Casino AML Risk Assessment: Compliance Guide & Best Practices Casinos sit on a paradox. They process enormous volumes of cash and high-value chip transactions every single day, which makes them a natural target for anyone trying to clean dirty money. At the same time, federal law treats them as financial institutions, subject to many of the same anti-money laundering obligations as banks.

Regulators haven't been shy about enforcing that standard. In November 2025, the Nevada Gaming Commission finalized a $7.8 million settlement with Caesars Entertainment over unsuitable methods of operation tied to illegal bookmaking activity, with remedial conditions centered almost entirely on AML program enhancements and staff training.

This guide walks through what regulators expect, how to build a defensible risk assessment, the red flags examiners look for, and the practices that keep a gaming AML program audit-ready year-round.

Key Takeaways

  • Casinos above the BSA revenue threshold are financial institutions and must run a written, risk-based AML program.
  • Credible risk assessments score real products, customers, geography, and channels—not generic templates.
  • Structuring, chip walking, and third-party funding are top red flags examiners cite.
  • Refresh risk assessments at least annually, or sooner when products, markets, or rules change.
  • Independent review from financial crime advisors can catch program gaps before an exam.

Are Casinos Required to Comply with Anti-Money Laundering Regulations?

Yes. Under 31 CFR 1010.100(t), any casino licensed under state, tribal, or territorial law with gross annual gaming revenue exceeding $1 million is defined as a financial institution under the Bank Secrecy Act. That designation isn't optional, and it applies to headquarters and domestic branches alike.

Federal Requirements Under the BSA and USA PATRIOT Act

The Bank Secrecy Act, reinforced by Section 352 of the USA PATRIOT Act, sets the baseline. Covered casinos must:

  • Maintain a written, risk-based AML compliance program
  • Designate a compliance officer responsible for day-to-day oversight
  • Keep records of large transactions and suspicious activity
  • File reports with FinCEN when statutory thresholds are met

FinCEN serves as the primary federal regulator for casino AML. It has issued specific casino guidance over the years, including risk-based compliance indicators, program assessment criteria, and red flag advisories that shape how examiners evaluate a program's adequacy.

Tribal, State, and Card Club Considerations

Federal BSA rules don't operate in isolation. Tribal casinos have been subject to AML controls since 1996, layered on top of oversight from the National Indian Gaming Commission and its Minimum Internal Control Standards.

State-licensed casinos face similar layering. In California, for example, the Gambling Control Commission handles licensing and ownership transactions while the state's Bureau of Gambling Control runs compliance inspections and enforcement. Card clubs fall under the same federal BSA framework as traditional casinos.

The takeaway: federal, state, and tribal requirements stack, and a compliant program has to satisfy all applicable layers, not just the one that feels most relevant.

Federal state and tribal casino AML regulatory layers overlapping diagram

The Five Pillars of an Effective Compliance Program

The USA PATRIOT Act built four core pillars into every covered AML program:

  • A designated compliance officer
  • Internal policies and controls
  • Independent testing
  • Ongoing employee training

Casino-specific rules under 31 CFR 1021.210 add another layer: requirements to use available customer and transaction information and, where systems allow, automated compliance tools.

Many practitioners now refer to customer due diligence as a "fifth pillar," but that formal CDD rule technically applies to banks, broker-dealers, and a handful of other covered institutions rather than casinos directly. Casinos still perform CDD-like functions under 1021.210, including identity verification, pattern detection, and recordkeeping, even without being named in that 2018 rule.

How to Conduct a Casino AML Risk Assessment (Step-by-Step)

A casino AML risk assessment is the foundation for staffing decisions, monitoring thresholds, and training priorities. Skip this step or rush it, and the rest of the program inherits the weakness.

Step 1: Identify Inherent Risk Categories

Before scoring anything, map risk across four areas:

  • Products and services: table games, slots, cage operations, marker accounts
  • Customer base: high rollers, junket players, walk-in traffic
  • Geographic footprint: proximity to borders, HIFCA or HIDTA zones
  • Delivery channels: in-person floor activity versus remote or online wagering

Step 2: Score Risk Using Objective Criteria

Assign low, medium, or high ratings to each category using measurable data rather than gut feel. Objective inputs include:

  • Transaction volumes
  • Mix of cash-intensive game types
  • Customer demographics

A casino with a heavy cage/marker business and a large non-resident clientele will score differently than a small regional slot parlor.

Step 3: Evaluate Existing Controls to Determine Residual Risk

Inherent risk is only half the picture. Assess how strong current controls actually are (CDD procedures, transaction monitoring, and reporting workflows) to arrive at residual risk after mitigation. This is where examiners tend to find the most gaps: a control that looks good on paper doesn't always hold up in daily practice.

Step 4: Document, Govern, and Obtain Sign-Off

Write the methodology down, show your work, and get senior management or board approval on record. Regulators want to see governance, not just a spreadsheet. Bringing in a CAMS-certified advisor to independently validate the methodology can add credibility that examiners notice.

Step 5: Establish a Review Cadence and Update Triggers

Refresh the assessment at least annually. Beyond that fixed schedule, update it whenever something changes materially:

  • New products or game types launch
  • Mergers, acquisitions, or ownership changes take place
  • Regulatory guidance changes
  • Prior-year SAR patterns show new trends

5-step casino AML risk assessment process from identification to review

Key Risk Factors Every Casino Should Evaluate

These are the specific inputs that feed the scoring exercise above: the "what" behind the risk assessment process.

