Free guide: How to use AI in compliance
Built for multi-vertical iGaming operators and US sportsbooks

KYC for iGaming That Clears the Same Player Across Verticals

KYC for iGaming used to mean one verification per product. A sportsbook KYC. A casino KYC. A separate flow for DFS. A different policy in every US state. Zyphe runs the KYC for iGaming check once (age, identity, address, sanctions, source of funds, geolocation) and lets the same player deposit on your sportsbook, lay a fantasy lineup, hit the casino, and buy a lottery ticket without re-verifying. The audit trail is regulator-ready. The PII never sits on your server.

KYC for iGaming architecture: one verified player credential reused across sportsbook, daily fantasy sports, casino, and lottery products
Used by multi-vertical iGaming operators and US sportsbooks to verify players against 4,000+ identity document versions from 213 countries and territories, across every product they run.
  • GDPR
  • UKGC age-assurance ready
  • MGA-aligned
  • AGCO-aligned
  • GeoComply-compatible
  • GLI-ready
  • SOC 2 + ISO 27001 in progress

KYC for iGaming is the verified-identity layer a multi-vertical operator runs once across sportsbook, daily fantasy, casino, and lottery on a single player base. It covers age, identity, address, sanctions, source of funds, and geolocation across US multi-state regimes, and runs perpetual monitoring at the credential layer rather than periodic review.

Why is KYC for iGaming uniquely hard in 2026?

Three things make KYC for iGaming harder than any single-vertical fintech or pure online casino. Operators run multiple verticals on one player base. The US side fragments into 27+ jurisdictions with different rules each. And the speed of in-play betting collides with the speed of legacy KYC vendors. The bill is now arriving.

The UKGC settled with Bet365 for £582,120 over ineffective KYC and customer due diligence. Flutter’s Paddy Power and Betfair were fined £2 million in December 2025 over customer interaction failures, for not identifying problem gamblers fast enough. The DFS world had its enforcement moment too: PrizePicks settled with the New York State Gaming Commission for nearly USD 15M, and Underdog Fantasy settled for USD 17.5M, both for offering contests outside the licensed scope.

For broader regulatory context, see our enhanced due diligence vs standard CDD breakdown and the dedicated KYC for casino page if your operation is casino-only.

What we hear from operators and partners

"Operators pour money into affiliates. Compliance vendors come last."
Strategic partner working into iGaming
"Casinos strictly limit data sharing to regulators. The KYC for iGaming stack has to respect that."
Same call
"Gambling rankings change multiple times a day. Onboarding is where you lose them."
Former in-house SEO at a major Italian operator
"Nobody budged on adding a new vendor. Nobody cared."
Founder reflecting on his first attempt to sell into gaming

The pattern is consistent. The compliance team needs a defensible audit. The product team needs the player to convert. The CTO doesn’t want yet another vendor in the data path.

What does KYC for an iGaming platform actually need to cover?

More than a single-vertical fintech, less than a fully regulated bank, and with three checks that get compliance leads fired when they fail: age, self-exclusion, and source of funds. Layer on geolocation for any US sportsbook, ongoing monitoring for problem-gambling triggers, and entity-level KYB for B2B partners on your rail. The table below is the minimum-viable KYC for iGaming stack the major regulators expect.

