GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

Transaction Monitoring and Escalation: Building a Documented Process

Transaction monitoring in an online casino rarely fails at detection. It fails later, at the point where an alert has to become a documented decision with a named owner, a timestamp and a reason that survives outside review. Supervisors and auditors read the same artefact: the case file explaining why an account was cleared, restricted or reported.

What GICNT-AML Requires of Transaction Monitoring

GICNT-AML is one of six mandatory domains in the GICNT Framework v4.2, and it runs on an annual third-party audit. Certification under it carries no supervisory force and does not replace a gambling licence. What it sets is an evidentiary standard. For any period under review, an operator has to show which rules were live, what those rules fired on, who read the output and what happened next.

The AML rules governing transaction monitoring in iGaming sit inside a wider control set. Onboarding due diligence establishes the pattern a player is expected to follow; monitoring tests reality against that expectation. Where the two diverge, the operator either explains the divergence with evidence or reports it. GICNT-AML treats an undocumented clearance the same way a supervisor does, as an absence of review, and it sits alongside the broader AML requirements for online operators covering risk assessment, verification and reporting.

How Monitoring Duties Are Written Into Law Across Major Markets

None of this starts from a blank page. FATF Recommendation 10 requires ongoing due diligence and scrutiny of transactions throughout a business relationship, including source of funds where necessary. Recommendation 20 requires prompt reporting of suspicion to the financial intelligence unit. National regimes then set the thresholds that trigger transaction monitoring in gambling markets, and they disagree with each other.

JurisdictionInstrumentMonitoring triggerReporting route
Great BritainMLR 2017, regulation 28(11); LCCP licence condition 12.1.1Scrutiny of transactions against the operator’s knowledge of the customer and their risk profile. No statutory monetary trigger.SAR to the NCA, and a defence against money laundering where the operator would otherwise handle criminal property
MaltaPMLFTR, with the FIAU and MGA Implementing Procedures Part II for the Remote Gaming SectorDue diligence and a customer risk assessment by the first withdrawal, or on cumulative deposits of EUR 2,000 across a rolling 180-day window, tracked per customerSTR to the FIAU, filed by the registered MLRO
NetherlandsWwft, supervised by the Kansspelautoriteit (Netherlands Gaming Authority)Objective indicators, including a non-cash payment transaction of EUR 15,000 or more, plus one subjective indicator resting on the operator’s own suspicionUnusual transaction report to FIU-Nederland, without delay
European Union, from 10 July 2027Regulation (EU) 2024/1624 (AMLR)Due diligence where stakes, winnings or linked transactions reach EUR 2,000National FIU, under supervisory arrangements set by AMLD6

Great Britain sets no monetary trigger at all. LCCP licence conditions require money laundering policies, procedures and controls to be implemented effectively, and the Commission tests that effectiveness case by case against what the operator actually did.

Typologies That Should Shape Rule Design in Online Gambling

Rules lifted from banking miss the behaviour that matters in gambling. Detection logic tuned to wire transfers and cash deposits does not see structured player deposits, voucher funding or turnover that never touches a game. The patterns below recur in published enforcement decisions and supervisory guidance across the markets above.

  • Open-loop prepaid vouchers. Funds arrive through an instrument the operator cannot trace back to a bank account. The Gambling Commission asked operators running such systems to report their use as a key event.
  • Structuring below a known trigger. Deposits repeatedly sized just under a published threshold, spread across days, brands or payment methods.
  • Deposit, minimal play, withdrawal. Turnover far below deposit volume, especially where the withdrawal destination differs from the funding source.
  • Withdrawal fan-out. Proceeds split across several destination accounts, sometimes in names other than the registered player’s.
  • Third-party funding. Cards, wallets or bank accounts not held by the account holder.
  • Geolocation drift. Sustained access from a jurisdiction inconsistent with the registered address, or from a market the licence does not cover.
  • Chip dumping and hedged betting. Peer-to-peer transfers in poker, or offsetting positions that turn a deposit into a clean withdrawal at a small and predictable loss.

