What a Money Laundering Reporting Officer Does Inside a Licensed Gambling Business
Every UK gambling operator must appoint someone to take the lead on spotting and reporting suspicious money, and the role carries real personal and criminal exposure.
Automated report. This article was drafted with AI assistance from the sources listed below, without a human writing step. Gambling News labels every article produced this way. A person is answerable for it: if something here is wrong, write to editor@gamblingnews.co.uk and we will correct it on the page and say what changed.
A named individual, not just a policy
UK gambling operators are required to have anti-money laundering (AML) controls built into how they run the business, but the law also insists on a specific person being accountable for making those controls work day to day. That person is the Money Laundering Reporting Officer, usually shortened to MLRO. The role exists because AML law recognises that policies on paper are worthless unless someone senior is personally responsible for judging borderline cases, deciding whether to file reports, and making sure staff actually follow procedure.
The requirement to appoint an MLRO comes from the Money Laundering Regulations, which apply to casinos specifically among gambling businesses, combined with the Gambling Commission’s own licence conditions, which extend similar expectations to other licensed activities where money laundering risk is judged significant. Exact scope and thresholds change from time to time, so operators should always check the current position with the Gambling Commission and HM Treasury rather than assume last year’s rules still apply.
Why gambling attracts this level of scrutiny
Gambling businesses handle large volumes of cash and electronic payments, offer a legitimate reason for money to move quickly in and out of an account, and in some formats allow funds to be paid in by one method and withdrawn by another. That combination is attractive to anyone trying to disguise the origin of criminal proceeds. It does not mean most customers are suspect. It means the sector is structurally exposed, which is why regulators expect a proportionate but genuinely functioning control system rather than a token compliance manual sitting unused in a drawer.
What the MLRO actually does
The MLRO sits at the centre of an operator’s AML system. Typical responsibilities include:
- Acting as the point of contact for staff who flag unusual customer behaviour, such as inconsistent spending patterns, reluctance to provide identity or source of funds information, or transactions that do not match a customer’s known profile.
- Deciding whether internal reports amount to genuine grounds for suspicion and, where they do, submitting a Suspicious Activity Report (SAR) to the National Crime Agency.
- Overseeing the operator’s business-wide risk assessment, which maps out where in the business model money laundering risk is highest, for example around particular payment methods, customer segments or product types.
- Making sure customer due diligence and enhanced due diligence are actually applied where required, rather than just described in a policy document.
- Reporting to the board or senior management on the effectiveness of controls, and escalating gaps or resourcing problems.
- Keeping records that demonstrate decisions were reasoned and timely, since regulators and law enforcement will look at the paper trail after the fact, not just the outcome.
The MLRO needs enough seniority and independence to say no to commercially attractive customers when the risk picture demands it. A reporting officer who can be overruled by sales or marketing on financial crime decisions is generally viewed as a governance failure.
Suspicious Activity Reports and the legal shield they provide
When an MLRO submits a SAR to the National Crime Agency, it does two things. It puts information into the hands of law enforcement about activity that might be linked to crime, and it can give the business a defence against a money laundering offence if it later transpires that funds were criminal in origin. Operators do not need certainty that money is dirty to justify a report; suspicion is a lower bar than proof. Getting the threshold right is one of the hardest parts of the job, because over-reporting swamps the system with low-value reports while under-reporting leaves genuine laundering unchallenged.
Training, testing and record-keeping
An MLRO is only as effective as the staff feeding information upward. Licence conditions expect frontline and compliance staff to receive regular AML training, refreshed periodically and tested for understanding, not simply delivered once at induction. Operators are also expected to keep records of customer due diligence, risk assessments and internal reports for a set retention period, so that a Gambling Commission audit or law enforcement inquiry can reconstruct what was known and when.
What happens when this goes wrong
Failures in AML controls are one of the most common reasons operators end up in regulatory settlements, alongside social responsibility failings. Typical findings include an MLRO who lacked independence, SARs that were filed too late, risk assessments that were generic rather than tailored to the actual business, and training records that could not be evidenced. Sanctions can include large financial penalties, licence conditions, and in serious cases suspension or revocation of the operating licence, on top of any separate criminal liability under proceeds of crime legislation for individuals involved.
Checking current requirements
Because the detail of what is required from an MLRO can be updated through Gambling Commission guidance, licence condition changes or amendments to the Money Laundering Regulations, operators and compliance professionals should treat this piece as background only and confirm the current, specific obligations directly with the regulator and government sources below before relying on them.

