Skip to content
2,183 standards indexed across 19 jurisdictions View the Atlas
Daily news + multi-week series Browse all insights
8 tools live Roadmap
AML · KYC 14 min read Sep 21, 2026

Source of Wealth vs. Source of Funds: The Distinction Regulators Will Actually Audit

SoW and SoF are distinct legal obligations. Learn what evidence each demands under UKGC, MGA, and FATF frameworks, and why getting it wrong costs six figures.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Sep 21, 2026 14 min read Filed AML & KYC

Source of Funds tells you where a deposit came from. Source of Wealth tells you how a person built their net worth. These are not variations of the same question, they are legally distinct obligations under every FATF-aligned gambling framework, and collecting one while the regulator expected the other is the compliance failure that appears most often in enforcement statements. According to the UK Gambling Commission’s August 2026 public statement on QuinnBet (Gibraltar) Limited, inadequate Source of Funds assessments constitute a specific breach of Licence Condition 12.1.1. The Malta Gaming Authority’s Compliance Audit Manual treats each as a separate audit line item. Getting the distinction wrong is not a technicality, it is the difference between a clean audit and a six-figure settlement.

What Source of Funds actually means

Source of Funds (SoF) refers to the origin of the specific money a customer is using to fund gambling activity at a given point in the relationship. It is a transactional question. The customer deposited £5,000 this week: which account did it come from, and how did those funds arrive in that account? The answer may be a salary payment, a property rental receipt, a savings transfer, or a business dividend. SoF is granular and contemporaneous, relating to the funds in motion rather than to the customer’s broader financial picture.

Under the UKGC’s framework, SoF sits within the enhanced customer due diligence obligations that flow from Licence Condition 12.1.1 of the Licence Conditions and Codes of Practice. LC 12.1.1 requires licensees to have appropriate policies, procedures and controls to prevent money laundering and terrorist financing following completion of the risk assessment, and further requires that those policies and controls are kept under review. According to the QuinnBet public statement published on 20 August 2026, the operator breached paragraphs 2 and 3 of LC 12.1.1 specifically because it had insufficient controls to act in a timely manner to identify and assess customers who presented SoF risk, and delayed filing Suspicious Activity Reports to the National Crime Agency.

Enforcement reference: According to enforcement sources, QuinnBet (Gibraltar) Limited agreed a regulatory settlement with the UK Gambling Commission on 20 August 2026 following a compliance review spanning March 2023 to August 2025. The public statement cites inadequate Source of Funds assessments and delayed SAR filing as named breaches of LCCP Licence Condition 12.1.1.

Acceptable SoF evidence for a remote gambling customer will typically include recent bank statements showing the inbound salary or dividend credit, a payslip corroborating the stated employment income, or documentation of a specific liquidity event such as a property sale completion statement. The key requirement is that the evidence is contemporaneous: it must relate to the specific funds being deposited, not to a historical financial picture that may no longer reflect the customer’s current position.

What Source of Wealth actually means

Source of Wealth (SoW) is a broader, biographical question. It asks how a customer accumulated their total assets and net worth over time. A customer who has accumulated £800,000 in liquid assets needs to be able to explain the origin of that wealth, not merely of this week’s deposit. The distinction is critical because a person can provide entirely legitimate SoF documentation for individual deposits while the underlying wealth is of entirely unexplained or criminal origin.

The MGA Compliance Audit Manual makes this point operationally explicit. Section 6.17.12 of the manual, which governs the audit of customer due diligence for high-risk players, asks auditors to confirm whether the licensee is requesting the source of wealth and the source of funds, listed as two separate verification steps for the same customer. A licensee that has collected SoF only, without a documented SoW assessment, will generate a finding under that section regardless of how thorough the transactional checks have been.

“Indicate whether the Licensee is requesting the source of wealth and source of funds for high risk profile players.”, MGA Compliance Audit Manual, section 6.17.12

SoW evidence is necessarily broader and often harder to obtain than SoF evidence. Acceptable documentation includes tax returns across multiple years, company accounts for business owners, professional qualifications combined with career history for high earners, inheritance documentation, or investment portfolio statements where the provenance of capital can be traced. According to the Gibraltar AML Code of Practice for Remote Gambling (v.1.0.2026, issued 8 January 2026), where public sources cannot, or cannot sufficiently verify, the information received, licence holders can request the customer to provide additional documents. The Code also confirms that inferential reasoning from payment method alone is not sufficient, such an inference is merely one aspect of building a customer profile and is not a substitute for effective customer due diligence measures.