Funds routed through exchanges add a further layer, because the on-chain trail stops at the exchange and resumes at the operator with nothing in between. Build crypto payments AML controls as a separate rule set rather than a branch of the card logic.

Calibrating Thresholds Against Real Player Behaviour

A fixed monetary trigger decays. The Dutch market shows how quickly. Since 1 October 2024 the Kansspelautoriteit has capped monthly net deposits at EUR 700 for adults and EUR 300 for players aged 18 to 24, which puts the EUR 15,000 objective indicator structurally out of reach. Reporting has shifted almost entirely onto the subjective indicator, where the operator’s own judgement carries the file. FIU-Nederland recorded 30,553 reports from online gambling licensees in 2024, of which 3,641 were designated suspicious.

British supervision points the same way. At a February 2025 industry training day, the Commission’s enforcement director set out that monitoring triggers were failing to account for a customer’s income and wealth, that risk profiles ignored transaction patterns and product usage, and that AML reviews were starting late. None of those findings concerns the size of a threshold. They concern what the threshold is measured against, which is why source of funds verification has to feed the monitoring model rather than sit downstream of it.

Retuning needs its own record. Every change to a rule, a threshold or a scoring weight should carry a date, an owner, a stated reason and the effect on alert volume. An auditor comparing two periods will otherwise read a drop in alerts as a control failure, and the operator will have nothing to answer with.

The Escalation Path From Alert to MLRO Decision

An escalation process that ends at the MLRO needs defined stages, named owners and clocks the operator holds itself to. No regulator in the markets covered here sets an alert-to-decision deadline, which is precisely why the operator has to set one.

StageOwnerActionRecorded outputInternal clock
1. TriageFirst-line analystDismiss, keep under observation or escalateDisposition code and a one-line rationale24 hours from the alert
2. InvestigationAML analystPayment history, KYC file, device and geolocation data, sanctions and adverse media screeningInvestigation note with the evidence attached, not summarised3 working days
3. Enhanced reviewSenior analyst or compliance managerSource of funds or source of wealth request, account restriction where the risk warrants itThe request, the response and a decision on whether it explains the activity7 days from escalation, immediate where a withdrawal is pending
4. DeterminationMLROApply the suspicion test and decide whether to reportSigned determination with reasoning, including no-report decisionsSame day where funds are held
5. OutcomeMLRO with senior managementContinue, restrict or terminate the relationshipDecision, approval and the steps taken towards the customerAt the point of decision

These stages belong in the written policy set rather than in a team’s working habits. A risk-based AML programme is assessed on documents, and an escalation path that exists only as practice cannot be evidenced a year later.

Filing a Suspicious Transaction Report Without Tipping Off the Player

Once suspicion crystallises, discretion narrows. A suspicious transaction report by a gambling operator goes to the FIAU in Malta and to FIU-Nederland in the Netherlands, where it takes the form of an unusual transaction report. Since October 2025, FIU-Nederland rejects subjective-indicator reports that arrive without a description of the circumstances that made the transaction unusual.

In Great Britain the report goes to the NCA. Where paying out would mean dealing with property the operator suspects is criminal, it needs a defence against money laundering first. The notice period runs seven working days from the first working day after submission, and silence within it gives deemed consent. A refusal opens a 31 calendar day moratorium, extendable by a court in further 31 day blocks up to 186 days. The Proceeds of Crime (Money Laundering) (Threshold Amount) (Amendment) Order 2025 raised the section 339A threshold from GBP 1,000 to GBP 3,000 with effect from 31 July 2025, which covers returning funds to a customer for the purpose of ending the relationship.

Section 333A of the Proceeds of Crime Act 2002 makes tipping off a criminal offence throughout. Customer-facing staff need wording that explains a restriction or a delayed withdrawal without referencing a report, and that wording belongs in the training record alongside everything else. From 10 July 2027 the trigger standardises for EU-licensed operators at EUR 2,000 in stakes, winnings or linked transactions under the EU AML package, although supervision stays with national authorities.

