Blog

AML Fundamentals

Identity Fraud in Gaming: What Licensed Operators Must Verify

Age and identity verification rules for online gambling in Great Britain and Australia, plus multi-accounting, chip dumping and mule risk in regulated operators.

Online gambling is one of the few sectors where identity verification is a licence condition in its own right, not only an anti-money laundering control. Great Britain requires name, address and date of birth to be verified before a customer gambles. Australia requires verification before the first bet is placed.

Key takeaways

  • Great Britain's rule has applied since 7 May 2019: verify name, address and date of birth before the customer is permitted to gamble.
  • Australia's verification window fell from 90 days to 14 days to 72 hours, and since 29 September 2023 verification must be completed before a customer can bet.
  • The Gambling Commission rates both remote betting and remote casino as high risk for money laundering, on gross gambling yields of 2.6 billion pounds and 5.0 billion pounds respectively for April 2024 to March 2025.
  • The Federal Court ordered Crown to pay 450 million Australian dollars over two years in 2023 and SkyCity to pay 67 million Australian dollars on 7 June 2024.
  • AUSTRAC alleges Entain deliberately obscured the identity of some high-risk customers on its own systems by using pseudonyms.

Why does gambling regulation treat identity as an age question first?

Because underage participation is the harm that licensing exists to prevent, and it can only be prevented by knowing who the customer is. In Great Britain, LCCP condition 17.1.1 requires licensees to obtain and verify a customer's name, address and date of birth before that customer is permitted to gamble.

That sequencing has a second effect. An operator that has verified age to a regulatory standard has also, incidentally, built the customer record that anti-money laundering obligations depend on. The two regimes converge on the same evidence.

Australia reaches the same place from a different direction. Its customer verification measure sits inside a consumer protection framework, and the stated reason is that underage gamblers and self-excluded people are the vulnerable groups pre-verification protects. This is the structural difference from most sectors: gaming verifies identity to stop people playing, not only to satisfy a financial crime rule.

When must an operator verify, in Great Britain and in Australia?

Both regimes have converged on verification before play, by different routes and under different regulators.

JurisdictionRule and instrumentTimingRegulator
Great BritainLCCP customer identity verification condition, in force from 7 May 2019Before the customer is permitted to gamble, with document requirements disclosed before depositGambling Commission
AustraliaMeasure 3 of the National Consumer Protection Framework, via the AML/CTF RulesBefore the customer can place a bet, since 29 September 2023AUSTRAC, with ACMA enforcing the Interactive Gambling Act

The Australian measure has tightened three times. The Department of Social Services records it as implemented on 26 February 2019, updated on 2 May 2022 and updated again on 29 September 2023, with the allowable verification period falling from 90 days to 14 days to 72 hours before pre-verification replaced it entirely.

Britain layers a second check on top. Under LCCP condition 3.4.4, remote licensees must run a financial vulnerability check using public record data, at a threshold of 500 pounds a month from 30 August 2024 and 150 pounds a month from 28 February 2025.

How does multi-accounting turn a bonus budget into a fraud loss?

Welcome offers, free bets and referral rewards are priced on the assumption of one account per person. Multi-accounting breaks that assumption, and the way it breaks it determines whether the operator is looking at a commercial leak or a criminal one.

A customer who opens a second account in their own name has breached the terms. A customer who opens accounts in other people's names has committed identity fraud, and the operator has verified nothing useful. The Gambling Commission's 2026 risk assessment records a case in which a customer deposited approximately 40,000 pounds over six months while creating accounts using the details of five different individuals.

The same assessment notes an increase in the scale and sophistication of attempts to bypass verification using false documentation, deepfake videos and face swaps generated by artificial intelligence. Bonus abuse is often the first visible symptom of a synthetic or stolen-identity cohort, which makes promotional analytics a fraud signal as much as a marketing one.

What is chip dumping, and why is peer-to-peer play a laundering channel?

In games where customers play each other rather than the house, the operator is a venue rather than a counterparty. That changes the risk. The Gambling Commission's assessment of remote casino treats poker and other peer-to-peer gaming as presenting risks of collusion and the transfer of criminal funds between customers.

Chip dumping is the mechanism. One player deliberately loses to another, so value moves between accounts with a plausible explanation attached to it. Neither transaction looks unusual in isolation, and the losing account can be a mule or a stolen identity that will never be reconciled to a real complainant.

Shared liquidity makes it harder still. Poker often runs on platforms shared by several operators, so the two sides of a dumped pot may sit with different licensees, each seeing only half the pattern. The Commission rates remote casino as high risk overall, on a gross gambling yield of 5.0 billion pounds for April 2024 to March 2025, of which 4.2 billion pounds came from slots.

How do mule accounts appear inside a betting platform?

