Where the accountability gap actually opens
White-label gambling lets a third-party brand operate under an established operator's licence, infrastructure, and compliance framework. The commercial logic is straightforward: the brand gets fast market access, the licence holder gets distribution it would not otherwise reach. The AML logic is where it breaks down.
UKGC's 2026 money laundering and terrorist financing risk assessment, published 30 July 2026, rates "inadequate due diligence on white-label partnerships" as a high risk, high impact vulnerability [1], unchanged in rating from the prior assessment, with only the guidance wording revised. The Commission's own risk assessment does not state or imply whether the underlying problem has improved, worsened, or stayed the same in practice, an unchanged rating records the Commission's current assessment, not a trend. The licensed operator carries the compliance obligation regardless of who owns the customer facing brand. Weak partner level checks let higher risk businesses, unusual payment arrangements, or unvetted customers into the regulated market without the scrutiny a direct relationship would get.
This guide works through where that accountability gap actually opens, using UKGC's own case material and a recurring pattern of enforcement across licensed operators between 2024 and 2025.
The structure
A white-label arrangement has three parties in practice, even though only two hold any formal position with the regulator. The licensee is the operator UKGC has actually authorised: the entity that passed fit and proper checks, submitted a personal and business risk assessment, and holds the licence conditions that make gambling activity lawful in Great Britain. The partner brand is the commercial front end, the website or app a customer actually sees and signs up to, running on the licensee's platform and, critically, under the licensee's licence. The customer interacts only with the partner brand and often has no visibility at all into which entity is legally responsible for the relationship.
That legal responsibility does not move. Whatever the commercial agreement says about who monitors transactions day to day, who runs first line checks, or who handles customer support, the licence, and every obligation attached to it, sits with the licensee. UKGC does not licence the partner brand. If the partner brand's own conduct, or the conduct of its customers, creates a regulatory problem, the Commission's action lands on the licensee, not on the brand the customer actually recognises.
This is why due diligence on a white-label partner has to work on two separate levels, not one. The obvious level is customer due diligence: checking the individuals and businesses that open accounts and move money through the partner's platform. The level that gets missed is due diligence on the partner itself, as a business relationship in its own right. Who actually owns and controls the partner entity. Where its own funding comes from. Whether its own commercial activity is lawful, in Britain and in whatever territory it actually operates from. A licensee's own due diligence obligations apply to that partner relationship exactly as they would to any other high risk business relationship, not as a lighter touch check because the partner already holds a commercial agreement. The legal basis differs by operator type: for casino operators specifically, this runs through the Money Laundering Regulations 2017, which impose additional responsibilities on non-remote and remote casinos alone. For the wider population of gambling operators, including most white-label betting and gaming arrangements, the equivalent obligation runs through the Proceeds of Crime Act 2002, the Gambling Act 2005, and the Licence Conditions and Codes of Practice, specifically the AML policy and procedure requirements at LCCP conditions 12.1.1 and 12.1.2.
What UKGC actually found
The accountability rule is not the risk assessment, it is the licence condition underneath it. LCCP condition 1.1.2 requires licensees to ensure that any third party they contract with, for any part of the licensed business, conducts itself as if bound by the same licence conditions and codes of practice as the licensee itself [9]. UKGC's own guidance on third-party responsibilities addresses white-label arrangements by name: the responsibility for compliance of all operating gambling websites, including white-labelled sites, sits with the licence holder and cannot be transferred to any other party [10]. Everything that follows in this chapter, the risk rating, the named enforcement case, the anonymised finding, is evidence of what happens when that rule is not followed in practice, not the rule itself.
Three separate pieces of evidence bear on this gap, and they carry different weight. UKGC's 2026 risk assessment rates inadequate due diligence on white-label partnerships as high risk, high impact, unchanged from the prior assessment with only the guidance wording revised [1]. That rating is the Commission's current view of the risk level, not a description of what the failure looks like inside a real firm. For that, the clearest evidence is six years old, and it has a name.
