Knowledge · Compliance

KYC & AML for iGaming operators: a practical implementation guide

Every regulated iGaming brand needs a documented KYC and AML program. This article covers when to verify, which thresholds trigger enhanced due diligence, how sanctions screening works, and how to wire it all into an AS Tech operator platform.

Updated June 2026 · AS Tech iGaming editorial

KYC vs AML — related but distinct

KYC is identity verification: who the player is, where they live, how old they are. AML is transactional: watching how money moves through the platform and flagging patterns consistent with laundering, structuring or fraud. A robust program needs both — KYC on the way in, AML continuously.

Tiered KYC

Most operators run a three-tier model:

  • Tier 1 (open account): email, DOB self-declaration, phone verification, geo/IP check. Allows deposits up to a low cap (e.g. €500 cumulative).
  • Tier 2 (first withdrawal or €2,000+ deposits): government-ID document, selfie liveness check, proof of address.
  • Tier 3 (VIP / €10,000+ activity): proof of source of funds (payslip, tax return, bank statement), enhanced due diligence, ongoing screening.

Sanctions & PEP screening

Every new player is screened against OFAC, EU, UN and UK sanctions lists plus PEP (Politically Exposed Person) databases at Tier 2. Screening is re-run on any material profile change and monthly for VIPs. AS Tech's KYC connectors run this synchronously as part of the verification flow.

AML transaction monitoring

  • Deposits within 24h that exceed 5× the player's monthly average.
  • Rapid deposit-then-withdrawal cycles with negligible gaming activity ("chip dumping").
  • Multiple failed deposits followed by a successful one from a different card or wallet.
  • Geographic mismatches: KYC address in country A, session IPs from country B for >30 days.
  • Structuring: repeated deposits just under the enhanced-due-diligence threshold.

Suspicious Activity Reports

When monitoring flags a case, the compliance team must decide within 30 days whether to file a Suspicious Activity Report (SAR) with the local FIU (Financial Intelligence Unit — FIAU in Malta, FinCEN equivalent in the US, NCA in the UK). Filing a SAR is confidential — you cannot tip the player off.

Record retention

Keep every KYC document, screening result, transaction record and SAR for 5 years minimum after the customer relationship ends (10 in some LatAm jurisdictions). AS Tech's operator panel automatically retains this data with role-based access controls and audit logs.

Frequently asked questions

What does KYC stand for?+

Know Your Customer — the regulatory process of verifying a player's identity, age and source of funds before allowing high-value activity.

What does AML stand for?+

Anti-Money Laundering — the framework of controls (transaction monitoring, sanctions screening, suspicious activity reporting) that prevent gambling platforms from being used to launder illicit funds.

When must an operator KYC a player?+

At minimum: before a first withdrawal, when deposits cross a jurisdiction-specific threshold (e.g. €2,000 in the EU), and whenever risk signals appear (rapid deposits, geo-mismatch, chargebacks).

Which KYC providers integrate with AS Tech?+

Sumsub, Jumio, Ondato and Veriff are supported natively. Custom providers can be wired via the KYC webhook contract in the operator panel.

Is PEP/sanctions screening mandatory?+

Yes for regulated jurisdictions (MGA, UKGC, Isle of Man, Gibraltar). Curaçao licensees are also expected to screen against OFAC, EU and UN sanctions lists as a matter of banking-partner risk policy.

How long must AML records be retained?+

Five years is the global baseline. UK, Malta and most EU jurisdictions require 5 years from the end of the customer relationship; some LatAm jurisdictions require 10.