Source of Funds for Casino Players: When You Must Ask and What to Accept
When must a casino operator's AML programme trigger a source of funds check, and what documentation actually satisfies it? A cross-jurisdiction guide for compliance teams.
Source of funds (SoF) verification is one of the most enforcement-active areas of casino AML compliance, yet the obligation it imposes is frequently misapplied. Operators treat it as a documentation collection exercise triggered only by conspicuously large deposits. The reality, across every major regulated jurisdiction, is that SoF is a risk-proportionate investigative obligation, calibrated to the customer’s risk profile, the pattern of their transactions, and specific threshold triggers that vary considerably by regulator. What a player must be asked, what they can be asked to provide, and how that evidence must be assessed differ between the UK, Malta, Canada, the US, and offshore licensing frameworks. Conflating these regimes, or applying one standard globally, creates gaps that regulators are actively finding and fining.
Source of Funds and Source of Wealth: The Legal Distinction That Matters
These two concepts are related but legally separate, and regulators treat them as distinct obligations at different points in the customer relationship.
Source of funds refers to how the specific funds used in a particular transaction or series of transactions were obtained. The Curaçao Gaming Control Board AML/CFT Policy defines it as “how the funds for a particular transaction were obtained by the player, like personal savings, pension release, property sales, share sales and dividends, gambling winnings, gifts, compensation from legal claims.” FINTRAC guidance under the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (PCMLTFR, SOR/2002-184) frames it similarly: “The origin of the particular funds or VC used to carry out a specific transaction or to attempt to carry out a transaction. It is how the funds were acquired, not where the funds moved from.” The focus is transactional and specific.
Source of wealth (SoW) is broader: it establishes the origin of the player’s overall financial position, not just the funds in play at any given moment. It answers the question of how the player accumulated their total assets. Regulators require SoW primarily in enhanced due diligence (EDD) contexts, particularly for politically exposed persons (PEPs), high-value customers with opaque income, and players from high-risk jurisdictions.
Under the Gibraltar Gambling Commissioner’s AML Code of Practice for Remote Gambling (v.1.0.2026), which applies to all Gibraltar-licensed remote operators, source of wealth and source of funds are both mandatory for PEP accounts: “S.20 POCA requires that Licence Holders evaluate all PEP accounts in terms of specific approval for the account to continue, the source of funds and the source of wealth to be established and enhanced ongoing monitoring to be applied to the account.” The Malta Gaming Authority Compliance Audit Manual echoes this: auditors are required to verify “whether the Licensee is requesting the source of wealth and source of funds for high risk profile players”, a paired requirement, not an alternative one.
Practical distinction: A player depositing £15,000 from the sale of a cryptocurrency holding requires SoF evidence tied to that transaction (exchange records, wallet-to-bank transfer documentation). If that player is also a foreign PEP with a history of large, irregular deposits, SoW evidence is additionally required, establishing the legitimacy of their entire financial position, not just the crypto proceeds.
When Must You Ask? Jurisdiction-by-Jurisdiction Triggers
No universal threshold governs when SoF checks become mandatory. Each jurisdiction sets its own triggers, and operators with multi-licence portfolios must apply the correct standard for each regulated market. The common thread across frameworks is risk: a customer’s profile, transaction patterns, and jurisdiction of residence determine both when the obligation arises and how deeply it must be investigated.
United Kingdom
The UK Gambling Commission’s primary AML obligation sits in Licence Conditions and Codes of Practice (LCCP) Condition 12.1.1, which requires all licensees to conduct an annual risk assessment of their business for money laundering and terrorist financing, implement appropriate policies and procedures, and keep those controls under ongoing review. The condition references the UKGC’s own published AML guidelines as a mandatory point of reference.
The timing of individual customer SoF checks is risk-based rather than threshold-triggered in the LCCP itself. The Commission’s enforcement posture, according to regulatory sources, makes clear that failing to verify source of funds and delaying Suspicious Activity Report submissions both constitute material compliance failures. The UKGC has stated explicitly that “operator-side failings remain a primary driver of AML/CTF risks in the industry.”
The UKGC issued a formal money laundering risk assessment in July 2026 and warned operators in June 2026 against over-reliance on AI for generating SARs without adequate human oversight, identifying this as a systemic gap in AML quality. Personal Management Licence holders are specifically flagged as failing to provide sufficient governance over AML controls.
