Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
AML · Casino Red Flags 14 min read Sep 4, 2026

Casino AML Red Flags: What Suspicious Activity Actually Looks Like Under FinCEN and FINTRAC

FinCEN and FINTRAC define specific casino red flags that trigger SAR/STR obligations. Learn the exact patterns compliance teams must recognise and document — or face enforcement.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Sep 4, 2026 14 min read Filed AML & KYC

Casino operations present a structurally distinctive money laundering risk: cash-intensive, high-volume, and capable of converting illicit funds into chips, credits, and ultimately clean cashouts in a single visit. FinCEN’s regulations at 31 CFR Part 1021 and FINTRAC’s guidance under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) both identify specific behaviours that require casinos to file Suspicious Activity Reports (SARs) in the United States and Suspicious Transaction Reports (STRs) in Canada. The indicators below are drawn from those primary sources and from enforcement decisions, not from generalised AML theory.

The Reporting Thresholds Compliance Teams Confuse

Under 31 CFR 1021.320, a US casino must file a SAR for any transaction conducted or attempted at, by, or through the casino that involves or aggregates at least $5,000 in funds or other assets, where the casino knows, suspects, or has reason to suspect that the transaction meets one of the statutory triggers. That $5,000 floor is distinct from the Currency Transaction Report (CTR) threshold. Under 31 CFR 1021.313, CTRs are required when multiple currency transactions by or on behalf of a single person result in cash in or cash out totalling more than $10,000 during any gaming day, with aggregation triggered when any sole proprietor, partner, officer, director, or employee of the casino has knowledge that the transactions are connected.

Conflating the two thresholds is a common audit finding. A patron who buys $7,000 in chips, plays briefly, and cashes out $6,800 does not trigger a CTR, but may well trigger a SAR if the pattern suggests structuring or the absence of any apparent lawful gambling purpose. The statutory triggers under 31 CFR 1021.320(a)(2) are:

The transaction involves funds derived from illegal activity, or is intended or conducted to hide or disguise funds or assets derived from illegal activity. The transaction is designed, whether through structuring or other means, to evade any Bank Secrecy Act reporting requirement. The transaction has no lawful purpose or is not the sort in which the particular customer would normally be expected to engage, and the casino knows of no reasonable explanation after examining the available facts. The transaction involves use of the casino to facilitate criminal activity.

Filing window: Under 31 CFR 1021.320(b)(3), a casino must file a SAR within 30 calendar days of initial detection. If no suspect is identified at detection, the casino may delay a further 30 days to identify a suspect, but the absolute outer limit is 60 calendar days from initial detection. Where ongoing money laundering is suspected, the casino must also immediately notify law enforcement by telephone, the SAR filing is not a substitute for that call.

In Canada, FINTRAC requires a casino to submit an STR whenever a transaction occurs or is attempted and there are reasonable grounds to suspect that it is related to the commission or attempted commission of a money laundering or terrorist activity financing offence. FINTRAC is explicit that this is an objective standard: the grounds must be articulable, not merely intuitive. The large cash transaction reporting threshold under the PCMLTFA is CAD $10,000.

What Does Structuring Actually Look Like at a Casino?

Structuring, breaking transactions into amounts deliberately kept below reporting thresholds, is the most common technique regulators observe. Under 31 U.S.C. 5324, structuring is itself a federal offence, separate from any underlying predicate crime. The evasion attempt is the violation.

At a casino, structuring manifests in patterns that frontline staff and monitoring systems must be calibrated to detect. A patron who makes multiple chip purchases across a gaming day, each just below $10,000, while staff collectively observe the cumulative amount is demonstrably above the CTR threshold, triggers the aggregation rule under 31 CFR 1021.313. The regulation deems the casino to have knowledge when any employee acting within the scope of employment is aware of the linked transactions, including awareness derived from examining books, records, logs, or information retained on magnetic disk or tape.

Structuring is also observable through payment method combinations: a patron who buys $8,000 in chips in cash, then purchases a further $4,000 in chips by credit card and another $3,000 by check on the same gaming day is presenting a pattern that the casino’s aggregation controls must capture. The FinCEN rule at 31 CFR 1021.313 covers cash-in, monitoring systems must separately flag the combined picture across instruments.

“Attempts by customers to circumvent the BSA, generally by structuring cash deposits to amounts lower than US$10,000 by breaking them up and depositing them on different days or at different locations, also violates the law.”

Source: Financial Crimes Enforcement Network (FinCEN), Bank Secrecy Act statutory and regulatory framework, 31 U.S.C. 5324 (structuring prohibition); 31 CFR Part 1021 Rules for Casinos and Card Clubs (current as of 26 May 2026).

