Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
AML · KYC 14 min read Jul 16, 2026

Source of Funds vs Source of Wealth: Where Operators Draw the Line and Get It Wrong

Conflating source of funds with source of wealth is the single most cited AML failure in UKGC and MGA enforcement. Learn where the line is and how to draw it correctly.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Jul 16, 2026 14 min read Filed AML & KYC

Compliance teams at remote gambling businesses routinely conflate two legally distinct obligations: verifying the source of funds used to make a specific deposit, and establishing the source of wealth that constitutes a customer’s broader asset base. The UK Gambling Commission, the Malta Gaming Authority, and the Gibraltar Gambling Commissioner have each documented this conflation in enforcement casework. The consequence is not academic. Regulators find either that licensees applied the wrong instrument, requesting a bank statement when the risk profile demanded a wealth declaration, or applied no instrument at all because their policy threshold architecture made meaningful due diligence impossible.

The Definitions Regulators Rely On

FINTRAC’s regulatory glossary, adopted under the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (PCMLTFR, SOR/2002-184), provides the clearest codified distinction in the English-language regulatory world. Source of funds is defined as “the origin of the particular funds or VC used to carry out a specific transaction or to attempt to carry out a transaction. It is how the funds were acquired, not where the funds may have been transferred from.” Source of wealth, by contrast, is defined as “the origin of a person’s total assets that can be reasonably explained, rather than what might be expected. For example, a person’s wealth could originate from an accumulation of activities and occurrences such as business undertakings, family estates, previous and current employment income, investments, real estate, inheritance, lottery winnings, etc.”

These definitions reflect the FATF risk-based approach. SoF is transactional and bounded: it asks how a particular deposit entered the gambling account. SoW is relational and cumulative: it asks how the customer came to possess the total asset base they draw from. Both can be triggered by the same customer event, but satisfying one does not satisfy the other. A bank statement showing that a £20,000 deposit originated from a current account addresses SoF, it tells you nothing about whether the customer’s broader wealth is legitimate. A tax return or business ownership declaration addresses SoW, it does not confirm that the funds used for today’s deposit are not borrowed, gifted, or criminal in origin.

Definitional baseline: Source of funds = origin of the specific deposit (transaction-level). Source of wealth = origin of the customer’s entire asset base (relationship-level). Both may be required simultaneously for high-risk customers, but they are documented and assessed separately.

What Does UKGC Actually Require Under LCCP 12.1.1?

The Gambling Commission does not prescribe a single SoF or SoW document checklist in the Licence Conditions and Codes of Practice. LCCP Licence Condition 12.1.1, which applies to all operating licences except gaming machine technical and gambling software licences, imposes three core obligations. Licensees must conduct a risk assessment of the potential for their business to be used for money laundering and terrorist financing, reviewed at least annually or when circumstances change. They must ensure appropriate policies, procedures, and controls flow from that assessment. They must keep those controls effective, under review, and revised in line with any applicable learning or guidelines published by the Commission.

That third obligation, incorporating Commission learning, is where SoF and SoW conflation becomes an enforcement issue. The Commission has published AML and counter-terrorist financing casework trends, sector-specific guidance, and the 2023 money laundering and terrorist financing risks document covering the British gambling industry. Licensees who do not read and act on those publications are in breach of LC 12.1.1(3) regardless of how well-drafted their general AML policy may be.

“The diligent work of so many of you in the industry and the controls you put in place go a long way to mitigating against this higher risk. But we do need to see those efforts, those mitigations making an impact and keeping your businesses compliant with regulation and our rules.”

John Pierce, the Commission’s Director of Enforcement, made that point at the Gambling Anti-Money Laundering Group (GAMLG) Annual Conference on 10 June 2026. He also addressed AI and algorithmic controls directly, warning that operators deploying automated AML tools must be able to demonstrate those systems are actually delivering compliant outcomes: “If your business is considering this type of approach, make sure it’s delivering compliance before you launch it.” The implication for SoF and SoW processes is direct. An automated trigger that generates an SoF request where an SoW review was warranted is not a mitigating factor, it is evidence that the control was misconfigured.

Where the Threshold Architecture Fails

The most common structural error is threshold-setting that is not risk-based. The Gambling Commission’s December 2025 enforcement action against Done Brothers (Cash Betting) Limited, trading as Betfred, made this explicit. The Commission found that “thresholds at which the operator made enquiries regarding customers’ source of income were not appropriately risk based, with thresholds set at £15,000 losses and at £125,000 stakes in 365 days.” The finding was listed as an AML failure, not merely a process weakness. Done Brothers paid £825,000 in settlement.

