AML & KYC Policy

Last updated: 1 September 2026. How we verify players, monitor activity and meet our anti-money-laundering obligations.

1. Purpose and scope

This policy sets out how AUBET33 prevents its platform being used to launder money, finance terrorism or move the proceeds of crime. It applies to every account, every transaction and every member of staff, and it is a condition of our gaming licence. Where this policy conflicts with a player's preference, the policy prevails.

2. Regulatory framework

Our programme is built on the Financial Action Task Force (FATF) recommendations as applied to the gambling sector, the AML requirements of our licensing jurisdiction, and the requirements imposed on us by our payment partners and card scheme rules. It is reviewed at least annually and after any material change in our risk profile.

The programme is owned by a designated Money Laundering Reporting Officer (MLRO), who reports to the board, has authority to freeze accounts and suspend payouts, and is the point of contact for our regulator and for law enforcement. The MLRO can be reached at [email protected].

3. Verification (Know Your Customer)

Verification is mandatory before the first withdrawal, and may be requested earlier where risk indicators are present. We require:

  1. Proof of identity — a valid government-issued photo ID (passport, national ID card or driving licence) showing full name, date of birth, document number and expiry date.
  2. Proof of address — a utility bill, bank statement or government correspondence dated within the last three months, showing name and residential address.
  3. Proof of payment method ownership — for cards, an image showing the cardholder name with only the first six and last four digits visible and the CVV obscured; for e-wallets, a screenshot of the account profile; for bank transfers, a statement header; for crypto, confirmation of wallet control.

Documents must be clear, in colour, unedited and show all four corners. Reviews are normally completed within two hours. If a document is rejected we tell you why and what to send instead.

Never send us your full card number, CVV or online banking password. We will never ask for them, and any message that does is not from us. Report it to [email protected].

4. Due diligence tiers

Checks are risk-based and escalate with cumulative activity:

TierTriggerChecks applied
Tier 1 — Standard At registration Age and identity declaration, email and mobile confirmation, device and IP risk scoring, sanctions screening
Tier 2 — Full CDD First withdrawal, or cumulative deposits of $2,000 Documentary ID, proof of address, proof of payment-method ownership
Tier 3 — Enhanced (EDD) Cumulative activity of $15,000, PEP match, high-risk jurisdiction, or an alert from monitoring Source-of-funds evidence, occupation and expected activity profile, senior management sign-off
Tier 4 — Source of wealth Cumulative activity of $50,000, or a single payout above $50,000 Full source-of-wealth documentation, ongoing enhanced monitoring, MLRO approval before release

5. Source of funds and wealth

Where enhanced due diligence applies we may ask for one or more of the following. We ask for the least we need, and we explain why:

  • Recent payslips or an employment contract.
  • Bank statements covering three to six months.
  • Tax returns or an accountant's letter for self-employed players.
  • Evidence of a specific one-off source — a property sale, inheritance, dividend, business sale or investment disposal.
  • For crypto funds, the transaction history and, where required, a blockchain analytics report on the originating wallet.

Where satisfactory evidence is not provided, we will restrict the account, return the verified deposits to source where lawful to do so, and close the relationship.

6. Payment controls

  • Own name only. Third-party deposits and withdrawals are prohibited and returned to source.
  • Closed loop. Withdrawals return to the depositing method up to the amount deposited before any alternative method is used.
  • Minimum play. Funds must be wagered at least once before withdrawal, to prevent the account being used as a pass-through.
  • No cash equivalence. We do not transfer balances between player accounts and do not offer any player-to-player transfer feature.
  • Anonymity limits. Privacy coins and mixing services are not accepted. Crypto deposits are screened for exposure to sanctioned, darknet or high-risk addresses.
  • Structuring. Repeated deposits just below a reporting or verification threshold are treated as a risk indicator in their own right.

7. Transaction monitoring

Automated rules run continuously against every account and raise alerts for manual review. Indicators include:

  • Deposits followed by withdrawal with little or no play.
  • Deposit volume inconsistent with the player's stated profile.
  • Rapid succession of deposits from multiple instruments or cards.
  • Multiple accounts sharing a device fingerprint, IP address or payment instrument.
  • Offsetting or low-risk betting patterns between linked accounts.
  • Frequent cancellation of withdrawals followed by further play.
  • Activity from a jurisdiction we do not serve, or signs of VPN use to conceal location.
  • Reluctance to complete verification, or documents that appear altered.

Alerts are reviewed by trained compliance analysts. An account may be restricted or frozen while a review is in progress; we are not always permitted to tell the player why.

8. Sanctions and politically exposed persons

Every player is screened at registration and rescreened daily against consolidated sanctions lists (including UN, OFAC, EU and UK lists) and against PEP and adverse-media databases. A confirmed sanctions match results in immediate blocking of the account and a report to the competent authority. A PEP match does not prevent an account, but triggers enhanced due diligence and senior management approval before the relationship continues.

9. Reporting obligations

Where the MLRO has knowledge or suspicion of money laundering or terrorist financing, a Suspicious Activity Report is filed with the relevant Financial Intelligence Unit within the statutory deadline. We may not inform the player that a report has been made — doing so is a criminal offence in most jurisdictions ("tipping off"). We will not process a transaction where doing so would place us in breach of the law, and we cooperate fully with lawful requests from regulators and law enforcement.

10. Record keeping

Identity records, verification documents, transaction histories, monitoring alerts and internal reports are retained for five years from the end of the business relationship or from the date of the transaction, whichever is later. Records are stored encrypted with access limited to authorised compliance personnel. Retention periods are set out in the Privacy Policy; AML records cannot be deleted at a player's request.

11. Training and governance

  • All staff complete AML and counter-terrorist-financing training on induction, and refresher training annually.
  • Customer-facing and payments staff receive additional role-specific training on typologies and escalation.
  • The MLRO reports to the board at least quarterly on alerts, reports filed and programme effectiveness.
  • The programme is subject to independent review at least annually, and findings are remediated on a deadline set by the reviewer.
  • Staff can escalate concerns to the MLRO confidentially and are protected from retaliation for doing so.

12. What this means for you

For the overwhelming majority of players, the entire AML programme amounts to one document upload before the first withdrawal. To keep it that simple:

  • Register with your real name and date of birth, exactly as they appear on your ID.
  • Only use payment methods in your own name.
  • Upload verification documents early — before you need to withdraw, not after.
  • Respond promptly if we ask a question. Most reviews close the same day when they do.
  • If something about a request seems unusual, contact [email protected] and ask. We would rather explain than have you guess.

Questions about verification or this policy: [email protected]. Related documents: Terms & Conditions, Privacy Policy, Payment Methods.