Why this sector
Gambling attracts money laundering attention for structural reasons rather than because operators are suspected of complicity.
It moves large sums rapidly, in and out, across borders.
It provides a plausible explanation for wealth. A person with unexplained funds who can point to gambling winnings has a story that is difficult to disprove.
It converts funds of one character into another. Money deposited from one source and withdrawn to another has changed its apparent origin, which is why closed loop routing exists.
It involves customer relationships with limited natural friction, in a sector where a person spending very large amounts is not inherently unusual.
And it operates across jurisdictions, with operators, customers, payment providers and settlement frequently in different places.
None of this makes gambling operators complicit. It makes them gatekeepers within the financial system, which is why they are supervised as such and why the obligations are substantial.
The typologies
Understanding how laundering actually occurs in this sector directs controls more effectively than general principles.
Deposit and withdraw with minimal play. Funds enter, are wagered lightly or not at all, and are withdrawn. The result is money with a gambling provenance. The signal is a very low ratio of wagering to deposits.
Loss-making play as a cost. A launderer accepts a genuine loss as the price of legitimising the remainder, which means the activity looks like ordinary gambling on most measures.
Third party funding. Deposits from instruments not belonging to the account holder, which is why payment instrument ownership verification matters.
Account networks. Coordinated accounts moving value between them, particularly in products where player-to-player transfer is possible.
Chip dumping and collusion. In poker and comparable products, deliberately losing to a confederate to transfer funds.
Winnings purchase. Acquiring a genuine winner's ticket or account to claim their winnings, which is more common in land-based contexts and has online analogues.
Abuse of bonuses and promotions to move value.
Sanctioned or politically exposed persons using accounts to move funds, which is a distinct concern from laundering and is supervised alongside it.
The controls that address these are behavioural as much as documentary, which is why monitoring matters as much as onboarding.
The risk assessment
Every framework begins here, and it is the document regulators examine first because everything else must follow from it.
A business risk assessment analyses the specific laundering risks the operator faces given its markets, its products, its customer profile, its payment methods and its delivery channels. It should be specific rather than generic: an operator serving markets with elevated financial crime risk, offering products with player-to-player transfer, and accepting payment methods with weak traceability faces a different risk profile from one that does not.
From the business assessment follow customer risk ratings, assigning individual customers to risk categories based on their jurisdiction, their behaviour, their payment methods, their spend and their status.
From the ratings follow proportionate controls: what due diligence applies at each level, what monitoring triggers exist, what thresholds require enhanced scrutiny.
The failure mode is a generic risk assessment that could describe any operator, followed by controls that do not visibly connect to it. Regulators recognise this immediately, and the question they ask is why a particular control exists and what risk it addresses. An operator whose answer is that it seemed sensible has a framework rather than a risk-based approach.
Assessments must be reviewed and updated, particularly when the operator enters a market, launches a product or changes payment methods. An assessment written at licensing and never revisited describes a business that no longer exists.
Customer due diligence
Standard due diligence identifies and verifies the customer, establishes the nature of the relationship, and applies to everyone. In gambling this overlaps substantially with the age and identity verification required for other reasons, which is why doing it once at registration serves several purposes.
Enhanced due diligence applies where risk is higher. The triggers typically include high spend, unusual patterns, politically exposed status, higher-risk jurisdictions, and behaviour matching known typologies.
Source of funds enquiries establish where the money comes from. Source of wealth enquiries, which are distinct and sometimes conflated, establish how the customer's overall wealth was accumulated. Higher-risk relationships may require both.
The practical difficulty is well documented. These enquiries are intrusive, they are unpopular with customers, they take time, and they fall hardest on the highest-spending customers. That last point is the crux. A risk-based approach directs scrutiny where exposure is greatest, which means the customers subject to the most demanding enquiries are the ones the commercial side least wants to inconvenience.
