Bonus Abuse and AML: How Free Bet Exploitation Creates Simultaneous Tax and Financial Crime Exposure
Inadequate KYC controls simultaneously generate AML exposure and invalid free bet tax deductions. Learn what compliance teams must address before the next audit.
Bonus exploitation sits at the intersection of three distinct compliance obligations: anti-money laundering controls, know your customer verification, and gambling duty calculations. When KYC programmes fail to detect synthetic identities, multi-account rings, or proxy accounts, the consequences are not confined to promotional budget leakage. The same accounts extracting value from welcome offers may simultaneously be processing funds that should have triggered a Suspicious Activity Report, and the free bet winnings they extract may be deducted from a tax liability the operator was never legitimately entitled to claim.
According to the Financial Action Task Force, the organisation made the connection between bonus exploitation and money laundering explicit in its September 2026 report, Risks of Gaming and Gambling. The report identified online casinos and sports betting as carrying the highest money laundering exposure across the gambling sector, and listed automated betting patterns, structuring of deposits through multiple accounts, and the use of e-wallets and virtual assets to move value without genuine play as documented risk indicators. The same operational patterns that characterise organised bonus abuse syndicates feature directly in the FATF typology list.
What does bonus abuse actually look like as an AML typology?
Organised bonus exploitation has evolved well beyond the single-user signup bonus hunter. Studies suggest that by 2025, iGaming fraud rates had doubled relative to 2023 levels, with deepfake-assisted identity fraud enabling coordinated account creation at industrial scale. Four operational profiles now dominate: solo hunters exploiting welcome bonuses through minimal wagering requirement fulfilment, sports arbitrage traders using free bets to lock in guaranteed margins, insider-assisted abuse where promotional mechanics are leaked, and organised syndicates deploying bot armies, synthetic identity documents, and proxy networks to claim bonuses across hundreds of accounts simultaneously.
From an AML perspective, the syndicate profile is the highest-risk category. The Gibraltar AML Code of Practice for Remote Gambling (v.1.0.2026, issued by the Gambling Commissioner pursuant to section 6(6)(f) of the Gambling Act 2005) specifically addresses the use of third-party identities by the true beneficial owner or controller of an account to mislead the licence holder as to the ownership of the account, source of funds, or to cause the operator to accept business it might otherwise have monitored or refused. That description maps directly to the multi-account syndicate structure: a single beneficial controller directing multiple accounts to claim bonuses, with the proceeds routed to a single destination.
The Gibraltar Code notes that certain payment methods “provide much less assurance” as to customer identity and source of funds, and requires that any payment method “whose use is disproportionately associated with irregular transactions in gambling or other sectors must be treated with proportionate caution” (Gibraltar AML Code, section 6.16).
E-wallets and prepaid instruments are the preferred deposit method for organised bonus abuse. They allow low-friction account creation with minimal identity linkage, rapid fund movement after bonus extraction, and structuring of amounts below reporting thresholds, precisely the pattern the FATF report flagged as “smurfing” in the gambling context. A compliance programme that treats e-wallet deposits as low-risk at the point of bonus issuance and then applies standard AML monitoring only at withdrawal is structurally inadequate.
The KYC gap that creates simultaneous AML and tax exposure
The MGA Compliance Audit Manual (MGA/G/001, August 2018) sets out the audit checkpoints that MGA-licensed operators must satisfy. Under section 6.17.3, player registration requires collection of date of birth, full identity, permanent residential address, and a valid contact means. Section 6.17.4 requires that players with identical main required details cannot register, that the same email address cannot be used twice, and that no player can wager before email verification is confirmed. Section 6.18.3 requires the system to flag a deposit where the total accumulation of deposits equals or exceeds €2,000, calculated either daily from account opening or on a rolling 180-day basis.
Under the Financial Intelligence Analysis Unit’s Implementing Procedures for the remote gaming sector, the threshold triggering Customer Due Diligence obligations is €150, as of the most recent version of those procedures. A standard welcome bonus deposit on an MGA-licensed platform will almost always trigger formal CDD obligations before a player takes a single spin. Operators that issue free play or free bets to accounts that have not cleared this CDD threshold are simultaneously issuing bonuses to unverified players and failing their AML obligations. The two failures are not parallel; they are the same failure.
Key Requirement: Under the FIAU Implementing Procedures for Malta-licensed remote gaming operators, CDD obligations are triggered at €150 of total deposits. Bonus issuance to accounts that have not cleared this threshold constitutes a KYC control failure that simultaneously produces AML non-compliance.
