iGaming Payment Compliance
Payment compliance isn't optional. Regulators increasingly enforce through payment processing requirements: gross deposit limits (UK RTS 12, live September 30, 2026), credit card bans, mandatory KYC before deposit, frictionless affordability, and on the crypto side the FATF Travel Rule plus the GENIUS Act for US stablecoin acceptance. PSD3 and PSR reshape liability across the EU rail. 9 jurisdictions covered with interactive compliance finder.
- $184.4M
- Fines in 2024
- 9
- Jurisdictions covered
- 7
- Credit card bans
- 4
- Compliance layers
Compliance Finder
Click your target market to see what's required. No other page in the search results provides this.
Select your target market to see payment compliance requirements:
Click a market above to see its compliance requirements
The Four Compliance Layers
Universal
PCI DSS, data protection. Applies everywhere.
License-Specific
Your gambling license rules (MGA, UKGC, Curaçao).
Jurisdiction-Specific
Where your PLAYERS are. Deposit limits, method bans, KYC timing.
Provider-Specific
Your PSP adds their own KYC, reserves, country restrictions.
Key: You follow the rules of your license AND the jurisdiction of each player. An MGA-licensed operator with UK players must comply with both.
PCI DSS Compliance
Which Level Do You Need?
- Level 1
- Transactions
- > 6 million/yr
- Requirements
- On-site QSA audit, annual ROC
- Level 2
- Transactions
- 1‑6 million/yr
- Requirements
- Annual SAQ, quarterly scan
- Level 3
- Transactions
- 20K-1M/yr
- Requirements
- Annual SAQ, quarterly scan
- Level 4
- Transactions
- < 20,000/yr
- Requirements
- Annual SAQ (self-assessment)
SAQ Types. What Applies to You
All card data handled by PSP (hosted page)
Recommended for most operators
Your website impacts transaction security
You store/process card data yourself
KYC and AML Requirements
Use the Compliance Finder above to see KYC timing for your specific market. Below: Enhanced Due Diligence triggers that apply everywhere.
Enhanced Due Diligence Triggers
Credit Card Ban Wave
The trend is expanding. UK started it in 2020. More jurisdictions are following.
Full ban (enacted June 2019)
First major market to follow
Credit ban in force June 2024
From market opening, Jan 2025
More jurisdictions expected
What This Means for Operators
Technical: BIN-level blocking
Credit card BINs have specific ranges. Your PSP can filter them per jurisdiction. Must be implemented per country. UK debit OK, UK credit blocked.
Commercial: offer alternatives
Players whose credit cards are blocked need another way to deposit. Open Banking, e-wallets, and debit cards fill the gap.
Strategic: prepare now
If you operate in markets where credit cards are still allowed, build the blocking capability anyway. The ban is coming to your market.
Responsible Gambling Payment Controls
- Self-imposed deposit limits
- Description
- Player sets daily/weekly/monthly
- Mandatory Where
- MGA, UKGC, Sweden, Netherlands
- Regulatory deposit cap
- Description
- Government-mandated maximum
- Mandatory Where
- Germany (€1,000/month)
- Limit decrease
- Description
- Takes effect immediately
- Mandatory Where
- UKGC, MGA
- Limit increase delay
- Description
- 24h (UKGC) to 7 days (MGA)
- Mandatory Where
- UKGC, MGA
- Self-exclusion register
- Description
- GAMSTOP, Spelpaus, CRUKS, OASIS
- Mandatory Where
- All regulated markets
- Reality check timer
- Description
- Reminder of time/money spent
- Mandatory Where
- UKGC (60 min)
- Affordability assessment
- Description
- Financial vulnerability check
- Mandatory Where
- UK (£150/30d net deposits)
Your Responsibility vs Your PSP's
Your Responsibility
Even if your PSP provides tools, the liability is yours.
Provider Handles
Using a PSP does NOT transfer your regulatory obligations.
Payment Compliance Checklist
Universal
KYC / AML
Responsible Gambling
Jurisdiction-Specific
Provider Compliance Capabilities
Using a PSP does NOT transfer regulatory obligations. But some providers make compliance easier than others.
7 Payment Compliance Mistakes That Lead to Fines
KYC at withdrawal only in UK
Not blocking credit cards in banned jurisdictions
Deposit limits not enforced cross-platform (Germany)
SAR not filed or filed late
Inadequate affordability checks (UK)
No audit trail on payment decisions
Non-compliant crypto processor in EU
iGaming Payment Compliance News
All 17 updates- Licensing
Vpag's e-money layer runs through a Lithuanian EMI with two AML fines
Vpag discloses that e-money and payment instruments are issued to operators by Era Finance Ltd as a registered agent of Pervesk UAB, a Lithuanian institution authorized by the Bank of Lithuania under code LB000426. That register records two enforcement measures against Pervesk: a warning with a EUR 244,000 fine on September 19, 2018, and a EUR 130,000 fine on August 26, 2025, for money laundering prevention breaches. Vpag also states the brand is a trademark of an Irish company, Monee Ltd.
Bank of Lithuania register, Pervesk UAB · Vpag site disclosure
- Licensing
Volt's Australian payouts run on Flexewallet's license, with funds held at Cuscal
Volt Connect Pty Ltd, ACN 662 145 708, issues its Australian Payout Initiation product as authorized representative 001309428 under Flexewallet Pty Ltd, AFSL 448066, not on a license of its own. Product funds sit in segregated accounts at Cuscal Limited, and the product disclosure statement, current as at August 27, 2024, warns that a balance is not protected by the Financial Claims Scheme if Cuscal fails. The counterparty chain for Australian payouts is three deep.
Volt Australia product disclosure statement · Volt Australia financial services guide · Volt regulatory disclosure
- Licensing
Payper and Gigadat are still RPAA applicants, Paramount Commerce is registered
The Bank of Canada's applicant list carries Gigadat Inc, which applied November 1, 2024, and Payper Inc., which applied November 7, 2024. Neither has a registration date. Element Financial Technology Inc, trading as Paramount Commerce, was registered October 10, 2025, the same day as Interac Corp. Registration under the Retail Payment Activities Act is required of every payment service provider in scope.
Bank of Canada, list of applicants · Bank of Canada, registry of payment service providers
FAQ
Most operators fall under Level 3 or 4. If you use a hosted payment page from your PSP, you need SAQ-A, the shortest questionnaire: 31 questions under v4.0.1, and just 6 when payment is fully outsourced. Don't store card data on your servers.
UK, Germany, Sweden, Netherlands, US, Brazil: before first deposit. Malta (MGA): before first withdrawal but tightening. The trend is pre-deposit verification everywhere.
UK (2020), Australia (June 2024), Brazil (January 2025), Belgium (2019), and US states like Iowa, Tennessee and Massachusetts ban credit cards for online betting. Germany limits via the €1K cap. Expect more jurisdictions to follow.
Ranges from warning to license revocation. Fines reach millions. Your PSP may also terminate your account independently.
Small: part of general compliance role. Medium+: dedicated payment compliance or MLRO recommended. UKGC and MGA require designated MLRO.
PSP handles PCI DSS, 3DS, basic fraud. You handle KYC, AML, SAR filing, deposit limits, self-exclusion, affordability, audit docs. Using a PSP doesn't transfer liability.
Crypto processors serving EU clients need CASP authorization under MiCA. The transitional period ended July 1, 2026, so a processor without a CASP license can no longer lawfully serve EU clients. If yours isn't authorized, you carry the risk.
Find Compliant Providers
Compare provider compliance capabilities across 79 iGaming payment processors.