GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

The EU AML Package and AMLA: What Gambling Operators Must Prepare For

The EU AML package hands gambling operators one fixed deadline instead of twenty-seven moving national ones. Regulation (EU) 2024/1624 applies directly from 10 July 2027, displacing the transposed directives that currently define anti-money laundering duties in each member state. Firms licensed in more than one EU jurisdiction face the sharpest adjustment, because the local divergences their onboarding and monitoring processes were built around stop being lawful variations on that date.

Three Instruments Replace the Directive Framework From July 2027

Four legal texts make up the package, and only one of them still needs national transposition. The Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, was adopted on 31 May 2024, published in the Official Journal on 19 June 2024 and entered into force on 9 July 2024. It binds a licensee in Valletta and a licensee in Tallinn in identical terms once it applies.

The regulation lists providers of gambling services among its obliged entities, which is no novelty in substance. Casinos were captured by Directive 2005/60/EC and the wider sector by Directive (EU) 2015/849. What changes is the disappearance of the transposition layer that allowed each member state to shape those duties in its own statute. Operators used to treating AML controls as a licence-condition matter, sitting alongside the wider set of AML and KYC requirements a certification body would test, will find directly applicable EU text sitting above their national regulator’s handbook.

InstrumentLegal natureDate that matters
Regulation (EU) 2024/1624 (AMLR)Directly applicable regulationApplies from 10 July 2027
Directive (EU) 2024/1640 (AMLD6)Directive requiring transpositionNational law due by 10 July 2027
Regulation (EU) 2024/1620 (AMLA Regulation)Directly applicable regulationApplied from 1 July 2025
Regulation (EU) 2023/1113 (transfers of funds)Directly applicable regulationApplied from 30 December 2024

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism has been operational since 1 July 2025 and is seated in Frankfurt. Its founding regulation applied in full from that date, with the exception of Article 103, which took effect on 31 December 2025 and moved the European Banking Authority’s AML and CFT mandate across. Professional football clubs and agents, added as obliged entities by the same package, are held back until 10 July 2029. Gambling providers get no such staggered entry.

Why Online Gambling Cannot Be Exempted Under Article 4

For the first time, EU law defines what gambling actually is. Article 2(1)(12) of the AMLR describes a gambling service as one involving a stake of monetary value in games of chance, including games with a skill element, covering lotteries, casino games, poker and betting transactions, whether supplied at a physical location or at a distance by electronic means. No national implementation is needed to give that definition effect, and no member state can narrow it.

Article 4 preserves a discretion that existed under the fourth directive: a member state may identify gambling services carrying low money laundering risk and decide not to apply some or all of the regulation to them. The discretion is narrower than it looks. The Commission may approve or reject those decisions, so a national carve-out is no longer a purely domestic act, and the recitals rule out any exception for activities associated with higher risk. Casinos, online gambling and sports betting are named as exactly that. Only state-administered online gambling sits outside the exclusion, whether the state supplies the service directly or regulates how it is organised and run.

AMLD6 pulls in the same direction from the supervisory side. Its Article 4(2) obliges member states to ensure that providers of gambling services are regulated, which closes the gap in jurisdictions where certain products sat outside any licensing perimeter. Anyone mapping obligations across markets should read the AMLR alongside the licensing picture that the national gambling regulators by country still control, because the package harmonises AML duties without touching who may lawfully offer a product.

The EUR 2,000 Threshold Changes When Verification Must Happen

Article 19 sets the trigger points, and the figure that governs the gambling sector is lower than the general one. The customer due diligence threshold for gambling transactions bites at EUR 2,000, applied to a stake wagered or winnings collected, whether in a single operation or through linked transactions. The practical consequences run through the whole player lifecycle.

  • Full due diligence is owed when a business relationship is established, which for a remote operator means registration rather than first deposit.
  • Occasional transactions bring the general EUR 10,000 threshold into play, while the gambling-specific EUR 2,000 figure applies to wagering and to collection of winnings.
  • Linked transactions must be aggregated, so structured deposits sitting just under the trigger cannot be treated as separate events.
  • Suspicion of money laundering or terrorist financing overrides every derogation, exemption and threshold in the article.
  • Doubts about the veracity of identification data already held reopen the obligation, regardless of how long the account has been active.
  • Land-based venues may satisfy identification on entry to the premises, provided systems can attribute transactions to specific customers. Remote operators have no equivalent shortcut.