The UKGC’s Licence Conditions and Codes of Practice require licensees to conduct ongoing monitoring of the business relationship with customers, including scrutiny of transactions to ensure consistency with the customer’s known profile and risk assessment. According to regulatory enforcement records, the QuinnBet settlement of August 2026 involved the operator paying £609,104 to resolve regulatory failures identified as inadequate Source of Funds assessments and delays in filing Suspicious Activity Reports. The UKGC noted that operators must ensure their systems can identify harm and financial crime quickly, a standard that an over-reliance on static, onboarding-only KYC checks fails to meet in the context of account clusters running bonus exploitation plays.
How free bet deductibility becomes a compliance risk
Under General Betting Duty (GBD) in the UK, free bets carry a notional value that the bookmaker must include in the duty calculation. When a successful free bet pays out, the resulting winnings can be deducted from the duty calculation, including free pool bets on horse and dog racing. This treatment was confirmed in the HM Treasury consultation on the tax treatment of remote gambling (April 2025, Chapter 4) and carried forward in the Government Response published in November 2025.
The deduction is legitimate only where the free bet was awarded to and used by a verified player conducting genuine play. Where a free bet is awarded to a synthetic account, a proxy-controlled account, or to a player who was never properly identified, the deductibility of the resulting winnings becomes vulnerable on two grounds. HMRC’s audit of gambling duty accounts can scrutinise the underlying transactions, and an operator that cannot demonstrate CDD compliance for the accounts generating those deductions may face a challenged duty calculation. Separately, if those accounts are subsequently identified as connected to financial crime, the deductions claimed against them may be considered proceeds of fraud, creating further liability.
The April 2025 consultation document noted explicitly that free bet treatments created “contrived arrangements” in some cases, designed to reduce tax liability. The Government Response confirmed it was not proceeding with full harmonisation but was proceeding with material duty rate increases. Remote Gaming Duty rose from 21% to 40% on 1 April 2026. A new remote betting rate within GBD of 25% takes effect from 1 April 2027.
| Duty Type | Rate Before April 2026 | Rate From April 2026 | Rate From April 2027 |
|---|---|---|---|
| Remote Gaming Duty (RGD) | 21% | 40% | 40% |
| General Betting Duty, Remote (GBD) | 15% | 15% | 25% |
| General Betting Duty, Horse Racing Remote | 15% | 15% | 15% (excluded) |
| Bingo Duty | 10% | Abolished | Abolished |
As of 1 April 2026, a miscalculated or improperly claimed deduction in the RGD context carries double the prior financial exposure. At 40%, the value of disputed deductions from abused free plays or gaming bonuses awarded to unverified accounts is materially larger than it was under the pre-2026 regime.
The FATF red flags operators must map to their bonus controls
According to the Financial Action Task Force’s September 2026 report Risks of Gaming and Gambling, this represents the most significant update to international AML typologies for the gambling sector since the organisation’s 2009 casino report. It draws on questionnaire responses from 80 jurisdictions and written contributions from a further 29, alongside industry consultation. The report identifies the following patterns as documented risk indicators, several of which map directly to organised bonus exploitation.
Account deposits arriving from multiple third-party sources, or from payment methods that do not match the registered identity, are listed as red flags. Deposits structured below reporting thresholds across multiple accounts, smurfing, appear explicitly. Unusually large or coordinated bets on events, including those connected to potential competition manipulation, are flagged. Account opening and closing in short time frames, combined with deposits and withdrawals that are not accompanied by genuine play, are highlighted. The GLI-19 standard for interactive gaming systems (section A.8.2) requires that AML monitoring specifically include systems to detect deposits and withdrawals without associated game play, the identical pattern that defines low-wagering bonus extraction.
FATF identified in September 2026 that unregulated and offshore sectors risk becoming “attractive gateways for fraudsters, professional money launderers and organised crime.”
The Spillemyndigheden (Danish Gambling Authority) confirmed, following publication of the FATF report, that the indicators are directly relevant for Danish licensees. The UK Gambling Commission had already, in August 2026, upgraded the gambling software sector to a medium risk threat level for money laundering and terrorist financing, an elevated classification from prior guidance. Compliance teams that built their AML risk assessments on pre-2026 sector risk classifications must update those assessments to reflect both the FATF report and the UKGC’s revised sector assessment.
Where the bonus abuse typology intersects the AML control framework
Compliance programmes that treat bonus abuse and AML as separate workstreams will have structural gaps. The control points that detect organised bonus exploitation are the same control points that the AML framework requires for suspicious transaction identification. Mapping them explicitly closes both gaps simultaneously.
