Enhanced due diligence is not simply a box-ticking exercise reserved for high-roller whales. For any licensed iGaming operator, getting EDD thresholds and triggers wrong carries real regulatory consequences, from formal warnings to licence revocation. This article sets out a practical checklist your compliance team can work through right now, grounded in current Financial Action Task Force guidance and the AML frameworks most relevant to European and island-jurisdiction operators.
What Enhanced Due Diligence Actually Means in iGaming
Standard customer due diligence collects identity, verifies it, and monitors transactions at a baseline level. Enhanced due diligence goes further: it requires deeper source-of-funds verification, more frequent account reviews, senior-management sign-off in many cases, and documented rationale for why a player relationship is being maintained despite elevated risk indicators. The legal basis in most EU-regulated markets flows from the Fourth and Fifth Anti-Money Laundering Directives, transposed into national law. Operators outside the EU but targeting European players via B2B agreements are still expected to apply equivalent standards.
Common EDD Triggers Operators Miss
Most operators correctly apply EDD when a player is flagged as a politically exposed person. Fewer apply it consistently in these situations:
- Deposit or withdrawal activity that reaches or approaches the operator's own suspicious activity reporting threshold, even if spread across multiple sessions
- Players residing in or transacting from FATF grey-list or high-risk jurisdictions, regardless of deposit size
- Inconsistency between a player's stated occupation and observed spending patterns, for example a self-reported retail worker depositing amounts consistent with a six-figure annual income
- Rapid changes in payment method, particularly a shift from card to cryptocurrency or e-wallet
- Third-party payment indicators, where the name on the funding instrument does not match the account holder
- Re-registration by a previously self-excluded or account-closed player under a slightly different profile
EDD Threshold Checklist: What to Review This Week
1. Confirm Your Documented Thresholds Are Current
Your risk-based approach document should specify exact monetary thresholds that trigger an EDD review. If those figures have not been reviewed since your last licence renewal, revisit them now. Regulators in Malta, Gibraltar, and the UK have all indicated in recent supervisory letters that static thresholds applied without contextual adjustment are insufficient.
2. Verify That Automated Alerts Fire at the Right Points
Cross-check your transaction monitoring system against your documented thresholds. A common operational gap is that the RBA document states one figure while the platform alert is set to a different amount because a developer changed it during a system migration. Test this with a controlled internal audit transaction if your platform permits it.
3. Ensure Source-of-Funds Evidence Is Collected, Not Just Requested
Requesting a document from a player and actually receiving and reviewing it are two different things. Your CRM or compliance platform should record the date a request was sent, the date evidence was received, and the name of the compliance officer who reviewed and approved it. Operators often have records of requests but not of the review decision.
4. Apply Senior-Management Sign-Off for PEP and High-Risk Country Relationships
The FATF Recommendations explicitly require that relationships with PEPs receive approval from senior management before or during onboarding. Implement this as a workflow step, not a verbal process. Document who approved what and when.
5. Set a Recurring Review Cadence, Not Just an Onboarding Check
EDD is not a one-time gate. High-risk accounts should be subject to periodic review, typically every three to six months depending on your risk appetite, with reviews triggered earlier by any new adverse media, sanctions list update, or significant change in playing behaviour.
6. Record Your Rationale for Continuing Relationships
When a compliance review concludes that a high-risk account can remain active, the reasoning must be documented in detail. Regulators audit these files and expect to see more than a single-line note. Include the evidence reviewed, the risk factors weighed, and the mitigation steps in place.
The Operational Cost of Getting EDD Wrong
Beyond regulatory fines, poorly calibrated EDD creates two practical problems. First, over-triggering EDD on low-risk players increases friction, damages retention, and wastes compliance resource on false positives. Second, under-triggering it exposes the operator to money-laundering facilitation risk. Calibration is an ongoing activity, not a launch-week decision.
Effective EDD in iGaming is a balance between player experience and regulatory integrity. The operators who get this right treat their risk-based approach as a living document, not a static policy file.
How OnlineShine Supports EDD Compliance
OnlineShine's MLRO-as-a-service model embeds experienced compliance practitioners directly into operator workflows. We review and recalibrate EDD thresholds as part of our ongoing managed-service engagement, so your team always has documented, defensible rationale ready for a regulatory inspection. If your AML framework has not been stress-tested recently, this checklist is a useful starting point, but it is not a substitute for a structured compliance review.