The error is not that the thresholds were high, though they were. A risk-based approach requires that thresholds vary with the customer’s risk profile. A customer with a documented high-net-worth profile and a pattern of annual sport betting deposits may warrant a higher tolerance before SoF review is triggered. A customer whose betting pattern is erratic, who uses multiple payment methods, or whose declared occupation is inconsistent with their deposit volume should trigger SoF review at a much lower absolute threshold. Setting one number for all customers is the structural failure. Whether the document collected is labelled “source of funds” or “source of wealth” is secondary to whether the trigger architecture produces the correct review at the right time.

The Commission’s enforcement register across 2022 to 2025 shows the breadth of operators caught in this failure mode. Entain’s £17 million settlement in August 2022 and William Hill’s £19.2 million settlement in March 2023, both records at the time, each contained AML findings alongside social responsibility failures. The pattern of allowing customers to deposit and lose significant sums before any source enquiry was made appears in both cases. ProgressPlay Limited paid £1 million in August 2025, with AML failures again listed. Platinum Gaming Limited paid £10 million in October 2025.

Source: UK Gambling Commission, Enforcement Notice, £825,000 fine for Done Brothers (Cash Betting) Limited, 3 December 2025, UKGC Enforcement Register 2022, 2025, UKGC GAMLG Annual Conference, John Pierce speech, 10 June 2026.

How Does the MGA Frame These Obligations?

The Malta Gaming Authority handles AML supervision in a split model: the MGA retains licensing and operational supervision, while the Financial Intelligence Analysis Unit (FIAU) is the designated AML/CFT supervisory authority for MGA licensees. A compliance audit by the MGA may identify procedural SoF and SoW gaps, while a separate FIAU review addresses the underlying AML legal obligations under the Prevention of Money Laundering Act.

The MGA Compliance Audit Manual is specific. Checklist item 6.17.12 requires auditors to determine whether the licensee is “requesting the source of wealth and source of funds for high risk profile players.” This is a distinct checklist item, listed separately from the checklist item on enhanced due diligence for high-risk players and the item on politically exposed persons. The separation is meaningful: auditors are expected to confirm that the licensee treats SoW and SoF as two separate documentary requirements, not as interchangeable concepts resolved by a single document collection event.

Item 6.17.3 establishes that basic registration data must include date of birth, identity, permanent residential address, and a valid email address. Identity verification status is tracked at item 6.17.5. SoW and SoF reviews are layered above those baseline requirements for customers who have been risk-profiled as high-risk. The audit manual also captures the €2,000 cumulative deposit monitoring threshold at item 6.18.3: the system must be able to flag when total deposits equal or exceed €2,000, either on a daily basis or on a rolling 180-day basis. That trigger is an SoF alert, not an SoW alert, and licensees who treat the resulting document request as satisfying both obligations will fail the audit. Compliance teams responsible for MGA audit preparation should also review the MGA’s system audit documentation requirements, which intersect directly with how SoF and SoW evidence is stored and made retrievable.

Gibraltar’s Explicit SoF/SoW Framework

The Gibraltar Gambling Commissioner’s AML Code of Practice for Remote Gambling, updated in January 2026 to version v.1.0.2026, provides the most operationally detailed treatment of the SoF/SoW distinction in any British Isles or Crown Dependency jurisdiction. The Code states in its provision on payment method inferences that Gibraltar Licence Holders cannot rely on an inference from a deposit method to “validate a source of funds/wealth,” describing such an inference as “merely one aspect of building up a customer profile and not a substitute for effective CDD measures.”

The Code addresses PEPs with particular specificity. Its provisions on PEPs require that for any customer identified as a politically exposed person, the Licence Holder must “take adequate measures to establish the legitimacy of the source of funds used by the individual concerned,” with senior management or the MLRO approving the deposit and gambling arrangements on a risk-sensitive basis. Separately, under section 20 of the Gibraltar Proceeds of Crime Act (POCA), PEP accounts must have the source of wealth established, a requirement that sits alongside SoF and cannot be collapsed into it. A licensee who obtains an SoF document for a PEP deposit without separately establishing SoW has satisfied half of the legal obligation.

“Transactional monitoring is an important part of the process (particularly in the case of customers who increase their rate of spend) and, on the basis of past cases, an area of historical weakness for some gambling operators.”

