FATF Gaming and Gambling Risks: The New AML Red-Flag Indicators

On 9 September 2026 the Financial Action Task Force published Risks of Gaming and Gambling, a Methods and Trends report drawn from contributions by more than 80 jurisdictions, industry associations and researchers, and it arrived with a set of new red-flag indicators written for compliance teams. For anyone running anti-money laundering controls inside a casino, an online betting platform or a gaming operator, the FATF gaming and gambling assessment is the risk reference every AML team at a casino or online operator needs to work through.

The report frames the sector as increasingly digital, cross-border and interconnected, and it warns that money laundering, terrorist financing and proliferation financing risks are emerging across casinos, gambling and online gaming. The report covers online platforms, the payment channels that feed player accounts, illegal operators, and the links between all of these and the wider financial system. The through-line for a reporting officer is practical: the indicators give you a fresh checklist to test your customer due diligence, your transaction monitoring rules and your suspicious transaction reporting against.

The report is a risk picture, not a new legal instrument. Your AML obligations continue to flow from the national law that transposes the FATF standards, the relevant regulation, directive or act where you are licensed. The 2026 publication identifies risk areas and indicators intended to help governments, regulators and private-sector entities identify and respond to money laundering, terrorist financing and proliferation financing risks.

Related reading: the FATF fraud roadmap for 2026 to 2028, which sits alongside this report in the same push on illicit-finance typologies.

What the FATF gaming and gambling report actually says

Risks of Gaming and Gambling is a typologies-and-indicators report, the kind the FATF files under Methods and Trends. It sets out findings on how the sector is misused and a list of behaviours that should prompt closer review. A common misreading holds that publishing a FATF report alone switches on new obligations; the report carries no new Recommendation, no additional return, no template and no filing deadline. The obligations continue to flow from national AML law. The report is the evidence base a supervisor can point to when examining whether your monitoring covered a pattern the FATF has now described in plain terms.

The sector has been on the FATF’s radar for a long time, which is why the 2026 report reads as an update built on nearly two decades of earlier work. In October 2008 the FATF adopted its Guidance on the Risk-Based Approach for Casinos, developed with the casino sector, setting out how a risk-based approach should work in practice. The following March, the APG and FATF published Vulnerabilities of Casinos and Gaming Sector, noting that casino obligations had been significantly enhanced in the revision of the FATF Recommendations. The 2026 report, published in Paris on 9 September, builds on that foundation.

My read of the 2026 report is that its centre of gravity has shifted from the land-based casino floor, where earlier FATF work concentrated, to the online, cross-border operator and the payment rails that feed it. That shift is the reason the indicators lean so heavily on geography, source of funds and account behaviour instead of chips and cage transactions.

Casinos, Online Gambling and the Obliged-Entity Boundary

Casinos have sat inside the FATF framework for years as a designated non-financial business, with obligations that were deliberately strengthened when the Recommendations were revised. The 2026 report widens the practical focus to online gambling and sports-betting operators and to the platforms and payment providers around them. Whether that focus becomes a legal obligation for a given operator still depends on how the local regime defines a gambling service.

Regulation (EU) 2024/1624 entered into force in 2024 but applies from 10 July 2027. From that date, providers of gambling services are obliged entities under the Regulation, subject to Article 4. Member States may exempt providers of gambling services in full or in part on proven low risk, subject to the Article 7 Commission-confirmation process. Casinos cannot be exempted. Providers whose principal activity is online gambling or sports betting also cannot be exempted, except for online gambling operated by the State or whose organisation, operation and administration are regulated by the State. Until 10 July 2027, the applicable EU-level framework remains Directive (EU) 2015/849 as transposed into national law; under Article 2(2) of that Directive, Member States may exempt certain gambling services other than casinos in full or in part following a risk assessment and notification to the Commission.

Australia draws a similar perimeter through a different mechanism. The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 lists gambling services as designated services, including paying out winnings or awarding a prize in a game of chance or mixed chance and skill carried on as a gambling business, so operators there are reporting entities in their own right. The lesson for a group operating across borders is that the FATF report is one document, but the entity that owes the duty, and the exact trigger, is defined jurisdiction by jurisdiction.

