GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

Crypto Payments in iGaming: Where AML Controls Break Down

AML controls designed for card and bank rails break once crypto payments reach an iGaming cashier, and blockchain transparency does not close the gap. The ledger records every hop between addresses. It says nothing about who holds the private key. Everything a licence demands, identity, source of funds, a trail an auditor can follow, sits on the other side of that gap, and AML requirements for online operators do not soften because a deposit arrived on-chain.

Pseudonymous Wallets Meet Identity Requirements at the Deposit Screen

A self-hosted wallet takes seconds to create and asks the holder for nothing: no document, no residential address, no name. A deposit from that wallet hands the operator an address string, an amount and a timestamp. The KYC requirements that attach to a crypto deposit are the same ones that attach to a debit card, and an address satisfies none of them. The same KYC onboarding verification standards apply, with a harder evidence problem behind them.

The chain answers a different question from the one a compliance officer asks. It shows where value moved. Attribution, meaning which natural person controls the sending key, comes from off-chain evidence: an exchange account statement in the customer name, a message signed with the private key, a small test transfer from the same address after identity checks have cleared.

Payment gateways push the problem one layer back. Where a processor converts the deposit and settles to the operator in euro, the operator sees a fiat balance and a reference, and the chain history stays with the processor. That conversion moves the data, not the obligation. An operator relying on a gateway needs contractual access to its screening output, not a monthly reconciliation file.

How the Travel Rule Reaches Operators That Are Not Crypto-Asset Service Providers

FATF Recommendation 16 binds virtual asset service providers, not gambling businesses. Operators still meet it from two directions: as customers of exchanges that hold withdrawals pending self-hosted wallet verification, and through their own status where a national supervisor treats custody of player crypto balances as a virtual asset service in its own right.

The seventh FATF targeted update, published on 15 July 2026, reports Travel Rule legislation in force in 83% of surveyed jurisdictions, 91 of 109, against 73% a year earlier. Supervision has not caught up: 55 of those 91 have issued no finding, directive or enforcement action on Travel Rule compliance. Applying the travel rule to crypto deposits in gambling therefore turns on where the counterparty sits rather than on a single global standard.

RegimeApplied fromData on transfers between providersSelf-hosted wallets
FATF Recommendation 162019 baseline; revised text agreed at the June 2025 plenarySuggested de minimis of USD or EUR 1,000Risk-based measures for transfers to and from unhosted addresses
EU: Regulation (EU) 2023/1113 (TFR)30 December 2024No de minimis; originator and beneficiary data on every transferOwnership or control verified above EUR 1,000, assessed cumulatively
United Kingdom: Money Laundering Regulations as amended1 September 2023Full data set, with a reduced set permitted below GBP 1,000Risk-based treatment of transfers involving jurisdictions without equivalent rules
United States: FinCEN travel ruleExisting Bank Secrecy Act ruleUSD 3,000 threshold; the 2020 proposal to cut it to USD 250 was never finalisedNo dedicated ownership verification requirement

The European Banking Authority guidelines of 4 July 2024 (EBA/GL/2024/11) set out what a provider does when data arrives missing or meaningless: request it, return the transfer, or report. From 10 July 2027 the EU AML package tightens the position again, and gambling service providers sit inside its scope as obliged entities.

Source of Funds Verification Fails Before the Wallet Is Identified

Verifying the source of funds behind crypto deposits usually stalls at the first document. An exchange withdrawal statement evidences the last hop and nothing before it. A wallet screenshot evidences nothing at all. Where a customer bought the asset years ago through a venue that has since closed, the paper trail the operator wants may not exist in any form a reviewer can test.

Volatility separates two numbers that fiat keeps together. A customer who acquired an asset for EUR 4,000 and deposits EUR 40,000 has not laundered anything, and the deposit still looks like a value the customer profile cannot support. Distinguishing source of funds and source of wealth resolves it: the trading history explains the wealth, the on-chain path explains the funds, and a review that collapses the two produces a file that fails on inspection.

The UK Gambling Commission has told licensees to treat funds described as coming from cryptoasset trading as a high-risk indicator feeding the customer profile, with due diligence sized accordingly. Treating that statement as an answer rather than as the start of an enquiry is the failure pattern its bulletins keep describing.

Mixers, Bridges and Privacy Coins Under Article 79 of the EU AML Regulation

The EU has set a date for anonymity at the account level, and the drafting leaves the hardest question open.

  • Article 79 of Regulation (EU) 2024/1624 bars credit institutions, financial institutions and crypto-asset service providers from keeping anonymous accounts or accounts holding anonymity-enhancing coins. It applies from 10 July 2027.
  • The regulation names no tickers, and no supervisor has published a list of qualifying assets. Whether optional shielding is treated like continuous obfuscation remains unsettled.
  • AMLA will directly supervise up to 40 crypto-asset service providers, which should pull classification decisions away from 27 separate national readings.
  • Chainalysis put illicit inflows at at least USD 154 billion in 2025, with stablecoins carrying 84% of illicit transaction volume. The volume risk is not sitting in privacy coins.
  • Chinese-language laundering networks processed USD 16.1 billion in 2025, roughly USD 44 million a day, and Chainalysis describes gambling services inside those networks splitting large transfers into small ones to stay under detection thresholds.

For an operator that never custodies crypto, Article 79 binds its counterparties rather than the operator itself. The practical effect arrives earlier than the date: exchanges offboard the assets, so the deposits stop arriving through regulated rails and what remains comes from self-hosted addresses with no counterparty to question. Privacy coins push gambling operators towards a written acceptance policy, and the reasoning belongs in the file before 2027 rather than after a supervisor asks when the decision was taken.

