AML Compliance
AML Compliance for your business. My Gaming License provides detailed support on licensing requirements, costs, and legal benefits for your gaming platform.

AML compliance is the programme of policies, controls and procedures a regulated business runs to detect and prevent money laundering and terrorist financing. Money laundering is the crime itself. Know Your Customer (KYC) is one step inside the programme. Core regimes: the FATF 40 Recommendations, the Bank Secrecy Act, the EU AML package and the UK Money Laundering Regulations 2017.
Businesses caught by these regimes are called obliged entities. Casinos, online gambling operators and sports betting operators sit inside that category in the European Union, the United Kingdom, Australia and most licensed markets.
Why does AML compliance matter?
AML compliance failures carry three costs: regulatory sanctions, loss of banking and payment access, and licence risk. Supervisors can fine an operator, order remediation, suspend a licence or hold senior managers personally liable. Payment providers and banks screen for AML maturity before onboarding, so a weak programme blocks revenue before any regulator acts.
Regulatory sanctions: pecuniary sanctions, remedial orders, licence suspension or revocation
Personal liability: senior management and named compliance officers can be sanctioned individually
Commercial access: banks and payment service providers decline high-risk applicants without a documented programme
Market entry: licence applications in regulated markets require AML documentation at submission, not after approval
Financial system integrity: reporting feeds financial intelligence units that investigate organised crime
What does an AML compliance programme include?
An AML compliance programme is a set of mandatory elements, not a single document. Every major regime requires the same five building blocks: a risk-based approach, customer due diligence, transaction monitoring with suspicious activity reporting, a named responsible officer with board oversight, and staff training backed by independent audit.
Risk-based approach
The risk-based approach requires a business to assess its own money laundering risk before choosing controls, then apply stronger measures where risk is higher. The FATF 40 Recommendations, the EU Anti-Money Laundering Regulation (AMLR) and the UK Money Laundering Regulations 2017 all make this the starting point rather than a fixed checklist.
Two assessments are required:
Business-wide risk assessment: products, delivery channels, customer geographies and payment methods
Customer risk assessment: applied at onboarding and refreshed when behaviour or profile changes
A risk matrix combining the business-wide and the customer assessment sets which customers get standard due diligence and which get enhanced due diligence.
Customer due diligence (CDD) and KYC
Customer due diligence (CDD) is the full process of identifying a customer, verifying that identity, understanding the purpose of the relationship and monitoring it over time. Know Your Customer (KYC) is the identification and verification step inside CDD. Enhanced due diligence (EDD) is the heavier version applied to higher-risk customers.
Standard CDD covers:
Legal name, date of birth and residential address
Verification against a government-issued photo identity document
Sanctions screening against consolidated lists, including the OFAC list in the United States, plus politically exposed person (PEP) databases and adverse media
Purpose and intended nature of the business relationship
CDD threshold for gambling services under the EU AMLR: EUR 2,000, met by a single transaction or by several smaller linked transactions. The duty bites on the collection of winnings, on the wagering of a stake, or on both. To know when the threshold is reached, you must be able to attribute transactions to a customer before you have verified that customer's identity, so attribution and monitoring have to run ahead of CDD.
Transaction monitoring and suspicious activity reporting
Transaction monitoring reviews customer activity against expected behaviour and flags anomalies for human review. Where suspicion of money laundering or terrorist financing arises, the business files a suspicious activity report (SAR) with its national financial intelligence unit. Filing is mandatory, and warning the customer is a separate criminal offence.
Report names differ by jurisdiction: SAR in the United States and the United Kingdom, SMR in Australia, STR in most European Union member states.
Tipping off is prosecuted in its own right. In the United Kingdom, section 333A of the Proceeds of Crime Act 2002 carries up to two years' imprisonment on conviction on indictment.
Typical monitoring triggers in gambling:
Deposits inconsistent with a customer's stated income or source of funds
Structuring, meaning transactions split to stay under a reporting threshold
Minimal play followed by a withdrawal request
Rapid changes in stake size, game type or payment method
Third-party funding of an account
AML compliance officer (MLRO) and governance
Every obliged entity must appoint a named individual accountable for the AML programme. The United Kingdom calls this role the Money Laundering Reporting Officer (MLRO) under the Money Laundering Regulations 2017. The United States calls the equivalent role the BSA/AML compliance officer. Both report to senior management, which retains ultimate responsibility.
You appoint the officer. The regulator decides whether they may hold the role. In Malta the MLRO is registered with the FIAU and approved by the MGA as a key function, must be a natural person, and holds a personal certificate of approval issued after a fitness and propriety assessment. The MGA bars one person from combining conflicting key functions.
