FOR SALE: B2B Malta Gaming Licence (MGA) | issued in 2024 | valid for 10 years | active bank account | FOR SALE: B2C Malta Gaming Licence (MGA) | Type 1 Casino | active bank account | licence renewal July 2026 | FOR SALE: Curacao Gaming Licence (CGA) | Curacao entity | CY payment agent | active bank account |

Contact Us

Gaming Licence Compliance Checklist 2026

Ensure your gaming operations are legal with our Gaming Licence Compliance Checklist for a smooth approval process.

A gaming licence compliance checklist gives operators a structured way to track ongoing regulatory obligations after licence issuance. Most operators focus heavily on the application phase and underestimate the compliance burden that follows. Licence conditions from the Malta Gaming Authority (MGA), the Gaming Authority Curacao (GCA), and other regulators carry specific, enforceable requirements. Missing a reporting deadline, failing a compliance audit, or maintaining an outdated AML policy can lead to fines, suspension, or licence revocation.

This guide covers the core areas every licensed operator must manage: AML and KYC, responsible gambling, technical compliance, reporting, key personnel, and multi-jurisdiction obligations.

1. What a Gaming Licence Compliance Checklist Covers for Operators

Every regulator publishes licence conditions. Those conditions are not a one-time hurdle: they are ongoing obligations that run for the life of the licence. The specific contents of a gaming licence compliance checklist depend on which regulator issued the licence and what class of operation you hold.

For MGA-licensed B2C operators, the checklist includes AML policies, KYC procedures, responsible gambling tools, RNG certification, player fund protection, quarterly and annual reporting, and Compliance Officer responsibilities. GCA master licence holders under the LOK framework must maintain AML frameworks aligned with Curacao national legislation, along with technical system documentation. For Anjouan-licensed operators, the requirements are less detailed but still include basic AML and KYC documentation.

The table below summarises the core compliance areas by jurisdiction:

Compliance areaMGA (Malta)GCA (Curacao)Anjouan
AML policyMandatory (EU AMLD)Mandatory (LOK)Required
KYC proceduresMandatoryMandatoryRequired
Responsible gamblingMandatoryRequiredBasic
RNG testingMandatory (BMM, GLI)RequiredNot specified
Player fund protectionRing-fenced requiredNot specifiedNot required
Annual reportingMandatoryMandatoryFee renewal
Key Function rolesCO + AMLRO (MGA-approved)Compliance contactNot mandated
Compliance auditsSystem audit every 2 yrsPeriodic reviewNot formal

This article focuses primarily on MGA compliance requirements, which are the most detailed and the most actively enforced in the EU-accessible iGaming market.

2. AML and KYC: the core of any gaming licence compliance checklist

AML and KYC are the most actively enforced areas across all major gaming regulators. The MGA bases its AML framework on the EU Anti-Money Laundering Directives, which means MGA-licensed operators follow the same standards as banks and payment providers in Malta. The Financial Action Task Force (FATF) publishes the international standards that underpin most national AML legislation, including Malta’s Prevention of Money Laundering and Funding of Terrorism Regulations.

Your gaming licence compliance checklist for AML must include:

  • A written AML/CFT policy, reviewed and updated at least annually
  • A risk assessment covering your player base, payment methods, and markets served
  • Customer Due Diligence (CDD) procedures: standard, simplified, and enhanced
  • Source of funds verification for high-value and high-risk players
  • Politically Exposed Person (PEP) screening on all customers
  • Sanctions screening against current EU, UN, and OFAC lists
  • Transaction monitoring rules with defined thresholds and alert procedures
  • Suspicious Transaction Report (STR) procedures, including filing records and FIAU submission logs
  • Staff AML training records, updated annually with sign-off documentation

The MGA requires a licensed Compliance Officer and a separate Anti-Money Laundering Reporting Officer (AMLRO). The MGA designates both as Key Function roles. A single person cannot hold both at the same time. The MGA must approve each holder before they take up the position.

