Enhanced due diligence is not a single, fixed standard. Across the four main iGaming verticals, regulators, licensing bodies and internal risk frameworks apply meaningfully different thresholds for when a player relationship must escalate beyond standard KYC. Operators who treat EDD as a one-size-fits-all checklist expose themselves to regulatory censure and, in some jurisdictions, criminal liability.
Why Thresholds Diverge by Vertical
The core logic is risk proportionality. Regulators calibrate EDD triggers to the specific financial flows, product mechanics and customer demographics of each vertical. A sports bettor placing frequent low-value in-play wagers presents a different risk profile than a high-roller at a live baccarat table or a crypto depositor sending funds from a self-custodied wallet. Understanding those distinctions is the first step toward building a compliant, commercially viable compliance programme.
Casino: Volume, Velocity and Table Limits
Traditional online casino operations typically attract EDD requirements once cumulative deposits or withdrawals cross a defined monetary threshold within a rolling period. In MGA-licensed operations, for example, the practical trigger is often set internally at EUR 2,000 per month in net deposits, though the licence conditions specify broader risk indicators rather than a single figure. UKGC-regulated sites are guided by the 2017 Money Laundering Regulations and must apply EDD whenever a customer is assessed as higher risk, regardless of whether a cash amount has been reached.
Key EDD indicators specific to casino operations include:
- Rapid cycling between deposit methods and withdrawal channels
- Bonus exploitation patterns combined with irregular play behaviour
- Session activity that is inconsistent with stated source of funds
- Requests to split withdrawals below reporting thresholds
For casino operators, the practical challenge is that EDD must be completed without creating friction that drives compliant high-value players to competitors. Proportionate document requests and clear communication of purpose reduce abandonment during the verification process.
Sportsbook: Transaction Frequency Over Single Amounts
Sportsbook EDD thresholds are less often triggered by single large transactions and more often by aggregated betting behaviour across markets. A customer placing EUR 500 per week across thirty separate bets may represent higher aggregate exposure than one placing a single EUR 1,000 wager. This means sportsbook compliance teams need monitoring rules built around cumulative stake values, bet-to-withdrawal ratios and the use of multiple accounts or referral structures.
Several European regulators also require sportsbook operators to apply EDD when a customer receives unusually large payouts relative to their historical staking pattern, even if no deposit threshold has been crossed. This is particularly relevant for in-play and exchange-style products.
Sweepstakes: A Distinct Framework Without Gambling Law Coverage
Sweepstakes casinos operate under promotional and consumer protection law rather than gambling regulation in many jurisdictions, particularly across US states. This creates a compliance gap: standard AML obligations may not formally apply, yet financial risk remains present through the purchase of virtual coin packages and prize redemption flows.
Responsible operators are increasingly applying voluntary EDD frameworks modelled on bank-grade customer due diligence, triggered at specific coin purchase volumes or redemption amounts. A practical internal threshold used by several operators is USD 500 in coin purchases within a calendar month, at which point source of funds documentation is requested. This approach anticipates incoming regulatory attention and demonstrates good-faith compliance posture to payment processors and banking partners, who increasingly assess sweepstakes operators using the same risk lens as licensed gambling businesses.
Crypto Gaming: Wallet Risk Scoring Replaces Traditional Income Checks
Crypto-native gaming platforms face EDD requirements shaped by the FATF travel rule, the EU's Transfer of Funds Regulation effective from 2024, and blockchain analytics risk scores. Rather than asking for a payslip, a crypto-focused operator must assess:
- Whether incoming wallets have exposure to sanctioned addresses or mixers
- The proportion of funds traceable to high-risk exchanges or DeFi protocols
- Whether the player's on-chain history is consistent with their stated activity profile
EDD in this vertical often means suspending withdrawals pending a blockchain analytics report rather than requesting a bank statement. Thresholds for escalation typically sit at transaction values of USD 1,000 or equivalent, though MiCA-aligned operators are moving toward lower triggers in anticipation of stricter supervisory expectations from 2025.
Building a Cross-Vertical EDD Policy
Operators running multiple products under a single licence or brand group need a unified EDD policy that accommodates vertical-specific triggers without creating internal inconsistencies that regulators will flag on audit. The policy should define threshold tiers by vertical, specify the evidence required at each tier, assign ownership to named compliance roles, and include documented escalation paths to the MLRO.
A defensible EDD programme is one where every decision, at every threshold, is documented, proportionate and consistently applied across the customer base.
At OnlineShine, we design and implement EDD frameworks for operators across all four verticals, aligning regulatory requirements with operational workflow so that compliance teams can act quickly and confidently without disrupting the player experience.



