Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
AML · Jurisdiction Comparison 17 min read Jul 31, 2026

iGaming AML: Canada vs US vs EU — Reporting Thresholds, KYC Timing, and Penalties Compared

FINTRAC, FinCEN, and the EU/MGA run on fundamentally different AML architectures. Master the thresholds, SAR triggers, and penalty exposure before operating across borders.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Jul 31, 2026 17 min read Filed AML & KYC

Three major AML regimes govern the iGaming operators most compliance teams work with every day: Canada’s FINTRAC framework under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), the United States’ FinCEN regime under the Bank Secrecy Act (31 CFR Part 1021), and the European Union framework applied through the Malta Gaming Authority (MGA) and the Financial Intelligence Analysis Unit (FIAU). The UK Gambling Commission sits alongside these as a major point-of-consumption regulator with its own distinct architecture under LCCP Condition 12.1.1 and the Proceeds of Crime Act 2002. Each framework shares the same underlying goal, but the specific obligations, reporting thresholds, customer identification timing, programme structure, effectiveness review cadence, and penalty exposure, diverge in ways that create genuine compliance risk for operators working across multiple jurisdictions.

How Do Reporting Thresholds Differ Between FINTRAC, FinCEN, and the EU?

Reporting thresholds are the most commonly misunderstood point of divergence across these three frameworks, and the differences are material enough to require separate control processes for each jurisdiction.

Under FINTRAC, casinos must file a Large Cash Transaction Report (LCTR) when they receive CAD $10,000 or more in cash in a single transaction, or when two or more cash amounts received within a consecutive 24-hour window from the same person or on behalf of the same person total CAD $10,000 or more. This is commonly referred to as the 24-hour rule, codified in the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, SOR/2002-184, section 126. The $10,000 threshold applies in Canadian dollars, foreign currency received must be converted using the Bank of Canada exchange rate at the time of the transaction. There is no minimum dollar amount triggering a Suspicious Transaction Report (STR) under FINTRAC. An STR is required as soon as practicable after a reporting entity has established reasonable grounds to suspect that a transaction or attempted transaction is related to the commission or attempted commission of a money laundering or terrorist activity financing offence, regardless of transaction size.

Under FinCEN’s 31 CFR Part 1021, casinos with gross annual gaming revenue exceeding USD $1,000,000 must file a Currency Transaction Report (CTR) for transactions in currency aggregating more than $10,000 during a single gaming day. The casino’s gaming day is the 24-hour period defined in its own books and records. The CTR covers a broad range of cash-in and cash-out activity, including chip purchases, front money deposits, cash bets, electronic gaming device bill insertions, chip redemptions, and payments on bets. Separately, the SAR threshold for casinos under 31 CFR 1021.320 is set at $5,000, not $10,000. A casino must file a SAR for any transaction conducted or attempted at the casino that involves or aggregates at least $5,000 in funds and where the casino knows, suspects, or has reason to suspect that the transaction involves funds from illegal activity, is designed to evade BSA requirements, or has no lawful business purpose. This $5,000 floor applies specifically to SARs, CTRs remain at $10,000.

In the EU framework applicable to MGA licensees, neither the FIAU Implementing Procedures for the remote gaming sector nor the underlying EU Anti-Money Laundering Directives set a single universal reporting threshold for suspicious activity reports. The obligation to report is triggered by suspicion alone. The FIAU Implementing Procedures for remote gaming set the CDD activation threshold at €150, meaning a licensee must have completed at least basic customer due diligence once cumulative deposits reach that level. A separate monitoring obligation under the MGA Compliance Audit Manual (MGA/G/001) requires that the system flag a deposit when total accumulated deposits equal or exceed €2,000, calculated either on a daily basis since the establishment of the business relationship or on a rolling 180-day period. These are CDD triggers, not reporting thresholds, the obligation to submit an intelligence report to the FIAU arises on suspicion regardless of whether any monetary threshold has been crossed.

Key Difference: The US SAR threshold ($5,000) is lower than the CTR threshold ($10,000). Canada has no dollar floor on STRs. The EU/MGA framework has no monetary floor for suspicious activity reporting at all. Operators running multi-jurisdiction programmes must maintain separate monitoring logic for each regime.

Customer Identification Timing: When Must KYC Be Completed?

The timing of identity verification is another point of meaningful divergence. All three frameworks share a risk-based philosophy, but the specific trigger points differ.

