
A practical guide to identity checks, customer due diligence, licensing rules, and player privacy in cryptocurrency gambling. This guide identifies jurisdiction-specific legal requirements, FATF standards, operator practices, and CryptoGambler editorial recommendations separately.
Know Your Customer, or KYC, is an industry term commonly used for identifying and verifying a customer. Some businesses use it more broadly to include parts of customer due diligence, such as customer risk assessment.
In a crypto casino, verified identity information can support age checks, sanctions screening, self-exclusion controls, fraud prevention, and customer risk assessment. These functions may use the same identity data, but they are separate from the act of verifying identity.
A basic verification process may compare the player's name, date of birth, address, and identity document with reliable and independent information.
Cryptocurrency does not remove the distinction between wallet control and legal identity. A blockchain address shows transaction activity but does not identify the person who controls it. Where the blockchain and wallet support message signing, a user may demonstrate control of an address by signing a message. An operator may also use a verification transaction. Neither method establishes the user's legal name, age, residence, or source of funds.
Some crypto gambling platforms also use blockchain analytics, wallet-risk review, and transaction monitoring. The applicable controls depend on the operator's activities, licence, jurisdiction, and internal risk policy.
The exact request depends on the applicable rules and the risk presented by the account or transaction.
- Full legal name
- Date of birth
- Residential address and country of residence
- Government-issued identity document
- Proof of address
- Evidence that the player owns the payment method
- Evidence of control over a cryptocurrency address
- Source-of-funds or source-of-wealth evidence in higher-risk cases
The operator may use verified information to carry out additional checks, including:
- Age and eligibility checks
- Sanctions and politically exposed person screening
- Self-exclusion matching
- Duplicate-account and identity-mismatch checks
- Wallet-risk and transaction review
- Additional due diligence after unusual or higher-risk activity
Identity verification and source-of-funds review answer different questions. Identity verification asks who the customer is. A source-of-funds review examines where the money or cryptocurrency used in a transaction came from.
There is no single global timing rule. Depending on the applicable rules and operator policy, verification may occur during onboarding, before the first deposit or bet, before withdrawal, at a transaction threshold, or after a later risk trigger. More than one trigger can apply to the same account.
In some regulated markets, verification must take place before the customer is allowed to gamble. Elsewhere, an operator may permit limited activity before requesting documents. Additional information may also be requested after unusual activity, a large withdrawal, a location mismatch, inconsistent account details, or exposure to a higher-risk wallet.
Clear disclosure helps players understand whether verification could delay a withdrawal. In Great Britain, covered licensees are specifically required to provide information about possible identity-document requests before deposit.
KYC commonly refers to identifying and verifying the customer.
Customer due diligence, or CDD, is the wider risk-based process. FATF Recommendation 10 includes identifying and verifying the customer, identifying the beneficial owner where relevant, understanding the purpose and intended nature of the relationship, and conducting ongoing scrutiny of transactions.
Enhanced due diligence, or EDD, means additional measures when the customer, transaction, jurisdiction, source of funds, or another factor presents a higher risk. Depending on the framework, the operator may obtain more information, examine source of funds or wealth, require management approval, or increase monitoring.
Anti-money laundering and counter-terrorist financing, or AML/CFT, is the broader compliance framework. CDD, record keeping, transaction monitoring, sanctions controls, and suspicious-transaction reporting may all form part of it.
Great Britain - Covered remote operators verify identity before gambling
EU AML Directive-CDD at the EUR 2,000 gambling threshold
FATF casino standard-CDD at the USD/EUR 3,000 casino threshold
FATF virtual-asset standard-Additional rules may apply where the operator performs VASP activities
UK Gambling Commission Licence Condition 17.1.1 applies to most remote licences, subject to the exclusions listed in the condition. It took effect on 7 May 2019 after being announced on 7 February 2019.
Paragraph 1 requires covered licensees to obtain and verify information establishing a customer's identity before the customer is permitted to gamble. The information must include, but is not limited to, the customer's name, address, and date of birth.
