Compliance Finder
Click your target market to see what's required. No other page in the search results provides this.
Select your target market to see payment compliance requirements:
Click a market above to see its compliance requirements
The Four Compliance Layers
PCI DSS, data protection. Applies everywhere.
Your gambling license rules (MGA, UKGC, Curaçao).
Where your PLAYERS are. Deposit limits, method bans, KYC timing.
Your PSP adds their own KYC, reserves, country restrictions.
Key: You follow the rules of your license AND the jurisdiction of each player. An MGA-licensed operator with UK players must comply with both.
PCI DSS Compliance
Which Level Do You Need?
| Level | Transactions | Requirements |
|---|---|---|
| Level 1 | > 6 million/yr | On-site QSA audit, annual ROC |
| Level 2 | 1-6 million/yr | Annual SAQ, quarterly scan |
| Level 3 | 20K-1M/yr | Annual SAQ, quarterly scan |
| Level 4 | < 20,000/yr | Annual SAQ (self-assessment) |
SAQ Types. What Applies to You
All card data handled by PSP (hosted page)
Recommended for most operators
Your website impacts transaction security
You store/process card data yourself
KYC and AML Requirements
Use the Compliance Finder above to see KYC timing for your specific market. Below: Enhanced Due Diligence triggers that apply everywhere.
Enhanced Due Diligence Triggers
Credit Card Ban Wave
The trend is expanding. UK started it in 2020. More jurisdictions are following.
First major market
Credit + debit limits
Full ban
April 2026
3-5 jurisdictions expected
What This Means for Operators
Technical: BIN-level blocking
Credit card BINs have specific ranges. Your PSP can filter them per jurisdiction. Must be implemented per country. UK debit OK, UK credit blocked.
Commercial: offer alternatives
Players whose credit cards are blocked need another way to deposit. Open Banking, e-wallets, and debit cards fill the gap.
Strategic: prepare now
If you operate in markets where credit cards are still allowed. build the blocking capability anyway. The ban is coming to your market.
Responsible Gambling Payment Controls
| Control | Description | Mandatory Where |
|---|---|---|
| Self-imposed deposit limits | Player sets daily/weekly/monthly | MGA, UKGC, Sweden, Netherlands |
| Regulatory deposit cap | Government-mandated maximum | Germany (€1,000/month) |
| Limit decrease | Takes effect immediately | UKGC, MGA |
| Limit increase delay | 24h (UKGC) to 7 days (MGA) | UKGC, MGA |
| Self-exclusion register | GAMSTOP, Spelpaus, CRUKS, OASIS | All regulated markets |
| Reality check timer | Reminder of time/money spent | UKGC (60 min) |
| Affordability assessment | Financial vulnerability check | UK (£125/mo net loss) |
Your Responsibility vs Your PSP's
Your Responsibility
Even if your PSP provides tools, the liability is yours.
Provider Handles
Using a PSP does NOT transfer your regulatory obligations.
Payment Compliance Checklist
Universal
KYC / AML
Responsible Gambling
Jurisdiction-Specific
Provider Compliance Capabilities
Using a PSP does NOT transfer regulatory obligations. But some providers make compliance easier than others.
| Provider | KYC | AML | Resp. Gambling | CC Blocking |
|---|---|---|---|---|
| Advanced | Good | Good | Advanced | |
| Advanced | Advanced | Good | Advanced | |
| Good | Good | Good | Advanced | |
| Good | Basic | Good | — | |
| Basic | Good | Good | Advanced | |
| Good | Good | Basic | Advanced |
7 Payment Compliance Mistakes That Lead to Fines
KYC at withdrawal only in UK
Not blocking credit cards in banned jurisdictions
Deposit limits not enforced cross-platform (Germany)
SAR not filed or filed late
Inadequate affordability checks (UK)
No audit trail on payment decisions
Non-compliant crypto processor in EU
FAQ
Find Compliant Providers
Compare provider compliance capabilities across 20+ iGaming payment processors.