This is precisely why regulators examine whether the enquiries are genuinely conducted. The enforcement record contains cases where source of funds requests were made and not pursued, where unsatisfactory responses were accepted, and where the process was applied to smaller customers and quietly not to larger ones. The pattern is consistent enough that it should be treated as the primary risk in this area.
The correct position is that where a customer declines to evidence their funds, or where the evidence does not support the level of spend, the relationship is restricted or ended. An enquiry that can be ignored without consequence is not a control.
Ongoing monitoring
Onboarding checks establish who someone is. Monitoring establishes whether their behaviour matches.
Transaction monitoring examines deposits, withdrawals, patterns and volumes against expected behaviour and against typology indicators.
Behavioural monitoring examines play patterns, particularly the ratio of wagering to deposits, which is the single most informative indicator for the dominant typology.
Screening against sanctions lists and politically exposed person data, conducted at onboarding and repeated, since status changes.
Threshold triggers requiring enhanced scrutiny when spend or activity crosses defined levels.
Network analysis identifying connections between apparently unrelated accounts through shared devices, payment instruments, addresses or behavioural patterns.
The design question is calibration. Thresholds set too high miss cases; set too low they generate volume that cannot be assessed properly, and a queue too large to work is functionally the same as no monitoring. The evidence of correct calibration is that alerts are genuinely assessed and that a meaningful proportion result in action.
Reporting
Where suspicion arises, the operator reports to the national financial intelligence unit.
Two points are frequently misunderstood.
The threshold is suspicion, not proof. It requires more than vague unease and considerably less than evidence. Operators that wait for certainty under-report, and under-reporting is itself an enforcement risk. The question is whether a reasonable person with the same information would be suspicious, not whether a case could be proven.
Tipping off is a criminal offence in most jurisdictions, attaching to the individual who discloses as well as to the business. A customer must not be told that a report exists, that one is contemplated, or given information from which they could infer it.
The practical consequence, covered from the operational side in the Customer Service course, is that customer-facing staff need pre-approved language that is accurate and non-disclosing, applied consistently to every case of the type. Consistency is what protects it, since a uniform response conveys nothing while a bespoke one may.
The MLRO is the named individual accountable for the regime, typically holding a personal licence and personal liability. The role requires genuine independence and access to senior management, and an MLRO who cannot escalate without commercial interference cannot discharge the function.
Records and evidence
The obligation extends to being able to demonstrate compliance afterwards, which is where many otherwise adequate frameworks fail.
Records must show who was verified, how and when; what due diligence was applied and on what risk basis; what enquiries were made and what responses were received; what monitoring alerts were generated and how each was assessed; what decisions were taken and by whom; and what was reported and when.
The retention periods are defined by jurisdiction and are typically long. The retrieval requirement is practical: an operator asked about a specific customer's history several years later must be able to produce it.
The tension with data protection minimisation is real and is resolved by the specific legal obligation to retain, which provides the basis. Documenting that reasoning is part of the compliance position rather than an optional refinement.
Where frameworks fail
The consistent findings from published enforcement in this area.
Policies not applied to significant customers. The single most common finding. Controls existed and were not applied to the relationships where they mattered most.
Enquiries made and not pursued. A source of funds request sent, ignored by the customer, and the relationship continuing.
Evidence accepted uncritically. Documentation that did not support the spend level, accepted because it existed.
Alerts generated and not assessed. Monitoring that produced output nobody worked.
Generic risk assessment. No visible connection between the assessment and the controls.
MLRO without authority. A named individual unable to act independently of commercial pressure.
Thresholds set to produce manageable volume rather than to catch risk, which inverts the purpose.
No aggregate view. Activity assessed transaction by transaction with nobody looking at the customer's overall picture.
Each of these describes a framework that exists on paper. The distinction regulators draw, and the one that determines outcomes, is whether the controls actually operated, and the evidence for that is in the records rather than in the policy.
Sanctions and politically exposed persons
Two obligations that sit alongside anti-money laundering and operate differently.
