AML Compliance Program for Online Casinos (8 Pillars)
Key takeaways
- An AML compliance program is a governance framework, not a piece of software - buying a KYC tool is not the same as running a program.
- The core pillars: risk assessment, policies and internal controls, an MLRO, CDD/EDD, transaction monitoring, SAR/STR and threshold reporting, recordkeeping, and independent testing plus training.
- It maps to FATF Recommendation 18 (programme) and Recommendation 22 (casino CDD at the FATF-designated USD/EUR 3,000 threshold), and in the US to the Bank Secrecy Act (31 CFR 1021.210).
- The program is risk-based: higher-risk customers, products and jurisdictions trigger Enhanced Due Diligence.
- Responsible-gambling and age checks sit inside the same control framework - never advise weakening or bypassing them.
An AML compliance program for an online casino is the governance framework that lets an operator detect, prevent and report money laundering - a documented, risk-based set of controls, not a single piece of software. Its pillars are a risk assessment, policies and internal controls, a designated Money Laundering Reporting Officer (MLRO), Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD), transaction monitoring, suspicious-activity and threshold reporting, recordkeeping, and independent testing with training. It mirrors FATF Recommendations and, in the US, the Bank Secrecy Act (BSA).
This guide lays out each pillar, what it means for an online casino, and how it maps to both FATF (Recommendation 18 and Recommendation 22) and US FinCEN rules. Thresholds and penalties are set by regulators, so we attribute them rather than invent figures. If you are choosing tooling to support the program, start with our guide to the best KYC providers for iGaming, and read our breakdown of KYC AML software for the tooling layer.
What an AML compliance program is (and is not)
The most common mistake new operators make is to equate Anti-money laundering (AML) compliance with buying a KYC product. A vendor tool automates checks, but it does not set your risk appetite, write your policies, file your reports, or stand up in front of a regulator. The program is the governance around those tools: who is accountable, what the rules are, how risk is assessed, how suspicion is escalated, and how all of it is evidenced. AML is also paired with Combating the financing of terrorism (CFT), so the same controls serve both goals.
FATF, the global standard-setter, frames this through a Risk-based approach: you do not treat every customer the same, you direct more scrutiny where the money-laundering risk is higher. That principle runs through every pillar below. Software is how you execute the controls; the program is why, when and to what standard. A useful test is to ask what you would hand a regulator or auditor who asked to see your AML arrangements. The answer should be a set of documents - a risk assessment, policies, appointment records, monitoring rules, filed reports, audit findings and training logs - not a vendor dashboard login. If the only thing you can point to is a tool, you have bought a capability, not built a program.
The pillars of a casino AML program
Different frameworks count the pillars slightly differently - the US BSA tradition often cites five, while a full online-casino program is clearer broken into eight working parts. Each needs an owner and, crucially, evidence that an auditor or regulator can inspect.
Risk assessment
Everything starts here: a documented assessment of the money-laundering and terrorist-financing risks the business faces, by customer type, product, payment method, delivery channel and geography. The assessment drives where CDD stops and EDD begins. For an online casino, the risk factors that matter most tend to be anonymity of onboarding, the speed and reversibility of payment methods, cross-border play, and products that allow rapid movement of large sums. A good assessment rates each factor, records the rationale, and sets the control response - which is what makes the rest of the program defensible rather than arbitrary.
Policies and internal controls
Written policies and procedures translate the risk assessment into day-to-day rules - onboarding steps, thresholds for escalation, payment controls, and record retention. The US BSA requires a system of internal controls as a core element.
MLRO / compliance officer
A designated individual (or team) is accountable for day-to-day AML compliance - the Money Laundering Reporting Officer (MLRO). Under 31 CFR 1021.210, a casino must designate an individual or individuals responsible for day-to-day compliance; the MLRO owns the reporting decision.
