bet365 Ordered to Overhaul AML Controls Under AUSTRAC Enforceable Undertaking

AUSTRAC has accepted a legally binding enforceable undertaking from online bookmaker bet365, requiring the company to strengthen its anti-money laundering and counter-terrorism financing controls.
The action follows an AUSTRAC investigation triggered by an independent audit of bet365’s operations. AUSTRAC identified serious gaps in how the bookmaker assessed money laundering risks and detected and reported suspicious activity.
Under the undertaking, bet365 must implement a remedial action plan covering two principal areas:
- Its money laundering, terrorism financing and proliferation financing risk assessment; and
- Its transaction monitoring and suspicious matter reporting framework.
The case highlights a central compliance issue for gambling operators: customer risk cannot be assessed only when an account is opened. It must be reviewed throughout the relationship as the customer’s activity, funding methods and transaction patterns change.
What AUSTRAC Requires bet365 to Change
AUSTRAC’s concerns arose from external audit and independent review findings covering bet365’s AML/CTF framework.
The enforceable undertaking requires bet365 to strengthen its risk assessment methodology and supporting processes. This includes:
- Conducting an updated business-wide ML/TF/PF risk assessment;
- Developing a clearer methodology for documenting and testing controls;
- Improving change-management processes so that new risks are considered when products, systems or operations change; and
- Reviewing and strengthening its customer risk assessment model.
The company must also improve its transaction monitoring and suspicious matter reporting processes by:
- Reviewing whether its transaction monitoring program is effective and fit for purpose;
- Improving the consistency and documentation of alert decisions;
- Strengthening unusual activity reporting;
- Ensuring alerts are reviewed within defined timeframes;
- Improving systems and controls supporting suspicious matter reports; and
- Using emerging risks and suspicious reporting patterns to update monitoring processes.
The remediation work is subject to independent assurance. bet365 must provide a progress report to AUSTRAC by the end of 2026, complete the principal remediation work by 31 May 2027 and provide an independent auditor’s final assessment in 2027.
Why Gambling Creates Distinct AML Risks
Online gambling platforms process large numbers of transactions at high speed. Customers may deposit money, place limited bets and withdraw funds through different payment channels within a relatively short period.
This can make gambling accounts attractive for:
- Introducing illicit funds into the financial system;
- Moving money between payment instruments;
- Disguising transfers as gambling activity;
- Using third-party accounts or payment methods;
- Cycling funds through deposits and withdrawals;
- Transferring value between connected customers; and
- Creating an apparently legitimate explanation for criminal proceeds.
A customer may appear low-risk at onboarding because their identity documents are valid and their initial deposits are modest.
That assessment may no longer be appropriate if the customer later begins depositing significantly larger amounts, using multiple funding sources or withdrawing funds with little genuine gambling activity.
The risk exists in the customer’s developing behaviour—not only in the information collected when the account was opened.
Customer Risk Assessment Must Be Ongoing
A customer risk rating is not a permanent label.
It is an assessment based on the information available at a particular time. When material information changes, the rating should be reconsidered.
For gambling operators, relevant changes may include:
- A sudden increase in deposit values or frequency;
- Deposits inconsistent with the customer’s known occupation or financial profile;
- The use of multiple bank accounts, cards or digital wallets;
- Frequent changes in funding methods;
- Payments made by unrelated third parties;
- Rapid withdrawals after deposits;
- Large deposits followed by minimal or low-risk betting;
- Repeated deposits and withdrawals that produce little genuine gambling loss;
- Multiple accounts displaying connected behaviour;
- Activity involving higher-risk jurisdictions;
- Adverse media or law-enforcement information; and
- New politically exposed person or sanctions exposure.
These events do not automatically prove money laundering. They should, however, trigger a review of whether the existing customer risk rating remains appropriate.
Depending on the circumstances, the operator may need to:
- Obtain updated customer information;
- Request evidence of source of funds or source of wealth;
- Review connected payment accounts;
- Examine the customer’s historical activity;
- Apply enhanced monitoring;
- Escalate the relationship for compliance review; or
- Consider whether a suspicious matter report is required.
Behavioural Monitoring Must Connect to Risk Rating
Many AML frameworks treat customer risk assessment and transaction monitoring as separate processes.
In practice, they should inform each other.
Customer risk determines the level of monitoring that should be applied. Transaction behaviour then provides new information that may change the customer’s risk.
For example, a customer initially classified as standard risk may begin making high-value deposits from several unrelated accounts. Transaction monitoring may detect this behaviour, but the response should not end when the alert is closed.
