Genting Casino Derby Riverlights
Genting Casino Derby Riverlights

This policy outlines the AML and KYC obligations applied by Genting Casino Derby Riverlights.

AML / KYC Policy

1. Purpose and Scope

This document sets out the Anti-Money Laundering (AML) and Know Your Customer (KYC) policy applied by Genting Casino Derby Riverlights. It describes the procedures, obligations, and controls maintained to prevent money laundering, terrorist financing, and related financial crime in connection with gambling activity conducted through or at the premises.

This policy applies to all customers who hold an account with Genting Casino Derby Riverlights or who conduct transactions at the premises, whether in a remote or non-remote capacity. It is informed by the requirements of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the MLRs) and the guidance issued by the UK Gambling Commission (UKGC), including the UKGC publication “The Prevention of Money Laundering and Combating the Financing of Terrorism.”

Genting Casino Derby Riverlights is licensed and regulated by the Gambling Commission of Great Britain. The AML and KYC framework is reviewed and approved by senior management and is subject to ongoing monitoring and independent audit.

2. Risk Assessment

A documented, firm-wide risk assessment is maintained to identify and evaluate the money laundering and terrorist financing risks associated with products, customer base, delivery channels, and geographic exposure. This assessment is kept up to date and is used to design and calibrate policies, controls, and procedures.

Where the UKGC publishes its own sector-level risk assessment, its findings are incorporated into the internal review.

3. Customer Due Diligence (CDD)

3.1 When CDD Applies

Customer Due Diligence measures are applied in the following circumstances:

  • When establishing a business relationship with a customer
  • When there is suspicion of money laundering or terrorist financing, regardless of transaction value
  • When there is reason to doubt the accuracy or adequacy of identification information previously obtained
  • When a customer conducts a transaction amounting to €2,000 or more, whether in a single operation or in several operations that appear to be linked

For non-remote casino activity, identification and verification are required when a customer:

  • Purchases or exchanges casino tokens valued at €2,000 or more
  • Pays €2,000 or more for the use of gaming machines
  • Collects winnings of €2,000 or more

For remote gambling activity, the same threshold applies to deposits, withdrawals, and winnings.

CDD may also be applied at any point during an existing customer relationship if circumstances relevant to that customer’s risk profile change, or if AML or counter-terrorist financing (CTF) red flags are identified, irrespective of transaction value.

3.2 What CDD Involves

Standard CDD measures include:

  • Identifying the customer and verifying their identity using reliable, independent sources such as a government-issued identity document or passport
  • Identifying and verifying the beneficial owner where applicable
  • For corporate customers, determining and verifying the full names of directors or equivalent management and senior persons responsible for operations, unless the company is listed on a regulated exchange

Electronic identity verification systems may be used for AML and CTF purposes. Such checks leave a distinct record in a customer’s electronic file. Customer consent is not required for these checks, but customers are informed that a check is taking place before it is conducted.

4. Tiered Due Diligence

A risk-based, tiered approach to due diligence applies.

Simplified Due Diligence (SDD)

SDD may be applied where, on the basis of the risk assessment and relevant UKGC information, a business relationship or transaction presents a low degree of money laundering or terrorist financing risk. Relevant factors include whether the customer’s country of residence has effective AML and CTF systems consistent with the recommendations of the Financial Action Task Force (FATF), as evidenced by credible international sources.

Customer Due Diligence (CDD)

Standard CDD applies in the circumstances described in section 3.

Enhanced Due Diligence (EDD)

Enhanced Due Diligence and enhanced ongoing monitoring are applied in higher-risk situations, including:

  • Where the risk assessment or UKGC information identifies elevated money laundering or terrorist financing risk
  • In any business relationship with a customer resident in a high-risk third country, or in transactions where either party is resident in such a country
  • Where a customer is a Politically Exposed Person (PEP), or a family member or close associate of a PEP
  • Where it is discovered that a customer has provided false or stolen identification documentation

5. Ongoing Monitoring

Customer transactions and behaviour are monitored throughout the business relationship to assess whether activity is consistent with the understanding of the customer’s profile, source of funds, and risk rating. Where activity appears inconsistent with a customer’s known profile or where suspicious patterns are identified, the matter is escalated in accordance with internal reporting procedures.

6. Suspicious Activity Reporting

Where there is suspicion that funds may represent the proceeds of crime or may be linked to terrorist financing, a Suspicious Activity Report (SAR) must be submitted to the UK Financial Intelligence Unit (UKFIU), which operates within the National Crime Agency (NCA). In certain circumstances, a Defence Against Money Laundering (DAML) consent must be obtained before proceeding with a transaction.

As of July 2025, the threshold for submitting a DAML increased from £1,000 to £3,000. This threshold relates to reporting permissions and does not alter the €2,000 CDD threshold applicable to casino transactions.

Internal escalation of suspicious activity is handled through the designated Money Laundering Reporting Officer (MLRO), who is responsible for assessing reports and determining whether an external SAR is required.

7. Record-Keeping

All documents and records used to carry out customer due diligence, as well as details of transactions, are retained for the periods required under the MLRs and UKGC guidance. These records are maintained in a manner that enables a prompt response to requests from the Gambling Commission, law enforcement, or other competent authorities.

8. Staff Training

All relevant employees receive training on AML and CTF obligations appropriate to their role. Training covers recognition of suspicious activity, internal reporting procedures, and the legal obligations that apply to individuals working in a regulated gambling environment.

9. Customer Obligations

Customers are required to cooperate with identity verification and due diligence procedures. This includes providing accurate identification documents and, where requested, information about the source of funds used for gambling activity. Failure to provide required information may result in the company being unable to establish or continue a business relationship, or to process a transaction.

Customer identity is verified before permitting gambling activity where required by the risk assessment or applicable thresholds. Customers must be 18 years of age or older to gamble, in accordance with the requirements of the Gambling Act 2005 and the applicable licence conditions.

10. Policy Governance

This policy is approved by senior management at Genting Casino Derby Riverlights and is subject to regular review. Updates are made when required by changes in legislation, UKGC guidance, or the outcomes of the internal risk assessment. Any material changes to this policy are reflected in the version published on the website.