
A casino has two separate jobs to do before it lets anyone play with real money. First, it has to confirm a player is who they say they are, their identity, their age, their address. That is KYC, Know Your Customer. Second, it has to track where a player's money comes from and where it goes, so the platform is never quietly used to clean illegal cash. That is AML, Anti-Money Laundering. Doing either by hand for every player would be too slow to run a real casino, which is why Whitelabels.com and every serious operator automates both. Here is what each check does, why a casino needs both and not just one, and what changes once software does the work instead of a person.
What does KYC mean for an online casino?
KYC means verifying that a player is a real person, not a stolen or fake identity, and that they meet the age and location rules for the market they are playing in. In practice that means checking a government ID document (a passport, a driver's license, a national ID card), confirming the date of birth on it, and verifying an address. No regulated casino can legally let a player deposit and gamble before this step clears.
The UK Gambling Commission's license conditions spell this out directly: operators must obtain and verify information to establish a customer's identity before that customer is permitted to gamble (LCCP Condition 17.1.1). It is not a nice-to-have step done for good practice. It is a licensing requirement, checked and enforced.
What does AML mean for an online casino?
Where KYC asks who a player is, AML asks a different question: is this player's money clean, and is the casino being used to move dirty money around. Criminals have long used gambling businesses to "wash" illegal cash: buy chips or credits with money from crime, play a little, then cash out with a clean-looking receipt that hides where the money came from. AML is the set of checks, limits and monitoring rules built to catch that pattern before it works.
The UK Gambling Commission requires every licensed operator to run a formal assessment of its money laundering and terrorist financing risk, then keep policies and controls in place to manage it (LCCP Condition 12.1.1). That assessment has to stay current and gets reviewed, not written once and filed away.
Why does a casino need both KYC and AML, not just one?
Because they answer different questions, and a casino can pass one while failing the other completely. A player can be exactly who their ID says they are (KYC clears) while still using the casino to launder money earned somewhere else illegally (an AML failure). The reverse happens too: an operator can run decent transaction monitoring while letting stolen or fabricated identities open accounts unchecked. Closing one gap and leaving the other open still leaves the whole platform exposed.
Real enforcement cases prove this is not a theoretical distinction. When the UK Gambling Commission fined bet365 £582,120 in April 2024, the failures cited sat on both sides at once: ineffective customer due diligence and incomplete financial sanctions checks on new customers (the KYC side), plus a weak Early Risk Detection System that should have caught unusual behavior after the fact (the AML side).
What happens during an automated identity check?
A player uploads a photo of their ID document and takes a live selfie. From there, a real automated pipeline runs through several steps in quick order:
- Document capture and data extraction. Optical character recognition (OCR) reads the name, date of birth, document number and expiry date off the ID and turns them into structured data the system can check.
- Forgery and tamper detection. Software examines the document's security features, its fonts, layout, holograms and microprint, for the kind of mismatches a fake or altered document tends to have.
- Liveness detection. The system confirms a live person is in front of the camera right now, not a printed photo, a recorded video, or a mask, since a static image is the easiest way to fake a selfie.
- Biometric face matching. The selfie gets compared to the photo on the ID document to confirm it is the same person holding it.
Only after all four steps clear does the identity move on to watchlist screening. A manual version of this same process, someone visually comparing a photo to an ID, squinting at a hologram, and trying to remember what a real passport font looks like, would take a trained reviewer minutes per document and would still miss forgeries a machine catches on its own. The automated version usually finishes in seconds.

What makes an AML system flag a player?
Two layers run here, one at signup and one for as long as the account stays open.
The first is watchlist screening. The moment an identity clears KYC, the player's name gets checked against sanctions lists, most notably the US Treasury's OFAC Specially Designated Nationals List, which names individuals and entities tied to terrorism, sanctioned regimes and organized crime. It also gets checked against politically exposed person (PEP) lists, which flag people who hold prominent public roles (heads of state, senior politicians, senior military officials) along with their close family, since their position carries a higher bribery and corruption risk. Being on a sanctions list generally means the casino cannot do business with that person at all. Being a PEP means extra scrutiny, not an automatic refusal.
The second layer is ongoing transaction monitoring, and this is where the classic example applies: a player who normally deposits $20 a session suddenly deposits $50,000 out of nowhere. That kind of jump gets flagged instantly, not because $50,000 is illegal on its own, but because it breaks so sharply from that player's own pattern that a human needs to look at it before more money moves. This is not a hypothetical either. When the UK Gambling Commission fined William Hill a record £19.2 million in 2023, one of the failures on record was a customer who staked £276,942 and lost £24,395 over two months, with source-of-funds evidence never requested at any point. A year earlier, Entain was fined £17 million after a customer deposited up to £186,000 over six months with the same check missing.
