Compliance teams often treat source of funds versus source of wealth as a labelling question rather than two separate checks. One asks where a specific deposit came from. The other asks how the customer built that money over years. Both sit inside the AML requirements for operators, and GICNT-AML expects each to be evidenced on its own once player spend enters the high-value band.
What Source of Funds and Source of Wealth Mean Under FATF Recommendations 10 and 12
The Financial Action Task Force split the two concepts in its 2013 guidance on politically exposed persons. Source of wealth covers the origin of a customer’s entire body of wealth, meaning total assets, and it indicates both the volume of wealth that person would be expected to hold and how they came by it. Source of funds is narrower. It covers the origin of the particular funds moving through the business relationship: the amounts deposited, staked or withdrawn.
Recommendation 10 sets customer due diligence as the base obligation for every relationship. Recommendation 12 goes further for PEPs and requires firms to take reasonable measures to establish source of wealth and source of funds alike. Source of funds verification in gambling follows the same logic banks apply, with one difference that surfaces at audit. An iGaming account produces hundreds of small movements instead of a handful of large wires, so the operator has to attribute activity across payment methods before it can say anything credible about origin.
Vocabulary drifts between teams. Payments staff say proof of funds, onboarding says SoF, and the policy document uses a third phrase. Settling on the AML and KYC terminology that supervisors themselves use removes a large share of the ambiguity an external auditor would otherwise flag.
Where the Two Checks Diverge: Scope, Evidence and Time Horizon
Source of wealth checks at an online casino answer a different question from the one a deposit review answers, and they call for different documents. The split below is what GICNT-AML expects an operator’s policy to reflect.
| Dimension | Source of Funds | Source of Wealth |
|---|---|---|
| Question answered | Where did this specific money come from | How did this customer accumulate their total assets |
| Scope | Individual deposits, transfers and linked transactions | The customer’s whole financial history |
| Time horizon | Days to months | Years or decades |
| Typical evidence | Bank statements, salary credits, sale completion statements, exchange records | Employment history, company accounts, probate documents, investment holdings, tax filings |
| Usual trigger | Threshold breach, unusual pattern, withdrawal request | PEP status, high-risk jurisdiction, spend inconsistent with the declared profile |
| How it fails at audit | The file shows the paying account but not the activity that generated the money | The file shows a declaration with no independent corroboration |
An operator that runs only the first column will pass a payment check and still hold no view of whether a player staking six figures a year has any legitimate means of doing so.
Which Thresholds Trigger Verification Across the EU, Malta and Great Britain
European law fixes one number for the sector. Article 11(d) of Directive (EU) 2015/849 obliges gambling providers to apply customer due diligence on the collection of winnings, the wagering of a stake, or both, at €2,000 or more, whether in a single operation or in operations that appear linked. Regulation (EU) 2024/1624 keeps that trigger in Article 19(5) and adds a duty to link fragmented transactions falling below it. The EU AML package was published in the Official Journal on 19 June 2024 and applies directly across all member states from 10 July 2027.
Malta reads the same figure as a risk signal rather than a finish line. The FIAU Implementing Procedures Part II for the Remote Gaming Sector, issued on 19 July 2018 in conjunction with the Malta Gaming Authority and revised on 2 July 2020, note that a customer reaching €2,000 inside a week carries a higher risk than one who reaches it across a full year. Same threshold, different conclusion.
Great Britain sets no single statutory figure for remote operators outside the casino provisions of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. AML thresholds that iGaming operators set for themselves have to hold up against their own risk assessment, and the Gambling Commission tests them. On 3 December 2025 the Commission required Done Brothers (Cash Betting) Limited, trading as Betfred, to pay £825,000 after finding that enquiries into a customer’s source of income were triggered only at £15,000 in losses or £125,000 in stakes over 365 days, levels it judged not appropriately risk based. The operator also received a warning and an obligation to undergo a third-party audit.
One British threshold gets confused with AML work. Since 28 February 2025, social responsibility code provision 3.4.4 requires a light-touch financial vulnerability check at £150 in net deposits over a rolling 30-day period, down from the £500 level that ran from 30 August 2024. That check reads public records such as county court judgments and bankruptcies. It says nothing about whether the money is clean, and it discharges no source of funds obligation.
Documents Operators Accept as Source of Funds Evidence
Documents accepted as source of funds evidence have to show the activity that generated the money, not only the account that transmitted it. That distinction decides most audit findings in this area.
| Evidence | What it establishes | Where it breaks down |
|---|---|---|
| Payslips with matching bank credits | Recurring income and the employer behind it | Payslips alone, with no corresponding credit landing in the named account |
| Bank statements covering 3–6 months | Balance movement and counterparties | Statements cropped to one page, or supplied as unverifiable screenshots |
| Property sale completion statement | A one-off inflow tied to a dated legal event | Proceeds far exceeding the equity the customer can evidence |
| Grant of probate or solicitor’s letter | Inherited funds and the estate they came from | An inheritance claimed with no estate document and no date |
| Company accounts and dividend vouchers | Business income for owner-managers | Accounts for a company the customer cannot be connected to |
| Exchange records with on-chain history | Crypto inflows and their prior hops | A wallet with no attribution, or funds routed through a mixer |
| Winnings held at another operator | A prior gambling balance | Recycled winnings offered as origin, which moves the question back a step rather than answering it |
Each of these carries more weight when the onboarding team collects it early instead of at the withdrawal stage, which is why KYC onboarding standards and source of funds policy belong in one process rather than two.
