Skip to content
2,183 standards indexed across 19 jurisdictions View the Atlas
Daily news + multi-week series Browse all insights
8 tools live Roadmap
AML · Payment Processors 17 min read Sep 18, 2026

Casino AML and Third-Party Payment Processors: Who Bears Liability Under FinCEN, FINTRAC, and UIGEA

Casinos cannot delegate AML liability to payment processors under FinCEN, FINTRAC, or UIGEA rules. Learn exactly what documentation each party must maintain and where the liability line sits.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Sep 18, 2026 17 min read Filed AML & KYC

Casinos operating in the United States and Canada cannot delegate their anti-money laundering obligations to the payment processors they contract to handle deposits and withdrawals. Under 31 CFR Part 1021, casinos are independently classified as financial institutions for Bank Secrecy Act purposes and carry direct reporting and recordkeeping duties that remain with the casino regardless of how the underlying funds flow. In Canada, the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) imposes parallel obligations on casinos as reporting entities, while the payment vendors handling remittance and electronic funds transfer functions qualify as money services businesses (MSBs) with their own independent registration and compliance obligations under FINTRAC. The UIGEA adds a third layer: it creates blocking duties at the financial institution level that sit alongside, not instead of, the gambling operator’s own obligations. These three frameworks interlock but do not overlap neatly, and the liability gaps between them are where enforcement actions arise.

How FinCEN Classifies Casinos and Their Payment Vendors

Under the Bank Secrecy Act, the Treasury Department extended the definition of “financial institution” to encompass casinos generating gross annual gaming revenue above $1,000,000. This is codified in 31 CFR Part 1021, which is specific to casinos and card clubs and is separate from the general financial institution rules in Part 1010. The consequence is that a casino subject to Part 1021 is not merely required to cooperate with AML obligations. It is itself a regulated financial institution with its own currency transaction report (CTR), suspicious activity report (SAR), recordkeeping, and compliance program obligations.

Section 1021.210 requires each casino to develop and implement a written AML compliance program. At a minimum, that program must provide for a system of internal controls to assure ongoing compliance, independent testing for compliance commensurate with money laundering and terrorist financing risk, training of casino personnel in identifying unusual or suspicious transactions, an individual responsible for day-to-day compliance, and procedures for using all available information to identify reportable transactions and patterns. This program requirement attaches to the casino as an entity. It cannot be satisfied by pointing to a payment processor’s own compliance posture.

Payment processors, depending on how they are structured and what services they provide, can independently qualify as MSBs under 31 CFR Part 1022. An entity engaged in transmitting or remitting funds on behalf of others must register with FinCEN as an MSB and maintain its own AML program. The key regulatory point for casinos is that a payment vendor’s independent MSB obligations under Part 1022 run in parallel with the casino’s Part 1021 obligations. The existence of an MSB compliance program at the vendor does not reduce, absorb, or satisfy any of the casino’s independent obligations. Both entities carry their own duties simultaneously.

Key threshold (31 CFR Part 1021): Casino SARs are required for transactions conducted or attempted at the casino involving or aggregating at least $5,000 where the casino knows, suspects, or has reason to suspect that the transaction involves funds derived from illegal activity, is designed to evade BSA requirements, lacks a lawful purpose, or involves use of the casino to facilitate criminal activity. CTRs are required for cash transactions in or out exceeding $10,000 in a single gaming day, with aggregation rules under § 1021.313 applying where the casino has knowledge of related transactions by the same person.

The SAR-Filing Obligation: Where Liability Cannot Be Contracted Away

Section 1021.320 sets out the casino’s SAR obligations in terms that leave no role for payment processors to absorb. The obligation to report attaches to suspicious transactions conducted “by, at, or through a casino.” A casino that identifies a suspicious transaction pattern must file a SAR within 30 calendar days of initial detection. If no suspect is identified on the detection date, the casino may delay filing for an additional 30 calendar days to identify a suspect, but the 60-day outer limit from initial detection is absolute under the relevant timing provisions of § 1021.320.

A casino, and any director, officer, employee, or agent of any casino, that makes a voluntary disclosure of any possible violation of law or regulation to a government agency or makes a disclosure pursuant to this section or any other authority shall not be liable to any person under any law or regulation of the United States for such disclosure or for any failure to provide notice of such disclosure to the person who is the subject of such disclosure.

