No headings found on page
crypto payments for igaming

TL;DR:

  • Fixed weights beat feature grids. Settlement certainty, screening depth, corridor coverage and exit terms should outweigh headline percentage fees, every time.

  • Three criteria are pass/fail, not scored: who owns the screening record, the provider's licence status, and whether you can walk away with your data. Fail any one and the vendor is out, whatever the total says.

  • Never accept "same day". Ask for the cut-off time and the value date. A 14:00 CET cut-off with T+1 settlement means a Friday run lands the following Tuesday, and your affiliates will tell each other about it.

  • Test the bulk API at your real volume, with idempotency keys and a deliberately broken line. A provider that handles 200 items in one call behaves nothing like one that wants 200 sequential requests and rejects the whole batch when line 137 has a bad IBAN.

  • Screening covers sanctions, PEP and adverse media on the affiliate entity and its beneficial owners, with a dated record your MLRO can pull inside 24 hours without reconstructing anything.

  • Total cost of a run is per-transaction fee plus FX spread plus failed-payment retries plus ops hours, and then there's the money the affiliate never sees because an intermediary bank took it.

  • Money out is many-to-many. Money in is one-to-many. Do not reuse your deposit PSP selection process and expect it to work.

Score the vendor, not the pitch deck.

Fifteen criteria. Fixed weights, agreed in writing before anyone books a demo. Settlement speed and cut-off times. Corridor coverage, plus what actually happens when a corridor gets withdrawn on you. Screening depth, and who owns the screening record. Bulk API behavior under partial failure.

FX and fee transparency, measured by what lands in the affiliate's account rather than what your invoice says. Security and custody. Licensing posture. Contractual liability. Reporting granularity. Exit terms.

Weight each one by what breaks your payout run. Then score every shortlisted vendor on identical evidence, not on how well their solutions engineer improvises.

Type "affiliate payout provider iGaming" into a search bar, and you get twenty companies who all settle "instantly", cover "200+ countries" and have "full compliance". Search the longer version that finance and payments people actually use, mass payout provider selection iGaming, and you get feature grids with green ticks in every row.

The checklist below exists for one reason: to turn those claims into statements that can be proved false.

Why does affiliate payout provider selection deserve its own process?

Affiliate payouts sit in an awkward spot.

They aren't player withdrawals, so they rarely get cashier-level scrutiny. They aren't standard supplier invoices either, because the counterparties are often individuals in jurisdictions your bank would rather not touch, paid in variable amounts, on a fixed monthly cycle, with an expectation of speed your accounts payable process was never built to meet.

So most operators inherit a payout method instead of choosing one. A programme of 80 affiliates limps along on bank transfers and a spreadsheet. At 400 the ops overhead becomes visible.

At 1,200 the run eats three working days a month and your Head of Affiliates is answering chase emails from partners who were paid two weeks ago and still haven't seen funds.

Switching later is expensive. Migrating rails means recollecting payment details from every active affiliate, which means a comms exercise, a verification exercise, and a cycle of dual running where everything is paid twice as slowly. Do it once.

How is this different from choosing a deposit PSP?

Completely different shape.

Deposits are one-to-many: thousands of players push money into a handful of your accounts, through a small set of acquiring relationships you control, on a continuous flow. If a card acquirer wobbles at 3am on a Tuesday, conversion dips and you route around it.

Payouts are many-to-many. Hundreds of separate counterparties, each with their own name-matching quirks, tax status and preferred rail.

Dozens of corridors. One deadline a month, usually the 1st to the 5th, and everything lands on it at once. There is no routing around a failure at 3am, because the failure is a named business partner in Belgrade who is now posting about you.

That structural difference changes what "good" looks like. A deposit PSP is judged on approval rates and chargebacks. A payout provider is judged on delivery certainty, per-line visibility and behavior under partial failure.

The vendor who is brilliant at the first is often mediocre at the second, and vice versa.

Ask directly which half of the business their engineering roadmap actually serves this year, and ask them to name the last three payout features they shipped. If the answer is a UI refresh and "better analytics", you have your answer.

