SupportIf gambling is causing harm, call GamCare free on 0808 8020 133, 24 hours, or visit gamcare.org.uk. GamStop.co.uk
Payments · UK 2026

Payments and checks, banks, cards, crypto, KYC

This is the payments chapter, written from inside the UK banking rails rather than from the operator side. It takes the Money Laundering Regulations 2017 as the starting point, sets out what a UK issuer sees on the wire when a cardholder pushes a debit to a Curaçao-licensed acquirer under merchant category code 7995, and walks through the customer-facing gambling switch on HSBC, Monzo, Starling, Lloyds and Barclays current-account cards, the enhanced customer due-diligence that runs when value or frequency shifts, the Suspicious Activity Report that follows a live suspicion, and the routes a UK reader is often told about that all end at the same source-of-funds question one hop later. Read it in one sitting or by section from the table of contents below.

  • 18+
  • Independent
  • Public sources
Illustration for payments and checks under UK banking rules
01

UK Money Laundering Regulations 2017 in a paragraph

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, universally shortened to the MLR 2017, are the operating statute for anti-money-laundering compliance across the UK regulated sector. They implement the Fourth and Fifth EU Anti-Money-Laundering Directives (4AMLD and 5AMLD) in domestic form and now sit alongside the criminal-liability scope of the Sixth Directive (6AMLD) as it applies to firms in the UK. For a UK bank, an e-money institution or a payment-service provider, the Regulations do not describe good practice; they describe legally mandatory behaviour. Every regulated firm has to run a written risk assessment under Regulation 18, apply customer due diligence under Regulation 27, apply enhanced due diligence under Regulation 33 where the transaction, customer or geography sits inside a higher risk band, run continuous monitoring under Regulation 28, and file internal Suspicious Activity Reports through its Money Laundering Reporting Officer to the National Crime Agency where knowledge or suspicion of laundering arises. The Financial Conduct Authority is the supervisor for banks, e-money institutions and payment-service providers, and its FCA Handbook Financial Crime Guide, currently at FCG 3 for AML systems and controls, is the operative day-to-day source that a compliance team writes its rules against.

What that means for the reader is that any UK-regulated payment institution touching a gambling debit sits inside a policy that already treats gambling as a higher-risk activity for AML purposes, not because gambling itself is unlawful, but because the sector generates the cash-like flow patterns that laundering typologies rely on. A UK-issued card is one endpoint of that policy. A UK current account, an e-money wallet, a Faster Payments push and a card-scheme pull are all endpoints of the same policy. When the transaction sits inside UKGC remit, the operator at the far end is also inside its own layer of the same policy, and the two layers reinforce each other. When the transaction sits outside UKGC remit at a Curaçao-licensed operator, the operator's own compliance layer sits under a different statute, but the UK-side layer does not change. The UK issuer still has to apply MLR 2017, still has to run enhanced due diligence at value or pattern thresholds, still has to file the internal report where suspicion arises. The offshore boundary of UKGC remit does not create an offshore boundary of the Money Laundering Regulations. The payment, from the issuer's perspective, is still a UK payment.

02

How offshore KYC differs from UKGC-licensed KYC

Know Your Customer under a UKGC-licensed operator is written against the UKGC Licence Conditions and Codes of Practice (the LCCP), the FCA Handbook where the operator is also a payment institution, and MLR 2017 where the operator is treated as a relevant person under Schedule 1. The result is that a UKGC-licensed operator is expected to identify the customer at sign-up, verify identity to a documentary or electronic standard, apply ongoing monitoring to the account, run affordability assessments in the shape set by the 2023 White Paper and the follow-up UKGC consultation on financial risk checks, and hold the customer due-diligence file in a form that can be produced to the UKGC on request. The customer sees this as identity checks at deposit, source-of-funds prompts at a certain volume of play, deposit limits offered as a mandatory affordability tool, and periodic re-verification when a return trigger fires. The visibility of the checks to the customer is a design feature; the whole point of the framework is that the customer knows the operator is watching the account.

