Home  /  News  /  Compliance & AML
Compliance & AMLOctober 17, 2025

Sanctions and PEP Screening: A 90-Day Roadmap for Gaming Operators

A practical 90-day implementation roadmap for sanctions and PEP screening in iGaming, covering tooling, workflows, and ongoing compliance obligations.

Sanctions and PEP Screening: A 90-Day Roadmap for Gaming Operators

Sanctions and politically exposed person screening are no longer optional extras in the iGaming compliance stack. Regulators across Malta, Gibraltar, the Isle of Man, and emerging markets are actively examining how operators identify, escalate, and resolve matches, and enforcement actions in 2025 have made clear that "we have a tool in place" is not a sufficient answer on its own. What follows is a structured 90-day roadmap that operations and compliance teams can use to build, or meaningfully improve, a screening programme that satisfies both regulatory expectation and practical operational reality.

Why Screening Failures Happen

Most screening failures in gaming do not stem from a complete absence of technology. They stem from misconfiguration, poor alert triage discipline, or a disconnect between the tool and the wider customer lifecycle. A player flagged at registration may be cleared from an incomplete name-match review. A PEP who later acquires political status may never be re-screened because ongoing monitoring was set to annual rather than real-time or near-real-time. The 90-day roadmap below addresses each of these failure modes systematically.

Days 1 to 30: Baseline Assessment and Vendor Selection

The first month is diagnostic. Before procuring or reconfiguring any technology, compliance teams should conduct a gap analysis against three reference points: the operator's current licence conditions, the Financial Action Task Force's Recommendation 12 on PEPs, and any jurisdiction-specific guidance issued by the relevant gaming authority.

  • Audit existing customer records to identify what proportion have been screened, when, and against which lists.
  • Map the full customer journey to locate every point where a new identity data element is collected, including payment method changes and account updates, and confirm that each triggers a rescreening event.
  • Evaluate screening vendors against four criteria: list coverage (UN, OFAC, EU, HMT and national lists), fuzzy matching capability and configurability, API response times compatible with your registration flow, and audit trail completeness for regulatory inspection.
  • Appoint a named internal screening owner, typically the MLRO or a deputy, with documented authority to approve configuration changes and escalate complex matches.

Output from this phase should be a written gap report and a vendor shortlist with a documented rationale for the selection decision.

Days 31 to 60: Configuration, Integration, and Internal Controls

Month two is where the technical work happens alongside the policy layer that gives it meaning. Integration priorities should follow a clear hierarchy.

  • Connect the screening API to the registration flow so that no account reaches an active state before a sanctions check returns a clear result.
  • Configure PEP matching thresholds carefully: overly broad settings generate alert fatigue; overly narrow settings create blind spots. Document the chosen thresholds and the reasoning behind them.
  • Build an ongoing monitoring schedule. Industry best practice in 2025 supports continuous or daily batch rescreening for active players, with a documented rationale for any less frequent approach.
  • Draft a match-management procedure covering three outcomes: clear match (immediate account restriction and MLRO notification), possible match (time-boxed enhanced due diligence period, typically 48 to 72 hours), and false positive (documented dismissal with named reviewer and timestamp).
Screening configuration is a compliance decision, not a technical default. Every threshold setting should be reviewable by your regulator and explainable in plain language by your MLRO.

Days 61 to 90: Testing, Training, and Governance Embedding

The final month converts a configured system into an auditable programme. Three workstreams run in parallel.

Testing

Run a structured sample of known positive names through the live system and verify that alerts fire correctly. Test the false positive handling pathway with similar names that are not on any list. Document results and resolve any configuration issues before the programme goes fully live.

Training

Customer-facing and risk teams need scenario-based training, not just policy reading. Focus on how to handle a possible match during a live chat interaction, how to apply a temporary deposit restriction without tipping off the player, and how to escalate within the documented timeframes.

Governance

Embed screening performance into the monthly compliance reporting pack. Key metrics should include total alerts generated, average time to disposition, false positive rate, and any matches that resulted in a Suspicious Activity Report or licence-required notification. Set a formal review cadence, at minimum quarterly, to assess whether list coverage and thresholds remain appropriate as the player base evolves.

Ongoing Obligations Beyond Day 90

A 90-day roadmap delivers a functioning programme, not a permanent solution. Sanctions lists update daily. PEP databases change with every election cycle and government reshuffle. Operators should treat screening as a living control that requires the same governance discipline as any other risk management function, with version-controlled configuration records, annual independent reviews, and clear escalation paths to senior management when edge cases arise.

FAQ

Frequently asked questions

What is the difference between sanctions screening and PEP screening for gaming operators?

Sanctions screening checks a customer's identity against lists of individuals and entities subject to legal asset freezes or transaction prohibitions, such as those maintained by the UN, OFAC, EU, and HMT. PEP screening identifies customers who hold or have held prominent public functions, such as senior politicians, judges, or military officials, and their close associates. Gaming operators are required to conduct both, because a PEP is not necessarily sanctioned but still requires enhanced due diligence due to elevated corruption and money laundering risk.

How often should a gaming operator rescreen its existing customer base for sanctions and PEP status?

Regulatory best practice in 2025 supports continuous or at minimum daily batch rescreening for active players. Sanctions lists can be updated without notice following geopolitical events, and a player's PEP status can change with any election or government appointment. Annual-only rescreening is unlikely to satisfy a regulator's expectation of ongoing monitoring and leaves operators exposed to the risk of unknowingly facilitating transactions for a newly sanctioned or newly elevated PEP individual.

What should a gaming operator do when a sanctions or PEP screening alert fires on an existing player account?

The operator should immediately restrict the account from withdrawals and further deposits pending investigation, classify the alert as a confirmed match or possible match, and notify the MLRO within the timeframe specified in the operator's match-management procedure. For a confirmed sanctions match, the account must be frozen and the relevant financial intelligence unit notified in line with the applicable jurisdiction's legal requirements. For a possible match, the MLRO should have a defined window, typically 48 to 72 hours, to conduct enhanced due diligence and reach a documented determination.

How should a gaming operator configure fuzzy matching thresholds for PEP and sanctions screening?

Fuzzy matching thresholds control how closely a customer name must resemble a listed name before an alert is generated, and they require deliberate calibration rather than acceptance of vendor defaults. Thresholds set too broadly generate high volumes of false positives, which creates alert fatigue and increases the risk that genuine matches are dismissed carelessly. Thresholds set too narrowly allow near-identical names to pass without review. Operators should test chosen thresholds against a sample of known positive and known negative names, document the configuration rationale, and review the settings at least quarterly as the player base and list content evolve.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.