Bet365 has reached a formal agreement with the Australian Transaction Reports and Analysis Centre (AUSTRAC) to implement a structured remediation plan, bringing a compliance review process that began in 2022 to a defined resolution pathway. The case carries practical lessons for any operator managing AML obligations in regulated markets.
Background: How the Review Began
AUSTRAC first signalled concerns about Bet365's anti-money laundering and counter-terrorism financing (AML/CTF) processes in August 2022. The regulator subsequently mandated an external audit later that year to independently assess the operator's compliance framework. External audits of this kind are a standard AUSTRAC enforcement tool, used when a reporting entity's internal controls are considered insufficient or unclear.
The period between initial concern and a formal remediation agreement stretched across several years, illustrating how protracted regulatory engagement can become when systemic control gaps are identified. For compliance officers, this timeline is a reminder that early voluntary disclosure and proactive engagement with regulators typically leads to faster, less costly outcomes.
What a Remediation Plan Actually Means
A remediation plan agreed with a regulator is not a simple fine-and-move-on resolution. It typically involves:
- A detailed gap analysis of existing AML/CTF policies, procedures and controls
- Defined milestones and timeframes for implementing corrective measures
- Ongoing reporting obligations to the regulator confirming progress
- Potential for continued external oversight or follow-up audits
For Bet365, operating at significant scale in the Australian market, the remediation process will demand sustained internal resources and executive accountability. Regulators rarely treat remediation as a closed matter until every milestone is independently verified.
AUSTRAC's Regulatory Posture in Context
AUSTRAC has established itself as one of the more assertive AML regulators in the Asia-Pacific region. Its enforcement history includes substantial civil penalty proceedings against major financial institutions and gambling operators alike. The regulator expects reporting entities, including online wagering providers, to maintain transaction monitoring systems capable of detecting suspicious activity patterns in real time, and to file suspicious matter reports (SMRs) consistently and accurately.
Bet365's situation is not unique within Australian iGaming. The sector has faced increasing regulatory scrutiny as AUSTRAC applies the same standards to wagering operators that it expects of banks and remittance providers. Operators without robust customer due diligence (CDD) workflows, ongoing transaction monitoring, and a designated and empowered MLRO function are at material risk of similar engagement.
Operational Implications for Operators
From an operational standpoint, the Bet365 case reinforces several fundamentals that OnlineShine advises clients on regularly:
- MLRO resourcing: A nominal MLRO title without genuine authority, budget and reporting lines to senior management is a compliance liability, not an asset.
- Transaction monitoring calibration: Rule sets that are never reviewed produce alert fatigue or missed suspicious activity. Periodic tuning against current player behaviour is essential.
- Third-party audit readiness: Operators should be able to produce evidence of control effectiveness at short notice. Documentation discipline is as important as the controls themselves.
- Regulatory relationship management: When a regulator raises concerns, the response quality in the first 30 days often shapes the trajectory of the entire engagement.
The OnlineShine Perspective
Regulatory remediation is almost always more expensive and more disruptive than the compliance investment that would have prevented it. Operators who treat AML as a cost centre rather than a risk management function tend to find out the hard way.
OnlineShine provides outsourced MLRO and AML compliance services to iGaming operators across multiple jurisdictions. Our practitioners work alongside internal teams to build control frameworks that satisfy regulatory expectations and scale with business growth, before an external auditor is ever mandated.