They appear as accounts that fund but barely gamble. A gambling account can receive money, hold it briefly and pay it out, and the wagering in between can be trivial. That is what makes the sector attractive as a pass-through.

The Gambling Commission's remote betting assessment gives a worked example: a student depositing 10,000 pounds in the early hours and then requesting a withdrawal without wagering, with investigation revealing multiple transfers from third parties. The same document lists the use of fraudulent documentation to bypass know your customer controls and the creation of mule accounts as distinct risks in the remote sector.

Third-party funding is the recurring tell. Where the person depositing is not the person named on the account, the identity record and the money have come apart, and every downstream control is now describing the wrong party. Remote betting carried a gross gambling yield of 2.6 billion pounds for April 2024 to March 2025 and is also rated high risk.

What have AUSTRAC's gambling cases found about customer identity?

Australian enforcement has moved from casinos to online betting, and identity sits at the centre of both. The Federal Court ordered Crown Melbourne and Crown Perth to pay 450 million Australian dollars over two years on 11 July 2023, and on 7 June 2024 ordered SkyCity Adelaide to pay 67 million Australian dollars plus 3 million dollars in costs, after failing to carry out required checks on 121 customers.

On 16 December 2024 AUSTRAC commenced its first civil penalty proceedings against an online betting operator, alleging that Entain did not have appropriate controls to confirm the identity of customers making third-party deposits, and did not conduct appropriate checks on 17 higher-risk customers.

The allegation that stands out is not a missed check. AUSTRAC alleges Entain deliberately obscured the identity of some high-risk customers on its own systems through the use of pseudonyms, described as protecting their privacy. Verification that is undone internally is worse than no verification, because it leaves a compliant-looking record.

How does a licensed operator differ from an illegal offshore one?

The difference is that a licensee is required to know the customer and can be penalised for not knowing. An unlicensed offshore site has no such condition, which is precisely why it can accept accounts that a licensed operator would decline.

That gap is what makes displaced demand a compliance issue rather than only a consumer one. As at 18 March 2026 the ACMA reported that 1,564 illegal gambling and affiliate websites had been blocked since its first blocking request in November 2019, and that over 225 illegal services had pulled out of the Australian market since it began enforcing the current rules in 2017.

For a licensed operator the practical consequence is that customers arriving from a blocked or exited site may have been gambling for years without ever being verified. Their stated history carries no evidential weight. Sector obligations are set out on our betting and gaming industry page, and the wider terminology sits in the glossary of AML terms.

Which checks should keep running after the account is open?

Pre-verification is a gate, not a control regime. Identity fraud in gaming is usually detected after the account exists, in the relationship between who the customer claims to be and how the account behaves.

Four checks do most of the work. Sanctions and PEP screening needs to rescreen the customer book, not just the applicant, because designations change after onboarding. Device and payment linkage needs to run across accounts, since multi-accounting and chip dumping are cluster behaviours that are invisible one account at a time.

Payment symmetry helps: the Commission notes that returning winnings by the same method used to deposit limits the opportunity to layer criminal proceeds. Finally, re-verification should be triggered by behaviour rather than by calendar, using document and biometric checks of the kind covered on our identity verification page. Related reading includes our post on updated casino regulations in the United Kingdom and the companion piece on identity fraud in fintech.

FAQ

Common questions.

When must an online gambling operator verify a customer's identity in Great Britain?
Since 7 May 2019, licensees must obtain and verify a customer's name, address and date of birth before that customer is permitted to gamble, and must tell the customer what documents may be required before they deposit funds. An operator cannot make the request for further identity information a condition of withdrawal if it could reasonably have asked earlier.
Does Australia allow a grace period for verifying online betting customers?
No. Under Measure 3 of the National Consumer Protection Framework, a customer's identity must be verified when they register and before they can place a bet. The allowable period fell from 90 days to 14 days to 72 hours before pre-verification took effect on 29 September 2023.
What is chip dumping?
Chip dumping is the deliberate transfer of value between players in peer-to-peer games such as poker, where one player intentionally loses to another to move funds under the appearance of gambling. The Gambling Commission identifies peer-to-peer play as a route for collusion and the transfer of criminal funds between customers.
Is bonus abuse a fraud offence or just a commercial loss?
It depends on how the accounts were opened. Claiming a promotion twice through a single verified identity is a terms breach. Opening multiple accounts using other people's identity details to claim the same offer is identity fraud, and the Gambling Commission has recorded a case of one customer depositing around 40,000 pounds over six months using the details of five different individuals.
Why are illegal offshore gambling sites a money laundering concern?
They operate outside any licence condition requiring customer verification, so accounts can be opened and funded without an identity being established. As at 18 March 2026 the ACMA had 1,564 illegal gambling and affiliate websites blocked since its first blocking request in November 2019, and over 225 illegal services had pulled out of the Australian market since enforcement of the current rules began in 2017.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.