What compliance is
Compliance is the function that knows what every licence requires, translates it into policies and controls, checks that the business follows them, reports to regulators, and deals with them when something goes wrong. In a small operator it may be two people; in a large multi-market group it is a department with specialists in AML, responsible gambling, marketing, licensing, data protection and technical standards. Whatever the size, the work has the same components, and this lesson walks through them.
The compliance framework
A framework is the structure that turns licence conditions into daily practice.
Policies state what the company does in each area: the AML policy, the responsible gambling policy, the marketing policy, the complaints policy. They are written to satisfy the regulator and are read by the regulator, so they must describe what actually happens.
Procedures say how: the steps a KYC analyst follows, the thresholds that trigger a source-of-funds request, the escalation path for a flagged customer.
Controls are the mechanisms that enforce the procedures: system rules that block play until verification, automated monitoring, approval workflows for marketing, access restrictions.
Training ensures staff know the policies; regulators require records of who was trained on what and when. Britain's Money Laundering Regulations, which cover casinos, for example require a written record of the AML training given to relevant employees.
Monitoring and testing check the controls work: sampling cases, reviewing decisions, testing that a self-excluded customer really cannot open a new account.
Reporting covers the returns to regulators and the internal reports to the board, which must be shown to have oversight.
Governance is who is accountable: named individuals in approved roles, a compliance committee, board minutes showing the matter was considered. In Britain the heads of functions including compliance, finance, marketing and AML must each hold a personal management licence.
The regulator's test of all this is simple: can the operator show, with records, that it did what its policies say? Enforcement cases are full of operators whose policies were fine and whose evidence was missing.
The regulatory calendar
Much compliance work is periodic and deadline-driven:
- Regulatory returns: revenue, customer numbers, self-exclusions, complaints, AML statistics, submitted monthly, quarterly or annually depending on the market. In Britain the regulatory return is due within 28 days of the end of each quarter.
- Licence fee payments and renewals.
- Gaming tax returns, usually handled with finance but a compliance responsibility if missed.
- Annual assurance statements in markets that require the board to attest to compliance. In Britain the boards of large gambling businesses submit assurance statements assessing the risks the business poses to the licensing objectives and how well it manages them.
- Independent audits of AML or responsible gambling, where required. British casinos, for example, must have an independent audit function for AML where appropriate to the size and nature of the business.
- Game and platform re-certification when systems change, following the regulator's technical standards and rules on the timing and procedures for testing.
- Data protection obligations: records of processing, impact assessments, breach reporting to the data protection authority, under the UK GDPR without undue delay and, where feasible, within 72 hours of becoming aware of it.
A multi-market operator maintains a calendar per licence and a team that lives by it.
Event-driven obligations
Alongside the calendar are the things that must be reported when they happen, often within days. In Britain, the events on the Commission's key events list, which covers most of the examples below, must be reported as soon as reasonably practicable and within five working days:
- A change in ownership above the threshold (5 per cent of shares or voting rights in Britain), or a new key person.
- A data breach affecting customer data.
- A material change to the business: a new platform, a new product, a new payment provider, entering or leaving a market.
- Financial difficulty or a material adverse event.
- Regulatory action in another jurisdiction.
- Suspicious activity, reported to the financial intelligence unit. In Britain the operator must also give the Commission the reference number of each suspicious activity report.
- Suspicious betting, reported to the regulator or sports integrity bodies.
Failing to report on time is itself a breach, independent of the underlying event.
Complaints and disputes
Every licensed operator needs a complaints process the customer can find and use, with defined response times, and in many markets an independent alternative dispute resolution body the customer can escalate to. In Britain, a customer whose complaint is not resolved within eight weeks must be able to refer it to an ADR entity free of charge. Regulators read complaint statistics as a signal of how an operator treats customers, and a pattern of complaints about bonus terms, withdrawal delays or account closures will bring attention.
The practical rule for staff handling complaints: the customer's reasonable understanding of the terms usually prevails over the operator's technical reading, because that is how the regulator and the adjudicator will see it. In Britain it is also the law: where a term in a consumer contract could have different meanings, the meaning most favourable to the consumer prevails.
When things go wrong: enforcement
Regulators enforce on a ladder, and the rung depends on the seriousness of the breach, whether the operator found and reported it itself, how it responded, and its history.
- Advice and warnings. For minor breaches, or first breaches promptly remedied.
- Additional conditions on the licence: a compliance review, an independent audit, a monitor, a restriction on a product or market.
- Financial penalties. Fines, or "regulatory settlements", in which the operator agrees to a payment and usually to a published statement of its failings, and the case stops short of a completed formal licence review. In Britain settlement money was long directed to socially responsible purposes; since July 2026 it goes to the Consolidated Fund, as fines do. The largest British case to date is the £19.2 million paid by three William Hill Group businesses in 2023.
- Suspension of the licence, meaning no trading until the regulator lifts it.
- Revocation. The licence is removed, ending the operator's right to offer gambling under it.
- Personal action against licensed individuals, such as a review of their personal licence, which can lead to removal from role.
- Criminal proceedings, brought by the regulator or referred to the police, in cases of unlicensed operation or serious offences.
Regulators publish enforcement outcomes, and reading them is the fastest education in what they care about. The recurring lessons match the published rules. In Britain the Commission's penalty principles treat early and voluntary reporting of a breach and cooperation with the investigation as mitigating factors; allow a discount of between 5 and 30 per cent on the penal element for early admissions; count the absence of internal controls that should have prevented the breach towards its seriousness; and treat repeated breaches and a poor regulatory history as aggravating.
The culture question
Regulators increasingly assess culture, and Britain's Gambling Commission describes its enforcement as intended to drive a culture in which operators minimise risks to the licensing objectives. Regulators look at whether compliance is respected inside the business, whether the board asks the right questions, whether commercial staff can override compliance decisions, whether the money-laundering reporting officer and the responsible gambling lead have genuine authority. A company with a good framework and a culture of finding ways round it is at greater risk than one with a modest framework applied honestly.
The signs a regulator looks for are practical: are compliance decisions documented, are they ever reversed by commercial pressure, is compliance represented at the executive level, is it resourced, does it report to the board without filtering.
Starting out
A first role in compliance is usually in one specialism: KYC and AML analysis, responsible gambling interactions, marketing review, licensing administration or regulatory reporting. From any of them, the skills that transfer are the same: read the actual rule, not the summary; record what you did and why; apply the same standard to every customer and every campaign; escalate rather than guess; and keep up with the changes, because the rules you learned this year will not be the rules next year.
That last point is the theme of this whole course. Gambling regulation is not a fixed body of law to be memorised. It is a moving set of answers to a stable question about harm, fairness and crime, and a compliance professional's value lies in understanding the question well enough to anticipate the next answer.