A fraud team that worked well when you had ten thousand active players will not hold up when you reach a hundred thousand. For growing iGaming operators, the structure of the fraud function is as important as the tools it uses, and getting the hierarchy right from the start prevents costly reorganisations later.
Why Fraud Team Design Is a Compliance Issue
Most operators treat fraud prevention as a technical or operational matter and keep it separate from compliance. That separation creates blind spots. Bonus abuse, account takeover, and payment fraud all carry AML implications: layering activity can disguise itself as ordinary bonus farming, and mule accounts are frequently caught first by fraud analysts rather than MLRO-level review. A compliance-aware fraud team closes that gap by reporting suspicious patterns upward to the MLRO rather than resolving them silently at the operational layer.
Regulators in mature markets increasingly expect documented escalation paths between fraud, payments, and compliance. Building those paths into your team structure from an early stage demonstrates organisational maturity and reduces regulatory risk during audits.
Stage One: The Generalist Foundation
At launch and through the first growth phase, most operators run fraud through a small group of generalist analysts, often sitting inside the payments or customer operations team. This works up to roughly twenty thousand monthly active players, provided the following conditions are met:
- At least one analyst has a defined ownership of fraud queues each shift.
- There is a clear escalation path to the MLRO for any case that touches potential money laundering.
- Decision logs are kept for every declined withdrawal and every blocked bonus claim.
- Tooling includes a basic rules engine, device fingerprinting, and velocity checks on payments.
The biggest mistake at this stage is allowing fraud decisions to be made informally, without documentation. Undocumented decisions cannot be audited, and an operator that cannot reconstruct its fraud rationale is exposed during licensing reviews.
Stage Two: Specialist Functions and Clear Ownership
When monthly active players pass the twenty-to-fifty-thousand range, generalist coverage breaks down. Volume forces triage, and triage without specialisation means the most complex cases, which carry the highest compliance risk, are handled by the least experienced available analyst.
At this stage, operators should split the fraud function into at least three defined roles:
- Fraud Analyst: handles first-line queue work, applies rules, documents outcomes, and flags escalations.
- Senior Fraud Investigator: owns complex cases, conducts device and network analysis, and liaises directly with the MLRO on dual-risk cases.
- Fraud Operations Lead: manages team output, owns rules configuration, and produces weekly MI reports for senior management and compliance.
The Fraud Operations Lead should have a formal reporting line to both the Head of Operations and the MLRO. This dual reporting structure reflects the dual nature of the role: it is operationally concerned with loss prevention, but it is also a compliance function when suspicious activity is involved.
The Compliance Bridge: Linking Fraud to MLRO Functions
One of the most practical steps a growing operator can take is establishing a weekly case review between the Fraud Operations Lead and the MLRO. This meeting should cover:
- Cases where fraud indicators overlap with AML red flags, such as structured deposits followed by withdrawal requests.
- Patterns identified by fraud tooling that have not yet triggered SAR thresholds but are trending toward them.
- Any accounts that fraud has restricted where the customer has since raised a complaint, to ensure the response is legally defensible.
This regular touchpoint prevents the two functions from developing incompatible views of the same player population. It also creates a documented compliance record that demonstrates proactive oversight.
Stage Three: Tooling and Automation at Scale
Beyond fifty thousand monthly actives, manual review cannot scale proportionally with headcount. Operators at this level should be investing in machine learning-assisted scoring, automated case creation linked to the rules engine, and integration between the fraud platform and the transaction monitoring system used by compliance.
The team structure at scale typically adds a Fraud Data Analyst role, responsible for model performance, rule tuning, and reporting, alongside a Vendor Manager function if multiple third-party tools are in use. Governance of those tools, including data-sharing agreements and model transparency, is itself a compliance obligation in regulated markets.
Practical Advice from the OnlineShine Perspective
Operators frequently underinvest in fraud team structure during rapid growth because headcount decisions lag behind player acquisition. The result is a reactive function rather than a preventive one. Building the compliance bridge early, formalising escalation paths, and documenting every consequential decision costs relatively little but pays significant dividends when a regulator asks how a specific case was handled twelve months ago.



