Authors
Introduction
On 30 July 2026, the Gambling Commission (the “Commission”) published its latest risk assessment into money laundering and terrorist financing (the “Commission’s Risk Assessment”), following its previous risk assessment, published in November 2023 (the “Commission’s 2023 Risk Assessment”), which we covered here.
The Commission’s Risk Assessment, which is required by Regulation 17(1) of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, serves as a resource to inform both operators’ own money laundering (“ML”) and terrorist financing (“TF”) risk assessments and the Commission’s licensing, compliance and enforcement activity. It has been updated to reflect key ML and TF risks identified in the period from 1 April 2023 to 31 October 2025, which should be taken into account by remote and non-remote gambling operators in Great Britain. Those risks continue to evolve, driven in particular by the use of artificial intelligence (“AI”) to circumvent customer due diligence controls, the growth of illegal gambling markets, and increasing exposure to cryptoassets and cross-border business-to-business (“B2B”) relationships.
The Commission’s Risk Assessment has practical implications for operators, who, under Licence Condition 12.1.1, must “take into account any applicable learning or guidelines published by the Gambling Commission from time to time” and should accordingly consider whether the Commission’s assessment of risk requires changes to their ML and TF risk assessment, as well as their policies, procedures and controls.
The methodology for the Commission’s Risk Assessment remains much the same as for the Commission’s 2023 Risk Assessment. The Commission has, however, used a number of labels to assist in identifying changes to its assessment of risk and risk ratings, including new risk, decrease or increase in likelihood and impact and new wording. It has also separately identified risks for which the relevant controls are principally the Commission’s responsibility; this article does not address those risks.
In the remainder of this article, we consider the key changes and developments as against the Commission’s 2023 Risk Assessment. Operators will need to review the sections of the Commission’s Risk Assessment relevant to their operations in full in order to assess its impact and whether updates to their own risk assessments and/or operational changes are required.
Overall risk ratings
At an overall sector level, the assessment of risk remains largely unchanged from the Commission’s 2023 Risk Assessment, with gambling software (remote and non-remote) being the only sector whose overall risk rating has changed, increasing from low to medium. Casino (remote and land-based) and betting (land-based, off-course) remain the high-risk sectors.
HM Treasury and the Home Office’s National Risk Assessment of Money Laundering and Terrorist Financing from 2025 (the “HMT National Risk Assessment”) increased the casino sector’s rating from low to medium. This change is stated to be driven by changes in customer, geographical and transaction risks, particularly an increase in funds moving through remote casinos, new ways of playing casino games, the updated assessment of money service business (“MSB”) activities offered by some casinos and the increased presence of illegal casinos targeting British consumers.
The difference in risk rating for casinos between the Commission’s Risk Assessment and the HMT National Risk Assessment is a result of the different basis on which the two assessments measure risk. The HMT National Risk Assessment considers casinos relative to other regulated sectors, such as retail banking, money services businesses, legal service providers, accountancy services and cryptoasset businesses, whereas the Commission compares the ML and TF risks of individual gambling sectors against one another, with both remote and non-remote casinos remaining high risk on that basis.
Gambling software (remote and non-remote) – increase in overall risk rating
The change from low to medium risk for gambling software (remote and non-remote) is attributed by the Commission to the risks posed by B2B relationships and by licensed operators supplying software to illegal website operators. This change is reflective of the Commission’s warning notice published earlier this year, which noted its objective to prevent gambling from being a source of crime and stressed the need for gambling software providers to review their own practices, actively monitor relationships and work proactively with the Commission.
The Commission’s Risk Assessment emphasises that inadequate monitoring of third-party contracts may expose operators to risk, particularly where software is supplied indirectly or through cross-border arrangements involving multiple parties. The exposure arising from these B2B relationships may also extend to the funds received by gambling software businesses in the form of cryptoassets or from businesses offering cryptoasset activity.
