For iGaming operators, high-roller accounts represent both significant revenue opportunity and heightened regulatory exposure. Source of wealth and source of funds checks are no longer a formality reserved for suspicious cases; they are a structured compliance obligation that, when executed well, protect the operator's licence, satisfy regulators and build defensible audit trails.
Defining the Two Checks and Why the Distinction Matters
Operators frequently conflate source of funds (SOF) and source of wealth (SOW), but regulators treat them as distinct inquiries. Source of funds refers to the specific origin of the money being deposited or wagered in a given transaction or series of transactions. Source of wealth describes the broader accumulation of a player's overall net worth and assets over time.
A player might have legitimate salary income funding their deposits (clean SOF) while their underlying wealth originates from activities that warrant further scrutiny (complex SOW). Treating the two checks as interchangeable creates gaps that regulators and financial intelligence units are trained to identify during inspections.
Trigger Points: When Do Checks Become Mandatory
Most licensing frameworks, including those under the UK Gambling Commission, Malta Gaming Authority and Dutch KSA, require enhanced due diligence when a customer is classified as high risk or when transactions exceed defined thresholds. Operators should build trigger logic around at least the following criteria:
- Cumulative deposits or losses reaching a defined monetary threshold within a rolling period, commonly 2,000 to 3,000 euros or the equivalent in a 30-day window
- Player behaviour inconsistent with their stated occupation or declared income, such as a self-employed trader depositing at volumes that suggest six-figure annual discretionary spending
- Sudden uplift in deposit frequency or stake size without a corresponding change in verified circumstances
- Jurisdiction of residence flagged as higher risk under the operator's own risk-based approach
- PEP or adverse-media flags identified at onboarding or during ongoing monitoring
Thresholds must be calibrated to the operator's specific player base and product type. A sports-betting operator serving recreational bettors will set different parameters than a live-casino platform with a dedicated VIP segment.
What Evidence Is Acceptable
Operators need a documented evidence hierarchy so that compliance staff apply consistent standards and cannot be accused of applying subjective judgement to individual accounts. Acceptable documentation typically falls into three tiers.
Tier One: Primary Documentary Evidence
- Payslips or employment contracts corroborating regular salary income
- Tax assessments or self-assessment returns from national revenue authorities
- Dividend or shareholder distribution notices from a verified company
- Inheritance or probate documentation for one-off receipts
Tier Two: Corroborative Evidence
- Bank statements showing consistent inflows aligned with declared occupation
- Company accounts filed at a national registry for business owners
- Proof of asset sale, such as a property completion statement
Tier Three: Open-Source Intelligence
- LinkedIn profiles, Companies House or equivalent registry data, and press coverage can support but never replace documentary evidence
Regulators expect operators to push back when documents appear inconsistent or when a player is unresponsive. Accepting implausible explanations without challenge is treated as a failure of the compliance function, not as good customer service.
Operational Challenges and Practical Solutions
The most common operational failure is a delay between the trigger event and the commencement of the review. Funds spent during that gap can be difficult to recover and create liability exposure. Operators should implement a temporary deposit restriction the moment a threshold is hit, pending completion of the SOF or SOW review.
Communication with the player must be handled carefully. A poorly worded request can be perceived as accusatory and generate complaints or chargeback disputes. Compliance teams benefit from scripted outreach templates that frame the request as a routine regulatory requirement rather than an accusation, while still making clear that play cannot continue until documentation is received and assessed.
A credible SOW file does not just satisfy a regulator during an audit; it demonstrates that the operator understands its own customer base and is not dependent on funds that could be subject to civil recovery proceedings.
Record-Keeping and Audit Readiness
Every SOF and SOW review must be documented regardless of its outcome. The compliance file should include the trigger event, the outreach timeline, the evidence received, the analyst's assessment rationale, the sign-off authority and any restrictions applied or lifted. Regulators reviewing a high-risk account expect to see a coherent, timestamped narrative. Missing entries or retrospective notes are red flags during licence reviews.
At OnlineShine, our MLRO team works directly with operators to design tiered SOF and SOW frameworks that are proportionate to their player volumes, calibrated to their licensing jurisdiction and integrated into their CRM workflows so that compliance reviews do not disrupt the player experience any more than is strictly necessary.



