Learn more about the latest security and privacy threats
Back

KYC for Online Casinos in 2026: MGA, UKGC, AGCO and ADM Requirements Compared

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published August 21, 2026 Updated August 21, 2026
Identity document with portrait and NFC chip representing KYC and age verification for online casinos

Online casino KYC across MGA, UKGC, AGCO and ADM sets four different bars. See what each regulator requires and where operators lose deposits at onboarding.

Table of contents
  • In August 2022 the UK Gambling Commission ordered Entain to pay £17 million, then its largest enforcement outcome, for anti-money-laundering and social-responsibility failures, including letting a customer deposit £742,000 in 14 months without source-of-funds checks.
  • KYC for online casino operators is governed by four reference regulators with four different bars: the Malta Gaming Authority, the UK Gambling Commission, Ontario's AGCO, and Italy's ADM.
  • Age thresholds differ: 18 in the UK, Malta, and Italy, but 19 in Ontario, which a single customer base has to handle.
  • Source-of-funds triggers diverge: the UKGC's high-risk customer framework, the MGA's player-protection and affordability expectations, and Italy's ADM regime each demand different evidence.
  • Self-exclusion is fragmented across GAMSTOP, the MGA register, and iGaming Ontario, and reusable identity is the cleanest way to honour bans across brands and jurisdictions.
  • Operators lose real money at the verification step, where document-upload friction drives deposit abandonment, so the onboarding design is a revenue issue, not just a compliance one.

KYC for online casino operators is the regulated process of verifying a player's identity, age, and source of funds before and during play, to meet anti-money-laundering and player-protection obligations. The Malta Gaming Authority, UK Gambling Commission, Ontario's AGCO, and Italy's ADM each set their own identity, age, and affordability requirements.

TL;DR

KYC for online casino operators is not one standard but four, and the gap between them is where fines happen. In August 2022 the UK Gambling Commission ordered Entain to pay £17 million for anti-money-laundering and source-of-funds failures, including a customer who deposited £742,000 in 14 months without proper checks. That is the cost of getting the verification layer wrong.

The four regulators that set the global tone, the Malta Gaming Authority, the UK Gambling Commission, Ontario's AGCO, and Italy's ADM, each define age limits, source-of-funds triggers, and self-exclusion differently. This guide compares them jurisdiction by jurisdiction, shows where operators lose deposits at the verification step, and explains how reusable identity lets a single customer base satisfy several regulators at once without re-verifying the same player over and over.

12 min read. Last updated 21 August 2026.

What KYC do online casinos need in 2026?

At minimum, an online casino has to verify who the player is, confirm they are old enough to gamble, check them against sanctions and politically exposed person lists, assess and monitor source of funds for higher-risk customers, and honour self-exclusion. That much is common across licences. The complexity is that each regulator specifies the thresholds, evidence, and timing differently, so KYC for online casino operators is really a set of overlapping regimes rather than one checklist.

The stakes are concrete. Gambling regulators have escalated enforcement, and source-of-funds and AML failures are the most common cause, as the Entain case shows. The job of KYC for online casino operators, then, is not just to verify a player but to verify them to the standard of every licence you hold, and to prove it later. For the underlying mechanics, our identity verification software comparison covers the platform layer beneath these gambling-specific rules.

How do MGA, UKGC, AGCO and ADM differ on KYC?

Four regulators set the reference standards that most casino compliance teams design around, and they diverge on the details that matter.

RegulatorJurisdictionGambling ageKYC emphasisSelf-exclusion
MGAMalta18Player protection, affordability, ongoing monitoringMGA self-exclusion
UKGCUnited Kingdom18Identity before play, high-risk customer source-of-funds, social responsibilityGAMSTOP
AGCO / iGaming OntarioOntario, Canada19Registrant standards, responsible gambling, player verificationiGaming Ontario self-exclusion
ADMItaly18Licensed remote gaming, advertising limits under the Decreto DignitàNational self-exclusion

The headline divergences: Ontario sets the gambling age at 19 while the others use 18; the UK requires identity verification before a customer can gamble or deposit and applies an explicit high-risk customer framework; Malta emphasises affordability and player-protection monitoring; and Italy layers strict advertising constraints from the Decreto Dignità on top of its licensing regime. A control that satisfies one regulator can leave a gap under another, which is why a single global KYC policy rarely passes all four.