These concerns are reflected in the Commission’s more detailed assessment of the sector, which identifies three new risks:
- insufficient monitoring of third-party contracts to identify the resale of software to unlicensed sites;
- cryptoasset transactions; and
- B2B partners based in or linked to a high-risk jurisdiction.
AI, deepfakes and identity fraud – new theme
A notable new theme in the Commission’s Risk Assessment, which did not feature in the Commission’s 2023 Risk Assessment, is the increasing role of AI in facilitating ML. Across the remote sector (casino, betting and bingo), the Commission reports an increase in the scale and sophistication of attempts to bypass ‘know your customer’ checks using false documentation, deepfake videos and face swaps generated by AI.
In light of that, the risk of false or stolen identity documentation being used to bypass controls for each remote sector now expressly refers to the fact that this includes “the use of AI tools to generate documents or videos”. In terms of risk ratings, the likelihood of this risk emerging for both bingo and betting (remote) has increased from medium to high (with casino (remote) unchanged as already rated high). These changes reinforce the need for operators to consider whether their existing verification controls remain effective as the methods used to circumvent them develop.
Customer monitoring and source of funds – cross-sector focus
The Commission’s Risk Assessment also places considerable emphasis on the approach to and effectiveness of ongoing customer monitoring, with new risks across all sectors relating to customer risk profiling and ongoing monitoring, transaction monitoring and the scrutiny of source of funds.
As well as new risks, there have also been additions to the wording of certain risks, such as for the risk of anti-money laundering (“AML”) thresholds being inappropriate, where there is now express reference to operators’ customer base and/or if predominantly loss based for casino (remote and non-remote), betting (remote) and bingo (remote).
Relatedly, the Commission’s Risk Assessment identifies a number of new risks relating to customer characteristics and activity. For casino, betting and/or bingo (remote and non-remote), these include the following, most of which are rated high:
- customers linked to criminal activity (which is broader than the risks related to organised crime identified in Commission’s 2023 Risk Assessment);
- customers who appear to be disproportionate spenders;
- customers presenting risks relating to their source of income, including access to third-party funds or funds originating from a cash-intensive business;
- customers using a third-party payment method that is not in their name; and
- customers displaying suspicious or unusual wagering patterns, including withdrawal after minimal play, placing large bets on ‘safe’ odds, betting on obscure markets or on events where the integrity has been called into question, as well as use of early ‘cash out’ features.
These customer-related risks are closely linked to the Commission’s focus on the adequacy of customer and transaction monitoring. The identified customer characteristics and activities are among the factors that operators should monitor and scrutinise to ensure that their controls are effective. However, many of these risks have previously been identified in the Commission’s guidance and enforcement updates, including its guidance on ‘The prevention of money laundering and combating the financing of terrorism’ for remote and non-remote casinos (the “AML Guidance”). Operators may therefore already have reflected some of them in their risk assessments, but should review the updates to ensure that all relevant risks are appropriately taken into account.
Insufficient or inadequately tailored staff training and lack of competence of key personnel, newly identified as risks across multiple sectors, are also relevant. Although operators are likely already to recognise, again including from the AML Guidance, the importance of staff in implementing controls effectively, the Commission’s Risk Assessment now expressly identifies inadequate training and a lack of competence among key personnel as distinct risk areas.
The Commission’s Risk Assessment acknowledges the challenges that the non-remote sector faces in terms of implementing effective controls in a live premises environment, in particular, noting that where casinos allow customers to enter without formal identification, they need to determine how to ensure customers’ identities are verified and customers are actively monitored.
It also emphasises that challenges might arise in the context of “high-profile events”, with new risks for betting (remote and non-remote) reflecting the particular monitoring challenges that may arise where a significant increase in betting activity generates a greater volume of transactions and previously unknown customers may place large bets. The Commission notes that this risk may arise in the context of events such as the Cheltenham Festival and Royal Ascot.
