GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

Building an AML Programme Aligned with FATF Recommendations

An AML programme aligned with the FATF Recommendations rests on five linked parts: a documented risk assessment, controls that answer it, named owners, trained staff, and proof that all of it ran. Supervisors test the last part hardest, and most enforcement follows from it. The GICNT-AML requirements apply that test through an annual third-party audit.

The FATF Recommendations That Shape an Operator AML Programme

The FATF Recommendations bind countries, not operators. National law converts them into duties, and the wording shifts from market to market, but the structure survives translation. Recommendation 22 pulls casinos into the customer due diligence and record-keeping regime that applies to banks once a customer engages in financial transactions at or above the designated threshold. Recommendation 18 describes the programme itself. In February 2025 the FATF rewrote Recommendation 1: the word commensurate became proportionate, countries must now allow and encourage simplified measures in lower-risk situations, and remote onboarding counts as a higher-risk factor only where the operator has failed to mitigate it. That last change carries weight for remote licensees, because distance verification is the whole business model.

RecommendationWhat it setsWhere it lands for an operator
R.1Identification, assessment and mitigation of risk through proportionate measures, with simplified measures available where risk is lower (amended 25 February 2025)The assessment drives every downstream control, and lighter handling of low-risk segments now has explicit backing
R.10 and R.12Customer due diligence; enhanced due diligence and senior management approval for politically exposed personsVerification and PEP handling become procedure-level questions with named decision owners
R.11Retention of transaction and due diligence records for at least five yearsRecords have to survive platform migrations and supplier changes
R.18Internal policies, procedures and controls; a compliance officer at management level; employee screening; ongoing training; an independent audit functionThis is the programme, and it is the part operators most often leave implicit
R.20Prompt reporting of suspicion to the financial intelligence unitEscalation routes and timing become auditable
R.22USD/EUR 3,000 threshold for casino customer due diligence, whether the transaction is single or made up of linked operationsLinked-transaction logic has to exist in the monitoring rules, not only in the policy text

Auditors and supervisors read these texts in their own vocabulary, so drafting internal documents in house shorthand creates friction later. Keeping to the AML and KYC terminology used in the source instruments costs nothing and removes an argument during review.

The Business-Wide Risk Assessment Comes First

A business-wide risk assessment for an iGaming operator starts from its own book: the customers on it, the games it runs, the payment rails it accepts, the markets it takes traffic from. In Great Britain, regulation 18 of the Money Laundering Regulations 2017 requires a written assessment covering customers, geographic areas, products and services, transactions and delivery channels, and licence condition 12.1.1 of the LCCP requires a review at least annually and whenever circumstances change materially. In the European Union, Article 10 of the AML Regulation gives the business-wide risk assessment a dedicated article from 10 July 2027. Maltese licensees already have to record the document version, the date of the latest revision and the date the board approved it.

The Gambling Commission published an updated Risk Assessment of Money Laundering and Terrorist Financing in the British Gambling Industry on 30 July 2026, replacing its 2023 analysis and drawing on the UK National Risk Assessment 2025. Casino licence holders must take it into account under the Money Laundering Regulations; every other licensee is expected to consider the sections relevant to its business and to update its own assessment where the ratings have moved. The risk-based approach to AML in gambling collapses when the sector assessment lands and nobody reopens the internal one.

Factors worth their own analysis rather than a single line in a matrix:

  • Customer segments, including high-value play and accounts funded by third parties
  • Product mix, including bonus mechanics that allow low-margin turnover
  • Delivery channels and the point at which verification blocks play
  • Payment methods, where prepaid instruments carry a high rating in the Commission analysis and crypto payment AML controls need separate treatment
  • Geography, both licensed markets and the residence of the customer base
  • Third parties: affiliates, payment providers, outsourced verification and monitoring vendors

Turning the Assessment Into Policies, Procedures and Controls

Approval sits at the top in every regime. Regulation 19 of the Money Laundering Regulations 2017 requires written policies, controls and procedures approved by senior management. Article 9 of the AML Regulation requires the management body to approve internal policies, with procedures and controls approved at least at the level of the compliance manager. In Canada, written compliance policies and procedures must be kept up to date and approved by a senior officer. AML policies and procedures across the casino product should then answer five questions in a form a new starter can follow:

  • What triggers action, expressed as a threshold, a pattern or an event
  • Who decides, by role rather than by name
  • Within what window, in hours or days
  • What evidence closes the item, and what happens when the customer supplies nothing
  • Where the decision and its reasoning are recorded

Malta gives a worked example of the fourth point: a customer risk assessment falls due within 30 days of a customer meeting the EUR 2,000 deposit threshold, and the Implementing Procedures set out what has to happen once that window passes with due diligence still incomplete. KYC onboarding standards should state the same thing in operational terms, down to the point at which the account stops accepting deposits.

