
How Do iGaming Operators Pass AML Audits?
- NUR Legal

- 4 days ago
- 6 min read
An AML audit rarely fails because an operator has no written policy. It fails because the policy says one thing, the platform does another, and nobody can produce reliable evidence to explain the gap. How do iGaming operators pass AML audits? By treating AML as an operating system that can be evidenced player by player, alert by alert and decision by decision.
For online casinos, sportsbooks and betting platforms, this is commercially critical. An adverse audit finding can delay a licence application or renewal, trigger remediation costs, restrict payment relationships and put senior management under direct regulatory scrutiny. The objective is not to create the largest compliance manual. It is to show that the business understands its risks, applies proportionate controls and can prove those controls work.
How iGaming Operators Pass AML Audits: Start With Evidence
Auditors test reality, not intentions. They will want to see how the operator identified its money laundering and terrorist financing risks, how those risks translate into player controls, and what happens when a control identifies an exception.
A defensible AML framework begins with a documented business-wide risk assessment. This should reflect the actual product mix, markets served, payment methods, customer profile, transaction volumes, distribution model and exposure to higher-risk jurisdictions. A sportsbook accepting low-value card deposits presents a different risk profile from a casino offering high deposit limits, crypto payment options, VIP management and rapid withdrawals.
The assessment must lead somewhere. If crypto deposits, prepaid instruments, third-party payments or high-risk countries are identified as elevated risks, the audit trail should show enhanced controls for those areas. Generic language copied from another operator is easy for an auditor to identify and difficult to defend.
The same principle applies to policies and procedures. A policy may require source of funds checks at a defined risk threshold, but an auditor will test whether the threshold is configured correctly, whether cases were opened on time, whether documents were assessed by trained staff and whether unresolved concerns led to restrictions or escalation. The evidence must be consistent across the policy, platform settings, case-management records and management reporting.
Build a Control Framework Around the Player Journey
AML controls should follow the player journey rather than sit in separate compliance documents. From registration to withdrawal, each stage creates a different risk and a different evidential requirement.
Onboarding and verification
The operator needs a clear customer due diligence process that verifies identity before the point required by the relevant licence, local law or risk trigger. This includes a documented approach to age verification, identity validation, duplicate account detection, politically exposed person screening, sanctions screening and adverse media checks where appropriate.
Auditors will look beyond a successful verification result. They may examine whether the identity provider is properly assessed, whether verification failures prevent gambling or withdrawals as intended, and whether manual overrides are authorised and recorded. If a customer was accepted despite a mismatch or incomplete document, the rationale needs to be visible.
A common weakness is treating customer due diligence as a one-off event. Player data changes, sanctions lists change and a previously low-risk customer can become high risk through their behaviour. Operators should set review cycles that reflect risk, with event-driven reviews for material changes in activity, payment behaviour or customer profile.
Deposits, gameplay and withdrawals
Transaction monitoring should be calibrated to gambling-specific behaviour. A high number of deposits alone may not indicate money laundering. However, repeated deposits followed by minimal gameplay and withdrawal, use of multiple payment instruments, rapid movement between accounts, unusual patterns of bonus use, or deposits that do not match the customer’s known profile can justify review.
The system must be able to connect related activity. A player may deposit through several cards, e-wallets or crypto wallets, while a linked account withdraws to a different destination. Monitoring that treats every event in isolation creates avoidable blind spots.
Alert thresholds should not be fixed indefinitely. They need periodic review against the operator’s risk assessment, actual alert volumes, confirmed suspicious activity and false-positive rates. Excessively low thresholds can overwhelm the team and cause genuine risk to be missed. Thresholds set too high can leave significant activity unreviewed. The right calibration depends on the business model, licence conditions and risk appetite, but the reasoning must be documented.
Enhanced due diligence and source of funds
Enhanced due diligence is where many operators lose control of their files. Asking for bank statements is not the same as assessing them. The file should explain why the customer triggered enhanced review, what evidence was obtained, how the evidence supports the customer’s financial profile, and whether the activity remains plausible after review.