That assessment from the Gibraltar AML Code’s section on ongoing monitoring describes exactly the pattern visible in UKGC enforcement. Operators whose systems flag a spending increase will generate a transaction-level SoF request. They will not automatically generate an SoW review unless their policy architecture explicitly connects spending-pattern changes to relationship-level risk reassessment. Most documented failures arise from this gap.

When Must SoW Be Collected Independently of SoF?

The answer is determined by risk profile, not by deposit threshold alone. SoW must be sought independently of SoF in at least four scenarios that appear across UKGC, MGA, and Gibraltar frameworks.

A customer is identified as a PEP. Under section 20 of the Gibraltar POCA, FATF Recommendation 12, and the MGA audit checklist items covering PEPs and source of wealth for high-risk players, SoW must be established for all PEP relationships alongside SoF for specific transactions. The PEP designation alone triggers the SoW obligation regardless of deposit size.

A customer’s spending pattern changes materially relative to their declared profile. A customer who declared self-employment income at registration and begins depositing amounts inconsistent with that income profile presents a disconnect between SoF (where did this specific deposit come from) and SoW (does the customer actually have legitimate assets of this scale). Both questions must be asked, because the SoF answer alone, “it came from my bank account,” does not resolve the SoW question.

A customer has accumulated total lifetime deposits that are disproportionate to their known or stated occupation. The MGA’s €2,000 cumulative deposit trigger is an SoF alert. For customers where cumulative deposits across months or years suggest significant wealth, the licensee’s risk assessment must determine whether an SoW review has become necessary. The Gibraltar Code’s section 6.6 on ongoing monitoring describes this as a further due diligence (FDD) obligation that increases as the relationship matures.

A customer presents an occupation or profile with inherent risk factors. Cash-intensive businesses, certain international business persons, individuals in sectors with elevated corruption risk, these profiles may require SoW enquiry from the point of onboarding, even before any threshold is reached.

Obligation Source of Funds (SoF) Source of Wealth (SoW)
Scope Specific deposit or transaction Customer’s total asset base
Trigger Risk-based threshold breach, suspicious activity High-risk profile, PEP, material profile inconsistency
Typical evidence Bank statement, payslip, sale proceeds receipt Tax return, business ownership records, estate documents, investment statements
Satisfies EDD alone? For transactional risk, yes For relationship risk, yes, but not transactional
MGA audit item 6.17.12 (combined with SoW) 6.17.12 (combined with SoF)
Gibraltar POCA obligation for PEPs PEP provision (SoF for deposits) Section 20 POCA (SoW mandatory)
FINTRAC definition source PCMLTFR SOR/2002-184 (SoF provision) PCMLTFR SOR/2002-184 (SoW provision)

The AI Problem in SoF and SoW Reviews

The Commission’s June 2026 GAMLG speech addressed a specific operational risk that is directly relevant to SoF and SoW processes: the deployment of AI and algorithmic tools that have not been validated to deliver compliant outcomes. John Pierce’s statement, that the evidence shows automated AML tools “simply aren’t delivering” in too many cases, reflects what the Commission is seeing in casework. For SoF and SoW specifically, the failure mode is an algorithm that triggers document collection requests based on deposit volume alone, without risk-profiling the customer to determine which type of review is actually required.

An AI system that generates an SoF document request whenever a deposit exceeds £5,000 satisfies the transactional monitoring obligation, but fails if the underlying risk assessment has already classified the customer as high-risk and SoW-eligible. The document collected, a bank statement, is the wrong instrument for the risk level identified. The Commission has been explicit that the instrument collected must match the risk profile: submitting an SoF document when the customer’s profile required an SoW review is a gap that automated systems can perpetuate at scale. For a B2B supplier like ProgressPlay, whose £1 million fine in August 2025 included AML failures across multiple operator sites, a misconfigured automated review system has multiplicative enforcement consequences.

The EU’s Evolving Framework and AMLA

At the EU level, the Anti-Money Laundering Authority (AMLA) launched in 2026 as a cooperative supervisory body, issuing a consultation in July 2026 calling on gambling licensees to participate in risk profiling and risk-based supervision guidance, according to SBC News reporting that month. MGA-licensed operators should monitor AMLA guidance as it develops, particularly any technical standards on customer risk profiling that may further define the relationship between SoF and SoW in the EU regulatory framework. The Gaming Act (Cap. 583) under which the MGA operates already requires licensees to comply with Malta’s Prevention of Money Laundering Act, which implements the EU’s Anti-Money Laundering Directives. Any AMLA-derived technical standards on risk profiling will feed into the FIAU’s supervisory expectations for MGA-licensed operators.

