The FATF published red flags for gaming and gambling on 9 September 2026. What they say about identity evasion, CDD thresholds and SARs for casinos and betting.
Table of contents
On 9 September 2026 the Financial Action Task Force published FATF gambling risk indicators that include identity evasion among the main money laundering signals across casinos, betting and online gaming. The red flags are non-binding guidance, but they give supervisors and operators a shared checklist for testing whether due diligence and monitoring are risk-based.
- The FATF published "Risks of Gaming and Gambling", a set of key findings and red-flag risk indicators, in Paris on 9 September 2026.
- The work drew on questionnaire responses from 80 jurisdictions and written comments from 29, and is the FATF's first detailed look at online and illegal gambling.
- Land-based and online casinos and sports betting are the most exposed; lotteries and scratch cards may be less exposed in some jurisdictions.
- Many red flags are identity signals: multiple accounts under fake names, refusal to verify on video, doctored documents and payment details that do not match the player.
What did the FATF publish on gaming and gambling?
The FATF published a 13-page report of key findings and red-flag indicators covering casinos, sports and novelty betting, other non-casino gambling and online video and mobile gaming. It updates the FATF and Asia/Pacific Group casino analysis of 2009, and adds illegal and offshore gambling.
The FATF press release calls it the FATF's first detailed examination of risks associated with online and illegal gambling. The headline finding is blunt. The FATF report states that "ML through gambling is an established risk across many jurisdictions." Terrorist financing typologies were more visible in online gaming than gambling, and proliferation financing risk in both was described as very limited.
Illegal gambling is the second major theme. The report says illegal markets rival or exceed legal ones in some countries, attracting players with promotions and confidentiality. In its press release, the FATF quoted President Giles Thomson warning that without safeguards "these sectors can be attractive gateways for fraudsters", and noted that operational case studies went only to public authorities.
| Item | Detail |
|---|---|
| Publisher | Financial Action Task Force, Paris |
| Published | 9 September 2026 |
| Document | Risks of Gaming and Gambling: key findings and red-flag risk indicators |
| Evidence base | Questionnaires from 80 jurisdictions, written comments from 29, industry consultation |
| Legal status | Non-binding guidance; no change to the FATF Recommendations |
| Previous global work | FATF and APG casino vulnerabilities report, 2009 |
How are the FATF gambling risk indicators organised?
The FATF gambling risk indicators fall into five groups: customer behaviour and profile, online accounts, betting patterns, payment methods and transactions, and product and platform features. Most came from land-based and online casinos, with fewer from betting. Video game indicators were rare, but the FATF says some casino and betting flags also apply to games.
Identity and profile signals
The online list in the FATF report reads like a KYC failure log. It flags repeated VPN use, multiple devices, and a gap between claimed residence and detected location. It also flags attempts to open multiple accounts under the same or a fake name, "reluctance or refusal to appear on video call to verify identity", and attempts to re-register a closed account. For both channels, it adds doctored or hard-to-authenticate documents, inconsistent personal information and customers who try to bypass CDD.
Payment and betting signals
In the payment and betting lists, payment flags centre on mismatches: betting account details that differ from the payment method, several payment methods in different names, and deposits from unrelated third parties. Betting flags include hedging on all outcomes, deposits followed by withdrawals with minimal play, structuring below reporting thresholds, and winnings collected just below an identification threshold.
Operator and ownership signals
The platform group turns the lens on operators. It lists complex cross-border ownership that conceals control during licensing, shareholdings structured to stay below regulatory check thresholds, white-label dependence without oversight, and "sham merchants" that disguise gambling payments as ordinary retail.
The FATF adds an important caveat: one indicator alone is not necessarily evidence of illicit activity, and some indicators may reflect problem gambling rather than laundering.
What do the FATF gambling risk indicators mean for your obligations?
The FATF gambling risk indicators do not create new duties, but they give firms and supervisors a detailed test of existing ones. Four duty sets are affected: customer due diligence at the gambling threshold, identity verification quality, source of funds and screening, and suspicious activity reporting. Each has a legal hook in at least one regime cited below.
