Regulators across Malta, Gibraltar, the Isle of Man and the Netherlands are tightening scrutiny of how online casinos document their anti-money laundering and counter-financing of terrorism controls. A well-structured AML/CFT manual is no longer a box-ticking exercise; it is the operational backbone that connects your risk appetite to daily procedures, staff behaviour and audit outcomes. Below is a tested 90-day roadmap that compliance teams and MLROs can follow to move from a blank page to a fully embedded, regulator-ready manual.
Why a Phased Approach Works
Attempting to write every policy chapter simultaneously creates gaps, contradictions and staff confusion. A phased roadmap forces the compliance function to complete foundational decisions before building dependent procedures on top of them. It also produces a clear audit trail showing regulators that the programme was built deliberately rather than assembled reactively under enforcement pressure.
Phase 1: Foundation (Days 1 to 30)
Governance and Scope
Start by confirming the legal entities covered by the manual, the applicable licensing regimes and the jurisdictions from which your platform accepts players. Appoint or formally document the MLRO's mandate in writing, including reporting lines, delegated authority and escalation paths. This governance chapter becomes the spine of the entire manual.
Business-Wide Risk Assessment
Conduct or update your Business-Wide Risk Assessment (BWRA). Map your product types, payment channels, player demographics and geographic exposure against the FATF typologies most relevant to online gambling: structuring through deposits, bonus abuse layered with withdrawals, and third-party payment patterns. Score each risk domain and document the methodology. Regulators will ask for this document first in any inspection.
Gap Analysis Against Current Controls
Compare existing procedures, if any, against the BWRA findings and your licence conditions. Produce a gap register with owners and target closure dates. This register drives the remaining 60 days of work.
Phase 2: Policy and Procedure Drafting (Days 31 to 60)
Core Policy Chapters
Draft the following chapters in sequence, because each one informs the next:
- Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) standards, including trigger thresholds for your jurisdiction
- Source of Funds and Source of Wealth procedures, with decision trees for front-line agents
- Politically Exposed Persons (PEP) and sanctions screening, including your chosen screening vendor configuration and escalation timelines
- Suspicious Activity Reporting (SAR) and internal Suspicious Activity Report (iSAR) workflows, from initial flag to MLRO decision to external filing
- Transaction monitoring rules: alert logic, tuning rationale, and the review SLA for each alert tier
- Record-keeping obligations: data fields captured, retention periods and access controls
Operational Detail Matters
Vague policies fail in practice. Each chapter should specify who performs the action, what system or form they use, how long they have to complete it and where the outcome is recorded. A compliance officer reading the manual at 11 pm during an incident should be able to follow it without calling anyone.
"An AML manual that cannot be executed without institutional memory is a liability, not an asset. Procedures must be specific enough for a competent new hire to follow on day one."
Phase 3: Embedding and Testing (Days 61 to 90)
Training and Awareness
Policy chapters are only as effective as the staff who execute them. Deliver role-specific training covering customer-facing agents, payments reviewers, the MLRO and senior management. Document completion, assessment scores and any remediation. Many regulators require evidence of annual training cycles, so establishing this infrastructure now avoids a scramble at renewal.
Parallel Testing
Run a structured testing exercise against your transaction monitoring system using historical data or synthetic scenarios. Verify that alert thresholds fire correctly, that iSAR forms reach the MLRO queue and that SAR submissions can be completed within your jurisdiction's required timeframe. Document the results and any tuning changes made.
Internal Audit and Version Control
Commission an internal or external read-through of the completed manual against your licence conditions and any recent regulatory guidance published before the go-live date. Assign a document owner, establish a review cadence of at least every 12 months, and implement version control so every change is tracked with a date and rationale.
Ongoing Maintenance
A manual completed on day 90 begins to age on day 91. Build a trigger list of events that require an unscheduled review: a new payment method, entry into a new market, a material change in player demographics, or updated FATF guidance. Regulators assess whether your programme evolves with your business risk, not just whether it existed at the time of your licence application.