Where the money moves: the payment channels the report flags

The report’s most operationally useful section for a monitoring team is its treatment of payment channels. It identifies payment systems used in gaming and gambling, including cash, e-wallets, mobile money and virtual assets, as vulnerable to money-laundering risks. The concern is that online gaming and gambling operators increasingly let value move rapidly, with limited friction, across borders, and convert between forms, so a player account can act as a switching point between a card, an e-wallet, a mobile balance and a token.

Virtual assets carry a specific warning because they combine speed, pseudonymity and cross-border reach. Crypto deposits or token payouts require a separate virtual-asset perimeter assessment. Under the FATF definition, VASP status depends on whether a person, as a business, conducts specified virtual-asset activities or operations for or on behalf of another natural or legal person; accepting a virtual asset as payment does not by itself establish VASP status. Our guide to the FATF standards on stablecoins and unhosted wallets sets out where those separate duties begin. The practical point is that monitoring has to cover the deposit and withdrawal rails and not stop at the wagers, because the laundering risk lives in how value enters and leaves the account.

The typologies: money in, money out, little gambling

Across the typologies, one pattern recurs: an account is funded, the balance moves, and very little genuine gambling happens in between. The report describes funds going in and out of accounts with minimal betting activity, transactions structured into smaller amounts to stay below thresholds, a practice known as smurfing, and unusual or coordinated betting linked to possible competition manipulation. Illegal and offshore operators are also among the sector’s most significant risks, including illegal gambling promoted through digital platforms and social media.

An auditor examining this evidence would test one ratio first: money staked against money moved. A customer who deposits large sums, wagers a fraction and withdraws the balance to a different instrument is using the account as a conduit, and high turnover through an account is not the same thing as gambling activity. Unusually large or co-ordinated bets on events flagged for possible competition manipulation are a distinct pattern identified by FATF. The question a monitoring team should be able to answer for any flagged account is simple to state and hard to fake: what did this customer actually play, and does it explain the money that passed through?

The new red-flag indicators, and how to wire them in

The report’s new indicators are the part most worth operationalising, because they translate directly into monitoring scenarios. The behaviours it highlights for compliance teams include transactions from an IP address that does not match the customer’s stated location; customers accessing the platform from a jurisdiction where the gambling activity is illegal; reluctance to provide source-of-funds information; customers or counterparties connected to higher-risk jurisdictions; and large cumulative deposits and withdrawals with little or no corresponding betting.

Risk indicators should feed into monitoring and investigation, but escalation must not be conditioned on multiple indicators being present. A single fact or indicator can be sufficient where, viewed in context, it creates knowledge, suspicion or reasonable grounds to suspect under the applicable AML law. Calibrate monitoring so that indicators are assessed individually and in combination, with the legal suspicion threshold governing any reporting decision.

Customer due diligence: the thresholds that actually bite

The FATF Recommendations set a designated CDD threshold for casinos: Recommendation 22 requires casinos to apply Recommendation 10, including customer identification and verification, when customers engage in financial transactions of at least USD/EUR 3 000. Domestic law determines the binding local trigger and may impose a different or lower threshold.

Under the EU framework currently applicable in September 2026, Article 11 of Directive (EU) 2015/849 requires CDD for gambling-service transactions of at least EUR 2 000, whether in one operation or several linked operations; its general occasional-transaction threshold is EUR 15 000. Regulation (EU) 2024/1624 will apply from 10 July 2027. Its Article 19 retains the EUR 2 000 gambling trigger, sets a general occasional-transaction threshold of EUR 10 000, and requires at least customer identification and verification for occasional cash transactions of EUR 3 000 or more. Article 19(9) mandated AMLA to develop and submit draft regulatory technical standards by 10 July 2026. AMLA’s 2026 consultation covered criteria for business relationships, occasional and linked transactions and possible lower thresholds; AMLA stated that, at that stage, it had chosen not to introduce additional lower CDD thresholds. AMLA continues to list the Article 19(9) instrument as a draft RTS.

Casinos get a specific accommodation. A casino may identify and verify the customer on entry to the premises, provided it has systems that attribute later transactions, including the purchase and exchange of gambling chips, back to that customer, which spares it from checking identity at every table or cash-desk transaction. A common error is to read CDD as a one-time onboarding event. The threshold logic means an operator has to attribute and monitor activity before the point at which verification is triggered, so it can tell when a run of smaller transactions has crossed EUR 2 000. Building that attribution capability is the difference between a control that works and one that only appears to work.