What happens after a transaction gets flagged?
If a review confirms real suspicion, the casino has a legal duty to file a Suspicious Activity Report, a SAR, with the relevant financial intelligence unit. In the United States, that is FinCEN, and the duty applies to any transaction involving $5,000 or more that the casino knows or suspects is tied to illegal funds, filed within 30 calendar days of first detecting the activity (extendable to 60 days if a suspect still needs identifying). In the UK, the same kind of report goes to the National Crime Agency under the Proceeds of Crime Act 2002, and UK operators can face criminal prosecution, not just a regulatory fine, for failing to file one when the law requires it.
A SAR is also confidential by law. A casino, or anyone working for it, cannot tell the customer a report was filed, which is why a flagged player is rarely told exactly why their account is under review.
What happens when a casino gets KYC or AML wrong?
The fines above are not one-off events. Since bet365's £582,120 penalty in 2024, the pattern keeps repeating across the industry: a customer deposits and loses a large sum, and nobody at the operator ever asks where the money came from. William Hill's record £19.2 million fine in 2023 covered three of its own businesses at once, and the Commission noted the failings were serious enough that it considered suspending the license outright before settling on a penalty. Entain's £17 million fine the year before followed the same shape: real money moving through real accounts with a missing check that should have caught it early.
If you are still deciding which regulator to build under in the first place, what a UK Gambling Commission license involves is worth reading alongside this, since the licensing cost and the compliance workload it commits you to are the same decision, not two separate ones.
What does automation change here?
Everything above, document checks, watchlist screening, transaction monitoring, used to be manual work done by compliance staff reading paperwork and comparing lists by hand. That does not scale past a small handful of players a day, and it is slow enough that honest players notice the wait. Automation is what lets a casino run the full KYC and AML pipeline in seconds for the overwhelming majority of players who are exactly who they say they are and depositing money that is exactly what it looks like, while still catching the small share of cases that need a real person's judgment.
This is also why compliance sits on the platform's side of the table on Whitelabels.com rather than yours. KYC and AML infrastructure ships built into every casino launched through the platform, configured to your license and your markets, so a new watchlist, a new reporting threshold, or a new enforcement trend is something tracked and handled on our side, not a compliance system you have to build and staff from nothing.
Do you really understand KYC and AML automation?
Answer 5 questions to see how solid your grasp of KYC and AML really is. Nothing is sent anywhere, this runs in your browser.
The bottom line
KYC checks who a player is. AML checks where their money comes from and where it goes. Regulators require both, and the fines keep landing on operators who treat either one as optional: bet365 in 2024, William Hill in 2023, Entain in 2022, each for a version of the same missing check. Doing this by hand for every player was never realistic at any real scale, which is exactly why automation exists. Software can scan a document, confirm a live face, screen a name against a watchlist and watch a deposit pattern in seconds, all at once, for every player, every time. That is what lets a casino stay compliant without making honest players wait for it.
Key takeaways
- KYC verifies a player's identity, age and address. AML tracks where their money comes from and where it goes. Regulators require both, not one or the other.
- A real automated identity check runs document forgery detection, liveness detection and biometric face matching, then screens the player's name against sanctions and politically exposed person lists, in seconds.
- In the United States, a casino must file a Suspicious Activity Report with FinCEN on any suspicious transaction of $5,000 or more, within 30 days of first detecting it.
- The UK Gambling Commission fined bet365 £582,120 in April 2024 for weak anti-money laundering checks, a year after fining William Hill a record £19.2 million for the same kind of failure at a much larger scale.
- The pattern behind most of these fines is the same one: a customer deposited and lost large sums with no source-of-funds check ever requested, which is exactly what automated monitoring exists to catch.
- Automation is what lets a casino run these checks in seconds instead of days, without slowing down the vast majority of players who are not doing anything wrong.
Sources and further reading
- UK Gambling Commission: LCCP Condition 12.1.1, Anti-money laundering
- UK Gambling Commission: Bet365 to pay £582,120 for regulatory failures
- UK Gambling Commission: How to submit Suspicious Activity Reports (SARs)
- eCFR: 31 CFR 1021.320, Reports by casinos of suspicious transactions
- US Treasury OFAC: Sanctions List Search Tool