Turning Blockchain Analytics Alerts Into a Documented Escalation Path

Vendors score an address for exposure to sanctioned entities, darknet markets, mixers and known scam clusters. A casino that buys blockchain analytics and folds the score into transaction monitoring has bought an input, and the audit finding lands on what happened after the alert. A documented process defines the following.

  • Which exposure categories trigger review, at what hop distance, and which produce an automatic block.
  • Value thresholds in the account currency and the cumulative window they are measured over.
  • Who reviews an alert, within how many hours, and who takes the decision when the reviewer is unsure.
  • What evidence a reviewer records to clear an alert, so the decision reads the same to an auditor two years later.
  • When the money laundering reporting officer files a suspicious activity report, and how the customer relationship is handled after filing.
  • Retention of the address, score, vendor, screening version and outcome, held for the period the licensing regime requires.

Vendor coverage differs by chain and by asset, and a score dated at deposit does not describe the wallet six months later. Rescreening on withdrawal catches what the deposit check missed, which is why transaction monitoring and escalation belongs at both ends of the flow rather than at onboarding alone.

Regulators Disagree on Whether Licensed Operators May Take Crypto at All

JurisdictionPosition on crypto depositsDates that matter
Great Britain, UK Gambling CommissionAcceptance requires prior authorisation through the key event process; in practice no licensee accepts direct crypto depositsIndustry Forum asked in February 2026 to examine a route; FSMA 2000 (Cryptoassets) Regulations laid before Parliament in December 2025, regime expected on 25 October 2027
Malta, MGAPrior approval required before an authorised person accepts or uses DLT assetsPolicy in force from 30 January 2023, replacing the sandbox framework and its EUR 1,000 monthly deposit cap
Curaçao, CGACrypto deposits permitted under the standard B2C licence, with AML obligations applying in fullLOK in force from 24 December 2024; AML regulations mandatory from 10 April 2025
EU member statesNational gambling law, MiCA and the TFR apply at the same timeTFR from 30 December 2024; AMLR from 10 July 2027

The British position is the instructive one. The Commission holds the power to authorise cryptoasset payments and no licensee has taken it up, because the evidential burden on identity and source of funds outweighs the commercial gain. Tim Miller told the Betting and Gaming Council annual general meeting in February 2026 that the Commission wants to look at a workable path, noting that crypto ranks among the two most common search terms sending British consumers to unlicensed sites.

Approval under MGA licence conditions turns on how the asset is classified and on the operator demonstrating its controls before acceptance, not afterwards. Curaçao sets the lowest barrier to entry of the three, and AML compliance for a crypto casino does not become lighter because the licence costs less: the LOK regime carries FATF-aligned obligations, a compliance officer approved by the regulator, and revocation powers the previous master licence structure never had.

What GICNT-AML Requires of Operators Accepting Crypto Deposits

Certification under GICNT-AML rests on an annual third-party audit, and crypto acceptance moves several requirements from paper into evidence.

  • Wallet attribution completed before the first withdrawal, evidenced by a signed message or a verified test transfer rather than a screenshot.
  • Closed-loop processing as the default, with any exception approved, dated and reasoned.
  • Screening of deposit and withdrawal addresses against sanctions lists and illicit clusters, with the vendor and screening version recorded against each decision.
  • Source of funds evidence proportionate to value, and source of wealth evidence for high-value play, assessed at the value credited to the account.
  • A written policy naming which assets the operator accepts and refuses, reviewed against the July 2027 prohibition on anonymity-enhancing coins.
  • Escalation and reporting lines that name the responsible officer, with response times an auditor can test against the alert log.

GICNT-LS runs in parallel here. An operator can hold sound controls and still fail review if its licence does not permit crypto acceptance in the first place, which is why the licensing evidence and the controls evidence are assessed together rather than in sequence. Both sit inside an AML programme aligned with FATF recommendations rather than alongside it as a crypto annex.

Crypto Payment Questions Operators Raise With GICNT-AML Assessors

Can a British licensee accept Bitcoin deposits today?

None currently does. The Commission can authorise cryptoasset payments through the key event process, and in February 2026 it asked its Industry Forum to examine what a sensible route would look like. Nothing shifts until that work concludes and the FCA cryptoasset regime takes effect, expected on 25 October 2027.

Does the travel rule apply if a processor converts crypto before the operator sees it?

The Travel Rule obligation sits with the crypto-asset service provider handling the transfer, not with the gambling operator receiving fiat. The operator still has to evidence what it knows about the origin of that value, which in practice means contractual access to the processor screening results and the underlying transfer data.

What counts as verifying control of a self-hosted wallet?

Under the EU TFR, a provider verifies ownership or control for transfers above EUR 1,000, measured cumulatively rather than per transaction. The accepted methods are a message signed with the private key or a small test transfer from the address after identity verification. A screenshot of a wallet interface proves nothing.

Are privacy coins already prohibited across the EU?

Not yet. Article 79 of Regulation (EU) 2024/1624 applies from 10 July 2027 and binds crypto-asset service providers rather than individuals holding assets in self-custody. Exchanges have been delisting such assets ahead of the date, so availability through regulated venues is already narrowing.

Does a Curaçao licence still support a crypto-first casino model?

The LOK regime permits crypto deposits under a standard B2C licence without a separate virtual asset authorisation, while AML obligations apply in full and have been mandatory since April 2025. Direct CGA licensing replaced the master licence structure in January 2025, so legacy sub-licence paperwork is no longer a basis for operating.