Knowledge Hub Scenario Lab About Try the tool →
This guide uses an experimental "Evidence Essay" layout, a one-off format test. Read why.
Evidence Essay · Gambling & AML

Gambling's white-label blind spot

A licensed operator supplies the licence. A separate brand supplies the front end. When something goes wrong, UKGC's own investigations show the gap between them is exactly where accountability gets lost.

Executive briefing

Where the accountability gap actually opens

White-label gambling lets a third-party brand operate under an established operator's licence, infrastructure, and compliance framework. The commercial logic is straightforward: the brand gets fast market access, the licence holder gets distribution it would not otherwise reach. The AML logic is where it breaks down.

UKGC's 2026 money laundering and terrorist financing risk assessment, published 30 July 2026, rates "inadequate due diligence on white-label partnerships" as a high risk, high impact vulnerability [1], unchanged in rating from the prior assessment, with only the guidance wording revised. The Commission's own risk assessment does not state or imply whether the underlying problem has improved, worsened, or stayed the same in practice, an unchanged rating records the Commission's current assessment, not a trend. The licensed operator carries the compliance obligation regardless of who owns the customer facing brand. Weak partner level checks let higher risk businesses, unusual payment arrangements, or unvetted customers into the regulated market without the scrutiny a direct relationship would get.

This guide works through where that accountability gap actually opens, using UKGC's own case material and a recurring pattern of enforcement across licensed operators between 2024 and 2025.

Chapter 1

The structure

A white-label arrangement has three parties in practice, even though only two hold any formal position with the regulator. The licensee is the operator UKGC has actually authorised: the entity that passed fit and proper checks, submitted a personal and business risk assessment, and holds the licence conditions that make gambling activity lawful in Great Britain. The partner brand is the commercial front end, the website or app a customer actually sees and signs up to, running on the licensee's platform and, critically, under the licensee's licence. The customer interacts only with the partner brand and often has no visibility at all into which entity is legally responsible for the relationship.

That legal responsibility does not move. Whatever the commercial agreement says about who monitors transactions day to day, who runs first line checks, or who handles customer support, the licence, and every obligation attached to it, sits with the licensee. UKGC does not licence the partner brand. If the partner brand's own conduct, or the conduct of its customers, creates a regulatory problem, the Commission's action lands on the licensee, not on the brand the customer actually recognises.

This is why due diligence on a white-label partner has to work on two separate levels, not one. The obvious level is customer due diligence: checking the individuals and businesses that open accounts and move money through the partner's platform. The level that gets missed is due diligence on the partner itself, as a business relationship in its own right. Who actually owns and controls the partner entity. Where its own funding comes from. Whether its own commercial activity is lawful, in Britain and in whatever territory it actually operates from. A licensee's own due diligence obligations apply to that partner relationship exactly as they would to any other high risk business relationship, not as a lighter touch check because the partner already holds a commercial agreement. The legal basis differs by operator type: for casino operators specifically, this runs through the Money Laundering Regulations 2017, which impose additional responsibilities on non-remote and remote casinos alone. For the wider population of gambling operators, including most white-label betting and gaming arrangements, the equivalent obligation runs through the Proceeds of Crime Act 2002, the Gambling Act 2005, and the Licence Conditions and Codes of Practice, specifically the AML policy and procedure requirements at LCCP conditions 12.1.1 and 12.1.2.

Where the obligation sits, regardless of who the customer sees
Licensee
Holds the UKGC licence. Carries the AML obligation, always.
Partner brand
Customer facing. Runs on the licensee's platform and licence.
End customer
Sees only the partner brand. Usually cannot see the licensee at all.
The compliance obligation runs back to the licensee regardless of which box the customer actually interacted with.
Chapter 2

What UKGC actually found

The accountability rule is not the risk assessment, it is the licence condition underneath it. LCCP condition 1.1.2 requires licensees to ensure that any third party they contract with, for any part of the licensed business, conducts itself as if bound by the same licence conditions and codes of practice as the licensee itself [9]. UKGC's own guidance on third-party responsibilities addresses white-label arrangements by name: the responsibility for compliance of all operating gambling websites, including white-labelled sites, sits with the licence holder and cannot be transferred to any other party [10]. Everything that follows in this chapter, the risk rating, the named enforcement case, the anonymised finding, is evidence of what happens when that rule is not followed in practice, not the rule itself.