CDD and EDD
Customer Due Diligence (CDD) identifies and verifies the customer and profiles their expected activity; Enhanced Due Diligence (EDD) applies deeper checks to higher-risk cases - including a Politically Exposed Person (PEP) and Sanctions screening hits, high-value play, or high-risk jurisdictions. EDD typically adds source-of-funds and source-of-wealth checks, closer ongoing monitoring, and senior sign-off before a relationship continues. The trigger for moving from CDD to EDD should come straight from the risk assessment, not from an individual analyst's judgement alone, so that the escalation is consistent and evidenced.
Transaction monitoring
Transaction monitoring watches deposits, wagering, withdrawals and payment patterns for signs of layering, structuring or other suspicious behaviour, generating alerts for human review.
SAR/STR and threshold reporting
When monitoring or staff identify suspicion, the MLRO files a Suspicious Activity Report (SAR/STR) with the relevant financial intelligence unit. US gaming programs also use threshold reports such as the Currency Transaction Report (CTR) and Negotiable Instrument Log where applicable; the exact dollar thresholds are set by the regulator and should be confirmed at the source, not assumed.
Recordkeeping
The program must retain customer records, verification evidence, monitoring alerts and reports for the periods the regulator requires - this is what makes the other pillars auditable.
Independent testing and training
Independent testing - an Independent audit of the program by someone not running it - checks that controls actually work, while ongoing staff training keeps the culture of compliance current. The US BSA explicitly requires both independent testing and training.
| Pillar | What it means for an online casino | Owner | Evidence for audit |
|---|---|---|---|
| Risk assessment | Documented ML/TF risk by customer, product, payment, geography | MLRO / compliance | Dated risk assessment, refresh log |
| Policies & internal controls | Written onboarding, escalation and payment rules | Compliance / operations | Policy documents, version history |
| MLRO / compliance officer | Named person accountable day to day | Board appointment | Appointment record, reporting lines |
| CDD and EDD | Identify/verify customers; deeper checks for higher risk | Onboarding / compliance | Verification records, EDD files |
| Transaction monitoring | Detect suspicious deposit/wager/withdrawal patterns | Compliance / analytics | Alert logs, tuning records |
| SAR/STR & threshold reporting | File suspicion and threshold reports to the regulator | MLRO | Filed reports, decision rationale |
| Recordkeeping | Retain records for the required period | Compliance / IT | Retained records, retention policy |
| Independent testing & training | Independent audit plus ongoing staff training | Internal audit / external | Audit reports, training logs |
How the pillars map to FATF and US BSA
FATF Recommendation 18 and Recommendation 22
FATF Recommendation 18 requires financial institutions to implement an AML/CFT programme including internal controls, and FATF promotes the Risk-based approach throughout. FATF Recommendation 22 brings casinos in as designated non-financial businesses and professions (DNFBPs): casinos must apply CDD and recordkeeping when a customer carries out a financial transaction at or above the FATF-designated threshold of USD/EUR 3,000. That threshold is a FATF standard; individual jurisdictions may set their own.
US Bank Secrecy Act (FinCEN)
Under the US Bank Secrecy Act, casinos and card clubs above a size threshold are treated as financial institutions administered by FinCEN. The regulation at 31 CFR 1021.210 requires each casino to maintain a written, risk-based compliance program with: a system of internal controls; internal or external independent testing; a designated individual (or individuals) responsible for day-to-day compliance; ongoing training; and procedures for using all available information to fulfil recordkeeping and reporting obligations.
UK/EU/Canada note
Other regimes layer on their own rules: the UK Gambling Commission (UKGC) sets AML obligations through its licence conditions, EU AML directives bind European operators, and in Canada regulators such as AGCO oversee Ontario operators. The pillars stay the same; the specific thresholds, report formats and supervisors change by jurisdiction.
| Pillar | FATF Recommendation | US BSA requirement (31 CFR 1021.210) | Notes |
|---|---|---|---|
| Policies & internal controls | Rec. 18 (programme, internal controls) | System of internal controls | Core of every program |
| MLRO | Rec. 18 (compliance management) | Designated day-to-day compliance person | Named, accountable |
| CDD / EDD | Rec. 22 (casino CDD at USD/EUR 3,000) | Procedures using available information | Risk-based depth |
| Independent testing | Rec. 18 | Internal/external independent testing | Not self-reviewed |
| Training | Rec. 18 | Ongoing training | Culture of compliance |
You can read the standards yourself in the FATF Recommendations; always confirm current thresholds and report formats with your own regulator before go-live.
