Closed-loop redemption, the requirement that withdrawals return funds to the same payment instrument used for the original deposit, has moved from a best-practice recommendation to a near-universal compliance expectation in regulated iGaming markets. Operators who treat it as a technicality rather than a structural policy risk regulatory censure, card scheme penalties, and exposure to money-laundering accusations.
What Closed-Loop Redemption Actually Means
In payment processing terms, a closed-loop policy mandates that any payout to a player must travel back through the same funding source, up to the deposited amount on that instrument, before any surplus can be routed to an alternative method. A player who deposits 200 EUR by Visa must receive up to 200 EUR of any withdrawal back to that Visa card before a bank transfer or e-wallet can receive the remainder. The principle mirrors the refund logic that Visa and Mastercard already enforce on their merchant and acquirer networks.
Why Card Schemes Enforce This Rule
Visa and Mastercard include closed-loop or "return to origin" requirements in their gambling merchant category codes (MCC 7995 and related codes). The rationale is straightforward: allowing funds to exit through a different channel than they entered creates a layering opportunity identical to classical money-laundering typologies. Card schemes face reputational and regulatory pressure from card-issuing banks, and they pass that pressure directly to acquirers through contractual obligations. Acquirers in turn embed the rules in their merchant agreements with operators.
Non-compliance can trigger several consequences for operators:
- Chargeback liability shifting to the merchant
- Fines levied by the scheme through the acquiring bank
- Placement on monitoring programs such as Visa's VAMP or Mastercard's MATCH list
- Termination of the acquiring relationship
The AML Dimension Operators Often Underestimate
Beyond card scheme rules, closed-loop redemption intersects directly with anti-money-laundering obligations under the EU's AMLD framework and equivalent national laws. Allowing a player to deposit via card and withdraw via crypto, an unverified e-wallet, or a third-party bank account undermines the traceability requirement that financial intelligence units rely on. Regulators in Malta, the Netherlands, Sweden, and the UK have each cited inadequate withdrawal controls in enforcement actions over the past two years.
A well-drafted closed-loop policy should address three specific AML risks:
- Third-party funding: funds deposited by one person withdrawn by another
- Instrument switching: replacing a traceable card with an anonymous or pseudonymous method
- Structuring: splitting withdrawals across methods to stay below monitoring thresholds
Building a Practical Closed-Loop Policy
Operators need a written policy that maps every accepted deposit method to its permitted withdrawal counterpart. The policy should be embedded in the cashier system logic, not left to manual review. Key elements include:
- A payment method register that pairs deposit instruments with authorised return channels
- Automated cashier rules that block non-matching withdrawal requests at the point of submission
- A documented exception process for expired cards, with enhanced due diligence steps before an alternative route is approved
- Audit trails that record the reason code for every withdrawal routed outside the primary instrument
- Periodic reconciliation to confirm the cashier system enforces the policy in practice, not just in documentation
Expired Cards and the Exception Problem
The most operationally complex scenario arises when the deposit card has expired or been cancelled. Card schemes generally allow the underlying account to still receive a credit return even on an expired card number via the original transaction ID, a process known as an "original credit transaction" or OCT. Operators should instruct their acquirer on the correct OCT workflow before defaulting to alternative payout routes. Only when OCT is technically impossible should an exception be opened, and at that point the compliance team must conduct identity verification equivalent to a new withdrawal source registration.
OnlineShine's Operational Perspective
At OnlineShine, we review closed-loop policies as a standard element of compliance audits for operator clients. The most common gap we encounter is not the absence of a policy on paper but the absence of cashier-system enforcement. A policy that relies on a payments agent manually checking withdrawal requests will fail under volume pressure. Automation, clear exception governance, and regular testing against live transaction data are the three controls that consistently satisfy both regulatory reviewers and card scheme auditors.



