You've just flagged a customer who deposits funds through three different e-wallets, makes minimal bets, and withdraws the balance within 48 hours. The account is registered in a Grey List jurisdiction. Your transaction monitoring system lit up. Your screening tool shows no direct sanctions hit, but the behavioral pattern matches FATF’s new red flags for gaming sector money laundering.
Do you block the account immediately, or do you monitor and gather more evidence?
This isn't just an academic question. The FATF published new risk indicators for gaming and gambling on September 9, 2026, drawing on responses from 80 jurisdictions. The guidance identifies the expansion of online platforms, cross-border activity, and multiple payment methods as factors increasing financial crime exposure. For compliance teams at payment processors, online gaming platforms, and banks serving the sector, these indicators create an immediate operational dilemma: how aggressive should your response be when you spot these patterns?
The Case for Immediate Blocking
Some compliance officers argue that high-risk gaming indicators warrant immediate account restrictions. Their reasoning is straightforward: the sector's velocity creates unique exposure.
When a customer uses multiple payment methods, operates accounts under different identities, or structures deposits to avoid reporting thresholds, you're looking at deliberate evasion. The FATF report explicitly flags these behaviors. Waiting to gather more evidence gives the actor time to move funds through your platform and disappear.
The regulatory risk supports this view. If you identify someone matched to sanctions lists, linked to high-risk jurisdictions, or associated with terrorist organizations and adverse media, your obligation under FATF Recommendation 6 and Recommendation 7 is clear. Freezing without delay isn't optional when you have reasonable grounds. A "wait and see" approach could put you in violation.
There's also the reputational dimension. Illegal and unlicensed gambling operators exploit regulatory differences between jurisdictions, according to the FATF findings. If your payment rails facilitate that activity, even unknowingly, you become part of the infrastructure. One Suspicious Activity Report after the fact doesn't erase the connection.
Practically, blocking is cleaner. You file your Suspicious Activity Report, document the decision, and move on. You don't tie up investigator time tracking a customer who's likely using your platform as a pass-through anyway.
The Case for Enhanced Monitoring
Other compliance teams take a different view. They argue that blocking on the first red flag creates more problems than it solves.
Start with false positives. Many legitimate customers exhibit some of the behaviors FATF describes. A frequent traveler might use multiple payment methods across jurisdictions. A customer who wins big early might withdraw funds quickly with minimal subsequent gambling activity. If you block every account that trips a single indicator, you'll alienate genuine users and create operational chaos.
The FATF guidance itself calls for a risk-based approach. That means calibrating your response to the actual threat level, not applying a binary rule. Enhanced monitoring lets you distinguish between isolated anomalies and systematic abuse. You can track whether the customer repeats the behavior, escalates the pattern, or introduces new risk factors.
There's also an evidence quality issue. A Suspicious Activity Report based on one transaction snapshot is weaker than a SAR supported by longitudinal data showing deliberate structuring or layering. If you're going to file, you want the narrative to be compelling. Monitoring gives you that depth.
From a customer relationship perspective, blocking is nuclear. If you're a payment processor serving licensed gaming operators, you can't afford to freeze accounts without solid justification. Your clients will push back hard, especially if the customer has a plausible explanation. Enhanced monitoring with conditional restrictions (transaction limits, additional verification steps) gives you a middle path.
Finally, some compliance officers point out that blocking can trigger Tipping Off risks if not handled carefully. If the customer is part of a larger network under law enforcement investigation, your abrupt action might alert other participants. Monitoring in coordination with your FIU may be the smarter play.
Where Practitioners Actually Land
In practice, most compliance teams don't pick one approach universally. They build a tiered response framework.
High-confidence indicators trigger immediate action. If screening produces a sanctions match or links to designated persons and entities, you freeze the account and file. No debate.
Medium-confidence patterns trigger enhanced monitoring with restrictions. If a customer shows multiple red flags (frequent account detail changes, discrepancies between customer and payment information, suspicious identity documents), you impose transaction limits, require additional verification, and monitor for 30 to 90 days. If the behavior continues or escalates, you escalate to MLRO and consider blocking.
Low-confidence anomalies trigger automated alerts but no immediate intervention. A single large withdrawal after a big win doesn't warrant blocking. You log it, watch for repetition, and move on.
The key is calibration. Your Customer Risk Rating should inform the threshold. A customer already rated high-risk due to jurisdiction or business type gets less tolerance than a low-risk retail user.
Our Take
Block when you have convergent evidence, monitor when you have isolated signals.
The FATF's new indicators are valuable because they describe patterns, not single events. Structuring deposits into smaller amounts to avoid reporting thresholds is suspicious. One deposit below the threshold is not. Using multiple payment methods or third-party accounts to move funds is a red flag. Using two payment methods because one failed is not.
Your transaction monitoring rules should reflect this distinction. Build scenarios that require multiple indicators within a defined time window before escalating to a human investigator. When you do escalate, give your team the authority to impose intermediate controls: enhanced verification, transaction limits, restricted withdrawal methods.
Reserve blocking for cases where you have either a direct regulatory obligation (sanctions, PEPs with adverse media, links to terrorist organizations) or a clear pattern of abuse documented over time. In those situations, speed matters more than additional data.
The risk isn't just that you'll miss financial crime. It's that you'll drown your team in false positives and train them to ignore alerts. FATF's guidance is a starting point, not a checklist. Your job is to translate those 80-jurisdiction findings into rules that work for your specific risk exposure and operational capacity.
If you can't distinguish between a customer who's laundering money and a customer who's just unlucky at blackjack, you need better data inputs before you need stricter blocking rules.