AMLA was mandated under Article 19(9) to submit draft regulatory technical standards to the Commission by 10 July 2026, specifying which sectors and transactions warrant lower thresholds and how occasional and linked transactions are to be identified. Operators reworking KYC onboarding standards ahead of the deadline should assume the gambling threshold is a floor rather than a settled number, and should build aggregation logic that can be retuned without re-engineering the verification flow.

Who Owns the Business-Wide Risk Assessment Under Article 10

The package converts a documentation exercise into a named accountability. Article 10 requires the business-wide risk assessment to be drawn up by the compliance officer and approved by the management body in its management function, then communicated to the supervisory function where one exists. Approval by a committee that never read the document will not survive an inspection built around that wording.

Article 11 splits the compliance role in two. One member of the management body is appointed compliance manager, responsible for matching policies to the entity’s risk exposure and for allocating people and technology to the task. Beneath that sits the compliance officer, who runs day-to-day execution and must be shielded from retaliation and from commercial pressure exerted by revenue-facing teams. Both the compliance officer and the internal audit function need direct access to the management body.

Article 9(2)(a) lists ten internal policies and procedures every obliged entity must hold, from due diligence through record retention to staff training, with the risk assessment first among them. Operators building an AML programme around FATF methodology will recognise the components; what is new is that the sequence, the sign-off and the reviewer are prescribed in directly applicable law rather than left to a national supervisor’s guidance note. GICNT-AML certification tests the same governance chain through an annual third-party audit, and evidence of who approved what, and when, is the part operators most often cannot produce.

Tasks a Gambling Operator May Never Outsource to a KYC Vendor

Article 18 is the first EU-level provision to regulate AML outsourcing comprehensively, and it draws a hard line around decision-making. Service providers are treated as part of the obliged entity while performing the task, the supervisor must be notified before the provider starts work, and full liability for every act and omission stays with the operator. Six categories cannot be delegated under any circumstances.

  • Proposing and approving the business-wide risk assessment.
  • Approving internal AML and CFT policies, procedures and controls.
  • Deciding the risk profile attributed to a customer.
  • Deciding whether to enter into a business relationship or carry out an occasional transaction.
  • Reporting suspicions and threshold-based reports to the financial intelligence unit, except where the task moves to another obliged entity in the same group and the same member state.
  • Approving the criteria used to detect suspicious or unusual transactions and activities.

Everything operational remains delegable. Document verification, data collection, identity checks, sanctions screening and the mechanics of transaction monitoring and escalation can all sit with a vendor, provided the written agreement, the qualification assessment and the periodic controls required by Article 18(4) are in place. Outsourcing to providers established in high-risk third countries is prohibited outside a narrow set of conditions, which matters for operators running verification desks offshore.

How AMLA Reaches Operators It Does Not Directly Supervise

AMLA supervision touches the iGaming sector without ever naming an operator. Direct supervision is reserved for credit and financial institutions: up to 40 groups and entities operating in at least six member states and carrying the highest assessed risk. Selection begins on 1 July 2027 and must conclude within six months, with supervision transferring on 1 January 2028 and the list reviewed every three years. Gambling providers are non-financial obliged entities and cannot be selected.

Supervisory layerWho it coversEffect on gambling operators
AMLA direct supervisionUp to 40 credit and financial institutions active in at least six member statesNone; the sector is outside the eligible population
National supervisorsAll obliged entities not selected, including the entire non-financial sectorPrimary supervisor remains the national AML authority or gambling regulator
AMLA indirect supervisionNational supervisors themselvesBinding technical standards, common risk methodology and convergence reviews reach operators through their own supervisor

The indirect route is where the pressure lands. AMLA is preparing a separate set of draft technical standards on assessing inherent and residual risk profiles for the non-financial sector, distinct from the financial-sector methodology mandated by Article 40(2) of AMLD6. Once those standards bind national supervisors, the risk classification applied to an operator in one market becomes comparable to the classification applied in another. That comparability changes the calculus behind choosing a licensing jurisdiction, because a lighter supervisory touch will be harder to sustain when the methodology behind it is common EU text.