Malta
The MGA Compliance Audit Manual specifies a deposit accumulation flag: the system must alert when a player’s total deposits equal or exceed €2,000, calculated either on a daily basis taking into account all deposits since the establishment of the business relationship, or on the basis of a rolling 180-day period. This is the operational trigger point at which auditors will test whether CDD measures, including SoF enquiry, were initiated. The MGA’s audit framework requires licensees to demonstrate that EDD, including SoF and SoW for high-risk players and PEPs, is actively carried out, not merely documented in policy.
Canada, FINTRAC
Canadian casino operators are reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and are supervised by FINTRAC regardless of which province they operate in. The key triggers are transactional: FINTRAC requires casinos to file a Large Cash Transaction Report when a client conducts a single cash transaction of CAD $10,000 or more, and to submit Suspicious Transaction Reports where reasonable grounds exist to suspect ML/TF regardless of amount.
The AGLC Standards and Requirements for Internet Gaming (SRIG, dated 17 March 2026) require registered Alberta operators to “specify times and situations, based on the assessment of risk, where the Operator will ascertain and reasonably corroborate a player’s source of funds.” This makes SoF verification a programme-level obligation that operators must define in their own risk-based policies, not a fixed-threshold trigger, while remaining subject to FINTRAC’s transactional reporting requirements.
AGCO enforcement in Ontario provides an instructive case. According to regulatory sources, AGCO reached a settlement with NorthStar Gaming after the operator failed to implement required Enhanced Due Diligence for a high-risk player who had deposited over CAD $189,000 without funds verification being triggered. The high-risk player threshold at issue was CAD $25,000 in cumulative deposits. The player was subsequently linked to criminal investigations. AGCO’s position: AML controls must function as active measures, not written policies sitting in a compliance manual.
United States
US casinos operating under the Bank Secrecy Act are regulated for AML purposes by FinCEN under 31 CFR Part 1021. The filing threshold for Suspicious Activity Reports is USD $5,000 in funds or other assets, where the casino knows, suspects, or has reason to suspect that the transaction involves funds derived from illegal activity, is structured to evade reporting requirements, or serves no known lawful purpose. Currency Transaction Reports are required for cash transactions exceeding USD $10,000.
Nevada enforcement illustrates the SoF dimension in high-stakes casino play. According to regulatory sources, the Nevada Gaming Commission approved a significant fine against the Venetian Resort Las Vegas for AML failures specifically related to failures to substantiate the source of funds for high-stakes gambling activities connected to a convicted bookmaker. This was part of a series of penalties linked to the same individual, with combined fines across Strip properties reported as substantial since early 2025.
Curaçao
Under the Curaçao CGA AML/CFT Policy, CDD is mandatory for transactions at or above NAf 4,000 (approximately EUR 1,926), either as a single transaction or as a series, combination, or pattern of transactions totalling that amount. Enhanced due diligence applies to high-risk customers, and the policy explicitly states that “in situations presenting a higher risk of ML/TF, source of funds information has to be requested from time to time even though there may not be any change in pattern or activity conducted by the customer,” making SoF enquiry an ongoing obligation for elevated-risk accounts, not a one-time onboarding check.
Source: Curaçao CGA AML/CFT Policy: Anti-Money Laundering and Counter-Financing of Terrorism, Gibraltar Gambling Commissioner, AML Code of Practice for Remote Gambling v.1.0.2026, UKGC LCCP Condition 12.1.1 (version effective 6 April 2026); AGLC SRIG 2026-03-17, FINTRAC PCMLTFA, 31 CFR Part 1021 (FinCEN).
| Jurisdiction | Regulator | SoF Trigger / Threshold | Framework |
|---|---|---|---|
| United Kingdom | UKGC | Risk-based, no fixed cash threshold, guided by business risk assessment and customer profile | LCCP Condition 12.1.1, Gambling Act 2005 |
| Malta | MGA / FIAU | €2,000 cumulative deposits (daily or 180-day rolling) as audit trigger, EDD for high-risk players | Gaming Act Cap. 583, MGA Compliance Audit Manual |
| Ontario (Canada) | AGCO / FINTRAC | CAD $10,000 single cash (FINTRAC LCT); risk-based SoF per Registrar’s Standards, EDD at CAD $25,000 deposit threshold for high-risk players (per enforcement action) | PCMLTFA, AGCO Registrar’s Standards for Internet Gaming |
| Alberta (Canada) | AGLC / FINTRAC | Risk-based per operator’s programme, CAD $10,000 cash (FINTRAC); SoF corroboration situations defined by operator policy | PCMLTFA, AGLC SRIG 2026-03-17 |
| United States | FinCEN / State regulators | USD $10,000 cash (CTR); USD $5,000 suspicious (SAR); SoF for high-value play where ML is suspected | Bank Secrecy Act, 31 CFR Part 1021 |
| Curaçao | Curaçao GCB / CGA | NAf 4,000 (~EUR 1,926) for standard CDD, EDD ongoing for elevated-risk accounts | CGA AML/CFT Policy, NORUT, NOIS |
| Gibraltar | Gambling Commissioner | Risk-based, mandatory SoF + SoW for all PEPs, risk-sensitive approach for high-value customers | Proceeds of Crime Act 2015 (POCA); AML Code of Practice v.1.0.2026 |
How Risk Rating Governs Verification Depth
A flat SoF check applied identically to every player above a deposit threshold is not a risk-based approach. Regulators across all major frameworks expect the depth and scope of SoF verification to scale with the risk presented by the customer and the transaction.
