SupportIf gambling is causing harm, call GamCare free on 0808 8020 133, 24 hours, or visit gamcare.org.uk. GamStop.co.uk
Payments · UK 2026

Payments and checks, banks, cards, crypto, KYC

This chapter reads the payments layer from inside a UKGC-licensed compliance function. It walks through how a source of funds request actually gets drafted, sent, reviewed and closed, why the schedule sits where it does under the Money Laundering Regulations 2017, and what happens on a Curaçao-licensed operator when the same customer, the same deposit and the same risk profile arrive at the payments queue without an equivalent supervisor behind it.

  • 18+
  • Independent
  • Public sources
Payments and checks inside a UK licensed operator
01

UK Money Laundering Regulations 2017 in a paragraph

Every UK Gambling Commission licensee sits inside the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the domestic instrument that transposes the Fourth and Fifth Anti-Money Laundering Directives and, in scope terms, the Sixth. The regulations do not hand the operator a single deposit figure at which a check must trigger. They hand the operator an obligation to write a business-wide risk assessment, to design a set of customer due diligence steps proportionate to that assessment, and to keep the evidence of every decision on file for the statutory retention window. In practice this means the operator's compliance manual runs to several hundred pages, the risk-based trigger schedule sits inside it as a controlled table, and the schedule is reviewed at least annually against the Commission's most recent enforcement notes and the operator's own internal SAR volumes.

Inside the operator I worked for, the schedule ran from a low-touch identity check at registration, through a documentary Enhanced Due Diligence file at a defined cumulative deposit trigger, up to a full source of wealth review at a higher one. Each step generated an event in the customer's account record and, where evidence was requested, a documented reason for the request. When a Commission audit team visited, that reasoning was the first thing pulled from the file. The regulator does not test whether a threshold is hit at some famous round number, it tests whether the trigger schedule the operator wrote is applied consistently to the customer's actual profile. Payment size is one input into that decision, not the whole of it.

02

How offshore KYC differs from UKGC-licensed KYC

A UKGC-licensed operator's customer due diligence is not a form somebody fills in during onboarding, closes down, and never reopens. It is a live file that carries the identity check, the address check, the age check, the risk score, the affordability signals, the marker of harm history if any, the source of funds evidence at each threshold, the source of wealth evidence at each higher one, and the internal MLRO sign-off that closes each item out. The Commission requires the file to be complete before certain transactions can proceed. Under Social Responsibility Code Provision 5.1.1 the file also has to interact with the safer gambling data, so a payments query does not run in isolation from the customer interaction record on the same account.

On a Curaçao-licensed operator the file exists in some form because the Landsverordening op de Kansspelen (LOK), in force from 24 December 2024, does mandate customer due diligence. The difference is enforcement weight, personal accountability and depth. The Curaçao Gaming Authority is a single regulator now, which is an improvement on the pre-2024 master-licence chain, but there is no personal management licence regime that names the individual holding the compliance role at a level a UK court could reach. When I dealt with an offshore counterpart in a joint fraud investigation the file was legible, but the reviewers behind it did not carry the same accountability structure that a UKGC MLRO carries under Licence Condition 15.2.

A closer look

The layer that goes missing on the offshore side is not the identity check, which any respectable operator runs to satisfy its payment processors and card acquirers. The layer that goes missing is the reasoned link between an identity check, an affordability signal, a source of funds decision and a live safer gambling review, all held together by a supervisor whose personal management licence sits on the line. When that link is missing, a customer with early markers of harm sees no friction in the payments queue and a customer without those markers sees the same lack of friction. The lack of friction is presented as customer service, and it looks like customer service to the person on the other end of the login, but from the compliance seat it is the difference between an audited relationship and an unaudited one.