Three separate pieces of evidence bear on this gap, and they carry different weight. UKGC's 2026 risk assessment rates inadequate due diligence on white-label partnerships as high risk, high impact, unchanged from the prior assessment with only the guidance wording revised [1]. That rating is the Commission's current view of the risk level, not a description of what the failure looks like inside a real firm. For that, the clearest evidence is six years old, and it has a name.

In May 2020, UKGC fined FSB Technology (UK) Ltd £600,000 following an investigation covering January 2017 to August 2019 [11]. FSB's business model included operating at least three separate websites as white-label partnerships, the exact structure Chapter 1 describes. The Commission's investigation found the oversight failures sitting on FSB's side of that structure, not the partner brands'.

The specific findings read as a checklist of what partner-level due diligence is supposed to catch [11]. Source-of-funds checks that should have flagged a customer wagering £282,000 over eighteen months while showing indicators of problem gambling did not. A marketing email went out to 2,324 customers who had already self-excluded. A VIP team manager operated without adequate oversight or anti-money laundering training. An unauthorised banner advertisement ran on a Great Britain facing site. None of these failures happened on a partner's own systems, outside FSB's reach, they happened inside relationships FSB itself was responsible for overseeing.

UKGC, 6 May 2020
“This arrangement, often referred to as a ‘white label’, places responsibility on the licensee to ensure that its third-party partners keep gambling fair, safe and crime-free.”
Gambling Commission, FSB Technology enforcement action [11]

UKGC imposed additional licence conditions requiring FSB to carry out risk-based due diligence before entering any new third-party partnership, and to review existing partnerships on the same basis at least annually, not as a one-time onboarding check [11]. The Commission's own director framed the case as a general warning, not a firm-specific one: operators are held fully responsible for third-party relationships, regardless of which brand the customer actually saw.

The practical lesson is not that FSB was unusually careless. It is that partner-level due diligence needs the same discipline as customer-level due diligence, applied on a schedule, not just at the point a partnership is signed. A partner relationship that looked acceptable in 2017 was still running the same way in 2019, because nothing forced a second look.

Six years after FSB, the same failure pattern surfaced again, this time in UKGC's own investigation work rather than a public enforcement notice. Section 9 of the Commission's 2026 risk assessment includes an anonymised finding that reads as close to a repeat of FSB's own failures as an anonymised case can [1].

UKGC investigation finding, Section 9 (paraphrased)

A licensed operator with white-label partnerships had failed to carry out effective due diligence on the ownership of the third party and on the source of funds for the business relationship. The operator had also not sufficiently considered whether the white-label partner's own activity was lawful, either in Britain or in the territory where it was actually conducted.

UKGC does not name the operator in its published finding.

Read against FSB, this is not a new problem, it is the same one recurring. The finding is not that the operator missed a suspicious customer transaction somewhere in the partner's platform. It is that the operator never properly checked the partner itself: who actually controlled it, where the money behind the arrangement came from, and whether the partner's own activity was even lawful in the place it was actually being carried out. Three separate checks, three separate gaps, on the one relationship a licensee cannot delegate away. The gap FSB was fined for in 2020 is the same gap UKGC's own investigators were still finding, anonymised, in the assessment published six years later. That is a persistent structural weakness, not an isolated incident.

UKGC does not name the operator in the 2026 finding. That is a genuine limit on this source, not something to gloss over. It is disclosed openly here because this guide's own sourcing standard treats an honestly flagged limitation as worth more than a more dramatic claim the primary source cannot actually support. The Methodology and limitations section explains why this guide still treats the finding as a strong corroborating illustration of the pattern, despite the anonymisation.

Process

The due diligence cycle in practice

FSB's failures and the anonymised 2026 finding both trace back to the same missing sequence. This is what the cycle looks like when it runs correctly, onboarding through to the point it starts again.

Step 1 · Partner onboarding proposed
Commercial proposes a new white-label partnership
Due diligence starts here, before any commercial commitment is made, not after terms are agreed.
Step 2 · Ownership verification
Confirm who actually owns and controls the partner entity
Independent documentation, registry extracts and identity verification, not the partner's own attestation.
Step 3 · Funding evidence
Establish the partner's own source of funds
The same evidentiary standard applied to a high risk customer relationship, not a lighter check because a commercial agreement exists.
Step 4 · Legality review
Assess the partner's activity against UK law and the law of the territory where it actually operates
Two separate legal tests, not one, per Chapter 1's structure.
Step 5 · Ongoing monitoring
Partner relationship reviewed on a fixed schedule once live
Not a one-time check at onboarding, the discipline UKGC's additional licence conditions required of FSB.
Step 6 · Escalation
Material findings route to the licensee's own decision-making process
Independent of the partner's own review timeline, the judgement Chapter 4's first scenario works through.
Step 7 · Governance approval
Partnership formally reapproved on the same basis at least annually
Closes the loop back to ownership, funding, and legality, the review is a genuine recheck, not a formality.
Chapter 3