The Curaçao CGA AML/CFT Policy identifies the specific customer risk factors that escalate the SoF obligation: customers with multiple sources of income, customers with irregular income streams, PEPs, high-spenders where income source is unclear, casual customers exhibiting changed spending patterns, and customers using multiple casino accounts. For each category, the assessment drives the documentary response. A low-risk customer may require nothing more than a self-declaration reviewed against open-source information, while a high-risk customer requires verified documentation from independent and reliable sources.
The Gibraltar AML Code of Practice (v.1.0.2026) makes the graduated approach explicit. Under section 6.13, licence holders may use third-party databases and information services for due diligence purposes but remain fully responsible for the outcome of that process. Third-party reliance does not discharge the CDD obligation. The Gibraltar code states that an inference about a customer’s identity or funds drawn from their deposit method “is merely one aspect of building up a customer profile and not a substitute for effective CDD measures.” The fact that a player deposits via a regulated retail bank account does not, by itself, verify source of funds.
“In situations presenting a higher risk of ML/TF, source of funds information has to be requested from time to time even though there may not be any change in pattern or activity conducted by the customer.”
The FATF Risk-Based Approach Guidance for Casinos is referenced by Spillemyndigheden’s AML guidance (Version 1.2) as a primary typology source for Danish online gambling operators. The FATF framework, which underpins all of these national regimes, treats the casino sector as inherently higher risk and requires that risk assessments be documented, regularly updated, and supported by relevant data, including national and supranational risk assessment findings. According to industry reporting, FATF issued guidance warning to regulatory authorities that gambling platforms are increasingly being used for money laundering, specifically naming brick-and-mortar and online casinos and sports betting as “particularly exposed to money laundering risks.”
What Documentation Is Acceptable?
No single universal list of acceptable SoF documents exists across jurisdictions, because regulators deliberately preserve flexibility. The consistent principle across frameworks is verification: a document is acceptable only if the operator can independently corroborate what it asserts, either through public sources or by cross-referencing the document itself against known account data.
For employment income, payslips covering a period consistent with the deposits in question, accompanied by a recent bank statement showing the salary credit, represent the standard acceptable combination. A payslip alone, without corroboration in bank records, is generally insufficient at EDD level.
For investment or business income, the Gibraltar code and the Curaçao CGA policy both identify public sources as the starting point. Share ownership, company directorships, and dividend income can often be partially verified through Companies House (UK), the Chamber of Commerce (Curaçao), or equivalent public registries before a document request is made. Where public sources cannot sufficiently verify the information, operators may then request supporting documents: sale agreements for property or shares, dividend statements, business accounts.
For gambling winnings as a declared source, operators must exercise particular scrutiny. A player claiming prior gambling winnings as their funding source presents a circular verification challenge. Regulators expect operators to seek corroborating evidence such as withdrawal records from the originating platform or confirmation from the sending institution, rather than accepting a self-declaration at face value.
For cryptocurrency holdings, the Curaçao CGA treats crypto users as a high-risk category triggering EDD by default. Exchange account statements, blockchain transaction records, and wallet-to-bank transfer documentation are expected. Gibraltar’s code warns that payment methods with no identity verification or due diligence procedures, citing e-money vouchers and virtual currencies explicitly, must be treated with proportionate caution, and that disproportionate use of such methods in gambling transactions is itself a red flag.
“The casino requests a statement from the player about the source of funds and verifies that by consulting independent and reliable sources. Depending on the risk in specific cases, these can in the first place be public sources. When public sources cannot, or can insufficiently verify the received information, the casino can request the customer to provide additional documents.”
