Why an operator has to know who it is dealing with
Two of the three regulatory objectives, keeping crime out and protecting the vulnerable (in Britain they are written into section 1 of the Gambling Act 2005), depend on the operator knowing who its customers are. You cannot keep children off a site without checking ages. You cannot spot a money launderer without knowing whose money it is. You cannot enforce a self-exclusion if the excluded person can open a new account under a slightly different name. Customer verification is therefore the foundation on which most other obligations stand, and it is the first thing a new compliance person should understand properly.
The terms you will meet: KYC (know your customer) is the general practice of establishing who a customer is. CDD (customer due diligence) is the regulatory term for the checks required. EDD (enhanced due diligence) is the deeper set of checks required for higher-risk customers. AML (anti-money laundering) is the wider framework of which these are part.
What has to be verified
At minimum, in every regulated online market, before a customer can gamble or at least before they can withdraw:
Age. That the customer is above the legal gambling age, which is 18 in most jurisdictions and 21 in some, including New Jersey, whose operators must verify that an online customer is of the legal age of 21. This is the single most serious check: allowing a child to gamble is treated as a grave breach everywhere.
Identity. That the customer is a real person, and the person they claim to be. Name, date of birth and address, verified against independent sources.
Location. That the customer is in a jurisdiction where the operator is licensed to serve them. Online this means geolocation checks, which in some markets must be repeated during play: New Jersey requires the system to detect the customer's location at login and as often as the operator's approved submission specifies, and to refuse wagers from outside the permitted area.
Beyond these, depending on the risk of the customer:
Source of funds and source of wealth. Where the money being gambled comes from, and where the customer's overall wealth comes from. Required for higher-risk customers and above spending thresholds, and increasingly expected earlier than operators would like. In the UK, the Money Laundering Regulations 2017 require enhanced due diligence in any high-risk case, for politically exposed persons and for unusually large or complex transactions, and casinos must apply customer due diligence to any transaction of £2,000 or more, including linked transactions, a sterling threshold in force since 30 June 2026.
Politically exposed persons and sanctions. Whether the customer is a person entrusted with a prominent public function, or a family member or known close associate of one, which raises corruption risk, and whether they appear on any sanctions list, which would make dealing with them unlawful.
How verification is done
Modern verification is mostly electronic. The customer's details are checked against credit reference agencies, electoral rolls, government databases and identity document verification services, often within seconds. Where electronic checks fail or the risk is higher, documents are requested: identity documents, proof of address, bank statements, payslips or tax returns for source of funds.
The design questions an operator faces:
- When to verify. Before any play, before deposit, before withdrawal, or on a risk-triggered basis. Regulators have pushed this earlier over time. In Britain, age must be verified before a customer can deposit, and identity before they can gamble, and an operator may not demand extra information as a condition of withdrawal if it could reasonably have asked for it earlier.
- How much friction to accept. Every check loses some customers who cannot or will not complete it. That is a commercial cost the regulator does not weigh, and one the operator must not let drive the decision.
- What to do when a check fails. A failed age check means no play, immediately; in Britain the operator must return the money a child paid and may not give them a prize. A failed identity check means an account restricted until it passes. A customer who will not provide source of funds when asked is a customer whose account is closed.
Money laundering, in plain terms
Money laundering is making money from crime look like money from a legitimate source. Gambling is useful for it because a person can deposit cash of doubtful origin, gamble a little, and withdraw the rest as "winnings" with an operator's payment behind it. Or use a gambling account simply to move money between people or across borders.
The operator's obligations are to assess its own risk (what products, customers, payment methods and countries make it more or less exposed), to apply checks proportionate to that risk, to monitor transactions and behaviour for patterns that suggest laundering, to report suspicious activity to the national financial intelligence unit (in the UK, the National Crime Agency's UK Financial Intelligence Unit), and to keep records. Reporting is done without telling the customer; "tipping off" is itself an offence in the UK, punishable by up to two years' imprisonment.
The patterns that trigger attention are well known: deposits and withdrawals with minimal play in between, use of many payment methods or third-party payment instruments, spending inconsistent with what is known about the customer, sudden changes in behaviour, structuring of amounts to stay under thresholds, and accounts that appear to be operated by someone other than the verified customer.
Fines for AML failures have been among the largest in the industry's history, and the failures were rarely exotic. In March 2023 three William Hill Group businesses agreed to pay £19.2 million, then the largest enforcement payment in the Gambling Commission's history, for social responsibility and anti-money laundering failures: customers allowed to deposit large amounts without appropriate checks, no source-of-funds evidence requested from a customer who staked £19,000 on a single bet, and policies that did not say what to do with the results of customer risk profiling. The common thread is controls that were not applied when they mattered: checks not done, warning signs not acted on, high-spending customers left unquestioned.
Affordability, the newer frontier
Several regulators have moved beyond "is this customer's money clean" to "can this customer afford to lose this much". Affordability checks require the operator to consider whether a customer's level of spend is consistent with their financial circumstances, and to act if it is not. In Great Britain this has become a formal framework. Operators must run a financial vulnerability check, a public-record search for bankruptcies, county court judgments and similar, once a customer's net deposits exceed £150 in a rolling 30 days, the threshold that has applied since 28 February 2025 (it was £500 when the checks began in August 2024). In July 2026 the Gambling Commission decided to introduce financial risk assessments from credit reference agencies in stages, starting with the largest operators at £5,000 of net deposits in a rolling 24 hours and, once fully implemented, reaching £1,000 in 24 hours or £3,000 over 90 days for customers aged 25 and over, with lower thresholds for those under 25. When this lesson was checked in September 2026 the Commission had not yet confirmed when stage one would begin. Elsewhere it is an expectation folded into responsible gambling and AML rules.
This is where customer verification and player protection meet, and it is contentious: operators worry about friction and about customers moving to unlicensed sites; regulators point to the harm caused by customers losing sums they plainly could not afford. Wherever you sit, the practical requirement is that the operator has a policy, applies it consistently, and can show it did.
Data protection sits on top of all of this
Everything above involves collecting personal data, sometimes sensitive data. Data protection law (the GDPR in Europe and its equivalents elsewhere) governs how it is collected, stored, used and shared, and gives customers rights over it. A verification programme that is excellent for AML and careless with data is a breach waiting to happen. The two regimes have to be designed together.
What a first job in this area looks like
Someone starting in KYC or AML will spend their time reviewing verification cases that automated checks could not resolve, requesting and assessing documents, investigating alerts from transaction monitoring, writing up findings, and escalating to the money-laundering reporting officer. The discipline to learn is consistency: the same facts get the same decision, the decision is recorded with the reasons, and nothing is waved through because the customer is valuable or impatient. The next lesson turns to the customer's own welfare.