In May 2020, UKGC fined FSB Technology (UK) Ltd £600,000 following an investigation covering January 2017 to August 2019 [11]. FSB's business model included operating at least three separate websites as white-label partnerships, the exact structure Chapter 1 describes. The Commission's investigation found the oversight failures sitting on FSB's side of that structure, not the partner brands'.
The specific findings read as a checklist of what partner-level due diligence is supposed to catch [11]. Source-of-funds checks that should have flagged a customer wagering £282,000 over eighteen months while showing indicators of problem gambling did not. A marketing email went out to 2,324 customers who had already self-excluded. A VIP team manager operated without adequate oversight or anti-money laundering training. An unauthorised banner advertisement ran on a Great Britain facing site. None of these failures happened on a partner's own systems, outside FSB's reach, they happened inside relationships FSB itself was responsible for overseeing.
“This arrangement, often referred to as a ‘white label’, places responsibility on the licensee to ensure that its third-party partners keep gambling fair, safe and crime-free.”
UKGC imposed additional licence conditions requiring FSB to carry out risk-based due diligence before entering any new third-party partnership, and to review existing partnerships on the same basis at least annually, not as a one-time onboarding check [11]. The Commission's own director framed the case as a general warning, not a firm-specific one: operators are held fully responsible for third-party relationships, regardless of which brand the customer actually saw.
The practical lesson is not that FSB was unusually careless. It is that partner-level due diligence needs the same discipline as customer-level due diligence, applied on a schedule, not just at the point a partnership is signed. A partner relationship that looked acceptable in 2017 was still running the same way in 2019, because nothing forced a second look.
Six years after FSB, the same failure pattern surfaced again, this time in UKGC's own investigation work rather than a public enforcement notice. Section 9 of the Commission's 2026 risk assessment includes an anonymised finding that reads as close to a repeat of FSB's own failures as an anonymised case can [1].
A licensed operator with white-label partnerships had failed to carry out effective due diligence on the ownership of the third party and on the source of funds for the business relationship. The operator had also not sufficiently considered whether the white-label partner's own activity was lawful, either in Britain or in the territory where it was actually conducted.
Read against FSB, this is not a new problem, it is the same one recurring. The finding is not that the operator missed a suspicious customer transaction somewhere in the partner's platform. It is that the operator never properly checked the partner itself: who actually controlled it, where the money behind the arrangement came from, and whether the partner's own activity was even lawful in the place it was actually being carried out. Three separate checks, three separate gaps, on the one relationship a licensee cannot delegate away. The gap FSB was fined for in 2020 is the same gap UKGC's own investigators were still finding, anonymised, in the assessment published six years later. That is a persistent structural weakness, not an isolated incident.
UKGC does not name the operator in the 2026 finding. That is a genuine limit on this source, not something to gloss over. It is disclosed openly here because this guide's own sourcing standard treats an honestly flagged limitation as worth more than a more dramatic claim the primary source cannot actually support. The Methodology and limitations section explains why this guide still treats the finding as a strong corroborating illustration of the pattern, despite the anonymisation.
The due diligence cycle in practice
FSB's failures and the anonymised 2026 finding both trace back to the same missing sequence. This is what the cycle looks like when it runs correctly, onboarding through to the point it starts again.
The enforcement pattern, not a single event
None of the enforcement actions below is a UKGC action specifically for a white-label control failure by name. That distinction belongs to Chapter 2's case alone. What this timeline shows instead is that the same licensee level AML weaknesses, inadequate due diligence, over reliance on customer or partner assurances, and insufficient monitoring, recur across operators managing multi-brand and white-label-adjacent portfolios, across 2024 and 2025, not in one quarter.
-
Jan 2024Gamesys Operations Limited, £6m. AML and social responsibility failures across 12 sites operated under one licence [2].
-
May 2025Spreadex Limited, £2,022,000. Second enforcement action after an earlier 2022 penalty, AML and social responsibility failures [3].
-
Aug 2025ProgressPlay Limited, £1m. No adequate money laundering and terrorist financing risk assessment in place [4].
-
Oct 2025Platinum Gaming Limited (unibet.co.uk, uk.bingo.com), £10m. Second penalty in under three years [5].