Under FINTRAC, casinos are required to verify the identity of persons in a range of defined circumstances, including when conducting a financial transaction of $10,000 or more in cash (the LCTR trigger), when disbursing $10,000 or more in casino chips, tokens, or cash equivalents, and when there are reasonable grounds to suspect a transaction or attempted transaction relates to money laundering or terrorist financing, irrespective of amount. FINTRAC guidance for the casino sector, effective October 2025, specifies the permissible identity verification methods: government-issued photo identification, the credit file method, or the dual-process method. Once a person’s identity has been verified using an acceptable method, re-verification is not required for subsequent transactions unless the entity has doubts about the previously obtained information.

Under 31 CFR Part 1021, casinos are required to secure and maintain, at account opening or at the time funds are deposited or a line of credit is extended, the name, permanent address, social security number, and other identifying information for each customer. The FinCEN programme requirement under 31 CFR 1021.210 requires procedures for using all available information to determine, when required, the name, address, social security number, and verification of the same of a person. Identification is also required for all currency transactions over $10,000. The BSA does not specify a single universal pre-play identification requirement for online gambling specifically, because US federal law has not yet created a comprehensive online gambling licensing framework at the federal level. State-licensed online gambling operators in New Jersey (DGE), Pennsylvania (PGCB), and Michigan (MGCB) layer state-specific KYC obligations on top of the federal BSA baseline.

For MGA licensees, the FIAU Implementing Procedures and the MGA’s Authorisations and Compliance Directive (Directive 3 of 2018) require that a player must be registered before engaging in gaming, with CDD obligations activating progressively. At registration, licensees must collect name and surname, date of birth, and permanent residential address as a minimum under Directive 3 of 2018. Full KYC verification must be completed and the identity verification status must be trackable in the back-office system, as auditors are instructed to verify during MGA compliance examinations. The FIAU’s €150 cumulative deposit threshold is where the formal CDD obligation activates for the remote gaming sector, with enhanced due diligence (EDD) required for high-risk players and source of wealth documentation required for those identified as presenting heightened risk.

Dimension Canada (FINTRAC) US (FinCEN) EU/MGA (FIAU) UK (UKGC)
Large cash / CTR threshold CAD $10,000 (24-hr rule) USD $10,000 per gaming day No cash threshold (online) No universal cash threshold
SAR / STR threshold No floor, reasonable grounds USD $5,000 + suspicion No floor, suspicion-based No floor, suspicion-based
CDD activation (online) At $10,000 cash, on suspicion At account opening + $10,000 €150 cumulative deposits (FIAU) Risk-based, no fixed floor
Deposit monitoring flag Not specified separately Not specified separately €2,000 (daily or 180-day rolling) Operator-defined under LCCP 12.1.1
STR / SAR timing As soon as practicable 30 calendar days (60 if no subject) Without undue delay Without delay (POCA 2002)
Effectiveness review Every 2 years (minimum) Independent testing, no fixed cycle Ongoing, MGA audit cycle Annual risk assessment review minimum
PEP enhanced due diligence Required Required (BSA/CDD rule) Required (MGA Audit Manual) Required (MLR 2017)

AML Programme Structure: The Four Pillars Compared

All three regimes require a documented AML programme, but the structural requirements differ in how they are codified and what elements are explicitly mandated.

FinCEN’s 31 CFR 1021.210 sets out the most explicitly codified programme structure for casinos. Each casino must develop and implement a written programme providing, at minimum, for four elements. A system of internal controls to assure ongoing compliance is the first. Internal and/or external independent testing for compliance, with scope and frequency commensurate with the money laundering and terrorist financing risks of the casino’s products and services, is the second. Training of casino personnel, including training in the identification of unusual or suspicious transactions to the extent that reporting is required, is the third. An individual or individuals designated to assure day-to-day compliance is the fourth. The FinCEN rule does not specify a fixed frequency for independent testing, frequency is scaled to risk.

FINTRAC’s compliance programme requirements under the PCMLTFA and associated regulations specify five components: compliance policies and procedures, a risk assessment, enhanced measures for higher-risk situations, a training programme and plan, and a two-year effectiveness review. The two-year effectiveness review is a firm requirement, not a recommendation. It must include a review of a sample of records to assess whether client identification policies are being followed, a review of transactions to assess whether suspicious transactions were reported, a review of large cash transactions for accurate and timely reporting, and a review of the frequency of ongoing monitoring against client risk levels. A reporting entity may conduct this review internally or engage an external auditor.