Account clustering detection identifies multiple accounts sharing device fingerprints, IP ranges, payment instruments, or registration data. Under the Gibraltar AML Code section 6.17, the use of proxy or beneficial ownership arrangements to mislead the licence holder as to account control is a specific money laundering typology. Detection of multi-account rings is therefore simultaneously a fraud prevention control and an AML obligation. Operators running separate fraud and AML teams with separate detection tools will detect the same account cluster twice, or miss it entirely in the gap between the two programmes.
Withdrawal velocity monitoring identifies accounts that deposit minimally, fulfil a wagering requirement using a bonus, and immediately withdraw. The Gibraltar AML Code requires that dormant accounts be monitored upon reactivation and that systems alert to unusual patterns when accounts are reactivated. An account opened to extract a welcome bonus, dormant until the next promotion cycle, and then reactivated exhibits precisely this pattern. It is both a classic bonus abuse signature and a textbook structuring behaviour.
Source of funds escalation during bonus eligibility is the point where tax and AML controls converge most directly. Under GBD, the deductibility of winnings from a free bet requires that the free bet was a genuine promotional instrument awarded to a bona fide customer. The UKGC’s enforcement position, as illustrated by the QuinnBet settlement, requires that source of funds assessments be triggered by customer behaviour and not deferred to an arbitrary deposit threshold. Where an operator issues a free bet to an account that has not undergone source of funds review because it has not yet made a cash deposit, the operator is simultaneously carrying an incomplete AML file and building a duty deduction on an unverified transaction.
The AGLC Standards and Requirements for Internet Gaming (SRIG, version 2026-03-17) require registered operators in Alberta to implement and comply with risk-based policies, procedures, and controls that provide for escalating measures to address players engaging in behaviours consistent with money laundering, terrorist financing, or sanctions evasion, including refusal of transactions or exclusion of the player. The SRIG also requires that operators specify, based on risk assessment, the times and situations in which source of funds will be ascertained and corroborated. This is a materially specific obligation: a generic tiered deposit threshold approach does not satisfy it if the operator’s risk assessment identifies bonus extraction patterns as a relevant money laundering indicator, which, post-FATF September 2026, it must.
Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), version 2026-03-17, AML/TF section, FATF, Risks of Gaming and Gambling (September 2026); Gibraltar Gambling Commissioner, Code of Practice for Remote Gambling: AML/CFT/CPF v.1.0.2026.
Enforcement precedents: the regulatory cost of the gap
The UKGC’s enforcement record in 2026 demonstrates that AML control failures at the account level attract significant financial penalties. According to regulatory settlement records, QuinnBet paid £609,104 in August 2026 following a settlement that identified inadequate Source of Funds assessments and delays in filing Suspicious Activity Reports as the core AML failures, alongside a platform migration error that allowed nearly 200 customers to unintentionally exceed deposit limits. The UKGC stated it expects other operators to learn from the findings. Evolution reached a £4.75m settlement with the UKGC after an investigation revealed games accessible through unlicensed third-party platforms, outdated AML risk assessments, and inadequate monitoring of third-party operators, with licence suspension considered before remedial actions averted that outcome.
In France, regulatory sources indicate the National Sanctions Committee (CNS) imposed fines and suspended bans on a French-licensed online sports betting operator and two senior executives in July 2026, following an investigation into AML control failures. In Germany, a coordinated multi-agency operation in September 2026 dismantled an illegal online casino that had processed approximately €5.8 billion in wagers between 2021 and 2023, with one suspect facing tax evasion charges of at least €77.6 million. The FATF report was published days later, with enforcement agencies citing it explicitly as contextual confirmation of the sector’s risk profile.
The connection between financial crime control failures and tax enforcement is direct. A licence holder that cannot demonstrate adequate CDD for a population of accounts is also unable to substantiate the duty deductions associated with those accounts. HMRC’s record-keeping requirements for GBD require four years of retention, sufficient for a duty enquiry to reach back into periods where bonus abuse was active before detection controls were strengthened.
Practical control requirements for compliance teams
Compliance teams should treat the bonus control framework and the AML transaction monitoring framework as a single integrated programme, not as adjacent workstreams. At a minimum, the following alignments are required.
The AML business-wide risk assessment must include bonus exploitation as a documented risk category. Post-FATF September 2026, any risk assessment that does not address automated account creation, low-wagering bonus extraction, and multi-account structuring below reporting thresholds is out of date on its face. The Gibraltar AML Code requires risk assessments to take into account new products and business practices, and to be updated when these change. Promotional mechanics, including welcome bonuses, free bets, free plays, and reload offers, are products in the AML risk assessment sense.
