Why this sector
Gambling attracts money laundering attention for structural reasons rather than because operators are suspected of complicity.
It moves large sums rapidly, in and out, across borders.
It provides a plausible explanation for wealth. A person with unexplained funds who can point to gambling winnings has a story that is difficult to disprove.
It converts funds of one character into another. Money deposited from one source and withdrawn to another has changed its apparent origin, which is why closed loop routing exists.
It involves customer relationships with limited natural friction, in a sector where a person spending very large amounts is not inherently unusual.
And it operates across jurisdictions, with operators, customers, payment providers and settlement frequently in different places.
None of this makes gambling operators complicit. It makes them gatekeepers within the financial system, which is why they are supervised as such and why the obligations are substantial. The scope varies by country. In Great Britain, for example, casinos are the only gambling businesses within the Money Laundering Regulations 2017, while every other licensed gambling business still has obligations under the Proceeds of Crime Act 2002 and the Commission's licence conditions.
The typologies
Understanding how laundering actually occurs in this sector directs controls more effectively than general principles.
Spending criminal proceeds. The simplest case, and by official assessment the most common in casinos: the Gambling Commission's 2026 risk assessment notes the UK National Risk Assessment's finding that most money laundering through licensed casinos takes the form of recreational spending of criminal property, rather than attempts to clean funds. This is why source of funds matters even when the customer loses.
Deposit and withdraw with minimal play. Funds enter, are wagered lightly or not at all, and are withdrawn. The result is money with a gambling provenance. The signal is a very low ratio of wagering to deposits, and the Commission's 2026 assessment rates withdrawing after minimal play as a high risk in remote casino.
Loss-making play as a cost. A launderer accepts a genuine loss as the price of legitimising the remainder, which means the activity looks like ordinary gambling on most measures.
Third party funding. Deposits from instruments not belonging to the account holder, which is why payment instrument ownership verification matters.
Account networks. Coordinated accounts moving value between them, particularly in products where player-to-player transfer is possible.
Chip dumping and collusion. In poker and comparable products, deliberately losing to a confederate to transfer funds.
Winnings purchase. Acquiring a genuine winner's ticket or account to claim their winnings, which is more common in land-based contexts and has online analogues.
Abuse of bonuses and promotions to move value.
Sanctioned or politically exposed persons using accounts to move funds, which is a distinct concern from laundering and is supervised alongside it.
The controls that address these are behavioural as much as documentary, which is why monitoring matters as much as onboarding.
The risk assessment
Every framework begins here, and it is the document regulators examine first because everything else must follow from it.
A business risk assessment analyses the specific laundering risks the operator faces given its markets, its products, its customer profile, its payment methods and its delivery channels. This mirrors the factors that UK law requires a firm's risk assessment to take into account: customers, countries or geographic areas, products or services, transactions and delivery channels. It should be specific rather than generic: an operator serving markets with elevated financial crime risk, offering products with player-to-player transfer, and accepting payment methods with weak traceability faces a different risk profile from one that does not.
From the business assessment follow customer risk ratings, assigning individual customers to risk categories based on their jurisdiction, their behaviour, their payment methods, their spend and their status.
From the ratings follow proportionate controls: what due diligence applies at each level, what monitoring triggers exist, what thresholds require enhanced scrutiny.
The failure mode is a generic risk assessment that could describe any operator, followed by controls that do not visibly connect to it. Regulators recognise this immediately, and the question they ask is why a particular control exists and what risk it addresses. An operator whose answer is that it seemed sensible has a framework rather than a risk-based approach.
Assessments must be reviewed and updated, particularly when the operator enters a market, launches a product or changes payment methods. In Great Britain a licence condition requires review in the light of material changes such as new products, technology or payment methods, and in any event at least annually. An assessment written at licensing and never revisited describes a business that no longer exists.
Customer due diligence
Standard due diligence identifies and verifies the customer, establishes the nature of the relationship, and applies to everyone. In gambling this overlaps substantially with the age and identity verification required for other reasons, which is why doing it once at registration serves several purposes. British remote licensees, for example, must verify a customer's name, address and date of birth before the customer is permitted to gamble. Money laundering rules add their own triggers: a British casino must apply due diligence to any wagering or collection of winnings amounting to £2,000 or more, a threshold expressed in euros until the regulations were amended with effect from 30 June 2026.
Enhanced due diligence applies where risk is higher. The triggers typically include high spend, unusual patterns, politically exposed status, higher-risk jurisdictions, and behaviour matching known typologies.
Source of funds enquiries establish where the money comes from. Source of wealth enquiries, which are distinct and sometimes conflated, establish how the customer's overall wealth was accumulated. Higher-risk relationships may require both.
The practical difficulty is well documented. These enquiries are intrusive, they are unpopular with customers, they take time, and they fall hardest on the highest-spending customers. That last point is the crux. A risk-based approach directs scrutiny where exposure is greatest, which means the customers subject to the most demanding enquiries are the ones the commercial side least wants to inconvenience.
