GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

KYC Onboarding: Verification Standards and Common Failure Points

KYC onboarding at an online casino sets the ceiling for everything the AML programme does afterwards, because every control further down the funnel depends on knowing who holds the account. Verification is no longer something an operator can defer to the cashier. GICNT-AML treats the registration flow as the point where AML requirements for operators are met or missed, and an annual third-party audit tests it against records rather than policy documents.

What GICNT-AML Requires Before a Player Funds an Account

GICNT-AML is one of six mandatory domains in the GICNT Framework v4.2 and carries an annual third-party audit. The standard requires an operator to establish the identity of a player before real-money play begins, apply due diligence proportionate to the risk the account presents, and record each decision so an external reviewer can reconstruct it later. Policy text alone satisfies none of those requirements.

Certification sits on top of the licence and does not stand in for one. GICNT issues no gaming licence and holds no supervisory powers over any operator. Where national law sets a lower bar than the framework, the certification requirement is the stricter of the two, and the operator still answers to its licensing authority for the statutory minimum.

Verification Tiers Operators Are Expected to Run

Requirements for player identity verification stack in tiers. The lower two settle who the person is. The tiers above them ask where the money came from, and they trigger on behaviour rather than on the calendar.

TierTriggerMinimum evidenceEffect until complete
Registration dataAccount creationName, date of birth, permanent residential address, remote contact detailsAccount not activated, duplicate detection runs first
Identity and age verificationBefore the first deposit or the first wager, depending on the regimeGovernment-issued document, or an electronic match against an authoritative data sourcePlay blocked
Standard customer due diligenceBusiness relationship established, or a monetary threshold reachedVerified identity plus a documented customer risk assessmentWithdrawal held
Enhanced due diligencePEP status, high risk score, high-risk third country, unexplained funding patternSource of funds or source of wealth evidence, approval at senior levelRelationship continues only once approved

The Malta Gaming Authority sets the registration floor in its Gaming Authorisations and Compliance Directive: name and surname, date of birth, permanent residential address, and for remote licensees an email address or other means of remote contact. If a licensee later finds that information to be materially false, it must cancel the registration, and it may not pay out winnings on that account.

How Long Each Regime Gives an Operator to Finish Verification

Deadlines are where the regimes diverge. Age verification in remote gambling is the one point of agreement, since no licensed market lets an unverified minor reach a deposit screen. After that, Great Britain closes the door at the front of the funnel, Malta allows a monetary threshold, and the EU will impose a single trigger from 2027. Under UKGC licence conditions, licence condition 17.1.1 requires a licensee to obtain and verify a customer’s name, address and date of birth before that customer is permitted to gamble, and bars the operator from demanding at withdrawal anything it could reasonably have requested earlier.

RegimeVerification deadlineAdditional trigger
Great Britain, LCCPName, address and date of birth verified before the customer gambles, age verified before a depositFinancial vulnerability check at £150 net deposits over a rolling 30 days, in force since 28 February 2025
Malta, FIAU proceduresDue diligence and the customer risk assessment by the first withdrawal, or once net deposits reach EUR 2,000, whichever comes firstRisk assessment and PEP screening within 30 days of the threshold being met
Netherlands, Koa (Remote Gambling Act)Identity established and verified before the account opens, CRUKS consulted before every attempt to playEvidence of disposable income above EUR 700 net monthly deposits, EUR 300 for players aged 18 to 23
Germany, GlüStV 2021 (State Treaty on Gambling)Identity verified before play, OASIS matched at registration and at every loginCross-operator deposit ceiling of EUR 1,000 per month enforced through the LUGAS limit file
European Union, AMLRDue diligence when a stake or a payout reaches EUR 2,000, including linked transactions, from 10 July 2027Directly applicable in all 27 member states with no national transposition

Regulation (EU) 2024/1624 fixes the customer due diligence threshold for gambling services at EUR 2,000 and counts linked transactions towards it rather than treating each deposit separately. Malta already works to that figure through the FIAU, calculated either daily or across a rolling 180-day window, so Maltese licensees will feel the 2027 change less than operators whose national rules set higher trigger points.

What Counts as Proof of Identity in an Audited Flow

Electronic identity verification across iGaming has displaced the document upload as the default first step, and regulators accept it, provided the operator can show which data source answered and when. The evidence an auditor will sample falls into a short list.

  • A government-issued photo document, meaning a passport, national identity card or driving licence, captured with a liveness check that ties the face in the session to the face on the document.
  • An electronic match against an authoritative source: a population register, a credit reference file, or a national eID scheme such as BankID in Sweden or iDIN in the Netherlands.
  • A verification payment from an account held in the player’s own name, which sits alongside the identity check rather than replacing it under KSA licensing and CRUKS duties.
  • Address evidence dated inside the window the operator’s own policy specifies, which the auditor reads back against the sampled accounts.
  • Screening output for sanctions, politically exposed persons and adverse media, stored with the list version and the timestamp of the search.

