Home  /  News  /  Compliance & AML
Compliance & AMLJanuary 18, 2025

Fraud Team Structure for the Growing iGaming Operator

How experienced iGaming operators should structure, layer and evolve their fraud teams as player volumes and threat complexity scale.

Fraud Team Structure for the Growing iGaming Operator

Scaling an iGaming operation introduces a structural problem that many operators underestimate: the fraud function that worked at 10,000 active players will fracture at 100,000. Tooling gaps, unclear ownership and siloed data create the exact conditions that sophisticated fraud rings exploit. This article examines how experienced teams should redesign their fraud function to stay ahead of volume and threat complexity simultaneously.

Why Flat Fraud Teams Stop Working at Scale

Early-stage operators typically run a flat model, one or two analysts handling chargebacks, bonus abuse and basic KYC escalations within the same queue. That model carries hidden costs that compound over time. Analysts context-switch constantly, which reduces detection depth. There is no institutional knowledge of attack patterns because cases are not categorised systematically. And when headcount grows, new hires replicate generalist habits instead of building specialist skills.

The inflection point varies by market, but most operators feel structural stress somewhere between 50,000 and 150,000 registered accounts. At that range, daily transaction volumes make manual review unsustainable, multi-account networks become harder to spot without dedicated graph analysis, and regulatory bodies start expecting documented escalation paths rather than ad-hoc responses.

The Three-Layer Model

A mature fraud function is best organised into three distinct layers, each with a defined mandate and clear handoff criteria.

Layer 1: Automated Screening and Triage

This layer is entirely rules- and model-driven. It handles first-pass velocity checks, device fingerprint matching, IP reputation scoring, payment method risk banding and bonus eligibility verification. The output is a scored transaction or account event, not a decision. Human analysts never touch Layer 1 output unless it crosses a defined threshold. Keeping humans out of routine screening is the single most effective way to free capacity for complex cases.

Layer 2: Specialist Investigation Cells

Layer 2 is where structure creates the most value. Rather than a general fraud queue, operators should organise analysts into specialist cells aligned to threat type. Recommended cells for an operator at scale include:

  • Payments and chargeback cell: Focused on dispute lifecycle management, card testing detection and acquirer relationship data.
  • Bonus and promotion abuse cell: Pattern analysis across promotion mechanics, affiliate traffic quality and multi-account graph mapping.
  • Account takeover cell: Credential stuffing detection, session anomaly review and victim recovery workflows.
  • AML and transaction monitoring cell: SAR preparation, PEP and sanctions screening escalations, and liaison with the MLRO. This cell must sit close to compliance but report operationally into the fraud function.

Each cell should maintain its own playbooks, case taxonomy and KPIs. Cross-cell handoffs need written criteria, not verbal agreements, because verbal agreements disappear with staff turnover.

Layer 3: Strategic Intelligence

This is the layer most operators build last and should build second. A small intelligence function, even two analysts, transforms reactive fraud control into proactive threat anticipation. Their responsibilities include tracking fraud typology trends across industry forums, reverse-engineering attack methodologies from closed cases, and feeding findings back into Layer 1 rule and model updates. Without this feedback loop, rules decay and models drift as attacker behaviour evolves.

Governance, Ownership and Escalation Paths

Structure without governance produces confusion. Operators should appoint a Head of Fraud Operations who owns the full three-layer model and holds a direct reporting line to the Chief Risk Officer or equivalent. This role is distinct from the MLRO, whose statutory obligations require independence. Conflating them creates regulatory exposure.

Escalation criteria must be documented and version-controlled. A case that crosses an AML threshold should automatically trigger an MLRO notification workflow, not rely on an analyst remembering the threshold. Similarly, fraud losses exceeding a defined value should escalate to senior management within a specified timeframe. Regulators in jurisdictions such as Malta, Gibraltar and the UK increasingly audit escalation documentation as part of licence reviews.

Technology Integration as a Structural Requirement

Team structure and tooling are interdependent. A specialist cell structure only functions if analysts have access to data scoped to their cell without manual extraction requests. This means the fraud platform must support role-based data views, case routing by type and shared entity graphs that cross cell boundaries. Operators still running fraud workflows inside generic CRM or back-office tools should treat platform migration as a structural investment, not an IT project.

Fraud team design is an operational discipline, not an HR exercise. The org chart you publish means nothing if data, tooling and escalation governance are not built to match it.

Metrics That Signal Structural Health

Beyond standard fraud loss rates, operators should monitor time-to-investigate by case type, cross-cell handoff failure rates, rule false-positive ratios by layer and intelligence-to-rule conversion rates. These metrics reveal whether the structure is functioning as designed or whether informal workarounds are masking dysfunction.

FAQ

Frequently asked questions

What is the recommended fraud team structure for a growing iGaming operator?

A mature iGaming fraud function should be organised into three layers: an automated screening and triage layer that handles first-pass risk scoring without human intervention, a specialist investigation layer with cells aligned to specific threat types such as payments fraud, bonus abuse and account takeover, and a strategic intelligence layer that identifies emerging attack patterns and feeds improvements back into automated rules. This structure improves detection depth, reduces analyst context-switching and creates clear accountability at each stage.

When should an iGaming operator move from a flat fraud team to a specialist cell model?

Most operators experience structural stress in their fraud function between 50,000 and 150,000 registered accounts, where daily transaction volumes make manual review unsustainable and multi-account networks become difficult to identify without dedicated analysis. A flat team model, where all analysts handle all case types, limits specialist skill development and creates detection blind spots. Operators should begin planning a specialist cell structure before reaching this threshold, not after fraud losses signal that the existing model has failed.

Should the fraud team and the MLRO function be combined in an iGaming operation?

No. The MLRO carries statutory obligations under anti-money laundering legislation that require a degree of independence from operational fraud management. Combining the roles creates regulatory exposure, particularly in jurisdictions such as the UK, Malta and Gibraltar where regulators audit the independence and documentation quality of AML functions. The AML and transaction monitoring cell within the fraud team should work closely with the MLRO but report operationally into the Head of Fraud Operations, with a separate dotted line to the MLRO for compliance matters.

What metrics indicate that a fraud team structure is functioning correctly?

Beyond overall fraud loss rates, operators should track time-to-investigate segmented by case type, cross-cell handoff failure rates, false-positive ratios for automated screening rules and the rate at which intelligence findings are converted into updated rules or model parameters. Deteriorating performance on any of these metrics typically signals that informal workarounds have developed, that data access is not properly scoped to specialist cells, or that the feedback loop between the intelligence layer and the automated screening layer has broken down.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.