KYC, AML and payments: the legal reality
A solicitor-reviewed account of the customer due diligence regime that binds a remote gambling licensee, the specific obligations that flow from the Money Laundering Regulations 2017 and the Licence Conditions and Codes of Practice, the interaction with the Financial Services and Markets Act 2000 and the Payment Services Regulations 2017 that transpose PSD2, and the payment mechanics that reach a British consumer at the moment funds cross the licensing perimeter.

The Money Laundering Regulations 2017, in one paragraph
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, SI 2017/692, are the working text that governs anti-money-laundering practice for United Kingdom firms captured by the definition of a relevant person in regulation 8. The Regulations transposed the Fourth Money Laundering Directive at entry into force on 26 June 2017 and have been amended repeatedly since, most materially in December 2019 to transpose the Fifth Directive and to bring cryptoasset exchange providers and custodian wallet providers within scope, and again in September 2022 to reflect the departure from the European Union architecture.
The Sixth Money Laundering Directive is in operative effect through parallel UK provisions rather than by direct transposition, chiefly the Proceeds of Crime Act 2002 and the Criminal Finances Act 2017. For a solicitor advising a remote gambling licensee, the Regulations are read alongside the Commission's own Prevention of Money Laundering and Combating the Financing of Terrorism guidance, published under section 24 of the Gambling Act 2005, which frames the same duties in gambling-specific language and sets out the enforcement expectations the Commission's compliance division will bring to a licence review.
The scheme of the Regulations is straightforward on the face of the text and more demanding in application. Part 3 sets out customer due diligence, defined at regulation 27, together with the standard, enhanced and simplified measures that apply to different classes of business relationship.
Regulation 27(7) provides that a casino must apply customer due diligence when it establishes a business relationship with a customer, when it carries out an occasional transaction that amounts to two thousand euros or more (whether the transaction is executed in a single operation or in several operations that appear to be linked) or when it has any doubt about the veracity or adequacy of documents obtained in the course of previous due diligence.
Regulation 28 sets out the identification and verification content, regulation 33 sets out enhanced due diligence for higher-risk situations, and regulation 35 governs the treatment of politically exposed persons. Part 4 sets out the internal controls a relevant person must maintain, including the appointment of a nominated officer under regulation 21, staff training under regulation 24 and record-keeping under regulation 40.
The Commission enforces the Regulations against its licensees; the enforcement decisions of 2024 and 2025, referenced in section seven below, illustrate the price of failure.
02How offshore KYC departs from UKGC-licensed KYC
A remote casino licensed by the Gambling Commission is bound to run identity verification, source-of-funds enquiries and ongoing monitoring to a standard set out in two overlapping instruments. The Money Laundering Regulations 2017 provide the statutory floor. The Licence Conditions and Codes of Practice provide the operational specification.
LCCP 5.1.3 requires the licensee to verify the age and identity of a customer before that customer deposits funds, before free-to-play offerings are made available and, in any case, before the seventy-second hour of the account's life. LCCP 5.1.4 addresses the accuracy of verification data and the timing of any repeat checks, and LCCP 12 provides the anti-money-laundering framework within which the operator's policies, procedures and controls must sit.
The consequence for a British customer is a settled expectation about the paperwork and process at first deposit, at balance thresholds and at withdrawal, together with the reasonable assurance that non-compliance will draw regulatory attention.
An operator sitting outside the Commission's licensing perimeter is bound by whatever anti-money-laundering framework its host regulator specifies, and those frameworks vary considerably in stringency and enforcement. A Malta Gaming Authority licensee will typically apply due diligence that resembles the LCCP shape, because Malta operates under the Fifth Directive and has itself been the subject of Council of Europe MONEYVAL evaluation.
A Curaçao licensee under the Landsverordening op de Kansspelen (LOK) in force from 24 December 2024 is now subject to a single-regulator model at the Curaçao Gaming Authority that closes the historic master-licence gap, but the CGA's supervisory practice is younger than the Commission's by more than a decade and its enforcement history is thinner.
Anjouan, Kahnawake, Isle of Man and Alderney sit at different points along that spectrum. None of them is answerable to the Commission and none can be compelled by a British court to alter its verification practice at the request of a British consumer.
A worked example
Consider a British customer opening an account at a Curaçao-licensed remote casino. Verification at onboarding is likely to consist of a photograph of a government-issued identity document, a selfie test against that document and confirmation of a residential address by utility bill or bank statement.