Sector-specific changes
In addition, the Commission’s Risk Assessment includes a range of sector-specific changes and developments. Although we do not address each of them in detail, two are particularly noteworthy:
- For casino (non-remote), the money laundering reporting officer (“MLRO”) risk has been reworded to focus more specifically on whether the MLRO “lacks the independence and resources to uphold their responsibilities”, placing greater emphasis on the wider practical ability of the MLRO to perform their role effectively. The Commission’s 2023 Risk Assessment focused on the risk of the MLRO being undermined by senior management specifically.
- For arcades and specifically adult gaming centres (“AGCs”), the Commission has identified “staff bonus schemes creating an incentive to overlook money laundering risks” as a new risk. This new risk is not identified for any other sector and is said to have been identified from the Commission’s casework; it is emphasised that appropriate safeguards must be in place to mitigate this risk.
Not all of the changes point towards greater risk, however, with various risks downgraded in likelihood. By way of example, for casino (remote), high value customer schemes, customers gambling with multiple remote operators, smurfing and pre-paid methods have all decreased in likelihood.
Terrorist financing
The overall TF risk remains medium, with all individual risk ratings unchanged since the Commission’s 2023 Risk Assessment, when increases in the impact of each TF risk resulted in the overall rating moving from low to medium.
Although the ratings have not changed, the Commission has expanded its ‘red flag’ indicators to include customers’ bank statements displaying suspicious activity, customers from higher-risk jurisdictions spending large amounts of cash, unusual card or payment methods, smurfing, withdrawals not commensurate with the conduct of an account, fraudulent documentation and suspicious activity in peer-to-peer gaming, including deliberate losses.
Proliferation financing
The Commission has also expanded its consideration of proliferation financing, moving beyond the Commission’s 2023 Risk Assessment, which principally noted that the 2022 amendment to The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 required regulated businesses to assess and mitigate proliferation financing risks.
The Commission’s Risk Assessment now emphasises that casino operators must take into account the HMT National Risk Assessment and identifies specific ‘red flag’ indicators, including links to sanctioned states or individuals, use of fraudulent documents, funds connected with dual-use goods and cryptoassets that have passed through mixers.
The Commission also includes a case study concerning the Democratic People’s Republic of Korea generating revenue through the development and sale of online gambling websites. That example brings the issue back to B2B relationships, with the Commission identifying appropriate due diligence on third parties as a means of mitigating the risk and encouraging all operators to consider their exposure through both customers and business relationships.
Illegal markets – new addition
Another significant addition to the Commission’s Risk Assessment is a dedicated section on illegal markets, which had no equivalent in the Commission’s 2023 Risk Assessment.
Reflecting the finding in the HMT National Risk Assessment that illegal casinos targeting the UK have increased, the Commission notes that the absence of regulatory oversight allows high-value activity without the same oversight and reporting procedures that apply to licensed operators. It is emphasised that payment service providers and cryptoassets allow funds from illegal gambling to filter into the legitimate financial system and move high volumes of money at speed with anonymity.
The Commission regards a compliant, mature and resilient regulated sector as a “critical baseline defence” and acknowledges that HM Government has allocated £26 million over 3 years to the Commission for it to focus on disrupting illegal gambling markets.
Comment
The Commission’s Risk Assessment reflects the changing nature of the ML and TF risks facing the gambling industry, with developments in AI, illegal gambling and cryptoassets sitting alongside a renewed focus on more established risks around customer monitoring, source of funds and due diligence around third-party and B2B relationships and activity.
Although most overall sector ratings remain unchanged, the number and breadth of changes within individual sectors, together with the increase in the gambling software risk rating from low to medium, mean that operators should not assume that an unchanged sector rating necessarily means that their existing risk assessment remains appropriate. As well as a significant number of new risks, there have been changes or additions to the wording of specific risks which will need to be carefully considered in the assessment of risk.
The practical implications of the Commission’s Risk Assessment will differ between operators, but the Commission will expect operators’ risk assessments to develop as the risks facing their businesses develop.
Co-authored by Leah Campion
For further information please email the authors or your usual CMS contact.