AML Compliance

AML Compliance for your business. My Gaming License provides detailed support on licensing requirements, costs, and legal benefits for your gaming platform.

AML Compliance hero
Complete Processing Time
2 to 4 months
Regulatory Requirements
Strict
Reputation
N/A
Coverage
FATF, US BSA, EU AMLR/AMLD6, UK MLR 2017, AU AML/CTF Act
Decorative gradient stripe

AML compliance is the programme of policies, controls and procedures a regulated business runs to detect and prevent money laundering and terrorist financing. Money laundering is the crime itself. Know Your Customer (KYC) is one step inside the programme. Core regimes: the FATF 40 Recommendations, the Bank Secrecy Act, the EU AML package and the UK Money Laundering Regulations 2017.

Businesses caught by these regimes are called obliged entities. Casinos, online gambling operators and sports betting operators sit inside that category in the European Union, the United Kingdom, Australia and most licensed markets.

Why does AML compliance matter?

AML compliance failures carry three costs: regulatory sanctions, loss of banking and payment access, and licence risk. Supervisors can fine an operator, order remediation, suspend a licence or hold senior managers personally liable. Payment providers and banks screen for AML maturity before onboarding, so a weak programme blocks revenue before any regulator acts.

  • Regulatory sanctions: pecuniary sanctions, remedial orders, licence suspension or revocation

  • Personal liability: senior management and named compliance officers can be sanctioned individually

  • Commercial access: banks and payment service providers decline high-risk applicants without a documented programme

  • Market entry: licence applications in regulated markets require AML documentation at submission, not after approval

  • Financial system integrity: reporting feeds financial intelligence units that investigate organised crime

What does an AML compliance programme include?

An AML compliance programme is a set of mandatory elements, not a single document. Every major regime requires the same five building blocks: a risk-based approach, customer due diligence, transaction monitoring with suspicious activity reporting, a named responsible officer with board oversight, and staff training backed by independent audit.

Risk-based approach

The risk-based approach requires a business to assess its own money laundering risk before choosing controls, then apply stronger measures where risk is higher. The FATF 40 Recommendations, the EU Anti-Money Laundering Regulation (AMLR) and the UK Money Laundering Regulations 2017 all make this the starting point rather than a fixed checklist.

Two assessments are required:

  • Business-wide risk assessment: products, delivery channels, customer geographies and payment methods

  • Customer risk assessment: applied at onboarding and refreshed when behaviour or profile changes

A risk matrix combining the business-wide and the customer assessment sets which customers get standard due diligence and which get enhanced due diligence.

Customer due diligence (CDD) and KYC

Customer due diligence (CDD) is the full process of identifying a customer, verifying that identity, understanding the purpose of the relationship and monitoring it over time. Know Your Customer (KYC) is the identification and verification step inside CDD. Enhanced due diligence (EDD) is the heavier version applied to higher-risk customers.

Standard CDD covers:

  • Legal name, date of birth and residential address

  • Verification against a government-issued photo identity document

  • Sanctions screening against consolidated lists, including the OFAC list in the United States, plus politically exposed person (PEP) databases and adverse media

  • Purpose and intended nature of the business relationship

CDD threshold for gambling services under the EU AMLR: EUR 2,000, met by a single transaction or by several smaller linked transactions. The duty bites on the collection of winnings, on the wagering of a stake, or on both. To know when the threshold is reached, you must be able to attribute transactions to a customer before you have verified that customer's identity, so attribution and monitoring have to run ahead of CDD.

Transaction monitoring and suspicious activity reporting

Transaction monitoring reviews customer activity against expected behaviour and flags anomalies for human review. Where suspicion of money laundering or terrorist financing arises, the business files a suspicious activity report (SAR) with its national financial intelligence unit. Filing is mandatory, and warning the customer is a separate criminal offence.

Report names differ by jurisdiction: SAR in the United States and the United Kingdom, SMR in Australia, STR in most European Union member states.

Tipping off is prosecuted in its own right. In the United Kingdom, section 333A of the Proceeds of Crime Act 2002 carries up to two years' imprisonment on conviction on indictment.

Typical monitoring triggers in gambling:

  • Deposits inconsistent with a customer's stated income or source of funds

  • Structuring, meaning transactions split to stay under a reporting threshold

  • Minimal play followed by a withdrawal request

  • Rapid changes in stake size, game type or payment method

  • Third-party funding of an account

AML compliance officer (MLRO) and governance

Every obliged entity must appoint a named individual accountable for the AML programme. The United Kingdom calls this role the Money Laundering Reporting Officer (MLRO) under the Money Laundering Regulations 2017. The United States calls the equivalent role the BSA/AML compliance officer. Both report to senior management, which retains ultimate responsibility.