For MGA licensees, the AML programme obligation flows from both the Gaming Act (Cap. 583 of the Laws of Malta) and the FIAU Implementing Procedures for the remote gaming sector. The MGA Compliance Audit Manual (MGA/G/001, August 2018 v1) specifies that auditors must verify the existence and adherence to KYC procedures, the ability to track identity verification status in the back-office, documentation of all player records and verification documents, controls for PEPs, and source of wealth procedures for high-risk profiles. Licensees are required to appoint a Money Laundering Reporting Officer (MLRO), who functions as the designated compliance officer for AML purposes. The MGA operates a dual-supervision structure with the FIAU: the MGA handles gaming licence compliance, while the FIAU supervises compliance with AML/CFT obligations under Maltese law implementing the EU Anti-Money Laundering Directives.

LCCP Condition 12.1.1 requires that licensees conduct an assessment of the risks of their business being used for money laundering and terrorist financing, and that such risk assessment must be reviewed as necessary in the light of any changes of circumstances, including the introduction of new products or technology, new methods of payment, changes in the customer demographic or any other material changes, and in any event reviewed at least annually.

Source: UK Gambling Commission, Licence Conditions and Codes of Practice (LCCP), Condition 12.1.1, version effective 6 April 2026.

The UKGC’s framework does not codify a four-pillar programme in the same prescriptive way as FinCEN. Under LCCP Condition 12.1.1, licensees must ensure appropriate policies, procedures and controls are implemented effectively, kept under review, revised appropriately to remain effective, and take into account any applicable learning or guidelines published by the Commission. The Commission’s AML guidance, published separately from the LCCP, provides sector-specific direction. The key structural distinction from the US and Canadian approaches is that the UKGC operates as the AML supervisor for the gambling sector, it does not route obligations through a separate financial intelligence unit, while in Malta the FIAU and MGA share supervisory responsibility. Operators seeking the full LCCP rulebook can consult the UKGC LCCP explorer, which covers all licence conditions including Section 12.

What Happens When Operators Miss a Suspicious Activity Report?

The consequences of failing to file a required report differ significantly across the three frameworks, both in the nature of the sanction and in the enforcement machinery used to detect and pursue violations.

Under FINTRAC, the primary enforcement tool is the Administrative Monetary Penalty (AMP), issued under the PCMLTFA and associated Proceeds of Crime (Money Laundering) and Terrorist Financing Administrative Monetary Penalties Regulations (SOR/2007-292). In July 2026, FINTRAC fined the Atlantic Lottery Corporation $212,025 for three violations: failure to report suspicious transactions, outdated compliance policies, and inadequate risk assessments. The company accepted the penalty rather than appeal. According to iGamingBusiness reporting in July 2026, FINTRAC issued a record 35 notices of violation across all industries, totalling $247 million in fines during 2025-26. The Saskatchewan Indian Gaming Authority faced a $1.175 million FINTRAC penalty in September 2025, according to Canadian Gaming Business. Both BCLC and SIGA are actively contesting larger penalties in federal court, illustrating that the AMP regime now involves material financial exposure for gaming entities.

Under FinCEN’s BSA regime, failure to file a required CTR or SAR can lead to civil money penalties under 31 U.S.C. 5321. Criminal sanctions under 31 U.S.C. 5322 are also available for wilful violations and carry penalties of up to $500,000 in fines and up to ten years’ imprisonment per violation. Casinos that disclose the existence of a SAR to the subject of the report face additional penalties: 31 CFR 1021.320(e) contains an explicit prohibition on tipping off, and violation of this prohibition is itself a federal offence. State gaming regulators add further penalty exposure. In 2026, four Nevada casino operators, Resorts World Las Vegas, Caesars Entertainment, MGM Resorts, and the Venetian, agreed to a combined approximately $34 million in AML penalties to the Nevada Gaming Control Board related to failures involving a single VIP bettor, according to iGamingBusiness.

The UKGC’s AML enforcement record against remote gambling operators is among the most aggressive of any gaming regulator globally. William Hill was fined £19.2 million in 2023, and Entain £17 million in 2022, for failures spanning AML controls and social responsibility obligations. In June 2026, the Commission issued a formal warning to operators at the Gambling Anti-Money Laundering Group Annual Conference, criticising overreliance on AI-generated Suspicious Activity Reports and warning that Personal Management Licence holders were frequently not providing sufficient oversight of AML controls. In July 2026, Evolution reached a £4.75 million settlement following an investigation that revealed its games were being accessed via unlicensed websites, the Commission had considered licence suspension before Evolution took swift remedial action, according to iGamingBusiness. For MGA licensees, the FIAU administers civil penalties under Maltese law, and the MGA can impose administrative sanctions up to the Gaming Act (Cap. 583) maximums, including licence suspension and revocation.