Affiliates are commercial partners with public voices

Finance teams routinely underrate this part. An affiliate is not a supplier waiting patiently on 60-day terms. They're a media business with a media budget, and your programme competes for their placement against every other operator on their site.

Pay late and the cost isn't goodwill. It's traffic.

Your brand drops from position two to position eleven on a comparison page, and the operator who replaced you keeps that slot for a year. Meanwhile the affiliate explains why, in public.

Affiliate forums, private Telegram and Skype groups, industry Slacks, the closed Facebook groups where the top 200 casino affiliates actually talk. "Brand X pays 40 days late and their payout provider blames the bank" travels fast and never gets retracted when you eventually fix it.

Reputation among affiliates compounds in both directions. Operators who pay on the 3rd, every month, without a chase email, get first refusal on inventory and better commercial terms. That's a payout provider outcome, not a marketing one.

Correspondent banks de-risk gambling-coded outbound payments differently

Your deposit acquiring can be perfectly healthy while your outbound payments are quietly strangled. Different plumbing.

Acquiring is card-scheme territory: MCC 7995, high-risk registration, a rolling reserve, a monitoring programme. Painful, but it's a known process with known paperwork and a named contact who answers email.

Outbound bulk payments go through correspondent banking, where nobody publishes rules. A SWIFT transfer from a Malta-licensed entity to an individual in Nigeria or the Philippines, referencing "affiliate commission" from a gambling-coded originator, gets held for enhanced due diligence at the intermediary, then sometimes returned weeks later with no meaningful explanation.

Your bank didn't decline it. A bank three hops down the chain, with which you have no relationship and no right of appeal, decided the file wasn't worth opening.

The practical consequences stack up fast:

  • Corridors disappear without notice, usually mid-cycle.

  • Payment references get stripped or truncated, so reconciliation breaks and your ledger fills with unmatched credits.

  • Intermediary deductions land on the affiliate rather than on you, and you find out from the affiliate.

  • Repeated returns from one corridor start attracting questions from your own relationship manager, which is a conversation you do not want during a banking review.

So when you ask a vendor about coverage, you're really asking whose correspondent chain you're borrowing and how exposed that chain is to the same de-risking wave that hit yours. Ask it that bluntly. The good ones answer.

What should you do before the first vendor call?

Homework first. Vendors are extremely good at defining the problem for you if you turn up without numbers.

Build the baseline

Pull the last three payout runs, not just the last one, and write down:

  • Payout frequency and the actual approval date each cycle, versus the date on the affiliate agreement.

  • Line count per run, and the trend over 12 months.

  • Average payout size and the largest single payout. The largest one drives limits, approval workflow and concentration risk.

  • Currency mix by value, not by count. Two hundred €150 payouts matter less than four £40,000 ones.

  • Top 10 corridors by value and by line count, with the failure rate for each.

  • Average days from your approval to affiliate receipt, measured from affiliate confirmations rather than your own system timestamps. The gap between those two numbers is usually where the complaints live.

  • Cost per payout, all in: per-transaction fees, FX spread in basis points against the mid-market rate on the day, retry costs, and the loaded hourly cost of internal ops time.

Those numbers are your test case. Every vendor gets the same one, in the same format, on the same day.

One more thing worth doing while you're in the data: count how many affiliates changed bank details in the last 12 months, and how many of those changes anyone verified by phone. That number tends to be sobering, and it will shape how hard you push on criterion 10.

Map the licence and record-keeping obligations first

Before anyone shows you a dashboard, write down what each licence you hold requires of affiliate payments. UKGC licensees have LCCP obligations around third-party marketing arrangements and record retention. MGA licensees have their own reporting and due diligence expectations on commercial partners.

Curaçao under the new LOK regime looks nothing like Curaçao did in 2022. Hold licences in three jurisdictions and you have three record-keeping standards, and you must satisfy the strictest of them.

Get specific. How long must the payment record and the screening record be retained? In what form? Who is entitled to demand it, and how quickly? Then ask whether the vendor's retention and export capability actually meets that standard.

This is a five-hour internal exercise. It saves you from signing with a provider who purges screening evidence after 12 months when your licence needs five years.