Minimal Gaming with Large Cash-In and Cashout

The most textbook casino ML typology is the patron who converts large amounts of cash into chips, conducts minimal or low-risk play, and then redeems the chips for a cashout, accepting the house edge as a laundering cost. The Curaçao Gaming Authority’s AML/CFT Policy identifies this pattern explicitly, noting that criminals launder money “by buying chips for cash, then redeeming value without playing or with minimal playing.” Gibraltar’s Gambling Commissioner’s AML Code of Practice for Remote Gambling (v.1.0.2026) similarly identifies a customer who “recycles or attempts to recycle criminal funds or a proportion of such funds through gambling facilities either through engaging in minimal or very low risk activity” as a prominent example of casino ML.

From a FinCEN perspective, this pattern triggers the “no lawful purpose” limb of 31 CFR 1021.320(a)(2)(iii): the transaction is not the sort in which the particular customer would normally be expected to engage, and the casino knows of no reasonable explanation. In practice, compliance teams should document the ratio of time at the table to the value of chips purchased and redeemed, the net gaming loss as a percentage of funds in (a minimal loss relative to the sum cycled through is the signal), and any refusal or reluctance by the patron to provide identification or source of funds documentation.

For Canadian casinos subject to FINTRAC, the FINTRAC STR guidance illustrates this scenario concretely through worked examples involving casino chip purchases and same-day redemptions. The Vega Casino scenarios in FINTRAC’s guidance show a patron receiving cash, purchasing chips, and redeeming chips across three transactions on consecutive days, a pattern FINTRAC treats as requiring an STR because of the multiple indicators: the cash source, the brief gaming interval, and the prompt redemption.

The Third-Party Deposit Problem

A third party depositing on behalf of a patron, whether in cash at the cage, by wire transfer, or through a shared payment account, is a recognised red flag under both FinCEN and FINTRAC frameworks. Under 31 CFR Part 1021, the aggregation rules apply regardless of whether cash is delivered by the patron directly or by someone acting on their behalf. The casino is deemed to have knowledge of linked transactions where any employee knows the transactions are connected.

FINTRAC addresses this through its third party determination requirements, which require a reporting entity to take reasonable measures to determine whether a transaction is being conducted on behalf of a third party. When a casino determines or has reason to suspect that a person is acting on behalf of another party, it must collect identifying information on the third party and include it in the STR.

The red flags to document: a patron who is funded by someone who does not appear at the table, funds arriving from a payment account held in a different name from the player account, multiple accounts funded from the same external source where the account holders have no apparent relationship, and cash handed to a patron by a companion immediately before chip purchase. Each of these creates a third-party determination obligation independent of whether the play itself appears normal.

Refund and Rebuy Patterns

Refund-and-rebuy, sometimes called the “credit-and-cashout” method, is a layering technique specific to online and electronic gaming. A patron deposits funds via one payment method, credit card or bank transfer, makes minimal play, and then requests a refund or cashout via a different route, most commonly a bank wire or cheque. The effect is the conversion of one form of funds into another with the casino acting as an unwitting intermediary.

The Gibraltar AML Code of Practice (v.1.0.2026) identifies customers who “mislead a Licence Holder as to the source of their deposits” as a primary ML example, encompassing situations where the funds are deposited, run through minimal gambling activity, and then withdrawn as “winnings” through a different channel. For remote gambling operators, the distinct payment method on deposit versus withdrawal, where the mismatch cannot be explained by the patron’s account history or the platform’s withdrawal policies, is a SAR trigger.

FINTRAC’s worked STR scenarios show this pattern in the context of a patron (using the name Gordie Gold in the published example) who provides cash to a third party’s casino account, from which chips are purchased and then redeemed, with the final cashout going to a different person. The three-transaction chain, cash receipt, chip purchase, chip redemption, across different dates and involving different conductors is the structural fingerprint FINTRAC asks casinos to recognise and report as a combined pattern.

Chip-to-Chip and Peer-to-Peer Transfers

Direct chip transfers between patrons at a table, or the online equivalent, credit transfers between player accounts, create a layering vehicle that does not require a casino account to be funded by illicit cash directly. Gibraltar’s Gambling Commissioner flags “chip dumping” in poker and other contrived peer-to-peer outcomes explicitly, noting that “the purposeful transfer of funds between players, including players in different countries or continents” constitutes an ML risk whether or not the receiving player is knowingly colluding.

