SupportIf gambling is causing harm, call GamCare free on 0808 8020 133, 24 hours, or visit gamcare.org.uk. GamStop.co.uk
Payments · UK 2026

Payments and checks, banks, cards, crypto, KYC

A statistics-led read of the payment chain that sits between a UK bank account and an operator outside the UKGC register. The Money Laundering Regulations 2017 threshold rules, the MCC 7995 merchant category code, the five voluntary bank switches, the FCA cryptoasset register and the National Crime Agency SAR volumes are all set out with the source that produced the figure and the date it was published. Nothing on this page is legal or financial advice, and nothing on this page is a recommendation to deposit or withdraw.

  • 18+
  • Independent
  • Public sources
Illustration for payments and identity checks at non-GamStop sites
01

UK Money Laundering Regulations 2017 in a paragraph

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, cited throughout this page as the MLR 2017, are the domestic statutory instrument that carries the fourth and fifth EU Anti-Money-Laundering Directives into UK law, updated by the amending regulations of 2019 and 2022 and read against the sixth directive for scope. For casino operators the Regulations trigger customer due diligence at a single transaction of 2,000 euro or its sterling equivalent, and enhanced due diligence at 10,000 euro across a series of linked transactions, both figures measured in stakes plus withdrawals rather than net position. The point that is regularly misread in popular coverage is that the trigger sits on the operator side of the transaction, and where the operator is offshore the trigger applies only to the parts of the payment chain that pass through a UK-regulated institution, typically the acquiring bank of the customer or the FCA-registered cryptoasset service provider that converts fiat to a wallet balance.

The practical reading follows. The offshore casino itself is not a UK Money Laundering Regulations 2017 obliged entity, and it is not supervised by HM Revenue and Customs or the UK Gambling Commission for anti-money-laundering purposes. The UK bank that funds the customer's card, the UK cryptoasset business that sits in the FCA register under the Regulations, and the payment institution that clears the merchant leg are the obliged entities in the chain. A deposit that reaches an offshore casino has, in nearly every case, already passed through at least one obliged entity whose customer due diligence file, source-of-funds record and transaction monitoring engine has recorded it. That is why the statement that offshore play is anonymous does not survive contact with the primary sources. The identity data is not held by the operator, and it is not visible on the operator's account page, but it is held in the file of the UK regulated party, retained for the statutory five-year window and available on request to law enforcement.

02

How offshore KYC differs from UKGC-licensed KYC

The UK Gambling Commission Licence Conditions and Codes of Practice have required age and identity verification before deposit at UKGC-licensed remote operators since 7 May 2019. The change followed the Commission's 2018 consultation response and closed the gap that had previously allowed play from an unverified account. Affordability information at defined trigger points was added by the phased introduction of financial-risk assessments from 2023, with the light-touch check at 500 pounds net loss over a rolling thirty days and the enhanced check at 1,000 pounds net loss over a rolling ninety days in the pilot design. The result at a UKGC-licensed site is that identity friction, address verification and, where relevant, source-of-funds documentation sit at the front of the customer journey rather than the back, and refusals or holds occur before a customer has staked significant funds.

The offshore pattern is the mirror image. The documented practice recorded in consumer complaint samples, in the Advertising Standards Authority and Committees of Advertising Practice adjudications on cross-border marketing, and in the Financial Ombudsman Service quarterly complaint tables, is that offshore operators typically defer identity collection until the first withdrawal. A UK-resident adult can, in most reported instances, deposit and play without producing a passport scan, an address verification document or an affordability declaration. The identity request lands when the customer attempts to withdraw, and the request is often accompanied by a source-of-funds enquiry that itself asks for bank statements over a period the customer had not expected to disclose. The design produces a documented pattern in the complaint data of withdrawals held, of accounts closed with balance forfeited and of accounts reopened only after further documentation. Nothing on the operator side is UK-regulated, and nothing in the customer's UKGC dispute route reaches it.

A closer look

The specific mechanic that produces the withdrawal-side pattern is the interaction between the operator's terms of use, the acquirer's obligations under the card scheme rules and the offshore jurisdiction's own anti-money-laundering framework. Curaçao's Landsverordening op de Kansspelen of 24 December 2024 imposes a KYC obligation on the operator, but the operator is free to set the trigger at a customer transaction milestone rather than at account opening, and in the transition window through 2025 the enforcement capacity of the Curaçao Gaming Authority remained materially below that of the UKGC. The customer therefore encounters the check when the operator's system reaches the milestone, not when the customer would prefer.

