KYC and AML are related but distinct processes. The first answers the question of who exactly stands behind an account; the second asks whether the activity on that account looks like money laundering. Both are mandatory for a licensed operator and both are examined by the regulator.

What KYC covers

Basic identification confirms the player's identity, age and address. Operators typically request an identity document, proof of address and evidence that the payment instrument belongs to the account holder. Sanctions lists and politically exposed person status are checked in addition. Where risk is elevated, enhanced due diligence follows, including confirmation of the source of funds.

AML transaction monitoring

Monitoring runs continuously and looks at behaviour rather than paperwork: turnover inconsistent with the declared profile, deposits followed by rapid withdrawals with almost no play, structuring of amounts, payments from third-party instruments, geography untypical for the player. Triggered scenarios go to a compliance officer for manual review, who decides whether to escalate the case.

The risk-based approach

Modern requirements do not reduce to one identical procedure for everyone. The operator is obliged to assess the risk of the customer and of the market and to allocate the depth of checks accordingly, documenting the reasoning behind each decision.

For the product this implies a practical constraint: KYC cannot be deferred until withdrawal — otherwise verification turns into a source of disputes and complaints.