When the Same Deposit Pattern Is Both a Money Laundering Red Flag and a Harm Indicator: Resolving the AML–RG Crossover
When a player's deposit pattern triggers both AML and responsible gambling alerts, who acts first and on what authority? This guide maps the crossover obligations across UKGC, MGA, AGCO, and AGLC.
A player deposits CAD $4,000 at 11 pm, loses it within 40 minutes, then deposits again at 2 am. By morning, the AML team flags it as structuring-adjacent behaviour. That afternoon, the responsible gambling team receives an alert that the same account has exceeded the operator’s harm-detection threshold. Each team opens a file. Neither knows the other has done so. The player keeps playing.
This is not a hypothetical scenario. It is the operational reality documented in enforcement decisions by the UK Gambling Commission, the Alcohol and Gaming Commission of Ontario, and FINTRAC, all issued within the last 18 months. The regulatory frameworks governing iGaming require operators to maintain anti-money laundering controls and responsible gambling protections as parallel obligations, but the data inputs for both functions (deposit frequency, net spend, session timing, source-of-funds status) are substantially identical. Where compliance teams are siloed by function, regulators have found failures on both sides simultaneously. Operators facing scrutiny have not been permitted to plead that one obligation was being addressed as a defence against failing the other.
Why Deposit Patterns Sit at the Intersection
Deposit behaviour is the single most information-rich signal available to both AML analysts and responsible gambling teams. For AML purposes, patterns such as rapid cycling of funds, deposits immediately preceding large withdrawals, multiple small deposits timed to stay below threshold, and an inability to demonstrate legitimate source of funds all constitute recognised money laundering typologies. According to the Financial Action Task Force, online casinos and sports betting platforms “are considered to be particularly exposed to money laundering risks,” with automated betting patterns and structuring of deposits identified as specific risk indicators.
For responsible gambling purposes, the same deposit signals carry a different but overlapping meaning. Rapid deposit sequences, deposits made late at night or in the early hours, escalating bet sizes following losses, and a player’s apparent inability to stop once credit or depositable funds are available are all recognised markers of disordered gambling. The UKGC’s customer interaction guidance treats these as triggers for the identify-act-evaluate cycle under Social Responsibility Code Provision 3.4.3.
The data sets are not merely similar, they are often drawn from the same transaction ledger. The operational problem is that two separate teams, governed by different regulatory frameworks and subject to different confidentiality obligations, may be analysing the same rows in the same database without sharing their conclusions.
What UKGC Requires Under LCCP 3.4.3 and 3.4.4
The UKGC has moved further than any other major regulator in explicitly bridging the two obligations in a single licence condition. SRCP 3.4.3, which applies to all remote licences except those specifically excluded, requires licensees to implement effective customer interaction systems and processes that minimise the risk of customers experiencing harms associated with gambling. The provision mandates that systems embed the three elements of customer interaction: identify, act, and evaluate. It came into full force on 31 October 2023 for the identification requirements.
Licensees must implement effective customer interaction systems and processes in a way which minimises the risk of customers experiencing harms associated with gambling. These systems and processes must embed the three elements of customer interaction, identify, act and evaluate, and which reflect that customer interaction is an ongoing process.
Source: UK Gambling Commission, Licence Conditions and Codes of Practice, Social Responsibility Code Provision 3.4.3, in force from 31 October 2023.
SRCP 3.4.4 introduces the financial vulnerability check obligation. From 28 February 2025, the relevant threshold is where a customer’s deposits minus withdrawals exceeds £150 in a rolling 30-day period. Between 30 August 2024 and 27 February 2025, the threshold was £500. The Commission has explicitly stated that information obtained through financial vulnerability checks and financial risk assessments must be used within the licensee’s overall approach to identifying risk of harm and taking action to prevent gambling harm. The LCCP requires licensees to have policies and procedures on whether decisions on proportionate action should be taken manually, in a fully automated manner, or through a combination of both, and on the circumstances where immediate action is necessary to limit harm where significant risk is identified.
The financial risk assessment (FRA) framework uses credit reference agency data to flag customers at higher financial risk. Tim Miller, the UKGC’s Executive Director, confirmed at the Ethical Gambling Forum that the checks “will not even attempt to make an assessment of what each customer can afford to gamble,” distinguishing FRAs from the source-of-funds requests used in AML due diligence. SRCP 3.4.4 data is harm-identification data, not AML data, but because both assessments draw on a customer’s financial profile, the compliance team performing AML source-of-funds checks and the team performing FRAs will inevitably be looking at the same customer from different angles. Regulators expect those angles to be coordinated.