03

Bank blocks and card gambling switches in 2026

The voluntary card gambling switches offered by HSBC, Monzo, Starling, Lloyds and Barclays are one of the quieter successes of UK harm reduction. Each bank enforces the switch at a slightly different point in its stack. Some check the merchant category code against a block list at authorisation, so the transaction never reaches the receiving operator. Others enforce inside the mobile banking app, refusing a payment that matches merchant category code 7995 on any card issued on the account. All the big five now enforce a mandatory delay of between 48 hours and seven days between requesting the block off and the block coming off, and the delay is not adjustable at the customer's request during the window. It is designed to survive a craving.

From the operator side, an attempted deposit that is refused by the customer's bank does not always leave a clean visible trail on the operator's dashboard. The customer sees a decline. The operator sees an authorisation failure with a reason code. The customer does not always see the reason code, and if the customer is calling live chat to ask why the payment failed, the customer service adviser is not always in a position to answer with certainty. What the adviser can do, and what the adviser should do under Social Responsibility Code Provision 3.4.1, is decline to guide the customer into a workaround. Inside a UKGC operator that guardrail is a specific script, refreshed at each quarterly training cycle, and monitored via random call sampling. The guardrail is one of the harder things to police, and it is one of the things that vanishes when the operator is not answering to a UK regulator.

04

Visa, Mastercard and the UKGC 2025 taskforce

The 2025 taskforce convened by the Gambling Commission with the two major card schemes tightened the enforcement of merchant category code 7995 for online gambling transactions. The tightening had two dimensions. The first was scheme-side sanction risk for acquirers that let a receiving operator route a gambling transaction under a non-gambling category. The second was better visibility for the customer, because the standardised transaction description shown on the mobile banking app statement now reads consistently across issuers as a gambling transaction, rather than a generic e-commerce entry.

The practical consequence is that a UK adult depositing at an offshore site no longer has plausible ambiguity in the transaction description that appears on their own statement. The transaction reads clearly, the block if active enforces on that reading, and the audit trail visible to any future debt adviser, IFA, family member or clinician is legible. The tightening did not make the offshore market illegal for UK customers, and it did not close the door on deposits at Curaçao-licensed sites. What it did was raise the visibility of the flow, which is the harm-reduction outcome the taskforce was actually pursuing. Visibility is what a compliance team is quietly grateful for even when it is not what the marketing side of the same business wants to see.

Key points

  • UK KYC is risk-based, not threshold-based, and every trigger sits inside a written business-wide risk assessment on file.
  • Bank gambling blocks now enforce with 48-hour to seven-day cool-downs and read consistently at merchant category code 7995.
  • Crypto does not remove KYC, it moves the KYC wall upstream to the exchange under Financial Conduct Authority supervision.
05

Crypto rails and why they still hit KYC eventually

Crypto rails are marketed to UK players as friction-free, anonymous, or scrutiny-free. In practice a UK adult who wants to buy cryptoasset with sterling still has to open an account at a regulated exchange, and every regulated exchange operating in the UK sits under the Financial Conduct Authority's registration framework for cryptoasset businesses under the Money Laundering Regulations 2017. The exchange applies the same customer due diligence at onboarding it would apply on any other financial product, and the transaction record is preserved on the exchange side even when the receiving operator claims to be anonymous by design.

What crypto does change is the audit trail on the operator's side. When the receiving operator does not itself hold a UK licence, and the customer's funds reach it via a self-custody wallet routed through a non-UK exchange, the reconstruction of the flow becomes considerably harder if a Suspicious Activity Report later has to be filed. From inside a UKGC-licensed operator we did not touch cryptoasset deposits at all, because the Commission's Remote Technical Standards require deposits to be processed via payment methods that leave a clean reconstruction path. The reconstruction path is what gives a UK customer a route back into a civil remedy if things go wrong; without it, the practical recovery route is limited to the jurisdiction where the wallet was created and the exchange is registered.

