Closed-loop redemption is one of the most consequential yet underexplained payment concepts in online gambling operations. Get the policy wrong and you face chargebacks, scheme fines, acquiring bank terminations and, in some jurisdictions, regulatory sanctions. This guide walks operators through the core rules, the card scheme obligations that govern them, and the operational controls that keep you compliant.
What Closed-Loop Redemption Actually Means
In a closed-loop context, funds deposited by a specific payment method must be returned to that same method up to the deposited amount before any surplus is paid out via an alternative channel. The logic is straightforward: it defeats money laundering by preventing a criminal from depositing via card, accumulating winnings, and withdrawing to a different account or method not linked to the original source of funds.
Card schemes, primarily Visa and Mastercard, embed this requirement into their merchant rules and reinforce it through their acquiring relationships. For iGaming merchants, this is not a guideline; it is a contractual obligation that sits beneath your merchant agreement.
Card Scheme Rules You Must Understand
Both Visa and Mastercard publish merchant rules that are updated regularly. As of early 2025, the key obligations for gambling merchants cover three areas:
- Return-to-origin principle: Withdrawals must route back to the originating card up to the deposited amount. Only net winnings above that deposit amount may be routed elsewhere.
- Transaction matching: The BIN, card number hash or token used at deposit must be retained and matched to any subsequent withdrawal request. Most PSPs provide tokenisation tools that automate this matching, but operators must verify that their platform actually uses them.
- Time limits: Schemes set windows within which a return-to-source must be completed. Attempting a return on a cancelled or expired card is expected to trigger an alternative payout workflow, not a simple rejection. Operators must document what that workflow is.
Building a Compliant Withdrawal Workflow
A compliant workflow has four sequential gates that every withdrawal request passes through.
Gate 1: Payment Method Inventory
Your back-office system must hold a verified record of every deposit method a player has used, the amounts deposited by each method and the current status of each instrument. This inventory is the foundation of closed-loop enforcement and doubles as evidence during an AML audit.
Gate 2: Return-to-Origin Check
When a withdrawal is requested, your system calculates how much of the requested amount must return to each card or e-wallet on record. The player cannot override this at the cashier stage. Giving players a free choice of withdrawal method before the closed-loop obligation is satisfied is one of the most common compliance failures we see in operator audits.
Gate 3: Instrument Validity Verification
Before attempting a return, confirm the instrument is still active. Most card scheme rules require you to make a reasonable attempt, but a clean failure on an expired or cancelled card must be logged and escalated to your MLRO if the player then requests an alternative payout route. That escalation step is where many operators have gaps.
Gate 4: Net Winnings Payout
Only after the return-to-origin obligation is fully satisfied does the player qualify to receive net winnings through a second method. At this stage, your standard KYC, AML and source-of-funds checks apply to the secondary instrument.
Where AML and Payment Rules Intersect
Closed-loop redemption is not purely a payment operations matter. Your AML programme must reference it explicitly. If a player requests a withdrawal to a method that does not match their deposit history, that is a red flag under most national AML frameworks, including those aligned with FATF Recommendation 16 on payment transparency. Your MLRO should have a documented escalation path for these cases.
Closed-loop redemption enforcement is only as strong as the data layer beneath it. If your platform cannot reliably match deposit tokens to withdrawal requests, your AML controls have a structural gap regardless of how well-written your policy documents are.
Practical Checklist for Operators
- Confirm your PSP retains card tokens for the full player lifecycle, not just the session.
- Test your cashier flow to verify players cannot select an alternative withdrawal method before the closed-loop balance is zero.
- Document your expired-instrument escalation procedure and share it with your MLRO.
- Review your merchant agreement annually; scheme rules on gambling merchants are updated more frequently than most operators realise.
- Train customer support staff to recognise and escalate withdrawal disputes that may have a closed-loop dimension.
Common Mistakes and How to Avoid Them
The most frequent errors are platform-level rather than policy-level. Operators invest in well-drafted terms but run cashier systems that do not enforce them technically. A player facing no system-level barrier will naturally choose the most convenient withdrawal route, which may violate closed-loop rules and create a chargeback or scheme fine liability for the operator. Conduct a quarterly cashier audit that tests actual withdrawal flows, not just policy documents.



