Gambling Compliance Policy Development

Gambling compliance policy development is the drafting of the policy documents a gaming regulator requires with a licence application: AML/CFT, KYC and customer due diligence, responsible gambling, and the procedures that support them. MGL Solutions writes each document against the named regulator, your products, your markets and your payment methods, then keeps it current as the rules move.

Decorative gradient stripe
What you getNine policy areas: AML/CFT, KYC/CDD, responsible gambling and six supporting policies
Written forThe regulator you apply to, plus your bank and payment provider
Who approvesYour board approves the policy; the regulator approves the appointments
Review cycleAt least annually, and immediately on any material change
Jurisdictions coveredMalta, Curacao, Isle of Man, Kahnawake, Tobique, Nevis, Anjouan, Costa Rica
Scope and feeQuoted per operator profile and per regulator

What compliance policies does a gambling licence require?

The core gambling compliance pack covers nine policy areas: AML/CFT, KYC and customer due diligence, responsible gambling, data protection, complaints and disputes, conflict of interest, risk assessment, record keeping, and staff training. No single regulator names all nine. The list follows the regulator: Malta names seven document categories, Nevis four website policies, Anjouan standards instead of a document list.

Tier-1 regimes add more: marketing standards, fair terms, outsourcing due diligence, information security and whistleblowing sit on top of the core nine.

AML/CFT policy. The document setting out how you detect and prevent money laundering and terrorist financing. Every licensed operator needs one. It covers the risk-based approach, customer acceptance, source of funds checks, sanctions and PEP screening before the first deposit, transaction monitoring, reporting to your financial intelligence unit, and escalation to the board. Set concrete thresholds: a policy that promises monitoring without naming the trigger, the threshold and the owner fails review. Our AML compliance page covers the regime itself in detail.

KYC/CDD procedures. The operational rules your onboarding and payments teams follow. What identity evidence you collect, what triggers enhanced due diligence, and when you refuse an account. Written for the people doing the work, not for the regulator's shelf.

Responsible Gambling policy. Deposit and loss limits, self-exclusion, age verification, problem-play indicators, and how staff act on them. Required in every gaming jurisdiction in the table below, including the offshore ones.

Data protection framework. How you collect, store, share and delete player data. Who your data protection officer is, and how you answer a subject access request. GDPR drives this where GDPR reaches you, and local data protection law where it does not. Regulators do not accept GDPR as a reason for failing a licence duty.

Complaints and disputes. Your internal complaints procedure plus the route to independent adjudication. Malta requires an ADR entity established in the EU or EEA, and its conclusions bind both parties. Kahnawake sets a 45-day deadline for your final decision on a complaint.

Conflict of Interest policy. How you handle a director, key person or supplier sitting on both sides of a transaction. Regulators that approve key function holders individually, Malta among them, read this one closely.

Business-Wide Risk Assessment. The written assessment of the laundering and terrorist financing risk your own business carries. It weighs your products, markets, delivery channels and payment methods. Every other AML control rests on this document, and it is the one most often missing.

Record keeping. What you retain, in what form, and for how long. Five years is the common floor, set at paragraph 17 of the Isle of Man AML and CFT Code 2019 and matching FATF Recommendation 11.

Internal procedures and staff training programme. Induction and refresher training, plus role-specific modules for payments, VIP and support teams. Keep the training logs: a supervisor will ask to see them.

What sections belong in an AML/CFT policy?

A complete operator AML and CTF policy runs to eleven sections. Use this structure as your benchmark:

  • Purpose.

  • Introduction.

  • Group approach.

  • Criminal sanctions.

  • How money laundering is detected and prevented.

  • Knowing our customers.

  • Adverse information checks, covering PEPs, sanctions and terrorism.

  • Governance.

  • Record keeping.

  • Training.

  • Audit.

A policy missing governance, record keeping, training or audit describes an intention rather than a programme.

Which policies are mandatory in each jurisdiction?

Requirements diverge sharply. Malta, the Isle of Man, Tobique and Kahnawake publish detailed policy obligations. Nevis publishes a four-item list. Anjouan publishes standards without a document schedule. Costa Rica has no gaming regulator at all, so nothing in the gaming columns applies. We read every cell below from the regulator or the governing instrument, never from a neighbouring jurisdiction.