Who Owns the Programme: The MLRO and the Compliance Function

The MLRO role at a gambling operator carries personal exposure, not only organisational responsibility. Under the Money Laundering Regulations 2017 the nominated officer receives internal reports and decides whether to report to the National Crime Agency, and failure to disclose is a criminal matter under the Proceeds of Crime Act 2002. Regulations vary on how the seniority is split.

RegimeSenior ownerDay-to-day role
FATF R.18Compliance officer at management levelOngoing training and an independent audit function sit alongside the role
Great Britain, MLR 2017Money laundering compliance principal, drawn from the board or senior management (regulation 21)Nominated officer, in practice the MLRO, receives internal reports and decides on disclosure; one person may hold both roles where sufficiently senior
European Union, AMLR from 10 July 2027Compliance manager, a member of the management body (Article 11)Compliance officer of sufficiently high standing, responsible for daily operation and for contact with the authorities
Malta, MGA and FIAUMLRO approved by the MGA as a Key AML Function and registered with the FIAUAnalyses unusual activity and files suspicious transaction reports with the FIAU
Canada, PCMLTFASenior officer approves the policies and receives review findingsAppointed compliance officer implements the five prescribed elements of the programme

Escalation is where the role stops being an org chart entry. Transaction monitoring and escalation routes have to deliver the whole file to the MLRO, including the account history and the analyst reasoning, and the MLRO has to be able to stop play without asking commercial colleagues for permission.

AML Training Requirements for Staff Who Touch Player Accounts

AML training requirements for staff run along the same line in each regime: awareness of the law, then recognition of the behaviour, then knowledge of the internal route. Regulation 24 of the Money Laundering Regulations 2017 covers awareness of money laundering, terrorist financing and data protection law and training in how to handle relevant transactions. Article 12 of the AML Regulation carries the awareness obligation into EU law from 2027, with Article 13 adding integrity checks on employees. Canadian reporting entities need a written, ongoing training programme plus a documented plan for delivering it.

The FIAU and the MGA measured how much of this survives contact with a remote operation. In their thematic review of the remote gaming sector, two thirds of MLROs and just over a third of relevant employees could state the inherent risk rating of their own business; half of MLROs and a fifth of relevant employees knew what to do once 30 days had passed with due diligence incomplete. Numbers like that decide how detailed the training has to be on the harder topics, PEP screening and enhanced due diligence among them, where the correct answer is rarely intuitive.

Documenting the Programme for the Annual Audit

An auditor tests whether the programme operated. The document set that supports that answer:

  • The risk assessment with its version number, revision date and evidence of board or senior approval
  • Policy approvals, with the date and the approving body recorded
  • Customer files showing the verification steps in the order the procedure prescribes
  • Escalation records, including cases closed without a report and the reasoning behind that decision
  • Training records: content, attendance, dates, and refresher cycles by role
  • Effectiveness testing. Canadian reporting entities review the programme at least every two years and report findings to a senior officer within 30 days of completion, while the independent audit function for AML controls under Recommendation 18 and regulation 21 runs on the same logic
  • Remediation tracking that shows dates of implementation, since the Gambling Commission expects updates to be made in a timely manner and evidenced

GICNT-AML sits on an annual third-party audit, which makes the evidence trail the certification artefact rather than the policy set. Audit frequency by standard differs across the six domains of the framework, and the AML cycle is the strictest of them.

Where AML Programmes Break Down in Enforcement Practice

Recent decisions read as documentation cases. FINTRAC imposed a penalty of CAD 212,025 on Atlantic Lottery Corporation on 29 May 2026, announced on 9 July 2026, for failing to submit a suspicious transaction report, failing to develop and apply written compliance policies and procedures that were kept up to date and approved by a senior officer, and failing to assess and document money laundering and terrorist financing risk. The operator paid rather than appeal, and the findings were administrative.

The same supervisor imposed CAD 1,075,000 on British Columbia Lottery Corporation on 17 July 2025 for failing to report suspicious transactions and for the absence of policies, procedures and special measures covering high-risk clients. In Great Britain, QuinnBet (Gibraltar) Limited agreed a regulatory settlement of GBP 609,104, including disgorgement of GBP 193,118, announced on 20 August 2026 after a compliance review spanning March 2023 to August 2025; the Gambling Commission found controls unable to act in a timely manner and suspicious activity reports submitted late.

