An AML programme aligned with the FATF Recommendations rests on five linked parts: a documented risk assessment, controls that answer it, named owners, trained staff, and proof that all of it ran. Supervisors test the last part hardest, and most enforcement follows from it. The GICNT-AML requirements apply that test through an annual third-party audit.
The FATF Recommendations That Shape an Operator AML Programme
The FATF Recommendations bind countries, not operators. National law converts them into duties, and the wording shifts from market to market, but the structure survives translation. Recommendation 22 pulls casinos into the customer due diligence and record-keeping regime that applies to banks once a customer engages in financial transactions at or above the designated threshold. Recommendation 18 describes the programme itself. In February 2025 the FATF rewrote Recommendation 1: the word commensurate became proportionate, countries must now allow and encourage simplified measures in lower-risk situations, and remote onboarding counts as a higher-risk factor only where the operator has failed to mitigate it. That last change carries weight for remote licensees, because distance verification is the whole business model.
| Recommendation | What it sets | Where it lands for an operator |
|---|---|---|
| R.1 | Identification, assessment and mitigation of risk through proportionate measures, with simplified measures available where risk is lower (amended 25 February 2025) | The assessment drives every downstream control, and lighter handling of low-risk segments now has explicit backing |
| R.10 and R.12 | Customer due diligence; enhanced due diligence and senior management approval for politically exposed persons | Verification and PEP handling become procedure-level questions with named decision owners |
| R.11 | Retention of transaction and due diligence records for at least five years | Records have to survive platform migrations and supplier changes |
| R.18 | Internal policies, procedures and controls; a compliance officer at management level; employee screening; ongoing training; an independent audit function | This is the programme, and it is the part operators most often leave implicit |
| R.20 | Prompt reporting of suspicion to the financial intelligence unit | Escalation routes and timing become auditable |
| R.22 | USD/EUR 3,000 threshold for casino customer due diligence, whether the transaction is single or made up of linked operations | Linked-transaction logic has to exist in the monitoring rules, not only in the policy text |
Auditors and supervisors read these texts in their own vocabulary, so drafting internal documents in house shorthand creates friction later. Keeping to the AML and KYC terminology used in the source instruments costs nothing and removes an argument during review.
The Business-Wide Risk Assessment Comes First
A business-wide risk assessment for an iGaming operator starts from its own book: the customers on it, the games it runs, the payment rails it accepts, the markets it takes traffic from. In Great Britain, regulation 18 of the Money Laundering Regulations 2017 requires a written assessment covering customers, geographic areas, products and services, transactions and delivery channels, and licence condition 12.1.1 of the LCCP requires a review at least annually and whenever circumstances change materially. In the European Union, Article 10 of the AML Regulation gives the business-wide risk assessment a dedicated article from 10 July 2027. Maltese licensees already have to record the document version, the date of the latest revision and the date the board approved it.
The Gambling Commission published an updated Risk Assessment of Money Laundering and Terrorist Financing in the British Gambling Industry on 30 July 2026, replacing its 2023 analysis and drawing on the UK National Risk Assessment 2025. Casino licence holders must take it into account under the Money Laundering Regulations; every other licensee is expected to consider the sections relevant to its business and to update its own assessment where the ratings have moved. The risk-based approach to AML in gambling collapses when the sector assessment lands and nobody reopens the internal one.
Factors worth their own analysis rather than a single line in a matrix:
- Customer segments, including high-value play and accounts funded by third parties
- Product mix, including bonus mechanics that allow low-margin turnover
- Delivery channels and the point at which verification blocks play
- Payment methods, where prepaid instruments carry a high rating in the Commission analysis and crypto payment AML controls need separate treatment
- Geography, both licensed markets and the residence of the customer base
- Third parties: affiliates, payment providers, outsourced verification and monitoring vendors
Turning the Assessment Into Policies, Procedures and Controls
Approval sits at the top in every regime. Regulation 19 of the Money Laundering Regulations 2017 requires written policies, controls and procedures approved by senior management. Article 9 of the AML Regulation requires the management body to approve internal policies, with procedures and controls approved at least at the level of the compliance manager. In Canada, written compliance policies and procedures must be kept up to date and approved by a senior officer. AML policies and procedures across the casino product should then answer five questions in a form a new starter can follow:
- What triggers action, expressed as a threshold, a pattern or an event
- Who decides, by role rather than by name
- Within what window, in hours or days
- What evidence closes the item, and what happens when the customer supplies nothing
- Where the decision and its reasoning are recorded
Malta gives a worked example of the fourth point: a customer risk assessment falls due within 30 days of a customer meeting the EUR 2,000 deposit threshold, and the Implementing Procedures set out what has to happen once that window passes with due diligence still incomplete. KYC onboarding standards should state the same thing in operational terms, down to the point at which the account stops accepting deposits.
