AML and KYC terminology in gambling compliance is not one shared vocabulary, and treating it as one is where operators get caught. The same player check is a threshold transaction in Great Britain, a due diligence trigger in Malta and an unusual transaction in the Netherlands. Each definition below is fixed to the instrument that creates it and to the duty it imposes on a licensed operator.
How AML Terminology Maps onto Gambling Regulation
Gambling sits inside the anti-money laundering perimeter because the Financial Action Task Force classifies casinos as designated non-financial businesses and professions. Recommendation 22 extends the customer due diligence and record-keeping duties written for banks to casinos once a customer engages in financial transactions at or above USD/EUR 3,000, whether in a single operation or in several operations that appear to be linked. National statute, supervisory guidance and licence conditions are all interpretations of that starting position.
The interpretations diverge more than the shared abbreviations suggest. In Great Britain the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 bite only on remote and non-remote casino operating licences, while every other gambling licensee is caught instead by the Proceeds of Crime Act 2002 and by licence condition 12.1.1 of the LCCP, which requires a money laundering and terrorist financing risk assessment from almost all operating licensees. In the European Union, Regulation (EU) 2024/1624 supplies the first EU-level definition of a gambling service and applies directly from 10 July 2027, removing the national transposition layer that produced twenty-seven near-identical but not identical vocabularies. Reading AML requirements for operators without first establishing which instrument is speaking produces confident answers that are wrong in the operator’s own jurisdiction.
Foundational Terms Every Compliance Function Uses
These terms appear in almost every policy document, and they are the ones most often used loosely.
- AML, anti-money laundering. The controls that prevent criminal proceeds from being placed, layered or integrated through a business. CFT, countering the financing of terrorism, addresses a separate risk with overlapping mechanics and is normally drafted into the same instrument, which is why the compound form AML/CFT is standard.
- Risk-based approach. Recommendation 1 requires obliged entities to identify their exposure and allocate controls in proportion to it. A risk-based approach to AML in gambling begins with a documented business-wide assessment, not with an individual player, and the allocation of resource has to be evidenced rather than asserted.
- Business risk assessment. The firm-level analysis of exposure across customers, products, delivery channels, payment methods and geography. It is the document a supervisor asks for first.
- Customer risk assessment, or CRA. The player-level equivalent, producing a rating that determines how much due diligence applies and how closely activity is monitored.
- KYC, know your customer. Industry shorthand for identifying and verifying a player and keeping that record current. It is rarely a defined legal term; the statutory concept is customer due diligence, and KYC onboarding checks are the workflow through which an operator discharges it.
- Obliged entity, subject person, relevant person. Three names for the same status, meaning a business inside the scope of AML law. EU instruments use obliged entity, Maltese law uses subject person, the British regulations use relevant person.
- DNFBP. Designated non-financial business or profession, the FATF category into which casinos fall.
- FIU. The national financial intelligence unit that receives reports: the UK Financial Intelligence Unit inside the National Crime Agency, the FIAU in Malta, FIU-Nederland in the Netherlands.
- Tipping off. The offence of disclosing to a customer, or to anyone else, that a report has been made or that an investigation is under way or contemplated.
Where Due Diligence Thresholds Actually Bite
A threshold is the point at which a definition becomes an obligation, and it is the most commonly misquoted figure in gambling AML because four numbers are in circulation and each belongs to a different instrument.
| Instrument | Threshold | What triggers it | Status |
|---|---|---|---|
| FATF Recommendation 22 | USD/EUR 3,000 | Financial transaction, single or several that appear linked | International standard, not directly binding |
| UK MLR 2017, regulation 27(5) and (6) | GBP 2,000 | Stake, deposit of funds for remote gambling, or collection of winnings | Converted from EUR 2,000 on 30 June 2026 |
| EU Regulation 2024/1624 (AMLR) | EUR 2,000 | Casino gambling transaction, with member state discretion to set a lower figure | Applies from 10 July 2027 |
| Malta, FIAU Implementing Procedures Part II | EUR 2,000 | Cumulative deposits over a rolling 180-day period, or the first withdrawal, whichever comes first | In force |
The customer due diligence obligations of an online casino do not sit still. From 30 June 2026 the British regulations narrow mandatory enhanced due diligence on geographic grounds to countries on the FATF Call for Action list rather than the Increased Monitoring list, and the enhanced measures trigger for unusually complex transactions instead of all complex ones. Geographic risk factors under regulation 33(6)(c) still have to be weighed in the customer risk assessment, so the change reduces the automatic trigger without reducing the analysis. Operators preparing for the EU AML package should treat July 2027 as an alignment deadline rather than a start date.