According to regulatory enforcement findings, settlement actions have resulted from coordination failures in this space. AML failures such as inadequate source-of-funds assessments and delays in filing Suspicious Activity Reports have been paired with social responsibility failures including failure to detect problem gambling patterns. Regulators have treated both sets of failures as arising from the same underlying cause: systems that were inadequate to identify risk quickly.
MGA: The FIAU Split and Audit Expectations
In Malta, AML supervision is divided between the Malta Gaming Authority and the Financial Intelligence Analysis Unit (FIAU). The MGA holds primary supervisory responsibility for player protection and responsible gaming, while the FIAU administers AML obligations under the Prevention of Money Laundering Act and its associated implementing procedures. Licensees report to both. This split creates a structural information gap at the supervisory level that operators cannot resolve by managing one relationship well, they must manage both.
The MGA’s Compliance Audit Manual (MGA/G/001) makes the monitoring expectations concrete. In the AML section, auditors check whether licensees request source of wealth and source of funds for high-risk profile players (section 6.17.12) and whether enhanced due diligence is carried out on Politically Exposed Persons (section 6.17.11). In the funds management section, auditors verify that the operator’s system can flag a deposit when the total accumulation of deposits equals or exceeds €2,000, calculated either on a daily basis taking into account all deposits since the establishment of the business relationship, or on the basis of a rolling period of 180 days (section 6.18.3).
In the responsible gaming section of the same audit cycle, auditors check whether the licensee’s website offers a responsible gaming page no more than one click away from any page, whether the licensee has controls for players who exhibit problem gambling behaviour, and whether those controls are documented. The audit manual reviews AML and responsible gaming in the same exercise, which means an auditor who identifies weakness in one area is reviewing the other in the same visit. MGA licensees cannot assume that strong responsible gaming documentation will mitigate poor AML controls, or vice versa.
AGCO and the $25,000 Threshold: When AML Failures Implicate Harm
In Ontario, the AGCO’s Registrar’s Standards for Internet Gaming require registered operators to maintain a comprehensive anti-money laundering programme compliant with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and FINTRAC guidelines. The standards require operators to implement risk-based policies, procedures and controls that provide for escalating measures to address players engaging in behaviours consistent with money laundering, terrorist financing, or sanctions evasion indicators, including the refusal of transactions or exclusion of the player.
Enforcement actions have illustrated how the AGCO treats coordination failure. Operators have faced penalties where AML controls failed to function as active measures following high-value player deposits, and separate enforcement actions have resulted from responsible gambling failures where high-volume players exhibited clear signs of distress and loss-chasing behaviour but were not properly identified and subject to meaningful due diligence. In both cases, the underlying trigger was the same type of signal: a high-volume player with an unusual or escalating deposit pattern.
Enforcement pattern: In multiple cases, the underlying trigger is the same type of signal: a high-volume player with an unusual or escalating deposit pattern. One case becomes an AML enforcement action, another becomes a responsible gambling enforcement action. Compliance teams that treat these as categorically separate risks will miss the shared data layer that regulators expect operators to have addressed.
AGLC SRIG: Mandating Data Convergence in Alberta
The AGLC’s Standards and Requirements for Internet Gaming (SRIG) impose clear structural requirements for data convergence. Under the social responsibility provisions (Section 3.3 and Attachment 3.3), operators must use available information from various sources to effectively identify indicators of situations where players may be experiencing harm, monitoring risk profiles and behaviours for all players. The SRIG specifies that operators must, at a minimum, incorporate player behaviour indicators into a comprehensive approach to player risk profiling.
On the AML side, the SRIG requires operators to specify times and situations, based on the assessment of risk, where the operator will ascertain and reasonably corroborate a player’s source of funds. It also requires reasonable measures to identify and prevent suspected money laundering activities in the iGaming site, with anti-money laundering internal controls aligned with those of the designated reporting entity under the PCMLTFA.
Attachment 3.3 requires operators to use both automated and manual tools to monitor players’ behaviour in a manner that enables timely and effective provision of support, and to monitor indicators continuously or at a rate that reflects the dynamic nature of player behaviour. The standard does not permit periodic batch reviews for high-risk players. For compliance teams in Alberta, source-of-funds data obtained through AML processes is expressly contemplated as one of the inputs into harm-identification risk profiling under Attachment 3.3. Running both programmes in isolation is structurally non-compliant with the SRIG’s plain text.
Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), Section 3.3 (Responsible Gambling) and Attachment 3.3 (Additional Requirements for Identifying and Supporting Players At Risk of Harm); AML/TF programme requirements.
The Tipping-Off Problem: Where the Two Obligations Conflict Directly
Can an operator simultaneously comply with its AML tipping-off prohibition and its responsible gambling customer interaction obligation when the same player triggers both?