Agree who signs off, and what each of them needs

Four functions hold a veto, and all four should be in the room before the shortlist, not after:

  • Payments/treasury owns funding, cut-offs, limits and reconciliation.

  • Finance owns cost per payout, FX treatment, ledger mapping and month-end close.

  • Compliance/MLRO owns screening standards, record ownership, jurisdictional exposure and the answer they'll give a regulator.

  • Affiliate management owns the relationships, and is the only function that knows which twelve partners will churn if payment slips a week.

Circulate a one-page brief with each function's non-negotiables before demos start. If compliance discovers on day 40 that the provider won't hand over dated screening records, you've burned 40 days and a lot of internal credibility.

Define must-haves versus nice-to-haves before you see a demo

Write the list down, get all four functions to sign it, and refuse to reopen it during procurement. Otherwise the demo defines your requirements, which is exactly what the demo is for.

A workable split for a mid-size programme:

Must-have: no daily cut-off, or a documented one you can live with; line-level status via API; dated screening records the operator owns; coverage of your top 10 corridors with contractual notice before withdrawal; FX spread visible pre-approval; dual authorisation on releases; full data export on exit.

Nice-to-have: white-labelled affiliate onboarding portal; native integration with your affiliate platform; automated tax form collection; multi-entity dashboards; a mobile app nobody will use after week two.

Then send the 15 questions in writing, before any call. Written answers are comparable. Demos are theatre. A vendor who answers criterion 1 with "same day, usually" has told you something useful without meaning to.

What are the 15 criteria for an iGaming affiliate payment provider comparison?

Work through them in order. Each has a definition and the exact question to put to the vendor, phrased to produce an answer that can be wrong.

1. Settlement speed and cut-off time

Time from your batch approval to the affiliate having spendable funds, including the vendor's internal cut-off and any funding prerequisite.

Ask: "What is your daily cut-off in CET, what is the value date for a batch submitted five minutes before it, and what happens to a batch submitted five minutes after? Do you require pre-funding, and if so, when must the funds land?"

2. Rails and currency coverage

Which payment methods they genuinely deliver on, and what currency the affiliate ends up holding. Ask: "For each rail, give me the median and 95th-percentile delivery time over the last 90 days, split by destination region."

Providers offering Lightning, on-chain Bitcoin and stablecoin settlement alongside conventional transfers give you somewhere to go when a corridor closes.

If you're reviewing the cashier at the same time, look at casino payment infrastructure that handles deposits and payouts on the same rails rather than stitching together two unrelated vendor relationships and reconciling across both.

3. Jurisdictional and corridor coverage gaps

Not where they can pay. Where they can't, and what happens contractually when that list changes mid-contract.

Ask: "Give me the written exclusion list: countries you will not pay into, countries where gambling-related outbound payments are restricted by your own policy, and countries where a partner bank imposes the restriction rather than you.

Which corridors have you withdrawn in the last 24 months, with how much notice? If you withdraw a corridor I depend on during the term, what do I get: notice period, migration support, pro-rata refund, right to terminate without penalty?"

Get the notice period into the contract. Verbal reassurance is worth nothing on the 2nd of the month with 90 affiliates in Brazil unpaid.

4. Bulk payout API and batch handling

Whether you can push the whole monthly run programmatically and reconcile it without a human reading a CSV.

Ask: "Show me the request and response shape for a 500-line batch. One call or 500? What's the rate limit? How do I retrieve per-line status? Do you support idempotency keys, and what happens if my client retries the same batch after a timeout: duplicate payments, or a replayed response?

On partial failure, is behavior all-or-nothing or best-effort? If line 137 has an invalid IBAN, do the other 499 go out?"

A real bulk affiliate payouts API for a casino programme returns line-level statuses you can push straight back into the affiliate platform, and it never pays anyone twice because your load balancer hiccupped.

5. Counterparty screening depth and ownership of the record

Sanctions, PEP and adverse media checks on affiliates and their beneficial owners. Then the part everyone forgets: who holds the evidence.

Ask: "Which lists, which data vendor, at what frequency do you rescreen existing affiliates, and what's your match threshold? Can you produce a dated screening record for a named counterparty within 24 hours?