Offshore KYC does not sit under any of those UK layers. A Curaçao-licensed operator under the Landsverordening op de Kansspelen in force since 24 December 2024 sits under the Curaçao Gaming Authority as the single regulator, and its player-verification obligations follow a regulator that is now more visible than it was under the pre-LOK master-licence system, but not under UK statute. The identity check the customer sees at the offshore operator does not produce a file the UKGC can inspect, does not carry a UK data-subject route under UK GDPR, and does not translate into any ability to force a withdrawal in a UK complaint context. What the reader tends to encounter in practice is a lighter identity flow at sign-up followed by a heavier one at first withdrawal, which is the reverse of what a UKGC-licensed operator would do and which is the pattern that fund-holding complaints against offshore operators most often begin with. The identity risk is not that the operator does no checks; it is that the checks fall in a different order and are not enforceable from the UK end.

A closer look

Two second-order differences follow from the ordering. The first is that a UKGC-licensed operator has to reconcile its customer file against the file the UK issuer would produce if asked, because both are subject to compatible UK data-protection and AML statutes. An offshore operator does not, which means the two files can drift apart and the customer only discovers the drift at the withdrawal moment. The second is that a UKGC-licensed operator carries affordability duties that use the same source-of-funds and source-of-wealth concepts that the issuer applies, whereas an offshore operator carries its own local affordability layer if any. A UK cardholder pushing four-figure sums to a UKGC-licensed operator will be seen by two aligned compliance surfaces. The same cardholder pushing four-figure sums to an offshore operator will be seen by one UK-side surface and one offshore surface that do not talk to each other, and the mismatch produces most of the friction that surrounds a large withdrawal.

03

Bank blocks and card gambling switches in 2026

The voluntary gambling switch is now standard across UK retail banking. HSBC operates a gambling block that can be enabled from the mobile-banking app, applies at the card-authorisation layer against any merchant coded to MCC 7995, and requires a cool-off period of a set number of hours between the customer toggling the block off and the next attempt at a gambling authorisation. Monzo runs the same architecture, was one of the first challenger banks in the UK to launch it, and applies a longer cool-off period; Starling runs a comparable switch with a similar cool-off; Lloyds and Barclays each run a gambling toggle at the account level with a cool-off between the off action and the first successful gambling debit that follows. The design of the cool-off is deliberate. It sits inside the behavioural evidence on urge-management and, in the same clinical literature as the GamStop twenty-four-hour post-expiry cool-off, treats a delay window between the intention and the transaction as a safety layer rather than as a bureaucratic hurdle.

The switch operates on the authorisation, not on the settlement. That distinction matters. When a cardholder attempts a gambling deposit, the acquirer sends an authorisation message to the issuer through the card scheme, tagged with the acquirer-supplied MCC. The issuer's authorisation engine reads the MCC on the inbound message, checks the account-level rules including any active gambling block, and returns approve or decline in real time before the transaction ever reaches the operator's cashier. If the block is on, the cashier sees a soft decline. The customer sees an app notification and, on most banks, a link to the switch settings. The offshore operator often responds to the decline with a suggestion to use another card, which is precisely the workaround pattern the switch is designed to interrupt, because the block is per-account rather than per-card and the same account holder toggling a switch on will have every gambling authorisation on every attached card returned as a soft decline.

04

Visa, Mastercard and the UKGC 2025 taskforce

Merchant category code 7995 is the four-digit code that the card schemes use to identify gambling-transaction merchants. It covers online casinos, online sports betting, lotteries where wagered, and other betting-transaction categories. The acquirer is contractually required to code the merchant correctly under the scheme rules, and the schemes audit routing. In 2025 the UK Gambling Commission established a joint taskforce with Visa and Mastercard to tighten enforcement of gambling MCC classification at the acquirer level, on the observation that a proportion of offshore gambling volume had been misrouted under non-gambling merchant categories such as digital goods, entertainment or e-commerce general, and that misrouting defeated both the gambling switches on UK issuer cards and the block-notifications customers had chosen through their banking apps. Under the taskforce work, an acquirer that misclassifies a gambling merchant now faces scheme-side consequences that materially exceed the position two years ago.