Governance requirements in most regimes:
A named officer with authority and direct access to the board
Board-level approval of the risk assessment and the AML policy
A documented escalation path from analyst to officer to board
Screening of staff in AML-sensitive roles
Training and independent audit
Staff training and independent audit close the programme. Training makes controls operational; audit tests whether they work in practice. Independent audit must be carried out by someone outside the day-to-day AML function, either internal staff without conflicting duties or an external firm. Frequency and scope are set by the applicable regime.
Training: onboarding for new staff, refresher cycles, role-specific modules for payments, VIP and customer support teams
Records: training logs retained as evidence for supervisors
Audit: independent testing of the risk assessment, CDD files, monitoring rules and reporting decisions
Review: the AML policy is reviewed at least annually and after any material change in risk, product or regulation
AML compliance in the gambling and iGaming sector
Gambling operators are obliged entities in the European Union, the United Kingdom, Australia and most licensed markets, and their AML obligations attach to the licence they hold. A licence application without an AML policy pack, a named MLRO and a documented risk assessment will not pass review, and post-licence audits test the same documents in operation.
What makes gambling AML different from banking AML:
Transaction volume is high and individual amounts are low, so monitoring rules must separate normal play from structuring
Player anonymity expectations conflict directly with CDD obligations
Bonus abuse, chip dumping and account sharing create laundering vectors that generic banking rules do not model
Payment mix spans cards, e-wallets, bank transfers and crypto, each with a different risk profile
Requirements vary by jurisdiction, and the applicable rules follow the licence rather than the operator's location. Malta sets the heaviest governance load: the MLRO is registered with the FIAU and separately approved by the MGA as a key function, and the business risk assessment must be documented and approved by the board. Curacao tightened after its 2024 reform and now requires a compliance officer the regulator authorises, reporting unusual transactions rather than suspicious ones alone. Kahnawake has published its own AML and counter-terrorist financing regulations since 2021, with fixed reporting deadlines. Nevis requires a compliance officer and a reporting officer approved under the Federation's rules, plus an AML policy at application. Anjouan carries the lightest documentary load of the five.
An offshore licence does not remove AML obligations. It changes how much is prescribed and how much is left to you. Expect a named officer, customer due diligence, monitoring and reporting under any of these regimes, and expect your bank and your payment providers to ask for the same policy pack whichever licence you hold.
Compare obligations on the individual jurisdiction pages: Malta, Anjouan, Curacao, Kahnawake and Nevis, or start from the full gaming licence hub.
AML maturity also decides banking and payment outcomes. Acquiring banks and payment service providers request the AML policy pack during onboarding, which links compliance directly to bank account setup and payment solutions.
What are the key AML regulations and frameworks?
No single global AML law exists. The FATF sets the international standard, and individual jurisdictions implement it through their own legislation. Four regimes matter most for internationally active operators: the FATF 40 Recommendations, the United States Bank Secrecy Act, the European Union AML package and the United Kingdom Money Laundering Regulations 2017.
| Region | Main instrument | Supervisor | Status (as of August 2026) |
|---|---|---|---|
| Global | FATF 40 Recommendations | FATF (standard-setter, no direct enforcement) | In force; countries assessed by mutual evaluation |
| United States | Bank Secrecy Act | FinCEN | In force |
| European Union | AMLR (EU) 2024/1624 and AMLD6 (EU) 2024/1640 | AMLA plus national supervisors | Adopted; applies from 10 July 2027 |
| United Kingdom | Money Laundering Regulations 2017 | HMRC, FCA, Gambling Commission and other named supervisors | In force |
| Australia | AML/CTF Act 2006 | AUSTRAC | In force |
Global standards: FATF and the 40 Recommendations
The Financial Action Task Force (FATF) is the intergovernmental body that sets the global AML and counter-terrorist financing standard. The FATF issues the 40 Recommendations, assesses countries through mutual evaluations, and publishes two lists of jurisdictions with weak controls three times a year.
Three facts about FATF enforcement:
The FATF issues the 40 Recommendations as a standard, not as directly binding law
The FATF does not fine businesses; countries write the Recommendations into national law and their supervisors enforce it
The FATF publishes Jurisdictions under Increased Monitoring (the grey list) and High-Risk Jurisdictions subject to a Call for Action (the black list)
The two lists carry different consequences. Grey listing means increased monitoring. It is not a sanction, and it does not by itself require enhanced due diligence. Treat it as an input to your country risk assessment. Mandatory enhanced due diligence, and countermeasures in the most serious cases, attach to the black list of high-risk jurisdictions subject to a call for action. In practice many banks and payment providers apply enhanced due diligence to grey-listed jurisdictions anyway, so the commercial effect can run ahead of the legal requirement.
