Home  /  News  /  Compliance & AML
Compliance & AMLMay 7, 2025

Building an AML/CFT Manual for Your Online Casino in 2025

What online casino operators must include in an AML/CFT manual today, covering recent regulatory shifts and practical compliance steps.

Building an AML/CFT Manual for Your Online Casino in 2025

An AML/CFT manual is no longer a formality operators can draft once and file away. Regulators across Malta, Gibraltar, the Isle of Man and several emerging markets have sharpened their expectations considerably over the past eighteen months, and the gap between a compliant manual and a decorative one is now wide enough to cost operators their licences.

Why the Compliance Baseline Has Shifted

The Financial Action Task Force updated its guidance on virtual assets and high-risk customer segments in 2023 and 2024, and national supervisors have since translated those updates into enforceable expectations. The Malta Financial Services Authority and the Malta Gaming Authority have both issued clarifications requiring licensees to reflect source-of-funds thresholds and enhanced due diligence triggers directly inside their written procedures, not just inside their risk assessments. Meanwhile, the EU's sixth Anti-Money Laundering Directive framework, which member states are progressively embedding into national law, has introduced stricter beneficial-ownership verification requirements that cascade directly into casino onboarding flows.

For operators, this means a manual written in 2022 is almost certainly missing mandatory sections. The practical consequence is that an audit or an MGA supervisory visit can produce findings even when the operator's actual day-to-day controls are sound, simply because the written procedures do not document what staff are doing.

Core Sections Every Manual Must Cover

1. Governance and Ownership of the Policy

The manual must name a designated Money Laundering Reporting Officer, confirm their reporting line to the board, and specify the review cadence. Most regulators now expect at least an annual review with a documented board sign-off, and a triggered review whenever the operator enters a new market or product vertical.

2. Risk Appetite and the Business-Wide Risk Assessment

The risk assessment is the engine of the manual. It should reflect the operator's specific player geography, payment method mix, average deposit and withdrawal volumes, and any affiliate or B2B relationships. Generic templates are a red flag for supervisors. The assessment must be version-controlled and linked explicitly to the controls described later in the manual.

3. Customer Due Diligence Procedures

This section needs to specify:

  • Threshold triggers for standard, simplified and enhanced due diligence, expressed in currency amounts relevant to each licensed jurisdiction.
  • The documents or data sources accepted for identity verification, including whether electronic verification is permitted and under what conditions.
  • Source-of-funds and source-of-wealth procedures, including escalation paths when a player cannot satisfy a request promptly.
  • Politically exposed person screening, including the definition used and the cadence for rescreening.

4. Transaction Monitoring Rules

Operators must document the specific scenarios and thresholds that generate alerts, whether those are system-generated or manually flagged. The manual should explain how alerts are reviewed, who reviews them, what escalation looks like, and how decisions are recorded. Regulators are increasingly asking to see alert-disposition logs during visits, so the manual must align precisely with what the system actually produces.

5. Suspicious Activity Reporting

The internal reporting chain and the external filing process to the relevant Financial Intelligence Unit must be written out step by step. Staff need to know how to submit an internal suspicion report without tipping off the customer, and the MLRO needs a documented process for deciding whether to file a Suspicious Activity Report externally.

6. Record Keeping

Most jurisdictions require a minimum five-year retention period for CDD records and transaction data. The manual should specify where records are stored, who controls access, and how records can be produced on regulatory request within the timeframe required by the relevant authority.

7. Training and Awareness

Staff training must be role-specific and documented. A customer-support agent needs different AML awareness content than a VIP manager or a finance officer. The manual should set out training frequency, how completion is recorded, and how new-joiner onboarding is handled.

What Operators Often Miss

The most common gap OnlineShine sees when reviewing operator manuals is the absence of a clear link between the risk assessment findings and the actual controls deployed. A manual that lists controls without explaining which risks they address will not satisfy a regulator looking for evidence of a risk-based approach. A second frequent gap is outdated payment method coverage: crypto, e-wallets and buy-now-pay-later options added after the manual was first drafted are often not reflected in the CDD or transaction monitoring sections.

A well-built AML/CFT manual does two things simultaneously: it tells a regulator exactly how the operation handles financial crime risk, and it gives compliance staff a reliable reference they can actually use under pressure.

Practical Next Steps for Operators

  • Commission a gap analysis against the current regulatory requirements in every jurisdiction where the licence is held.
  • Update the business-wide risk assessment before revising the manual, since the controls must follow the risk picture.
  • Version-control every draft and retain superseded versions, as regulators may ask to see the evolution of the document.
  • Confirm that the MLRO has formally signed off on the final version and that board acknowledgement is minuted.
FAQ

Frequently asked questions

What must an AML/CFT manual for an online casino include?

An online casino AML/CFT manual must cover governance and MLRO responsibilities, a business-wide risk assessment, customer due diligence procedures including enhanced due diligence triggers, transaction monitoring rules and alert-handling processes, suspicious activity reporting procedures, record-keeping requirements, and a staff training framework. Each section should be linked explicitly to the operator's specific risk profile rather than using generic language.

How often should an online casino review its AML/CFT manual?

Most licensing jurisdictions, including those governed by the Malta Gaming Authority, expect operators to review their AML/CFT manual at least once every twelve months, with a formal board sign-off documented in board minutes. A triggered review is also required whenever the operator launches in a new market, adds a significant new payment method, or when material regulatory guidance is updated by the relevant authority.

What has changed in AML compliance requirements for online casinos recently?

Between 2023 and 2025, the Financial Action Task Force updated its guidance on virtual assets and high-risk customer segments, and EU member states began embedding the sixth Anti-Money Laundering Directive into national law. These changes require operators to document stricter beneficial-ownership verification steps, reflect updated source-of-funds thresholds in their written procedures, and ensure transaction monitoring rules cover newer payment methods such as cryptocurrency and digital wallets.

What is the role of an MLRO in an online casino compliance manual?

The Money Laundering Reporting Officer is the accountable individual named in the AML/CFT manual who oversees the operator's financial crime controls, receives internal suspicion reports from staff, decides whether to file Suspicious Activity Reports with the relevant Financial Intelligence Unit, and signs off on the manual itself. The MLRO's reporting line to the board and their authority to act independently on compliance matters must be stated explicitly within the manual.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.