03

Bank blocks and card gambling switches in 2026

HSBC opened the first UK card-level gambling switch in July 2018, initially on debit cards issued through the HSBC UK current account and extended progressively to first direct and to Amex-branded cards issued through the HSBC group. Monzo added a similar switch in June 2018, Barclays in December 2018, Starling in February 2019 and Lloyds Banking Group across Halifax, Bank of Scotland and Lloyds-branded accounts by the end of 2019. Coverage was extended to credit cards at several providers in the years that followed, and Nationwide, Santander UK and NatWest Group added their own switches within the same design pattern. UK Finance quarterly data records rising adoption year on year, with the switch active on a growing share of active gambling-transacting current accounts by the end of 2025.

The operational shape of the switch is uniform. Once activated the switch causes the card issuer to decline any authorisation request coded MCC 7995 at the network level. The transaction is stopped before the funds move, the decline is returned to the merchant within the standard authorisation window and the customer receives a notification through their banking app. Reversal is not instant. Each of the five largest UK providers has published a cool-off period at the customer's own settings, typically forty-eight hours from the request to switch off, before the block is lifted. The cool-off is designed as a friction feature rather than a bureaucratic obstruction, and the published complaint data at the Financial Ombudsman Service records a low volume of substantive complaints on the mechanic itself, with most complaints turning on communication rather than on the block.

04

Visa, Mastercard and the UKGC 2025 taskforce

The joint taskforce between Visa Europe, Mastercard Europe and the UK Gambling Commission was announced in the second quarter of 2025 and formalised through a memorandum of understanding published in the Commission's annual report. The remit covers enforcement on the correct application of the merchant category code 7995 to remote gambling transactions, on the fallback codes used by offshore acquirers to route transactions around the primary code and on the operational escalation path where an offshore operator is identified as systematically misclassifying gambling as digital goods, general retail or telecommunications. The taskforce publishes no operator-level enforcement data, but the Commission's quarterly enforcement returns show a rising trend line of merchant-side interventions running alongside the domain-level takedowns.

The number that a UK reader can hold in mind is the enforcement volume the Commission reported for its 2024 to 2025 year, running to more than seven hundred and seventy cease-and-desist notices, roughly sixty-four thousand URL removals through the co-operation route with Google Search and two hundred and sixty-four domain removals through the co-operation route with domain registrars. The merchant category code work sits alongside the domain work rather than replacing it. The observable result on the customer side is that offshore deposit success rates on UK-issued cards have fallen through 2024 and 2025 according to the operator-side data reported in industry trade coverage, and that first-time deposits from a UK IP address on a Visa or Mastercard branded card face a documented probability of decline that was not present in the 2020 or 2021 samples.

Key points

  • MLR 2017 customer due diligence trigger sits at 2,000 euro single transaction; enhanced due diligence at 10,000 euro linked total
  • UKGC LCCP has required KYC before deposit at UKGC-licensed sites since 7 May 2019
  • Voluntary card gambling switches now active at HSBC, Monzo, Starling, Lloyds and Barclays with typical forty-eight hour reversal cool-off
  • FCA cryptoasset register applies MLR 2017 to UK exchanges; Travel Rule in force from 1 September 2023
  • NCA UK Financial Intelligence Unit received approximately nine hundred thousand SARs in the last reporting year
05

Crypto rails and why they still hit KYC eventually

The Financial Conduct Authority maintains a statutory register of cryptoasset businesses under the Money Laundering Regulations 2017 as amended, and registration has been required for UK-facing exchanges and custodian wallet providers since 10 January 2020. Applications that were incomplete or that failed the fit-and-proper test have been rejected, and the FCA has published the outcome of each application. The Travel Rule under the amending regulations came into force on 1 September 2023, requiring the originator and beneficiary information to travel with a cryptoasset transfer above a set sterling equivalent, and the enforcement position has hardened through 2024 and 2025 as the FCA's supervision work has settled into a routine. The customer-visible consequence is that a UK exchange, an approved custodian wallet or an on-ramp integrated into a UK banking application performs customer due diligence at account opening in the same way a bank does.