Check Why an iGaming operator needs it Zyphe coverage
Age verification Variable thresholds: 18 in most EU jurisdictions, 21 in some US states, 19 in Nebraska / Alabama for DFS NFC chip read, ID OCR, and liveness with jurisdiction-specific thresholds
Identity (ID and liveness) UKGC and MGA technical standards, deepfake-resistant under 2025 guidance Document OCR, NFC, liveness, deepfake detection
Address verification Tax residency, jurisdiction routing, deposit-limit assignment Document or trusted-source verification
Geolocation US sportsbook licensing requires the player to be physically in-state Zyphe geolocation: GPS against IP country, VPN and proxy detection, IP blacklist; result stored in Zyphe. GeoComply-compatible if you already run it.
Sanctions, PEP, adverse media AML obligation under FATF and local AMLDs Continuous re-screening, configurable thresholds
Source of funds (EDD) Required for high-deposit and VIP players in nearly every regime Document upload, automated review, sign-off workflow
Self-exclusion GAMSTOP (UK), Spelpaus (SE), Coalition for Fantasy Sports plus idPair (US DFS), state-specific registries Integrated registry checks at signup, deposit, and configurable triggers
Ongoing monitoring Continuous CDD, transaction monitoring, problem-gambling triggers Pair with AML software; see our perpetual KYC breakdown

For deeper detail, see adverse media screening AML guide and the three pillars of customer verification.

What does online gambling verification require, market by market?

Online gambling verification is regulated by licence, not by product, so the same sportsbook faces different rules in London, Malta, Toronto and Trenton. The constants are identity and age before the first deposit or bet, sanctions and PEP screening, a self-exclusion check, and enhanced due diligence as risk rises. The variables are the age threshold, the register to check, whether geolocation is a licence condition, and whether affordability is a formal obligation.

  • United Kingdom. Name, address and date of birth verified before deposit or play under licence condition 17; GAMSTOP; customer interaction rules; financial vulnerability checks at net deposits of 500 pounds a month from August 2024 and 150 pounds from February 2025.
  • Malta and the EU licences. Customer due diligence under the AML framework with enhanced due diligence thresholds; national self-exclusion where one exists (Spelpaus in Sweden, the ANJ framework in France, ADM in Italy).
  • Ontario. Age and identity before play under the Registrar’s Standards; self-exclusion; responsible gambling triggers.
  • US states. Age 21 in most states, 18 or 19 for some DFS markets; in-state geolocation as a licence condition; state self-exclusion lists; identity verification against a government document or knowledge-based data.

The KYC for casino page covers the casino licence regimes in more depth. Whichever market, the operator that verifies at signup and recognises the player across brands has the shorter audit.

How does online gambling identity verification differ from fintech KYC?

Identity verification in online gambling borrows its AML core from banking and adds three checks a fintech never runs. Age is a hard gate with thresholds that change at state lines. Self-exclusion is a register lookup against people who have asked not to be served, and missing one is a public reprimand. Affordability watches spend against means, which no payment app does. Gambling also front-loads everything: the UK removed the 72-hour verification window in 2019, so identity and age must be confirmed before the first bet, not within a grace period. And the same player is re-verified far more often, at every brand and vertical, which is why reusable verification matters more here than anywhere else.

How does Zyphe support multi-vertical KYC for iGaming on one player base?

This is the core problem a KYC for iGaming stack has to solve and the part most vendors get wrong. A multi-vertical operator runs sportsbook, casino, DFS, lottery, and sometimes poker on the same player. Most KYC vendors verify each entry point independently, which means three or four full re-verifications on what should be one customer record. Every duplicate is a breach surface and a drop-off point.

Zyphe verifies once and the same player walks across every vertical. Once cleared, they hold a portable KYC Passport: a signed, user-controlled credential, shared with the next operator after an accepted invite and the player’s consent, unlocked with a passkey. Your sportsbook reads it. Your casino reads it. Your DFS app reads it. Your lottery reads it. Each vertical applies its own policy on top: different age threshold for DFS in Iowa versus sportsbook in Nevada, different EDD threshold for high-stakes casino versus low-stakes lottery, but the underlying identity is the same record.

For BaaS-style aggregator setups and affiliate networks where the verification happens upstream, the affiliate or platform pre-verifies the player and the operator receives a cleared deposit. See reduce KYC onboarding drop-off and the KYC onboarding process: ultimate guide.

How does Zyphe handle US multi-state sportsbook fragmentation?