The Curaçao CGA AML/CFT Policy defines this verification sequence precisely. The obligation is not simply to collect a statement, but to verify it. If that verification cannot be completed, because the player refuses to provide documentation or the documents provided cannot be authenticated, the business relationship must not be commenced or must be terminated, and the casino must consider whether an unusual transaction report is required.
The UK Affordability Check Intersection: Separate Regimes, Separate Purposes
A persistent source of confusion in the UK market is the relationship between the UKGC’s forthcoming financial risk assessment (FRA) framework and the existing AML obligation under LCCP Condition 12.1.1. They operate in parallel and must not be conflated.
The FRA framework, confirmed by the UKGC and government in July 2026, introduces two tiers of check calibrated to customer losses. Light checks apply to customers losing more than £125 over 30 days or £500 over a year, using publicly available data such as bankruptcy records. Enhanced risk assessments apply to customers losing more than £1,000 within 24 hours or £2,000 over 90 days, using credit reference agency data to identify signs of serious financial distress. The UKGC’s target is that approximately 97% of these checks complete automatically, with only around 3% of accounts requiring further review.
According to UKGC statements, the checks piloted will not make an assessment of what each customer can afford to gamble, and operators will not be required to ask for financial documents such as bank statements as a result of an FRA. This is a consumer protection instrument, not an AML instrument. Its purpose is to identify financial vulnerability and distress, not to establish the legitimacy of the player’s funding source.
The AML obligation under LCCP Condition 12.1.1 remains entirely separate. A player who passes an FRA, meaning credit data shows no indicators of financial distress, may still be subject to an SoF check under the operator’s AML risk assessment if their deposit or betting patterns raise money laundering concerns. The FRA result is irrelevant to the AML trigger. Operators who treat a clean FRA result as discharging their SoF obligation are misconstruing both frameworks.
Key distinction: The UK’s financial risk assessment determines whether a player appears to be in financial distress (consumer protection). Source of funds verification determines whether the money being deposited is legitimate (AML). A high-net-worth player may pass every FRA check while still presenting an ML risk that requires SoF investigation. Both obligations must be met independently.
Ongoing Monitoring and Re-Verification
SoF verification is not a static, once-at-onboarding event. Every major framework reviewed here requires ongoing monitoring of the business relationship, with re-verification triggered by changes in the customer’s risk profile or transaction patterns.
The Curaçao CGA policy requires casinos to consider obtaining evidence of identity and source periodically, refresh data on key events such as a change in payment instrument, and track expiry dates on documentary evidence. If a player switches from credit card to cryptocurrency or from modest deposits to high-value frequent deposits, the risk assessment must be revisited and, where warranted, SoF re-established.
Gibraltar’s AML Code of Practice identifies transactional monitoring as “an important part of the process (particularly in the case of customers who increase their rate of spend)” and characterises it as “an area of historical weakness for some gambling operators.” An operator that conducts SoF at onboarding but applies no subsequent monitoring fails this standard. The code makes clear that even deposits received through the retail banking system do not warrant positive assumptions about the adequacy of transactional monitoring in that sector.
For compliance teams at multi-licence operators, ongoing monitoring rules for individual customers must reflect the most stringent applicable jurisdiction’s requirements, not a single harmonised approach drawn from the least demanding regime. Where an operator serves players under both an MGA licence and a UK Gambling Commission licence, the UK regime’s AML expectations apply to UK-facing customers, and the MGA’s framework, administered jointly with the FIAU, applies to players in other permitted territories.
Enforcement Trends: What Regulators Are Finding
Across jurisdictions, enforcement patterns reveal consistent themes. SoF failures cluster around three failure modes: the check was not triggered at all despite clear risk indicators, the check was triggered but documentation was accepted without independent verification, and SoF procedures existed in policy but were not operationally implemented.
According to regulatory sources, enforcement actions have illustrated the second and third failures, with findings that operators had “insufficient controls to act in a timely manner to identify” high-risk customers, that SoF assessments were inadequate, and that SAR submissions were delayed. These enforcement outcomes have included disgorgement components and investigation costs, a structure that has become standard in regulatory settlements.
The Evolution £4.75 million UKGC settlement, reached in 2025, exposed a different vector: the AML risk assessments were outdated, and inadequate monitoring of third-party operator relationships allowed games to be accessed on unlicensed sites. The SoF dimension here was systemic rather than customer-specific. Evolution could not demonstrate that its distribution chain was subject to equivalent AML controls.
