
PEP status is not an accusation and is not a reason to refuse a relationship by default. It is a reason to apply enhanced due diligence, obtain senior management approval, establish source of wealth and source of funds, and monitor the relationship more closely.
Domestic and foreign PEPs are treated differently in some frameworks, with some regimes applying a risk-based approach to domestic PEPs rather than automatic enhanced measures.
Screening is only as good as the list and the matching. Commercial PEP databases vary in coverage, currency and false-positive rate, and name matching across transliterations, diminutives and common names is genuinely difficult. A screening process that produces an unmanageable volume of weak matches will be worked around.
Status changes. A customer who was not a PEP at onboarding may become one. Screening has to be periodic, not just initial.
Enhanced and simplified due diligence
Enhanced due diligence applies where risk is higher: PEPs, high-risk jurisdictions, unusually complex or large transactions with no apparent purpose, relationships conducted in unusual circumstances, and whatever else the operator's own risk assessment identifies. It typically means additional identity evidence, establishing source of funds and source of wealth, senior approval to enter or continue the relationship, and closer ongoing monitoring.
Simplified due diligence applies where risk is demonstrably low, permitting reduced measures. It does not permit no measures, and the justification has to be documented. In practice, simplified measures are hard to justify for remote gambling customers, and an operator applying them broadly should expect to be asked why.
The recurring error with enhanced due diligence is treating it as a document-collection exercise. Obtaining a payslip and filing it is not enhanced diligence if nobody assesses whether the payslip explains the activity. The measure is the assessment, not the artefact.
Ongoing due diligence
This is the element most often neglected and most often cited.
The obligation is to keep the information current and to ensure transactions remain consistent with what is known about the customer. That requires a trigger model and a periodic model, working together.
Event triggers should include a material change in transaction behaviour, a new payment instrument, a change of jurisdiction, a screening hit, a monitoring alert, a third-party deposit attempt, a failed verification, and information from outside the operator such as a law enforcement request or adverse media.
Periodic review should be risk-rated: high-risk relationships reviewed frequently, low-risk relationships at longer intervals. What matters is that the interval is defined, justified and actually met, because an overdue review population is one of the first things a supervisor asks to see.
A review that changes nothing is fine. A review that never happens is not, and a review process with a large backlog is a control the operator has documented itself as failing to operate.
Where due diligence meets responsible gambling
The two disciplines share evidence and are frequently run by overlapping teams, so the distinction has to be held deliberately.
Due diligence asks who the customer is and where the money came from. Responsible gambling asks whether the customer can bear the loss and whether they are being harmed. A customer with impeccable source of funds can be experiencing severe harm. A customer who can plainly afford their play can be moving criminal proceeds.
The practical consequence is that the two processes must be able to reach opposite conclusions about the same customer without one overriding the other, and the operator must act on both. The failure mode is a single team running one process, labelling it with both names, and resolving every case in the direction of whichever discipline it knows better.
There is also a hard constraint the other way. Tipping-off provisions mean a customer under suspicion cannot be told why their account is restricted. A responsible gambling interaction with such a customer has to be conducted without disclosing the financial crime concern, and the teams need a protocol for that situation rather than improvising it.