-
Nov 2025Videoslots Limited, £650,000. Gaps in AML policy, record keeping, over reliance on an automated scoring system [6].
-
Dec 2025Paddy Power Betfair, £2m. Harm detection systems failed to identify high velocity spending without manual review [7].
Verified separately against UKGC's own full enforcement list rather than taken from any secondary report: the Commission recorded 12 operator level regulatory actions, fines and licence suspensions, between 1 July and 31 December 2025 alone, excluding individual criminal cases such as arrests and sentencing [8]. Not all 12 were AML specific, some were social responsibility or unfair terms actions. The figure is offered as evidence of a high enforcement tempo generally across the sector, not as 12 white-label failures specifically. The Methodology and limitations section sets out exactly how this figure was checked.
Two judgement calls
The structural gap Chapters 1 and 2 describe shows up as concrete decisions, not abstract policy. The two scenarios below map to two of the four Risk, Signal, Response patterns introduced later on this page: an escalation call under pressure from a partner's own review, and an onboarding call under commercial pressure to move fast.
The Distant Principal
Your firm holds the licence. A white-label partner's own transaction monitoring flags unusual deposit velocity on an account operating under your infrastructure: three deposits totalling £18,000 within 40 minutes, from a customer onboarded four days earlier. The partner's compliance team has opened an internal review but has not yet reached a conclusion.
Material facts. Your firm's own AML policy requires SAR consideration on velocity patterns of this kind, regardless of source. The partnership agreement gives the partner first line monitoring responsibility, but the licence, and the underlying legal obligation, sit with your firm alone. No information sharing agreement specifies a maximum time for a partner to escalate a finding.
The Fast-Tracked Partner
Commercial has negotiated a new white-label partnership with an offshore-registered gaming brand. A competitor is also courting the same partner, and commercial wants to sign and go live within two weeks. Compliance has been asked to sign off, but the beneficial ownership information supplied is a one-page attestation letter from the partner itself, no independent verification. The partner's ownership runs through two intermediary holding companies in different jurisdictions. This is a first-time relationship, with no history to draw on.
Material facts. The attestation names a beneficial owner but includes no supporting documentation, no corporate registry extract, no identity verification of the named individual. Commercial has already discussed a go-live date informally with the partner. LCCP condition 1.1.2 requires the partner to be treated, for compliance purposes, as if bound by the same licence conditions as your own firm.
Counterfactual
Change one fact: the white-label partner is itself independently licensed by UKGC for a related activity, not merely operating under your firm's licence for this product line. Does the analysis change?
Partially. Where the partner holds its own separate licence for other activity, it carries its own independent AML obligations for that activity, and UKGC can act against it directly. But for the specific product operating under your firm's licence, the legal obligation still sits with you as the licensing operator. The partner's own separate licensing status does not transfer or dilute your firm's obligation for activity conducted under your licence.
This is the distinction UKGC's case study makes explicit [1]: the operator had also not sufficiently considered whether any activity by the white-label partner was illegal, either in Britain or the territory in which it was conducted, a check that exists independently of whatever licences the partner separately holds elsewhere.
Risk, signal, response
Four recurring failure patterns behind the case and the timeline above, each with the risk it creates, the signal that should catch it, and the response that closes it.
Test your understanding
Common questions
Is a white-label partnership itself against the rules?
Who is actually fined if a white-label partner's customer turns out to be a money laundering risk?
Were any of the six enforcement actions in Chapter 3 specifically about white-label failures?
Does the 12 figure for H2 2025 mean 12 white-label failures?
At a glance
Four patterns, the risk that makes each one look routine, the signal that actually gives it away, and the response that fits.
Summary snapshot
The full guide in one image, for quick reference or sharing.
Sources
Each numbered claim above is checked against the specific source below it. Every article page was opened and read individually, not taken from the enforcement index listing alone.