Source of Funds and Source of Wealth Answer Different Questions
Source of funds, abbreviated SoF, is the origin of the specific money moving in a given transaction: the salary credit, the property sale, the account the deposit left. Source of wealth, or SoW, is the wider question of how the customer accumulated their assets in the first place. An operator can trace the origin of a EUR 40,000 deposit and still have no view on whether a player on a declared salary could plausibly hold that money at all, which is why source of funds verification is documented separately from source of wealth enquiries.
The distinction is enforced rather than academic. On 23 March 2026 the FIAU imposed an administrative penalty of EUR 225,730 on Stanleybet Malta Limited, a remote gaming licensee, together with a periodic penalty payment of EUR 2,000 per day and a follow-up directive. Among the findings, onboarding forms recorded employment status as broad categories such as employed, unemployed or student, and expected source of funds as savings, wages or dividends, with some fields left blank altogether. The FIAU committee held that descriptors of that kind never satisfy the profiling obligation, whatever the customer risk rating, because they do not explain how the funds were accumulated or what the underlying source was. Verification of source of funds in gambling has to produce information that can be tested against what the player actually does.
Screening Terms: PEPs, Sanctions and Adverse Media
Screening vocabulary covers three checks that run on different legal bases and different timings, which is why politically exposed person screening cannot simply be bolted onto a sanctions filter and treated as one control.
- PEP. A politically exposed person, meaning an individual entrusted with a prominent public function. Recommendation 12 calls for senior management approval before the relationship proceeds, establishment of source of wealth and source of funds, and enhanced ongoing monitoring throughout.
- Domestic and non-domestic PEP. Since 10 January 2024 regulation 35 of the British regulations has required the starting point for a domestic PEP, or a family member or known close associate, to be a lower level of risk than a non-domestic PEP, with lighter enhanced measures where no other enhanced risk factors are present. It is a starting point for assessment, not an exemption from it.
- RCA. Relatives and close associates, brought into scope alongside the PEP because the exposure travels through them.
- Sanctions screening. A distinct legal obligation with no risk-based discretion attached. Maltese guidance is explicit that screening is completed regardless of whether the customer has reached the due diligence threshold, because the obligation arises outside the AML instrument.
- Adverse media, sometimes negative news screening. Open-source checking for criminal proceedings, regulatory action or credible reporting that changes the risk picture. Screening for politically exposed persons in iGaming is usually run in the same pass, though the two produce different escalation routes.
- UBO. Ultimate beneficial owner, the natural person who ultimately owns or controls a corporate customer. It matters for affiliate counterparties, white-label partners and payment intermediaries rather than for retail players.
Reporting Abbreviations Change Name at the Border
The report itself is broadly the same document everywhere. Its name, its recipient and the standard that triggers it are not.
| Jurisdiction | Report | Recipient | Trigger standard |
|---|---|---|---|
| International standard | STR, suspicious transaction report | National FIU | Suspicion that funds are proceeds of crime or relate to terrorist financing |
| Great Britain | SAR, suspicious activity report; DAML SAR where a defence is sought | UK Financial Intelligence Unit, National Crime Agency | Knowledge, suspicion or reasonable grounds for suspicion |
| Malta | STR filed through goAML | FIAU | Suspicion, with no monetary threshold |
| Netherlands | Unusual transaction report | FIU-Nederland | Objective indicator, reported automatically, or subjective indicator, assessed case by case |
The Dutch construction catches operators trained on a suspicion standard. The Wet ter voorkoming van witwassen en financieren van terrorisme, the Dutch money laundering and terrorist financing prevention act known as the Wwft, requires reporting of transactions that are unusual rather than suspicious, and FIU-Nederland decides whether an unusual transaction is reclassified as suspicious and passed to prosecutors. Gaming casinos work from a defined set of indicators, and since October 2025 subjective-indicator reports submitted without a description of the circumstances are rejected outright. Suspicious activity reports filed by casino licensees in Great Britain sit alongside a separate figure: since 31 July 2025 the threshold in section 339A of the Proceeds of Crime Act 2002 has been GBP 3,000, raised from GBP 1,000, below which a casino may return funds to exit a customer relationship without submitting a defence against money laundering request. The duty to submit an information report where there is knowledge or suspicion is untouched by that threshold. So is the risk of split transactions engineered to sit just underneath it, which is what transaction monitoring processes exist to surface.
What the MLRO Role Carries in a Gambling Operator
MLRO stands for money laundering reporting officer. In British law the equivalent statutory concept is the nominated officer, the individual to whom internal reports are made under sections 330 to 332 of the Proceeds of Crime Act 2002 and who decides whether a report goes to the financial intelligence unit. Maltese law names the MLRO directly, and the FIAU Implementing Procedures set expectations on who may hold the role, including seniority, independence and enough time to discharge it. The MLRO is not interchangeable with the compliance officer, and in several jurisdictions it is a separately approved function.
