No headings found on page
crypto payments for igaming

TL;DR:

  • No mainstream licence still treats crypto deposits as outside AML scope — the question is evidentiary depth, not existence.

  • MGA and UKGC supervision focuses on whether you can show a documented, risk-based decision at the point of transaction, not just an annual policy.

  • Curacao's post-LOK framework has moved crypto from tolerated to explicitly supervised, with the regulator asking operators to demonstrate monitoring capability.

  • US sweepstakes operators face the least gaming-specific crypto rulebook and the most exposure from FinCEN/state money transmission and sanctions expectations.

  • The common capability gap is timing: most stacks screen after settlement, then reconcile reports to player ledgers to prove they acted.

Every major gaming licence now expects risk-based crypto transaction monitoring in some form, but depth, retention periods and reporting channels differ sharply.

The MGA and UKGC are the most prescriptive on documented monitoring and record-keeping, Curacao is tightening quickly under its post-LOK regime, and US sweepstakes operators are pulled toward FinCEN and state money transmission expectations instead.

Why does "we already do AML" no longer answer the crypto question?

Most operators reading this have a functioning AML programme built around card, bank transfer and e-wallet flows: thresholds, velocity rules, a case management queue, a nominated officer, an annual risk assessment. The instinct is that crypto deposits simply route into the same machinery.

Regulators have started asking a narrower question. Not "do you monitor deposits?" but "what do you know about the wallet and counterparty that funded this deposit, and when did you know it?" That is a different technical capability. Fiat monitoring is fundamentally about behaviour — patterns in a player's own activity.

Crypto monitoring adds a provenance dimension: the on-chain history of the address, its exposure to sanctioned entities, mixers, darknet markets, high-risk exchanges or known fraud clusters. A player can look perfectly ordinary in your ledger while depositing from a wallet two hops from a sanctioned service.

Every licence framework discussed below now touches that provenance question, either explicitly or through a general obligation that supervisors have interpreted to include it. The budget consequence is that "extend our existing rules engine" is usually insufficient — you need a blockchain analytics dependency and, more importantly, a decision point in the payment flow where its output changes what happens to the funds.

What does each licence actually require, at a glance?

Licence

Crypto monitoring status

Primary reporting route

MGA (Malta)

Explicit, risk-based, documented

FIAU via reporting portal

UKGC

Explicit, prescriptive expectations

UKFIU SAR channel

Curacao (post-LOK)

Increasingly explicit, supervised

Curacao FIU

Anjouan / light-touch

Implied via general AML duty

Local FIU, thin guidance

US sweepstakes

Implied via FinCEN/state rules

FinCEN SAR filing

Everything that matters is in the prose below. The table tells you the shape; it cannot tell you what evidence survives an inspection.

What do the MGA crypto transaction monitoring rules expect in practice?

Malta remains the most instructive regime because the MGA supervises alongside the FIAU, and the two produce complementary expectations. The MGA expects licensees accepting virtual financial assets to treat them as a distinct risk category within the business risk assessment — not a footnote to the payments section.

Guidance indicates supervisors look for ongoing monitoring of both the customer relationship and the individual transaction, with crypto-specific typologies reflected in your rules.

Concretely, operators under MGA supervision are generally expected to be able to demonstrate: wallet address screening against sanctions and high-risk exposure; a documented rationale for thresholds and risk appetite; escalation paths where analytics flag exposure; and retention of the underlying data.

Record retention under Maltese AML law typically runs five years from the end of the relationship or the transaction, and in practice that means retaining the screening result itself — not merely the fact that a screening tool was licensed at the time.

Suspicious activity reporting goes to the FIAU. The obligation is to report promptly on forming knowledge or suspicion; there is no comfortable grace period, and delayed filing is itself a supervisory finding.

Tipping-off restrictions apply, which has a payments-stack implication operators often miss: your player communications templates need a path for holding or declining funds that does not reveal the reason.

The MGA crypto transaction monitoring rules also carry a governance expectation. The MLRO or equivalent must have genuine visibility into crypto flows, which is hard to satisfy if analytics output lives in a separate vendor dashboard that never joins the player record.

How prescriptive is the UKGC, and does crypto change the answer?

The UKGC's licence conditions and codes of practice apply regardless of deposit method, and the Commission has been consistent that accepting cryptoassets does not reduce obligations — if anything it raises the expected standard of source-of-funds enquiry and ongoing monitoring.

Casework and enforcement notices have repeatedly criticised operators for policies that existed on paper but were not applied at transaction level.

For crypto specifically, expect scrutiny on three points: whether you can establish provenance to a standard proportionate to the amounts involved, whether monitoring is continuous rather than at-onboarding, and whether flagged cases were actioned with documented outcomes.

Suspicious activity reports go to the UK Financial Intelligence Unit within the NCA, and where you need to stop a transaction, the defence against money laundering consent process introduces fixed timelines that your operations team must be able to hold funds through.

The retention and audit dimension is where UK-licensed operators most often find gaps. Producing "the analytics report for that month" is not the same as producing the decision you made about a specific deposit at a specific timestamp.

What are the curacao gaming AML crypto obligations now that the regime has changed?

Curacao's transition under the National Ordinance on Games of Chance has changed the supervisory posture materially. The Curacao Gaming Authority now conducts direct supervision rather than relying on master-licence intermediation, and AML expectations have been drawn closer to international standards including FATF's virtual asset guidance.

For operators, the practical Curacao gaming AML crypto obligations now include maintaining a written AML/CFT programme that names crypto as a risk vector, appointing a compliance officer with real authority, conducting ongoing transaction monitoring, and reporting unusual transactions to the Curacao FIU.