This table maps FATF gambling risk indicators to detection data and the provisions cited below.
| Indicator group | Data point that detects it | Legal hook |
|---|---|---|
| Betting patterns | Linked stakes and winnings near the threshold | MLR 2017 reg. 27(5); AMLR Art. 19(5) |
| Customer profile, identity | Fake-name accounts, altered documents, refusal to verify | MLR 2017 reg. 28; AMLR Art. 20(1)(a) |
| Online accounts | Device, IP and address changes against the declared profile | MLR 2017 reg. 28(11); AMLR Art. 20(1)(f) |
| Customer profile, funds and screening | PEP status, sanctions match, funds inconsistent with profile | MLR 2017 reg. 35(5); AMLR Art. 20(1)(d) |
| Payment methods | Payment instrument name differing from the account holder; third-party deposits | MLR 2017 reg. 28; 31 CFR 1021.320 |
Product and platform indicators concern operator licensing and ownership rather than customer due diligence, so they are not mapped to a CDD provision.
CDD thresholds and linked transactions
Several betting red flags describe customers keeping just below a threshold, so the threshold and the linking rules matter. The FATF standard sets USD/EUR 3,000 for casinos under the Interpretive Note to Recommendation 22. In the UK, regulation 27(5) of the Money Laundering Regulations 2017 requires casinos to apply CDD to stakes or winnings of £2,000 or more, including linked operations, a sterling figure in force since 30 June 2026. Under Article 19(5) of the EU AML Regulation, providers of gambling services must apply CDD at EUR 2,000, and Article 90 makes the Regulation apply from 10 July 2027. Recital 64 says gambling providers should be able to attribute transactions to a customer before verifying identity, so they can tell when the threshold is met.
| Regime | Trigger | Status |
|---|---|---|
| FATF Recommendation 22 | Casino transactions of USD/EUR 3,000 or more | Standard, implemented nationally |
| UK MLR 2017, reg. 27(5) | Casino stakes or winnings of £2,000 or more, linked operations included | In force (sum substituted 30 June 2026) |
| EU AMLR 2024/1624, Art. 19(5) | Gambling stakes or winnings of EUR 2,000 or more, linked transactions included | Adopted, applies from 10 July 2027 |
| US 31 CFR 1021.311 | Currency transactions over $10,000 (CTR) | In force |
| US 31 CFR 1021.320 | Suspicious transactions of at least $5,000 (SAR) | In force |
Identity verification and ongoing monitoring
Refusal to verify on video, fake-name accounts and doctored documents are verification-quality signals, not only monitoring alerts. Regulation 28 of the MLR 2017 requires firms to identify and verify customers and, under regulation 28(11), to monitor relationships and keep CDD records up to date. Article 20(1) of the AML Regulation sets the same verification and ongoing monitoring duties in the EU. Operators should be able to show that verification detects reused identities and manipulated documents, and that ongoing monitoring re-triggers checks when devices, addresses or payment instruments change. Our guide to KYC for online casinos sets out the onboarding steps.
Source of funds, sanctions and PEP screening
The profile list names sanctions list matches, links to sanctioned states, PEP status and funds inconsistent with a customer's profile. That places source of funds and source of wealth checks, and screening at onboarding and on change, inside the same review. For PEPs, regulation 35(5) of the MLR 2017 requires senior management approval and adequate measures to establish source of wealth and source of funds. Article 20(1)(d) of the AML Regulation requires checks on whether customers and beneficial owners are subject to targeted financial sanctions. Our source of funds verification guide and PEP screening guide cover the evidence standard.
Suspicious activity reporting
In the US, 31 CFR 1021.320 requires casinos to report suspicious transactions involving at least $5,000, including structuring. The indicators give examiners a shared vocabulary for testing whether alerts on minimal play, third-party deposits or chip dumping led to a documented decision. See our suspicious activity report glossary entry.
What is still uncertain after the FATF report?