Business and Operational Risk Indicators

Operational factors that push inherent risk higher include:

  • High-limit table games with large cash exposure
  • Cage and marker account services
  • Proximity to High Intensity Financial Crime Areas (HIFCA), High Intensity Drug Trafficking Areas (HIDTA), or international borders
  • Third-party check-cashing arrangements

Customer Risk Indicators

Certain patron profiles carry elevated risk:

  • Non-resident aliens from jurisdictions the U.S. flags as higher risk
  • Politically exposed persons (PEPs), including closely related family members
  • Patrons whose spending appears inconsistent with known income
  • Individuals on barred or self-exclusion lists

Red Flags Signaling Potential Money Laundering

FinCEN's guidance on recognizing suspicious activity points to specific, observable behaviors rather than vague suspicion. Watch for:

  • Structuring: Reducing a cash-out below $10,000 after an ID request, or splitting a large marker payment into sub-threshold transactions in one gaming day
  • Chip walking: Buying in heavily, gaming minimally, then leaving with chips and no known disposition
  • Third-party cash-outs: Having someone else redeem chips to avoid CTR or tax reporting
  • Identification issues: Presenting conflicting, altered, or false ID, or shrinking a transaction once ID is requested

Customer Due Diligence and Reporting Obligations

A casino's KYC program verifies patron identity, screens against OFAC and other sanctions lists, and applies enhanced due diligence to PEPs and other elevated-risk accounts. From there, three reporting obligations drive most day-to-day BSA compliance.

Currency Transaction Reports (CTRs) are required for each cash-in or cash-out transaction exceeding $10,000. Multiple smaller transactions get aggregated when the casino knows they belong to the same person and combined cash-in or cash-out tops $10,000 in a single gaming day.

Suspicious Activity Reports (SARs) are required for transactions totaling at least $5,000 when the casino knows, suspects, or has reason to suspect illegal proceeds, structuring, or no apparent lawful purpose. File within 30 days of detection, or within 60 days if no suspect has been identified.

Beyond CTRs and SARs, casinos must maintain a Negotiable Instrument Log for checks, money orders, and similar instruments valued at $3,000 or more. Each entry should capture:

  • Date and amount
  • Customer details
  • Issuing employee

CTRs, SARs, and the Negotiable Instrument Log together set the core BSA recordkeeping standard for casinos.

Best Practices for Building a Scalable, Audit-Ready AML Program

Volume grows. Manual review doesn't scale with it. Casinos that lean on technology for transaction monitoring and risk scoring tend to see better alert quality and less analyst burnout than those relying on spreadsheets and tribal knowledge.

A few practices consistently separate strong programs from ones that struggle in an exam:

  1. Automate what can be automated: use monitoring systems to flag patterns like structuring or chip walking so staff can focus on real investigations, not false positives.
  2. Build a real culture of compliance: ongoing, role-specific training beats a single annual session; cage staff need different scenarios than pit bosses or marketing teams.
  3. Test independently, and often: periodic independent testing catches gaps before an examiner does, and benchmarking against current expectations keeps the program current.

Outside expertise often pays for itself here. Firms focused on financial crime compliance, such as Pillars FinCrime Advisory, help fintechs, payments companies, and financial institutions design risk assessments, build policies, optimize transaction monitoring, and prepare for regulatory exams.

Founded by CAMS-certified Joshua Douglas, Pillars supports the full program lifecycle, from the initial risk assessment through documented, board-ready governance. That model fits gaming and payments-adjacent operators who face the same cash-intensive risks casinos do.

For an operator closing gaps before they become findings, practical end-to-end support can mean the difference between passing an exam and explaining a deficiency letter.

Financial crime compliance advisors reviewing casino AML program documentation

Frequently Asked Questions

How do you conduct a casino AML risk assessment?

Identify inherent risk across products, customers, geography, and delivery channels, then score each category with objective data. Evaluate existing controls for residual risk, document the methodology with formal sign-off, and review it on a set schedule.

Are casinos required to comply with anti-money laundering (AML) regulations?

Yes. Casinos with gross annual gaming revenue exceeding $1 million are classified as financial institutions under the Bank Secrecy Act and must maintain a written, risk-based AML compliance program.

What are common red flags for money laundering in casinos?

Structuring cash transactions below reporting thresholds, chip walking, using third parties to cash out winnings, and spending patterns inconsistent with a patron's known income are common red flags.

How often should a casino update its AML risk assessment?

At minimum, annually. Updates should also happen whenever the casino launches new products, expands into new jurisdictions, or regulatory guidance changes materially.

What is the difference between a CTR and a SAR in a casino setting?

A CTR is a mandatory report for cash transactions exceeding $10,000, filed regardless of suspicion. A SAR is filed for suspicious activity involving $5,000 or more, based on suspected illegal activity rather than cash volume alone.

What penalties can casinos face for AML compliance failures?

Penalties range from civil monetary fines to consent orders and license restrictions. In March 2025, Nevada regulators fined Resorts World Las Vegas $10.5 million after acknowledging its AML program needed enhanced source-of-funds controls.