For KYC, your procedures must verify customer identity before allowing withdrawals. Under MGA rules, you cannot allow cumulative deposits beyond 2,000 EUR without completing full identity verification. Some jurisdictions set lower thresholds or require KYC at account creation. Your systems must enforce the applicable threshold automatically and log every check.

The FATF Recommendations provide the internationally recognised framework for AML/CFT obligations. Gaming regulators in Malta and other jurisdictions align their AML requirements to these standards. See the full FATF Recommendations for the underlying framework.

3. Responsible gambling obligations

Every MGA-licensed operator must implement responsible gambling tools as a licence condition. These are not optional features: the MGA enforces them through compliance audits and treats failures here as serious breaches.

Your gaming licence compliance checklist for responsible gambling must include:

  • Deposit limits (daily, weekly, monthly) available to all players at account creation
  • Loss limits and session time limits, adjustable by the player at any time
  • Reality checks: session reminders at intervals the operator defines
  • Self-exclusion: a minimum 6-month exclusion period; a permanent exclusion option must also be available
  • Integration with national self-exclusion registers for any regulated market you serve
  • Cooling-off periods: a minimum 24-hour cooling-off option at the player’s request
  • Problem gambling indicators: your platform must flag players who show patterns associated with disordered gambling behaviour
  • Marketing restrictions: no promotional material to self-excluded players or players who have activated deposit or loss limits

The MGA also requires operators to contribute to a Safer Gambling fund. For B2C operators, this contribution forms part of the 25,000 EUR annual compliance contribution.

Responsible gambling tools must work in real time. Systems that allow a self-exclusion to take effect with a 24-hour delay, or that accept a deposit after a player reaches their limit, fail the audit regardless of what the policy documentation says.

4. Technical compliance requirements

Your gaming licence compliance checklist must include a technical section. Regulators do not review policies in isolation: they audit the system itself.

RNG certification

All games with random outcomes must use a certified Random Number Generator. The MGA accepts testing from approved laboratories including BMM Testlabs and Gaming Laboratories International (GLI). Certificates are not permanent. Most labs issue them on an annual review cycle, and new game integrations require separate certification before you can make them available to players.

System audits

The MGA requires a System Audit every two years and a System Review between audits. The System Audit examines the gaming platform’s integrity, the accuracy of game results, and the completeness of transaction records. In May 2025, the MGA updated the procedures for System Audits and System Reviews. Operators should confirm current requirements through the MGA Licensee Hub before each audit cycle.

Data protection

Operators accepting players from EU member states must comply with the General Data Protection Regulation (GDPR). This requires documented data processing agreements with all third-party vendors, clear privacy notices in player-facing interfaces, defined data retention periods, and a documented process for handling data subject access requests within the 30-day statutory deadline.

Payment processing

You must use only payment methods approved under your licence. Adding a new payment service provider requires either notification or prior approval from the MGA, depending on the provider type. Operators who add payment methods without the required steps breach their licence conditions.

Server location

MGA rules require all gaming servers to sit in approved jurisdictions or with MGA-approved hosting providers. Offshore server arrangements require disclosure. Operators running hybrid cloud infrastructure must confirm that data residency rules do not conflict with MGA server location requirements.

5. Reporting and record-keeping in the gaming licence compliance checklist

Regulators expect detailed, accurate records. MGA-licensed operators must keep all transaction records, game records, player identification documents, and AML reports for a minimum of 10 years. The MGA can request these records at any time.

Reporting obligations for MGA-licensed operators:

  1. 1. Quarterly financial reports: submitted to the MGA through the Licensee Portal within the prescribed deadline after each quarter.
  2. 2. Annual audited financial statements: prepared by a licensed auditor and submitted to the MGA within the defined annual deadline.
  3. 3. Annual compliance self-assessment: the MGA publishes a self-assessment tool that operators complete and submit each year, covering all licence conditions.
  4. 4. Suspicious Transaction Reports (STRs): filed with the Financial Intelligence Analysis Unit (FIAU) in Malta. The filing obligation runs independently of whether a criminal investigation follows.
  5. 5. Material change notifications: any material change to the business, including ownership, Key Function changes, or software platform changes, requires prior MGA notification and, in some cases, prior approval.
  6. 6. Incident reports: technical failures that affect game outcomes or player funds require reporting to the MGA within defined timeframes, which vary by the severity of the incident.

