Home  /  News  /  Compliance & AML
Compliance & AMLJanuary 6, 2025

Age Verification in iGaming: What Regulators and Banks Expect

Regulators and banking partners now demand robust age verification from online operators. Here is what your compliance stack must include in 2025.

Age Verification in iGaming: What Regulators and Banks Expect

Age verification has moved well beyond a checkbox on a registration form. As of early 2025, both licensing authorities and the banks that process your payments are scrutinising how operators verify player age, and the gap between minimum compliance and what those partners actually expect is wider than most operators realise.

Why the Bar Has Risen

Several European regulators concluded 2024 by issuing updated technical standards that explicitly name age verification methods in their licensing conditions. At the same time, acquiring banks and payment processors have tightened their merchant onboarding requirements, partly in response to pressure from card schemes. The result is that an operator's age verification setup is now evaluated by at least two independent parties, and both have different, sometimes overlapping, criteria.

Regulators focus primarily on consumer protection and harm prevention. Banks focus on reputational risk and chargeback exposure. Satisfying one without the other is no longer a viable strategy for operators seeking stable payment processing.

What Regulators Are Looking For

Licensing bodies across the UK, Netherlands, Sweden and Germany have converged on several common expectations:

  • Pre-play verification: Age checks must be completed before a player can access real-money games, not at the point of first deposit. Operators allowing any session activity before identity is confirmed face formal findings.
  • Document-plus-liveness: A static document upload is no longer considered sufficient. Regulators now expect a liveness check, typically a selfie or short video, combined with automated document verification to reduce the risk of falsified IDs being used by underage individuals.
  • Credit reference database matching: Many jurisdictions require that age and identity be cross-checked against a recognised database, such as a credit bureau or national identity register, in addition to document review.
  • Audit trails: Full, timestamped records of every verification step must be retained and available for regulatory inspection, often for a minimum of five years.
  • Friction escalation protocols: If automated checks return inconclusive results, operators must have a defined manual review path with clear time limits for resolution and account restrictions applied in the interim.

What Banking Partners Require

Payment processors and acquiring banks approach age verification from a risk management perspective. Their concerns centre on three areas:

  • Documented vendor certifications: Banks want to see that the age verification tool itself holds recognised certifications, such as ISO 27001 for data security or certifications from the Age Verification Providers Association. An operator saying they use a reputable vendor is not the same as providing the vendor's compliance documentation.
  • Chargebacks and friendly fraud: When a cardholder claims they are not the registered account holder, a strong verification record, including a matched selfie and confirmed identity, gives the operator clear evidence to contest the dispute. Banks notice when operators lack this documentation.
  • Integration proof: Processors increasingly request technical evidence that verification is integrated at the account creation stage, not added as a later manual step. Screen recordings, API logs or third-party audit reports all serve this purpose.

The Operational Implications

Operators managing age verification as a pure compliance cost often underinvest in tooling and then face problems from two directions simultaneously: a regulatory finding and a payment partner review. The practical solution is to treat verification as a shared infrastructure component that serves both audiences.

Age verification documentation prepared for one regulator should be packaged so it can be adapted quickly for any banking partner review. A single source of truth, maintained by your compliance team, reduces duplication and response time significantly.

From an operational standpoint, operators should conduct quarterly internal audits of their verification stack, confirm vendor certifications are current, and maintain a clear escalation workflow for failed or inconclusive checks. Outsourcing the MLRO function or compliance management to a specialist partner can help smaller operations maintain this standard without building a full in-house team.

Vendor Selection Considerations

Not all age verification providers are equal in the eyes of regulators and banks. When evaluating vendors, operators should assess:

  • Coverage of national identity documents across your target markets
  • Availability of database cross-referencing for jurisdictions that require it
  • Data residency options, particularly important for EU-licensed operators under GDPR
  • Responsiveness of the vendor's own compliance team when regulators request information

The vendor's ability to produce a certification pack at short notice, and to participate in regulatory correspondence if needed, is a practical differentiator that operators rarely check during procurement but frequently need later.

FAQ

Frequently asked questions

What age verification methods do online gaming regulators currently accept?

Most major European regulators now require a combination of automated document verification and a liveness check, such as a selfie matched against the submitted ID, completed before a player accesses real-money games. Many jurisdictions additionally require a cross-reference against a credit bureau or national identity database. A static document upload alone is generally no longer considered compliant as of 2025.

Why do payment processors care about age verification in online gaming?

Acquiring banks and payment processors view inadequate age verification as a reputational and financial risk. If a dispute arises where a cardholder claims they are not the registered account holder, a complete verification record gives the operator grounds to contest the chargeback. Processors also face scrutiny from card schemes and therefore require documented evidence that age verification is integrated at account creation, not applied manually after the fact.

How long must online gaming operators retain age verification records?

Retention requirements vary by jurisdiction, but a minimum of five years is a common standard across several major European licensing regimes. Records must include timestamped logs of each verification step, the documents or data sources used, and any manual review decisions. These records must be available for regulatory inspection on request.

What should an operator do if an automated age verification check is inconclusive?

Operators must have a documented escalation protocol for inconclusive automated results. This typically involves restricting the account immediately, initiating a manual review with a defined completion deadline, and notifying the player of the temporary restriction. The entire escalation path, including timelines and the criteria used to reach a final decision, should be recorded and held as part of the player's compliance file.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.