The practical outcome for a UK cardholder is that a non-GamStop deposit made against an offshore operator whose acquirer is compliant with the schemes will read as MCC 7995 to the issuer and will hit whatever gambling controls the cardholder has enabled. A deposit made against an offshore operator whose acquirer is not compliant may still authorise, but the position is unstable at the scheme layer. The card schemes have shown willingness to withdraw processing rights from acquirers found to be persistently misrouting gambling volume, and where that withdrawal happens the operator loses its card-scheme rail overnight. From the reader's perspective the takeaway is that a live card payment to an offshore operator is a live payment at the schemes' discretion; the payment is not covered by UKGC dispute rules; and the acquirer's own regulatory position is more fragile than the operator's advertising typically suggests.

Key points

  • Every UK card debit sits inside MLR 2017 regardless of the operator's licensing jurisdiction
  • MCC 7995 catches the gambling switch on HSBC, Monzo, Starling, Lloyds and Barclays cards at authorisation
  • The Visa and Mastercard 2025 taskforce with the UKGC has tightened acquirer-side enforcement of MCC 7995 routing
  • Enhanced due diligence under Regulation 33 of MLR 2017 kicks in on pattern shifts, not only on value
05

Crypto rails and why they still hit KYC eventually

The crypto rail is the most persistently misdescribed payment route in the non-GamStop conversation. A UK adult who buys cryptocurrency to fund an offshore gambling account does not sidestep UK AML checks; they front-load them. The Financial Conduct Authority is the supervisor for cryptoasset firms operating in the UK under the Money Laundering Regulations 2017 (as amended by the 2019 amending regulations that brought crypto into scope), and every UK-registered cryptoasset firm has to apply the same customer due diligence and continuous monitoring that a bank applies to a fiat account. The customer opening a UK-registered exchange account provides identity documents at sign-up, sees source-of-funds prompts at deposit thresholds, and can be asked source-of-wealth questions above internal review triggers. The exchange rail is not lighter-touch than the card rail; it is a rail that runs its checks earlier and in a slightly different vocabulary.

Once the coin leaves the exchange and lands at the operator, a second layer applies. Offshore operators typically enforce their own crypto-side KYC before permitting withdrawal, and travel-rule requirements under FATF Recommendation 16, mirrored into UK-registered exchange terms, require the exchange to hold identifying information on the originator and beneficiary for transfers above a threshold. The result is that a coin bought on a UK-registered exchange, sent to an offshore operator's wallet, played through, and later withdrawn will encounter identity verification at the operator side and, at the point of moving fiat back to a UK bank account through a UK-registered exchange, will encounter source-of-funds prompts on the return leg. Every step that a UK reader is told bypasses KYC in practice hits KYC one step later, and the delayed check is usually harder to satisfy than the check that would have applied at the front of the flow.

A closer look

Peer-to-peer routes, unregulated exchanges and self-custody wallets can move a coin without the UK-side check, but they cannot solve the final-mile problem. A withdrawal from an offshore operator into a peer-to-peer route, or into a wallet self-custodied by a UK resident, eventually needs to be converted to sterling to be spent on anything sitting in the UK economy. That conversion happens at a regulated exchange, and the exchange applies its checks at the sterling-out step. The customer who avoided KYC at the front of the flow now meets it at the back, without the transaction history that a front-loaded flow would have produced. This is the pattern that most withdrawal-side disputes at the offshore end trace to, and it is the pattern that the reader is least often warned about at the point of deposit.