This safe harbour applies to the casino filing the SAR, not to a payment processor filing on the casino’s behalf. The disclosure prohibition in § 1021.320(e)(1)(i) bars any casino, director, officer, employee, or agent from disclosing a SAR or any information revealing its existence. The explicit carve-out in § 1021.320(e)(1)(ii) permits sharing SAR information within the casino’s own corporate organisational structure for purposes consistent with the BSA, but this does not extend to external payment vendors who are not part of that corporate structure.

In practice, this means a casino cannot instruct a payment processor to file the casino’s SAR, cannot share draft SAR content with an external vendor to let the vendor decide whether to file, and cannot rely on information a vendor has about a transaction without independently evaluating whether that information creates a SAR obligation at the casino level. The FinCEN rules for casinos, as updated through 26 May 2026, are structured around the casino as the filer, the casino as the holder of documentation, and the casino as the entity that retains a copy of any SAR filed with supporting documentation for five years from the filing date under § 1021.320(d).

What UIGEA Actually Requires of Financial Institutions

Who the statute restricts

The Unlawful Internet Gambling Enforcement Act of 2006 (Pub. L. 109-347, 31 U.S.C. §§ 5361 to 5367, effective 13 October 2006) is regularly misread as primarily a payment-processor statute. It is not. Section 5363 prohibits persons “engaged in the business of betting or wagering” from knowingly accepting payments from participants in unlawful internet gambling. The restriction on accepting funds runs against the gambling operator, not the payment intermediary. Critically, the UIGEA explicitly excludes financial transaction providers from the definition of being “in the business of betting or wagering,” which means the statute does not make it a crime for a payment processor or depository institution to transmit funds to a gambling site merely on an aiding-and-abetting theory.

Section 5364 is where financial institution obligations arise, and they arise through regulation rather than directly. The UIGEA mandated that the Federal Reserve and the Treasury Department issue regulations within 270 days of enactment, requiring financial institutions and payment system participants to identify and block or otherwise prevent and prohibit restricted transactions. Those regulations were finalised in November 2008 and apply to depository institutions, credit card operators, money transmitting businesses, and other designated payment system participants. The blocking obligation attaches to these entities when they receive a notice from a U.S. Attorney or state attorney general identifying specific operators or transaction types as restricted.

What this means for casino-vendor relationships

The UIGEA framework creates two separate liability tracks that exist simultaneously. The gambling operator bears the § 5363 obligation not to accept restricted transactions. The financial institution or payment processor bears a § 5364 regulatory obligation to block or prevent restricted transactions when notified. A casino’s contractual agreement with a payment processor does not transfer the operator’s § 5363 exposure to the processor, nor does a processor’s § 5364 compliance program discharge the casino’s independent obligation. PokerStars, Full Tilt Poker, and Absolute Poker were indicted in April 2011 in the Southern District of New York precisely because they allegedly arranged for external payment processors to disguise gambling transactions as payments for non-existent goods. The casino-side operators remained criminally exposed despite routing funds through intermediaries.

Source: Unlawful Internet Gambling Enforcement Act of 2006, Pub. L. 109-347, codified at 31 U.S.C. §§ 5361, 5367, § 5364 implementing regulations finalised November 2008 by the Federal Reserve and Treasury Department.

FINTRAC: Parallel MSB Obligations in the Canadian Framework

Under the PCMLTFA (S.C. 2000, c. 17) and associated regulations (SOR/2002-184), casinos are reporting entities under paragraphs 5(k) to (k.3) of the Act. This classification covers government-run, charitable, and commercial gaming operations. As reporting entities, casinos must maintain a compliance program, appoint a compliance officer, conduct a risk assessment, implement policies and procedures, and carry out an effectiveness review, all documented and subject to FINTRAC examination.

Payment vendors operating in Canada and providing fund transmission, foreign exchange, or virtual currency services qualify as money services businesses under PCMLTFA. The definition, as set out in FINTRAC’s large cash transaction reporting guidance, captures any person or entity with a place of business in Canada that engages in remitting or transmitting funds by any means or through any person, entity, or electronic funds transfer network. A payment processor routing deposits between Canadian bank accounts and a casino’s account qualifies on its face. That MSB must register separately with FINTRAC, maintain its own AML compliance program, file large cash transaction reports and suspicious transaction reports where applicable, and keep records as prescribed under SOR/2002-184.

