Almost every operator we work with arrives with an AML policy already in hand: usually a template, sometimes drafted by a previous advisor. In most cases, it isn't the problem. The problem is that the policy describes a business that doesn't quite match the one being licensed.
Here's what a regulator's AML reviewer is actually checking, roughly in the order they check it.
Does the risk assessment match the actual product?
A sportsbook, a live casino and a peer-to-peer poker room carry different money laundering risk profiles. A generic policy that doesn't reflect the specific product, payment methods and player geography in front of the reviewer is usually the first thing that gets flagged.
Is the MLRO appointment real, or a name on a page?
Regulators increasingly ask direct questions about the Money Laundering Reporting Officer: their experience, their authority to act independently of the business, and whether they'd actually have the access needed to do the job. An MLRO listed only to satisfy a checkbox is easy to spot in an interview.
Do the transaction monitoring thresholds make sense for the volumes involved?
Thresholds copied from a template rarely map cleanly onto a specific operator's expected transaction sizes and frequency. Reviewers look for evidence that the thresholds were actually calibrated: not just inherited.
Is there a real escalation path, not just a flowchart?
A policy document can describe an escalation process perfectly and still fail in practice if there's no clear owner, no defined timeframe, and no record-keeping requirement attached to it. Regulators ask for examples, not just diagrams.
Does the business understand its own reporting obligations?
Suspicious activity reporting requirements differ by jurisdiction, and by product type within a jurisdiction. Confusion here: even innocent confusion: is read as a sign that the compliance framework hasn't been operationalised yet.
None of this requires an unusually large compliance team. It requires a policy suite that was actually built around the business being licensed, reviewed by someone who understands both the product and the regulator's expectations. That's the gap we're usually closing when we take over AML documentation mid-application.
Related: Compliance & AML, banking & payments, and choosing your first iGaming licence.