State of play as of 19 June 2026: 22 jurisdictions are under increased monitoring, after Iraq and Bosnia and Herzegovina were added and Algeria and Namibia were removed. The black list is unchanged: Iran, North Korea and Myanmar.
United States: BSA, FinCEN and the five BSA/AML pillars
The Bank Secrecy Act (BSA) is the foundation of United States AML law, administered by the Financial Crimes Enforcement Network (FinCEN). A compliant BSA/AML compliance program rests on five pillars. The fifth pillar, customer due diligence and beneficial ownership, was added by the 2016 CDD Rule and took effect on 11 May 2018.
The five BSA/AML pillars:
A designated BSA/AML compliance officer
Internal policies, procedures and controls
Independent audit and testing of the program
Ongoing staff training
Customer due diligence and beneficial ownership identification
SAR filing deadline: 30 calendar days from initial detection, extendable to a maximum of 60 calendar days where no suspect has been identified.
For broker-dealers, FINRA Rule 3310(c) requires annual independent testing, reduced to every two years for members that do not execute customer transactions, hold customer accounts or act as an introducing broker.
European Union: the AML package (AMLR, AMLD6, AMLA)
In 2024 the European Union adopted a single AML package that replaces the previous directive-only regime. Three instruments carry it: a directly applicable Single Rulebook, a directive covering national mechanisms, and a new supervisory authority. Most of the package applies from 10 July 2027, so national rules still govern until that date.
AMLR matters to gambling operators because of the form of the law. It lists providers of gambling services among the obliged entities in Article 3 and defines gambling services in Article 2, inside a directly applicable single rulebook, so the core duties stop varying with each member state's transposition. The definition itself is not new: Directive (EU) 2015/849 already used the same wording.
AMLR, Regulation (EU) 2024/1624: the directly applicable Single Rulebook. Applies from 10 July 2027, with a later date of 10 July 2029 for the obliged entities listed in Article 3, points (3)(n) and (o).
AMLD6, Directive (EU) 2024/1640: national mechanisms, supervision and sanctions. Repeals Directive (EU) 2015/849 with effect from 10 July 2027.
AMLA, Regulation (EU) 2024/1620: the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, seated in Frankfurt. Entered into force on 26 June 2024 and applies from 1 July 2025. Direct supervision of selected obliged entities starts on 1 January 2028 and is limited to credit institutions and financial institutions, so gambling operators stay with their national supervisors.
Maximum pecuniary sanctions under AMLD6 for serious, repeated or systematic breaches, applying from 10 July 2027: Member States must provide for a maximum of at least twice the benefit derived from the breach, or at least EUR 1,000,000, whichever is higher. For credit institutions and financial institutions the maximum is at least EUR 10,000,000 or 10% of total annual turnover, whichever is higher.
Crypto-asset transfers are covered separately by Regulation (EU) 2023/1113, the Union travel rule.
Article 4 AMLR: exemptions for certain gambling providers
Article 4 AMLR lets a member state exempt providers of gambling services from the regulation, in full or in part, on the basis of the proven low risk posed by the nature and, where appropriate, the scale of operations of such services. The exemption is a national choice, not automatic relief, and it is narrow.
It will not reach most online operators. Article 4(1) states that the exemption does not apply to casinos, or to providers of gambling services whose principal activity is online gambling or sport betting. Two carve-outs remain: online gambling operated by the State, and online gambling whose organisation, operation and administration is regulated by the State.
Before granting an exemption, the member state must assess the money laundering and terrorist financing risk of the gambling services, the risks linked to the size of transactions and payment methods used, and the geographical area in which the services are administered, including cross-border accessibility. It must also run risk-based monitoring so exemptions are not abused. Plan on the full regime applying to you.
United Kingdom: Money Laundering Regulations 2017
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, known as MLR 2017, are the operative AML rules in the United Kingdom. MLR 2017 sets a risk-based approach, defines required internal controls, lists supervised sectors and fixes record-keeping obligations.
Regulation 21: appoint an officer responsible for compliance, appoint a nominated officer for reporting, screen relevant staff and establish an independent audit function
Regulation 40: retain CDD documents and records sufficient to reconstruct a transaction for at least five years
Supervised sectors: each sector has a named supervisor, including HMRC, the Financial Conduct Authority, and the Gambling Commission for licensed gambling operators in Great Britain
AML requirements for regulated businesses
Obliged entities are the businesses that AML law binds directly, including banks, payment institutions, crypto-asset service providers, gambling operators, accountants, lawyers and company service providers. Obligations differ in detail between jurisdictions but converge on six duties, and supervisors expect documented evidence for each one.