What the Annual Third-Party Audit Expects to Find in Your Records

Record keeping for AML alert investigations is where most programmes come apart, because a reviewer cannot audit judgement, only its trace. GICNT-AML runs on an annual third-party audit, so a file has to stand on its own a year after the analyst who wrote it has moved on.

  • Alert inventory for the period, with the rule identifier, the disposition and the analyst who closed it.
  • Investigation notes carrying the evidence relied on rather than a description of it.
  • Source of funds and source of wealth documentation, with the assessment of whether it explained the observed activity.
  • MLRO determinations, including the no-report decisions, which is where an auditor usually starts.
  • Reports filed and acknowledgements received, matched to the accounts they concern.
  • Rule change log, showing approval, effective date and alert volume before and after.
  • Model testing evidence, showing rules were sampled against known cases instead of assumed to work.
  • Retention to the statutory floor. Regulation 40 of the MLR 2017 requires records sufficient to reconstruct a transaction, held for five years from the end of the business relationship or completion of the transaction.

Where Monitoring Programmes Fall Apart: Lessons From Recent Enforcement

Public decisions from the Gambling Commission through 2025 keep landing on the same faults. Automated scoring left unchecked, reviews opened too late, and records that cannot show what anyone considered.

On 20 November 2025 the Commission imposed a GBP 650,000 penalty on Videoslots Limited, together with a formal warning and an additional licence condition requiring an independent third-party audit, finding breaches of paragraphs 2 and 3 of licence condition 12.1.1. One customer funded an account with more than GBP 75,000 in prepaid digital vouchers over 16 days and moved the proceeds to four bank accounts, while the operator’s automated risk scoring failed to prompt timely source of funds checks.

Earlier that year, on 15 May 2025, the Commission fined Spreadex Limited GBP 2,022,000, finding that the operator had relied on customer assurances about source of funds instead of independent and verifiable evidence. It fined Platinum Gaming Limited GBP 10 million on 22 October 2025, and on 3 December 2025 Done Brothers (Cash Betting) Limited, trading as Betfred, agreed to pay GBP 825,000, both following anti-money laundering and social responsibility findings. Reading the pattern across regulatory fines in iGaming tells an operator more than any single decision, since the same control gap turns up at businesses of very different sizes.

Frequently Asked Questions

How often should transaction monitoring rules be retuned?

No regulator in these markets sets an interval. Practice clusters on a formal review at least once a year, plus an unscheduled review whenever the operator adds a payment method, enters a market or changes deposit limits. Each review needs a dated record of what changed and why, because a fall in alert volume with no explanation reads as degradation.

Does an automated alert system satisfy ongoing monitoring obligations?

Not on its own. The Gambling Commission’s November 2025 decision against Videoslots turned on over-reliance on an algorithm that failed to escalate a customer depositing more than GBP 75,000 in vouchers over 16 days. Automation handles volume. A named person still has to test the output and record what they decided.

Should an operator hold a withdrawal while an alert is open?

Where paying out would mean dealing with property the operator suspects is criminal, British law requires a defence against money laundering before the funds leave. The Maltese Implementing Procedures require a withdrawal to be held where customer due diligence is incomplete. The hold also has to be explained to the player in terms that do not disclose the existence of a report.

Can the MLRO role be outsourced?

Malta requires an MLRO of sufficient seniority who is registered with the FIAU and approved by the MGA as a key AML function, which limits how far the role can move to a service provider. Outsourced analyst capacity is common and permitted. Accountability for the suspicion decision stays with the appointed officer.

How long must alert investigation records be kept?

Five years is the working floor. Regulation 40 of the MLR 2017 requires copies of due diligence documents and supporting records sufficient to reconstruct a transaction, held for five years from the end of the business relationship or completion of the transaction. Alert dispositions and MLRO determinations fall inside that scope even where no report followed.