The preparatory work is already visible. AMLA published a reporting package on 12 May 2026 for identifying provisionally eligible entities, national supervisors were required to submit data by 15 August 2026, and a provisional list was expected by the end of September 2026. None of that reaches gambling firms directly, but it establishes the supervisory habits and data expectations that indirect supervision will carry into the sector.

Sanctions Under AMLD6 Reach 10% of Annual Turnover

The ceiling doubles. For serious, repeated or systematic breaches, AMLD6 raises the maximum pecuniary sanction from EUR 5 million or 5% of total annual turnover to EUR 10 million or 10%, whichever is higher. It also sets out a minimum toolkit of administrative measures national supervisors must hold, and allows periodic penalty payments to compel compliance with a measure already imposed rather than merely punish the original failure.

AMLA carries a parallel power over the entities it supervises directly, capped at the same 10% or EUR 10 million figure under Article 22 of Regulation (EU) 2024/1620, with a EUR 5 million ceiling for individuals in management roles and publication of the decision for at least five years. Gambling operators will not sit in that population, but the sanctioning methodology AMLA develops for it shapes what national supervisors are expected to apply. Anyone reading across from historic penalties should note that the enforcement pattern behind regulatory fines in iGaming was set under national law with lower maxima, so past settlement figures are a poor guide to exposure after the transposition deadline.

Preparing an AML Programme Against the July 2027 Deadline

Two and a half years of lead time is less generous than it sounds, because the substantive work sits in systems and evidence rather than in policy text. The AML compliance deadline of 10 July 2027 applies without transition for the gambling sector, and readiness for an online casino operating across several EU markets is mostly a data and governance problem.

  • Map every jurisdiction where the entity holds a licence or serves customers, and identify which national requirements survive the AMLR as permitted additional measures under Article 8.
  • Rebuild aggregation logic so that stakes and winnings are cumulated against the EUR 2,000 trigger across products, wallets and linked accounts.
  • Document the approval chain for the business-wide risk assessment, including who proposed it, who approved it and on what date.
  • Re-paper vendor contracts so that non-outsourceable decisions demonstrably sit inside the entity, and notify supervisors of arrangements that continue.
  • Align retention practice with Article 77, which sets five years from the end of the business relationship or the date of the occasional transaction, extendable by a further five years where a member state finds it necessary and proportionate.
  • Review enhanced due diligence triggers, since PEP screening and enhanced due diligence obligations under Articles 42 to 46 apply from the same date and cover family members and known close associates.
  • Confirm that beneficial ownership identification uses the 25% ownership criterion and that discrepancies with central registers are reported as Article 24 requires.

GICNT-AML frames these as certification conditions rather than as aspirations, and the annual third-party audit cycle is deliberately timed to give operators an external read on their programme before a supervisor forms one. Certification carries no licensing effect and substitutes for nothing a national authority requires; it evidences that the controls a regulator will test have been examined independently.

Frequently Asked Questions on the EU AML Package and Gambling

Does the AMLR replace national AML rules for gambling operators entirely?

Not entirely. The AMLR is directly applicable and supersedes national provisions covering the same ground from 10 July 2027, but member states may still impose additional requirements to mitigate specific risks. Article 8 determines which national rules apply when an operator provides services outside its home member state, so multi-market licensees still need a jurisdiction-by-jurisdiction overlay.

Will AMLA directly supervise online gambling operators?

No. Direct supervision from 1 January 2028 is limited to up to 40 credit and financial institutions active in at least six member states. Gambling providers are non-financial obliged entities and remain with their national supervisor, which will itself be bound by AMLA technical standards and convergence oversight.

What is the customer due diligence threshold for gambling under the AMLR?

Due diligence is triggered at EUR 2,000 for a stake wagered or winnings collected, in a single operation or through linked transactions. That sits below the general EUR 10,000 occasional transaction threshold, and suspicion of money laundering triggers due diligence at any value.

Can a member state exempt online casinos from the regulation?

No. Article 4 allows exemptions for gambling services shown to carry low risk, subject to Commission approval, but the regulation excludes higher-risk activities from any exception. Casinos, online gambling and sports betting are named. Only state-administered online gambling can fall within a national carve-out.

How long must operators retain customer due diligence records?

Article 77 sets five years from the end of the business relationship or the date of an occasional transaction, harmonising what were previously divergent national retention periods. Member states may extend that by up to a further five years where they assess the extension as necessary and proportionate.