Where the two obligations diverge: a practical matrix

The confusion between SoW and SoF is compounded by the fact that they trigger in different circumstances, demand different evidence, and serve different analytical purposes. The table below maps the key operational differences as they apply under UKGC, MGA, and FATF-aligned frameworks including Gibraltar’s 2026 Code.

Dimension Source of Funds (SoF) Source of Wealth (SoW)
Core question Where did these specific deposited funds come from? How did this person accumulate their total net worth?
Temporal scope Contemporaneous, relates to funds in motion now Biographical, covers the customer’s lifetime financial history
Typical triggers Deposit thresholds, elevated transaction frequency, unexplained payment patterns High-value customers, PEPs, EDD designation, significant net-worth indicators
Acceptable evidence Bank statements, payslips, dividend confirmations, sale proceeds receipts Tax returns, company accounts, inheritance documents, portfolio statements, career history
UKGC reference LCCP LC 12.1.1, QuinnBet public statement (Aug 2026) LCCP LC 12.1.1 risk-based EDD, UKGC published AML guidance
MGA audit reference Compliance Audit Manual, section 6.17.12 Compliance Audit Manual, section 6.17.12 (separate line item)
Gibraltar Code reference AML Code of Practice v.1.0.2026, sections 6.16, 6.17 AML Code of Practice v.1.0.2026, section S.20 (PEPs)
FATF alignment Recommendation 10, Customer Due Diligence Recommendation 10 EDD, Recommendation 12, Politically Exposed Persons

How the UKGC operationalises the distinction

The Gambling Commission does not publish a standalone SoW/SoF definition document, but the distinction is embedded in the structure of LC 12.1.1 and in the pattern of enforcement statements published since 2022. LC 12.1.1 requires licensees to maintain a documented risk assessment and to implement policies, procedures and controls proportionate to that risk. The Commission’s accompanying guidance on anti-money laundering, referenced in ordinary code provision 2.1.1, directs casino licensees in particular to act in accordance with its published AML guidance.

The practical consequence is that a UKGC licensee’s AML policy must distinguish between the two concepts at the procedural level. A policy that uses “SoF” and “SoW” interchangeably, or that does not specify when each is required and what evidence satisfies each, will fail a compliance assessment. The QuinnBet review found that the operator’s controls were insufficient to identify SoF risk in a timely manner. That word “timely” is significant because it points not just to the existence of a procedure but to its operationalisation: how quickly the trigger fires, how quickly the customer interaction follows, and how quickly any SAR obligation is discharged. Delays between identifying SoF risk and filing a SAR are treated by the Commission as a breach, not merely an inefficiency.

According to industry sources, the reclassification of the UK gambling software sector from low to medium money-laundering risk, which the UKGC announced in 2026 following the Evolution investigation, extends the SoF/SoW obligation up the supply chain. B2B suppliers must now consider whether their contractual due diligence on operator clients reflects the same granularity. According to enforcement announcements, Evolution agreed a settlement in 2026 that arose partly because of outdated AML risk assessments and inadequate monitoring of third-party operators, a B2B failure in supply-chain oversight with direct parallels to SoF governance at the operator level.

The MGA and FIAU framework

MGA licensees operate under the Gaming Act (Chapter 583 of the Laws of Malta) and the Prevention of Money Laundering Act, with supervisory responsibility split between the MGA and the Financial Intelligence Analysis Unit (FIAU). The MGA’s Compliance Audit Manual governs what auditors will examine during a compliance inspection, and section 6.17.12 treats SoW and SoF as two discrete deliverables for high-risk players. An MGA audit that finds SoF documentation in the file but no SoW assessment for a customer flagged as high-risk will record a finding against the licensee regardless of how comprehensive the SoF documentation is.

The MGA’s funds management framework adds a specific monetary reference point. Under section 6.18.3 of the Compliance Audit Manual, the system must flag a deposit if the total accumulation of deposits equals or exceeds €2,000, calculated either on a daily basis or on a rolling 180-day period. As of the current version of the manual, this €2,000 threshold does not automatically require SoW, that depends on the overall risk profile of the customer, but it is a documented trigger for customer due diligence review. A licensee’s AML policy should map the relationship between this deposit trigger, the customer risk score, and the decision tree that determines whether SoF alone suffices or whether SoW is also required.

According to regulatory guidance, the MGA issued a directive ahead of the 2026 FIFA World Cup requiring licensed bookmakers to intensify monitoring of suspicious betting patterns. That directive reinforced the principle that enhanced due diligence is not a one-time event at onboarding but an ongoing obligation calibrated to changing risk profiles. A customer whose betting volume increases sharply during a major tournament may require a refreshed SoF assessment even if SoW was collected at account opening.