The EU AML Architecture Is Changing: AMLA and AMLR

MGA licensees face an additional layer of structural change that Canadian and US operators do not: the creation of the EU Anti-Money Laundering Authority (AMLA) and the transition to the directly applicable EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, “AMLR”) alongside the Sixth Anti-Money Laundering Directive (Directive (EU) 2024/1640, “AMLD6”).

In 2025, the MGA called on all authorised persons and stakeholders to engage with AMLA’s open public consultations on three draft Regulatory Technical Standards (RTS). The first covers the draft RTS under Article 28(1) of the AMLR on customer due diligence. The second covers the draft RTS under Article 19(9) on criteria for identifying business relationships, occasional and linked transactions, and the determination of lower thresholds. The third covers the draft RTS under Article 53(10) of AMLD6 on reporting material weaknesses. These RTS, once finalised, will directly affect how MGA licensees structure their CDD programmes, determine what constitutes a linked transaction for monitoring purposes, and what material weaknesses must be reported to supervisory authorities.

AMLA is now consulting on the non-financial sector, which includes the gaming sector. This consultation phase offers licensees a valuable opportunity to familiarise themselves with the proposed measures and to contribute feedback that reflects operational realities within both the online and land-based gambling sectors.

For operators holding MGA licences alongside UKGC or FINTRAC registrations, the AMLA transition introduces a risk that EU-specific CDD thresholds, particularly around what constitutes “linked transactions”, may diverge from or add specificity to the existing FIAU Implementing Procedures. Compliance teams should engage with the AMLA consultation process directly and map draft RTS requirements against their existing FIAU-compliant procedures before the RTS are finalised and binding. The MGA licence requirements profile covers the broader supervisory framework within which these AML obligations sit.

Tipping Off: A Universal Prohibition with Jurisdiction-Specific Scope

All three frameworks prohibit disclosing to a suspect that a suspicious transaction report has been filed. The prohibition is worded differently in each regime, but the operational risk is identical: a system that allows a customer to infer from a staff interaction that a report has been made creates legal liability for the operator and potentially compromises law enforcement investigations.

Under FinCEN’s 31 CFR 1021.320(e)(1), no casino, and no director, officer, employee, or agent of any casino, shall disclose a SAR or any information that would reveal the existence of a SAR. Any casino subpoenaed or otherwise requested to disclose a SAR must decline and notify FinCEN of the request and the response. The prohibition extends to internal corporate communications beyond those permitted by the BSA’s information-sharing provisions. The rule includes a limited liability protection for casinos that make a voluntary disclosure in good faith.

Under FINTRAC’s regime, casinos are similarly prohibited from tipping off the subject of an STR. The prohibition applies to the fact that a report was filed and to any information that would lead a person to conclude that a report was filed. The FIAU in Malta and the UKGC under the Proceeds of Crime Act 2002 both maintain equivalent tipping-off prohibitions, and the UKGC’s guidance on AML procedures explicitly addresses the risk that CDD requests during an active suspicious transaction investigation could inadvertently tip off the player. Operators that integrate their CDD workflows with their STR filing process must ensure the two do not generate a visible account-level flag that a player can observe through a customer-facing interface.

Multi-Jurisdiction Operators: Where the Frameworks Actually Conflict

An operator licensed in Ontario under AGCO’s Registrar’s Standards for Internet Gaming (Standard 6.02) and simultaneously holding an MGA licence faces a layered AML obligation. Standard 6.02 requires that AML policies and procedures supporting obligations under the PCMLTFA shall be implemented and enforced, and that copies of all reports filed with FINTRAC and supporting records shall be made available to the Registrar. The standard also requires that AML internal controls align with those of the designated reporting entity under the PCMLTFA. For an Ontario-licensed operator, FINTRAC is the controlling external compliance standard for AML, and AGCO defers to it while adding its own reporting matrix and documentation expectations.

Where genuine conflict arises is not typically between FINTRAC and AGCO, which are designed to work together, but between FINTRAC’s two-year effectiveness review requirement and the UKGC’s expectation of at least annual risk assessment reviews. An operator holding both a UKGC remote gambling licence and a FINTRAC casino reporting entity registration cannot satisfy both obligations with a single review cycle. The FINTRAC two-year review and the UKGC annual review are distinct deliverables with distinct documentation requirements, the more frequent UKGC cycle must be run regardless of the FINTRAC schedule.