Source of funds may not be asked until an aggregate deposit threshold is passed, and that threshold is a matter of the operator's own risk assessment rather than a Commission-approved figure. Withdrawal will typically trigger a further verification round, sometimes intrusive and sometimes delayed, and there is no ADR jurisdiction under LCCP 6.1.1 if the withdrawal is not paid. The verification friction is real, and it is not equivalent to the friction a UKGC-licensed operator will present.
03HSBC, Monzo, Starling, Lloyds blocks and card gambling switches
The card-level gambling switch is a voluntary product feature offered by the five largest UK retail banks and by every large digital challenger. HSBC, Monzo, Starling, Lloyds and Barclays each provide an in-app control that instructs the card scheme to decline transactions coded as merchant category 7995, the code assigned to gambling merchants at the acquiring end of the payment chain.
The switch is not a system-wide coordinated block imposed by any statute; it is a contractual feature of the current account, offered on the same basis a bank offers travel notifications, contactless-limit adjustments or a temporary block on international transactions. The legal ground on which the bank declines the transaction is regulation 71 of the Payment Services Regulations 2017, which transposes Article 68 of the Second Payment Services Directive and permits a payment service provider to refuse to execute a payment order in defined circumstances. Where the customer has instructed the bank to block gambling transactions, refusal to execute is straightforwardly consistent with that instruction.
Each bank layers a protective delay onto the removal of the switch. HSBC applies a forty-eight-hour cool-off before a request to disable the block takes effect, Monzo and Starling apply twenty-four hours and Lloyds and Barclays apply variations depending on the account product. The delay is a design choice, not a statutory requirement, and it exists because the population most likely to seek to disable the block includes the population most likely to benefit from a further moment of reflection.
A concerned other cannot activate the block on behalf of an account holder, but a concerned other can accompany the account holder to the branch or to the in-app support channel, and the National Gambling Helpline can talk a caller through the switching process on a call.
None of the five banks discloses the underlying merchant identifiers or the specific reroute reports it maintains, and the switch remains imperfect against operators that present themselves through non-gambling MCCs.
04The Visa and Mastercard taskforce and its legal weight
The joint taskforce between the Gambling Commission, Visa Europe and Mastercard Europe stood up in the second half of 2025 and reports quarterly to the Commission's enforcement branch. Its principal focus is the reroute problem: the practice by which an offshore gambling operator presents a deposit to the issuing bank through a payment processor coded as digital services (MCC 5817), remittance (MCC 4829) or a general e-wallet category, so that the bank's category-7995 gambling switch does not fire.
The Commission's own reporting for the 2024/25 financial year records 264 domain removals through registrar action, a ten-fold year-on-year increase, and the taskforce is intended to attach a payments-side lever to the same enforcement engine. The mechanism is not a statutory power; it is co-operation among regulated firms, each of which is subject to the Financial Conduct Authority's principles and to the Payment Services Regulations 2017.
The consequence for a British consumer is a payments environment that is tightening quarter by quarter. A deposit that cleared through a non-gambling MCC in early 2025 may be declined through the same processor in late 2026, because the taskforce has identified the reroute and the acquiring bank has repriced or terminated the merchant relationship.
A declined transaction does not, by itself, generate a suspicious activity report, but a pattern of declined attempts followed by a successful attempt through a differently coded processor may. The consumer sees only the payment result on her banking app; the taskforce sees the merchant category coding and the acquiring identifier behind it.
It is a slow-motion enforcement action against operators, executed through payments infrastructure rather than through registrar takedowns, and it does not directly involve the consumer, though the consumer inherits the friction.
Points worth knowing
- SI 2017/692 binds licensees. It does not bind offshore operators, but it does bind UK banks and card acquirers in the payment chain
- The card-level gambling switch relies on merchant category 7995 and can be defeated by rerouted processors coded as digital services or e-wallets
- Enforcement penalties of £2.0m (Spreadex, 15 May 2025), £1.4m (AG Communications, 4 Mar 2025) and £686,070 (Corbett Bookmakers, 20 Mar 2025) illustrate the Commission's AML enforcement posture in 2025
Crypto rails and the KYC that still bites at the exchange
Cryptoasset exchange providers and custodian wallet providers were brought within the scope of the Money Laundering Regulations 2017 by amendment in January 2020, and a firm that wishes to carry on cryptoasset business in the United Kingdom must be registered with the Financial Conduct Authority under regulation 54A. That registration requires satisfaction of the fit-and-proper test in regulation 58A and the maintenance of policies, procedures and controls in respect of customer due diligence, ongoing monitoring, staff training and internal audit.