You appoint the officer. The regulator decides whether they may hold the role. In Malta the MLRO is registered with the FIAU and approved by the MGA as a key function, must be a natural person, and holds a personal certificate of approval issued after a fitness and propriety assessment. The MGA bars one person from combining conflicting key functions.

Governance requirements in most regimes:

  • A named officer with authority and direct access to the board

  • Board-level approval of the risk assessment and the AML policy

  • A documented escalation path from analyst to officer to board

  • Screening of staff in AML-sensitive roles

Training and independent audit

Staff training and independent audit close the programme. Training makes controls operational; audit tests whether they work in practice. Independent audit must be carried out by someone outside the day-to-day AML function, either internal staff without conflicting duties or an external firm. Frequency and scope are set by the applicable regime.

  • Training: onboarding for new staff, refresher cycles, role-specific modules for payments, VIP and customer support teams

  • Records: training logs retained as evidence for supervisors

  • Audit: independent testing of the risk assessment, CDD files, monitoring rules and reporting decisions

  • Review: the AML policy is reviewed at least annually and after any material change in risk, product or regulation

AML compliance in the gambling and iGaming sector

Gambling operators are obliged entities in the European Union, the United Kingdom, Australia and most licensed markets, and their AML obligations attach to the licence they hold. A licence application without an AML policy pack, a named MLRO and a documented risk assessment will not pass review, and post-licence audits test the same documents in operation.

What makes gambling AML different from banking AML:

  • Transaction volume is high and individual amounts are low, so monitoring rules must separate normal play from structuring

  • Player anonymity expectations conflict directly with CDD obligations

  • Bonus abuse, chip dumping and account sharing create laundering vectors that generic banking rules do not model

  • Payment mix spans cards, e-wallets, bank transfers and crypto, each with a different risk profile

Requirements vary by jurisdiction, and the applicable rules follow the licence rather than the operator's location. Malta sets the heaviest governance load: the MLRO is registered with the FIAU and separately approved by the MGA as a key function, and the business risk assessment must be documented and approved by the board. Curacao tightened after its 2024 reform and now requires a compliance officer the regulator authorises, reporting unusual transactions rather than suspicious ones alone. Kahnawake has published its own AML and counter-terrorist financing regulations since 2021, with fixed reporting deadlines. Nevis requires a compliance officer and a reporting officer approved under the Federation's rules, plus an AML policy at application. Anjouan carries the lightest documentary load of the five.

An offshore licence does not remove AML obligations. It changes how much is prescribed and how much is left to you. Expect a named officer, customer due diligence, monitoring and reporting under any of these regimes, and expect your bank and your payment providers to ask for the same policy pack whichever licence you hold.

Compare obligations on the individual jurisdiction pages: Malta, Anjouan, Curacao, Kahnawake and Nevis, or start from the full gaming licence hub.

AML maturity also decides banking and payment outcomes. Acquiring banks and payment service providers request the AML policy pack during onboarding, which links compliance directly to bank account setup and payment solutions.

What are the key AML regulations and frameworks?

No single global AML law exists. The FATF sets the international standard, and individual jurisdictions implement it through their own legislation. Four regimes matter most for internationally active operators: the FATF 40 Recommendations, the United States Bank Secrecy Act, the European Union AML package and the United Kingdom Money Laundering Regulations 2017.

RegionMain instrumentSupervisorStatus (as of August 2026)
GlobalFATF 40 RecommendationsFATF (standard-setter, no direct enforcement)In force; countries assessed by mutual evaluation
United StatesBank Secrecy ActFinCENIn force
European UnionAMLR (EU) 2024/1624 and AMLD6 (EU) 2024/1640AMLA plus national supervisorsAdopted; applies from 10 July 2027
United KingdomMoney Laundering Regulations 2017HMRC, FCA, Gambling Commission and other named supervisorsIn force
AustraliaAML/CTF Act 2006AUSTRACIn force

Global standards: FATF and the 40 Recommendations

The Financial Action Task Force (FATF) is the intergovernmental body that sets the global AML and counter-terrorist financing standard. The FATF issues the 40 Recommendations, assesses countries through mutual evaluations, and publishes two lists of jurisdictions with weak controls three times a year.

Three facts about FATF enforcement:

The two lists carry different consequences. Grey listing means increased monitoring. It is not a sanction, and it does not by itself require enhanced due diligence. Treat it as an input to your country risk assessment. Mandatory enhanced due diligence, and countermeasures in the most serious cases, attach to the black list of high-risk jurisdictions subject to a call for action. In practice many banks and payment providers apply enhanced due diligence to grey-listed jurisdictions anyway, so the commercial effect can run ahead of the legal requirement.