This is precisely why regulators examine whether the enquiries are genuinely conducted. The British enforcement record contains cases where very high spenders were never asked, such as a Coral customer who spent £1.5m over two years and ten months without being asked to evidence their source of funds; where the request came late, as when a Daub Alderney customer was allowed to deposit £50,000 before source of funds evidence was sought; and where an unsatisfactory answer was accepted, as when William Hill assumed a customer's income could be £365,000 a year on the strength of a conversation, when he earned around £30,000 and was stealing from his employer. The pattern is consistent enough that it should be treated as the primary risk in this area.
The correct position is that where a customer declines to evidence their funds, or where the evidence does not support the level of spend, the relationship is restricted or ended. An enquiry that can be ignored without consequence is not a control.
Ongoing monitoring
Onboarding checks establish who someone is. Monitoring establishes whether their behaviour matches.
Transaction monitoring examines deposits, withdrawals, patterns and volumes against expected behaviour and against typology indicators.
Behavioural monitoring examines play patterns, particularly the ratio of wagering to deposits, which is a key signal of deposits withdrawn after minimal play.
Screening against sanctions lists and politically exposed person data, conducted at onboarding and repeated, since status changes.
Threshold triggers requiring enhanced scrutiny when spend or activity crosses defined levels. The Gambling Commission warns against relying on financial thresholds alone, or setting them too high for the customer base, since other risk factors may be visible from the start of the relationship.
Network analysis identifying connections between apparently unrelated accounts through shared devices, payment instruments, addresses or behavioural patterns. The Commission's 2026 assessment for remote casinos rates weak controls on linked or duplicate accounts as a high risk.
The design question is calibration. Thresholds set too high miss cases; set too low they generate volume that cannot be assessed properly, and a queue too large to work is functionally the same as no monitoring. The evidence of correct calibration is that alerts are genuinely assessed and that a meaningful proportion result in action.
Reporting
Where suspicion arises, the operator reports to the national financial intelligence unit, which in the UK is the National Crime Agency.
Two points are frequently misunderstood.
The threshold is suspicion, not proof. It requires more than vague unease and considerably less than evidence. Operators that wait for certainty under-report, and under-reporting is itself an enforcement risk. In the UK regulated sector, the offence of failing to disclose covers both what a person actually knows or suspects and what they had reasonable grounds to know or suspect. The question therefore includes whether a reasonable person with the same information would be suspicious, not whether a case could be proven.
Tipping off is a criminal offence in most jurisdictions, attaching to the individual who discloses as well as to the business. A customer must not be told that a report exists, that one is contemplated, or given information from which they could infer it. In the UK, tipping off in the regulated sector carries up to two years' imprisonment, and a separate offence of prejudicing an investigation applies more widely.
The practical consequence, covered from the operational side in the Customer Service course, is that customer-facing staff need pre-approved language that is accurate and non-disclosing, applied consistently to every case of the type. Consistency is what protects it, since a uniform response conveys nothing while a bespoke one may.
The MLRO is the named individual accountable for the regime, typically holding a personal licence and personal liability. In Great Britain, except at small-scale operators, the person appointed to submit reports of suspected money laundering occupies a specified management office requiring a personal management licence, and where serious AML failings are found that licence can be reviewed, suspended or revoked. The role requires genuine independence and access to senior management, and an MLRO who cannot escalate without commercial interference cannot discharge the function.
Records and evidence
The obligation extends to being able to demonstrate compliance afterwards, which is where many otherwise adequate frameworks fail.
Records must show who was verified, how and when; what due diligence was applied and on what risk basis; what enquiries were made and what responses were received; what monitoring alerts were generated and how each was assessed; what decisions were taken and by whom; and what was reported and when.
The retention periods are defined by jurisdiction: under the UK regulations the standard period is five years from the end of the business relationship or the completion of an occasional transaction. Records must also be made at the time, and the Gambling Commission says that adding them retrospectively is not sufficient. The retrieval requirement is practical: an operator asked about a specific customer's history several years later must be able to produce it.
The tension with data protection minimisation is real and is resolved by the specific legal obligation to retain, which provides the basis. The same UK regulation requires personal data to be deleted once the retention period expires, unless another legal ground to keep it applies. Documenting that reasoning is part of the compliance position rather than an optional refinement.
Where frameworks fail
The consistent findings from published enforcement in this area.
Policies not applied to significant customers. A recurring finding. Controls existed and were not applied to the relationships where they mattered most.
Enquiries made and not pursued. A source of funds request sent, ignored by the customer, and the relationship continuing.
Evidence accepted uncritically. Documentation that did not support the spend level, accepted because it existed. The Commission has reported bank statements showing significant third-party deposits, or outgoings higher than income, passing without action.
Alerts generated and not assessed. Monitoring that produced output nobody worked.