Sanctions compliance is absolute rather than risk-based. There is no threshold below which dealing with a sanctioned person is acceptable, and no proportionality argument available. The requirement is to screen customers against applicable lists at onboarding and on an ongoing basis, since designations change, and to freeze and report where a match arises.
The practical difficulties are matching quality and list scope. Name matching produces false positives at volume, and screening tuned to eliminate them will miss genuine matches. Which lists apply depends on the jurisdictions the operator is connected to, which for a multi-market operator with international payment relationships can be several.
Politically exposed persons hold prominent public functions, and their position creates elevated corruption risk. The obligation is not to refuse them but to apply enhanced due diligence, to establish source of wealth, and to obtain senior approval for the relationship. The definition typically extends to family members and close associates, which is where identification becomes difficult.
Both obligations require screening infrastructure and both generate alerts requiring assessment. The same calibration problem applies: screening producing volume nobody can work is functionally absent.
Working with payments and support
Financial crime controls sit across several functions, and the coordination determines whether they operate.
Payments holds the transaction data, the instrument information and the relationships with providers who have their own obligations. Closed loop routing, instrument ownership verification and payment method restrictions are all implemented here, and a routing change made for commercial reasons can defeat a control without anyone intending it.
Customer support encounters the human side. Agents hear things, notice patterns and handle the conversations with customers subject to review. They need training on what to escalate, a route that works, and the approved language for the undisclosable case.
VIP and account management hold the closest view of the highest-risk customers and, as the Customer Service course covered, may hold incentives pointing away from raising concerns. The structural remedy is the same: separate the decision from the relationship.
Data and technology build the monitoring, and the quality of the underlying identity resolution determines whether network analysis works at all.
Compliance owns the framework and, critically, must be able to require action rather than only recommend it.
The failures in this area are frequently coordination failures. A monitoring alert generated and routed to a queue nobody works. A support escalation that reached compliance months after the agent raised it. A payment routing change that bypassed a control. Each is preventable by connection rather than by additional policy.
Building and evidencing the framework
To make the requirements operational, the components a functioning framework contains.
A documented business risk assessment, specific to the operator, reviewed on a schedule and updated on material change.
Customer risk rating methodology applying the assessment to individuals, with defined criteria rather than discretion.
Due diligence procedures at each risk level, specifying what is required, what evidence is acceptable and what happens when it is not provided.
Monitoring rules and models, calibrated so that alert volume is workable and documented so that the basis for each trigger is explicable.
An alert handling process with defined ownership, timescales and recorded outcomes for every alert.
Escalation and reporting, with the MLRO able to act independently.
Training, role-specific, refreshed rather than delivered once, and evidenced.
Record keeping sufficient to reconstruct any customer's history and any decision's basis years later.
Independent assurance, meaning periodic testing by someone other than the people running the framework, which is what establishes whether it operates.
The last of these is the one most often absent and the one that most reliably predicts whether an operator will be surprised by an enforcement finding. A framework reviewed only by the people who built it will be found compliant, and the first genuinely independent examination will be the regulator's.
Proportionality and the limits of the obligation
A closing point of balance, since this lesson has emphasised the failures.
The obligation is risk-based, not absolute. An operator is not required to prevent all financial crime, to investigate every customer to the same depth, or to refuse anyone whose circumstances are unusual. It is required to assess its risks honestly, to apply controls proportionate to them, to act on what it finds and to be able to demonstrate all three.
Over-application carries its own costs. Excessive due diligence on low-risk customers consumes resource that should go to higher-risk ones, generates friction that drives customers away, and produces alert volumes that dilute attention. An operator applying enhanced scrutiny uniformly has not implemented a risk-based approach; it has implemented an expensive undifferentiated one, and regulators do not credit it as compliance.
The skill in this discipline is calibration: directing scrutiny where the risk actually is, resourcing it adequately, and being able to explain the basis for both. That is harder than either extreme and is what the obligation actually asks for.