HomeInsightsGambling Commission publishes 2026 money laundering and terrorist financing risk assessment


Contact

On 30 July 2026, the Gambling Commission (“Commission”) published its 2026 risk assessment of money laundering (“ML”) and terrorist financing (“TF”) within the British gambling industry (“2026 Risk Assessment”).

As the supervisory authority for casinos in Great Britain – a regulated sector – the Commission is required, under Regulation 17(1) of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (“2017 Regulations”), to identify and assess ML and TF risk relevant to the casino sector.

The 2026 Risk Assessment represents an update to, and builds upon, the Commission’s previous risk assessment, published in November 2023. Notably, the 2026 Risk Assessment also takes account of the National Risk Assessment published jointly by the Home Office and HM Treasury in July 2025 (“National Risk Assessment”).

As set out within the 2026 Risk Assessment, the “purpose of [the 2026 Risk Assessment] is to:

  • provide a resource for the industry to inform their own ML and TF risk assessments
  • provide support to the National Risk Assessment of Money Laundering and Terrorist Financing conducted by HM Treasury and the Home Office
  • inform and prioritise our licensing, compliance and enforcement activity in order to raise standards in the industry…”

Significance of 2026 Risk Assessment

Those operators that maintain a casino licence are subject to the 2017 Regulations and, as such, must maintain their own ML / TF risk assessment, which must take account of the 2026 Risk Assessment. It is, however, important to emphasise the need for all operators licensed by the Commission to review and digest the 2026 Risk Assessment – not just casinos. Indeed, Licence Condition 12.1.1(3) sets out that an operator’s policies, procedures and controls must “take into account any applicable learning or guidelines published by the [Commission] from time to time”.

The publication of the 2026 Risk Assessment should, therefore, be treated as a trigger point for all licensed operators to review their anti-money laundering (“AML”) / counter-terrorist financing (“CTF”) control framework and – where necessary – update their own risk assessments, policies and procedures and controls.

B2B operators that hold a host licence – and are therefore subject to Licence Condition 12.1.1(3) – should likewise review their AML / CTF control framework, especially in the light of the Commission’s statements on the B2B sector within the 2026 Risk Assessment, which we touch on below.

2026 Risk Assessment: Key Observations

We set out below key observations concerning the 2026 Risk Assessment:

  • New risk vulnerabilities: The risk assessment matrix explains that the Commission has introduced: (i) ‘New wording’ to “add more clarity and consolidate risk”; and (ii) ‘New risk’, which “refers to identified and emerging risks and previously unidentified risks that were not considered in the previous assessment”.

The Commission’s efforts to clarify and consolidate its description of risk vulnerabilities are, of course, welcome. Having said that, it will become very quickly apparent to readers of the 2026 Risk Assessment that what the Commission terms a ‘New risk’ is, in very many cases, not an emerging risk at all. While that may be the case in certain instances (e.g., the emergence of AI and the use of the same to bypass customer due diligence  – see below), the Commission tags as a ‘New risk’ vulnerabilities such as, but by no means limited to, the following: (i) disproportionate spend; (ii) inappropriate AML thresholds; (iii) duplicate or linked accounts; and (iv) failure to appropriately scrutinise source of funds documents. While these are ‘new’ in the sense they may not have been specifically identified in the Commission’s 2023 risk assessment, operators will (or certainly should) have identified and addressed such risk vulnerabilities – either expressly or implicitly – within their overarching ML / TF control framework given that they represent well-established risk vulnerabilities.

  • Gambling software risk rating: The overall risk rating associated with gambling software has increased from ‘Low’ to ‘Medium’. Further, the 2026 Risk Assessment:
  • Introduces a number of ‘new risks’ relevant to gambling software, such as insufficient monitoring of third-party contracts to identify the resale of software to unlicensed sites; and
  • Sets out that, in connection with existing risks set out in the Commission’s previous risk assessments, there is now an increase in the impact and / or likelihood of such risks, such as the adequacy of due diligence checks on third-party business relationships.