Risk assessment: a written business-wide assessment, kept current
Customer due diligence: identification, verification, ongoing monitoring and enhanced due diligence for higher-risk customers
Transaction monitoring: systems proportionate to transaction volume and product risk
Reporting: suspicious activity reports filed with the national financial intelligence unit within the applicable deadline
Training: documented programme covering all staff in AML-sensitive roles
Record keeping: CDD and transaction records retained for at least five years under the EU, UK and US regimes
| Jurisdiction | Report name | Filing deadline | Recipient |
|---|---|---|---|
| United States | Suspicious Activity Report (SAR) | 30 calendar days from initial detection; up to 60 where no suspect is identified | FinCEN |
| Australia | Suspicious Matter Report (SMR) | 3 business days; 24 hours where terrorism financing is suspected | AUSTRAC |
| United Kingdom | Suspicious Activity Report (SAR) | As soon as practicable after suspicion arises | National Crime Agency (UKFIU) |
| European Union | Suspicious Transaction Report (STR) | No single Union deadline; set by national law | National financial intelligence unit |
How does MGL help with AML compliance?
MGL builds and documents AML programmes for gambling operators and B2B suppliers, then keeps them current. Work covers the written programme, the people who run it and the evidence supervisors ask for. AML documentation forms part of every licence submission MGL files.
Business-wide risk assessment and customer risk matrix
AML/CFT policy pack: CDD and EDD procedures, monitoring thresholds, reporting workflow, record-keeping standards
Compliance officer appointment support: we source the candidate, prepare the application pack and support the approval process. The regulator approves the appointment.
Jurisdiction mapping: which obligations attach to your licence and which reporting channel applies
Filing setup: registration with the relevant financial intelligence unit and reporting workflow configuration
Staff training programme and training records
Independent audit coordination and remediation of findings
AML documentation prepared to the standard the licensing regulator reviews at application
If you already have a qualified MLRO and an experienced compliance team in-house, you may not need an external provider. In that case we review your existing documentation against the regime that applies to your licence, instead of building a pack you do not need.
FAQ
Everything you need to know about Our company. Can't find the answer you're looking for? Please chat to our team.
The five pillars of a BSA/AML compliance program are a designated compliance officer, internal policies and controls, independent audit and testing, ongoing staff training, and customer due diligence with beneficial ownership identification. The fifth pillar took effect on 11 May 2018.
A named compliance officer holds day-to-day responsibility, called the Money Laundering Reporting Officer (MLRO) in the United Kingdom and the BSA/AML compliance officer in the United States. Senior management and the board retain ultimate accountability and can be sanctioned personally.
Know Your Customer (KYC) is the identification and verification of a customer. AML compliance is the wider programme that contains KYC alongside risk assessment, transaction monitoring, suspicious activity reporting, training and audit. KYC is one component of AML compliance.
An AML policy is the written document setting out rules and procedures. An AML compliance programme is the policy plus the controls, systems, people and records that put it into operation. Supervisors assess the programme, not the document alone.
A politically exposed person (PEP) is an individual entrusted with a prominent public function, together with immediate family members and close associates. PEP status triggers enhanced due diligence, including source-of-funds verification and senior management approval of the relationship.
Penalties include pecuniary sanctions, licence suspension or revocation, criminal charges and personal liability for senior managers. For serious, repeated or systematic breaches from 10 July 2027, AMLD6 requires Member States to provide for a maximum of at least twice the benefit derived from the breach or at least EUR 1,000,000, whichever is higher, rising to at least EUR 10,000,000 or 10% of turnover for credit and financial institutions.
No. Under the FinCEN interim final rule of 26 March 2025, entities created in the United States and their beneficial owners are exempt. Only entities formed abroad and registered in a US State or Tribal jurisdiction still report.
Yes. Crypto-asset service providers are obliged entities under the EU AML package, and crypto-asset transfers fall under Regulation (EU) 2023/1113, the Union travel rule. Requirements match those for financial institutions: CDD, monitoring, reporting, training and audit.
An AML compliance audit is an independent test of whether a programme works in practice, covering the risk assessment, CDD files, monitoring rules and reporting decisions. UK Regulation 21 requires an independent audit function; FINRA Rule 3310(c) requires annual independent testing for most broker-dealers.
Navigating the gaming license process can be complex. Here's a streamlined guide to each step