Paragraph 2 states that a withdrawal request must not trigger a demand for additional information as a condition of withdrawal when the licensee could reasonably have requested that information earlier. The condition preserves requests required by another legal obligation.
Paragraph 3 says that before a customer is permitted to deposit, the licensee should explain what identity documents or other information may be needed, the circumstances in which they may be requested, and how they should be supplied.
Paragraph 4 requires reasonable steps to keep identity information accurate.
The Gambling Commission described the 2019 changes as measures intended to support age restrictions, self-exclusion controls, the detection of criminal activity, and fairer withdrawal procedures.
Article 11(d) of Directive (EU) 2015/849 required Member States to ensure that providers of gambling services apply customer due diligence when an occasional transaction involves the collection of winnings, the wagering of a stake, or both, and the amount is EUR 2,000 or more. The threshold covers a single operation or several operations that appear to be linked.
Article 67(1) set 26 June 2017 as the deadline for Member States to transpose the Directive. The precise duties imposed on an operator depend on the national law that implemented it.
The EUR 2,000 figure is an AML threshold for gambling services. It is not a universal rule requiring every crypto casino to verify every customer at registration.
Regulation (EU) 2024/1624 was published in the Official Journal on 19 June 2024. Under Article 90, most of the Regulation applies from 10 July 2027. Until then, it is a future harmonised EU AML framework rather than the current source of day-to-day operator duties.
The FATF Recommendations were adopted on 16 February 2012 and are listed by FATF as amended in June 2026. They are international standards for countries to implement through domestic law, regulation, supervision, and enforceable requirements. They are not automatically direct player-facing law.
Recommendation 10 sets out the core CDD measures.
Recommendation 15 addresses risks associated with new technologies and includes the FATF framework for virtual assets and virtual asset service providers, or VASPs. A casino is not automatically a VASP merely because it accepts cryptocurrency. Classification depends on the services the business performs and the applicable national legal framework. Activities such as exchanging virtual assets, transferring them for another person, or providing custody or administration may bring an entity within the VASP definition.
Recommendation 22 applies relevant CDD and record-keeping requirements to casinos when customers conduct financial transactions at or above the designated threshold. The Interpretive Note sets the casino threshold at USD/EUR 3,000 and states that casinos should identify and verify customers at that level. It also requires countries to ensure that a casino can link a customer's CDD information to the transactions that customer conducts.
The FATF threshold of USD/EUR 3,000 is separate from the EUR 2,000 threshold in Article 11(d) of Directive (EU) 2015/849.
A remote identity-verification flow may include document capture, optical character recognition, database validation, facial comparison, and liveness detection. Sanctions screening, device-risk analysis, blockchain analytics, and ongoing transaction monitoring are separate processes that may operate alongside identity verification.
FATF guidance states that reliable digital identity can make identification easier, cheaper, and more secure and may support transaction monitoring. It also says that regulated entities and authorities should understand the system's assurance levels, technology, architecture, governance, reliability, and independence before relying on it.
Digital identity can reduce manual document handling, but it also creates privacy and security risks. A useful privacy policy explains what data is collected, why it is needed, who receives it, and how long it is retained.
KYC usually requires a player to provide personal information or verified identity attributes to an operator or verification provider. From a privacy perspective, the operator should collect only what is needed for the relevant check, protect the information, and explain the retention period.
A "no KYC" claim does not necessarily mean that the casino will never request documents. It may mean only that routine verification is not required at registration. The terms may still allow checks before withdrawal, above a transaction threshold, after suspicious activity, or when required by law.
Transactions on transparent public blockchains are publicly visible. Privacy-oriented cryptocurrencies and protocols may obscure addresses, amounts, or links between transactions, but they do not necessarily make the user legally anonymous.
Before depositing, players can check the legal operator and licensing authority, when KYC may be requested, what documents may be required, whether withdrawals can trigger additional checks, how identity and biometric data are handled, and whether "anonymous" marketing matches the terms.