JurisdictionAML/CFTKYC/CDDResponsible gamblingData protectionComplaints and ADRRisk assessment
Malta (MGA)RequiredRequiredRequiredRequiredRequiredRequired
Curacao (CGA)RequiredRequiredRequiredRequiredRequiredRequired in substance
Isle of Man (GSC)RequiredRequiredRequiredRequiredRequiredRequired
Kahnawake (KGC)RequiredRequiredRequiredNot publishedRequiredRequired
Tobique (TGC)RequiredRequiredRequiredRequiredRequiredRequired
Nevis (NOGA)RequiredRequiredRequiredNot publishedNot publishedNot published
Anjouan (AGA)RequiredRequiredRequiredRequired in substanceRequiredNot published
Costa RicaNo gaming regimeNo gaming regimeNo gaming regimeRequired under Law 8968No gaming regimeNo gaming regime

Reading the table. Required means the regulator or the governing instrument names the obligation. Required in substance means the duty exists but no named policy document is specified. Not published means the regulator publishes no such requirement. That does not mean the obligation disappears: your bank and your payment provider will still ask. No gaming regime means the jurisdiction licenses no gaming activity, so gaming duties do not arise; general Costa Rican law on money laundering and personal data still applies.

Sources, in table order:

  • Malta: Malta Gaming Authority licensee hub, System Documentation Checklist, Player Protection Directive and ADR Directive, with the PMLFTR and FIAU Implementing Procedures Part II for the remote gaming sector.

  • Curacao: Curacao Gaming Authority licence conditions for an indefinite-term online gaming licence, in force 17 December 2025, articles 6, 11, 13 and 14.

  • Isle of Man: Gambling (Anti-Money Laundering and Countering the Financing of Terrorism) Code 2019, paragraphs 4, 6, 7, 8, 9 to 15, 17, 21 and 27, with GSC guidance v1.3 of June 2025, the Online Gambling Registration and Accounts Regulations 2008, the GSC player protection and complaints pages, and the OGRA licence application checklist v8.

  • Kahnawake: Regulations concerning Interactive Gaming of 25 March 2026, parts XXIII, XXIV and XXVI, with the Regulations concerning Anti-Money Laundering and Counter Terrorism Financing of 30 June 2021, sections 9, 13, 14, 18, 19 and 24.

  • Tobique: General Code of Practice v2.0, enacted 5 April 2024 under section 22 of the Tobique Gaming Act 2023, parts 4, 7 and 8, with the TGC Remote Gambling AML Code of Practice v3.0, section 10.

  • Nevis: Nevis Online Gaming Ordinance No. 2 of 2025, section 17, with the published NOGA application policy list.

  • Anjouan: Anjouan Gaming Authority published regulatory standards, licence conditions and player complaint process under the Anjouan Computer Gaming Licensing Act 2005, with the authority's register of authorised ADR providers.

  • Costa Rica: Law 8968 on the protection of personal data, supervised by PRODHAB.

  • FATF: Jurisdictions under Increased Monitoring and High-Risk Jurisdictions subject to a Call for Action, both of 19 June 2026, and the June 2026 plenary outcomes.

Malta (MGA) policy requirements

The Malta Gaming Authority (MGA) assesses documents through the System Documentation Checklist. It covers seven categories:

  • Company structure.

  • Business plan.

  • Operating policies and procedures.

  • Gaming and technical setup.

  • KYC and AML procedures.

  • Responsible gaming procedures.

  • Sports integrity procedures.

The AML side runs on three documents: a business risk assessment, a customer acceptance policy, and written AML/CFT procedures under the PMLFTR. The FIAU Implementing Procedures set the customer due diligence trigger at €2,000.

Malta separates the document from the person. Your MLRO is registered with the FIAU and approved by the MGA as a key AML function. Your data protection officer and compliance officer are approved key functions in their own right. The MGA also blocks one individual from holding key functions that conflict. See our Malta gaming licence page for licence detail.

Curacao (CGA, post-LOK) policy requirements

The Curacao Gaming Authority (CGA) publishes an explicit list. Article 14 of the licence conditions for an indefinite-term online gaming licence, in force since 17 December 2025, names six areas. Every licensee must hold policies and procedures for:

  • Customer identification and verification.

  • Player account and fund management.

  • Responsible gaming.

  • Information security.

  • AML/CFT/CPF.

  • Suspension and closure of player accounts.

The CGA can demand any of them at any time.

