From anonymity to customer due diligence: how casino compliance has changed
Casino compliance has moved a long way from systems in which relatively limited information could accompany some transactions. Today, regulated operators are expected to know who their customers are, understand relevant financial activity and apply additional scrutiny when risks increase.

This shift reflects a broader change in anti-money-laundering policy. Identity checks are no longer treated simply as an administrative step at the start of a relationship. They form part of an ongoing process that can include transaction monitoring, risk assessment and further enquiries when customer activity changes.
Identity became part of financial oversight
Customer due diligence, usually shortened to CDD, requires businesses to identify customers and verify that identity using reliable information.
For British casinos, the Gambling Commission explains that verification can involve checking information such as a customer’s name and address against independent documents, data or other sources. The objective is to establish that the person is who they claim to be.
That requirement has particular significance online. A customer accessing an online casino is not physically present in front of staff, so verification has to operate through remote systems and documentation.
The Gambling Commission’s 2026 risk assessment notes that this creates its own challenges. Fraudulent documents, mule accounts and increasingly sophisticated techniques involving AI-generated material can all be used in attempts to bypass customer due diligence controls.
Checks do not end when an account is opened
Modern CDD is not a one-off identity exercise.
Once a business relationship exists, operators need to consider whether subsequent transactions remain consistent with what they know about the customer. A change in behaviour, payment methods or financial activity may therefore require additional scrutiny.
This reflects the wider principle behind UK anti-money-laundering rules. HM Revenue & Customs describes customer due diligence as including identification, risk assessment and monitoring rather than simply collecting personal information.
The level of scrutiny is not necessarily identical for every customer. A risk-based system allows controls to be adjusted according to the circumstances.
Higher risk can require enhanced checks
Where a relationship or transaction presents a higher money-laundering or terrorist-financing risk, ordinary CDD may not be sufficient.
Casino operators can be required to apply enhanced due diligence and enhanced ongoing monitoring. Depending on the circumstances, this may involve obtaining additional information about the customer, the purpose of transactions or the source of funds.
The important distinction is that enhanced checks are triggered by risk rather than by an assumption that unusual activity is automatically criminal.
This approach also explains why financial monitoring has become inseparable from identity verification. Knowing who a customer is provides context; monitoring helps determine whether later activity is consistent with that context.
Technology has changed both controls and risks
The move towards remote gambling has increased the amount of electronic information potentially available for compliance purposes. Account records, payment information and transaction histories can all contribute to a more detailed audit trail than an isolated cash transaction might provide.
At the same time, digital systems introduce different vulnerabilities.
The Gambling Commission’s 2026 assessment of remote casino risk highlights risks involving fraudulent identification, multiple payment methods, e-wallets and attempts to circumvent verification.
Compliance has therefore not simply become easier because more information is digital. Operators also have to assess whether that information is genuine and whether apparently separate pieces of activity are connected.
From identification to an ongoing relationship
The major change in casino compliance is not merely the introduction of more documents. It is the shift towards continuous assessment.
Identity verification establishes a starting point. Transaction monitoring adds context over time. Enhanced due diligence provides additional scrutiny where risk increases, while record-keeping allows decisions to be reviewed later.
Modern casino compliance is therefore less about a single moment at which a customer’s identity is checked and more about maintaining an informed picture throughout the business relationship. As payment technology and methods of identity fraud evolve, that picture has to be updated as well.

