Source of funds concerns the money used for gambling. Source of wealth goes further, examining how the customer accumulated their overall wealth. The distinction matters, particularly for VIP customers or players with high-value, repeated activity. The required depth of review depends on risk. A regulator will expect the operator to apply judgement, not merely collect documents.
Where the customer does not provide satisfactory evidence, the procedure should be clear: apply limits, suspend activity, refuse withdrawal only where legally permissible and properly assessed, consider a suspicious activity report, and avoid tipping off the customer. Every decision should have an owner, timestamp and stated rationale.
Governance Must Be Visible From the Board to the Front Line
An AML audit tests governance as much as operations. The business needs a named money laundering reporting officer or equivalent responsible officer, with sufficient authority, access to information and independence from commercial pressure. A title alone is insufficient if the officer cannot challenge VIP decisions or obtain data from product and payments teams.
Senior management should receive meaningful AML reporting. Useful reports show high-risk customer volumes, overdue reviews, alert ageing, enhanced due diligence outcomes, suspicious activity reports, sanctions hits, quality assurance results, training completion and material control failures. Reporting that only records the number of alerts closed tells decision-makers very little about exposure.
The board or governing body should be able to demonstrate oversight through meeting minutes, risk acceptance decisions, approval of policies and documented follow-up on material issues. This is especially relevant where commercial teams manage high-value players. Auditors will examine whether revenue considerations have overridden compliance decisions and whether escalation routes are used in practice.
Training should also be role-specific. Customer support, payments staff, VIP managers, fraud teams and compliance analysts encounter different warning signs. A generic annual slide deck will not demonstrate that a VIP manager understands when an apparently valuable player presents an AML concern. Keep attendance records, test understanding and refresh training when processes or risks change.
Control Your Outsourcing and Technology Dependencies
Most iGaming operators rely on third parties for KYC, sanctions screening, transaction monitoring, payments, game aggregation, hosting and customer support. Outsourcing does not outsource regulatory accountability.
Maintain due diligence files for critical providers, including their capabilities, security arrangements, service levels, data handling and escalation processes. Contracts should define responsibilities, audit rights, access to records, incident notification and exit arrangements. Where a provider supports screening or monitoring, test its configuration and data flows rather than relying solely on vendor assurances.
Technology changes require particular discipline. A new payment method, CRM integration, game vertical or market launch can alter the AML risk profile overnight. Compliance should be involved before deployment, with documented testing to confirm that customer risk ratings, screening, transaction data and case triggers continue to operate correctly.
Prepare for the Audit Before the Notice Arrives
The most efficient audit preparation is continuous. Keep an indexed evidence repository with current policies, risk assessments, governance minutes, training records, provider due diligence, system configuration records, sample customer files, alert investigations, suspicious activity escalation logs and internal audit reports.
Before a formal review, conduct a focused mock audit. Select files across low, medium and high-risk customers, including VIPs, rejected applicants, customers subject to enhanced due diligence and accounts with unusual withdrawals. Trace each file from onboarding through monitoring and closure. If the story cannot be understood without asking several teams for missing records, the process is not audit-ready.
Internal quality assurance should test not just whether analysts closed alerts, but whether they reached sound conclusions. Review the quality of narratives, supporting evidence, escalation decisions and adherence to service-level expectations. Repeated errors should result in documented remediation, retraining or system changes.
The Failures Auditors See Most Often
The recurring problems are usually operational: risk assessments that have not been updated after market or product changes; incomplete customer files; screening records that cannot show which lists were checked; monitoring alerts closed with vague notes; unmanaged backlogs; and VIP exceptions approved without adequate compliance challenge.
Another serious failure is a disconnect between AML and safer gambling teams. These functions have different legal purposes, but both may identify affordability concerns, unusual behaviour or patterns requiring escalation. Clear information-sharing rules can improve detection while respecting data protection and confidentiality obligations.
Passing an audit does not mean eliminating every exception. It means identifying exceptions promptly, making defensible decisions and correcting weaknesses before they become systemic. For operators entering new markets, changing payment flows or preparing for licensing, an independent legal and compliance gap assessment can turn an uncertain review into a controlled implementation plan. The strongest position is simple: when an auditor asks for proof, your team can produce it quickly and explain why it supports the decision made.



Comments