EU AMLA and iGaming: Operator Obligations Under the New Anti-Money Laundering Architecture
AMLA is live, the AMLR single rulebook applies directly, and AMLD6 transposes by July 2027. Here is what EU-licensed iGaming operators must prepare for before the deadlines close.
The EU’s Anti-Money Laundering Authority began operational life in 2026 with a mandate that affects every gambling operator licensed in a member state. Authorised by Regulation (EU) 2024/1620 and accompanied by a directly applicable single rulebook in Regulation (EU) 2024/1624 (the AMLR), the package ends the era in which AML obligations for gambling operators were defined entirely at national level. The 6th Anti-Money Laundering Directive (Directive (EU) 2024/1640, AMLD6) must be incorporated into national law by 10 July 2027, setting a hard deadline for member states to align their domestic frameworks with the new EU floor. For operators with licences in Malta, Spain, Denmark, Sweden, or any other EU jurisdiction, the regulatory baseline is changing now, not in 2027.
What AMLA Is and How It Fits Into the EU AML Architecture
AMLA is not a replacement for national supervisors. It is a coordination and standard-setting authority whose primary output consists of binding Regulatory Technical Standards and supervisory guidelines that national competent authorities must apply. Its mandate under Regulation (EU) 2024/1620 covers both the financial sector and the non-financial sector, which expressly includes gambling. The Authority operates from Frankfurt and reports to the European Parliament and Council.
The three-instrument package adopted in June 2024 works as follows. The AMLR (Regulation EU 2024/1624) is a directly applicable regulation, meaning its provisions bind obliged entities, including gambling operators, without requiring national implementation. The AMLD6 (Directive EU 2024/1640) sets requirements that member states must transpose into domestic law by July 2027. AMLA’s role under Regulation (EU) 2024/1620 is to develop the RTS and guidelines that give both instruments operational content. National supervisors then apply those standards to the entities they supervise.
For iGaming compliance teams, this architecture has a practical consequence. Some obligations are already in force via the directly applicable AMLR. Others will crystallise through each RTS as it is finalised. Still others await the AMLD6 transposition in each member state. The obligations do not arrive as a single event in 2027, they are phasing in, and AMLA’s active consultation programme is the mechanism through which the detailed standards are being built.
Key deadline: The 6th Anti-Money Laundering Directive (Directive (EU) 2024/1640) must be transposed into national law by 10 July 2027. Member states that fail to meet this deadline expose operators to a period of legal uncertainty where new EU obligations exist but national implementing rules have not yet been enacted. Operators with multi-jurisdiction EU footprints should monitor transposition timelines in each member state independently.
Gambling as an Obliged Entity Under the AMLR
Gambling operators fall within the definition of obliged entities under Article 3(3) of the AMLR. This classification carries direct legal weight: it is not a reference to national AML law but to a directly applicable EU regulation. The scope covers online and retail operations, meaning both remote gambling services and land-based establishments.
The AMLR’s CDD framework requires obliged entities to identify customers, verify their identity, identify beneficial owners and verify their identities, understand the nature and purpose of business relationships, and conduct ongoing monitoring. For gambling operators, the interaction between these requirements and existing customer account management creates both compliance obligations and, where systems are well designed, operational efficiency. A player account that already collects verified identity, funding sources, and transaction history provides the factual basis for CDD. The question is whether the processes, triggers, and documentation meet the AMLR standard.
The MGA has notified all authorised persons of AMLA’s open consultations, describing the transition to “a more unified and risk-sensitive EU legislation” and characterising the consultation phase as offering licensees a “valuable opportunity to familiarise themselves with the proposed measures and to contribute feedback that reflects operational realities within both the online and retail gaming sectors.”
Source: Malta Gaming Authority, notice on AMLA draft Regulatory Technical Standards consultations, citing Regulation (EU) 2024/1624 (AMLR) Art. 28(1), Art. 19(9) and Directive (EU) 2024/1640 (AMLD6) Art. 53(10).
The RTS Consultations That Will Define Operator Obligations
AMLA’s consultation programme has been running since December 2025. As of mid-2026, the consultations directly relevant to gambling operators cover the following areas.
The draft RTS on customer due diligence, issued under Article 28(1) of the AMLR, will define how obliged entities must structure their CDD processes, what evidence is acceptable for identity verification, and how enhanced due diligence must be applied in higher-risk situations. For gambling, the practical stakes are high: the CDD RTS will set the minimum standard against which national supervisors test operator KYC programmes.
The draft RTS on criteria for identifying business relationships, occasional and linked transactions, and the determination of lower thresholds, under Article 19(9) of the AMLR, is directly relevant to how gambling operators distinguish a registered account holder (a business relationship) from a one-off cash transaction in a land-based setting (an occasional transaction). It also governs how linked transactions are aggregated to determine whether a CDD trigger has been crossed. The consultation for this RTS ran from 9 February to 8 May 2026 and is now closed.