Gibraltar’s 2026 Code and the PEP dimension

The Gibraltar AML Code of Practice for Remote Gambling (v.1.0.2026), issued on 8 January 2026 under the authority of the Gambling Act 2005 and approved by the Minister for Gambling, provides the most operationally detailed treatment of the SoW/SoF distinction across any single regulatory document in this jurisdiction profile. It is directly relevant to any operator holding a Gibraltar remote gambling licence and instructive as a model for operators seeking to understand what FATF-aligned regulators expect.

“POCA requires that Licence Holders evaluate all PEP accounts in terms of specific approval for the account to continue, the source of funds and the source of wealth to be established and enhanced ongoing monitoring to be applied to the account.”, Gibraltar AML Code of Practice for Remote Gambling, v.1.0.2026, section S.20

For PEP accounts, the Code is unambiguous: both SoF and SoW must be established, a senior manager (the MLRO or a designated representative) must approve the continuation of the account on a risk-sensitive basis, and enhanced ongoing monitoring must be maintained throughout the relationship. The approval obligation is ongoing, it is not discharged by a one-time sign-off at onboarding.

The Code also addresses a common operator shortcut: the inference from payment method. Licence holders are expressly told that inferring SoF legitimacy from the use of a regulated payment method is not a substitute for effective customer due diligence. A customer depositing via a major credit card or regulated e-wallet does not thereby satisfy the SoF obligation. That inference is “merely one aspect of building up a customer profile.” This principle applies equally under the UKGC’s framework, where payment-method inference has appeared in enforcement statements as an insufficient substitute for documented SoF checks.

FATF alignment and the risk-based calibration problem

FATF Recommendation 10 sets the international standard for customer due diligence and specifies that enhanced measures must include identifying the source of wealth and the source of funds for high-risk customers. The FATF’s published guidance on the risk-based approach for the gambling sector emphasises that thresholds for triggering SoF and SoW checks must be calibrated to the specific risk profile of each customer, not applied as fixed monetary bands uniformly across a customer base.

This risk-based calibration requirement is where many operators fail structurally. A policy that triggers SoF at £10,000 cumulative deposits and SoW only for PEPs will be inadequate for a customer who deposits £9,800 frequently, maintains a high loss rate, and whose profile is otherwise inconsistent with their stated occupation. The FATF framework, and the UKGC’s interpretation of it through LC 12.1.1, requires the trigger to respond to the totality of the risk signal, not to a single numerical threshold.

According to regulatory documentation, Curaçao’s post-LOK AML/CFT framework, which entered into force under the Landsverordening op de Kansspelen on 24 December 2024, reflects the same FATF alignment. The Curaçao Gaming Authority’s AML/CFT policy requires casinos to take reasonable measures to establish the source of wealth and the source of funds for high-risk customers, including PEPs, and to verify SoF using independent and reliable sources rather than relying solely on the customer’s self-declaration. The formal structure parallels Gibraltar’s Code: self-declaration is a starting point, not a terminus.

The evidence file an auditor will actually inspect

When the UKGC, MGA, or Gibraltar Gambling Commissioner conducts a compliance inspection, the auditor will review a sample of customer files flagged as high-risk. For each file, the auditor will look for documentary evidence that the licensee has collected and assessed both SoF and SoW where the customer profile required it. A file that contains a payslip but no explanation of how a customer with a £35,000 salary has accumulated £200,000 in gambling deposits over three years will not satisfy the SoW requirement, regardless of how clean the SoF documentation is.

In practice, operators should structure their EDD files to contain four distinct categories of documentation. The customer profile should include occupation, employer, and stated net worth at the point of EDD trigger. The SoF file should include the specific bank statements, transfer records, or payment receipts that confirm the origin of deposits reviewed. The SoW file should include the broader wealth verification evidence proportionate to the customer’s net-worth profile, with a documented rationale for why the evidence is considered sufficient. The decision record should include the compliance officer’s or MLRO’s documented assessment of whether the evidence is consistent with the customer profile, and the outcome: whether the relationship continues, is modified, or is exited.

Absent one of these four components, the file will generate a finding on inspection. Absent the decision record, even a complete evidence file can fail because the auditor cannot verify that someone with appropriate authority reviewed and assessed the evidence rather than simply collecting it.