The enforcement pattern, not a single event

None of the enforcement actions below is a UKGC action specifically for a white-label control failure by name. That distinction belongs to Chapter 2's case alone. What this timeline shows instead is that the same licensee level AML weaknesses, inadequate due diligence, over reliance on customer or partner assurances, and insufficient monitoring, recur across operators managing multi-brand and white-label-adjacent portfolios, across 2024 and 2025, not in one quarter.

Six enforcement actions, licensee level AML and social responsibility failures, verified individually against UKGC's own published articles
  1. Jan 2024
    Gamesys Operations Limited, £6m. AML and social responsibility failures across 12 sites operated under one licence [2].
  2. May 2025
    Spreadex Limited, £2,022,000. Second enforcement action after an earlier 2022 penalty, AML and social responsibility failures [3].
  3. Aug 2025
    ProgressPlay Limited, £1m. No adequate money laundering and terrorist financing risk assessment in place [4].
  4. Oct 2025
    Platinum Gaming Limited (unibet.co.uk, uk.bingo.com), £10m. Second penalty in under three years [5].
  5. Nov 2025
    Videoslots Limited, £650,000. Gaps in AML policy, record keeping, over reliance on an automated scoring system [6].
  6. Dec 2025
    Paddy Power Betfair, £2m. Harm detection systems failed to identify high velocity spending without manual review [7].

Verified separately against UKGC's own full enforcement list rather than taken from any secondary report: the Commission recorded 12 operator level regulatory actions, fines and licence suspensions, between 1 July and 31 December 2025 alone, excluding individual criminal cases such as arrests and sentencing [8]. Not all 12 were AML specific, some were social responsibility or unfair terms actions. The figure is offered as evidence of a high enforcement tempo generally across the sector, not as 12 white-label failures specifically. The Methodology and limitations section sets out exactly how this figure was checked.

Chapter 4 · Worked scenarios

Two judgement calls

The structural gap Chapters 1 and 2 describe shows up as concrete decisions, not abstract policy. The two scenarios below map to two of the four Risk, Signal, Response patterns introduced later on this page: an escalation call under pressure from a partner's own review, and an onboarding call under commercial pressure to move fast.

The Distant Principal

Situation

Your firm holds the licence. A white-label partner's own transaction monitoring flags unusual deposit velocity on an account operating under your infrastructure: three deposits totalling £18,000 within 40 minutes, from a customer onboarded four days earlier. The partner's compliance team has opened an internal review but has not yet reached a conclusion.

Material facts. Your firm's own AML policy requires SAR consideration on velocity patterns of this kind, regardless of source. The partnership agreement gives the partner first line monitoring responsibility, but the licence, and the underlying legal obligation, sit with your firm alone. No information sharing agreement specifies a maximum time for a partner to escalate a finding.

The Fast-Tracked Partner

Situation

Commercial has negotiated a new white-label partnership with an offshore-registered gaming brand. A competitor is also courting the same partner, and commercial wants to sign and go live within two weeks. Compliance has been asked to sign off, but the beneficial ownership information supplied is a one-page attestation letter from the partner itself, no independent verification. The partner's ownership runs through two intermediary holding companies in different jurisdictions. This is a first-time relationship, with no history to draw on.

Material facts. The attestation names a beneficial owner but includes no supporting documentation, no corporate registry extract, no identity verification of the named individual. Commercial has already discussed a go-live date informally with the partner. LCCP condition 1.1.2 requires the partner to be treated, for compliance purposes, as if bound by the same licence conditions as your own firm.

Chapter 5

Counterfactual

Change one fact: the white-label partner is itself independently licensed by UKGC for a related activity, not merely operating under your firm's licence for this product line. Does the analysis change?

Partially. Where the partner holds its own separate licence for other activity, it carries its own independent AML obligations for that activity, and UKGC can act against it directly. But for the specific product operating under your firm's licence, the legal obligation still sits with you as the licensing operator. The partner's own separate licensing status does not transfer or dilute your firm's obligation for activity conducted under your licence.

This is the distinction UKGC's case study makes explicit [1]: the operator had also not sufficiently considered whether any activity by the white-label partner was illegal, either in Britain or the territory in which it was conducted, a check that exists independently of whatever licences the partner separately holds elsewhere.

