Home  /  News  /  Compliance & AML
Compliance & AMLAugust 8, 2024

Choosing a PSP for High-Risk Gaming Merchants: A Compliance View

How iGaming operators can evaluate payment service providers through a compliance lens, reducing regulatory and financial risk from day one.

Choosing a PSP for High-Risk Gaming Merchants: A Compliance View

Selecting a payment service provider is one of the most consequential decisions an online casino operator makes, and approaching it purely on fee schedules or approval rates is a common and costly mistake. From a compliance standpoint, the PSP relationship defines a significant portion of your AML exposure, your chargeback liability and your ability to satisfy regulatory audits.

Why Gaming Is Treated Differently by Acquirers

Payment networks classify online gambling as a high-risk merchant category, primarily because of elevated chargeback rates, the potential for money laundering and the patchwork of licensing requirements across jurisdictions. Acquirers and processors that accept gaming merchants must themselves apply enhanced due diligence, which means they will impose stricter onboarding requirements, reserve accounts and monitoring conditions on you. Understanding that dynamic from the outset shapes how you negotiate and what you present during onboarding.

Compliance Criteria That Actually Matter During PSP Selection

Regulatory Standing and Jurisdiction of the Processor

A PSP's own licensing status is the first filter to apply. Look for processors that hold authorisations from recognised financial regulators such as the FCA, De Nederlandsche Bank, or a comparable EU National Competent Authority under PSD2. A processor operating in a lightly regulated jurisdiction may accept you quickly but will create downstream problems when your own licensing authority reviews your payment flow documentation.

AML and KYC Framework Compatibility

Your PSP must be able to demonstrate its own anti-money-laundering controls, because your regulator may ask you to evidence that your entire payment chain is compliant. Request the processor's AML policy summary, ask whether they conduct ongoing transaction monitoring, and confirm how they handle suspicious activity reports. A PSP that cannot answer these questions clearly is not ready for a regulated gaming relationship.

Accepted Jurisdictions and Restricted Country Lists

PSPs maintain their own lists of restricted geographies, and those lists rarely match your own GEO targeting perfectly. Before signing any agreement, compare the processor's restricted country schedule against your player acquisition markets. A mismatch creates a scenario where players from a permitted jurisdiction on your licence cannot actually transact, which damages revenue and creates support escalations.

Chargeback and Fraud Management Tools

Chargebacks in gaming carry a dual risk: direct financial loss and potential Visa or Mastercard monitoring programme placement, which can threaten your entire acquiring relationship. Evaluate whether the PSP offers real-time fraud scoring, velocity checks, 3DS2 implementation support and a clear chargeback dispute workflow. These features are not optional; they are compliance infrastructure.

Data Handling and GDPR Obligations

If you operate in the EU or accept European players, the PSP's data processing agreement must be GDPR-compliant. Confirm where transaction data is stored, how long it is retained and whether sub-processors are named and auditable. This matters during regulatory inspections and in the event of a data breach.

Structural Protections to Build Into the Contract

  • Rolling reserve terms: negotiate the percentage and the release schedule before signing, not after your first high-volume month.
  • Termination notice periods: aim for a minimum 90-day notice clause so you have time to onboard a backup processor.
  • Audit rights: include a clause giving you the right to request compliance attestations annually.
  • Liability caps and indemnities: understand who bears liability if the processor's own compliance failure causes a regulatory sanction against you.

Red Flags That Compliance Officers Should Escalate

Certain signals during PSP negotiations should trigger immediate escalation to your MLRO or legal counsel. These include processors who waive standard KYC on your business because you bring high volume, those who cannot name their correspondent banking relationships, and those who discourage you from asking about their own regulatory audits. Speed of onboarding is never a substitute for due diligence.

A PSP that is easy to board with is often easy to board with because they are not asking the questions your regulator will later expect you to have answered yourself.

The Practical Onboarding Checklist

  • Collect and review the PSP's most recent AML policy document.
  • Confirm their regulatory authorisation number and verify it on the relevant public register.
  • Map their restricted jurisdictions against your active GEOs.
  • Obtain their data processing agreement and forward to your DPO for review.
  • Run a test transaction flow including 3DS2 before going live.
  • Document the entire due diligence process for your compliance file.

The PSP selection process is, in effect, a compliance exercise. Operators who treat it as a purely commercial negotiation often discover the regulatory consequences well after the contract is signed.

FAQ

Frequently asked questions

What makes a payment service provider suitable for high-risk gaming merchants?

A suitable PSP for gaming merchants holds a recognised financial regulatory authorisation, maintains its own documented AML and KYC framework, and explicitly supports the merchant categories and jurisdictions relevant to the operator. It should also offer chargeback management tools, 3DS2 support and a GDPR-compliant data processing agreement. Operators should verify all of these elements before signing any agreement.

How should an iGaming operator assess a PSP's AML compliance?

Operators should request the PSP's AML policy document and confirm whether the processor conducts ongoing transaction monitoring and files suspicious activity reports where required. The PSP's own regulatory authorisation should be verified on the relevant public register. Because regulators can ask operators to demonstrate that their entire payment chain is compliant, a PSP that cannot provide clear AML documentation is unsuitable for a regulated gaming environment.

What contract terms are most important when signing with a PSP as a gaming operator?

The most important contractual protections include the rolling reserve percentage and its release schedule, termination notice periods of at least 90 days, annual audit rights over the PSP's compliance attestations and clearly defined liability caps. Operators should also ensure the contract specifies which sub-processors handle data, as this is relevant to GDPR obligations and regulatory inspections.

What are the red flags that a PSP is not appropriate for a licensed gaming operator?

Key red flags include a processor that waives standard KYC requirements in exchange for high transaction volume, an inability to name their correspondent banking relationships, and reluctance to provide information about their own regulatory audits or AML policies. An unusually fast onboarding process with minimal documentation requests is itself a warning sign rather than a benefit, as it often indicates inadequate compliance controls on the processor's side.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.