Establishing Source of Wealth for High-Value and PEP Accounts
Enhanced due diligence on high-value players starts from a narrative, not a document request. The reviewer has to be able to write two or three sentences explaining how this customer came to hold the assets they hold, then attach evidence to each claim in those sentences. Regulation 35 of the Money Laundering Regulations 2017 requires firms to establish source of wealth and source of funds for PEPs, their family members and known close associates. Malta’s Implementing Procedures require licensees to obtain information sufficient to establish source of wealth and the expected level of account activity, scaled to the risk the customer presents, and allow 30 days from the point a PEP threshold is reached for the enhanced measures to be in place.
A declaration signed by the player is not verification. Corroboration means testing the claim against something the customer does not control: an employer’s filings, a land registry entry, published accounts, a court record. Where the customer will not disclose enough to close the gap, the gap is itself the finding, and screening politically exposed persons on an ongoing basis will keep raising it until somebody records a decision.
Recording the Decision So an External Auditor Can Follow It
GICNT-AML is assessed through an annual third-party audit, and an auditor reconstructs decisions from files, not from conversations. Record keeping requirements that AML rules place on operators run to five years under the EU framework, counted from the end of the business relationship or from the date of the occasional transaction. A file that survives that review contains the following.
- The trigger, named: which threshold, alert or behaviour opened the review, with its date and the system that raised it
- The request sent to the customer, with the date it went out and the deadline given
- Every document received, stored unaltered, with its date of receipt
- The checks run against each document, including which independent source was used
- The reviewer’s reasoning in plain sentences: what was accepted, what was rejected, on what basis
- The outcome recorded as an action, whether that is continue, restrict, request more, close the account or report
- The approver by name and role, with senior management approval where the relationship involves a PEP
- The date set for the next reassessment
The same discipline covers alerts closed with no action taken. An auditor who finds transaction monitoring and escalation records showing outcomes but no reasoning will treat the control as undocumented, whatever the analyst remembers about the case.
What GICNT-AML Requires of Source of Funds and Source of Wealth Controls
The domain is Mandatory under the GICNT Framework v4.2 and reviewed through an annual third-party audit. The requirements bearing on this area:
- Policy that defines source of funds and source of wealth as separate checks, with distinct triggers for each
- Thresholds derived from the operator’s own risk assessment, documented, and reviewed at least once a year
- Enhanced due diligence for PEPs, customers connected to high-risk jurisdictions, and players whose spend outruns the profile they declared
- Verification by independent corroboration rather than customer attestation
- Escalation to a named officer, with senior management approval recorded for high-risk relationships
- Retention of the full decision trail for the period the licensing jurisdiction requires, with five years as the floor
- Staff training covering document fraud, altered statements and recycled winnings
Most of this falls out of the risk assessment when the operator is building an AML programme aligned with FATF recommendations. Certification confirms those controls exist and function. It does not replace the licence, or the supervision that comes with holding one.
FAQ About Source of Funds Checks
Is a source of funds check the same as an affordability check?
No. A source of funds review asks whether the money is legitimate, under anti-money laundering rules. An affordability or financial vulnerability check asks whether the customer can sustain the spending without harm. In Great Britain the two sit in different rulebooks, the Money Laundering Regulations 2017 and the social responsibility code, and clearing one clears nothing in the other.
At what deposit level should an operator request source of funds?
EU law fixes a due diligence trigger at €2,000 in stakes or winnings, single or linked. Above that, the level is the operator’s to set from its risk assessment, and it has to be defensible. The Gambling Commission has penalised thresholds set in the tens of thousands of pounds as too high to count as risk based.
Can previous gambling winnings count as source of funds?
Winnings held at another operator explain where a balance came from, but not how the original stake was funded. Treat recycled winnings as a prompt to go one step further back and evidence the money that entered the earlier account. Auditors read an unexamined winnings claim as a gap in the file.
Does source of wealth verification apply to every high-value player?
It applies where risk calls for it: PEPs and their close associates, customers linked to high-risk jurisdictions, and players whose activity does not match the profile they gave at onboarding. High deposit volume on its own triggers source of funds work first, and source of wealth once the funds picture fails to explain the level of play.
How long must these records be kept?
Five years is the baseline under the EU framework, counted from the end of the business relationship or from the occasional transaction. Several licensing jurisdictions require longer. An operator holding licences in more than one market should apply the longest period across the group rather than tracking each separately.