DraftKings now operates in 27 states plus DC. FanDuel and BetMGM run similar footprints. Each state has its own age threshold (mostly 21, sometimes 18), its own self-exclusion register, its own geolocation requirements, its own deposit-limit defaults, and its own data-residency expectations. Building a separate KYC for iGaming pipeline per state used to be the only option.

We ship preset state policies for the major sports-betting regimes (NJ, NY, PA, IL, MI, AZ, MA, OH, NC, VA, plus the broader DraftKings footprint) and let your team configure the rest from the dashboard. Geolocation runs against your existing GeoComply integration, with our verification result and the geo result both written to the same audit trail.

The same architecture extends to MGA, UKGC, AGCO Ontario, and the EU regimes covered on the KYC for casino page. For multi-state operators specifically, the operational gain is replacing N parallel KYC pipelines with one verified record and N policy overlays.

How does Zyphe handle DFS, fantasy contests, and the variable age problem?

The variable age problem is why the minimum age in Zyphe’s age verification is configured per flow and per market, read from a verified document rather than a self-declared field, with the geolocation step confirming which market’s rule applies.

DFS sits in a different regulatory bucket from sportsbook in most US states, with age thresholds that swing between 18, 19, and 21 depending on the jurisdiction. The PrizePicks and Underdog settlements made it clear: enforcement is no longer theoretical, and the safety net is operator-side verification, not regulator forbearance.

Zyphe handles DFS the same way it handles sportsbook: same KYC for iGaming verification, different policy threshold. A player verified for sportsbook in a 21+ state automatically clears an 18+ DFS market on the same record. A player who tries to deposit on a DFS contest in Iowa (21+) fails the policy check even if they cleared an earlier 18+ vertical, because the policy layer is per-vertical and per-jurisdiction. The audit trail captures the exact policy version that was applied.

The Coalition for Fantasy Sports’ national self-exclusion partnership with idPair is the kind of cross-operator registry our policy layer integrates with directly. When the player is on the list, the deposit is rejected and the rejection is logged.

iGaming identity verification: age, self-exclusion and affordability

These three checks are where iGaming identity verification is won or lost, and where a generic KYC vendor is weakest.

Age verification. The date of birth is read from the verified document, not typed by the player, and the threshold is applied per market and per vertical by the age verification policy layer. A returning player proves they are over the limit again without a new capture.

Self-exclusion. GAMSTOP and Spelpaus are integrated; the Coalition for Fantasy Sports list through idPair and state registers are wired through the same policy hook. The check runs at signup, at first deposit and on configurable triggers, and a positive result rejects the deposit and logs the rejection.

Affordability checks. The UK Gambling Commission’s social responsibility code 3.4.4 requires a financial vulnerability check once deposits minus withdrawals exceed 500 pounds in a rolling 30 days from 30 August 2024, and 150 pounds from 28 February 2025, run against public records such as bankruptcy orders and county court judgments rather than documents from the player. Because they key off net deposits, they depend on knowing that the player at brand A and the player at brand B are the same person, which a verification reused across the group delivers and a per-brand pipeline does not. The thresholds live in the operator’s responsible gambling system; Zyphe supplies the verified identity they attach to.

KYC gaming checklist: what does an operator need before launch?

A KYC gaming stack is ready for a licence application when every item below has an owner and a test case.

  1. Document and liveness verification with injection detection, against every document your markets issue.
  2. Age threshold per market and per vertical, read from the document.
  3. Sanctions, PEP and adverse media screening with ongoing re-screening.
  4. Self-exclusion register checks at signup, deposit and on triggers.
  5. Geolocation for state-bound licences, joined to the same audit record.
  6. Source of funds and enhanced due diligence workflow for higher-risk players.
  7. Affordability signals fed by a single player identity across brands.
  8. An audit export that reconstructs any case, with the policy version applied, in under an hour.

How does perpetual monitoring apply to KYC for iGaming compliance?

