AML requirements for online casino operators account for a large share of the penalties regulators issue in this industry, and GICNT-AML is the domain where certification most often stalls. It is the anti-money laundering standard inside the GICNT compliance framework, mandatory for every certified operator and reviewed through an annual audit carried out by an external party rather than by GICNT itself.
What GICNT-AML Requires of a Certified Operator
GICNT-AML treats an operator’s controls as a system rather than as a folder of policies. Certification turns on whether the controls exist, whether they work, and whether the operator can demonstrate both to someone outside the business. The standard is written against the FATF Recommendations rather than any single national rulebook, because certified operators hold licences in different jurisdictions and meet the same underlying obligation in different statutory wording.
The domain requires each of the following:
- a business-wide money laundering and terrorist financing risk assessment, approved at senior level and revisited whenever products, markets or payment methods change
- a named money laundering reporting officer with authority to suspend an account and standing to report directly to the board
- customer due diligence completed and evidenced before the relationship carries material risk, rather than retrospectively at the point of a large withdrawal
- verification of source of funds, and of source of wealth where the risk profile calls for it
- enhanced due diligence for politically exposed persons, their family members and known close associates
- transaction monitoring with documented escalation, so that every alert has a recorded outcome and a named decision maker
- an annual audit performed by a party independent of the function being reviewed
Operators building this from a standing start usually work outwards from an AML programme aligned with FATF, then map it onto the specific obligations of the licensing jurisdiction, rather than the other way round.
How FATF Recommendations Reach Online Gambling Operators
The FATF Recommendations bind countries, not companies. Operators meet them second hand, through the national statute that transposes them and through the supervisor that enforces it. That transmission explains why the same international text produces very different national trigger points.
Recommendation 22 brings casinos into scope as designated non-financial businesses and professions, and its interpretive note sets the due diligence trigger at USD/EUR 3,000 for financial transactions, whether carried out in a single operation or in several that appear to be linked. Recommendation 10 supplies the due diligence measures themselves, Recommendation 12 covers politically exposed persons, and Recommendation 20 requires the reporting of suspicion. Read together, what the FATF Recommendations expect of casinos is a risk-based programme: identify the customer, understand the relationship, watch it, and report when the activity stops making sense.
Definitions travel badly between regimes, which is why written policy should follow the supervisor’s vocabulary rather than industry shorthand. AML and KYC terminology shifts in meaning between the FATF text, the EU rulebook and the British statutory instrument, most visibly around the words occasional transaction and business relationship.
Customer Due Diligence Thresholds by Licensing Jurisdiction
A single customer due diligence threshold for casino transactions does not exist across the markets a certified operator is likely to serve. The trigger points below are those in force at the time of writing, each with the instrument that creates it.
| Jurisdiction | Instrument | What triggers due diligence or reporting | Status |
|---|---|---|---|
| European Union | Regulation (EU) 2024/1624 (AMLR) | Collection of winnings, wagering of a stake, or both, at EUR 2,000 or more, single or linked transactions | Applies from 10 July 2027; national transpositions of the earlier directives apply until then |
| Malta | PMLFTR and FIAU Implementing Procedures Part II for the remote gaming sector | Due diligence and a customer risk assessment by the first withdrawal, or once deposits reach EUR 2,000 over a rolling 180-day period, whichever comes first | In force; supervised by the FIAU in cooperation with the MGA |
| Great Britain | Money Laundering Regulations 2017 and LCCP licence condition 12.1.1 | Casino licensees fall inside the Regulations; every licensee must hold an ML/TF risk assessment and controls that reflect Commission guidance | In force; emerging risk bulletins must be taken into account under condition 12.1.1(3) |
| Australia | AML/CTF Act as amended by the AML/CTF Amendment Act 2024 | Initial due diligence exemption threshold for gambling services lowered from AUD 10,000 to AUD 5,000 | Reformed obligations commenced 31 March 2026; initial due diligence transition runs to 30 March 2029 |
| Canada | PCMLTFA and FINTRAC guidance | Large cash transaction reports at CAD 10,000, including amounts aggregated inside a 24-hour window; casino disbursement reports at the same figure | In force; cash reports filed within 15 calendar days, casino disbursements within 5 business days |
Thresholds mark the point at which verification becomes compulsory, not the point at which it becomes sensible. The KYC requirements gambling operators actually work to tend to run ahead of the statute, because an unverified account that has already been funded is awkward to remediate without freezing player money. Most supervisors now expect KYC onboarding standards that place identity verification before the first withdrawal in every case.