The draft RTS on reporting material weaknesses, issued under Article 53(10) of AMLD6, sets out what constitutes a reportable deficiency in AML controls and the format and timing for reporting it to national supervisors. Operators subject to compliance audits under frameworks like the MGA’s Compliance Audit Manual should expect material weakness reporting to become a formalised, harmonised obligation rather than a discretionary disclosure.
A further consultation of direct operational relevance opened on 13 July 2026 and runs until 27 September 2026: the draft RTS on the assessment of the inherent and residual risk profile of obliged entities in the non-financial sector. This standard will determine how national supervisors assess the ML/TF risk of gambling operators as a class of entity, and how individual operators are risk-profiled within that class. AMLA has stated explicitly that the consultation is designed to prevent disproportionate compliance burdens by avoiding a straightforward replication of financial institution mandates for non-financial obliged entities.
What AMLA’s Supervisory Risk Assessment RTS Means for iGaming
The inherent-risk RTS for the non-financial sector is the standard with the broadest long-term implications for how gambling operators are regulated across the EU. It will define the methodology by which national supervisors, whether the MGA, Spillemyndigheden (Denmark), Spelinspektionen (Sweden), SEPBLAC, or the GGL, assess the risk that a gambling operator poses as an obliged entity. That methodology will shape supervisory intensity: higher inherent risk means more frequent inspections, more detailed CDD expectations, and closer scrutiny of transaction monitoring outputs.
AMLA’s consultation document identifies gambling alongside real estate financing, online retail of high-value goods, arts and antiques dealing, and professional services as the non-financial sectors to which the RTS applies. The inclusion of both online and retail gambling in the same instrument means the risk profile being developed must accommodate the structural differences between the two, including the absence of an ongoing business relationship in many land-based transactions.
Sweden’s Spelinspektionen has formally endorsed operator participation in the consultation process, publishing AMLA’s consultation launch on its own news feed in April 2026. Denmark’s Spillemyndigheden has done the same, flagging all AMLA consultation rounds to its licensees. Both signals indicate that national supervisors are treating AMLA’s RTS development as an active process that will reframe their own supervisory methodologies, not as an abstract legislative exercise.
Operators that engage with AMLA’s consultations during 2026 have a concrete opportunity to shape the risk assessment methodology that their national supervisors will be required to apply, an opportunity that closes permanently once each RTS is finalised.
Beneficial Ownership Requirements: The AMLR Standard
The AMLR’s beneficial ownership requirements apply to gambling operators in two directions. Operators themselves, as obliged entities, must identify and verify the ultimate beneficial owners of corporate customers and business participants. Separately, the AMLR imposes requirements on gambling operators’ own ownership structures, reinforcing what most EU licensing regimes already require but setting a harmonised EU floor for transparency.
Under the AMLR, a beneficial owner is a natural person who ultimately owns or controls a customer. For corporate accounts, operators must identify any person holding 25% or more of the shares or voting rights, or who otherwise exercises ultimate effective control. Where no such person is identified, the senior managing official of the corporate entity serves as the default beneficial owner for identification purposes. These thresholds align with the approach already embedded in a number of national frameworks, but their codification at EU level means they are no longer subject to national variation.
For gambling operators, the beneficial ownership obligation is most operationally demanding in two contexts: corporate affiliate relationships, where a company rather than a natural person holds a player account or manages betting on behalf of third parties, and high-value customer accounts where corporate structures may be used to obscure the true source of funds. The AMLR’s requirement to verify beneficial ownership using information obtained from reliable sources, rather than simply self-declaration, sets a higher evidentiary bar than many current operator onboarding processes meet.
How National Supervisors Are Already Responding
The harmonising effect of AMLA’s programme is already visible in how national regulators are updating their own frameworks ahead of the RTS being finalised.
In Spain, the gambling sector is adapting to the full June 2024 package, covering the AMLA Regulation, the AMLR, and the AMLD6. Gambling operators remain under dual supervision by SEPBLAC and the DGOJ. In 2025, SEPBLAC adopted a stricter interpretation of its own compliance requirements, clarifying that video identification has been mandatory since 2016 under its official authorisation. That clarification has created significant operational pressure on operators because live video calls at onboarding are substantially more expensive and friction-generating than document-and-selfie KYC flows. Industry discussions with SEPBLAC about more technologically advanced alternatives are ongoing, but as of mid-2026, SEPBLAC’s position requiring live video identification has not changed.
