Getting licensed is the beginning of an operator’s compliance obligations, not the end of them. AML and responsible-gambling duties are where most ongoing regulatory attention — and most enforcement action — actually lands.
What AML compliance covers in practice
For a licensed operator, AML compliance is a live system, not a policy document: customer due diligence at onboarding, source-of-funds checks that scale with a player’s activity, ongoing transaction monitoring for unusual patterns, and a process for filing suspicious-activity reports with the relevant authority. Regulators expect a named person responsible for AML, not just a written procedure sitting unused.
Responsible gambling as a compliance function, not a slogan
Responsible-gambling obligations typically include self-exclusion tools, deposit and loss limits, affordability checks triggered by play patterns, and staff training to recognise signs of harm. Regulators increasingly assess whether these tools are actually used and acted on — a self-exclusion feature that exists but isn’t enforced is a compliance gap, not a compliance measure.
Where operators most often fall short
Enforcement patterns across jurisdictions point to recurring gaps: monitoring systems that flag risk but don’t trigger a documented review, marketing that reaches self-excluded or vulnerable players, and AML policies that aren’t updated as the business or its markets change. Most of these are process failures rather than knowledge failures — the obligation was understood, but not operationalised.
Building compliance that scales with the business
The operators who manage this well tend to treat compliance as infrastructure: monitoring tools that grow with transaction volume, policies reviewed on a set schedule rather than only after an incident, and clear internal ownership. That’s also what regulators are checking for at renewal and audit — evidence that compliance runs day to day, not just that it exists on paper.