Home › AML compliance › KYC AML Software for Casinos: Unified or Separate?

KYC AML Software for Casinos: Unified or Separate?

IE By iGaming Expert Hub Editorial· Updated 2026-10-05·8 min read

Key takeaways

KYC AML software splits into two jobs: KYC software verifies and screens a player at onboarding, while AML software watches behaviour over time, aggregates transactions, raises alerts and supports reports such as suspicious transaction reports. A casino can buy both from one vendor or two, provided they share one player record and one audit trail.

This guide is for compliance, product and payments leads at online casinos and sportsbooks. It turns Canada's published casino reporting triggers into software requirements, compares unified, separate and hybrid stacks, explains what the shared record must contain, and ends with a decision matrix and buyer questions. The comparisons are our editorial analysis, not vendor data, and nothing here is legal advice.

KYC AML software: where KYC ends and AML begins

Know your customer (KYC) and anti-money laundering (AML) overlap, which is why vendors blur them. KYC software answers who the player is: it captures data and documents, runs identity checks and screens against sanctions lists and politically exposed person (PEP) data. AML software answers what the player is doing: it monitors activity, flags unusual patterns, manages the investigation and supports the filing of reports. Customer due diligence (CDD) is the thread between them, because the risk rating set at onboarding decides how closely the monitoring side watches.

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) lists the building blocks for casinos: a compliance program, KYC, record keeping, the travel rule, business relationship and ongoing monitoring requirements. A FINTRAC compliance program has a compliance officer, written and up-to-date policies and procedures, a documented risk assessment, a written ongoing training program and plan, and an effectiveness review at least every two years. Software supports those elements; it does not replace the officer, the policies or the review.

Software is where a risk-based approach becomes rules and thresholds; the Financial Action Task Force's recommendations are the usual international reference for that approach. If you are comparing vendors, start from our guide to how to compare KYC and AML screening providers, which covers vendor categories, benchmarks and an RFP checklist. For how a screening programme works day to day, see KYC screening for iGaming; this page deliberately does not repeat it.

FINTRAC reporting triggers your AML software has to support

A caution before the table. FINTRAC's casino sector is defined in physical terms: a casino conducts gaming with more than 50 slot machines or similar devices at a fixed place of business, or runs lottery schemes. These are FINTRAC's casino-sector reporting triggers under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and we use them as the clearest published gambling AML example. Whether a particular online operator is a PCMLTFA reporting entity depends on its structure, so check with counsel before assuming you file these reports. Other regulators have their own rules.

The rules below come from FINTRAC's casino sector page and its casino disbursement report guidance. The right-hand column is our editorial reading of what software would need to do.

Trigger or reportRuleWhat the software must do
Suspicious transaction report (STR)Submit as soon as practicableTurn alerts into cases, record the reviewer's reasoning and keep timestamps so the path from alert to report can be shown.
Casino disbursement report (CDR)A single disbursement of $10,000 or more, or two or more disbursements totalling $10,000 within a consecutive 24-hour period for the same person; submit within 15 calendar days after the day of the disbursementAggregate disbursements per person on a rolling 24-hour basis and run a deadline timer from the day of disbursement.
Large cash transaction report (LCTR)The 24-hour rule appliesAggregate qualifying transactions per person across the period; confirm thresholds in FINTRAC's own guidance before configuring.
Large virtual currency and electronic funds transfer reportsThe 24-hour rule appliesTag transaction types correctly and apply the same per-person aggregation; confirm thresholds in FINTRAC's guidance.
Listed person or entity property reportReport immediatelyRoute a confirmed screening hit to an urgent queue with a named owner, not the normal alert backlog.
Sanctions evasion reportListed among casino obligationsLet reviewers escalate a case to this report type and keep supporting evidence together.
Ongoing monitoring and business relationshipRequired under the compliance programRe-screen players on a schedule and on trigger events, and update the risk rating.

Three lessons follow for buying. Deadlines differ: STRs turn on timeliness, CDRs have a 15-calendar-day window and listed-person property is immediate, so one generic alert queue does not fit. The 24-hour rule is an aggregation problem across transactions, a data-model question before it is a rules question. And a tool that detects and supports is not the same as one that files: ask each vendor where its responsibility ends.

Unified, separate or hybrid: how the stacks compare

Three architectures are common. A unified platform covers verification, screening, monitoring and cases in one product. A separate stack uses a KYC vendor and a different AML or transaction-monitoring vendor, joined by an application programming interface (API). A hybrid uses one vendor for identity and screening, with transaction monitoring and case management built in-house or bought separately. The table is editorial analysis and contains no performance claims.

OptionData flowAudit trailStrengthsFailure points
Unified platformOne vendor holds identity, screening results and activity dataOne system of record by designFewer integrations, one contract, one support lineWeakest module becomes your weakest control; harder to leave; transaction monitoring may be partner-provided
Separate best-of-breedKYC results pass to the monitoring tool through an API or file feedTwo logs that you must reconcile or consolidatePick the strongest tool for each job; swap one without the otherMismatched player IDs, missed events and delayed webhooks; two sets of retention rules
HybridIdentity and screening from one vendor; monitoring and cases elsewhere or in-houseYour own case system must hold the master recordControl over alert logic and workflowEngineering cost; you own the integration and its upkeep

What breaks in each setup

The unified failure is dependence: if the vendor's monitoring is thinner than its onboarding, you find out after go-live. Vendor pages commonly list screening, case management, risk scoring, identity verification integration and transaction monitoring, but module lists describe the product catalogue, not how deep each module goes, and some vendors supply monitoring through a partner. Test depth in a pilot with your own scenarios.

