Anti-money laundering, or AML, in online gambling is the system of risk assessment, customer checks, monitoring, escalation and reporting used to prevent gambling services from handling criminal proceeds or financing terrorism.
This explainer is for operators, suppliers, compliance teams, analysts and journalists. It uses Great Britain as a current worked example and adds international context from FATF and the Swedish Gambling Authority. Exact duties, reporting routes and thresholds depend on the jurisdiction, licence, product and legal entity. This is not legal advice.
What AML means in online gambling
AML is the set of governance, risk and operational controls intended to stop a gambling business from being used to disguise, move or spend criminal property. Closely related controls address terrorist financing and, in some regimes, proliferation financing. The legal language and scope differ, so an operator must map each control to the rules that apply to its entity and activity.
The system begins with a business risk assessment and continues through policies, customer due diligence, transaction and activity monitoring, staff training, escalation, record keeping and external reporting. A policy document is only one part of the evidence. Effective implementation requires the control to produce reviewable decisions and to change when risks, products or payment methods change.
In Great Britain, LCCP condition 12.1.1 requires most operating licensees to assess the risk of their business being used for money laundering or terrorist financing and to maintain appropriate, effective controls. Casino businesses also sit within the regulated sector for additional legal duties under the Money Laundering Regulations.
AML, KYC, CDD and source of funds are related but different
| Role | What it means | Where to verify |
|---|---|---|
| AML framework | How the business identifies, assesses, controls, escalates and reports money laundering and terrorist financing risk. | Risk assessment, policies, ownership, training, monitoring, decisions, testing and reporting records. |
| KYC and identity verification | Who the customer is and whether the supplied identity details are supported by reliable evidence. | Collected data, verification source, result, time, exceptions and later changes. |
| Customer due diligence | What is known about the customer, beneficial ownership where relevant, purpose and expected relationship. | Risk rating, evidence obtained, rationale, reviewer and refresh schedule. |
| Source of funds or wealth | Where particular funds came from or how the customer's wider wealth was accumulated, when required by risk and law. | Request reason, documents or data, assessment, inconsistencies and decision. |
Our separate guide to KYC in online gambling explains identity, age and due diligence checks in more detail. The practical distinction is that KYC evidence feeds the AML framework, but a verified identity does not establish that every later transaction is legitimate or consistent with the customer profile.
The risk-based approach
A risk-based approach starts by identifying where the business could be exposed, then applies controls in proportion to the assessed risk. Relevant dimensions can include product design, delivery channel, customer type, geography, payment method, transaction pattern, technology, agents, business partners and links between accounts.
This is not permission to ignore lower-risk activity. It is a method for directing attention and evidence. Higher-risk situations can require stronger due diligence, closer monitoring, senior approval, limits or termination. Lower-risk treatment still needs a legal basis, a documented rationale and a mechanism for detecting change.
The FATF casino guidance includes internet casinos in its use of the term and describes evaluation of customer and transaction risks, account management, customer due diligence, record keeping, monitoring and suspicious activity reporting. FATF also warns that the 2008 sector paper should be read alongside later revisions to its standards.
A practical AML control cycle
- Assess the business model and document product, customer, geography, payment, channel and partner risks.
- Assign accountable owners and translate the assessment into policies, procedures, systems and staff responsibilities.
- Identify and verify customers, then apply due diligence that matches the legal and risk context.
- Monitor transactions, deposits, withdrawals, play and linked activity against the known customer and expected use.
- Investigate alerts, gather evidence, record the reasoning and escalate to the responsible compliance function.
- Apply the jurisdiction-specific process for restrictions, relationship decisions and suspicious activity reporting.
- Test control effectiveness, learn from cases and update the assessment when products, technology or risks change.
The cycle should connect front-end account activity with payment data and relevant records across products. It should also preserve who made a decision, what evidence was available and which rule or risk rationale supported it. That audit trail allows internal assurance, regulators and future reviewers to distinguish an operating control from a policy that exists only on paper.
Ongoing customer and transaction monitoring
Monitoring asks whether observed activity remains consistent with what the operator knows about the customer, the expected relationship and the assessed risk. It can consider deposits, withdrawals, stake patterns, payment instruments, account links, changes in behaviour, geographic signals and movement across products or channels.
The Commission's customer monitoring guidance says casino arrangements should cover the accounts a customer holds across outlets, products and platforms. Where the profile or gambling pattern creates an increasing level of suspicion, the operator should consider further due diligence and whether the relationship can continue within the law.
Automated alerts can help prioritise cases, but the alert is not the conclusion. Rules can create false positives, miss linked behaviour or reproduce poor assumptions. Human review needs sufficient context, clear escalation thresholds and feedback into the monitoring design. If artificial intelligence is used, accountability, validation and explainability still remain with the operator.
What suspicious activity indicators do and do not prove
An indicator is a signal that activity deserves assessment. It is not, by itself, proof that the customer has committed a crime. Context may explain a pattern, while several individually weak signals can become significant when combined. Reviewers should document both supporting and contradictory evidence rather than force every alert into one narrative.