The Flutter and Paddy Power £2 million fine in December 2025 was anchored on customer interaction failures, the operator’s failure to identify problem gamblers fast enough, not on a one-time onboarding gap or a self-exclusion breach. That is the perpetual KYC pattern applied to KYC for iGaming.

Three operational layers worth flagging:

  1. Continuous sanctions and PEP re-screening at the credential layer. When a player matches a sanctions list update, re-screening updates their risk score, and transaction monitoring returns Allow, Review or Block on the next deposit.
  2. Behavioural-pattern monitoring at the operator layer. Velocity, deposit-size deviation from baseline, time-of-day patterns, and chasing-loss signals feed into a real-time risk-tier update. For the architectural argument, see our perpetual KYC breakdown.
  3. Real-time verification for in-play betting and live wagering. For a returning player with a KYC Passport, re-validation against geolocation, sanctions, and self-exclusion runs via passkey without a new capture. That catches a self-exclusion at the wager rather than at the next periodic review.

For the broader monitoring framework, pair with Zyphe AML software and see our adverse media screening AML guide for the false-positive analysis.

Which iGaming verticals does Zyphe’s KYC for iGaming support?

Most of the verticals running real-money flows under a regulated licence. The fit is sharpest where one operator runs multiple verticals on the same player or where the operation spans multiple US states. In practice that’s:

  • Multi-vertical operators: sportsbook, casino, poker, DFS, and lottery on the same platform.
  • US sportsbooks: multi-state KYC for iGaming, geolocation, age, self-exclusion, American Gaming Association best-practices alignment.
  • Daily fantasy sports: variable age threshold per state, Coalition self-exclusion integration.
  • Esports betting: under-age risk, DFS-style fantasy on top of esports markets.
  • iLottery and online lottery: state-by-state, age, address, AML screening.
  • Sportsbook aggregators and affiliate networks: pre-verify upstream, deliver cleared players to operators.
  • Land-based casinos with online arms: unify the player record across the floor and the website.
  • Bingo and skill-gaming platforms: lightweight verification, configurable per-jurisdiction.

If your vertical isn’t listed, configure a custom policy from the dashboard or talk to compliance via contact.

How does Zyphe compare to Sumsub, Onfido, IDnow, and Jumio for KYC for iGaming?

The feature lists overlap. The differences that matter for an iGaming operator are about player drop-off, multi-vertical reuse, audit posture under inspection, and what happens to the data when the next centralized vendor gets breached.

What an iGaming operator cares about Sumsub / Onfido / IDnow / Jumio Zyphe
Player documents stored on vendor Yes, retained 5 to 7 years per licence rules Sharded, user-held, vendor cannot reconstruct
Reusable verification across verticals Vendor-locked or unsupported KYC Passport, one record reads on every vertical
Multi-state US sportsbook policies Engineering effort per state Preset policies for the major US regimes, configurable from dashboard
In-play re-verification Often a fresh capture for re-auth Passkey re-validation, no new capture
Geolocation Often a separate vendor Zyphe geolocation stored on the same audit trail; GeoComply-compatible
Self-exclusion registry coverage Often a separate vendor per registry GAMSTOP, Spelpaus, Coalition self-exclusion in one layer
Time to ship in production 2 to 6 weeks 15 minutes (no-code) or 1 to 2 days (API)
Audit posture under UKGC, MGA, AGCO inspection Manual, vendor-dependent Threshold-encrypted, regulator and player co-sign

Read the head-to-head on Zyphe vs. Sumsub, the breach context in is KYC safe in 2026?, and the procurement framework in our top compliance tools evaluation.

What does an integration look like for a KYC for iGaming deployment?