The separate and hybrid failures are about joins. When player identifiers differ between systems, a watchlist hit cannot be tied to the player's deposits. When a webhook arrives late, the monitoring system scores a player on an outdated verification status. Plan identifiers, retries and reconciliation before choosing vendors. Our guide to KYC API integration for iGaming covers webhooks and retention detail.

One player record and one audit trail

Whatever you buy, keep one record per player and one place where the story of that player can be read end to end. The Alcohol and Gaming Commission of Ontario (AGCO) sets two relevant expectations in its Registrar's Standards for Internet Gaming: standard 3.04 requires player information to be collected and validated before an account is created, and standard 3.10 requires an auditable trail of events for account creation, activation, deactivation and account changes.

In practice the shared record should hold:

Decide up front which system is the system of record, and make every other tool a contributor to it. Then test the export: ask a vendor to produce one complete player history, in a form you could hand to a regulator, from sample data in the sandbox.

Which setup fits which operator

There is no universal answer, and the profile below is a starting point to test, not a recommendation of any vendor.

Operator profileSuggested starting pointWhyWatch-out
Single-market small operatorUnified platform, or hybrid with a managed review teamFew staff; one contract and one record keep the compliance workload manageableConfirm the monitoring module is native, not a partner add-on, and test its depth.
Multi-licence operatorHybrid or separate with a clear system of recordRules, thresholds and retention differ by jurisdictionKeep one player ID across markets; watch for conflicting retention periods.
High-volume operator with an in-house data teamSeparate or hybridThe team can tune monitoring logic and own the integrationDo not underestimate maintenance of the integration and the rules.
Operator outsourcing manual reviewUnified or hybrid with the review partner working inside your case systemThe partner needs access to your records without exporting themDefine who decides on reports and who holds the audit trail. See KYC managed services.

Questions to ask before you buy

  1. Which reports does the software support, and where does its role end: detect, draft, or file?
  2. Does it run deadline timers, such as the 15-calendar-day window for casino disbursement reports, and the urgent path for listed-person property?
  3. How does it handle 24-hour aggregation across payment methods and transaction types?
  4. Can you export a complete case, including notes, decisions and timestamps?
  5. Is the transaction monitoring native or provided by a partner, and who is responsible for it contractually?
  6. What is the data licence for screening lists and PEP data, and does it cover commercial, automated use?
  7. What are the retention rules and can they differ by jurisdiction?
  8. Which APIs and webhooks exist, and is there a sandbox for testing?
  9. How does politically exposed person screening work after signup, and how are new hits routed?
  10. What are the support SLAs, and how do you export your data if you leave?

Take the answers into the RFP checklist in our operator guide, and compare KYC and AML screening providers against the same criteria.

Responsible gambling: online gambling is for adults only: 19+ in Ontario and 18+ in many other jurisdictions, depending on local law. Compliance controls exist to protect players as well as operators. If gambling stops being fun, contact your local support service and use deposit limits, time-outs and self-exclusion tools.

Frequently asked questions

Is KYC software the same as AML software?

No. KYC software verifies and screens a player at onboarding. AML software monitors activity over time, aggregates transactions, raises alerts, manages investigations and supports reports. Some vendors sell both in one platform, and some supply transaction monitoring through a partner.

Do online casinos need transaction monitoring software?

It depends on the regulator and the operator structure. FINTRAC lists ongoing monitoring among casino obligations, but whether an online operator is a PCMLTFA reporting entity depends on its structure. Check with counsel, and note that licensing conditions elsewhere may also require monitoring.

What is the 24-hour rule for casino reports?

FINTRAC applies a 24-hour rule to several casino reports. For the casino disbursement report, two or more disbursements totalling $10,000 within a consecutive 24-hour period for the same person count together, and the report is due within 15 calendar days after the day of the disbursement.

Is a unified KYC and AML platform better than separate tools?

Neither is better in every case. Unified platforms mean fewer integrations and one record but tie you to one vendor. Separate or hybrid stacks let you choose the strongest tool for each job but need careful identifier matching and a single audit trail.

What should AML software record for a regulator?

Verification status, risk rating and its reasons, screening hits and who cleared them, deposit and withdrawal events, case notes and report references. AGCO standard 3.10 expects an auditable trail of account creation, activation, deactivation and account changes.

Authoritative referenceBeGambleAware — responsible gambling ↗

Compare independently vetted sites.

See reviews

18+ only. Gambling can be addictive — please play responsibly and only bet what you can afford to lose. If gambling is affecting you or someone you know, contact a local support service. This content is informational and never a guarantee of winnings.

Written and reviewed by the iGaming Expert Hub editorial team. Facts checked against primary sources; see the reference above.

← All articles