The offshore casino accepting the crypto deposit therefore sits at the far end of a chain whose front is already inside the FCA register. The operator may not see the customer's identity file, and the operator's account page may not display more than a wallet address, but the identity is captured earlier at the exchange, retained for the statutory five-year window, and available on lawful request. The public discussion that treats crypto rails as an anonymous alternative to card payment is out of step with the register. Where a customer chooses to fund an offshore deposit through peer-to-peer trading or through a wallet that has not touched a UK exchange, the identity is not captured at that specific point, but the moment the funds return to a UK bank as a withdrawal the AML monitoring engine at the bank encounters the flow and the transaction returns to the mainstream regulated chain.

A closer look

Stablecoins occupy a separate cell in the same table. The UK stablecoin regime under the Financial Services and Markets Act 2023 is now in phased implementation, with issuance and custody of designated fiat-referenced tokens brought inside the FCA's regulated activities perimeter. The upshot for a UK customer is that a stablecoin deposit funded through a UK-registered exchange is inside the same MLR 2017 obligations as a fiat deposit, and the pattern of identity capture at the front and monitoring across the chain is preserved. The claim that a specific stablecoin route bypasses UK oversight does not survive contact with the FCA's cryptoasset supervision approach.

06

When your bank flags a suspicious deposit

UK bank transaction monitoring engines flag inbound and outbound gambling-linked flows against a defined set of typologies. The recorded typologies in Joint Money Laundering Steering Group guidance and in the National Economic Crime Centre's public awareness papers include round-sum inbound transfers from unregulated exchanges, patterned deposits followed by rapid withdrawal to a different beneficiary, cross-border cryptoasset flows that show short custody at a UK exchange between two offshore movements, and deposits sourced from a facility whose credit limit has been drawn down to its edge. Where a flow matches enough of the typology set the engine raises an internal alert, the alert is reviewed by a Level 1 analyst and, where confirmed, escalated to a Level 2 analyst who prepares the suspicious activity return.

The customer-visible surface of the process is limited. A first flag typically produces a hold of twenty-four to seventy-two hours on the specific transaction while the analyst review runs, and the customer receives a notification that a transaction has been declined or that a step-up authentication is required. Where the alert is closed as false positive the transaction is released and the customer sees no further contact. Where the alert is escalated to a Suspicious Activity Report, the customer is not told, because tipping off the customer to the fact of a report is itself an offence under section 333A of the Proceeds of Crime Act 2002. Account closure at short notice is the more visible consequence for a small population of customers and is separate from the SAR process itself, applied under the bank's contractual right rather than under the regulated intelligence pathway.

Worth noting A hold applied by a bank at the transaction level is not the same as a Suspicious Activity Report at the National Crime Agency level. The first is a friction step the customer sees, the second is a regulated intelligence submission the customer cannot see, and the two can occur separately.
07

What a Suspicious Activity Report actually is

A Suspicious Activity Report is a submission by a UK regulated entity to the UK Financial Intelligence Unit at the National Crime Agency under the Proceeds of Crime Act 2002 and the MLR 2017. The submission carries a defined field set, a narrative and a supporting document pack, and is entered through the SAR Online portal maintained by the NCA. Where the submission includes a Defence Against Money Laundering request the submitting entity is asking the NCA for consent to proceed with a specific transaction and the statutory windows for response run to seven working days for the initial notice and thirty-one calendar days for the moratorium. During the moratorium the transaction is held and the customer sees a hold on the specific facility rather than on the entire account.

The UK Financial Intelligence Unit's most recent published annual return records SAR volumes in the region of nine hundred thousand for the reporting year, of which a growing share are DAML requests. Gambling-linked SARs are a small subset of the total, and the Unit publishes typology bulletins that indicate which patterns produced the majority of gambling-related reports in the prior period. For a UK adult reader the practical point is not the volume, which is inaccessible at the individual level, but the mechanism, which sets out clearly why a bank cannot tell a customer that a report has been raised and why an unexplained hold on a specific transaction can persist for a defined window without a public reason.

08

Practical steps to reduce personal risk

The steps that follow are informational and are not a personal recommendation. Turn on the card-level gambling switch at every UK current account and every UK credit card facility the household holds, using the in-app control at the five largest providers and the equivalent control at Nationwide, Santander UK and NatWest Group. Add a second layer at the payment aggregator level by revoking any stored recurring authority to a gambling merchant from PayPal, Apple Pay and Google Pay. Where the household includes a credit card, request that the gambling merchant category is treated as a cash-advance-equivalent, which is the position several UK card issuers have already applied and which produces a higher declined-authorisation rate at MCC 7995 without requiring a customer switch.