In Nevada, enforcement actions demonstrate that regulators treat SoF failures in high-stakes play as categorically serious, regardless of whether ML was actually proven. The standard applied is that the casino “knew, suspected, or had reason to suspect,” a lower bar than actual knowledge of ML activity.
Atlantic Lottery Corporation’s CAD $212,025 FINTRAC fine in July 2026 involved three violations: failure to report suspicious transactions, outdated compliance policies, and inadequate risk assessments. The corporation chose to pay without appeal rather than contest. FINTRAC’s enforcement context that year, with notices of violation totalling significant amounts across all industries, signals the regulator’s escalating posture on reporting entity compliance.
For operators managing the AML compliance function across multiple regulated markets, the consistent message from enforcement actions is that passive SoF policies, procedures documented but not operationally wired to monitoring and alert systems, satisfy no regulator’s standard. The obligation is to verify, document, and act, not to create the paper record of having asked.
Practical Implementation: What Compliance Teams Must Build
Effective SoF compliance requires system design, not just policy drafting. At the operational level, the following components are required across all major frameworks.
A customer risk rating methodology that scores players at onboarding and updates that score dynamically as transaction history develops. The risk rating must drive verification depth. Low-risk customers receive standard CDD, high-risk customers receive EDD including SoF and potentially SoW, and PEPs receive EDD plus senior management approval as a precondition for continued operation of the account.
Deposit and behaviour thresholds wired to automated alerts, calibrated to the most stringent applicable jurisdiction’s requirements. For a multi-jurisdiction operator, the alert architecture must be configurable by player country of residence and applicable licence. The MGA’s €2,000 cumulative deposit trigger and FINTRAC’s CAD $10,000 cash transaction trigger must both be live in the system, applied to the relevant player population.
A verification workflow that begins with open-source and public-data checks before escalating to documentary requests. As the Curaçao and Gibraltar frameworks both require, the operator must demonstrate that it first exhausted available public information before placing a document burden on the player. This sequencing matters for audit and enforcement purposes.
Documented outcomes for every SoF check, including the evidence reviewed, the conclusion reached, and the action taken. Where a check was triggered and not completed because the player refused to provide documentation, the file must record the refusal, the decision to restrict or close the account, and the SAR analysis, regardless of whether an SAR was ultimately filed.
Operators holding a UKGC licence alongside an MGA licence face dual reporting lines: the UKGC as the gambling-specific AML supervisory body under the Money Laundering Regulations 2017, and the FIAU in Malta for MGA-licenced operations. Each has its own SAR/UTR reporting mechanism, and compliance teams must ensure that the right report goes to the right FIU for transactions involving players in the relevant jurisdiction.
Qualified legal counsel should be retained for jurisdiction-specific application of these frameworks, particularly where an operator serves players across multiple regulated territories or where the customer risk profile involves PEPs, high-value accounts, or cryptocurrency funding sources. To deepen your understanding of these complex regulatory environments, review the Key Resources section below and consult with your compliance team about how these frameworks apply to your specific licence portfolio.
Key Resources
UKGC LCCP Condition 12.1.1, Anti-money laundering: Prevention of money laundering and terrorist financing. Available at: gamblingcommission.gov.uk. Version effective 6 April 2026.
UKGC AML Hub, Includes the Gambling Commission’s money laundering risk assessment 2026 (published 30 July 2026) and guidance on AML responsibilities for casino businesses. Available at: gamblingcommission.gov.uk/licensees-and-businesses/aml.
Gibraltar Gambling Commissioner, Code of Practice for the Remote Gambling Industry: AML/CFT/CPF Arrangements, v.1.0.2026 (issued 8 January 2026). Available at: gibraltar.gov.gi/new/remote-gambling.
Curaçao CGA AML/CFT Policy, Anti-Money Laundering and Counter-Financing of Terrorism policy document. Available via the Curaçao Gaming Authority.
FINTRAC Casino Client Identification and KYC Requirements, Guidance under PCMLTFA and associated Regulations. Available at: fintrac-canafe.gc.ca.
31 CFR Part 1021, FinCEN Rules for Casinos and Card Clubs, Current to 26 May 2026. Available at: ecfr.gov.
MGA Compliance Audit Manual, MGA/G/001, v.August 2018. Issued by the Malta Gaming Authority under the Gaming Act (Cap. 583 of the Laws of Malta). Available at: mga.org.mt.
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.