Who Owns the Programme: The MLRO and the Compliance Function
The MLRO role at a gambling operator carries personal exposure, not only organisational responsibility. Under the Money Laundering Regulations 2017 the nominated officer receives internal reports and decides whether to report to the National Crime Agency, and failure to disclose is a criminal matter under the Proceeds of Crime Act 2002. Regulations vary on how the seniority is split.
| Regime | Senior owner | Day-to-day role |
|---|---|---|
| FATF R.18 | Compliance officer at management level | Ongoing training and an independent audit function sit alongside the role |
| Great Britain, MLR 2017 | Money laundering compliance principal, drawn from the board or senior management (regulation 21) | Nominated officer, in practice the MLRO, receives internal reports and decides on disclosure; one person may hold both roles where sufficiently senior |
| European Union, AMLR from 10 July 2027 | Compliance manager, a member of the management body (Article 11) | Compliance officer of sufficiently high standing, responsible for daily operation and for contact with the authorities |
| Malta, MGA and FIAU | MLRO approved by the MGA as a Key AML Function and registered with the FIAU | Analyses unusual activity and files suspicious transaction reports with the FIAU |
| Canada, PCMLTFA | Senior officer approves the policies and receives review findings | Appointed compliance officer implements the five prescribed elements of the programme |
Escalation is where the role stops being an org chart entry. Transaction monitoring and escalation routes have to deliver the whole file to the MLRO, including the account history and the analyst reasoning, and the MLRO has to be able to stop play without asking commercial colleagues for permission.
AML Training Requirements for Staff Who Touch Player Accounts
AML training requirements for staff run along the same line in each regime: awareness of the law, then recognition of the behaviour, then knowledge of the internal route. Regulation 24 of the Money Laundering Regulations 2017 covers awareness of money laundering, terrorist financing and data protection law and training in how to handle relevant transactions. Article 12 of the AML Regulation carries the awareness obligation into EU law from 2027, with Article 13 adding integrity checks on employees. Canadian reporting entities need a written, ongoing training programme plus a documented plan for delivering it.
The FIAU and the MGA measured how much of this survives contact with a remote operation. In their thematic review of the remote gaming sector, two thirds of MLROs and just over a third of relevant employees could state the inherent risk rating of their own business; half of MLROs and a fifth of relevant employees knew what to do once 30 days had passed with due diligence incomplete. Numbers like that decide how detailed the training has to be on the harder topics, PEP screening and enhanced due diligence among them, where the correct answer is rarely intuitive.
Documenting the Programme for the Annual Audit
An auditor tests whether the programme operated. The document set that supports that answer:
- The risk assessment with its version number, revision date and evidence of board or senior approval
- Policy approvals, with the date and the approving body recorded
- Customer files showing the verification steps in the order the procedure prescribes
- Escalation records, including cases closed without a report and the reasoning behind that decision
- Training records: content, attendance, dates, and refresher cycles by role
- Effectiveness testing. Canadian reporting entities review the programme at least every two years and report findings to a senior officer within 30 days of completion, while the independent audit function for AML controls under Recommendation 18 and regulation 21 runs on the same logic
- Remediation tracking that shows dates of implementation, since the Gambling Commission expects updates to be made in a timely manner and evidenced
GICNT-AML sits on an annual third-party audit, which makes the evidence trail the certification artefact rather than the policy set. Audit frequency by standard differs across the six domains of the framework, and the AML cycle is the strictest of them.
Where AML Programmes Break Down in Enforcement Practice
Recent decisions read as documentation cases. FINTRAC imposed a penalty of CAD 212,025 on Atlantic Lottery Corporation on 29 May 2026, announced on 9 July 2026, for failing to submit a suspicious transaction report, failing to develop and apply written compliance policies and procedures that were kept up to date and approved by a senior officer, and failing to assess and document money laundering and terrorist financing risk. The operator paid rather than appeal, and the findings were administrative.
The same supervisor imposed CAD 1,075,000 on British Columbia Lottery Corporation on 17 July 2025 for failing to report suspicious transactions and for the absence of policies, procedures and special measures covering high-risk clients. In Great Britain, QuinnBet (Gibraltar) Limited agreed a regulatory settlement of GBP 609,104, including disgorgement of GBP 193,118, announced on 20 August 2026 after a compliance review spanning March 2023 to August 2025; the Gambling Commission found controls unable to act in a timely manner and suspicious activity reports submitted late.
