TLDR
- Regulators collected $34 million from casino operators in September over anti-money laundering (AML) and know-your-customer (KYC) failures.
- One casino let a man gamble on 80 separate days without checking where his money came from.
- Another casino was fined for letting a high-risk gambler keep playing, even after it received a tip about him.
- Panelists at the Global Gaming Expo said regulators now want proof that compliance programs actually work.
- A DraftKings AML officer said poor communication between compliance and other teams was a common problem.
Casino operators paid $34 million in fines in September over anti-money laundering and know-your-customer failures. The figure was shared at the Global Gaming Expo, a major gaming industry event in the United States.
Melissa Gomez Nelson, a partner with law firm Dentons US, gave the number during a panel called “Identifying and Managing Emerging Financial Crime Risks.”
“That’s what regulators collected from casino ownership in response to investigations related to AML and KYC concerns,” Nelson said.
What the Casinos Did Wrong
The casinos involved were not named. However, Nelson described several of the cases.
One casino allowed a man to gamble on 80 separate days without verifying where his money came from. Another was fined for system-wide weaknesses in its anti-money laundering oversight, including past problems.
A third casino let a man keep gambling after it had labeled him a high-risk gambler. The casino had also received a tip about him.
“This is obviously a concerning issue because there were a lot of red flags that were flagged and issues that were raised within the operators’ organizations,” Nelson said.
Regulators Want Programs That Work
Abigail Singley, an advisory director at PwC, said enforcement actions have recently been loosened. Because of this, she said, having the basic parts of an AML program on paper is no longer enough.
“It’s really about being able to demonstrate and implement a true risk-based program that’s effective in identifying and ultimately actioning on risk to the operator,” Singley said.
Elise Lebourg, a senior manager of Forensics and Integrity Services at Ernst & Young, said many programs have become a box-checking exercise. She described companies pulling out a binder, checking a few boxes, and closing it until someone asks for evidence.
“Is it moving with your product road map or are you just arbitrarily updating your risk assessment spreadsheet?” Lebourg asked.
Dave Foppert, vice president and AML officer at DraftKings, said policies over the last year have often met only minimum requirements.
“Having a policy is the floor, not the ceiling,” Foppert said. He added that state and federal regulators are focusing on how effective a program really is.
Foppert said many recent enforcement cases involved breakdowns between different teams inside the same operator. He said compliance staff need strong communication with marketing, product, and customer teams, who deal with players every day.
“What we saw with the enforcement actions in many ways was a breakdown of that,” Foppert said.
Lebourg said she starts with risk assessment because it is the foundation of these procedures. She said gaps often appear when assessments are not updated or when companies do not know what to do with the results.
“A lot of times we see compliance build these beautiful risk assessments, but the output isn’t something that’s digestible,” she said.
Panelists said regulators are now focusing on whether AML and KYC programs actually work, not just whether written policies exist.