State of play as of 19 June 2026: 22 jurisdictions are under increased monitoring, after Iraq and Bosnia and Herzegovina were added and Algeria and Namibia were removed. The black list is unchanged: Iran, North Korea and Myanmar.

United States: BSA, FinCEN and the five BSA/AML pillars

The Bank Secrecy Act (BSA) is the foundation of United States AML law, administered by the Financial Crimes Enforcement Network (FinCEN). A compliant BSA/AML compliance program rests on five pillars. The fifth pillar, customer due diligence and beneficial ownership, was added by the 2016 CDD Rule and took effect on 11 May 2018.

The five BSA/AML pillars:

  • A designated BSA/AML compliance officer

  • Internal policies, procedures and controls

  • Independent audit and testing of the program

  • Ongoing staff training

  • Customer due diligence and beneficial ownership identification

SAR filing deadline: 30 calendar days from initial detection, extendable to a maximum of 60 calendar days where no suspect has been identified.

For broker-dealers, FINRA Rule 3310(c) requires annual independent testing, reduced to every two years for members that do not execute customer transactions, hold customer accounts or act as an introducing broker.

European Union: the AML package (AMLR, AMLD6, AMLA)

In 2024 the European Union adopted a single AML package that replaces the previous directive-only regime. Three instruments carry it: a directly applicable Single Rulebook, a directive covering national mechanisms, and a new supervisory authority. Most of the package applies from 10 July 2027, so national rules still govern until that date.

AMLR matters to gambling operators because of the form of the law. It lists providers of gambling services among the obliged entities in Article 3 and defines gambling services in Article 2, inside a directly applicable single rulebook, so the core duties stop varying with each member state's transposition. The definition itself is not new: Directive (EU) 2015/849 already used the same wording.

  • AMLR, Regulation (EU) 2024/1624: the directly applicable Single Rulebook. Applies from 10 July 2027, with a later date of 10 July 2029 for the obliged entities listed in Article 3, points (3)(n) and (o).

  • AMLD6, Directive (EU) 2024/1640: national mechanisms, supervision and sanctions. Repeals Directive (EU) 2015/849 with effect from 10 July 2027.

  • AMLA, Regulation (EU) 2024/1620: the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, seated in Frankfurt. Entered into force on 26 June 2024 and applies from 1 July 2025. Direct supervision of selected obliged entities starts on 1 January 2028 and is limited to credit institutions and financial institutions, so gambling operators stay with their national supervisors.

Maximum pecuniary sanctions under AMLD6 for serious, repeated or systematic breaches, applying from 10 July 2027: Member States must provide for a maximum of at least twice the benefit derived from the breach, or at least EUR 1,000,000, whichever is higher. For credit institutions and financial institutions the maximum is at least EUR 10,000,000 or 10% of total annual turnover, whichever is higher.

Crypto-asset transfers are covered separately by Regulation (EU) 2023/1113, the Union travel rule.

Article 4 AMLR: exemptions for certain gambling providers

Article 4 AMLR lets a member state exempt providers of gambling services from the regulation, in full or in part, on the basis of the proven low risk posed by the nature and, where appropriate, the scale of operations of such services. The exemption is a national choice, not automatic relief, and it is narrow.

It will not reach most online operators. Article 4(1) states that the exemption does not apply to casinos, or to providers of gambling services whose principal activity is online gambling or sport betting. Two carve-outs remain: online gambling operated by the State, and online gambling whose organisation, operation and administration is regulated by the State.

Before granting an exemption, the member state must assess the money laundering and terrorist financing risk of the gambling services, the risks linked to the size of transactions and payment methods used, and the geographical area in which the services are administered, including cross-border accessibility. It must also run risk-based monitoring so exemptions are not abused. Plan on the full regime applying to you.

United Kingdom: Money Laundering Regulations 2017

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, known as MLR 2017, are the operative AML rules in the United Kingdom. MLR 2017 sets a risk-based approach, defines required internal controls, lists supervised sectors and fixes record-keeping obligations.

  • Regulation 21: appoint an officer responsible for compliance, appoint a nominated officer for reporting, screen relevant staff and establish an independent audit function

  • Regulation 40: retain CDD documents and records sufficient to reconstruct a transaction for at least five years

  • Supervised sectors: each sector has a named supervisor, including HMRC, the Financial Conduct Authority, and the Gambling Commission for licensed gambling operators in Great Britain

AML requirements for regulated businesses

Obliged entities are the businesses that AML law binds directly, including banks, payment institutions, crypto-asset service providers, gambling operators, accountants, lawyers and company service providers. Obligations differ in detail between jurisdictions but converge on six duties, and supervisors expect documented evidence for each one.