Verifying Source of Funds Before a Withdrawal Is Released
Source of funds asks where the money in this relationship came from. Source of wealth asks how the customer’s total assets were built. The two checks answer different questions and fail differently on audit: a payslip explains a deposit, it does not explain a portfolio. GICNT-AML requires the answer to be evidenced and recorded, not asserted by the customer in a free-text field.
- Fix the trigger. Deposit velocity, cumulative turnover, a change in risk rating, a mismatch between declared occupation and observed play, or a screening match.
- Request documents that carry independent corroboration: bank statements showing salary credits, sale contracts, tax filings, dividend or trust records. Screenshots are not evidence.
- Test the file for consistency. Does declared income support observed deposits across the same period, and does the customer’s stated occupation support the declared income?
- Record the reasoning, the reviewer and the date, then set the point at which the evidence is treated as stale and refreshed.
Where the funds themselves look unremarkable but the overall picture does not, source of wealth verification becomes the harder exercise, and it is the one external auditors sample first.
Screening Politically Exposed Persons and Applying Enhanced Due Diligence
Enhanced due diligence for gambling operators is at its most prescriptive around politically exposed persons, because the obligations are drafted as concrete steps rather than as outcomes.
- Senior management or MLRO approval before the relationship is established or continued. In Great Britain this sits in regulation 35(5)(a) of the Money Laundering Regulations 2017.
- Establishing source of wealth and source of funds for the relationship, and holding the documents that support the conclusion.
- Enhanced ongoing monitoring, with more frequent and more sceptical review of activity than the standard population receives.
- Coverage of family members and known close associates, which is where screening most often falls short.
- Continued enhanced treatment for at least 12 months after the person leaves the public function, followed by a risk-based decision rather than an automatic downgrade.
- Under the EU rulebook the same measures appear in Articles 42 to 46 of Regulation (EU) 2024/1624, applicable from 10 July 2027.
A domestic politically exposed person is not automatically high risk in every regime, and British supervisors have pushed firms away from treating them that way. The judgement has to be written down: PEP screening obligations are met by a reasoned classification, not by the absence of a match in a database.
What Transaction Monitoring Must Show an Auditor
Monitoring is judged on its output. A reviewer reads alerts, dispositions and the trail between them, and a rule set that never produces an escalation is read as evidence of miscalibration rather than of an unusually clean customer base.
| Typology | What the system should detect | Expected response |
|---|---|---|
| Threshold avoidance | Deposits held just below a verification or reporting trigger, repeated across days, brands or outlets | Aggregation at customer level across every brand and channel, then review against the cumulative figure |
| Low-play churn | Funds deposited and withdrawn with minimal wagering in between | Hold the withdrawal, request source of funds, record the outcome either way |
| Third-party funding | Payment instruments held in a name other than the account holder’s | Reject the instrument, verify ownership, consider whether suspicion has arisen |
| Value transfer between players | Coordinated losses at the same table, or repeated transfers between the same accounts | Game-level review read alongside the payment record |
| Jurisdictional exposure | Logins, documents or payment origins tied to high-risk third countries | Enhanced due diligence and a sanctions check before the next transaction is processed |
| Account takeover | Device, address and behaviour changes followed by immediate withdrawal attempts | Freeze the withdrawal, re-verify the account holder, treat as potential handling of criminal property |
An alert is worth what its audit trail is worth. Transaction monitoring and escalation has to name the reviewer, the decision and the reason, in a record that survives staff turnover.
Reporting Suspicion: The MLRO Decision Trail
Suspicion is a low bar and a legal one. Once it exists, the operator reports to the national financial intelligence unit: the National Crime Agency in the United Kingdom, the FIAU in Malta, FINTRAC in Canada, AUSTRAC in Australia. Anti-money laundering compliance in iGaming comes apart at this stage more often than at detection, not because reports are never filed, but because the reasoning behind the ones that were not filed was never written down.