One pattern connects all three. The documents existed. What the operator could not show was that they were current, approved by the right person, and applied to the accounts in front of them. FINTRAC issued 35 notices of violation in its 2025 to 2026 year, the highest count in its history, which suggests supervisors are testing programmes rather than reading them. Reading through regulatory fines in iGaming by category shows how few of these decisions turn on a laundering event as opposed to a control gap.

Thresholds and Dates to Build the Programme Around

Reference pointValueInstrument
Casino due diligence thresholdUSD/EUR 3,000, single or linked transactionsInterpretive Note to FATF Recommendation 22
EU gambling due diligence thresholdEUR 2,000 on the wagering of a stake, the collection of winnings, or bothAMLR Article 19(5)
EU cash occasional transactionsEUR 3,000AMLR Article 19(4)
AMLR application date10 July 2027Regulation (EU) 2024/1624
AMLD6 transposition deadline10 July 2027Directive (EU) 2024/1640
AMLAOperational in Frankfurt since 1 July 2025, direct supervision of selected entities from 2028Regulation (EU) 2024/1620
British risk assessment reviewAt least annually and on material changeLCCP licence condition 12.1.1
British sector risk assessmentUpdated version published 30 July 2026Gambling Commission
Canadian effectiveness reviewAt least every two years, findings to a senior officer within 30 daysPCMLTFA compliance programme requirements
Maltese customer risk assessmentWithin 30 days of the deposit threshold being metFIAU Implementing Procedures Part II

Timelines matter more than the numbers here. Preparation for the EU AML package has to start well before the application date, because splitting the compliance manager and compliance officer roles, and rebuilding the business-wide risk assessment to the format of Article 10, are governance changes rather than drafting exercises.

An AML Programme Checklist Before External Audit

Use the following as an AML programme checklist for operators approaching a first external review:

  • Business-wide risk assessment written, versioned, dated, approved, and reopened after the latest sector assessment
  • Policies approved by senior management or the management body, with the approval evidenced
  • Procedures that name triggers, owners, windows, evidence standards and record locations
  • Compliance ownership split correctly for the licensing regime, with the MLRO registered or approved where the regulator requires it
  • Monitoring rules that cover linked transactions and account funding by third parties
  • Escalation route tested end to end, with a documented decision on at least one closed case
  • Training delivered by role, recorded, and refreshed after any material change to the assessment
  • Employee screening applied to relevant roles at hiring and during employment
  • Record retention set to at least five years and confirmed with every supplier holding the data
  • Independent testing scheduled, with findings routed to a named senior recipient and remediation dated

Operators building this from nothing rather than remediating an existing programme should sequence it against the wider roadmap, since compliance for new operators puts several of these items before the first player deposit rather than after it.

Frequently Asked Questions on AML Programme Requirements

Does an operator have to comply with the FATF Recommendations directly?

No. The FATF sets standards for countries, which implement them through national law. An operator complies with the Money Laundering Regulations 2017, the Maltese PMLFTR, the PCMLTFA or the AML Regulation, depending on where it holds a licence. The Recommendations matter because they explain why the national rules look the way they do, and because certification schemes and correspondent banks use them as the common reference.

How often should a business-wide risk assessment be reviewed?

At least annually under licence condition 12.1.1 in Great Britain, and immediately on any material change: a new product, a new payment method, a shift in the customer base, a new market. Publication of a sector or national risk assessment is itself a trigger. The Canadian two-year effectiveness review is a separate obligation and does not replace the annual review of the assessment.

Can the same person be the MLRO and the compliance officer?

In Great Britain, yes, where the individual sits high enough in the management structure to act as money laundering compliance principal as well as nominated officer. The EU AML Regulation keeps the two apart from 10 July 2027, with the compliance manager drawn from the management body and the compliance officer running the function day to day. Malta requires the MLRO to be registered with the FIAU and approved by the MGA.

What should operators change before the EU AML package applies?

Three things carry lead time: the governance split between compliance manager and compliance officer, the business-wide risk assessment rebuilt to the structure of Article 10, and group-wide arrangements for operators running several licensed entities. Thresholds change less, since the EUR 2,000 gambling threshold already applies in most member states through national transposition.

What does an external AML audit examine first?

Evidence of operation. An auditor typically starts with the risk assessment, checks whether the policies answer it, then samples customer files to see whether the procedures were followed on real accounts. Gaps between the written control and the sampled file account for most adverse findings, which is also what the FINTRAC and Gambling Commission decisions of the last two years turn on.