  • Risk assessment: a written business-wide assessment, kept current

  • Customer due diligence: identification, verification, ongoing monitoring and enhanced due diligence for higher-risk customers

  • Transaction monitoring: systems proportionate to transaction volume and product risk

  • Reporting: suspicious activity reports filed with the national financial intelligence unit within the applicable deadline

  • Training: documented programme covering all staff in AML-sensitive roles

  • Record keeping: CDD and transaction records retained for at least five years under the EU, UK and US regimes

JurisdictionReport nameFiling deadlineRecipient
United StatesSuspicious Activity Report (SAR)30 calendar days from initial detection; up to 60 where no suspect is identifiedFinCEN
AustraliaSuspicious Matter Report (SMR)3 business days; 24 hours where terrorism financing is suspectedAUSTRAC
United KingdomSuspicious Activity Report (SAR)As soon as practicable after suspicion arisesNational Crime Agency (UKFIU)
European UnionSuspicious Transaction Report (STR)No single Union deadline; set by national lawNational financial intelligence unit

How does MGL help with AML compliance?

MGL builds and documents AML programmes for gambling operators and B2B suppliers, then keeps them current. Work covers the written programme, the people who run it and the evidence supervisors ask for. AML documentation forms part of every licence submission MGL files.

  • Business-wide risk assessment and customer risk matrix

  • AML/CFT policy pack: CDD and EDD procedures, monitoring thresholds, reporting workflow, record-keeping standards

  • Compliance officer appointment support: we source the candidate, prepare the application pack and support the approval process. The regulator approves the appointment.

  • Jurisdiction mapping: which obligations attach to your licence and which reporting channel applies

  • Filing setup: registration with the relevant financial intelligence unit and reporting workflow configuration

  • Staff training programme and training records

  • Independent audit coordination and remediation of findings

  • AML documentation prepared to the standard the licensing regulator reviews at application

If you already have a qualified MLRO and an experienced compliance team in-house, you may not need an external provider. In that case we review your existing documentation against the regime that applies to your licence, instead of building a pack you do not need.

FAQ

Everything you need to know about Our company. Can't find the answer you're looking for? Please chat to our team.

The five pillars of a BSA/AML compliance program are a designated compliance officer, internal policies and controls, independent audit and testing, ongoing staff training, and customer due diligence with beneficial ownership identification. The fifth pillar took effect on 11 May 2018.

A named compliance officer holds day-to-day responsibility, called the Money Laundering Reporting Officer (MLRO) in the United Kingdom and the BSA/AML compliance officer in the United States. Senior management and the board retain ultimate accountability and can be sanctioned personally.

Know Your Customer (KYC) is the identification and verification of a customer. AML compliance is the wider programme that contains KYC alongside risk assessment, transaction monitoring, suspicious activity reporting, training and audit. KYC is one component of AML compliance.

An AML policy is the written document setting out rules and procedures. An AML compliance programme is the policy plus the controls, systems, people and records that put it into operation. Supervisors assess the programme, not the document alone.

A politically exposed person (PEP) is an individual entrusted with a prominent public function, together with immediate family members and close associates. PEP status triggers enhanced due diligence, including source-of-funds verification and senior management approval of the relationship.

Penalties include pecuniary sanctions, licence suspension or revocation, criminal charges and personal liability for senior managers. For serious, repeated or systematic breaches from 10 July 2027, AMLD6 requires Member States to provide for a maximum of at least twice the benefit derived from the breach or at least EUR 1,000,000, whichever is higher, rising to at least EUR 10,000,000 or 10% of turnover for credit and financial institutions.

No. Under the FinCEN interim final rule of 26 March 2025, entities created in the United States and their beneficial owners are exempt. Only entities formed abroad and registered in a US State or Tribal jurisdiction still report.

Yes. Crypto-asset service providers are obliged entities under the EU AML package, and crypto-asset transfers fall under Regulation (EU) 2023/1113, the Union travel rule. Requirements match those for financial institutions: CDD, monitoring, reporting, training and audit.

An AML compliance audit is an independent test of whether a programme works in practice, covering the risk assessment, CDD files, monitoring rules and reporting decisions. UK Regulation 21 requires an independent audit function; FINRA Rule 3310(c) requires annual independent testing for most broker-dealers.

Need an AML programme for your licence? MGL builds the policy pack, risk assessment and MLRO setup regulators expect.

Navigating the gaming license process can be complex. Here's a streamlined guide to each step