The operator should consider whether the customer’s underlying risk profile has changed and whether future activity requires closer scrutiny.
Similarly, when an investigation identifies a new method of misuse, the findings should be used to improve:
- Customer risk factors;
- Monitoring rules;
- Alert thresholds;
- Staff guidance;
- Enhanced due diligence procedures; and
- The business-wide risk assessment.
This feedback loop is essential in sectors where customer behaviour can change quickly.
Suspicious Matter Reporting Depends on Effective Detection
A suspicious matter reporting process is only as strong as the systems that identify activity for review.
If transaction monitoring rules do not reflect the operator’s current risks, suspicious behaviour may never reach an investigator.
AUSTRAC’s expected minimum standards require bet365’s monitoring program to be based on its updated risk assessment. Monitoring must therefore respond to the risks actually faced by the business rather than relying on static or generic rules.
An effective framework should clearly define:
- Which behaviours generate alerts;
- How alerts are prioritised;
- The time allowed for review;
- What information investigators must consider;
- How decisions are documented;
- When matters are escalated;
- Who decides whether an SMR is submitted; and
- How reporting outcomes are used to improve future detection.
AUSTRAC also expects suspicious matter reports to be accurate and submitted on time.
A reporting entity should not delay filing until it can prove that criminal activity occurred. The reporting threshold is based on reasonable grounds for suspicion, not the completion of a criminal investigation.
Alert Closure Is Not the End of the Process
A recurring weakness in transaction monitoring programs is treating each alert as an isolated event.
An individual transaction may have a plausible explanation. However, a series of alerts may reveal a pattern that is not apparent when each event is reviewed separately.
Investigators should therefore consider:
- Previous alerts involving the customer;
- Changes in deposit and withdrawal behaviour;
- Connected accounts or payment instruments;
- Earlier explanations provided by the customer;
- Whether supporting documents remain credible;
- The customer’s total activity over time; and
- Whether the same behaviour appears across other accounts.
Repeatedly closing alerts without considering the broader customer relationship may allow suspicious patterns to continue undetected.
Monitoring should generate both transaction-level decisions and customer-level conclusions.
The Undertaking Is Directly Enforceable
An enforceable undertaking is not informal guidance or a voluntary improvement plan.
Once accepted by AUSTRAC, it becomes legally binding. Failure to meet its terms may expose the reporting entity to further enforcement action and civil penalty consequences.
bet365 must continue using an independent auditor to monitor its remediation progress. Material changes to the agreed action plan also require AUSTRAC’s written consent.
The undertaking does not prevent AUSTRAC from taking action in relation to other contraventions or future conduct.
This gives the regulator ongoing visibility over whether the redesigned controls are implemented and operating effectively, rather than merely documented.
What Other Gambling Operators Should Review
AUSTRAC states that the minimum standards imposed under the undertaking reflect its expectations for reporting entities more broadly.
Gambling operators should consider whether they can demonstrate that:
- Their business-wide risk assessment reflects current products, customers and payment channels;
- Customer risk ratings are updated when behaviour changes;
- Ongoing customer due diligence is applied in higher-risk cases;
- Transaction monitoring rules are linked to identified risks;
- Alert-review deadlines are defined and monitored;
- Investigators consider the customer’s full history rather than isolated transactions;
- Unusual activity reports are reviewed consistently;
- Suspicious matter reporting decisions are documented;
- New typologies and previous SMRs are used to improve controls; and
- Senior management receives meaningful reporting on risk, alerts and remediation.
The key question is not whether the operator completed a risk assessment in the past. It is whether the assessment, customer ratings and monitoring controls continue to reflect the risks present today.
The Compliance Takeaway
The bet365 undertaking reinforces that AML risk assessment is a continuing process.
Customer identity checks performed at account opening are only the starting point. They do not establish how the account will actually be used.
In the gambling sector, meaningful risk indicators often emerge after onboarding through deposit behaviour, payment methods, betting activity, withdrawals and connections with other accounts.
Operators must be able to detect those changes, reassess the customer and adjust their controls accordingly.
A customer who was low-risk when the relationship began may not remain low-risk.
Ongoing monitoring is effective only when changes in customer behaviour can lead to changes in customer risk.
Main Sources
AUSTRAC — bet365 to Overhaul AML Systems Under AUSTRAC Enforceable Undertaking
AUSTRAC — Enforceable Undertaking: Hillside (Australia New Media) Pty Limited Trading as bet365