GCA master licence holders report through the GCA online system. Reporting cycles are less frequent than under the MGA framework, but record-keeping obligations remain. GCA operators must also comply with the reporting requirements of the LOK legislation.

For the full reporting requirements and access to the Licensee Portal, see the MGA Licensee Hub.

6. Key Personnel Requirements for Gaming Licence Compliance

Gaming regulators control who can operate a licensed business. For MGA-licensed operators, the following Key Function roles require MGA approval before the person takes up the position:

  • Chief Executive Officer (or equivalent senior management role)
  • Chief Financial Officer (or equivalent)
  • Compliance Officer
  • Anti-Money Laundering Reporting Officer (AMLRO)
  • All persons with qualifying shareholdings above 10%

Each Key Function holder must pass a fit and proper assessment. The MGA examines financial history, criminal record, and professional experience relevant to the role. An executive with undisclosed prior regulatory sanctions at another operator will fail the assessment.

A change of Key Function holder requires immediate notification to the MGA and a formal re-approval process for the incoming person. You cannot leave a Key Function role vacant. If a Compliance Officer resigns, you must appoint an interim within the prescribed period and begin the formal approval process without delay.

DD Consultus provides Compliance Officer and AMLRO services to MGA-licensed operators who do not employ suitable in-house candidates. This arrangement is common for startups and smaller operators who need to satisfy Key Function requirements before they have built a full compliance team.

For information on obtaining your MGA licence and meeting Key Function requirements from the outset, see our gaming licence acquisition service. For ongoing compliance management after licensing, see our gaming licensing compliance service.

7. Using a gaming licence compliance checklist across multiple jurisdictions

If you hold licences in more than one jurisdiction, your compliance programme must cover both. This creates operational complexity, particularly when jurisdictions carry different or conflicting requirements.

A common scenario: an operator holds an MGA licence for EU markets and a GCA master licence for markets where the MGA licence does not grant access. The AML framework under the MGA (EU Anti-Money Laundering Directive standard) is more stringent than the current Curacao framework. Most multi-jurisdiction operators apply the higher standard across the entire operation rather than maintaining two separate compliance systems. This reduces compliance risk and simplifies audit preparation.

Operators accepting Romanian players must hold a separate ONJN licence. The MGA licence does not grant access to the Romanian market. The Romania gaming licence cost breakdown covers the full ONJN fee structure and compliance requirements, which run entirely separately from the MGA framework.

For the banking requirements that run alongside your compliance setup, the gaming company bank account guide covers what banks require from licensed gaming operators and how to structure accounts across multiple jurisdictions.

Multi-jurisdiction operators should also confirm whether their AML policy explicitly states which regulatory framework takes precedence for specific player segments. Auditors in each jurisdiction look for documented evidence that the operator understands which rules apply to each market.

8. What happens when a compliance audit finds gaps

Regulators take different approaches to enforcement. The MGA publishes all enforcement actions publicly and maintains a full Enforcement Register on its website. Typical enforcement outcomes for compliance failures include:

  • Administrative penalty: fines for specific breaches, typically calculated on gross gaming revenue
  • Compliance directive: a formal instruction to correct a specific breach within a defined deadline
  • Suspension: temporary removal of the licence pending remediation of identified failures
  • Revocation: applied for repeated or serious breaches, or for failures the operator did not self-report

The MGA has issued fines of several hundred thousand euros to operators for AML and KYC failures. However, these cases did not involve minor paperwork gaps. Instead, they involved failures to identify high-risk players, absent transaction monitoring, and AMLRO roles held by persons with no actual authority to act on the findings. As a result, operators should treat AML controls as active compliance systems, not just written policies.