The point at which a British consumer converts fiat currency into a cryptoasset at a registered exchange is a customer-due-diligence event under regulation 27 of the same instrument that governs a regulated casino. Identity verification, address confirmation and source-of-funds enquiry at higher thresholds are the same in substance, though the documentary process differs.
The theory that a foreign gambling deposit routed through cryptoasset rails escapes British anti-money-laundering scrutiny does not survive contact with the payment chain. The fiat leg at the exchange has already produced a verified record of the depositor's identity and residential address; the onward transfer to a foreign gambling site changes the venue of the funds, it does not erase the verification event.
A subsequent withdrawal from the operator to the same exchange re-triggers due diligence on receipt. A withdrawal to a non-custodial wallet defers the point of re-conversion, but the re-conversion event at any FCA-registered exchange re-triggers due diligence in due course. The use of a foreign exchange, a mixer, or a chain-hopping conversion adds friction and cost without removing the ultimate risk of a suspicious activity report through the wider banking chain.
A worked example
A British consumer purchases a stablecoin at a UK-registered exchange, transfers it to a Curaçao-domiciled gambling site, plays for a period and then withdraws a larger stablecoin balance to the same exchange for conversion back to sterling. The exchange sees a purchase, a withdrawal to an external address that is publicly known as a gambling operator wallet cluster, and a return several weeks later of an amount materially larger than the original purchase.
Under regulation 33 of SI 2017/692 the exchange is required to apply enhanced due diligence and, in an appropriate case, to make a suspicious activity report to the National Crime Agency under Part 7 of the Proceeds of Crime Act 2002. The transaction is not in itself unlawful, and reporting is not a criminal accusation. It is a record.
06The lawful grounds on which a bank may freeze a deposit
The freezing of a payment or the closure of an account is not a discretionary act of customer relations; it is a structured response to a compliance signal. Under regulation 71 of the Payment Services Regulations 2017 a payment service provider may refuse to execute a payment order where the refusal is justified on objective grounds.
Under Part 7 of the Proceeds of Crime Act 2002 the bank must make a disclosure to the National Crime Agency where its nominated officer knows or suspects that a person is engaged in money laundering, and while the disclosure is in progress the bank must have consent from the NCA before proceeding with the transaction (a defence known as a defence against money laundering, or DAML).
The bank's own account terms will further contemplate suspension where there is a material breach or where the bank has been directed by a competent authority to act.
What the consumer sees is a declined transaction, a temporarily frozen balance or, in the more serious cases, a written notice of account closure. What the bank sees is a pattern that has hit one or more risk indicators built into its transaction-monitoring system, calibrated to the guidance the Joint Money Laundering Steering Group publishes for financial-sector firms.
Gambling-coded transactions at merchants operating outside a recognised licensing regime are one such indicator, and repeated transactions across multiple processors coded as digital services or e-wallets are another. The consumer's remedy in an unmerited case is the complaints procedure of the bank followed, if unresolved after eight weeks, by referral to the Financial Ombudsman Service under the Financial Services and Markets Act 2000, which provides the statutory basis for the Ombudsman's jurisdiction.
SARs in the UK and their Tracfin-equivalent function
The suspicious activity report in the United Kingdom is a disclosure to the National Crime Agency under sections 330, 331 or 332 of the Proceeds of Crime Act 2002, or under section 21A of the Terrorism Act 2000 in a terrorist-finance context. The reporting person is a relevant person under SI 2017/692, and the reporting officer within that person is the nominated officer required by regulation 21 of the same instrument.
The National Crime Agency operates the SAR regime through the United Kingdom Financial Intelligence Unit, which received 901,255 SARs in the 2023/24 reporting period per its annual report, of which 39.6 per cent came from the retail banking sector. The France Tracfin analogue is different in constitutional form (an administrative service of the Ministry of the Economy) but similar in function.
The consequences of a SAR for the reported customer vary. A single SAR triggered by a discrete transaction may result in nothing more than a delay while consent is sought from the NCA under section 335 of POCA. A pattern of SARs across multiple institutions may result in the closure of accounts, the refusal of subsequent applications for credit and difficulty in opening banking relationships with other firms, because banks share risk information through the Joint Fraud Taskforce and through CIFAS.