06

When your bank flags a suspicious deposit

A UK bank flags a transaction under a set of internal rules that turn value, frequency, merchant category, geography and behavioural change into automated review triggers. On the gambling-adjacent surface, the specific rules a UK reader will encounter tend to run against three axes. The first is single-transaction value, where a debit above an internal threshold, typically expressed as a rolling seven-day or thirty-day figure, opens a review case. The second is aggregate value within a window, where a sequence of smaller debits accumulating above a threshold in a rolling window opens a review even if no single debit reached the single-transaction limit; this is the anti-structuring rule that catches the classic small-and-frequent pattern. The third is pattern shift, where an account that has not previously carried gambling debits begins carrying them, or where the merchant fingerprint changes, or where the account starts sending Faster Payments to named beneficiaries whose merchant type is not visible on the wire in the way an MCC would be.

When a review opens, the customer typically sees an in-app message asking for a plain-English explanation of the source of funds. The message is not an accusation and it does not indicate that a Suspicious Activity Report has been filed. In most cases the review closes on the customer's response, the account carries on, and the internal note sits on file to inform the next review if one runs. Where the response does not satisfy the reviewer, the case can escalate to enhanced due diligence, at which point the customer may be asked for documentary evidence such as payslips, tax records, or statements from a linked account, and the review timeline extends. During an active review the account can be subject to transactional friction; some issuers hold outbound gambling debits until the review closes, some restrict card-not-present transactions across the board, and some apply no restriction at all. The specific pattern depends on the firm and on the internal risk score of the account.

Worth noting A source-of-funds request from a UK issuer is not evidence of wrongdoing and does not carry any consequence in itself. It is a Regulation 28 monitoring step; most cases close on a plain-English explanation. Withholding the response, however, will escalate the review, not defuse it.
07

What a Suspicious Activity Report actually is

A Suspicious Activity Report, or SAR, is an internal report filed by a UK regulated firm to the National Crime Agency under sections 330 to 332 of the Proceeds of Crime Act 2002 (as amended) and, in the terrorism-financing context, under Part 3 of the Terrorism Act 2000. The reporting duty falls on the firm's nominated officer, in most banks the Money Laundering Reporting Officer, who filters internal escalations against the statutory threshold and lodges a report where the threshold of knowledge or suspicion is met. A SAR is a report; it is not a finding, not an accusation, and not evidence of wrongdoing. The customer is not usually informed at the time of filing, both because tipping-off is a separate offence under section 333A of the same Act and because the SAR system's purpose is to feed intelligence to the NCA's Financial Intelligence Unit rather than to shape the day-to-day customer experience.

In the gambling-adjacent context, SARs are filed against a range of unusual value or frequency patterns, against inconsistencies between deposits and the customer's stated income profile, against structured deposits below reporting thresholds, and against payment routes that a compliance team has already tagged as higher-risk. Ordinary UK adult gambling activity, at values consistent with the account's income profile, at operators the customer has been using for a period, and without other risk markers, does not produce a SAR by default. Reading press coverage that suggests otherwise is one of the more common misunderstandings in this area; the compliance surface is designed to fire on pattern, not on the mere presence of gambling debits. The SAR system exists to catch laundering typologies that use gambling as a wrapper, and the vast majority of UK gambling customers never come close to the threshold. Where a SAR is filed against an account, the customer usually notices only through downstream account restrictions, and even that is not universal.

08

Practical steps to reduce personal risk

The practical harm-reduction steps on the payments side of this topic are the ones that any UK adult can take without asking the bank's permission and without reading any operator's terms. Enable the gambling switch on the current-account card through the mobile-banking app, so that any gambling authorisation returns as a soft decline at the issuer before it reaches the operator's cashier. Review the direct-debit and standing-order list monthly for any subscription that carries a gambling adjacency, from lottery syndicates through to the small monthly draws that can drift below the attention line. Set a spending alert on the account at a threshold well below the review triggers the bank will otherwise apply on its own, so the notification arrives from the reader's own settings rather than from a compliance case being opened. Keep salary and gambling activity in separate mental columns by using a savings pot or a linked account for the discretionary spend, so the gambling column is capped by the transfer rather than by the account balance.