At land-based casinos, compliance teams should flag: a patron who accepts chips directly from another patron at the table rather than purchasing from the cage, a patron who redeems chips that are demonstrably not from their own play based on cage records, and table game dynamics where one player consistently loses to the same opponent in a pattern inconsistent with the statistical outcomes of the game being played. For online platforms, the equivalent red flags are account-to-account transfer requests, bonus-transfer arrangements between linked accounts, and head-to-head play where the losing account consistently funds the winning account over multiple sessions.

How Enforcement Turns These Indicators Into Liability

The enforcement record demonstrates what failure to act on these indicators costs. In Nevada, the Venetian agreed to a $7.2 million fine approved by the Nevada Gaming Commission in July 2026, after regulators found the property had failed to substantiate the source of funds for a patron later convicted of operating an illegal bookmaking operation. According to iGaming Business reporting in July 2026, the Venetian case was the fourth in a series involving the same patron, the Venetian, Resorts World, MGM Resorts, and Caesars Entertainment together incurring approximately $34 million in combined penalties for the same category of failure: inadequate investigation of a high-value patron’s source of funds despite indicators of suspicious activity.

The core failure in each case was not the absence of a transaction alert, it was the absence of follow-through once the alert was generated. Compliance teams that generate SAR narratives without conducting the underlying investigation, or that clear structuring alerts without documenting a reasoned basis for clearance, are replicating the exact gap that regulators identify in enforcement proceedings.

In Canada, FINTRAC fined the Atlantic Lottery Corporation $212,025 for three violations: failure to report suspicious transactions, outdated compliance policies, and inadequate risk assessment documentation. New Brunswick Lotteries and Gaming Corporation and the Nova Scotia Gaming Corporation faced combined FINTRAC penalties exceeding $630,000 for failing to submit suspicious transaction reports. According to iGaming Business reporting in September 2026, both provincial gaming entities claimed no actual laundering had occurred, a position that underscores a critical point in FINTRAC’s framework: the obligation to report arises at the point of reasonable grounds to suspect, not at the point of confirmed money laundering. The absence of a confirmed predicate offence is not a defence to a failure-to-report violation.

“Red flags typically stem from one or more facts, behaviours, patterns or other contextual factors that identify irregularities related to a client’s transactions. These often present inconsistencies with what is expected or considered normal based on the facts and context you know about your client and their transactional activities.”

Source: FINTRAC, Suspicious Transaction Reporting Requirements (PCMLTFSTRR, SOR/2001-317), Section 8, Indicators guidance.

A Jurisdiction Comparison of Casino Red Flag Thresholds

Indicator Type FinCEN (US), 31 CFR 1021 FINTRAC (Canada), PCMLTFA Gibraltar GRA, AML Code 2026
SAR/STR monetary threshold $5,000 (SAR); $10,000 (CTR per gaming day) No fixed monetary threshold for STR, CAD $10,000 for large cash report No fixed threshold, risk-based trigger
Structuring prohibition 31 U.S.C. 5324, criminal offence PCMLTFA, structuring is a reportable indicator POCA 2015, layering offence
Minimal gaming with chip redemption SAR trigger: no apparent lawful purpose (§1021.320(a)(2)(iii)) STR indicator: chip purchase/redemption pattern (FINTRAC Vega Casino scenario) Named example in AML Code §4.6(IV)
Third-party deposits Aggregation rule applies regardless of who delivers cash (§1021.313) Third party determination obligation (PCMLTFR) EDD required, SAR filing where ML suspected
Chip-to-chip / peer transfer SAR trigger if no lawful purpose STR if reasonable grounds to suspect Explicitly named red flag: chip dumping, P2P transfers (§4.7)
SAR/STR tipping-off prohibition 31 CFR 1021.320(e)(1), strict prohibition on disclosure PCMLTFA, prohibition on informing subject POCA §338, prohibited disclosure
Record retention 5 years from SAR filing date (§1021.320(d)) 5 years from report date (PCMLTFSTRR §12) 5 years minimum (AML Code)

Building the SAR/STR Narrative: What Regulators Actually Read

A SAR or STR that simply states “patron purchased chips for cash and cashed out shortly after” does not meet the documentation standard regulators expect. FINTRAC is explicit that the Details of Suspicion section must explain who the parties are, what each transaction consisted of, the relationships between parties, the facts and context that created the suspicion, and the indicators relied upon. The narrative should answer the questions: who conducted the transactions, on whose behalf, what was the source of funds, what was the sequence of actions, and what in that sequence is inconsistent with normal gambling activity for this patron profile.