Under the PCMLTFA in Canada, under the UK’s Proceeds of Crime Act 2002, and under the anti-tipping-off provisions applicable to MGA licensees through FIAU implementing procedures, a licensee that has filed or is considering filing a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) is prohibited from disclosing that fact to the customer or to any third party. The prohibition is absolute. Under the Curaçao CGA’s AML/CFT policy, the same principle applies: if the operator suspects money laundering or terrorist financing, it should take into account the risk of tipping off the player when performing the customer due diligence process, and if it reasonably believes that performing CDD will tip off the player, it may choose not to pursue that process and should file a report to the FIU instead.
The UKGC’s SRCP 3.4.3 requires the licensee to act when a customer is identified as at risk of harm. Inaction is itself a breach. If a player whose deposit pattern has triggered an internal SAR is simultaneously flagged by the responsible gambling monitoring system, the RG team has an obligation to interact. That interaction, whether a message, a call, or an account restriction, could constitute tipping-off if it occurs at a point where the player could infer that a financial crime investigation is under way.
Compliance officers should resolve this by maintaining a joint watchlist protocol under which a player subject to an active SAR investigation is flagged in the RG monitoring system with a hold instruction, authorised at MLRO level, documenting the reason the standard interaction workflow has been suspended pending investigation outcome. This is not a regulatory waiver, it is a risk-managed sequencing decision. The RG interaction obligation does not disappear, it is queued. The queue must have a maximum duration and a documented escalation pathway. Operators in the UK should ensure their nominated MLRO and their Head of Responsible Gambling or safer gambling lead have a documented joint protocol covering this scenario, because regulatory guidance has indicated that oversight by Personal Management Licence holders of AML controls is an active area of scrutiny.
How the Frameworks Compare Operationally
| Jurisdiction | AML deposit trigger | RG harm-detection obligation | Explicit crossover requirement | Key enforcement |
|---|---|---|---|---|
| UKGC (UK) | SAR on suspicion, FRA at £150 net/30-day (SRCP 3.4.4) | Continuous identify-act-evaluate (SRCP 3.4.3) | Yes, SRCP 3.4.4 data must feed harm-identification approach | Dual AML + SR enforcement action (2024, 2025) |
| MGA (Malta) | EDD above €2,000 cumulative, source of wealth for high-risk players | RG page, player controls, documented harm procedures (Audit Manual) | Implicit, same audit cycle covers both, FIAU split creates structural gap | Dual-team audit, no single crossover precedent published |
| AGCO (Ontario) | EDD above CAD $25,000 cumulative deposit, PCMLTFA/FINTRAC compliance | Real-time monitoring, meaningful due diligence on high-risk players | Implicit, same high-volume player category triggers both, separate enforcement actions | AML enforcement and RG enforcement actions (2024, 2025) |
| AGLC (Alberta) | Risk-based SOF corroboration, PCMLTFA/FINTRAC alignment | Continuous monitoring, Attachment 3.3 multi-source risk profiling | Yes, SRIG expressly requires multi-source data including SOF in harm profiling | Framework in effect, enforcement emerging |
What Does “Is This Gambling Harm or Financial Crime?” Actually Mean in Practice?
The question compliance teams ask, whether this is a gambling harm case or a financial crime case, is often the wrong question. Regulators in every major jurisdiction covered here have confirmed, through enforcement and through the language of their frameworks, that high-volume deposit behaviour must be assessed against both risk frameworks simultaneously. The operational architecture that supports this is a unified player risk profile, not two parallel files.
Operators should build a shared player risk view maintained at the account level that is accessible to both the AML team and the RG function, subject to appropriate information barriers and access controls to prevent tipping-off through inadvertent disclosure. The profile should record the current AML risk rating and the basis for it, any active SAR or STR status, with access restricted to the MLRO and designated deputies, the current RG risk score and the monitoring triggers that have fired, and the status of any RG interaction, whether pending, completed, or outcome recorded. A joint protocol document, signed off by both the MLRO and the senior responsible gambling officer, should define the escalation path when both functions have flagged the same player.
The AGLC’s SRIG Attachment 3.3 expects operators to use available information from various sources, including player behaviour indicators, in harm identification. Source-of-funds data is one such source. Treating it as ringfenced to the AML team is not consistent with the standard’s plain language, and for operators registered in Ontario, where enforcement actions demonstrate an appetite for both AML and RG enforcement, treating these as siloed functions creates double exposure. Enforcement records make this pattern explicit.
For the UK market, regulatory guidance has identified overreliance on AI tools and poor oversight by Personal Management Licence holders as specific weaknesses. RG monitoring has faced similar criticism: enforcement actions arising from compliance assessments found that operators lacked robust automated processes to flag key indicators including excessive spending, prolonged playtime, and behavioural patterns linked to harm under SRCP 3.4.3. Both findings point to the same underlying gap: automated systems need to communicate with each other, and the humans who own the systems need a shared protocol for players who appear in both queues.