Suspicious transaction reporting when the play does not add up

The reporting duty is where the indicators and the CDD thresholds meet. For an operator that remains an obliged entity under the applicable AML regime, suspicion is a reporting trigger regardless of transaction amount. Under Article 11(e) of Directive (EU) 2015/849, CDD applies on suspicion regardless of any derogation, exemption or threshold. A gambling service that has been exempted in full or in part under Article 2(2) must, however, be assessed against the scope of that exemption and the applicable national law before assuming that the same reporting obligations continue to apply. In Luxembourg, for example, that report goes to the Cellule de Renseignement Financier through goAML, and our walkthrough of the goAML suspicious transaction reporting workflow shows how the file is built and submitted.

The quality of that report is what a supervisor examines after the fact. A report that simply attaches the alert without explaining the account behaviour, the deposit-to-wager mismatch, the payment channels used and the geography involved gives the FIU little to work with. The 2026 indicators are useful here as a drafting aid: they name the features an analyst should describe, which turns a thin alert into a report that an FIU can actually action.

How the global standard becomes binding at home

The FATF Recommendations are international standards that jurisdictions implement through measures adapted to their circumstances. FATF mutual evaluations assess jurisdictions’ technical compliance with the Recommendations and the effectiveness of their AML/CFT/CPF systems; they do not themselves create or enforce firm-level legal obligations. The 2026 gaming and gambling report can inform risk assessment and supervision, but binding duties for firms come from the applicable domestic or EU legal framework.

For a reporting officer, the sequence is worth keeping straight. Read the FATF report for the risk picture and the indicators. Then check your obligation against the local instrument that actually governs you, whether that is the EU AML Regulation, the Australian Act or a national gambling-and-AML regime, because the trigger, the threshold and the reporting channel are set there. AUSTRAC’s 2026 materials confirm that gambling remains an active supervisory risk area: in May 2026 it ordered an external audit of a NSW club over AML concerns involving poker machines, and its current guidance includes suspicious-activity indicators for casinos and other gambling-related sectors.

Frequently Asked Questions

Does the FATF report create a new reporting obligation for my firm?

Risks of Gaming and Gambling is a typologies and indicators report, not a new legal instrument. It carries no new template, no return and no filing deadline. Your obligations continue to come from the AML law applicable where you are licensed, and the report is the risk evidence a supervisor has when examining whether your controls addressed a pattern the FATF has described.

Are online video-gaming platforms in scope the same way a casino is?

The report covers online gaming and platforms as a misuse channel, but a formal customer due diligence duty attaches to activities that count as a regulated gambling service under local law. In-game currencies and marketplaces can be used to move value even where the operator is not a licensed gambling service, so flag that exposure for monitoring and check the local definition before assuming it sits inside or outside the perimeter.

If a customer keeps every bet under EUR 2 000, do we still have to do anything?

Yes. In the EU, linked transactions that add up to EUR 2 000 or more trigger customer due diligence, so an operator must be able to aggregate a run of smaller stakes. Separately, if the pattern resembles structuring to stay below the threshold, that is itself a reason to consider a suspicious transaction report, independent of any threshold.

We run a State-administered lottery in the EU. Are we exempt?

Possibly, but not automatically. Under the framework currently applicable in September 2026, Directive (EU) 2015/849 allows Member States, after an appropriate risk assessment, to exempt certain gambling services other than casinos in full or in part and to notify the Commission. From 10 July 2027, Regulation (EU) 2024/1624 will introduce a Commission-confirmation process; casinos remain non-exemptible, while the no-exemption rule for online gambling and sports betting contains exceptions for State-operated online gambling and online gambling whose organisation, operation and administration are regulated by the State.

Do we file a report whenever one of the FATF red-flag indicators appears?

An indicator does not automatically determine whether a report is required. Under Article 33(1) of Directive (EU) 2015/849, an obliged entity must cooperate fully by promptly informing the FIU, including by filing a report, where it knows, suspects or has reasonable grounds to suspect that funds, regardless of amount, are the proceeds of criminal activity or are related to terrorist financing; all suspicious transactions must be reported.

How do virtual-asset deposits change our obligations?

Crypto deposits or token payouts require a separate perimeter assessment. VASP or equivalent crypto-asset-service obligations apply only where the relevant activities and operating model fall within the applicable FATF and local legal definitions, so map the crypto flows and the entities performing each activity before launch.