The Commission explains that the increase in overall risk is “due to the risk posed by business-to-business relationships and the risk of licensed operators supplying software to illegal website operators”. The Commission also points to an example of a licence applicant having obtained funding through an initial coin offering but having not conducted sufficient diligence on its investors.

It is perhaps not a surprise that the Commission has sought to increase its assigned risk rating of the gambling software sector. Indeed, the Commission has, especially since the previous risk assessment, placed a greater focus and emphasis on the B2B sector.

  • Illegal markets: Linked to the above, the Commission has introduced a new, albeit high-level, section on illegal markets. The Commission explains that illegal gambling websites “undermine the integrity of the gambling industry” because such sites are not subject to necessary oversight, thereby allowing for “high-value activity to be conducted”. The Commission also points to the operation of such sites by organised crime groups as well as the acceptance by such sites of crypto assets as payment.
  • High value customers (“HVC”): The ‘HVC schemes’ risk vulnerability set out within the remote casino section of the 2026 Risk Assessment states there is now a ‘decrease in likelihood’ (moving from ‘Medium’ to ‘Low’) of such schemes posing an ML / TF risk. Notably, the remote betting section no longer includes HVC schemes as a vulnerability. This is, almost certainly, due to the decline in the number of what many would think of as an HVC scheme in the British market some five years ago.
  • AI risks: The Commission has sought to address risk posed by the increased prevalence and widespread availability of AI within the 2026 Risk Assessment. There is a particular focus on the risk associated with the use of AI to create mule accounts and also bypass customer due diligence.
  • Casinos & the National Risk Assessment: The National Risk Assessment, last published in July 2025, set out that ML risk in the casino sector is now ‘Medium’, having previously been ‘Low’ in 2020. The increase in rating was “mainly driven by changes in customer, geographical and transaction risks, particularly the increase in funds moving through remote casinos”.

It is important to recognise that the National Risk Assessment’s risk score of ‘Medium’ assigned to casinos must be read in the context of HM Treasury and the Home Office’s view on ML risk occurring in other regulated sectors. The Commission explains that the National Risk Assessment “captures the relative risk of ML and TF occurring across all regulated financial sectors”, whereas the Commission “compares the ML and TF risks in individual gambling sub-sectors and rates them in comparison to each other”.

While the Commission’s overall risk rating of the casino sector (both remote and non-remote) remains ‘High’ relative to other gambling sub-sectors, HM Treasury and the Home Office’s macro-level view of ML risk in the casino sector is ‘Medium’. A casino operator should, therefore, be entitled to design their risk-based framework with that broader context in mind and not just based on the Commission’s stated position. In many instances, casino operators appear to be held to a higher standard of AML compliance compared to businesses operating in other regulated sectors. That elevated standard of compliance seemingly stems from the Commission’s expectation of operators to, for example, apply enhanced scrutiny of customer relationships compared to businesses operating in other regulated sectors or set transaction level triggers below those used in other regulated sectors. A casino operator’s risk-based approach to AML/CTF compliance should take account of not just the Commission’s narrow view on risk relative to gambling as a whole, but also the actual risk which is informed by the broader context in which casinos find themselves.

Comment

The Commission will, as part of a compliance assessment, review a casino operator’s risk assessment against its own. For some time now, the Commission has adopted a rigid approach when reviewing an assessment, with the overriding sense being that the Commission essentially undertakes something of a box-ticking exercise to test whether a casino operator has reflected, in its own assessment, each and every single risk vulnerability that appears in the Commission’s risk assessment. We continue to see the Commission criticise casino operators for not expressly including every risk vulnerability that appears in the Commission’s assessment – even if certain risk vulnerabilities are clearly not of relevance to a particular casino’s business.

In view of that, and given the various changes within the 2026 Risk Assessment, casino operators would be well-advised to undertake a review of their own risk assessments to ensure that they take account of the 2026 Risk Assessment in both substance and form.

As noted above, all licensed operators should – in accordance with their obligation under Licence Condition 12.1.1(3) – review their AML / CTF control framework and, where necessary, update their own risk assessments, policies, procedures and controls.

The 2026 Risk Assessment can be accessed here.