Most operators go live in one to two weeks. The fastest path is the no-code verification link with one of our preset KYC for iGaming policies, configurable in about 15 minutes. Engineering teams integrate over the HTTP API with signed webhook callbacks, using the browser and Node packages; mobile apps open the hosted flow in a WebView, because capture and liveness stay on Zyphe’s side rather than shipping in your binary. Shared-policy mode lets you run multiple brands or multiple states on the same player base without duplicating configuration.

curl -X POST "https://api.zyphe.com/sdk/flow/$ZYPHE_FLOW_ID/vr/create?sandbox=false" \
-H "x-api-key: $ZYPHE_SECRET_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "email": "player@example.com",
  "customData": { "playerReference": "player_42", "state": "NJ", "vertical": "sportsbook" }
}'

# The response carries the session id, token and access signature.
# Compose the hosted URL and open it for the player:
# https://verify.zyphe.com/flow/<flowSlug>?zypheVr=...&zypheToken=...&zypheAccessSig=...

For pricing by verification volume, see pricing. For the technical walkthrough, how it works.

How do you integrate KYC for iGaming with Zyphe across multiple verticals?

A multi-vertical operator goes from vendor selection to a live, regulator-ready verification across every product in five steps. The sequence below assumes a sportsbook plus DFS plus casino plus lottery footprint with US multi-state exposure.

  1. Inventory verticals, jurisdictions, and registries. List every product (sportsbook, DFS, casino, lottery, poker), every US state and EU licence (NJ, NY, MI, PA, MGA, UKGC, AGCO), and every self-exclusion register that applies (GAMSTOP, Spelpaus, Coalition for Fantasy Sports plus idPair).
  2. Configure one base policy plus per-vertical and per-state overlays. Set the underlying KYC for iGaming checks once (age, identity, address, sanctions, source of funds), then layer overlays for the 21+ Iowa DFS threshold, the 18+ California DFS threshold, the EDD trigger for VIP casino, and the deposit-limit defaults each state expects.
  3. Turn on Zyphe geolocation so location sits with identity. The step checks GPS against the IP country, flags VPN or proxy use, checks the IP against the blacklist, and stores the result in Zyphe next to the KYC record. GAMSTOP, Spelpaus and Coalition for Fantasy Sports plus idPair are called by Zyphe at signup, at deposit and on configurable triggers.
  4. Issue the KYC Passport so the same player clears every vertical. Once verified, the player holds a portable, user-controlled credential that your sportsbook, DFS, casino, and lottery surfaces all read on the next deposit. No re-upload, no parallel pipeline per product, audit trail unified.
  5. Turn on perpetual monitoring and in-play re-validation. Enable continuous sanctions, PEP, and self-exclusion re-screening at the credential layer, plus passkey re-validation for in-play and live wagering so a self-exclusion is caught at the wager rather than at the next periodic review.
  6. Run an audit-export drill before go-live. Pull a representative case file end-to-end (signup, geo result, deposit, in-play re-validation, self-exclusion event) and confirm the evidence chain is reconstructable in under an hour for UKGC, MGA, AGCO, or US state-regulator inspection.

What’s the best KYC for iGaming software in 2026?

For multi-vertical iGaming operators and US sportsbooks, Zyphe is the best KYC for iGaming software because it verifies once, reuses the same player record across every vertical and every state, runs perpetual monitoring at the credential layer, and stores zero documents. Onboarding goes from weeks of vendor selection to a 15-minute no-code policy. The audit trail satisfies UKGC, MGA, AGCO, and US state regulators without your team rebuilding KYC for iGaming pipelines from scratch.

This page was reviewed against the sources cited below on 18 September 2026.

Stop building a separate KYC for iGaming pipeline for every vertical and every state.

If you run sportsbook, DFS, and casino on the same player, or if you're standing up KYC for iGaming across a dozen US states with different rules, you already know the cost. Book a 30-minute walkthrough and we'll run a real verification on a multi-vertical policy, show the audit trail, and price it against your current vendor.

Frequently asked questions

KYC for iGaming requires identity, age, address verification, sanctions and PEP screening, source-of-funds review for higher-stakes players, self-exclusion register checks (GAMSTOP, Spelpaus, Coalition for Fantasy Sports plus idPair), geolocation for US sportsbook, and ongoing CDD. UKGC, MGA, AGCO, and US state regulators each layer specific technical standards on top of the AML baseline.