The biggest uncertainty is calibration. The FATF gambling risk indicators are long, partly overlapping and explicitly non-exhaustive, and the FATF itself says some reflect problem gambling rather than crime. Operators must decide which combinations justify escalation without flooding analysts or treating vulnerable players as launderers.
False positives and legitimate behaviour
VPN use, multiple devices and a mismatch between IP address and stated location all have innocent explanations, from travel to privacy tools. A foreign national with no clear local connection is also listed. Turning those into automatic declines risks discrimination complaints and customer harm, so risk scoring needs documented weighting rather than single-flag triggers.
Private sector gets the lists, not the cases
The case studies and operational material sit on a platform open only to public authorities. Operators receive the red flags without the typologies behind them, which makes it harder to tune rules or explain to a board why a pattern matters.
Regulatory arbitrage and illegal markets
The report says divergent national frameworks enable arbitrage and hinder information sharing. Its recommendations, from stronger licensing to international co-operation, are suggestions only, with no timetable. Licensed operators can raise their controls while offshore operators serving the same customers stay out of reach.
Video gaming sits outside most regimes
The FATF found money laundering through video gaming smaller in scale today, and many connected services, such as marketplaces and social platforms, fall outside AML frameworks. Whether any jurisdiction extends obligations to in-game value transfer remains open.
More identity data, more breach exposure
Stronger verification pushes operators to collect more identity documents and selfies. Stored copies become a target, as the IDScan breach showed. How to satisfy the indicators while minimising retained data is a design question the report does not address.
How does this compare with earlier gambling AML guidance?
The 2026 report is broader than the FATF's earlier casino work. The 2008 risk-based approach guidance for casinos and the 2009 FATF and APG vulnerabilities report focused on casinos. The new project covers betting, lotteries, online and illegal gambling and video gaming, and adds payment channels such as e-wallets, mobile money and virtual assets.
National supervisors have been moving in the same direction. The UK Gambling Commission flagged AI-forged identities in its 2026 risk assessment. The FATF list now gives that national finding a common global reference point.
How should compliance teams respond?
Compliance teams should run a gap analysis of the FATF gambling risk indicators against their current rules, mapping each flag to an existing detection, a new rule, or a documented reason it does not apply. Record the weighting logic, especially for flags that overlap with problem gambling.
Next, test threshold attribution: can the platform link stakes and winnings across sessions, devices and payment methods before identity is verified? Review whether onboarding catches reused identities and altered documents, and whether device, address or payment changes trigger re-verification. Add operator-level checks, including beneficial ownership of white-label partners and payment agents. Finally, train staff on the brick-and-mortar flags, such as bribery attempts and third-party chip purchases.
For operators that need stronger identity assurance without uploading ID images, Zyphe reads the document's NFC chip to the ICAO 9303 standard, runs two-step liveness, and splits personal data so there is no single store of ID copies to breach. See our KYC for iGaming page or book a demo.
The bottom line
The FATF has written down what gambling supervisors already probe: whether an operator knows who is really playing, whose money funds the account, and who owns the platform. Many of the new red flags are identity and payment mismatches visible at onboarding. Operators that treat identity assurance and threshold attribution as one control will find the indicators easier to evidence.
Cited sources
- FATF, press release: FATF warns of emerging risks in gaming and gambling and publishes new risk indicators, 9 September 2026
- FATF, Risks of Gaming and Gambling: key findings and red-flag risk indicators, September 2026 (PDF)
- FATF Recommendations, Interpretive Note to Recommendation 22, casino CDD threshold (PDF)
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, regulation 27
- Money Laundering Regulations 2017, regulation 28, customer due diligence measures
- Money Laundering Regulations 2017, regulation 35, politically exposed persons
- Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing, Articles 19 and 20 and recital 64
- Regulation (EU) 2024/1624, Article 90, entry into force and application
- 31 CFR 1021.311, casino currency transaction reporting
- 31 CFR 1021.320, casino suspicious transaction reporting
- FATF and APG, Vulnerabilities of Casinos and Gaming Sector, March 2009
- FATF, Guidance on the Risk-Based Approach for Casinos, October 2008
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.