AGCO Standard 6.02 in Ontario’s Registrar’s Standards for Internet Gaming makes the casino-side obligation explicit in a regulated iGaming context. It requires that anti-money laundering policies and procedures supporting obligations under the PCMLTFA be implemented and enforced, and that copies of all reports filed with FINTRAC and supporting documentation be retained. The vendor’s own FINTRAC compliance program satisfies the vendor’s obligations. It does not substitute for the casino’s.

A money services business [is] a person or entity that has a place of business in Canada and that is engaged in the business of providing at least one of the following services: (i) foreign exchange dealing, (ii) remitting funds or transmitting funds by any means or through any person, entity or electronic funds transfer network, (iii) issuing or redeeming money orders, traveller’s cheques or other similar negotiable instruments… (iv) dealing in virtual currencies, or (v) any prescribed service.

FINTRAC has demonstrated its willingness to enforce casino reporting obligations. According to iGamingBusiness reporting in July 2026, Atlantic Lottery Corporation paid a $212,025 FINTRAC fine for violations including failure to report suspicious transactions, outdated compliance policies, and inadequate risk assessments. FINTRAC issued a record 35 notices of violation across all industries in 2025-26, totalling $247 million in penalties. According to iGamingBusiness reporting in September 2026, the New Brunswick Lotteries and Gaming Corporation was fined $399,712.50 and the Nova Scotia Gaming Corporation $231,826 for failures in suspicious transaction reporting. In none of these enforcement actions did the existence of external payment processing relationships reduce the regulated entity’s AML exposure. Compliance teams seeking a foundational overview of FINTRAC, FIAU, and FATF obligations across the major regulated jurisdictions will find the AML and financial compliance hub a useful starting reference.

Liability Thresholds: A Comparative Overview

Obligation US (FinCEN / BSA) Canada (FINTRAC / PCMLTFA)
Large cash transaction reporting (casino) CTR above USD $10,000 in a single gaming day (§ 1021.311) Large Cash Transaction Report above CAD $10,000
SAR / STR threshold (casino) USD $5,000 (§ 1021.320) No fixed dollar threshold, based on reasonable grounds to suspect
Payment processor classification MSB under 31 CFR Part 1022 if transmitting funds MSB under PCMLTFA if transmitting/remitting funds in Canada
Payment processor registration FinCEN MSB registration required FINTRAC MSB registration required
Casino’s liability for vendor’s AML failures Casino retains independent Part 1021 liability, vendor’s MSB compliance does not transfer Casino retains independent PCMLTFA liability, vendor’s MSB compliance does not transfer
UIGEA blocking duty Applies to financial institutions and payment system participants under § 5364 regulations (November 2008) No equivalent federal blocking regulation, provincial gaming regimes govern

What Casinos Must Document About Payment Provider Relationships

Regulators examining a casino’s AML program expect to find documentation of the payment provider relationship that goes beyond a commercial contract. The casino’s risk assessment must address the money laundering and terrorist financing risks presented by each payment channel it accepts. A casino accepting deposits via a third-party aggregator, digital wallet, or payment facilitator that the casino has not separately evaluated has a gap in its risk assessment that will be visible to any examiner reviewing the AML program under § 1021.210(b).

Before activating any new payment vendor, the casino must obtain written confirmation that the vendor has registered with FinCEN or FINTRAC as an MSB where that classification applies. The casino must also hold a current copy of or documented reference to the vendor’s own AML policies and procedures, with evidence that the casino’s compliance function has reviewed those policies and found them adequate. A contractual clause must require the vendor to notify the casino of any material change in its regulatory status, any regulatory action taken against it, and any transaction the vendor has flagged as suspicious that relates to the casino’s customer base. Each of these items is a discrete record, maintained separately, and must be producible on examination.

The Gibraltar AML Code of Practice for Remote Gambling (2026 update) articulates the principle that applies across all competent jurisdictions: a licence holder that uses a third party to provide information for due diligence purposes remains responsible for the outcome of that process and cannot rely on the third party to have concluded CDD on the licence holder’s behalf. The Code states this explicitly under section 6.13, referencing S.25(6) of Gibraltar’s Proceeds of Crime Act: the exception allowing reliance on a third party exists only where the third party undertakes in writing to make available immediately to the licence holder copies of all relevant information it holds and used to establish CDD. The same logic governs US and Canadian casino obligations, even though those frameworks articulate it through different regulatory language.