One verified player record. Sportsbook, DFS, casino, lottery, and poker each apply their own policy on top: age threshold, EDD trigger, jurisdiction-specific self-exclusion list. The underlying identity is the same record. No duplicate uploads and no parallel pipelines.

Yes. We ship preset policies for the major US sports-betting regimes (NJ, NY, PA, IL, MI, AZ, MA, OH, NC, VA, and more) and integrate with GeoComply for real-time geolocation. The same player record clears every state your operation runs in, with the policy overlay applied per state and logged in the audit trail.

The KYC Passport carries the player's verified date of birth. The policy layer applies the right threshold per jurisdiction: 18 in most states, 19 in Nebraska and Alabama, 21 in Arizona, Iowa, Louisiana, and Massachusetts. A failure on one state's threshold is logged without exposing the underlying document.

A first verification completes in the time it takes the player to capture a document and a selfie; for a returning player with a KYC Passport, re-validation against geolocation, sanctions, and self-exclusion runs via passkey without a new capture. That is fast enough to catch a self-exclusion at the wager rather than at the next periodic review.

Perpetual KYC for iGaming at the credential layer means continuous sanctions, PEP, and self-exclusion re-screening rather than periodic review. The Flutter Paddy Power £2 million fine in December 2025 was anchored on failure to identify problem gamblers fast enough; perpetual monitoring closes that gap. Behavioural-pattern signals at the operator layer feed into a real-time risk-tier update.

Yes. GAMSTOP ([participation is required by social responsibility code 3.5.5](https://www.gamblingcommission.gov.uk/licensees-and-businesses/lccp/condition/3-5-5-remote-multi-operator-sr-code)) and [Spelpaus](https://www.spelinspektionen.se/lagar-regler/spelansvar-och-konsumentskydd/spelpaus.se), which is checked at registration and at every login, are integrated by default. The Coalition for Fantasy Sports' partnership with [idPair](https://coalitionforfantasysports.com/idpair) is supported through the same policy layer. For state-specific registries where the data feed is less mature, your team can add or swap checks from the dashboard without a code release.

There's nothing reconstructable to leak. Documents and biometrics are processed transiently and stored encrypted in the player's own vault, with the player holding the key. The operator keeps verification results, audit logs and proofs, not a database of passports. Audit access uses threshold encryption that requires explicit player and authority co-sign.

No to both. KYC for iGaming at signup and ongoing CDD are different from real-time transaction monitoring (pair with Zyphe AML software) and different from physical-presence geolocation (continue running GeoComply if your licence requires that vendor). Zyphe ships its own geolocation step, checking GPS against the IP country, flagging VPN and proxy use and screening the IP against a blacklist, and that result is stored in Zyphe on the same audit trail as the identity evidence. Zyphe does not ingest GeoComply payloads.

Online gambling verification is the set of checks a licensed operator runs before and during play: identity and age from a government document with liveness, address, sanctions and PEP screening, self-exclusion register checks, geolocation where the licence is state-bound, and affordability or source of funds review as risk rises. Regulators require identity and age to be confirmed before the first deposit or bet.

Three checks have no fintech equivalent: age against a jurisdiction-specific threshold that can be 18, 19 or 21, self-exclusion against national or state registers such as GAMSTOP and Spelpaus, and affordability checks tied to net deposits. Gambling also verifies before the first transaction rather than within a grace period, and re-verifies the same player across brands and verticals far more often.

Document verification with liveness and injection detection, a date of birth read from the document rather than typed, configurable age thresholds per market, sanctions and PEP screening, integrated self-exclusion register checks, a policy layer that applies each licence's rules on one player record, an audit trail with the policy version, and a data model that does not leave identity documents on the operator's servers.