GICNT-AML specifies the evidence trail, not the vendor. An operator running checks in-house against a national register passes the same test as one buying an eIDV service, so long as both can reproduce the result for a named account on a named date.

Triggers That Force Re-verification of an Existing Player

Onboarding data decays. Ongoing monitoring of player accounts exists to catch the point where the file stops describing the customer, and an auditor treats a stale file as an open finding regardless of how clean the original check was.

  • An identity document expires while the account stays live, which is among the easiest findings for an examiner to raise.
  • The player changes name, address, or the payment instrument funding the account.
  • Deposits cross a monetary threshold and move the file from identity questions to money questions, where source of funds and source of wealth evidence carries the decision.
  • Periodic screening returns a politically exposed person or sanctions match that did not exist at registration.
  • Funds arrive from a third party, or the account is used from a jurisdiction the operator does not serve.
  • The player asks to raise a deposit limit in a market that ties limits to proof of income, as the Netherlands does above EUR 700 a month.
  • A dormant account reactivates after a long absence, with payment details the operator never verified.

Where KYC Onboarding Fails in an Audit

The failure points a KYC audit exposes repeat across operators, and published regulatory decisions describe them in more detail than most internal reviews manage. Scoring models fail quietly, which is why transaction monitoring and escalation has to be tested against live accounts instead of signed off on design.

  • High-spending accounts that were never verified. The Gambling Commission reported in July 2026 that its financial risk assessment pilot surfaced high-spending customers whose age and identity the operator had not properly verified, which the regulator flagged as a potential breach of requirements already in force.
  • Checks deferred to the withdrawal request. Licence condition 17.1.1 prohibits asking at that stage for information the operator could reasonably have sought earlier, and the practice still drives a large share of consumer complaints against remote operators.
  • Automated risk scoring that never escalates. The Commission fined Videoslots Limited £650,000 on 20 November 2025 after a customer funded an account with more than £75,000 in prepaid digital vouchers over 16 days, moved the proceeds to four different bank accounts, and still scored below the level that would have prompted a source of funds request. The operator assumed the money was recycled winnings and held no evidence for that assumption.
  • Thresholds tracked per brand or per transaction rather than per customer across the whole estate, so cumulative deposits never reach the trigger on paper.
  • Duplicate accounts left undetected. Maltese licensees must screen for matching player details, shared IP addresses, device identifiers and SIM identifiers, and satisfy themselves before activation that the applicant holds no other account.
  • Decisions taken but not recorded. The reviewer accepted the account, nobody logged who decided, on what basis, or on which date.

Documenting Onboarding Decisions for the Annual Audit

An external auditor works backwards from a sample of accounts, asking the same questions of each: what did the operator know at registration, what changed afterwards, and who signed it off. For politically exposed persons the bar rises again, since PEP screening and enhanced due diligence both need approval recorded at senior level. The file has to hold the following.

  • The customer-level deposit ledger, showing the date any threshold was reached.
  • The dates due diligence started and finished, not only its outcome.
  • The customer risk assessment, with the criteria and the model version applied at the time.
  • The name of the person who approved a continuing relationship, and for a PEP, evidence that the approval came from senior management.
  • Retention for the period the licensing regime demands, with five years the common floor across EU and Maltese practice.

Common Questions About KYC Onboarding Requirements

Does age verification have to happen before a deposit or before the first bet?

In Great Britain, before both. Social responsibility code provision 3.2.11 requires age verification before a customer deposits or gambles, and licence condition 17.1.1 requires name, address and date of birth to be verified before gambling. Other regimes word it differently, but none of the regulated markets permits an unverified account to reach the cashier.

Can an operator complete KYC at the first withdrawal?

In Malta, the first withdrawal is one of two deadlines under FIAU procedures, the other being cumulative net deposits of EUR 2,000. In Great Britain the answer is no. Operators serving both markets build to the stricter rule, because a single flow configured to Maltese timing will fail a British compliance assessment.

Is electronic verification sufficient on its own?

Yes, where the data source is authoritative and the result is stored. Auditors test whether the operator can reproduce a check for a named account on a named date, along with the source that answered. The brand of tool matters far less than the retrievability of the record.

How often should an existing player be re-verified?

No regime sets a fixed interval. Re-verification follows triggers: document expiry, changed details, threshold crossings, screening hits, unusual funding. GICNT-AML expects that trigger list to be written down and applied the same way to every account, which is what an auditor samples against.

Does GICNT certification replace a licence or a statutory AML obligation?

No. GICNT is an independent certification body, not a regulator, and the mark substitutes for neither a gaming licence nor compliance with national AML law. It evidences that an independent audit tested the controls an operator says it runs.