The Commission enforces the reporting duty against its own licensees; the fines listed above under section four reflected, in each case, failure to make or to escalate a SAR in circumstances where a compliant licensee would have done so. For a British consumer transacting with an offshore operator, the practical point is not whether her transactions are reportable in some theoretical sense; it is that the reporting mechanism sits several steps back in the payment chain, at the bank or at the exchange, and it operates without her knowledge.
08Steps to limit your personal legal exposure
The steps a British adult can take to reduce her personal risk exposure to the payment mechanics described above are not complicated, and they do not require any specialist assistance beyond what her existing bank or card issuer already offers. The card-level gambling switch on the current-account app takes under a minute to enable and is subject to a protective delay before it can be disabled again.
Deposit limits, time-outs and reality checks are available on every UKGC-licensed remote gambling account and are enforceable against the licensee under LCCP 3. The GamStop registration itself is the most durable of these protections in the licensed market and is treated in full on the dedicated page linked below.
Where the concern is a live gambling problem rather than a payments question, the National Gambling Helpline runs free of charge, confidentially and around the clock on 0808 8020 133, with a live-chat channel and a WhatsApp route through the GamCare website. Where the concern is problem debt driven by gambling losses, the free financial counselling service at StepChange, and the network of local Citizens Advice offices, can help with a household budget and, where necessary, with a formal debt-management plan or an application under the Insolvency Act 1986.
Where the concern is a suspected fraud by a purported GamStop removal service, the correct route is the Action Fraud reporting service at actionfraud.police.uk, run by the City of London Police as the national reporting centre for fraud and cybercrime under the Fraud Act 2006.
Where the concern is a breach of a UK bank's own duties in the handling of a gambling-related payment (a switch failure, an unmerited account closure, a mis-handled complaint), the escalation route is the Financial Ombudsman Service under the Financial Services and Markets Act 2000 after the bank's own eight-week internal process has been exhausted.
Read next
- What GamStop is and how it actually works
- Legality for UK players and where UKGC remit ends
- Consumer-protection risks of offshore sites
- Cancelling GamStop the right way
- Help, support and where to talk to someone today
Sources and verification
Verified against the text of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692) at legislation.gov.uk, the Payment Services Regulations 2017 at legislation.gov.uk, the Financial Services and Markets Act 2000 at legislation.gov.uk and the Commission's public enforcement decisions at gamblingcommission.gov.uk. Last checked 5 August 2026.
Frequently asked questions
Are the Money Laundering Regulations 2017 written specifically for gambling operators
The Regulations (SI 2017/692) implement the Fourth Money Laundering Directive in United Kingdom law and apply to a defined list of relevant persons that includes casinos through regulation 8(2)(k). They are not gambling-specific in origin, but Part 3 of the Regulations is what bites in a gambling context, together with the Commission's own AML guidance issued under section 24 of the Gambling Act 2005.
Does an offshore operator have to run KYC on me
An operator that holds no UKGC licence is not bound by SI 2017/692 in the sense that the Commission enforces it, and no UK regulator can compel that operator to conduct customer due diligence to a British standard. Foreign licensees run KYC to their own regulator's requirements, which vary considerably. The absence of a British-standard verification process is a risk indicator, not a convenience.
Can my bank block deposits to a foreign gambling site
The five largest UK retail banks each offer an in-app gambling switch that instructs the card scheme to decline transactions coded as merchant category 7995. Payment institutions authorised under the Payment Services Regulations 2017, which transpose PSD2, are also permitted to decline a transaction on financial-crime grounds under regulation 71. Reroutes through non-gambling MCCs can defeat the switch, though enforcement is tightening.
Do cryptocurrency deposits escape KYC entirely
They do not. A UK-facing cryptoasset exchange must be registered with the Financial Conduct Authority under the Money Laundering Regulations 2017 and must apply customer due diligence at the point fiat is converted to cryptoasset. The subsequent movement to a foreign gambling site changes the venue of the deposit; it does not remove the verification point that has already occurred at the exchange.
What is a suspicious activity report and can it affect my future banking
A suspicious activity report is a disclosure to the National Crime Agency under Part 7 of the Proceeds of Crime Act 2002 made by a regulated person, including a bank, an e-money issuer or a licensed gambling operator. The report itself is confidential, though the pattern of activity that produces it forms part of the customer file that a bank may consider in later credit, mortgage or business banking decisions.
Talk to someone today
The National Gambling Helpline is free, confidential, and open 24 hours a day, seven days a week.