The Commission's examples of suspicious activity are expressly non-exhaustive. They include unusual increases in stakes, spending apparently beyond known means, high aggregate spend built from smaller activity and low-risk betting patterns involving high spend. The examples guide judgement; they are not a universal automated rulebook.
Reporting and customer action must follow the relevant legal process. A public article should not describe confidential alert logic in a way that helps evasion, and staff should avoid disclosures that could prejudice an investigation. The responsible internal officer or function determines the next step using the information and law available in that jurisdiction.
Why AML evidence extends beyond the operator
An online gambling service can involve a licensed operator, iGaming platform, identity vendor, payment provider, game suppliers, hosting providers and outsourced compliance tools. Outsourcing a process does not automatically outsource regulatory accountability. Contracts, data flows, access controls, service levels and assurance results need to match the real operating model.
The same issue appears in a white-label gambling arrangement. The consumer-facing brand, licence holder and technology provider may be different entities. An AML review must resolve the contracting party, licensed entity, payment flow and accountable control owner instead of assigning every obligation to the visible brand.
Licensing claims require the same precision. Start with the role of a gambling operator, identify the market-facing entity, then verify the gambling licence in the regulator's own register. A group-level AML statement cannot automatically be attributed to every subsidiary, brand or jurisdiction.
The 2026 British risk picture
The Gambling Commission published its 2026 industry risk assessment on 30 July 2026. It rates remote casino, betting and bingo collectively as high risk, and non-remote casino as high risk. Other sectors receive different ratings. These are sector assessments, not findings that every operator or customer presents the same risk.
The assessment highlights an evolving environment, including artificial intelligence challenging customer due diligence controls and illegal gambling sites creating exposure to illicit financial flows in business relationships. It says operators must take the assessment into account when conducting the risk assessments required under Licence Condition 12.
This makes the topic timely for September 2026, but freshness should not be confused with permanence. A compliance article needs a visible verification date and scheduled review. Changes to legislation, guidance, enforcement priorities, payment methods or risk typologies can alter what an operator must do and what evidence a reviewer should expect.
How to assess an operator's AML claim
- Resolve the exact legal entity, licence, market and products covered by the claim.
- Check the regulator's current rules and guidance, not a generic group policy alone.
- Look for a dated business risk assessment that reflects products, technology, payments and customers.
- Identify accountable roles, escalation routes, training, monitoring and independent testing.
- Confirm that records connect alerts, evidence, decisions, restrictions and reports without exposing confidential details.
- Record gaps, conflicting sources and the date on which each public claim was checked.
Public evidence has limits. An operator should not publish sensitive rules that would help criminals avoid detection, and an outside reviewer rarely sees the full case file. The appropriate conclusion may be that governance is publicly described but operating effectiveness cannot be independently verified. That is more accurate than calling a system strong or weak from one policy page.
Frequently asked questions
Is AML the same as KYC?
No. AML is the wider system for assessing and controlling money laundering and terrorist financing risk. KYC identifies and verifies customers and may support customer due diligence. AML also includes business risk assessment, ongoing monitoring, staff responsibilities, escalation, record keeping, testing and suspicious activity reporting where the applicable law requires it.
Why do gambling operators ask for source-of-funds evidence?
An operator may request evidence when law, licence conditions or the assessed risk requires it to understand where particular gambling funds came from. The request should have a defined purpose and proportionate scope. Exact triggers and acceptable evidence vary, so customers should read the operator's notice and the relevant regulator's guidance.
Does a suspicious activity indicator prove money laundering?
No. An indicator is a reason to examine context, not a criminal finding. Reviewers consider the customer's known profile, transactions, gambling behaviour, linked accounts and explanations, then follow the relevant escalation process. Multiple signals may change the assessment, while credible contradictory evidence can also matter. Decisions and reasons should be recorded.
Are AML rules the same in every gambling market?
No. International standards influence national systems, but legal scope, thresholds, regulators, reporting routes and licence conditions differ. Casino, betting, lottery and software activities may also be treated differently within one country. Always identify the legal entity, product, customer location and licence before applying a rule from another jurisdiction.
Can an operator outsource AML checks to a vendor?
A vendor can provide identity data, screening, monitoring or case-management tools, subject to law and contract. That does not automatically transfer the operator's regulatory responsibility. The operator still needs appropriate governance, validation, access controls, oversight, escalation and evidence that the outsourced process works for its own products, customers and risks.
The BETTIMES AML research rule
BETTIMES treats AML as a system of entities, controls and dated evidence. The minimum record identifies the legal entity, licence, regulator, market, product, risk assessment date, accountable function, relevant policy, monitoring scope, source URL, verification date and unresolved limitations. Public disclosure and independently verified effectiveness are recorded separately.
A gambling licence can establish regulatory permission, but it does not prove that every control operated effectively in every period. We therefore avoid converting a licence badge, vendor partnership or broad compliance statement into a case-level conclusion. Where evidence is incomplete, the status remains unknown and is scheduled for review.
Why this record matters
BETTIMES links this publication to structured company, market and source records. Material changes can therefore be checked and refreshed without detaching the article from its original evidence.