The four patterns

Risk, signal, response

Four recurring failure patterns behind the case and the timeline above, each with the risk it creates, the signal that should catch it, and the response that closes it.

👤
The Distant Principal
A partner's suspicious pattern goes unescalated because no one owns it end to end.
Risk
Diffused accountability across the licensee and partner boundary.
Signal
Slow or absent escalation from the partner side.
Response
The licensee must retain independent control of suspicion assessment, internal escalation and any reporting decision required by its policy and applicable law.
🔒
The Unchecked Owner
A partnership goes live on brand strength alone, without the licensee ever verifying who actually controls the partner entity.
Risk
Onboarding a partner without ownership level due diligence.
Signal
Partnership approved on commercial terms with no compliance sign off on beneficial ownership.
Response
Apply the same ownership scrutiny to a partner entity that you would apply to a direct high risk customer.
📋
The Borrowed Assurance
A licensee accepts a partner's own compliance claims about its funding sources without independent verification.
Risk
Relying on a partner's self attestation instead of evidence.
Signal
No documentary source of funds trail exists for the business relationship itself, only for individual end customers.
Response
Verify the partner's own funding and ownership with the same evidentiary standard used for customer source of funds checks.
The Legality Gap
A partner's activity turns out to be unlawful in its own operating territory, something the licensee never checked because the partner held a UK facing brand.
Risk
Assuming a partner's activity is lawful because the partnership itself is UK licensed.
Signal
No documented assessment of the partner's activity against the law of the territory where it actually operates.
Response
Assess partner activity against both UK law and the law of the partner's operating jurisdiction, not UK law alone.
Knowledge check

Test your understanding

1. Under UKGC's case study, what specifically did the licensed operator fail to check about its white-label partner?
2. In the worked scenario, why is option A better supported than option C, even though both eventually involve escalation?
3. Which of the following changes if a white-label partner holds its own separate UKGC licence for unrelated activity?
4. Approximately how many operator level UKGC regulatory actions were recorded in the second half of 2025?
5. Why does this guide's corroborating 2026 UKGC finding stay anonymised rather than naming the operator?
6. What did UKGC's additional licence conditions require FSB Technology to do after the 2020 enforcement action?
0/6
FAQ

Common questions

Is a white-label partnership itself against the rules?
No. White-label partnerships are a legitimate, common commercial structure in UK gambling. UKGC's own risk assessment does not say the model itself is the problem, it says due diligence on the partner as a business relationship, not just on the partner's customers, is the recurring gap.
Who is actually fined if a white-label partner's customer turns out to be a money laundering risk?
The licensee. UKGC licenses the operator holding the licence, not the customer facing partner brand. The partnership agreement can allocate day to day monitoring tasks to the partner, but it cannot reassign the legal AML obligation that comes with the licence itself.
Were any of the six enforcement actions in Chapter 3 specifically about white-label failures?
No, and this guide does not claim otherwise. None of the six named actions is a UKGC action specifically for a white-label control failure by name, that is Chapter 2's case material, the named FSB Technology enforcement action and the anonymised 2026 finding. The six Chapter 3 actions show a recurring pattern of licensee level AML weaknesses across operators running multi-brand portfolios, which is the same underlying discipline gap the white-label structure depends on getting right.
Does the 12 figure for H2 2025 mean 12 white-label failures?
No. It is 12 operator level regulatory actions of any kind recorded by UKGC in that six month window, not all of them AML related and none of them labelled a white-label failure specifically. It is offered as evidence of enforcement tempo across the sector generally, not as a white-label specific count. The Methodology and limitations section explains exactly how this figure was checked.
Quick reference

At a glance

Four patterns, the risk that makes each one look routine, the signal that actually gives it away, and the response that fits.

Quick reference

Summary snapshot

The full guide in one image, for quick reference or sharing.

Gambling's White-Label Blind Spot summary infographic showing UKGC's high risk, high impact rating on white-label due diligence, the licensee to partner brand to end customer structure with the compliance obligation running back to the licensee, six enforcement actions from January 2024 to December 2025 including Platinum Gaming's GBP10m fine, the 12 operator-level regulatory actions recorded in H2 2025, and the four Risk, Signal, Response patterns: The Distant Principal, The Unchecked Owner, The Borrowed Assurance, and The Legality Gap.
⬇️ Download summary
Verification

Sources

Each numbered claim above is checked against the specific source below it. Every article page was opened and read individually, not taken from the enforcement index listing alone.

