The Financial Action Task Force's 2023–2024 mutual evaluation cycle produced some of the most candid assessments of AML framework effectiveness seen in over a decade. The pattern across jurisdictions was consistent: technical compliance was common; effective implementation was rare. Policies existed. Risk assessments had been conducted. Transaction monitoring was in place. But the systems were not working in the way their architects intended — and regulators knew it.
For regulated industries heading into 2026, the question is no longer whether an AML framework exists. It is whether the framework actually reduces the probability of money laundering, is capable of detecting it when it occurs, and can demonstrate both of those things to a regulator who is no longer satisfied with documentation alone.
FATF Updates: What Actually Matters in Practice
FATF's fourth-round mutual evaluations introduced a dual assessment methodology that scores both technical compliance (does the legal and regulatory framework exist?) and effectiveness (does it actually work?). The shift matters because it changes what regulators look for during inspections — and what they expect to find documented in supervised firms.
The immediate practical implications for regulated businesses include:
- Immediate outcomes focus: FATF's eleven immediate outcomes are now the lens through which national regulators assess their supervisory approach. Firms operating in jurisdictions that received poor effectiveness ratings on specific outcomes should expect intensified scrutiny in those areas.
- Proliferation financing: FATF's expanded focus on proliferation financing — the financing of weapons of mass destruction programmes — has moved from a niche concern to a standard risk assessment requirement. Regulated firms need to demonstrate that their risk assessment addresses proliferation financing as a distinct typology, not just as a subset of sanctions compliance.
- Beneficial ownership quality: FATF's push for meaningful beneficial ownership data has shifted from encouraging registers to demanding that data in those registers is accurate, verified, and actually used by regulated firms in their CDD processes. Accepting Companies House data uncritically is no longer adequate where ownership structures are complex or jurisdictions involved have verification quality concerns.
Beneficial Ownership: Beyond Register Checks
The gap between beneficial ownership register data and beneficial ownership reality has been well documented. Nominee directors, layered corporate structures, discretionary trust arrangements, and jurisdictions with weak verification requirements all create conditions where the registered beneficial owner is not the actual controller of funds.
For regulated firms, the obligation to identify the beneficial owner is not discharged by checking a register and accepting the result. Where the corporate structure is complex, where the jurisdiction of incorporation has known beneficial ownership transparency concerns, or where there is any inconsistency between the presented ownership structure and other risk signals, additional verification is required. This is not new law — it is existing CDD obligation applied to a reality that register-dependent processes routinely fail to capture.
"A beneficial ownership register tells you who someone says owns the company. Your obligation is to form a reasonable belief about who actually does. In complex structures, those are often different answers."
Practical approaches to meaningful beneficial ownership verification include:
- Corporate structure mapping using multiple independent sources, not single-register lookups
- Source of control analysis — who gives the instructions, not just who has the share certificate
- Jurisdiction risk weighting for ownership chains that pass through high-risk or low-transparency jurisdictions
- Consistency checking between declared ownership and actual fund flows
Virtual Asset Service Providers: The Compliance Overlap
The FATF Travel Rule, requiring VASPs to pass originator and beneficiary information with virtual asset transfers above threshold, is now law in most major jurisdictions. For regulated businesses that accept funds from or transact with VASPs — including gaming operators who accept crypto payments or whose high-value customers hold significant crypto wealth — this creates obligations that many have not yet fully integrated into their AML frameworks.
The specific risks that regulated non-VASP businesses need to manage in relation to virtual assets include:
- Source of wealth from crypto: A customer who declares crypto holdings as a source of wealth requires a different verification approach from a customer declaring earned income or business revenue. Blockchain analytics, exchange account verification, and consistency between declared holdings and transaction history are all relevant.
- VASP counterparty risk: Businesses that accept payments routed through VASPs need to assess the compliance standards of the VASP involved. A payment from a non-compliant or sanctioned VASP carries the risk of the underlying transaction regardless of the intermediary layer.
- Mixing and obfuscation indicators: Funds routed through mixing services, privacy coins, or multi-hop wallet chains before reaching a regulated business are a red flag that standard transaction monitoring is not calibrated to detect without specific rule configuration.
Most legacy transaction monitoring systems were designed for fiat bank transfer patterns. They are not configured to assess crypto-origin fund flows, chain-hop patterns, or VASP counterparty risk. If your system does not have dedicated crypto risk rules, you have a monitoring gap that a regulator will identify.
Risk-Based Approach Maturity: Moving Beyond Tick-Box
The risk-based approach has been the foundation of AML frameworks since FATF Recommendation 1 established it as the central methodology. In practice, many organisations have implemented a form of the risk-based approach that satisfies the documentation requirement without achieving the underlying purpose.
A genuinely mature risk-based approach has specific characteristics that distinguish it from checkbox compliance:
Source of Funds vs Source of Wealth: The Distinction That Matters
The conflation of source of funds and source of wealth is one of the most persistent practical errors in casino and high-value dealer CDD processes. They are different questions, they require different evidence, and confusing them creates compliance gaps that regulators consistently identify.
Source of funds is the answer to: where did the specific money used in this transaction come from? It is a question about the immediate provenance of the funds being deposited, wagered, or transferred. The answer should be specific and verifiable: salary payment from a named employer, dividend from a named company, property sale proceeds from a named transaction.
Source of wealth is the answer to: how did this person accumulate their overall wealth? It is a question about the origin of the total wealth base that funds the customer relationship. The answer requires understanding of career history, business interests, inheritance, or investment activity over time — and for high-value customers, that understanding needs to be supported by evidence, not just declaration.
For gaming operators with high-value customers, both questions are relevant and neither substitutes for the other. A customer who can demonstrate that their stake came from a specific bank transfer has answered the source of funds question. They have not answered the source of wealth question. In an enhanced due diligence context, both need answers.
Casino-Specific AML Obligations: The 2026 Landscape
Gaming operators face AML obligations that are both general (applying to all regulated sectors) and sector-specific (reflecting the particular vulnerabilities of the casino environment). The sector-specific obligations — cash transaction reporting thresholds, chip purchase monitoring, suspicious activity in play — sit alongside the general framework and create an overlapping compliance requirement that is not always well-integrated in operational practice.
The areas where casino AML frameworks most commonly fall short in regulatory inspection:
- Transaction monitoring that covers cage transactions but not in-play patterns or chip redemption sequences
- CDD trigger calibration that relies on single-session thresholds rather than cumulative relationship values
- SAR decision-making that is inconsistent across shifts and not documented at the point of decision
- Third-party payment controls that do not address the risk of chip purchase by a third party for the benefit of a player subject to EDD
- Risk appetite statements that have not been reviewed since initial framework development and do not reflect the current customer base or product mix
AML framework review and gap analysis
Wise Key Solutions conducts structured AML framework reviews for regulated businesses, identifying gaps against current regulatory expectations and producing prioritised remediation recommendations. Contact us to discuss your requirements.
Speak to our team →This article reflects the operational perspective of the Wise Key Solutions founding team, drawing on experience across regulated industries in the UK and Europe. It does not constitute legal or regulatory advice. Operators should assess their specific obligations with qualified legal counsel.