A closer look

The subtler point about crypto rails is that the perception of anonymity is itself part of the harm profile. A player who believes a deposit will not appear on their bank statement plays differently from a player who knows every deposit reads back to the same account statement their partner or their debt adviser will eventually see. The visibility of the flow is a component of the guardrail, and the practical anonymity that crypto rails advertise weakens the guardrail even when the transactions themselves remain reconstructable at some later point. The Commission's ongoing engagement with the FCA on cryptoasset gambling flows is aimed at closing exactly this gap.

06

When your bank flags a suspicious deposit

UK banks run their own transaction monitoring under the Money Laundering Regulations 2017. When a deposit toward a gambling merchant fires a rule in the bank's system, the bank may hold the transaction, ask the customer for context, or refer the case to its own MLRO for review. The bank is not choosing whether the customer is allowed to gamble; it is discharging its own obligation to consider whether the transaction sits inside the bank's own risk appetite. In some cases the bank will process the transaction after a short conversation. In other cases the bank will decline the transaction and, in a narrow subset, close the account under the standard notice period set in the account terms.

From the operator's side, a bank hold appears as an authorisation delay or a subsequent chargeback. Inside a UKGC-licensed operator the chargeback triggers its own review, because a spike in chargebacks is one of the metrics the Commission looks at during a targeted audit. Offshore, the same chargeback often triggers a friction moment for the customer only, because the receiving operator has fewer routes to escalate, and the customer's account may be closed or the withdrawal held pending resolution. The customer does not always have a route to challenge that decision. On the licensed side the operator's own dispute route runs into an Alternative Dispute Resolution provider accredited by the Commission, and the customer's complaint carries a documented escalation path that ends with the ADR file being reviewable on request. On the offshore side there is no equivalent, and the withdrawal timeline is set by whatever internal policy the receiving operator applies at the moment the case reaches its own queue. The difference is not a technical detail. It is the difference between a documented remedy and an internal decision the customer cannot see the workings of.

Worth noting A refused deposit is not a punishment. It is one of the guardrails working the way the scheme's designers intended, and it is often the first legible signal that something is worth talking to a debt adviser about. Ignoring the signal and re-routing the deposit through a different rail is the response a compliance manager most often sees, and it is the response that most reliably escalates the underlying pattern.
07

What a Suspicious Activity Report actually is

A Suspicious Activity Report (SAR) is a filing made to the National Crime Agency under the Proceeds of Crime Act 2002. UK-licensed operators file SARs when their internal review team, escalated by the MLRO, forms a suspicion that the funds passing through a customer's account may be the proceeds of crime. The threshold is not proof, it is reasonable suspicion, and the filing is legally protected. Once filed, the SAR removes any liability the operator would otherwise carry for continuing to hold or process the customer's funds. It also puts the funds into a defined consent framework whilst the NCA reviews the filing.

The customer is not told that a SAR has been filed. That is a legal requirement, not an operator preference; tipping-off is itself an offence under the same statute. From the compliance seat the discipline of writing a SAR that will survive an NCA review is one of the more demanding parts of the job, because a poorly drafted narrative wastes the time of an under-resourced national resource. Every SAR I contributed to at the operator went through two rounds of internal review, and the language was pared back until it read as a statement of suspicion supported by evidence rather than an opinion. That discipline does not exist at the same weight on the offshore side because the receiving jurisdiction is not a UK Financial Intelligence Unit signatory.

08

Practical steps to reduce personal risk

For a UK adult reading this page, the practical steps sit in a short list. Turn on the card gambling switch at the primary bank. Ask any second bank on the household to do the same. Review the last six months of statements with a debt adviser or trusted family member if the pattern is worrying, and take the offer of a free StepChange or Citizens Advice session even if the money position feels manageable, because a second reader on the statement often notices what the first reader has learned not to see. Do not open new accounts at additional banks with the intention of routing around a block that is already in place, because the routing itself is a harm signal and the customer's own future self will be grateful for the friction the block provides.