Generic risk assessment. No visible connection between the assessment and the controls.
MLRO without authority. A named individual unable to act independently of commercial pressure.
Thresholds set to produce manageable volume rather than to catch risk, which inverts the purpose.
No aggregate view. Activity assessed transaction by transaction with nobody looking at the customer's overall picture.
Each of these describes a framework that exists on paper. The distinction regulators draw, and the one that determines outcomes, is whether the controls actually operated, and the evidence for that is in the records rather than in the policy.
Sanctions and politically exposed persons
Two obligations that sit alongside anti-money laundering and operate differently.
Sanctions compliance is absolute rather than risk-based. There is no threshold below which dealing with a sanctioned person is acceptable, and no proportionality argument available. The requirement is to screen customers against applicable lists at onboarding and on an ongoing basis, since designations change, and to freeze and report where a match arises. In the UK the holder of a casino operating licence is among the relevant firms that must report to OFSI as soon as practicable when it knows or has reasonable cause to suspect that a customer is a designated person.
The practical difficulties are matching quality and list scope. Name matching produces false positives at volume, and screening tuned to eliminate them will miss genuine matches. Which lists apply depends on the jurisdictions the operator is connected to, which for a multi-market operator with international payment relationships can be several.
Politically exposed persons hold prominent public functions, and their position creates elevated corruption risk. The obligation is not to refuse them but to apply enhanced due diligence: under the UK regulations, senior management approval for the relationship, adequate measures to establish both source of wealth and source of funds, and enhanced ongoing monitoring. The obligations extend to family members and known close associates, which is where identification becomes difficult, and continue for at least 12 months after a person leaves the public function. UK law also treats domestic PEPs as presenting a lower starting level of risk than foreign ones.
Both obligations require screening infrastructure and both generate alerts requiring assessment. The same calibration problem applies: screening producing volume nobody can work is functionally absent.
Working with payments and support
Financial crime controls sit across several functions, and the coordination determines whether they operate.
Payments holds the transaction data, the instrument information and the relationships with providers who have their own obligations. Closed loop routing, instrument ownership verification and payment method restrictions are all implemented here, and a routing change made for commercial reasons can defeat a control without anyone intending it.
Customer support encounters the human side. Agents hear things, notice patterns and handle the conversations with customers subject to review. They need training on what to escalate, a route that works, and the approved language for the undisclosable case.
VIP and account management hold the closest view of the highest-risk customers and, as the Customer Service course covered, may hold incentives pointing away from raising concerns. The structural remedy is the same: separate the decision from the relationship.
Data and technology build the monitoring, and the quality of the underlying identity resolution determines whether network analysis works at all.
Compliance owns the framework and, critically, must be able to require action rather than only recommend it.
The failures in this area are frequently coordination failures. A monitoring alert generated and routed to a queue nobody works. A support escalation that reached compliance months after the agent raised it. A payment routing change that bypassed a control. Each is preventable by connection rather than by additional policy.
Building and evidencing the framework
To make the requirements operational, the components a functioning framework contains.
A documented business risk assessment, specific to the operator, reviewed on a schedule and updated on material change.
Customer risk rating methodology applying the assessment to individuals, with defined criteria rather than discretion.
Due diligence procedures at each risk level, specifying what is required, what evidence is acceptable and what happens when it is not provided.
Monitoring rules and models, calibrated so that alert volume is workable and documented so that the basis for each trigger is explicable.
An alert handling process with defined ownership, timescales and recorded outcomes for every alert.
Escalation and reporting, with the MLRO able to act independently.
Training, role-specific, refreshed rather than delivered once, and evidenced.
Record keeping sufficient to reconstruct any customer's history and any decision's basis years later.
Independent assurance, meaning periodic testing by someone other than the people running the framework, which is what establishes whether it operates.
The last of these is the one most often absent and the one that most reliably predicts whether an operator will be surprised by an enforcement finding. A framework reviewed only by the people who built it will be found compliant, and the first genuinely independent examination will be the regulator's.
Proportionality and the limits of the obligation
A closing point of balance, since this lesson has emphasised the failures.
The obligation is risk-based, not absolute. An operator is not required to prevent all financial crime, to investigate every customer to the same depth, or to refuse anyone whose circumstances are unusual. It is required to assess its risks honestly, to apply controls proportionate to them, to act on what it finds and to be able to demonstrate all three.
Over-application carries its own costs. Excessive due diligence on low-risk customers consumes resource that should go to higher-risk ones, generates friction that drives customers away, and produces alert volumes that dilute attention. An operator applying enhanced scrutiny uniformly has not implemented a risk-based approach; it has implemented an expensive undifferentiated one, and regulators do not credit it as compliance.
The skill in this discipline is calibration: directing scrutiny where the risk actually is, resourcing it adequately, and being able to explain the basis for both. That is harder than either extreme and is what the obligation actually asks for.