The Agent-as-Casino Problem

One liability structure that warrants specific attention is the use of payment agents or casino cage agents who accept funds from players on behalf of the casino. Under § 1021.320, SARs must be filed for suspicious transactions conducted “by, at, or through a casino.” The word “through” is significant. A transaction that flows through an agent acting on behalf of the casino, accepting cash, issuing credits, or exchanging chips, can be a casino transaction for BSA purposes even if the physical exchange occurs away from the licensed premises. FinCEN’s aggregation rule at § 1021.313 reinforces this: multiple currency transactions must be treated as a single transaction where the casino has knowledge, through any sole proprietor, partner, officer, director, or employee acting within the scope of employment, that they are by or on behalf of the same person and aggregate above $10,000.

A casino using third-party collection agents, common in certain junket and VIP arrangements, must ensure those agents’ transactions flow into the casino’s own transaction monitoring system, are subject to the same aggregation analysis, and are captured in the casino’s SAR decision-making process. Structuring a payment channel through an agent does not move the suspicious transaction outside the casino’s reporting perimeter. It extends the casino’s reporting obligation to include transactions the agent facilitates on the casino’s behalf.

The Brazil Parallel: Expanding Payment Processor Liability in Regulated Markets

While the US and Canadian frameworks maintain a clear division between the casino’s AML obligations and the payment processor’s independent MSB obligations, some jurisdictions are moving toward direct joint liability models. Brazil’s Ministry of Finance issued Ordinance No. 1,766, establishing joint and several liability for financial and payment institutions involved in illegal betting transactions, requiring those institutions to block unauthorised transactions within 24 hours of notification or face responsibility for unpaid taxes. Ordinance SPA/MF No. 2,750/2026, published 14 September 2026, further requires licensed financial institutions and payment processors to monitor suspicious transaction patterns and block accounts linked to unlicensed operators, with reporting deadlines set at the next business day after identification.

This Brazilian model represents a meaningful departure from the US and Canadian approach, under which payment processors carry independent MSB obligations but are not jointly liable for the casino’s AML failures. Operators building global payment infrastructure for licensed gaming operations should not assume that the liability allocation familiar from FinCEN and FINTRAC frameworks applies in LATAM markets, where regulators are increasingly treating payment intermediaries as co-responsible parties. The federal licensing obligations underpinning Brazil’s payment-blocking regime are set out in detail in our coverage of Brazil’s Bets Act federal licensing requirements. Qualified legal counsel should be consulted for jurisdiction-specific application of these rules.

FATF context (September 2026): FATF’s updated report, Risks of Gaming and Gambling, published 11 September 2026, identifies land-based and online casinos and sports betting as carrying the highest money laundering exposure among gambling sub-sectors, based on questionnaire responses from 80 jurisdictions. The report updates FATF’s 2009 casino sector analysis and draws specific attention to payment intermediary risks in online gaming environments. According to iGamingBusiness reporting on the report, online gaming shows more documented terrorist financing activity than gambling in aggregate.

Practical Compliance Framework for Casino Payment Vendor Onboarding

A casino’s payment vendor onboarding protocol should operate as a distinct compliance process, separate from the commercial procurement process. The compliance team, not the finance or product team, should control the go/no-go decision for each payment channel. The elements that must be documented before a new payment vendor is activated include the vendor’s MSB registration status with FinCEN or FINTRAC as applicable, the vendor’s written AML policy or compliance program summary, the casino’s own risk assessment of the channel (including transaction velocity limits, geography of user base, and known customer profile), and the contractual AML provisions governing the relationship.

Ongoing monitoring of active payment vendor relationships must be built into the casino’s AML program explicitly. The § 1021.210(b) program requirement for internal controls to assure ongoing compliance extends to monitoring the casino’s exposure through payment channels. A vendor that loses its MSB registration, receives a regulatory enforcement action, or is identified in suspicious transaction patterns related to the casino’s own customer accounts creates a material risk that the casino’s transaction monitoring must be designed to detect. For operators active in both the US and Canada, the key differences between AGCO and AGLC standards article sets out how the two Canadian iGaming frameworks approach AML, payment vendor relationships, and compliance program requirements side by side. Standard 6.02 of AGCO’s Registrar’s Standards for Internet Gaming makes the PCMLTFA linkage explicit within the Ontario gaming-specific framework, and the AGLC framework mirrors that structure for Alberta operators from its 13 July 2026 market launch. Review these standards and apply them to your jurisdiction before finalizing your payment vendor strategy.

Frequently Asked Questions

Does a casino’s AML liability transfer to its payment processor if the processor processes a suspicious transaction?