Operators holding both a UKGC remote operating licence and an MGA B2C gaming service licence face the practical challenge of maintaining two separate SoF/SoW threshold architectures calibrated to different regulatory risk expectations. The UKGC’s risk-based approach requires thresholds that are documented and justified by the operator’s own risk assessment. The MGA’s audit checklist is structured around high-risk player designation rather than absolute deposit thresholds. A single global policy that attempts to satisfy both with one threshold level is likely to be misconfigured for at least one jurisdiction.

Building a Defensible SoF/SoW Framework

A defensible framework requires four components that apply across UKGC, MGA, and Gibraltar licensing, and that align with FATF guidance on risk-based approaches.

The policy document must treat SoF and SoW as separate defined terms with distinct trigger conditions and distinct document requirements. A combined “SoF/SoW check” section is not compliant if it uses the same documentation table for both: auditors from both the UKGC and the MGA will identify this as evidence that the licensee does not understand the distinction.

Trigger thresholds must be risk-stratified. Operators should maintain at minimum three risk tiers: standard customers triggering SoF review at a threshold calibrated to their declared profile, elevated-risk customers triggering SoF review at a lower threshold and SoW review at a defined relationship-level event, and high-risk customers, including PEPs, triggering both from onboarding. The Betfred December 2025 finding that a single threshold across all customers was “not appropriately risk based” applies equally to any licensee using undifferentiated thresholds.

Escalation records must document which review was triggered, which documents were collected, and the compliance officer’s assessment of whether the evidence satisfied the specific risk being addressed. A bank statement accepted as SoW evidence, when the customer’s profile required a broader wealth declaration, is a documented failure that a third-party audit will surface.

Ongoing monitoring must include a mechanism for converting an SoF-eligible account into an SoW-eligible account as the relationship matures. The Gibraltar Code’s further due diligence concept and the MGA’s high-risk profile designation both contemplate this lifecycle transition. Operators whose monitoring systems treat each deposit as an isolated transaction, without feeding the cumulative pattern into a customer risk profile that can upgrade the required review type, are structurally exposed.

Compliance note: Qualified legal counsel should be engaged when designing or auditing SoF and SoW threshold architectures for any jurisdiction. The UKGC, MGA, and FIAU each apply jurisdiction-specific risk expectations that cannot be fully captured in a single cross-jurisdiction policy template. This article reflects regulatory requirements as published at the dates indicated, operators should verify current guidance directly with the relevant regulator.

Compliance teams managing AML obligations across multiple European licences should also review the UKGC’s current casework trends guidance, updated by the Commission as part of the ongoing learning requirement under LCCP 12.1.1(3). For a practical audit checklist and step-by-step remediation template, consult the SoF/SoW policy remediation guide to begin calibrating your threshold architecture to your specific risk profile and jurisdiction.

Key Resources

UKGC Licence Conditions and Codes of Practice, Licence Condition 12.1.1, gamblingcommission.gov.uk/licensees-and-businesses/lccp

UKGC GAMLG Annual Conference, John Pierce speech, 10 June 2026, gamblingcommission.gov.uk/news/article/gamlg-annual-conference-john-pierce-speech

UKGC Enforcement, £825,000 fine for Done Brothers (Cash Betting) Limited, 3 December 2025, gamblingcommission.gov.uk (enforcement notices)

MGA Compliance Audit Manual, section 6.17.12, mga.org.mt

Gibraltar AML Code of Practice for Remote Gambling, v.1.0.2026, gibraltar.gov.gi/new/remote-gambling

FINTRAC source of funds and source of wealth definitions, PCMLTFR, SOR/2002-184, as published at fintrac-canafe.gc.ca

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged AML & KYC

Browse all →

AML & KYC

Sweden AML and CTF Requirements: What SIFS 2019:2 Means for Licensed Casino Operators

Jul 17 · 13 min read

AML & KYC

UKGC Anti-Money Laundering: What UK Licensed Operators Must Have in Place

Jul 10 · 14 min read

AML & KYC

MGA AML Requirements: Malta’s Casino Due Diligence Framework Explained

Jul 3 · 16 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.