FINTRAC and Provincial Enforcement: Canada’s Structural Complexity
Canadian operators face a compliance structure that compounds the crossover challenge. FINTRAC administers the PCMLTFA at the federal level, meaning that AML reporting obligations, including SAR/STR filing, large cash transaction reporting, and cross-border reporting, run to a federal body. Responsible gambling obligations run to provincial regulators: the AGCO in Ontario, the AGLC in Alberta. There is no statutory mechanism for FINTRAC to share SAR data with provincial RG regulators, and there is no mechanism for provincial RG authorities to access federal AML filings.
FINTRAC has imposed enforcement actions on gaming entities for reporting failures under the PCMLTFA, including failure to identify common player identifiers and unverified identification documents. Operators cannot point to an absence of actual money laundering as a defence, FINTRAC enforcement is based on the reporting obligation, not the underlying crime. Private operators in Ontario and Alberta face the same enforcement exposure.
AML obligations run to FINTRAC regardless of what provincial RG regulators observe or report. A player who triggers a provincial responsible gambling enforcement action and is also a FINTRAC-reportable actor creates compliance exposure at both the federal and provincial level simultaneously, with no coordination mechanism between the two regulators. Operators must maintain a compliance programme that satisfies both frameworks independently, while building the internal architecture to prevent the two functions from working at cross-purposes against the same player account.
For guidance specific to the Ontario and Alberta market differences, including how the dual-entity model (AGCO plus iGaming Ontario, AGLC plus AiGC) affects where compliance obligations are routed, the AGCO vs AGLC comparison provides a current framework-level breakdown. Operators entering Alberta’s market for the first time should consult current AGLC SRIG compliance guidance for go-live obligations under the responsible gambling and AML/TF requirements.
Building the Joint Protocol: Minimum Requirements
No single regulator has published a mandated template for an AML, RG joint protocol. What follows represents the operational consensus drawn from enforcement findings and regulatory guidance across jurisdictions. Operators should confirm the precise requirements applicable to their licensed jurisdictions with qualified legal counsel, as obligations differ between the UKGC, MGA, AGCO, and AGLC frameworks described above.
A joint protocol should define the conditions under which a player’s file is subject to concurrent AML and RG review. It should assign named role responsibility for managing the file under each function, with a designated escalation point, typically a senior compliance officer with authority over both functions, who can make a sequencing decision when obligations appear to conflict. It should document the tipping-off suspension procedure: the circumstances under which the standard RG interaction workflow is held, the maximum duration of that hold, and the conditions under which it is lifted or escalated.
The protocol should address data access: which members of the RG team can see the AML risk rating without seeing SAR status, and how that access boundary is technically enforced. It should include a review cadence for players on the joint watchlist and a record-retention requirement consistent with the longer of the AML retention obligation (five years under most frameworks) and any applicable RG record-keeping requirement. Every player who exits the joint process, whether through account closure, voluntary self-exclusion, SAR resolution, or a combination, should have a documented outcome record accessible to both functions.
Enforcement actions make clear that reliance on player self-assessment is not an adequate substitute for documented due diligence. Regulatory frameworks make clear that multi-source data integration is expected, not treated as a future enhancement. Enforcement against operators makes clear that simultaneous failures across the AML and social responsibility divide compound rather than cancel each other.
Compliance teams at operators active in multiple jurisdictions should verify, for each market, where the specific deposit thresholds sit: £150 net per 30 days under UKGC SRCP 3.4.4, €2,000 cumulative under MGA audit expectations, and CAD $25,000 under AGCO EDD precedent. Those thresholds define the trigger points at which joint-protocol procedures must activate. Building a single global process calibrated to the most demanding threshold is operationally simpler, and regulators in each jurisdiction will accept a higher standard of protection. Review the joint protocol implementation guide for a detailed checklist of technical, procedural, and documentation requirements.
Key Resources
UKGC Licence Conditions and Codes of Practice (LCCP), Social Responsibility Code Provisions 3.4.3 and 3.4.4: gamblingcommission.gov.uk
AGLC Standards and Requirements for Internet Gaming (SRIG), Section 3.3 and Attachment 3.3: aglc.ca
MGA Compliance Audit Manual (MGA/G/001, August 2018), sections 6.17 (KYC/AML) and 6.18 (Funds Management): mga.org.mt
AGCO Registrar’s Standards for Internet Gaming, AML and responsible gambling provisions: agco.ca
FATF, Money Laundering and Terrorist Financing in the Online Gambling Sector: fatf-gafi.org
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.