Risk-based approach and keeping the risk assessment current
A Risk-based approach means the program is never static. Higher-risk products (for example certain fast, high-stakes play), higher-risk payment methods, and higher-risk jurisdictions drive more EDD and tighter monitoring thresholds, while lower-risk segments get proportionate checks. The risk assessment should be refreshed on a defined cadence and whenever something material changes - a new market, a new payment rail, a new product, or a regulatory update. A stale risk assessment is one of the first things an auditor will flag.
Transaction monitoring in practice
In iGaming, Transaction monitoring is where theory meets reality. Rule-based systems alone tend to generate high volumes of false positives and can still miss risk-specific patterns, so monitoring must be tuned to the operator's own risk profile rather than left on vendor defaults. Good practice is a triage workflow: automated alerts, human review, escalation to the MLRO, and - where suspicion is confirmed - a SAR/STR, all without tipping off the customer. Alert thresholds, scenarios and tuning decisions should themselves be documented, because the quality of monitoring is judged on outcomes and evidence, not on alert volume. It is worth stressing that a very high alert rate is not proof of diligence - it can simply mean poorly tuned rules that bury genuine risk under noise and exhaust the review team. Equally, a very low alert rate may mean the scenarios are not calibrated to the business. The regulator's interest is whether the monitoring is reasonably designed to catch the risks the assessment identified, and whether confirmed suspicion is escalated and reported promptly.
Where responsible gambling and age checks fit
AML does not sit apart from player protection. Age verification protects minors and is a licence condition in regulated markets; self-exclusion data must feed onboarding and payment controls; and affordability and source-of-funds checks overlap directly with EDD. In practice the same identity and CDD pipeline that supports AML also supports responsible gambling, which is why document-level identity work matters - see our guide to KYC ID verification documents. A defensible program treats AML, sanctions, and responsible-gambling obligations as one connected control set, never as reasons to weaken or delay checks.
Put together, these pillars are what separate a genuine AML compliance program from a shopping list of tools. Align each pillar to FATF and your local regulator, evidence it for audit, and keep the risk assessment alive - then choose software to execute it, not to replace it.
Frequently asked questions
What is an AML compliance program for an online casino?
It is the governance framework an operator uses to detect, prevent and report money laundering - a documented, risk-based set of controls covering risk assessment, policies, an MLRO, CDD/EDD, transaction monitoring, reporting, recordkeeping, and independent testing. It is not a single piece of software.
What are the pillars of a casino AML program?
Risk assessment; policies and internal controls; a designated MLRO; CDD and EDD; transaction monitoring; SAR/STR and threshold reporting; recordkeeping; and independent testing with training. These map to FATF Recommendation 18 and 22 and the US BSA (31 CFR 1021.210).
Who is the MLRO and what do they do?
The Money Laundering Reporting Officer is the designated individual responsible for day-to-day AML compliance. Under 31 CFR 1021.210 a casino must name such a person; the MLRO owns escalation and the decision to file a SAR/STR.
What is the difference between CDD and EDD?
Customer Due Diligence (CDD) identifies and verifies every customer and profiles expected activity. Enhanced Due Diligence (EDD) applies deeper checks to higher-risk cases - such as PEPs, sanctions hits, high-value play or high-risk jurisdictions.
How does an AML program relate to KYC software?
KYC software executes checks like identity verification and screening, but it is only one input to the program. The program sets the risk appetite, policies, reporting and audit around the tools. Buying software is not the same as having an AML program.
Compare independently vetted sites.
See reviews18+ only. Gambling can be addictive — please play responsibly and only bet what you can afford to lose. If gambling is affecting you or someone you know, contact a local support service. This content is informational and never a guarantee of winnings.
Written and reviewed by the iGaming Expert Hub editorial team. Facts checked against primary sources; see the reference above.