Guidance indicates the authority is asking applicants and existing licensees to describe their monitoring toolset specifically — which vendor, which risk categories, what happens on a hit.

The gap between Curacao and Malta is narrowing on what is required and remains wider on how intensively it is examined. That is a risky basis for a budget decision.

Operators who built minimal monitoring on the assumption that Curacao would not look closely are now retrofitting under time pressure, which costs more than building it once.

Anjouan, Costa Rica-style structures and comparable light-touch setups sit further down the same continuum. The general AML duty usually exists in local law; the crypto-specific guidance often does not.

In practice, banking partners, payment providers and B2B suppliers impose the effective standard, because they need to satisfy their own regulators. Assume your counterparties will require what your licence does not.

What drives sweepstakes casino AML compliance in the US?

US sweepstakes operators occupy the most awkward position, because there is no gaming regulator issuing crypto AML guidance to them.

Sweepstakes casino AML compliance in the US is instead shaped by federal money services business rules under FinCEN, OFAC sanctions obligations that apply to every US person regardless of licensing, and a patchwork of state money transmission and consumer protection regimes.

Two exposures dominate.

First, OFAC: sanctions screening is strict-liability territory, and accepting a deposit from a wallet with sanctions exposure is not cured by a good-faith policy.

Second, the money transmission question — depending on how coin purchases, redemptions and cash-out mechanics are structured, an operator or its payment partner may fall within MSB definitions, which brings SAR filing, a written AML programme, independent testing and recordkeeping duties. FinCEN SAR filing timelines are defined in days from initial detection, with a limited extension where no subject has been identified.

State attorneys general and regulators have been increasingly active on sweepstakes models. The monitoring capability you build now is the same capability that answers a state inquiry later.

Where does monitoring actually sit in the payment flow?

This is the question that determines whether your compliance spend produces usable evidence.

Most stacks screen after the fact. The deposit lands, the credit posts to the player balance, and blockchain analytics runs on a batch or webhook basis afterward. When a hit surfaces, the operator is already holding tainted value, may already have allowed wagering against it, and must now reconstruct a chain of events across the analytics dashboard, the payment processor's records and the player ledger to prove that action was taken.

The alternative is to make the decision earlier. Using a crypto payment gateway that screens deposits before they settle moves the sanctions and high-risk determination in front of the balance credit, so the outcome is recorded as a single event rather than reconstructed from three systems.

Three architectural questions worth answering before you spend anything:

  1. Can your gateway hold a deposit pending a screening result, or does it credit on confirmation with no hold state?

  2. Does the screening result persist in a record joined to the player and the transaction, retrievable for five-plus years without vendor dependency?

  3. Can you produce a timestamped decision trail — screened at, result, action, reviewer — for any single deposit on request?

If the answer to any of those is no, that is your capability gap, and it is the same gap under every licence discussed here. If you hold licences in more than one of these jurisdictions, see how LightningPay handles multi-licence crypto payments across differing evidentiary standards.

What does pre-settlement screening change about your evidence position?

LightningPay performs wallet and counterparty screening at the gateway layer, before funds are credited to a player balance. The sanctions and high-risk decision is made pre-settlement, not reconciled afterward.

The reason that matters here is narrowly evidentiary. Multi-licence operators otherwise have to align post-hoc analytics reports against player ledgers to demonstrate they acted — a reconciliation exercise that is slow, error-prone and unconvincing when an MGA or UKGC examiner asks what happened to one specific deposit on one specific date.

A pre-settlement decision produces the artefact directly: screened at this timestamp, this result, funds declined or held, credited or not. That is the record supervisors ask for, and it is the same record whether the file is a FIAU submission, a UKFIU SAR or a FinCEN filing.

Final thoughts

The useful dividing line between jurisdictions is no longer strict versus lax.

Curacao's tightening, banking counterparties imposing standards that light-touch licences do not, and US sweepstakes exposure running through FinCEN and OFAC rather than a gaming regulator have all compressed the range.

What separates operators now is whether they can evidence a risk-based decision at the moment of the transaction — and that is an architecture question, not a policy question.

If you hold or are pursuing more than one licence, build to the strictest standard in your footprint and inherit compliance downward; maintaining differentiated monitoring per licence costs more than a single high standard and produces weaker evidence in every jurisdiction.

The operators who will handle the next three years of supervision comfortably are the ones treating suspicious activity reporting for crypto gambling as an output of their payment flow rather than a report assembled after it.

If you want to pressure-test your current setup against the jurisdictions you actually hold, talk to the LightningPay team about your licence footprint.

Frequently Asked Questions

Is crypto transaction monitoring explicitly required under a Curacao licence?

How long must we retain crypto screening records?

What is the reporting timeline for a suspicious crypto deposit?

Do US sweepstakes operators need a full AML programme?

Power your payments & payouts with LightningPay

Accept Bitcoin and stablecoins, enable instant withdrawals, and deliver better player experiences with infrastructure built for iGaming.

Trusted & Certified

SOC2 Type 2

PCI-DSS

ISO 27001

KYC/AML

Power your payments & payouts with LightningPay

Accept Bitcoin and stablecoins, enable instant withdrawals, and deliver better player experiences with infrastructure built for iGaming.

Trusted & Certified

SOC2 Type 2

PCI-DSS

ISO 27001

KYC/AML

Power your payments & payouts with LightningPay

Accept Bitcoin and stablecoins, enable instant withdrawals, and deliver better player experiences with infrastructure built for iGaming.

Trusted & Certified

SOC2 Type 2

PCI-DSS

ISO 27001

KYC/AML