  1. UK Gambling Commission, The 2026 money laundering and terrorist financing risks within the British gambling industry, Section 9 (Betting, remote), published 30 July 2026, including the white-label case study. gamblingcommission.gov.uk
  2. UKGC enforcement action, Gamesys Operations Limited, £6m, 10 January 2024. gamblingcommission.gov.uk
  3. UKGC enforcement action, Spreadex Limited, £2,022,000, 15 May 2025. gamblingcommission.gov.uk
  4. UKGC enforcement action, ProgressPlay Limited, £1m, 21 August 2025. gamblingcommission.gov.uk
  5. UKGC enforcement action, Platinum Gaming Limited, £10m, 22 October 2025. gamblingcommission.gov.uk
  6. UKGC enforcement action, Videoslots Limited, £650,000, 20 November 2025. gamblingcommission.gov.uk
  7. UKGC enforcement action, Paddy Power Betfair, £2m, 17 December 2025. gamblingcommission.gov.uk
  8. UKGC, full enforcement action list, used to independently count 12 operator level regulatory actions between 1 July and 31 December 2025, verified by reading the complete list rather than an index summary. gamblingcommission.gov.uk
  9. UKGC, Licence Conditions and Codes of Practice, condition 1.1.2, "Responsibility for third parties, all licences." gamblingcommission.gov.uk
  10. UKGC, "Licensees' responsibilities for third parties," guidance page, explicitly addresses white-label arrangements by name. gamblingcommission.gov.uk
  11. UKGC enforcement action, FSB Technology (UK) Ltd, £600,000, 6 May 2020, third-party white-label oversight failure. gamblingcommission.gov.uk
Methodology and limitations

How this guide was built and checked

The corroborating anonymised finding. Chapter 2's primary case is FSB Technology (UK) Ltd's named 2020 enforcement action. Alongside it, UKGC's own 2026 risk assessment contains a second, anonymised finding that shows the same failure pattern recurring, and that finding does not name the operator involved. That is disclosed here rather than hidden: this guide treats a genuine, primary sourced finding from the regulator itself as stronger material than a more dramatic but unverifiable claim naming an operator UKGC never actually named. Knowledge check question 5 tests this same point directly, because the sourcing choice is meant to be visible to the reader, not smoothed over.

The corrected H2 2025 figure. An earlier count of enforcement actions in the second half of 2025 was checked directly against UKGC's own full enforcement list rather than accepted from a secondary report, and against an index summary that itself first appeared to undercount the real figure. The complete list was read in full and every operator level regulatory action between 1 July and 31 December 2025 was counted individually: Taichi Tech (3 Jul), ProgressPlay (21 Aug), Maple International Ventures (17 Sep), Petfre Gibraltar (1 Oct), Platinum Gaming (22 Oct), Spribe (30 Oct), VGC Leeds (31 Oct), NetBet (5 Nov), Videoslots (20 Nov), Deadheat Racing (21 Nov), Done Brothers (3 Dec), and Paddy Power Betfair (17 Dec), 12 in total, excluding two individual criminal matters in the same window that are not operator level sanctions.

Two corrections made during this final verification pass. Spreadex's enforcement action is dated 15 May 2025 on UKGC's own article, not an earlier date used in an interim draft. Platinum Gaming's October 2025 fine names unibet.co.uk and uk.bingo.com as the operator's brands, it does not name 32Red, which was fined alongside Platinum Gaming in a separate, earlier 2023 action.

Illustrative detail. The specific figures in Chapter 4's worked scenario, the £18,000, the 40 minutes, the four day account age, are original composite teaching detail built around the real regulatory principle in Chapter 2's case. They are not tied to a specific real customer or case and are correctly uncited, consistent with this project's standard that illustrative worked examples do not carry a citation the way a regulatory or enforcement claim does.

Format. This guide uses an experimental layout, an "Evidence Essay" with a source record panel, distinct from both the standard Knowledge Hub card format and the PEP and SAR series' narrative format. See the note on format for why the site's guides do not all look the same.

Practice the underlying judgement

The licensee versus partner accountability question in Chapter 4 is one version of a pattern that comes up across financial crime investigation generally, not just gambling. FinCrimeRadar's Scenario Lab puts related judgement calls in front of you under time pressure, free, no signup required.

Try Scenario Lab →

The exported summary image contains: guide title, FinCrimeRadar.org, verification date 13 August 2026, source markers 1 to 8, a statement that the image is a summary and not complete regulatory guidance, and the four Risk, Signal, Response cards already present as readable text earlier on this page.