Source: UKGC, Licence Conditions and Codes of Practice, Licence Condition 12.1.1, UKGC Public Statement, QuinnBet (Gibraltar) Limited, 20 August 2026, MGA Compliance Audit Manual, sections 6.17.12 and 6.18.3, Gibraltar AML Code of Practice for Remote Gambling, v.1.0.2026 (issued 8 January 2026), sections S.20 and 6.16, 6.17, Curaçao CGA AML/CFT Policy, section III.4.

Frequently asked questions

What is the difference between source of funds and source of wealth in gambling compliance?

Source of Funds identifies the origin of the specific money a customer is depositing at a given time, for example salary income or a property sale. Source of Wealth establishes how the customer accumulated their total assets and net worth over their lifetime. Regulators including the UKGC and MGA treat these as separate obligations: collecting one without the other when both are required is a documented compliance breach.

When does a UKGC licensee need to collect source of wealth rather than just source of funds?

Under LCCP Licence Condition 12.1.1, the trigger is risk-based. SoW is required where the customer’s overall profile, cumulative spend, and risk indicators suggest that transactional SoF checks alone cannot adequately address the money-laundering risk. High-value customers, customers whose deposits are disproportionate to stated income, and any customer subject to enhanced due diligence will typically require SoW documentation in addition to SoF evidence. The UKGC does not publish a fixed monetary threshold at which SoW becomes mandatory, the assessment must respond to the totality of the risk signal.

How does the MGA audit source of wealth compliance?

The MGA Compliance Audit Manual, at section 6.17.12, requires auditors to confirm whether the licensee is requesting the source of wealth and the source of funds for high-risk players as two separate questions. A licensee that has SoF documentation only will produce a finding under that section. The MGA also applies a €2,000 cumulative deposit flag (daily or rolling 180-day basis) that triggers a customer due diligence review, within which the determination of whether SoW is additionally required depends on the customer’s risk profile.

Does payment method verification satisfy source of funds requirements?

No. According to the Gibraltar AML Code of Practice (v.1.0.2026, section 6.16), inferring SoF legitimacy from a customer’s use of a regulated payment method is not a substitute for effective customer due diligence. The same principle applies under UKGC guidance. Payment-method inference is “merely one aspect of building up a customer profile” and cannot replace documented, verified SoF evidence.

What enforcement consequences follow from inadequate source of funds checks?

According to the UKGC’s August 2026 public statement on QuinnBet (Gibraltar) Limited, inadequate SoF assessments and delayed SAR filing constitute specific breaches of LCCP Licence Condition 12.1.1. The Commission has also taken enforcement action against other operators where AML deficiencies including SoF failures contributed to the regulatory risk assessment.

Key resources

Compliance teams should consult the following primary sources directly and verify that their AML policies are tested against the current version of each document. Regulatory guidance in this area updates frequently, and the UKGC’s LCCP has been amended multiple times since 2022. Qualified legal counsel should be engaged for jurisdiction-specific application, particularly where a single operator holds licences across multiple frameworks simultaneously.

For a detailed comparison of how UKGC and MGA licence obligations differ across governance, compliance infrastructure, and cost, the analysis at UKGC vs MGA in 2026: Which Licence Actually Costs More to Maintain covers both frameworks including AML staffing and audit spend. The full text of the UKGC’s Licence Conditions and Codes of Practice, including Licence Condition 12.1.1, is navigable via the UKGC LCCP explorer, which tracks dated amendments to the rulebook.

Operators holding UKGC licences should consult the Licence Conditions and Codes of Practice in full (Licence Condition 12.1.1), the UKGC’s published AML guidance for casino and non-casino licensees, and enforcement public statements published on the UKGC public register. MGA licensees should consult the Prevention of Money Laundering Act (Malta), FIAU implementing procedures for remote gaming, and the MGA Compliance Audit Manual. Gibraltar licence holders should consult the AML Code of Practice for Remote Gambling v.1.0.2026 as their primary operational reference. All operators subject to FATF-aligned frameworks should review FATF Recommendation 10 and the associated interpretive notes on customer due diligence. Start by conducting an audit of your current EDD files using the four-component framework outlined in this article to identify any gaps in your SoF and SoW documentation before your next compliance inspection.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged AML & KYC

Browse all →

AML & KYC

Bonus Abuse and AML: How Free Bet Exploitation Creates Simultaneous Tax and Financial Crime Exposure

Sep 27 · 15 min read

AML & KYC

Self-Exclusion and AML: When Responsible Gambling Obligations Trigger Financial Crime Reporting

Sep 25 · 15 min read

AML & KYC

FINTRAC and AGLC AML Obligations in Alberta iGaming: Two Compliance Layers, One Operator

Sep 22 · 18 min read