And critically: is that record mine or yours? Can I export the full screening history, including negative results and the analyst decision on false positives, on demand and on exit?" Search around for affiliate KYC AML sanctions screening operators and you'll find dozens of vendors happy to describe which lists they hit.

Almost none volunteer who keeps the file afterwards. That's the question that matters, because if the provider owns the record and you can't extract it, your MLRO is relying on a third party's goodwill during a licence review. Pass/fail.

6. FX and fee transparency, and what the affiliate actually receives

Whether you can see the applied rate and the spread before you approve, and whether the number you approve is the number that arrives.

Ask: "Show me a completed payout displaying the reference rate, the applied rate and the spread in basis points as separate fields. Does the affiliate receive gross or net after beneficiary and intermediary deductions?

Who bears intermediary bank charges on SWIFT, and can I fix that contractually?" A €500 commission that arrives as €478 because a correspondent took its cut is your problem, not the affiliate's, no matter what your fee table says.

7. Failure handling and retries

What happens when a payout bounces: wrong details, closed account, rejected by the receiving institution, held for enhanced due diligence.

Ask: "Who is notified, how fast, is the retry automatic or manual, who bears the cost of the failed attempt, and what's the median time from failure to funds back in my balance?

Show me the failure reason codes you actually return, not the categories on the marketing page."

8. Reporting and data granularity

How much detail finance gets, and whether it exports into something your ledger accepts without a macro.

Ask: "Can I export a run with affiliate ID, gross amount, fees, FX reference rate, applied rate, spread, net delivered, rail, failure reason and final timestamp per line, as CSV and via API?

Can I regenerate a historical run's report 18 months later, unchanged?" This is the interface with month-end close, and month-end close is a discipline of its own.

9. Licensing, regulatory posture and jurisdictional fit

The provider's own authorisations, and whether they line up with the licences your group holds.

Ask: "Under which authorisations do you operate, in which jurisdictions, under which legal entity will you contract with me, and where are the funds held between my funding and the affiliate's receipt?

Can your compliance team complete our standard counterparty due diligence pack, and will your regulator's register confirm the entity name on the contract?" Pass/fail. An unlicensed intermediary in the payment chain is a finding waiting to happen.

10. Security and custody controls

Who can move your money, and what stops them. Ask: "How are keys managed: HSM, MPC, shards, and how many people are needed to release funds? Is dual authorisation enforced on batch release and on changes to beneficiary details?

Can I allow-list destination addresses and bank details, with a cooling-off period on new additions? What happens when an affiliate changes their payout address: who approves it, and is the change logged with the approver's identity?

Send me the executive summary of your last penetration test, with dates, scope and remediation status, plus your SOC 2 Type II or ISO 27001 certificate." Fake-invoice fraud against affiliate payment details is real and growing.

Change-of-bank-details approval workflow is not a nice-to-have.

11. Contractual liability and compliance posture

What the paper says when something goes wrong. Ask: "What indemnity do you offer if your screening fails and I pay a sanctioned party? What's the liability cap, and is it per-incident or aggregate? Do I have audit rights, and on what notice?

Send me your data processing agreement, your sub-processor list, your breach notification window and where personal data is stored and transferred." Read the liability cap next to your monthly payout value. If the cap is €50,000 and you move €800,000 a month, you now know exactly who's carrying the risk.

12. Limits, thresholds and concentration risk

Per-transaction, per-batch and monthly ceilings, and whether one large affiliate payment triggers manual review at the worst possible moment.

Ask: "What are the per-affiliate, per-batch and monthly limits, who reviews an exception, and what's the turnaround? Have you ever held a client's batch for internal review, and what was the delay?"

13. KYB and onboarding friction for affiliates

How much work the affiliate does before their first payment, and how long verification takes.

Ask: "What's the median time from affiliate invitation to first payable status, what proportion fail onboarding outright, and what documents do you require from a sole trader in a country with no company register?" Every extra document is a partner who delays onboarding and keeps running your competitor's offer instead.