What are the age verification rules across these jurisdictions?

Age is the simplest rule to state and a surprisingly common failure. The threshold is 18 in the UK, Malta, and Italy, and 19 in Ontario. For an operator running one platform across these markets, that single-year difference means age logic cannot be hard-coded once; it has to be jurisdiction-aware, so an 18-year-old verified for the UK is not waved into Ontario.

The document set also varies in practice, from government ID and proof of address to chip-verified documents, and the UK's expectation that identity is confirmed before play raises the bar on doing this fast at onboarding. Reliable age verification therefore depends on robust identity verification rather than a self-declared date of birth, which is where chip reads and liveness checks matter, as covered in our proof of address verification guide.

When do source-of-funds checks trigger?

Source-of-funds is where the largest fines cluster, and each regulator frames the trigger differently. The UK Gambling Commission expects operators to identify high-risk customers and obtain source-of-funds evidence proportionate to risk, and its enforcement has repeatedly punished firms that let large deposits flow without checks, the Entain £742,000 example being the cautionary one. Malta's MGA emphasises affordability and player-protection monitoring, expecting operators to act on signs that play exceeds a customer's means. Italy's ADM operates within its licensing and advertising framework, with its own customer-diligence expectations.

The practical rule is to treat source of funds as an ongoing, risk-based obligation, not a one-time onboarding box. A customer who was low-risk at sign-up can become high-risk through deposit velocity, and the regulator will ask what you did when the pattern changed. That is the perpetual KYC principle applied to gambling: keep the assessment live.

How do you honour self-exclusion across jurisdictions?

Self-exclusion is both a player-protection duty and an operational headache, because the registers are fragmented. The UK runs GAMSTOP, Malta operates its own self-exclusion register, and Ontario has the iGaming Ontario self-exclusion scheme. A player excluded in one scheme is not automatically blocked in another, and an operator with brands across jurisdictions has to honour each relevant ban.

This is exactly where reusable identity earns its place. If a verified player carries a portable, reusable credential rather than a fresh account at every brand, an operator can reliably recognise a returning or self-excluded individual across its estate instead of relying on re-entered details that a determined player can vary. Wiring identity to self-exclusion checks across brands and jurisdictions turns a fragmented obligation into a single, enforceable control, which is one reason decentralised, reusable KYC suits multi-brand gambling groups.

Where do casino operators lose deposits at onboarding?

For KYC for online casino operators, the verification step is a revenue leak as much as a compliance gate. When a player has to leave the deposit flow to photograph documents, re-upload after a failed capture, or wait for manual review, a meaningful share abandon, and industry research, including Sumsub's State of Identity Fraud reporting, has highlighted significant drop-off at gambling onboarding. Every abandoned verification is a deposit the operator never receives.

The fix is not weaker KYC, it is faster, higher-completion KYC: chip reads instead of blurry photo uploads, passive then active liveness instead of repeated selfies, and reusable credentials so a returning or cross-brand player does not re-verify from scratch. Done well, the strongest compliance posture and the highest deposit-conversion rate are the same design, not a trade-off, a point our identity verification software comparison and work on why your KYC vendor is your biggest data breach risk both reinforce.

What audit pack does each regulator inspect?

When a gambling regulator reviews an operator, it wants to reconstruct decisions, not just see a policy. Across the MGA, UKGC, AGCO, and ADM the common audit expectations are: a documented AML and risk assessment, evidence that identity and age were verified before play where required, source-of-funds records for higher-risk customers with the rationale for the threshold applied, self-exclusion checks and their outcomes, and an audit trail showing what changed when a customer's risk profile shifted.

The operators that survive examination are the ones who can produce, per customer, what was checked, when, and why. Build the onboarding and monitoring stack so that record assembles itself, and the audit pack stops being a fire drill. KYC for online casino compliance, in the end, is judged on the defensibility of that trail.

