How Anti-Money Laundering Duties Apply to Licensed Gambling Operators

A look at the core AML obligations that sit behind every UK gambling licence, from risk assessments to suspicious activity reports.

a tall building with lots of windows next to another building
Photo · Photo by Rose Galloway Green on Unsplash

Automated report. This article was drafted with AI assistance from the sources listed below, without a human writing step. Gambling News labels every article produced this way. A person is answerable for it: if something here is wrong, write to editor@gamblingnews.co.uk and we will correct it on the page and say what changed.

Why gambling is treated as high risk

Cash-rich, fast-moving and international by nature, gambling has long been identified as a sector vulnerable to money laundering. Criminals can use betting accounts, casino chips or online wallets to convert illicit funds into apparently legitimate winnings, or to move money across borders with minimal scrutiny. Because of this, operators licensed under the Gambling Act are treated as businesses regulated for anti-money laundering (AML) and counter-terrorist financing purposes, alongside banks, estate agents and law firms.

The legal foundation is the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations, commonly known as the MLRs. Casinos are directly captured by these regulations. Other gambling operators are brought into scope primarily through the Gambling Commission’s licence conditions and codes of practice (LCCP), which impose parallel duties. In practice, any operator holding a Commission licence needs a functioning AML and counter-terrorist financing programme, whether or not the MLRs technically apply to their specific activity.

The risk-based approach

AML law does not prescribe a single checklist that fits every business. Instead it requires a risk-based approach: operators must assess the money laundering and terrorist financing risks they actually face, given their customer base, products, channels and geography, and then design controls proportionate to that risk. A high-street bingo hall and a global online casino accepting cryptocurrency deposits will reasonably have very different risk profiles and therefore different levels of scrutiny.

This starts with a written business risk assessment, which operators must keep up to date and be ready to show the Gambling Commission on request. It should cover factors such as customer types, delivery channels, payment methods, and the jurisdictions customers and funds come from. From this flows the customer risk assessment applied to individual players, which determines how much due diligence is needed and how closely their play is monitored.

Customer due diligence and source of funds

At the most basic level, operators must verify who their customers are. This typically involves identity verification, often now completed digitally, before or shortly after a customer is able to gamble with real money, depending on the risk level and product.

Where risk indicators are present, enhanced due diligence kicks in. This is the area that has drawn the most regulatory attention in the sector. Enhanced due diligence can mean asking a customer to evidence the source of the funds they are gambling with, for example through payslips, bank statements or documentation of savings, investments or business income. Triggers for this scrutiny commonly include unusually large or rapid deposits, spending patterns inconsistent with a customer’s known circumstances, use of multiple payment methods or third-party cards, or links to jurisdictions considered higher risk.

Operators are expected to build indicators into their systems that flag this kind of behaviour automatically rather than relying solely on manual review, and to act on those flags promptly rather than allowing play to continue unchecked while checks are pending.

Ongoing monitoring, not one-off checks

AML compliance is not a single event at account opening. Operators are required to monitor customer behaviour throughout the relationship, watching for changes that might indicate laundering, such as a sudden shift from small stakes to large ones, rapid deposit-and-withdrawal cycles with little genuine play in between, or patterns suggesting an account is being used to move money rather than to gamble. This ongoing monitoring needs to be documented, so the operator can show a regulator or investigator why decisions were made and what evidence supported them.

Suspicious Activity Reports and the MLRO

Where an operator knows or suspects that funds are the proceeds of crime, it has a legal duty to submit a Suspicious Activity Report (SAR) to the National Crime Agency. This obligation exists independently of any commercial decision to close or restrict an account, and operators must be careful not to alert a customer that a report has been made, since doing so can amount to the criminal offence of tipping off.

Every licensed operator is required to appoint a nominated officer, generally known as the Money Laundering Reporting Officer (MLRO), who takes responsibility for AML compliance, oversees SAR submissions and acts as the main point of contact with law enforcement and the regulator. Larger operators typically also need a senior manager with overall AML oversight, and staff across the business need regular training so they can recognise red flags relevant to their role.

Record-keeping and regulatory consequences

Operators must retain records of identity checks, risk assessments, source of funds evidence and monitoring decisions for a set retention period, and be able to produce them on request. Failure to do so is itself a compliance failure, regardless of whether any actual laundering took place.

The Gambling Commission has repeatedly taken enforcement action against operators for AML and social responsibility failings, ranging from financial penalties to licence reviews. These cases typically centre not on isolated mistakes but on systemic weaknesses: risk assessments that were not kept current, source of funds checks not applied consistently, or monitoring alerts that were not acted on quickly enough.

Where to check current requirements

Because guidance, licence conditions and enforcement priorities change, operators and compliance teams should always check the current position directly with the primary sources rather than relying on summaries. The Gambling Commission publishes the LCCP and specific AML guidance for the sector, HM Treasury and the Home Office maintain the underlying MLRs framework, and the National Crime Agency provides guidance on SAR submission.

Sources