An AML/CFT manual is no longer a formality operators can draft once and file away. Regulators across Malta, Gibraltar, the Isle of Man and several emerging markets have sharpened their expectations considerably over the past eighteen months, and the gap between a compliant manual and a decorative one is now wide enough to cost operators their licences.
Why the Compliance Baseline Has Shifted
The Financial Action Task Force updated its guidance on virtual assets and high-risk customer segments in 2023 and 2024, and national supervisors have since translated those updates into enforceable expectations. The Malta Financial Services Authority and the Malta Gaming Authority have both issued clarifications requiring licensees to reflect source-of-funds thresholds and enhanced due diligence triggers directly inside their written procedures, not just inside their risk assessments. Meanwhile, the EU's sixth Anti-Money Laundering Directive framework, which member states are progressively embedding into national law, has introduced stricter beneficial-ownership verification requirements that cascade directly into casino onboarding flows.
For operators, this means a manual written in 2022 is almost certainly missing mandatory sections. The practical consequence is that an audit or an MGA supervisory visit can produce findings even when the operator's actual day-to-day controls are sound, simply because the written procedures do not document what staff are doing.
Core Sections Every Manual Must Cover
1. Governance and Ownership of the Policy
The manual must name a designated Money Laundering Reporting Officer, confirm their reporting line to the board, and specify the review cadence. Most regulators now expect at least an annual review with a documented board sign-off, and a triggered review whenever the operator enters a new market or product vertical.
2. Risk Appetite and the Business-Wide Risk Assessment
The risk assessment is the engine of the manual. It should reflect the operator's specific player geography, payment method mix, average deposit and withdrawal volumes, and any affiliate or B2B relationships. Generic templates are a red flag for supervisors. The assessment must be version-controlled and linked explicitly to the controls described later in the manual.
3. Customer Due Diligence Procedures
This section needs to specify:
- Threshold triggers for standard, simplified and enhanced due diligence, expressed in currency amounts relevant to each licensed jurisdiction.
- The documents or data sources accepted for identity verification, including whether electronic verification is permitted and under what conditions.
- Source-of-funds and source-of-wealth procedures, including escalation paths when a player cannot satisfy a request promptly.
- Politically exposed person screening, including the definition used and the cadence for rescreening.
4. Transaction Monitoring Rules
Operators must document the specific scenarios and thresholds that generate alerts, whether those are system-generated or manually flagged. The manual should explain how alerts are reviewed, who reviews them, what escalation looks like, and how decisions are recorded. Regulators are increasingly asking to see alert-disposition logs during visits, so the manual must align precisely with what the system actually produces.
5. Suspicious Activity Reporting
The internal reporting chain and the external filing process to the relevant Financial Intelligence Unit must be written out step by step. Staff need to know how to submit an internal suspicion report without tipping off the customer, and the MLRO needs a documented process for deciding whether to file a Suspicious Activity Report externally.
6. Record Keeping
Most jurisdictions require a minimum five-year retention period for CDD records and transaction data. The manual should specify where records are stored, who controls access, and how records can be produced on regulatory request within the timeframe required by the relevant authority.
7. Training and Awareness
Staff training must be role-specific and documented. A customer-support agent needs different AML awareness content than a VIP manager or a finance officer. The manual should set out training frequency, how completion is recorded, and how new-joiner onboarding is handled.
What Operators Often Miss
The most common gap OnlineShine sees when reviewing operator manuals is the absence of a clear link between the risk assessment findings and the actual controls deployed. A manual that lists controls without explaining which risks they address will not satisfy a regulator looking for evidence of a risk-based approach. A second frequent gap is outdated payment method coverage: crypto, e-wallets and buy-now-pay-later options added after the manual was first drafted are often not reflected in the CDD or transaction monitoring sections.
A well-built AML/CFT manual does two things simultaneously: it tells a regulator exactly how the operation handles financial crime risk, and it gives compliance staff a reliable reference they can actually use under pressure.
Practical Next Steps for Operators
- Commission a gap analysis against the current regulatory requirements in every jurisdiction where the licence is held.
- Update the business-wide risk assessment before revising the manual, since the controls must follow the risk picture.
- Version-control every draft and retain superseded versions, as regulators may ask to see the evolution of the document.
- Confirm that the MLRO has formally signed off on the final version and that board acknowledgement is minuted.