The MGA’s supervisory engagement in 2026 reflects the same trajectory. The authority notified licensees of AMLA’s February 2026 RTS consultations on CDD and business-relationship thresholds as soon as they opened, describing participation as important for ensuring the final standards reflect operational realities in the gaming sector. MGA-licensed operators under the MGA Compliance Audit Manual already face AML testing as a component of compliance reviews under the Gaming Act (Cap. 583), with the Financial Intelligence Analysis Unit (FIAU) retaining a supervisory role alongside the MGA on AML/CFT matters. The AMLA framework does not replace that dual-supervisory structure but standardises the floor beneath it. Operators weighing the MGA’s compliance posture against the UKGC’s will find relevant context in our comparison of UKGC and MGA licence costs and regulatory obligations in 2026.
Denmark’s Spillemyndigheden supervises gambling operators’ compliance with the Danish Anti-Money Laundering Act and conducts targeted inspections of online betting, land-based betting, online casino, and land-based casino licensees. The regulator has flagged all AMLA consultation rounds to its licensees, treating AMLA’s output as directly relevant to how it will calibrate its own AML inspections.
The Cross-Border Enforcement Dimension
AMLA’s mandate extends to FIU coordination. The consultation on the draft RTS for cross-border information exchange between Financial Intelligence Units opened on 6 July 2026 and runs until 6 October 2026. This standard, once finalised, will govern how national FIUs share suspicious transaction data across borders, a mechanism directly relevant to detecting the money laundering patterns most prevalent in online gambling, where players and funds routinely cross member-state borders.
The scale of the enforcement challenge that AMLA is being asked to address is significant. According to iGaming Business reporting in July 2026, the European Casino Association presented data at a European Parliament roundtable showing that the EU black market for online gambling reached an estimated €91.6bn in 2025, up approximately 14% year-on-year, with more than 6,200 unlicensed operators actively targeting EU consumers. Representatives of AMLA participated in that roundtable alongside Eurojust and the Joint Parliamentary Scrutiny Group on Europol. The ECA has specifically called for closer cooperation between Europol and AMLA in tackling cross-border illegal gambling, including using the Digital Services Act to remove unlicensed operators’ advertising from major platforms.
For licensed operators, this enforcement dimension matters beyond the obvious compliance framing. A regulatory environment in which AMLA is actively coordinating FIU information exchange means that suspicious transaction reports filed by a Malta-licensed operator will increasingly be cross-referenced against data held by FIUs in other member states. The quality of an operator’s STR programme, not just the volume of reports filed, will determine whether that cross-referencing produces actionable intelligence or generates false positives that consume enforcement resources.
Practical Compliance Implications: What Operators Must Do Now
EU-licensed gambling operators should treat the AMLA consultation window as a compliance preparation deadline, not simply an industry engagement opportunity. The RTS being finalised during 2026 will set the standards against which national supervisors test operator controls. Operators who have read and engaged with the draft RTS will be better positioned to map current gaps before the standards become binding.
The CDD RTS (Article 28(1) AMLR) will standardise what evidence is acceptable for identity verification. Operators currently relying on document-and-selfie KYC without liveness detection, or on third-party KYC providers whose verification methodology has not been audited against the draft RTS, should initiate that review now.
The business-relationship and linked-transaction RTS (Article 19(9) AMLR) has already closed for consultation. Its finalisation will determine at what aggregate transaction value a land-based occasional transaction triggers CDD obligations and how linked transactions are counted for online platforms. Operators running both retail and online channels in the same EU member state face the most immediate complexity here.
The material weakness reporting RTS (AMLD6 Article 53(10)) will create a standardised obligation to report compliance deficiencies to national supervisors. Operators should review their current internal AML audit and escalation procedures against this incoming requirement, particularly where existing processes treat AML control gaps as internal remediation items rather than potential reportable matters.
The inherent-risk RTS for the non-financial sector (consultation open until 27 September 2026) will set the risk-profiling methodology that determines supervisory intensity. Operators should engage through their national trade associations or directly with AMLA’s consultation process before the deadline.
| AMLA Consultation | Legal Basis | Status (as at July 2026) | iGaming Relevance |
|---|---|---|---|
| Draft RTS, Customer Due Diligence | AMLR Art. 28(1) | Closed (8 May 2026) | KYC verification standards for all obliged entities |
| Draft RTS, Business relationships, occasional &, linked transactions | AMLR Art. 19(9) | Closed (8 May 2026) | CDD trigger thresholds, linked-transaction aggregation |
| Draft RTS, Material weakness reporting | AMLD6 Art. 53(10) | Closed (8 May 2026) | Mandatory disclosure of AML control deficiencies |
| Draft Guidelines, Business-wide risk assessment | AMLR | Closed (15 July 2026) | Internal ML/TF risk assessment methodology |
| Draft RTS, Inherent &, residual risk profiling (non-financial sector) | AMLR | Open, closes 27 September 2026 | Supervisory risk profiling of gambling operators |
| Draft ITS, Format for reporting suspicions and transaction records | AMLR | Open, closes 20 September 2026 | STR formatting and submission standards |
| Draft RTS, Cross-border FIU information exchange | AMLR | Open, closes 6 October 2026 | Cross-border STR data sharing, multi-jurisdiction operators |
The Operator’s Compliance Preparation Checklist
Compliance teams at EU-licensed gambling operators should work through the following before the key consultation deadlines close. The objective is not formal regulatory submission, though that option is available, but internal gap analysis against the draft standards before they are finalised.