For FinCEN SAR filings, casinos must retain a copy of the SAR and the original or business record equivalent of all supporting documentation for five years from the filing date, under 31 CFR 1021.320(d). Supporting documentation, cage records, player tracking logs, surveillance notes, account history, must be identified as such and maintained, because it is deemed filed with FinCEN and subject to law enforcement access without additional process.

The tipping-off prohibition under 31 CFR 1021.320(e)(1) is absolute: no casino, director, officer, employee, or agent may disclose a SAR or any information that would reveal a SAR’s existence. The prohibition applies even when the casino receives a subpoena, the casino must decline, cite the statute, and notify FinCEN of the request. Compliance teams must train cage staff, compliance investigators, and surveillance personnel on this requirement, because inadvertent disclosure in a patron conversation, even a denial that anything has been filed, can constitute a violation.

Source of Funds: The Investigation That Must Precede the Decision

Across every enforcement action reviewed, the systemic failure is not the absence of an initial alert, it is the failure to conduct and document a source of funds investigation that could either confirm or rebut the suspicion. The Nevada casino enforcement cluster involving four major Strip properties and $34 million in combined fines all turned on the same point: high-value patrons whose play levels were inconsistent with any known or documented source of legitimate wealth, and compliance teams that cleared the alerts without obtaining and scrutinising supporting documentation.

QuinnBet’s £609,104 UKGC settlement, reported by iGaming Business in August 2026, identified AML failures including failure to verify source of funds and delays in filing Suspicious Activity Reports, the same two-part failure pattern visible in the Nevada cases. The UKGC’s public statement noted that the operator “had insufficient controls to act in a timely manner to identify” high-risk customer behaviour, and emphasised that operators must ensure systems can identify financial crime quickly. The settlement included a disgorgement of £193,118.

In practice, source of funds investigations for a casino patron flagged for suspicious activity require: a documented request for supporting evidence proportionate to the risk level, a defined internal timeframe for obtaining and reviewing that evidence, a named decision-maker responsible for the SAR/STR determination, and a written record of the rationale, whether the decision is to file or not to file. The FINTRAC framework requires that when a casino takes reasonable measures to verify identity during a suspicious transaction, those measures must not tip off the client. Compliance teams must pre-design investigation protocols that allow staff to request documentation naturally, without indicating that a report is being or will be filed.

Operators managing compliance programs across multiple jurisdictions should consult qualified legal counsel on jurisdiction-specific obligations, particularly where the same player activity may engage reporting requirements in more than one regulatory framework simultaneously. The AML and financial compliance resources on this site cover FATF methodology, FIAU guidance under the MGA framework, and transaction monitoring obligations across the major iGaming jurisdictions.

Key Resources

31 CFR Part 1021, FinCEN Rules for Casinos and Card Clubs (current as of 26 May 2026): the primary US regulatory text covering SAR obligations, CTR aggregation, structuring prohibition, tipping-off rules, and record retention for casino licensees. Available at the Electronic Code of Federal Regulations (eCFR).

FINTRAC Suspicious Transaction Reporting Requirements (under PCMLTFSTRR, SOR/2001-317): FINTRAC’s operational guidance including the “reasonable grounds to suspect” standard, worked STR scenarios for casinos, and the indicator framework. Available at fintrac-canafe.gc.ca.

Gibraltar Gambling Commissioner, AML Code of Practice for Remote Gambling (v.1.0.2026, issued 8 January 2026): covers ML typologies, placement/layering/integration, chip recycling, P2P transfers, and the CDD inspection process for remote gambling licensees.

Bank Secrecy Act (codified at 31 U.S.C. 5311-5336): the statutory foundation for all FinCEN casino reporting requirements, including the structuring prohibition at 31 U.S.C. 5324 and civil and criminal penalties at 31 U.S.C. 5321-5322.

Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA): Canada’s primary AML statute, administered by FINTRAC, establishing reporting obligations for casinos including STR, large cash transaction, and casino disbursement reporting requirements. To strengthen your compliance program now, review the FINTRAC portal and FinCEN’s SAR filing system, test your transaction monitoring against the red flags outlined in this article, and schedule a documented review of your source of funds investigation protocols with your compliance team.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged AML & KYC

Browse all →

AML & KYC

FINTRAC Reporting for Alberta iGaming Operators: STR, LCTR, EFTR, and Casino Disbursement Obligations

Aug 21 · 17 min read

AML & KYC

Cryptocurrency and Casino AML: What Online Operators Must Do Under FINTRAC, FinCEN, and Global Frameworks

Aug 21 · 16 min read

AML & KYC

Beneficial Ownership Verification in iGaming: Mapping FATF Guidance onto Your KYC Programme

Aug 10 · 14 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.