If your gaming licence compliance checklist shows gaps, address them before the next audit cycle. The cost of remediation is almost always lower than the cost of a regulatory penalty. Operators who self-report a compliance gap to the MGA receive more favourable treatment than operators whose breach the MGA identifies through its own audit programme.

For a compliance gap assessment or remediation support, contact the DD Consultus advisory team at contact@licencegaming.com or +356 99408536.

9. Frequently asked questions

What is a gaming licence compliance checklist?

A gaming licence compliance checklist is a structured list of regulatory obligations an operator must meet under their gaming licence. In practice, it covers AML and KYC policies, responsible gambling tools, technical system requirements, reporting deadlines, and key personnel requirements. However, the specific items depend on the issuing regulator. Therefore, operators should adapt the checklist to the licence conditions that apply in each jurisdiction.

What AML requirements apply to MGA-licensed operators?

MGA-licensed operators must maintain a written AML/CFT policy, conduct customer due diligence at defined deposit thresholds, screen players against sanctions and PEP lists, file STRs with the FIAU, and appoint a licensed AMLRO. In addition, the MGA aligns its AML framework with the EU Anti-Money Laundering Directives. Therefore, operators need procedures that meet both Malta-specific licence conditions and wider EU AML standards.

How often do gaming regulators audit compliance?

The MGA requires a System Audit every two years and an annual compliance self-assessment. In addition, AML compliance reviews can include on-site inspections. However, audit frequency varies by licence type and the operator’s risk profile. As a result, higher-risk operators may face more frequent review.

What Key Function roles does the MGA require?

The MGA requires a Compliance Officer and an AMLRO as a minimum. The MGA must also approve the CEO, CFO, and all qualifying shareholders before they take up their roles. A single person cannot hold both the Compliance Officer and AMLRO roles at the same time.

Does a Curacao gaming licence require AML compliance?

Yes. Since the 2023 to 2024 LOK reform, GCA master licence holders must implement AML frameworks compliant with Curacao national legislation. The standard is less detailed than the EU AML Directive framework the MGA requires, but AML obligations exist and the GCA enforces them.

What happens if an operator fails a compliance audit?

The MGA can issue an administrative penalty, a compliance directive, or suspend or revoke the licence for serious or repeated failures. The MGA publishes all enforcement actions publicly. The severity depends on the nature of the breach, whether the operator self-reported, and the history of prior compliance.

Can one person hold both the Compliance Officer and AMLRO roles?

Under MGA rules, no. Instead, separate individuals must hold the two roles. Therefore, the MGA will not approve an arrangement where one person acts as both Compliance Officer and AMLRO. However, operators without suitable in-house candidates can outsource one or both roles to an approved compliance service provider.

What records must a gaming operator keep?

MGA-licensed operators must retain all transaction records, game records, player identification documents, and AML reports for a minimum of 10 years. In addition, the MGA can request these records at any time. Therefore, operators need clear storage procedures, secure document access, and regular internal checks. Moreover, failure to maintain adequate records is a standalone compliance breach, separate from any substantive AML failure.

About the author

DD Consultus Advisory Team

DD Consultus Limited is a Malta-based iGaming consultancy operating under the Licence Gaming brand. In addition, the team advises gaming operators on licence acquisition, compliance management, Key Function provision, company incorporation, and iGaming bank account opening. Moreover, DD Consultus supports operators across Malta, Curacao, Anjouan, Kahnawake, Romania, Bulgaria, and the Isle of Man. Therefore, clients can manage licensing, compliance, corporate setup, and banking support through one advisory team. Office: Office 1, Piazzetta Business Plaza, Ghar il-Lembi Street, Sliema SLM 1560, Malta. Contact: contact@licencegaming.com | +356 99408536.

Not sure which licence is right for your situation?

Book a consultation and get a clear jurisdiction recommendation for your situation.

Get a Recommendation

Share this article

← Back to iGaming News
Denitza Dimitrova, Managing Partner

Reviewed by Denitza Dimitrova, Managing Partner. Former Manager for Legal and Enforcement at the Malta Gaming Authority. About the team