The role of an MLRO at a gambling operator is routinely under-resourced, and supervisory findings repeat the same three patterns. The officer holds a commercial role that conflicts with the reporting duty. The escalation path from first-line analysts exists in practice but not in writing, so nothing can be evidenced after the fact. Or the officer has no authority to freeze an account or hold a withdrawal without commercial sign-off, which converts an independent judgement into a negotiation. An AML programme aligned with FATF recommendations should record who may override an escalation, on what grounds, and where that decision is logged.
Payment and Crypto Terminology Operators Now Have to Know
Crypto deposits import a second vocabulary, drawn from financial services rather than gambling law.
- Travel rule. Recommendation 16 requires originator and beneficiary information to accompany a transfer. In the European Union, Regulation (EU) 2023/1113 applies from 30 December 2024 and, unlike the funds transfer rules it recast, sets no de minimis for crypto-asset transfers: the data must travel whatever the amount.
- VASP and CASP. Virtual asset service provider is the FATF term; crypto-asset service provider is the European term used in MiCA, Regulation (EU) 2023/1114, which also applies from 30 December 2024. The two are not perfectly co-extensive, and contracts that use them interchangeably create gaps.
- Self-hosted wallet, also called an unhosted wallet. An address controlled by the user rather than by a service provider. Transfers to or from a self-hosted address at or above EUR 1,000 attract additional checks on ownership or control.
- Sunrise issue. The mismatch that arises when a compliant service provider transacts with a counterparty in a jurisdiction that has not implemented the travel rule, so the data exchange fails at one end.
- On-ramp and off-ramp. The points at which fiat becomes crypto and crypto becomes fiat. The travel rule for crypto in gambling matters most here, because a gambling operator is usually not a CASP itself, yet it inherits counterparty exposure the moment deposits arrive through a processor, which is where AML controls on crypto payments most often break down.
How GICNT-AML Applies These Definitions
Anti-Money Laundering and KYC is the GICNT-AML domain within the GICNT framework v4.2. It is a mandatory domain and is assessed through an annual third-party audit. GICNT is an independent certification body rather than a licensing or supervisory authority, and certification neither creates legal obligations nor substitutes for an operating licence.
At the definitional level GICNT-AML asks for a mapping rather than a glossary: each term used in an operator’s policy tied to the instrument that governs it in the licensing jurisdiction, with the applicable threshold, the trigger event and the reporting route stated on the face of the document. A policy that defines customer due diligence in generic terms, without naming the regulation and the figure, cannot be audited against anything. Where an operator holds licences in more than one jurisdiction, the mapping is maintained per licence, because the same defined term will carry different numbers and sometimes a different reporting standard entirely.
Frequently Asked Questions on AML and KYC Terminology
What is the difference between KYC and CDD?
Customer due diligence is the legal obligation: identifying the customer, verifying identity from reliable and independent sources, understanding the purpose of the relationship and monitoring it on an ongoing basis. KYC is the industry name for the operational workflow that delivers it. The practical consequence is that satisfying an internal KYC process does not by itself evidence compliance if the process was never mapped to the statutory measures.
Does an online casino have to verify a player before the first deposit?
It depends on the regime, and the answer is often driven by licence conditions rather than AML law. In Great Britain, licence condition 17.1.1 requires remote licensees to obtain and verify at least name, address and date of birth before a customer is permitted to gamble, which is separate from the money laundering threshold. In Malta, the Implementing Procedures require customer due diligence by the first withdrawal or once cumulative deposits reach EUR 2,000 over a rolling 180-day period, whichever comes first.
What is the difference between an STR and a SAR?
They describe the same act of reporting a suspicion to a financial intelligence unit. Suspicious transaction report is the international and Maltese term, suspicious activity report is the British one, and the British form covers conduct that is not strictly a transaction. The Netherlands departs from both by requiring reports of unusual transactions, with the reclassification to suspicious made by FIU-Nederland rather than by the operator.
Who can act as MLRO for a remote gambling operator?
Requirements vary by jurisdiction, but the recurring expectations are seniority, sufficient independence from commercial functions, adequate time and resource, and direct access to the board. Some regulators approve the appointment individually, and several treat prolonged vacancy in the role as a reportable event. Outsourcing parts of the function is common; outsourcing accountability for it is not accepted anywhere.
Does the travel rule apply to gambling operators that accept crypto?
The obligation falls on crypto-asset service providers rather than on gambling operators as such, so an operator that accepts crypto through a licensed processor is usually not the obliged entity for the transfer itself. The exposure is indirect and real: the operator relies on that processor for originator data, and a counterparty that cannot supply it leaves the operator unable to establish where deposited funds came from.