The bottom line

KYC for online casino operators is four standards wearing one name. The Malta Gaming Authority, the UK Gambling Commission, Ontario's AGCO, and Italy's ADM each set their own age, source-of-funds, and self-exclusion bars, and the gap between them is exactly where the largest fines land. Entain's £17 million is the reminder that source-of-funds failures, not exotic schemes, drive enforcement.

Design onboarding to be jurisdiction-aware, treat source of funds as a live obligation, wire reusable identity to self-exclusion across brands, and make the audit trail assemble itself. Do that and the strongest compliance posture is also the one that loses the fewest deposits at the cage.

Get a casino-specific compliance assessment, or see how it works.

Cited sources

  • UK Gambling Commission, Entain enforcement action (August 2022): https://www.gamblingcommission.gov.uk/news
  • Malta Gaming Authority: https://www.mga.org.mt/
  • Alcohol and Gaming Commission of Ontario (AGCO) and iGaming Ontario: https://www.agco.ca/
  • Agenzia delle Dogane e dei Monopoli (ADM), Italy: https://www.adm.gov.it/
  • GAMSTOP, UK national self-exclusion: https://www.gamstop.co.uk/
Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

The UK Gambling Commission expects operators to apply enhanced due diligence to higher-risk customers, identified through factors like deposit size and velocity, and to obtain source-of-funds evidence proportionate to that risk. Enforcement has repeatedly targeted firms that allowed large cumulative deposits without checks, so the practical trigger is any customer whose activity outpaces what their known profile would support.

Reusing a verified identity across brands can reduce friction, but each licence still has its own requirements, so a Malta verification does not automatically satisfy the UK or Ontario. Reusable credentials help an operator recognise a returning player and avoid re-collecting documents, while the operator must still confirm the specific checks each regulator demands. Treat reuse as efficiency, not as a regulatory shortcut.

Ontario's AGCO and iGaming Ontario framework expects registrants to maintain player verification and responsible-gambling controls, and to re-verify where information is out of date, risk changes, or integrity of the original check is in doubt. As with other regulators, re-verification is risk-based and event-driven rather than a fixed calendar, so material changes in a player's profile or behaviour are the trigger.

Italy sets the gambling age at 18, like the UK and Malta, but its regime is distinctive for the advertising and sponsorship restrictions introduced by the Decreto Dignità, which constrain how operators can market. For KYC that means strong age and identity verification at onboarding combined with marketing-side controls, so the compliance surface in Italy extends beyond the verification flow into how players are acquired.

No single rule mandates a specific biometric method across all four regulators, but the expectation that identity is genuinely verified, especially before play in the UK, makes liveness the practical standard for defeating impersonation and spoofing. Two-step liveness, passive detection plus an active check, gives a stronger, more defensible result than a static selfie, which matters when a regulator questions whether a verification was real.

It is 18 in the UK, Malta, and Italy, and 19 in Ontario. For an operator running one platform across these markets, age logic must be jurisdiction-aware so a player eligible in one market is not admitted in another with a higher threshold. Reliable age verification depends on verified identity documents rather than a self-declared date of birth.

Reusable credentials let a verified player be recognised across brands and jurisdictions without re-uploading documents, which reduces onboarding abandonment and, critically, makes self-exclusion enforceable across the estate. Instead of a determined player opening a fresh account at a sister brand, a portable credential ties them to a known identity, turning fragmented self-exclusion registers into a control the operator can actually apply.

Source-of-funds and AML control failures dominate gambling enforcement, typically where operators allowed large or rapid deposits without proportionate checks, failed to act on affordability signals, or could not evidence their decisions. The Entain £17 million outcome is emblematic. The lesson is that source of funds is an ongoing, risk-based obligation, and the ability to prove what you did is as important as the check itself.

See why teams switch to Zyphe

Privacy-first KYC that verifies identity without holding your customers' PII — reusable credentials, usage-based pricing, no central honeypot.

Book a demo