14. Support model and escalation SLA

Who you reach during a stalled run, and how fast. Ask: "Name the escalation contact, the business-hours response SLA, and the out-of-hours path when a batch fails on the 1st of the month. Is support in my time zone, and is it the same team on the 1st as on the 15th?"

15. Exit terms and data portability

What you keep if it ends badly. Ask: "On termination, which affiliate payment credentials, screening records and historical payout data are returned, in what format, within how many days?

Is there any lock-in on stored counterparty records, and what does it cost to get a full export?" Pass/fail. If you can't leave with your data, you haven't chosen a provider, you've been adopted by one.

How should you weight the scorecard?

Fixed weights force honesty. Without them, whichever vendor gives the best demo wins, and the winning reason will turn out to be a dashboard nobody logs into after month three.

Score each criterion 1–5, multiply by weight, sum. Maximum 500. Any criterion scoring 1 or 2 on a weight of 8 or above is a blocker, not a deduction: you either fix it in contract or you drop the vendor.

Three criteria aren't scored at all. Screening record ownership (5), licence status (9) and exit portability (15) are pass/fail.

A vendor that fails one of those with a total of 460 still loses to a vendor that passes all three with 380, because the failure isn't a weakness. It's an unmanaged liability sitting inside your licence.

#

Criterion

Weight

Evidence to request

Disqualifier threshold

Vendor A

Vendor B

Vendor C

1

Settlement speed & cut-off time

11

90-day delivery-time report, cut-off in writing, funding requirement

Cut-off before 12:00 CET with T+2 or worse




2

Rails & currency coverage

9

Rail list with median/p95 delivery by region

Cannot deliver your top-3 currencies natively




3

Corridor coverage gaps & withdrawal terms

7

Written exclusion list, 24-month withdrawal history, notice clause

No contractual notice on corridor withdrawal




4

Bulk payout API & batch handling

9

Sandbox 500-line batch, idempotency docs, partial-failure spec

No idempotency keys, or all-or-nothing batches only




5

Screening depth & record ownership

10

Sample dated screening record, list coverage, rescreen frequency

Pass/fail: operator cannot export or own the record




6

FX & fee transparency, net delivered

9

Completed payout with reference rate, applied rate, spread in bps

Spread not disclosed pre-approval




7

Failure handling & retries

8

Anonymised failure log with timestamps and reason codes

Cost of failure borne by operator with no reason code




8

Reporting & data granularity

6

Sample CSV and API export, 18-month regeneration test

No per-line fee/FX breakdown




9

Licensing & jurisdictional fit

7

Licence numbers, regulator register entry, contracting entity

Pass/fail: unlicensed entity in the payment chain




10

Security & custody controls

6

Pen test summary, SOC 2/ISO cert, dual-auth and allow-list config

No dual authorisation on batch release




11

Contractual liability & compliance posture

4

Draft MSA, indemnity and cap, DPA, sub-processor list

Liability cap below one month's payout value




12

Limits & concentration risk

3

Written limit schedule and exception turnaround

Largest single affiliate payout exceeds per-txn limit




13

KYB







Frequently Asked Questions

Why does affiliate payout provider selection deserve its own process?

How is this different from choosing a deposit PSP?

What should you do before the first vendor call?

What are the 15 criteria for an iGaming affiliate payment provider comparison?

How should you weight the scorecard?

Power your payments & payouts with LightningPay

Accept Bitcoin and stablecoins, enable instant withdrawals, and deliver better player experiences with infrastructure built for iGaming.

Trusted & Certified

SOC2 Type 2

PCI-DSS

ISO 27001

KYC/AML

Power your payments & payouts with LightningPay

Accept Bitcoin and stablecoins, enable instant withdrawals, and deliver better player experiences with infrastructure built for iGaming.

Trusted & Certified

SOC2 Type 2

PCI-DSS

ISO 27001

KYC/AML

Power your payments & payouts with LightningPay

Accept Bitcoin and stablecoins, enable instant withdrawals, and deliver better player experiences with infrastructure built for iGaming.

Trusted & Certified

SOC2 Type 2

PCI-DSS

ISO 27001

KYC/AML