- UK Gambling Commission, The 2026 money laundering and terrorist financing risks within the British gambling industry, Section 9 (Betting, remote), published 30 July 2026, including the white-label case study. gamblingcommission.gov.uk
- UKGC enforcement action, Gamesys Operations Limited, £6m, 10 January 2024. gamblingcommission.gov.uk
- UKGC enforcement action, Spreadex Limited, £2,022,000, 15 May 2025. gamblingcommission.gov.uk
- UKGC enforcement action, ProgressPlay Limited, £1m, 21 August 2025. gamblingcommission.gov.uk
- UKGC enforcement action, Platinum Gaming Limited, £10m, 22 October 2025. gamblingcommission.gov.uk
- UKGC enforcement action, Videoslots Limited, £650,000, 20 November 2025. gamblingcommission.gov.uk
- UKGC enforcement action, Paddy Power Betfair, £2m, 17 December 2025. gamblingcommission.gov.uk
- UKGC, full enforcement action list, used to independently count 12 operator level regulatory actions between 1 July and 31 December 2025, verified by reading the complete list rather than an index summary. gamblingcommission.gov.uk
- UKGC, Licence Conditions and Codes of Practice, condition 1.1.2, "Responsibility for third parties, all licences." gamblingcommission.gov.uk
- UKGC, "Licensees' responsibilities for third parties," guidance page, explicitly addresses white-label arrangements by name. gamblingcommission.gov.uk
- UKGC enforcement action, FSB Technology (UK) Ltd, £600,000, 6 May 2020, third-party white-label oversight failure. gamblingcommission.gov.uk
How this guide was built and checked
The corroborating anonymised finding. Chapter 2's primary case is FSB Technology (UK) Ltd's named 2020 enforcement action. Alongside it, UKGC's own 2026 risk assessment contains a second, anonymised finding that shows the same failure pattern recurring, and that finding does not name the operator involved. That is disclosed here rather than hidden: this guide treats a genuine, primary sourced finding from the regulator itself as stronger material than a more dramatic but unverifiable claim naming an operator UKGC never actually named. Knowledge check question 5 tests this same point directly, because the sourcing choice is meant to be visible to the reader, not smoothed over.
The corrected H2 2025 figure. An earlier count of enforcement actions in the second half of 2025 was checked directly against UKGC's own full enforcement list rather than accepted from a secondary report, and against an index summary that itself first appeared to undercount the real figure. The complete list was read in full and every operator level regulatory action between 1 July and 31 December 2025 was counted individually: Taichi Tech (3 Jul), ProgressPlay (21 Aug), Maple International Ventures (17 Sep), Petfre Gibraltar (1 Oct), Platinum Gaming (22 Oct), Spribe (30 Oct), VGC Leeds (31 Oct), NetBet (5 Nov), Videoslots (20 Nov), Deadheat Racing (21 Nov), Done Brothers (3 Dec), and Paddy Power Betfair (17 Dec), 12 in total, excluding two individual criminal matters in the same window that are not operator level sanctions.
Two corrections made during this final verification pass. Spreadex's enforcement action is dated 15 May 2025 on UKGC's own article, not an earlier date used in an interim draft. Platinum Gaming's October 2025 fine names unibet.co.uk and uk.bingo.com as the operator's brands, it does not name 32Red, which was fined alongside Platinum Gaming in a separate, earlier 2023 action.
Illustrative detail. The specific figures in Chapter 4's worked scenario, the £18,000, the 40 minutes, the four day account age, are original composite teaching detail built around the real regulatory principle in Chapter 2's case. They are not tied to a specific real customer or case and are correctly uncited, consistent with this project's standard that illustrative worked examples do not carry a citation the way a regulatory or enforcement claim does.
Format. This guide uses an experimental layout, an "Evidence Essay" with a source record panel, distinct from both the standard Knowledge Hub card format and the PEP and SAR series' narrative format. See the note on format for why the site's guides do not all look the same.
Practice the underlying judgement
The licensee versus partner accountability question in Chapter 4 is one version of a pattern that comes up across financial crime investigation generally, not just gambling. FinCrimeRadar's Scenario Lab puts related judgement calls in front of you under time pressure, free, no signup required.
Try Scenario Lab →