Six further conditions shape the pack. Personal data must be handled under the National Ordinance on the Protection of Personal Data. Your terms must carry a complaints procedure and ADR under article 5.3 of the LOK (Landsverordening op de kansspelen), in force since 24 December 2024, and complaint and ADR reports go to the CGA.

Unusual transactions go to the FIU through the goAML portal under the NORUT. The same AML framework adds a designated compliance officer and a standing AML/CFT training programme covering the MLRO and staff. An independent expert approved by the CGA reports on your compliance with the NORUT and the NOIS. Our Curacao gambling licence page covers the licence itself.

Anjouan and other offshore jurisdictions

A lighter regime is not an absent one. The Anjouan Gaming Authority (AGA), which licenses under the laws of the Autonomous Island of Anjouan, publishes regulatory standards covering five areas:

  • AML and CTF controls, with customer due diligence, transaction monitoring, suspicious activity reporting and record keeping.

  • A designated compliance officer responsible for AML/CTF oversight.

  • Responsible gaming, including age verification, self-exclusion, and deposit and loss limits.

  • Data protection measures.

  • A player complaints process, with a 30-day operator response deadline and mandatory ADR through an authorised provider at the operator's cost.

Anjouan publishes no document schedule, so no checklist tells you the pack is finished.

Do not copy a Curacao or Malta pack into an Anjouan application. Wording that names the wrong regulator and the wrong statute is the clearest available signal that the document was not written for this application. For the licence itself, see our Anjouan gaming licence page.

Nevis takes a third position. The Nevis Online Gaming Authority publishes four required website policies: KYC, AML, responsible gaming and underage gaming. Section 17 of the Nevis Online Gaming Ordinance No. 2 of 2025 adds a Compliance Officer and a Reporting Officer. Data protection, complaints and risk assessment are absent from that published list, which moves them from the regulator's desk to your bank's.

Why do generic policy templates fail regulatory review?

A template fails because it names no regulator and no statute. A risk-based approach means the document reflects your business: your products, your target markets, your payment methods and your player profile. A policy that could belong to any operator in any jurisdiction describes none of them, and a reviewer sees that on the first page.

Four checks tell you whether you were sold a template:

  • Search the document for the name of your regulator. If it appears only in the header, or not at all, it is a template.

  • Search for the statute you are applying under. A Curacao pack should cite the LOK, the NORUT and the NOIS. A Malta pack should cite the PMLFTR.

  • Find your own products. If the policy discusses sports betting and you run a crypto casino, nobody read your business.

  • Find your payment methods. Cards, e-wallets, bank transfers and crypto carry different risk, and the monitoring rules should differ accordingly.

What does a gambling compliance documentation package include?

One pack serves three readers, and each reader wants a different depth. The regulator tests whether you meet licence conditions and local law. Your bank tests whether the operation is safe to hold. Your payment provider tests whether the risk profile is workable at volume. Same policies, different assembly.

ReaderWhat the pack coversWhat that reader is testing
RegulatorThe full policy set named in the licence conditions, plus appointments and the business risk assessmentWhether you meet licence conditions and the law of the jurisdiction
BankAML/CFT policy, KYC procedures, source of funds handling, sanctions screening, ownership and controlWhether the account is safe to hold and who ultimately controls it
Payment providerAML/CFT policy, KYC and age verification, chargeback and refund handling, responsible gambling controlsWhether the risk profile is workable at transaction volume

Build the regulator pack first, because that one has a deadline, then cut the onboarding version from it. Operators who build only for the regulator get a licence and then spend weeks rebuilding documents for banking.

Who approves and signs off gambling compliance policies?

Three parties are involved, and each does a different thing. Your provider drafts the policy. Your board or senior management approves and adopts it. The regulator approves the people, not the paper. A regulator assesses your policy inside a licence application, but what it formally approves is your key function holders.

Malta shows the split clearly. The MLRO must be a natural person. That person holds a personal certificate of approval issued after a fitness and propriety assessment, registers with the FIAU, and keeps up continuing professional development. Directors need prior MGA approval. The MGA bars one person from combining conflicting key functions. Our AML compliance page defines the MLRO role in full.

Nobody can promise you an approval. MGL prepares, files and manages the application; the decision belongs to the regulator.

How often must gambling compliance policies be reviewed?

At least annually, and immediately on any material change. The Isle of Man Gambling (Anti-Money Laundering and Countering the Financing of Terrorism) Code 2019 requires a business risk assessment to be reviewed regularly, with each review recorded. GSC guidance sets the floor at annual where nothing material has changed.