A second area of practical divergence is in source of funds (SoF) documentation thresholds. FINTRAC does not prescribe a specific monetary threshold for SoF requests, the obligation is tied to risk assessment outcomes. Under UKGC guidance, SoF requests for remote gambling customers have been calibrated in practice around loss-based triggers, with the Commission’s recent financial risk assessment programme proposing light-touch checks for customers losing over £125 in 30 days or £500 annually. The FIAU’s approach under the MGA framework ties SoF to the high-risk player designation following enhanced due diligence findings, with no single universal threshold. Operators running a single global KYC platform must design their SoF workflow to satisfy the most prescriptive applicable jurisdiction for each customer, which in practice means the UKGC thresholds will frequently be the operative standard for UK-facing accounts even where the technical licence is held elsewhere.

Operational Note: Compliance teams managing multi-jurisdiction AML programmes should maintain a jurisdiction matrix that maps each obligation, threshold, timing, review cadence, documentation format, to its source authority. A single global AML policy document that attempts to satisfy all regimes simultaneously typically satisfies none of them fully. Qualified legal counsel in each jurisdiction should review any consolidated policy before deployment.

Training Requirements: What Each Framework Mandates

AML training requirements share broad similarity across the three frameworks but differ in specificity and in who bears responsibility for delivery.

FinCEN’s 31 CFR 1021.210 requires training of casino personnel in the identification of unusual or suspicious transactions to the extent that reporting is required. The regulation does not set minimum training hours or require a specific delivery format, leaving programme design to the casino. The independent testing component of the four-pillar requirement effectively functions as a quality check on whether training is translating into correct reporting behaviour.

FINTRAC’s compliance programme requirements mandate a training programme and plan that covers the entity’s obligations under the PCMLTFA, its policies and procedures, record-keeping and client identification requirements, and reporting obligations. The training plan must be documented and kept current. The two-year effectiveness review must include an assessment of employee training, specifically checking whether staff knowledge of the policies and procedures is adequate.

MGA licensees must ensure that all staff involved in AML-relevant functions receive training covering their obligations under Maltese AML law and the FIAU Implementing Procedures. The MLRO bears primary responsibility for organising staff training and must ensure that training specifically addresses suspicious transaction recognition and CDD procedures.

The UKGC’s position, stated publicly at the GAMLG Annual Conference in June 2026, is that Personal Management Licence holders are expected to provide active oversight of AML training programmes, not merely to sign off on a documented training schedule. The Commission has criticised operators whose AML training is delivered entirely through automated AI-assisted workflows without adequate human oversight. Licensees whose training programmes rely heavily on automated compliance systems without documented human review of outputs should treat this as a priority remediation area ahead of any UKGC compliance assessment.

Key Resources

Canada: FINTRAC, Suspicious Transaction Reporting Requirements (fintrac-canafe.gc.ca); FINTRAC, Compliance Program Requirements (fintrac-canafe.gc.ca); FINTRAC, Large Cash Transaction Reporting Requirements (fintrac-canafe.gc.ca); Proceeds of Crime (Money Laundering) and Terrorist Financing Act, S.C. 2000, c 17, Regulations SOR/2002-184.

United States: FinCEN, 31 CFR Part 1021, Rules for Casinos and Card Clubs (eCFR, current to 26 May 2026); Bank Secrecy Act, 31 U.S.C. chapter 53.

EU/Malta: MGA, Compliance Audit Manual (MGA/G/001, August 2018 v1); FIAU, Implementing Procedures for the Remote Gaming Sector; MGA, Authorisations and Compliance Directive (Directive 3 of 2018, v2 October 2021); Regulation (EU) 2024/1624 (AMLR); Directive (EU) 2024/1640 (AMLD6).

UK: UKGC, Licence Conditions and Codes of Practice (LCCP), Condition 12.1.1, effective 6 April 2026 (gamblingcommission.gov.uk); UKGC, Prevention of Money Laundering and Combating the Financing of Terrorism guidance, Proceeds of Crime Act 2002; Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017).

For operators active in Ontario or Alberta, the AGCO vs AGLC comparison covers how FINTRAC AML obligations layer with provincial gaming regulator requirements across Canada’s two largest competitive markets. The AML and Financial Compliance hub provides additional resources on FATF standards, FIAU guidance, transaction monitoring frameworks, and source of funds best practice across all major jurisdictions.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged AML & KYC

Browse all →

AML & KYC

Politically Exposed Persons in iGaming: EDD Requirements Across FINTRAC, UK MLR 2017, and the EU Framework

Aug 7 · 19 min read

AML & KYC

EU AMLA and iGaming: Operator Obligations Under the New Anti-Money Laundering Architecture

Jul 24 · 15 min read

AML & KYC

Sweden AML and CTF Requirements: What SIFS 2019:2 Means for Licensed Casino Operators

Jul 17 · 13 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.