No. Under 31 CFR Part 1021, the casino retains its own SAR-filing and recordkeeping obligations regardless of the payment channel used. The processor may independently carry BSA MSB obligations under Part 1022, but satisfying those does not discharge the casino’s separate obligations. Both entities carry concurrent duties under their respective regulatory classifications.

What does UIGEA require of payment processors specifically?

UIGEA § 5364 required the Federal Reserve and Treasury Department to issue regulations mandating that financial institutions and payment system participants identify and block or prevent restricted transactions. Those regulations were finalised in November 2008. The statute itself does not create a crime of transmission for payment processors, the criminal prohibition in § 5363 runs against the gambling operator accepting the funds, not the intermediary transmitting them. The UIGEA explicitly excludes financial transaction providers from the definition of being in the business of betting or wagering, which eliminated aiding-and-abetting liability for processors in ordinary circumstances.

Are Canadian payment processors that handle casino deposits required to register with FINTRAC?

Yes, if they are transmitting or remitting funds by any means or through any person, entity, or electronic funds transfer network and have a place of business in Canada, they qualify as MSBs under PCMLTFA and must register with FINTRAC, maintain a compliance program, file large cash transaction reports for transactions exceeding CAD $10,000, and file suspicious transaction reports on reasonable grounds to suspect. A foreign money services business (FMSB) with no Canadian place of business but directing services at Canadian residents must also register with FINTRAC under the PCMLTFA provisions for FMSBs.

What written documentation should a casino maintain about its payment processor relationships?

At minimum, the casino must hold the processor’s MSB registration confirmation (FinCEN or FINTRAC as applicable), a current copy of or reference to the processor’s AML compliance program, the casino’s documented risk assessment for that payment channel, and contractual provisions requiring the processor to notify the casino of regulatory actions, SAR-triggering activity related to casino customers, and any change in the processor’s regulatory status. The casino’s risk assessment must address the ML/TF risk profile of each payment channel as part of the AML program required under § 1021.210(b).

Does accepting deposits via a digital wallet or cryptocurrency processor change the casino’s AML obligations?

No, the obligations are additive rather than substitutive. A casino accepting deposits via virtual currency must address that channel in its risk assessment, apply the same aggregation analysis under § 1021.313 where the casino has knowledge of related transactions, and evaluate whether the virtual currency processor qualifies as an MSB dealing in virtual currencies under FINTRAC’s definition (for Canadian operations) or under FinCEN’s virtual currency guidance (for US operations). The novelty of the payment channel does not create an exemption from existing BSA or PCMLTFA reporting obligations.

Key Resources

31 CFR Part 1021, Rules for Casinos and Card Clubs, FinCEN (as updated to 26 May 2026): the primary US federal regulatory framework governing casino AML, CTR, SAR, and recordkeeping obligations. Available via the eCFR at ecfr.gov.

Unlawful Internet Gambling Enforcement Act of 2006, Pub. L. 109-347, 31 U.S.C. §§ 5361, 5367: the statutory text governing restricted transactions and the blocking obligations imposed on financial institutions and payment system participants through § 5364 implementing regulations (November 2008).

FINTRAC Guidance on Reporting Large Cash Transactions and Suspicious Transactions (under PCMLTFA S.C. 2000, c. 17 and SOR/2002-184): the Canadian framework governing casino and MSB reporting obligations, available at fintrac-canafe.gc.ca.

FINTRAC Guidance, Methods to Verify the Identity of Persons and Entities: sets out CDD and identity verification standards applicable to all reporting entities including casinos, available at fintrac-canafe.gc.ca.

Gibraltar Gambling Commissioner, AML Code of Practice for Remote Gambling (2026 update): provides the most detailed publicly available statement of the third-party reliance principle in a gambling AML context, including the conditions under which operators may rely on third-party CDD while retaining ultimate responsibility for the outcome.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged AML & KYC

Browse all →

AML & KYC

Bonus Abuse and AML: How Free Bet Exploitation Creates Simultaneous Tax and Financial Crime Exposure

Sep 27 · 15 min read

AML & KYC

Self-Exclusion and AML: When Responsible Gambling Obligations Trigger Financial Crime Reporting

Sep 25 · 15 min read

AML & KYC

FINTRAC and AGLC AML Obligations in Alberta iGaming: Two Compliance Layers, One Operator

Sep 22 · 18 min read