If a decision has already been made to play at an offshore site, keep a note of every transaction with dates and amounts, keep the operator's terms and conditions at the moment of deposit, and keep the identity of the licensing regulator on file so that any later civil claim has a starting point. None of this is a substitute for the audited relationship a UKGC-licensed operator would provide, but it reduces the recovery difficulty if the withdrawal is later contested. Above all, the number at the top of every page of this site is not decorative. GamCare on 0808 8020 133 is a free, confidential, 24-hour service, and the advisers do not need a threshold of harm before a call is worth making.

The compliance perspective on all of the above is unfashionable to state out loud. The friction that the licensed sector applies at the payments layer is not a service failure, it is the service functioning as designed. A UKGC-licensed operator that never asks a source of funds question, never delays a large deposit for review, and never sends an Enhanced Due Diligence request would be an operator failing its Licence Conditions. The offshore operator that answers to no equivalent supervisor can advertise the absence of that friction as a feature, but the absence itself is what the audit layer removes. A UK adult reading this page should weigh the friction as evidence of the guardrail working, not as evidence of an obstacle to be worked around.

Read next

Sources and verification

Verified against the Money Laundering Regulations 2017, the Gambling Commission Licence Conditions and Codes of Practice, and the Commission's published guidance on customer due diligence at gamblingcommission.gov.uk. Last checked 5 August 2026.

J
Written by James Callaghan
Reviewed by Peter Renshaw, ex-Sky Betting & Gaming compliance manager, updated 5 August 2026

Frequently asked questions

At what point does a UKGC-licensed operator ask for source of funds evidence?

There is no single legal threshold. Under the Money Laundering Regulations 2017 the requirement is risk-based, and each licensee sets its own trigger schedule under its business-wide risk assessment. In the operator I sat in, the standard trigger sat at a cumulative net deposit of around £2,000 per rolling thirty days, with earlier triggers for higher-risk profiles and later triggers for lower-risk profiles. Enhanced Due Diligence began at a separate threshold with a longer document list. The Gambling Commission expects the schedule to be evidenced, reviewed, and applied consistently, not to sit at any particular round number.

Why does an offshore site let me deposit thousands without a single question?

Because no equivalent regulator is standing behind the payments team and requiring a documented risk-based trigger. Under a UKGC permit the operator's Money Laundering Reporting Officer is personally accountable for the schedule; on a Curaçao permit there is no equivalent personal accountability at the same enforcement weight. The absence of the question is not evidence that the transaction has been assessed and cleared, it is evidence that the assessment layer is not running.

How do UK bank gambling blocks actually work in 2026?

HSBC, Monzo, Starling, Lloyds and Barclays each offer a voluntary card gambling block that can be switched on inside the mobile banking app. Most enforce at merchant category code 7995 at authorisation. Turning the block off requires a cool-down of between 48 hours and seven days, so it cannot be lifted in the moment. The block is not perfect and will not catch every routing, but it removes the frictionless path that is the biggest driver of session drift.

Does using crypto let me bypass the checks altogether?

No. UK-regulated exchanges apply the same customer due diligence at onboarding under the Money Laundering Regulations 2017, and the Financial Conduct Authority now supervises cryptoasset businesses under the same framework. The KYC wall moves upstream to the exchange, but it does not vanish. Where the offshore site itself is unregulated, funds that pass through it lose the audit trail a UK bank would ordinarily have preserved, and that is a problem when a subsequent SAR has to reconstruct the flow.

If a UK-licensed operator has already verified me, can they share the KYC file with another operator?

No, and this is a common misconception. Each licensee runs its own KYC file under its own risk-based framework, and the retention period runs against the individual operator's own AML policy. The exception is a joint venture within a licensed group under a single licence framework. A completely separate operator has to complete its own onboarding, and an offshore operator has no obligation to accept, verify or refresh any UK-licensed operator's file.

Talk to someone today

The National Gambling Helpline is free, confidential and open 24 hours a day, seven days a week.

0808 8020 133 GamCare, free, 24 hours