CDD must be completed before bonus funds are available for withdrawal. This is the structural control that prevents abused free bets from becoming deductible winnings on an unverified account. Under MGA rules, the €150 CDD threshold is typically crossed by the deposit that qualifies a player for a welcome bonus. Under GBD, a free bet’s notional value enters the duty calculation the moment it is issued. The duty deduction is sustainable only where the account has cleared identity verification, source of funds review, and ongoing monitoring before the first bonus is credited.
Suspicious Activity Reports must be filed promptly when the account cluster pattern is identified, not deferred until withdrawal is attempted. The UKGC’s criticism in the QuinnBet case centred specifically on delays in SAR filing, not on whether a suspicion was eventually formed. The pattern of multiple accounts sharing infrastructure, extracting bonuses systematically, and draining balances through minimal wagering is sufficient to form a suspicion at the point of detection, not at the point of confirmed identity linkage.
For UK remote gambling licensees, free bet duty records must be maintained account by account and cross-referenced against the CDD file for each account at the time the free bet was issued. Where accounts later prove to have been created fraudulently or operated by a beneficial owner other than the registered name, the duty deductions taken against those accounts must be reviewed and, where necessary, corrected. Operators should consult qualified tax and legal counsel on the treatment of duty adjustments in respect of accounts identified as fraudulent after the relevant duty period has closed.
Operators registered in Ontario or preparing for the AGLC Alberta launch should review the AGCO vs AGLC standards comparison for jurisdiction-specific AML obligations that apply to promotional structures under each framework. For a broader account of how UKGC enforcement has developed across AML and customer interaction obligations, see the Ontario iGaming at Year Three analysis, which covers the enforcement patterns compliance teams in regulated markets should treat as forward indicators. Begin by reviewing your own risk assessment against the FATF September 2026 indicators to identify gaps in your bonus exploitation controls.
Warning: From 1 April 2026, Remote Gaming Duty in the UK applies at 40%. Disputed or incorrectly claimed deductions from bonus winnings paid to unverified or fraudulent accounts carry double the financial exposure they did under the pre-2026 rate of 21%. Operators should audit their free bet and free play duty deduction records against their CDD files for the current and preceding duty periods.
Frequently asked questions
Does bonus abuse constitute a money laundering risk under FATF guidance?
According to the FATF’s September 2026 report Risks of Gaming and Gambling, the organisation lists automated betting patterns, structuring through multiple accounts, deposits and withdrawals without associated play, and the use of e-wallets to move funds below reporting thresholds as documented risk indicators for money laundering in the gambling sector. Organised bonus abuse syndicates using synthetic identities and multi-account rings exhibit all of these patterns and must be treated as an AML typology, not purely as a promotional fraud category.
Can an operator deduct free bet winnings for gambling duty if the account was later found to be fraudulent?
Under GBD, winnings from successful free bets are deductible in the duty calculation. Where the account holding the free bet was created using a synthetic or stolen identity, or was operated by a beneficial controller other than the registered name, the legitimacy of that deduction is open to challenge by HMRC. Operators should review duty deductions for accounts subsequently identified as fraudulent and take qualified tax advice on whether corrections to previously filed duty returns are required.
What is the CDD threshold that MGA-licensed operators must apply before issuing bonuses?
According to the FIAU’s Implementing Procedures for the remote gaming sector, the CDD trigger is set at €150 of total deposits as of the current version of those procedures. Most welcome bonus qualifying deposits exceed this threshold, meaning formal CDD must be completed before a bonus award is made to any account. Issuing a free bet or free play credit to an account that has not cleared CDD is simultaneously a bonus control failure and a breach of AML obligations under Maltese law.
What enforcement action has the UKGC taken for AML failures linked to account monitoring?
According to regulatory settlement records, in August 2026 QuinnBet paid a £609,104 settlement following findings that included inadequate Source of Funds assessments and delayed SAR filing. Earlier, William Hill paid £19.2 million and Entain £17 million for combined AML and social responsibility failures. Evolution reached a £4.75 million settlement in 2026 over AML risk assessment deficiencies and inadequate third-party operator monitoring. The UKGC has stated it expects the industry to learn from each published enforcement outcome.
Key Resources
FATF, Risks of Gaming and Gambling (September 2026): fatf-gafi.org
HM Treasury, The Tax Treatment of Remote Gambling: Summary of Responses and Government Response (November 2025); HMRC, Changes to Gambling Duties Policy Paper (Autumn Budget 2025): gov.uk
Gibraltar Gambling Commissioner, Code of Practice for Remote Gambling: AML/CFT/CPF, v.1.0.2026: gibraltar.gov.gi
MGA, Compliance Audit Manual, MGA/G/001, August 2018: mga.org.mt
AGLC, Standards and Requirements for Internet Gaming (SRIG), 2026-03-17: aglc.ca
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.