The financial-hygiene layer sits alongside the behavioural layer, and both matter. Contact the National Gambling Helpline at GamCare on 0808 8020 133, twenty-four hours a day, seven days a week, before the payment layer is your only lever. The helpline is delivered by GamCare, funded through the Statutory Levy that came into force on 6 April 2025, and the trained advisers can direct the caller to a structured brief conversation, to a specialist counsellor within the National Gambling Support Network or to the National Health Service specialist clinic pathway. The bank switches are effective and the SAR process is real, but neither substitutes for a conversation with a trained adviser at the point at which the pattern of deposits has become a household concern.

Two further steps are worth noting for readers who want a full financial-hygiene picture. First, request a Standard Financial Statement from a debt-advice body if the household has taken on card debt to fund gambling; the Standard Financial Statement is the shared budget format used by StepChange, Citizens Advice and National Debtline, and it is the format most UK creditors will engage with. Second, consider the Financial Conduct Authority guidance on persistent credit card debt, which requires the issuer to intervene where a customer has paid more in interest and charges than in principal repayments across an eighteen-month window. These steps sit alongside the gambling-specific tools rather than replacing them, and together they cover most of the household-level friction a UK adult can arrange without professional financial advice.

Read next

Sources and verification

Verified against public UK sources including the UK Gambling Commission enforcement report and Licence Conditions and Codes of Practice at gamblingcommission.gov.uk. Last checked 5 August 2026.

R
Written by Rachel Emsworth
Reviewed by Dr Adrian Foulke, gambling statistician, ex-Behavioural Insights Team, updated 5 August 2026

Frequently asked questions

What is MCC 7995 and does every offshore gambling deposit get flagged under it?

MCC 7995 is the merchant category code used by Visa and Mastercard for betting and casino transactions. It is applied by the acquiring bank of the merchant, not by the customer's bank. Where the acquirer classifies the payment as MCC 7995 the customer's bank sees the code and applies any gambling switch or filter. Offshore operators routinely test alternative codes to avoid the label, and Financial Ombudsman Service complaint tables record recurring examples of digital-goods, general-retail and telecommunications codes being used in place of the correct one.

Do offshore casinos verify identity before a first deposit in the way UKGC-licensed sites do?

In most cases they do not. UKGC Licence Conditions and Codes of Practice have required age and identity verification before deposit since May 2019, and affordability information at defined trigger points since 2023. Offshore operators typically defer identity collection until first withdrawal, and the documented result in complaint sample data is that identity friction, funds held pending verification and requests for source-of-funds documents appear at the withdrawal stage rather than the deposit stage.

Which UK banks currently offer a voluntary gambling block on debit or credit cards?

HSBC opened the first UK card-level gambling switch in 2018. Monzo, Starling, Lloyds and Barclays have added equivalent switches in the intervening period, and the coverage has been broadened to include credit cards at several providers. UK Finance has recorded rising adoption year on year. Once switched on the block applies at authorisation, so a transaction coded MCC 7995 is declined at the network before the funds move. Reversal requires an active customer action and a cool-off period at the bank's own settings.

Does depositing in cryptocurrency let a UK player avoid the identity checks entirely?

No. The identity data is captured further up the chain. FCA-registered UK cryptoasset businesses have been required to complete customer due diligence under the Money Laundering Regulations 2017 as amended since January 2020, and the Travel Rule has applied to transfers since 1 September 2023, meaning originator and beneficiary information travels with the value. The offshore operator may not see the identity file, but the exchange or wallet provider does, and the record is retained under the standard five-year retention window.

What happens if a UK bank raises a Suspicious Activity Report on gambling-linked deposits?

A Suspicious Activity Report is filed with the UK Financial Intelligence Unit at the National Crime Agency under the Proceeds of Crime Act 2002. The customer is not told a SAR has been filed, and tipping off is itself an offence. The bank may pause a transaction or freeze a facility pending consent, and the National Crime Agency has statutory windows for responding. The most likely consequence for a UK account holder is a temporary hold on specific payments rather than a permanent account closure, but the reporting regulator has recorded rising SAR volumes in recent years.

Talk to someone today

The National Gambling Helpline is free, confidential and open 24 hours a day, seven days a week.

0808 8020 133 GamCare, free, 24 hours