One pattern connects all three. The documents existed. What the operator could not show was that they were current, approved by the right person, and applied to the accounts in front of them. FINTRAC issued 35 notices of violation in its 2025 to 2026 year, the highest count in its history, which suggests supervisors are testing programmes rather than reading them. Reading through regulatory fines in iGaming by category shows how few of these decisions turn on a laundering event as opposed to a control gap.
Thresholds and Dates to Build the Programme Around
| Reference point | Value | Instrument |
|---|---|---|
| Casino due diligence threshold | USD/EUR 3,000, single or linked transactions | Interpretive Note to FATF Recommendation 22 |
| EU gambling due diligence threshold | EUR 2,000 on the wagering of a stake, the collection of winnings, or both | AMLR Article 19(5) |
| EU cash occasional transactions | EUR 3,000 | AMLR Article 19(4) |
| AMLR application date | 10 July 2027 | Regulation (EU) 2024/1624 |
| AMLD6 transposition deadline | 10 July 2027 | Directive (EU) 2024/1640 |
| AMLA | Operational in Frankfurt since 1 July 2025, direct supervision of selected entities from 2028 | Regulation (EU) 2024/1620 |
| British risk assessment review | At least annually and on material change | LCCP licence condition 12.1.1 |
| British sector risk assessment | Updated version published 30 July 2026 | Gambling Commission |
| Canadian effectiveness review | At least every two years, findings to a senior officer within 30 days | PCMLTFA compliance programme requirements |
| Maltese customer risk assessment | Within 30 days of the deposit threshold being met | FIAU Implementing Procedures Part II |
Timelines matter more than the numbers here. Preparation for the EU AML package has to start well before the application date, because splitting the compliance manager and compliance officer roles, and rebuilding the business-wide risk assessment to the format of Article 10, are governance changes rather than drafting exercises.
An AML Programme Checklist Before External Audit
Use the following as an AML programme checklist for operators approaching a first external review:
- Business-wide risk assessment written, versioned, dated, approved, and reopened after the latest sector assessment
- Policies approved by senior management or the management body, with the approval evidenced
- Procedures that name triggers, owners, windows, evidence standards and record locations
- Compliance ownership split correctly for the licensing regime, with the MLRO registered or approved where the regulator requires it
- Monitoring rules that cover linked transactions and account funding by third parties
- Escalation route tested end to end, with a documented decision on at least one closed case
- Training delivered by role, recorded, and refreshed after any material change to the assessment
- Employee screening applied to relevant roles at hiring and during employment
- Record retention set to at least five years and confirmed with every supplier holding the data
- Independent testing scheduled, with findings routed to a named senior recipient and remediation dated
Operators building this from nothing rather than remediating an existing programme should sequence it against the wider roadmap, since compliance for new operators puts several of these items before the first player deposit rather than after it.
Frequently Asked Questions on AML Programme Requirements
Does an operator have to comply with the FATF Recommendations directly?
No. The FATF sets standards for countries, which implement them through national law. An operator complies with the Money Laundering Regulations 2017, the Maltese PMLFTR, the PCMLTFA or the AML Regulation, depending on where it holds a licence. The Recommendations matter because they explain why the national rules look the way they do, and because certification schemes and correspondent banks use them as the common reference.
How often should a business-wide risk assessment be reviewed?
At least annually under licence condition 12.1.1 in Great Britain, and immediately on any material change: a new product, a new payment method, a shift in the customer base, a new market. Publication of a sector or national risk assessment is itself a trigger. The Canadian two-year effectiveness review is a separate obligation and does not replace the annual review of the assessment.
Can the same person be the MLRO and the compliance officer?
In Great Britain, yes, where the individual sits high enough in the management structure to act as money laundering compliance principal as well as nominated officer. The EU AML Regulation keeps the two apart from 10 July 2027, with the compliance manager drawn from the management body and the compliance officer running the function day to day. Malta requires the MLRO to be registered with the FIAU and approved by the MGA.
What should operators change before the EU AML package applies?
Three things carry lead time: the governance split between compliance manager and compliance officer, the business-wide risk assessment rebuilt to the structure of Article 10, and group-wide arrangements for operators running several licensed entities. Thresholds change less, since the EUR 2,000 gambling threshold already applies in most member states through national transposition.
What does an external AML audit examine first?
Evidence of operation. An auditor typically starts with the risk assessment, checks whether the policies answer it, then samples customer files to see whether the procedures were followed on real accounts. Gaps between the written control and the sampled file account for most adverse findings, which is also what the FINTRAC and Gambling Commission decisions of the last two years turn on.