Three habits separate a defensible file from an indefensible one. Internal reports reach the MLRO through a fixed channel rather than by ad hoc message. The MLRO’s decision, including a decision not to report, carries a written rationale. Records are retained for the statutory period, commonly five years, in a form that can be produced on request without reconstruction.
Tipping off is a separate offence in most regimes, so customer-facing wording after a report should be agreed in advance with the MLRO. Support staff cannot be left to improvise an explanation for a frozen withdrawal.
Evidence the Annual Third-Party AML Audit Expects
GICNT-AML requires the audit to be performed each year by a party independent of the function it reviews. An AML audit of a gambling operator looks for artefacts, and their absence is what generates findings.
- the current risk assessment, with version history showing what changed and why
- a traceable line from each identified risk to the control that addresses it
- a sample of customer files covering standard cases, enhanced cases and refused relationships
- MLRO reporting to the board, with dates, attendance and follow-up actions
- training records, including completion rates and role-specific content for payments and VIP staff
- monitoring documentation: thresholds, tuning decisions, alert volumes and disposition rates
- the suspicious report register, with the rationale recorded for each decision
- remediation from previous audits, closed out and evidenced rather than carried forward
Why Recent Enforcement Cases Turn on the Same Failures
On 23 July 2026, the Gambling Commission announced that Evolution Malta Holding Limited would make a payment in lieu of a financial penalty of £4,750,000 after its games were found on six unlicensed websites reaching consumers in Great Britain. The finding was not that the games were counterfeit. It was that the supplier’s assessment of its own money laundering and terrorist financing risk was not effective enough to flag that two businesses it dealt with were supplying that content into the British market without a Commission licence, with large volumes of visits recorded between December 2023 and November 2024.
Four months earlier, on 23 March 2026, the Financial Intelligence Analysis Unit in Malta imposed an administrative penalty of EUR 225,730 on Stanleybet Malta Limited under Regulation 21 of the PMLFTR, together with a periodic penalty of EUR 2,000 per day until remediation and a follow-up directive. Due diligence had been applied only where a customer deposited EUR 2,000 or more in one transaction, or reached that figure inside a single betting shop on a single day, with staff relying on recognising customers by sight. Activity was not linked across the network, and the rolling 180-day calculation set out in the Implementing Procedures was not performed. The decision is subject to appeal.
Neither case involved an exotic laundering scheme. Both turned on aggregation and on a risk assessment that had stopped describing the business it belonged to, which is the pattern running through most published regulatory fines in iGaming.
Common Questions About GICNT-AML Certification
Does GICNT-AML certification replace a gambling licence?
No. GICNT is a certification body, not a licensing authority and not a supervisor. Certification records that an operator’s controls were assessed against the framework. It does not authorise gambling activity and it removes no obligation owed to a national regulator or financial intelligence unit.
What triggers customer due diligence for an EU-facing operator?
Until 10 July 2027 the national law transposing the earlier directives applies. From that date Regulation (EU) 2024/1624 sets a EUR 2,000 trigger on the collection of winnings, the wagering of a stake, or both, counting linked transactions together. Member States may exempt certain gambling services where low risk is demonstrated.
How often should a money laundering risk assessment be reviewed?
At least annually, and immediately after any material change: a new market, a new payment method, a new product vertical, or a shift in the customer base. Both enforcement cases above involved assessments that had fallen out of step with the business they described.
Who is independent enough to perform the annual AML audit?
Anyone outside the line of responsibility for the controls being tested and without commercial dependence on the result. An internal audit function reporting to the board can qualify in a large business; in a smaller one this normally means an external firm. Compliance staff cannot audit their own programme.
Do betting operators in Great Britain carry the same obligations as casinos?
Not identical ones. The Money Laundering Regulations 2017 apply to casino operators, while every licensee remains bound by licence condition 12.1.1 and by the Proceeds of Crime Act 2002. In practice the Commission expects a risk assessment, proportionate controls and reporting from betting operators as well, and its casework bulletins address them separately.