A customer is playing from a country where our product is illegal. What does that indicator tell us?

It carries two signals at once. It is a laundering red flag under the FATF indicators, and it suggests your platform may be accepting bets it is not licensed to accept in that market. Geolocation and IP controls address both, which is why the report ties account behaviour to geography so tightly.

Key Takeaways

  • The FATF published Risks of Gaming and Gambling on 9 September 2026 with new red-flag indicators; the report is a risk lens and typology set, not a new legal obligation or reporting return. Map every indicator to the local instrument that governs you, whether Regulation (EU) 2024/1624, the Australian AML/CTF Act or your national equivalent, because the trigger and channel are set there, not in the FATF text.
  • From 10 July 2027, Regulation (EU) 2024/1624 will allow proven-low-risk gambling exemptions through the Article 7 Commission-confirmation process. Casinos cannot be exempted; the no-exemption rule for online gambling and sports betting does not apply to State-operated online gambling or online gambling whose organisation, operation and administration are regulated by the State.
  • The EU gambling CDD trigger is EUR 2 000 on winnings or stakes, counted across linked transactions; casinos may verify at entry if they attribute later chip and cash activity to the customer.
  • Cash, e-wallets, mobile money and virtual assets are the priority payment channels; monitor the deposit and withdrawal rails, not only the wagers.
  • Map verified FATF indicators into monitoring and investigation scenarios and assess them individually and in combination. Do not require multiple indicators before escalation where a single fact is sufficient to meet the applicable suspicion or reasonable-grounds threshold.
  • File a suspicious transaction report to the FIU on suspicion regardless of thresholds; for operators that remain obliged entities under the applicable regime, below-threshold activity does not switch the duty off.

Sources and References

What to do before your next inspection

Take the verified indicators and run them against your live monitoring rules this quarter. For EU operations, confirm that you can aggregate linked gambling transactions to the EUR 2 000 CDD threshold and, where you rely on entry verification at a casino or other physical gambling premises, attribute later transactions to the verified customer. For other jurisdictions, apply the threshold and attribution rules in the applicable local AML law. Where the crypto rails are open, check whether virtual-asset service provider obligations apply before the next deposit lands. The FATF report is the risk picture; the deliverable is an updated risk assessment and a monitoring scenario set that a supervisor can see you have already mapped to the indicators.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • FINMA Sudan and South Sudan Sanctions: Annex 2 Updated 11 August

    FINMA published two updated sanctions notifications on 11 August 2026, one for Sudan and one for South Sudan, after the Federal Department of Economic Affairs, Education and Research (EAER/WBF) amended Annex 2 of each ordinance. For a Swiss supervised institution, the FINMA notifications are an operational alert that the relevant Annex 2 lists changed. The…

  • Luxembourg AML Law: CRF Fraud Alerts for Banks and CASPs

    On 4 August 2026, Luxembourg published the Law of 22 July 2026 in Mémorial A No 412. It is a short instrument, two substantive articles, and it adds a power the Luxembourg AML law had not carried before: it lets the Cellule de renseignement financier (CRF), the country’s financial intelligence unit, push fraud-risk account numbers…

  • AMLA Risk Assessment Data Collection: The 2027 Selection Exercise

    From 2028, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) is due to directly supervise a first group of up to 40 credit and financial institutions or groups across the EU; under Article 13(4) of Regulation (EU) 2024/1620, direct supervision starts six months after AMLA publishes the selected-entity list. The exercise…

  • AMLA Central Contact Point Survey: The 15 September Deadline for PSPs

    On 6 August 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) opened a voluntary survey asking electronic money institutions (EMIs) and payment service providers (PSPs) about their experience with the central contact point framework, and the window closes on 15 September 2026. The CSSF relayed the exercise to the Luxembourg…

  • CSSF de-risking communique: managing ML/FT risk instead of avoiding it, what Luxembourg-regulated firms must address in their AML/CFT frameworks

    Updated July 2026In this guideWhat the CSSF de-risking communique actually saysThe Luxembourg legal basis the communique sits onWhy blanket exits weaken your own frameworkWhat the EBA guidance expects insteadHow simplified and enhanced due diligence fit the pictureWhat AMLR and AMLA change from July 2027The FATF backdrop and why “proportionate” is now the testBuilding a de-risking…