Map current CDD processes against the draft CDD RTS. Identify where existing KYC documentation, verification methods, and beneficial ownership procedures meet the AMLR standard and where they fall short. Pay particular attention to the evidentiary requirements for UBO verification in corporate accounts.
Review internal risk assessment methodology against the draft business-wide risk assessment guidelines. The AMLA guidelines, once finalised, will define the methodology AMLA and national supervisors consider adequate. Where current business-wide risk assessments have not been updated since AMLD4 or AMLD5 transposition, they are unlikely to meet the incoming standard.
Assess STR quality, not just volume. The incoming ITS on STR format and the cross-border FIU exchange RTS together create a higher analytical bar for suspicious transaction reporting. Reports that are formally compliant but analytically thin will generate regulatory scrutiny as cross-border data sharing improves the ability of FIUs to identify reporting patterns.
Engage national supervisors proactively. Operators licensed by the MGA, Spillemyndigheden, or SEPBLAC should review their supervisor’s published guidance on AMLA’s consultations and consider requesting a supervisory dialogue on how the incoming RTS will be implemented in that jurisdiction. In Spain in particular, the SEPBLAC video identification requirement demonstrates that national supervisors are already tightening enforcement ahead of formal AMLA harmonisation.
Operators holding licences in multiple EU member states should also map which jurisdictions are currently above the AMLR floor and which are below it. The AMLR sets a minimum standard, but member states can maintain stricter national requirements. The compliance programme for a multi-jurisdiction EU operation must be built to the highest national standard in each market while remaining consistent with the EU floor across all of them. Legal counsel with jurisdiction-specific expertise should be consulted to identify member-state-level requirements that exceed the AMLR baseline.
For MGA licensees specifically, the interaction between the existing FIAU/MGA supervisory split and the incoming AMLA framework deserves close attention. The FIAU retains responsibility for AML/CFT supervision of MGA licensees as obliged entities under Maltese law. As AMLA’s RTS are finalised, the FIAU’s implementing guidance will need to reflect them. Operators should monitor FIAU publications alongside MGA announcements, because the detailed implementing rules for Malta-licensed operators will come through the FIAU rather than the MGA directly. For the audit documentation obligations that run alongside AML compliance for MGA licensees, see our analysis of MGA system audit requirements.
Sweden’s channelisation challenge illustrates a structural risk that AMLA’s coordination role is partly designed to address. When licensed markets become harder to operate in and unlicensed alternatives remain easily accessible, players migrate offshore. That migration concentrates AML risk in the unregulated segment and undermines the supervisory value of the licensed sector’s STR programme. The Swedish experience, where the channelisation rate has declined to approximately 84%, gives concrete operational context to why AMLA is focused on calibrated, proportionate standards for licensed gambling operators rather than maximally restrictive ones. Our coverage of Sweden’s channelisation challenges under Spelinspektionen sets out the licensed market pressures in full.
Key Resources
Compliance teams working through the AMLA framework should refer to the following primary sources.
The AMLA public consultations page at amla.europa.eu lists all open and closed consultations with direct links to the EU Survey submission platform. The inherent-risk RTS for the non-financial sector and the cross-border FIU RTS are both open as at publication. The MGA’s notice on AMLA’s draft Regulatory Technical Standards consultations provides the MGA’s formal signalling to licensees and is available on the MGA news page. The establishing regulation (Regulation (EU) 2024/1620), the AMLR (Regulation (EU) 2024/1624), and the AMLD6 (Directive (EU) 2024/1640) are each available on EUR-Lex. Spain’s Chambers Global Practice Guide for Gaming Law 2025 provides jurisdiction-specific context on the SEPBLAC and DGOJ supervisory framework as it adapts to the new EU architecture.
Sources: Regulation (EU) 2024/1620 (AMLA establishing regulation); Regulation (EU) 2024/1624 (AMLR); Directive (EU) 2024/1640 (AMLD6); AMLA Public Consultations page (amla.europa.eu); MGA notice on AMLA RTS consultations (mga.org.mt); Spillemyndigheden AML supervision page (spillemyndigheden.dk); Chambers Global Practice Guide, Spain Gaming Law 2025, ECA report on EU black market gambling, July 2026.
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.
The Tuesday brief, every week.
One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.
Unsubscribe with one click. We'll never share your address.