On the identity side, keep the source-of-funds explanation legible before it is asked for. That means holding statements, payslips and tax records in one place, so that a Regulation 28 monitoring prompt is a five-minute reply rather than a two-week search. If the reader is deep offshore and the account statement has started to read like a foreign-currency ledger, the money-management strand is the entry point rather than the operator strand. A conversation with GamCare on 0808 8020 133 sits at the front of that route. A conversation with StepChange, National Debtline or the Debt Advice Foundation sits behind it if credit lines have already been touched. And the coming-off route through the official GamStop portal, if a self-exclusion has been considered and not activated, remains the single most durable payment-side control that a UK reader has access to, because it stops the deposit at the operator hand-off rather than at the wire.

Read next

Sources and verification

Verified against UK Gambling Commission published guidance and Money Laundering Regulations 2017 as amended, held at gamblingcommission.gov.uk and gov.uk. Last checked 5 August 2026.

O
Written by Oliver Ashton-Reed
Reviewed by Yasmin Cardoso, ex-Monzo AML compliance lead, updated 5 August 2026

Frequently asked questions

What is merchant category code 7995 and why does it matter for a non-GamStop deposit

MCC 7995 is the Visa and Mastercard four-digit code for gambling-transaction merchants, including online casinos, sports books and lotteries. When a UK-issued card authorises a transaction to a merchant coded 7995, the issuer sees it as gambling before the transaction is settled, and any account-level gambling switch, block or transaction limit will act on the authorisation at that point. The offshore acquirer may attempt to route the transaction under a different code, but the schemes now audit routing under the 2025 taskforce and misclassified gambling volumes carry material scheme-side consequences for the acquirer.

Do HSBC, Monzo, Starling, Lloyds and Barclays gambling switches work at offshore operators

Yes, when the offshore merchant is correctly coded to MCC 7995 the gambling switch sits at the authorisation layer of the card and returns a decline regardless of the operator's licensing jurisdiction. The switch does not care whether the merchant sits inside UKGC remit; it cares about the merchant category the acquirer submits. All five issuers now apply a cool-off between the customer toggling the switch off and the first successful gambling authorisation that follows, and Monzo and Starling apply the longer cool-off of the group.

Can I get around the switch by using a different payment method

This site does not describe workarounds. In factual terms, prepaid instruments funded from a UK current account still originate the funds inside that account and are subject to the account holder's own AML monitoring; e-money accounts sit under the same Money Laundering Regulations 2017; and cryptocurrency purchased through a UK-registered exchange is subject to KYC and source-of-funds prompts at the exchange before it reaches any wallet. Every route that begins in a UK bank account ends up inside the UK AML surface at one hop or another.

What triggers a source of funds request from my bank

Value thresholds and pattern shifts. A single deposit large enough to sit above an internal rule threshold, a sequence of smaller deposits that aggregate above the same threshold in a rolling window, a change of merchant, a change of frequency, or a mismatch between the deposit pattern and the salary credit sitting on the account will each trigger a review under the second-line customer due-diligence work required by Regulation 28 of the Money Laundering Regulations 2017. The customer usually sees the review as an in-app message asking for a source-of-funds explanation and, at higher thresholds, source of wealth.

What is a Suspicious Activity Report and does it mean I have done something wrong

A Suspicious Activity Report is an internal report filed by a UK regulated firm to the National Crime Agency under sections 330 to 332 of the Proceeds of Crime Act 2002 where the firm has knowledge or suspicion of money laundering. It does not amount to a finding, it is not an accusation, and the customer is not usually informed at the time of filing. In the gambling-adjacent context most SARs sit against unusual value or frequency patterns rather than against the fact of gambling itself, which is a legal adult activity in the UK.

Talk to someone today

The National Gambling Helpline is free, confidential and open 24 hours a day, seven days a week.

0808 8020 133 GamCare, free, 24 hours