Curacao requires an independent expert report on NORUT and NOIS compliance when the CGA asks for one.

Five events force an unscheduled review:

  • A change in the rules of your licensing jurisdiction.

  • Entry into a new market, which brings a new country risk profile.

  • A product change, for example adding live casino or a sportsbook.

  • A change in payment methods, particularly adding crypto rails.

  • An FATF list update.

The FATF list moves three times a year, and every update is a trigger to re-run your country risk assessment. As of the plenary of 17 to 19 June 2026, 22 jurisdictions sit under increased monitoring. What grey listing and the call-for-action list each require of you is set out on our AML compliance page.

When do you not need external policy development?

Skip external drafting when you already hold the capability. Two situations qualify. The first: you employ a qualified MLRO and a compliance team that has already taken an application through this regulator. The second: you are renewing a licence and the documentation has been kept current against every rule that changed since.

A third option falls between the two. If you hold documents but no confidence in them, commission a review rather than a full project. A review reads your existing pack against the current requirements of your regulator and returns a gap list. That is smaller work than drafting, and for operators who bought a template it is usually the honest starting point.

What does a policy pack not do?

A policy pack does not guarantee approval, does not replace an appointed MLRO, and does not stay valid without review. The biggest limit is the one operators miss: a policy only protects you while the controls inside it run day to day.

No pack guarantees approval. That decision stays with the regulator, and no advisor controls it.

A pack does not replace an appointed MLRO. The document describes the process. A named person has to run it, and in most regulated jurisdictions the regulator approves that appointment separately.

Buying once does not cover you forever. Left unreviewed through a rule change, a market entry or a product change, the pack stops describing your business and stops protecting you.

A policy is not a programme. Supervisors test whether your controls operate. They sample customer files, monitoring alerts and reporting decisions. A well-written file that nobody follows fails an inspection faster than a plain one that everybody does. Enforcement action turns on that gap far more often than on the wording of the document itself.

Why do operators outsource policy development to MGL?

Operators outsource policy development to MGL for three reasons. Each policy is written against the regulator you are actually applying to, rather than a generic offshore standard. One engagement covers licensing, incorporation and policy drafting, which removes the handoff where documents start contradicting each other. Support continues after the licence is issued, when the review obligations begin.

MGL works across offshore, onshore and EU or UK tier-1 regimes in 30+ jurisdictions, and has obtained 300+ licences. MGL does not issue licences and does not guarantee approval. Where a jurisdiction requires local counsel, you still need local counsel.

Reviewing all the options first? Start from the gambling licence hub.

FAQ

Everything you need to know about Our company. Can't find the answer you're looking for? Please chat to our team.

Yes. A lighter regulatory regime does not remove the obligation. The Anjouan Gaming Authority requires AML and CTF controls, and Nevis lists an AML policy among four required website policies. Where a regulator asks for less, your bank and your payment provider still request the full pack.

Technically yes, and it will not survive review. A risk-based approach requires the document to reflect your specific business model, not a generic text. Run this test yourself: if the document does not name your regulator and cite the acts of your jurisdiction, it is a template.

Three parties handle sign-off. Your provider drafts the policy, your board or senior management approves it, and the regulator approves your key appointments. A regulator assesses the policy as part of the application; it does not sign the policy itself.

GDPR applies where the operator has an establishment in the European Union. GDPR also applies where the operator offers services to data subjects in the Union, or monitors their behaviour there. Gaming regulation and data protection are independent legal regimes, so being licensed changes nothing here.

The retention period follows your licence conditions and the AML code of your jurisdiction. Five years is the common floor: the Isle of Man AML and CFT Code 2019 sets five years at paragraph 17, matching FATF Recommendation 11. No single figure is universal.

In regulated jurisdictions, usually yes, because the appointment forms part of the application pack. We can source a candidate for you, and the regulator decides whether that person may hold the role. The regulator sets the approval timeline; no provider controls it.

A regulator checks the policy against licence conditions and the law of the jurisdiction. A bank or payment provider checks your risk profile and whether the controls are workable in daily operation. Both versions come from one pack, cut to different depths.

Which policies does your regulator actually require?

Send us the jurisdiction you are applying in and the documents you already hold. We will tell you which policies that regulator requires, which of yours would not survive review, and what is missing.