
AML compliance sits at the front line of payments for iGaming. Every deposit and withdrawal a payment provider processes is a transaction a regulator may later ask about, and operators increasingly judge suppliers by how well their controls can be evidenced. This checklist sets out what B2B payment providers should have in place in 2026, based on FATF standards, the EU anti-money laundering framework and UK Gambling Commission (UKGC) expectations. It is a practical starting point, not legal advice, so confirm your obligations with counsel in each jurisdiction where you are licensed or operate.
Why AML obligations reach payment providers
Operators hold the primary gambling licence and the primary AML duty, but they depend on payment partners for transaction data and for the controls behind it. The UKGC expects operators to understand the services their payment providers offer, and it requires operators to review their AML risk assessment when they introduce a new payment method. Where crypto-assets are involved, the Commission expects the operator to explain the payment method, the provider and how the risks were assessed. Suppliers that can document their controls clearly are therefore easier to onboard.
The global baseline comes from the Financial Action Task Force (FATF), whose recommendations cover a risk-based approach, customer due diligence, record keeping and suspicious transaction reporting. In the EU, the sixth Anti-Money Laundering Directive (AMLD6) was adopted in June 2024. Member states have three years to implement it. It widens the definition of money laundering offences and makes legal entities, not only individuals, liable for failures.
The checklist
1. Maintain a business-wide risk assessment
- Document the money laundering and terrorist financing risks across your payment methods, corridors, customer types and markets.
- Re-run the assessment whenever you add a payment method, especially crypto, and whenever you enter a new jurisdiction.
- Record the reasoning behind each risk rating, not only the rating itself.
2. Apply customer due diligence and screening
- Verify the identity of merchant and operator clients at onboarding, and verify beneficial owners where the client is a legal entity.
- Apply enhanced due diligence to politically exposed persons (PEPs), high-risk jurisdictions and unusual corporate structures.
- Screen against EU, UN and OFAC sanctions lists and PEP databases at onboarding, and re-screen on an ongoing basis.
- Under the EU framework, gambling service providers must apply customer due diligence to transactions of €2,000 or more. Build that threshold into the payment flow so it is enforced automatically rather than checked by hand.
3. Monitor transactions for mule and layering patterns
- Set alert thresholds by payment method and by counterparty, not only by amount.
- Flag rapid in-and-out movement of funds, many senders paying into one account, and deposits split to stay below thresholds.
- Watch for new accounts making high-value deposits soon after opening.
- Review alert outcomes regularly so that rules are tuned, and document every decision to close an alert.
4. Collect source of funds on a risk basis
- Request source of funds information in proportion to risk. The UKGC warns against treating it as a tick-box step.
- Do not rely on customer self-declarations or open-source information alone when assessing money laundering risk. The Commission has named this as a common failure.
- Train staff to review documents, spot red flags and record their decisions and the evidence behind them.
- Treat AI-altered documents as a live risk. The UKGC has reported more customers using artificial intelligence to forge identity and source of funds evidence, so check documents against independent sources where you can.
5. Add crypto-specific controls
- Map every supported chain and asset, and every exchange, custodian or on-ramp you rely on.
- Pass the originator and beneficiary information that FATF Recommendation 16 requires for virtual asset transfers, where it applies in your jurisdiction.
- Screen wallet addresses against sanctions lists and illicit-activity data before funds move.
- Make sure operator clients receive a clear description of the crypto service, as the UKGC expects.
6. Report suspicious activity and keep records
- Set a documented escalation path from first alert to suspicious activity report (SAR), with clear deadlines at each step.
- File reports with the relevant financial intelligence unit (FIU) in each jurisdiction where you are obliged to do so.
- Keep customer due diligence and transaction records for the period your regulator sets. Five years after the end of the relationship is a common standard.
7. Assign ownership and test the programme
- Appoint a money laundering reporting officer (MLRO) with real authority and direct access to the board.
- Run role-specific AML training at least once a year, and keep attendance and assessment records.
- Commission an independent review of the programme periodically, and act on its findings with a tracked action plan.
Common mistakes
- Treating AML as a one-off onboarding task. Regulators expect ongoing monitoring and periodic re-screening.
- Relying on self-declared source of funds. Declarations need independent corroboration when risk is elevated.
- Assuming the operator's controls cover your risk. Payment providers carry their own obligations and must evidence them.
- Launching a new payment method without updating the risk assessment. Crypto is the most common trigger for this gap.
- Keeping weak records. Supervisors judge decisions by what was written down at the time, so document reasoning as you go.
How to evidence your programme to operators
Operators rarely ask for a policy document alone. They want proof that controls run in practice. Prepare a short evidence pack that includes a summary of the current risk assessment, a description of screening and monitoring rules with their last review date, anonymised examples of alerts and how they were closed, and the training record for staff who handle alerts. Refresh the pack at least once a year so it reflects what your team actually does.
Keep the pack short. A two-page summary with links to underlying records is easier to review than a long manual, and it lets a due diligence team reach a decision faster.
What to do this quarter
Map each control above against the licences you hold and the jurisdictions you serve. Then ask your operator clients which AML evidence they need from you, and prepare that pack before a due diligence review asks for it. A short gap analysis now is cheaper than a remediation programme after a regulator's review.
FAQ
Do payment providers need their own AML registration?
It depends on the jurisdiction and the services you provide. Many payment providers are regulated as payment or e-money institutions, and crypto services may fall under separate virtual asset rules. Confirm your position with local counsel before you launch in a new market.
How often should the AML risk assessment be updated?
At least once a year, and immediately after any material change. That includes a new payment method, a new market, a new product or a significant change in customer profile. The UKGC expects a review when a new payment method is introduced, so treat that as a minimum trigger.
What is the biggest AML risk in iGaming payments?
Regulators most often point to mule accounts and to crypto used to layer funds. Both can move money quickly across accounts and borders, which is why monitoring by payment method and counterparty matters as much as monitoring by amount.
Source: iGaming Pulse Editorial Desk

Illia Lisovskyy
Senior Editor
Member of the iGaming Pulse editorial team. Covering industry news, analysis, and B2B developments across the global iGaming sector.


