Home  /  News  /  Compliance & AML
Compliance & AMLApril 16, 2025

Building a Casino AML/CFT Manual: A 90-Day Roadmap

A practical 90-day roadmap for online casino operators to build, document and embed a compliant AML/CFT manual from scratch.

Building a Casino AML/CFT Manual: A 90-Day Roadmap

Regulators across Malta, Gibraltar, the Isle of Man and the Netherlands are tightening scrutiny of how online casinos document their anti-money laundering and counter-financing of terrorism controls. A well-structured AML/CFT manual is no longer a box-ticking exercise; it is the operational backbone that connects your risk appetite to daily procedures, staff behaviour and audit outcomes. Below is a tested 90-day roadmap that compliance teams and MLROs can follow to move from a blank page to a fully embedded, regulator-ready manual.

Why a Phased Approach Works

Attempting to write every policy chapter simultaneously creates gaps, contradictions and staff confusion. A phased roadmap forces the compliance function to complete foundational decisions before building dependent procedures on top of them. It also produces a clear audit trail showing regulators that the programme was built deliberately rather than assembled reactively under enforcement pressure.

Phase 1: Foundation (Days 1 to 30)

Governance and Scope

Start by confirming the legal entities covered by the manual, the applicable licensing regimes and the jurisdictions from which your platform accepts players. Appoint or formally document the MLRO's mandate in writing, including reporting lines, delegated authority and escalation paths. This governance chapter becomes the spine of the entire manual.

Business-Wide Risk Assessment

Conduct or update your Business-Wide Risk Assessment (BWRA). Map your product types, payment channels, player demographics and geographic exposure against the FATF typologies most relevant to online gambling: structuring through deposits, bonus abuse layered with withdrawals, and third-party payment patterns. Score each risk domain and document the methodology. Regulators will ask for this document first in any inspection.

Gap Analysis Against Current Controls

Compare existing procedures, if any, against the BWRA findings and your licence conditions. Produce a gap register with owners and target closure dates. This register drives the remaining 60 days of work.

Phase 2: Policy and Procedure Drafting (Days 31 to 60)

Core Policy Chapters

Draft the following chapters in sequence, because each one informs the next:

  • Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) standards, including trigger thresholds for your jurisdiction
  • Source of Funds and Source of Wealth procedures, with decision trees for front-line agents
  • Politically Exposed Persons (PEP) and sanctions screening, including your chosen screening vendor configuration and escalation timelines
  • Suspicious Activity Reporting (SAR) and internal Suspicious Activity Report (iSAR) workflows, from initial flag to MLRO decision to external filing
  • Transaction monitoring rules: alert logic, tuning rationale, and the review SLA for each alert tier
  • Record-keeping obligations: data fields captured, retention periods and access controls

Operational Detail Matters

Vague policies fail in practice. Each chapter should specify who performs the action, what system or form they use, how long they have to complete it and where the outcome is recorded. A compliance officer reading the manual at 11 pm during an incident should be able to follow it without calling anyone.

"An AML manual that cannot be executed without institutional memory is a liability, not an asset. Procedures must be specific enough for a competent new hire to follow on day one."

Phase 3: Embedding and Testing (Days 61 to 90)

Training and Awareness

Policy chapters are only as effective as the staff who execute them. Deliver role-specific training covering customer-facing agents, payments reviewers, the MLRO and senior management. Document completion, assessment scores and any remediation. Many regulators require evidence of annual training cycles, so establishing this infrastructure now avoids a scramble at renewal.

Parallel Testing

Run a structured testing exercise against your transaction monitoring system using historical data or synthetic scenarios. Verify that alert thresholds fire correctly, that iSAR forms reach the MLRO queue and that SAR submissions can be completed within your jurisdiction's required timeframe. Document the results and any tuning changes made.

Internal Audit and Version Control

Commission an internal or external read-through of the completed manual against your licence conditions and any recent regulatory guidance published before the go-live date. Assign a document owner, establish a review cadence of at least every 12 months, and implement version control so every change is tracked with a date and rationale.

Ongoing Maintenance

A manual completed on day 90 begins to age on day 91. Build a trigger list of events that require an unscheduled review: a new payment method, entry into a new market, a material change in player demographics, or updated FATF guidance. Regulators assess whether your programme evolves with your business risk, not just whether it existed at the time of your licence application.

FAQ

Frequently asked questions

What should be in an online casino AML/CFT manual?

An online casino AML/CFT manual should cover the business-wide risk assessment, customer due diligence and enhanced due diligence procedures, PEP and sanctions screening processes, suspicious activity reporting workflows, transaction monitoring rules, record-keeping obligations and staff training requirements. Each section should specify who is responsible, which systems are used, and what timelines apply so that procedures can be followed without relying on institutional memory.

How long does it take to build an AML manual for an online casino?

A structured 90-day implementation plan is realistic for an online casino building an AML/CFT manual from scratch. The first 30 days focus on governance and risk assessment, days 31 to 60 on drafting policy and procedure chapters, and the final 30 days on staff training, system testing and internal audit. Operators with existing partial frameworks can compress the timeline, while those entering multiple jurisdictions simultaneously may need longer.

What is a Business-Wide Risk Assessment and why does it come first?

A Business-Wide Risk Assessment (BWRA) is a documented analysis of all money laundering and terrorist financing risks facing a specific gambling operator, mapped against its products, payment methods, customer base and geographic footprint. It must come first because every subsequent policy decision, including CDD thresholds and monitoring alert logic, should be calibrated to the risk levels identified in the BWRA. Regulators typically request the BWRA as their first document during an inspection.

How often should an online casino review its AML/CFT manual?

Online casinos should formally review their AML/CFT manual at least once every 12 months, but they should also conduct unscheduled reviews whenever a material business change occurs, such as launching a new payment channel, entering a new regulated market or receiving updated guidance from their licensing authority or FATF. Maintaining a trigger list of events that prompt an unscheduled review is considered good practice and demonstrates to regulators that the compliance programme evolves alongside business risk.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.