Every gaming licence you can buy comes with policy conditions attached, and almost every operator treats them as paperwork to be produced once and filed. That is the mistake. The AML programme, the responsible gaming policy and the player terms are the first documents a payment provider asks for at onboarding, the first thing a regulator tests when a complaint lands, and the reason licences get suspended rather than fined.
This is what the policy pack actually has to contain, who it has to satisfy, and where template documents fail. Curacao licensees have a hard deadline of 8 October 2026 for the player terms overhaul specifically, covered in the LOK deadlines guide.
The four documents, and who reads each one
- AML programme. Read by the regulator at application, by your bank and payment providers at onboarding, and by an auditor if anything goes wrong. It is the document that carries criminal exposure if it is ignored in practice.
- KYC procedures. Operationally the most important, because it is the one your staff actually follow. Thresholds, document standards, escalation and record retention.
- Responsible gaming policy. Read by the regulator and increasingly by game suppliers, who do not want their content on a site that ignores problem gambling.
- Player terms of service. Read by players, by the regulator when a dispute is escalated, and by you when you refuse a withdrawal. This is where disputes are won or lost.
What an AML programme has to contain
A programme that satisfies a licence condition and survives a bank's due diligence needs all of the following, not a subset:
- A named Money Laundering Reporting Officer with defined authority, a deputy, and a documented reporting line. Curacao requires this expressly under the LOK.
- A written risk assessment covering your customer base, geographies, products and delivery channels. Generic risk assessments are the clearest sign of a template pack.
- Customer due diligence tiers with monetary thresholds, plus the triggers for enhanced due diligence: politically exposed persons, high-risk jurisdictions, unusual deposit patterns.
- Ongoing transaction monitoring with defined red flags and who reviews them.
- Suspicious transaction reporting to the correct authority in your licence jurisdiction, with timeframes and a no-tipping-off rule.
- Record retention, typically five to seven years depending on jurisdiction.
- Training and annual review, both evidenced.
Crypto changes the AML picture
Most template AML packs were written for fiat operations and retrofitted badly. A crypto casino needs specific provisions that fiat templates simply do not contain:
- Wallet screening and blockchain analytics. Which provider, what risk scores trigger review, and what happens to a deposit from a sanctioned or mixer-linked address.
- Source of funds for crypto. Exchange withdrawal records and transaction history, not a bank statement that will never exist.
- Handling of privacy coins and of deposits routed through mixers or bridges: state the position rather than leaving staff to improvise.
- Volatility and conversion. How deposit value is fixed for threshold purposes when the asset moves between deposit and play.
- Freeze and return procedure for a deposit you cannot clear, including who authorises it and what the player is told.
That last point matters more than it looks. Freezing funds without a documented procedure is how an AML measure becomes a player dispute, a chargeback and a regulator complaint at the same time.
Responsible gaming: the tooling has to exist
A responsible gaming policy is only credible if the platform can actually deliver what it promises. Before you sign the policy, confirm your platform supports deposit limits, loss and wager limits, session reminders, cooling-off periods, and self-exclusion that genuinely blocks re-registration rather than merely hiding the account.
Accepting a policy obligation your software cannot perform is a licence risk, not a documentation risk, and it is a common outcome when the policy pack is drafted by one party and the platform chosen by another. Check the platform agreement against the policy, using the clauses that decide your exit as a checklist.
Player terms: where disputes are actually decided
When a player escalates a withheld withdrawal, the regulator reads your terms. Vague or unfair terms lose, and increasingly the terms themselves are assessed for fairness rather than merely enforced as written.
The clauses that generate almost every dispute: bonus wagering requirements and maximum win caps, dormant account charges, account closure and fund return, identity verification timing, and withdrawal processing periods. Each needs to be specific, and each needs to say what happens rather than reserving unlimited discretion. A term giving you sole and absolute discretion to void winnings reads well in a template and fails in front of a regulator.
Crypto operations need their own provisions: which assets are accepted, how conversion is calculated, what happens to a deposit sent on the wrong network, and whether withdrawals are returned to the depositing wallet.
Why template packs fail
- They name the wrong regulator or cite the wrong reporting authority, which is the fastest way to signal that nothing was drafted for your licence.
- Thresholds do not match licence conditions, because they were copied from a different jurisdiction.
- The risk assessment is generic, so it describes no actual operation.
- They promise tooling the platform lacks.
- Nobody follows them. A programme kept in a drawer offers no defence, because the test is what you did rather than what you wrote.
What to do
Policies drafted to your specific licence conditions, your actual platform capability and your real risk profile are part of every licensing engagement we run, and available separately for operators already licensed. If you are on a Curacao licence, the October 2026 terms deadline is the nearest hard date and the work is substantive rather than cosmetic.
Compare licence regimes and their conditions on the licensing page, see the wider legal counselling practice, or describe your operation and a principal will tell you which documents you are actually missing. Quotes are fixed in writing before any work begins.
Frequently asked questions
What documents does a crypto casino licence require?
At minimum an AML programme, KYC procedures, a responsible gaming policy and player terms of service, all drafted to the conditions of your specific licence. Most regimes also require a named Money Laundering Reporting Officer and an annually reviewed written risk assessment.
Do I need an MLRO for a crypto casino?
In most licensed jurisdictions yes, and Curacao requires one expressly under the LOK. The role needs defined authority, a deputy, and a documented reporting line rather than being a name on a form.
Can I use a template AML policy?
You can produce one, but it tends to fail where it matters. Templates typically name the wrong reporting authority, carry thresholds copied from another jurisdiction, contain a generic risk assessment, and promise responsible gaming tooling your platform does not support. Payment providers read these documents closely at onboarding.
What is the Curacao player terms deadline?
8 October 2026 for B2C licensees. It is a substantive review covering account closures, dormant accounts, payouts, refunds and crypto transactions specifically, not a footer edit, and it should be budgeted at six to eight weeks for a multi-brand operation.
How does AML work differently for crypto deposits?
Source of funds evidence is exchange and transaction history rather than bank statements, and you need wallet screening with defined risk thresholds, a stated position on privacy coins and mixers, a rule for fixing deposit value despite volatility, and a documented freeze and return procedure for deposits that cannot be cleared.
What happens if my policies are not followed in practice?
The exposure is to the licence rather than to a fine, and the test regulators apply is what you did rather than what you wrote. A programme that exists on paper but is not evidenced in training, monitoring and reporting offers little defence when a complaint or an audit arrives.