Gambling Licensing

Player fund segregation and the compliance rules operators keep getting wrong

Player fund segregation sounds simple. Keep customer money separate from your own. Don’t spend it. Don’t get creative. And yet, operators keep messing this up in ways that cause banking problems, licence headaches, and ugly regulator questions.

Usually it starts small. A startup casino or sportsbook opens one account, pushes all receipts into it, pays affiliate invoices from the same balance, then tells itself it’ll “sort the structure later”. Later turns into six months. Then a bank asks for source-of-funds logic, or a licensing adviser asks how player balances are protected, and suddenly there’s a problem you can’t explain away with a spreadsheet.

If you run gaming, especially cross-border, you need to treat player money like it’s radioactive. Separate it properly. Document the flow. Make sure your legal structure and payment setup match the story you’re telling regulators and banks. Anything else is asking for trouble.


What player fund segregation actually means

At a practical level, segregation means player funds are ringfenced away from the operator’s own working capital. So deposits, unsettled balances, pending withdrawals, jackpot contributions where relevant, and other customer-held amounts shouldn’t be casually mixed with payroll, marketing spend, software invoices, or shareholder distributions.

That’s the basic idea. But the real issue is deeper than “two bank accounts instead of one”. Regulators, banks, and payment providers want to understand:

  • which entity receives player deposits
  • where those funds sit after receipt
  • who has signing authority over the account
  • how reconciliation happens each day or each cycle
  • what happens if the business becomes insolvent

If you can’t answer those points clearly, your segregation setup probably isn’t good enough. Or at least won’t look good enough to the people reviewing it.

And yes, the exact standard depends on jurisdiction. Some licensing regimes classify levels of player fund protection differently. Some expect formal safeguarding language. Some focus more on disclosure to players. Check current requirements for the licence you hold or plan to apply for. Don’t assume what worked in one market will carry across neatly.


The mistake founders make first

They think this is just a finance issue.

It isn’t. It’s licensing, AML, banking, payments, and corporate structuring all rolled together into one annoying little knot.

I’ve seen operators build a decent front-end compliance story, with KYC flows and transaction monitoring, then completely blow the back-end setup by using a payment route that settles player deposits into a group company’s general treasury account. On paper, the licensed entity is holding customer balances. In reality, another company is touching the money first. Big mistake.

That gap between “legal model” and “actual money flow” is where problems start.


Four rules operators keep getting wrong

1. The licensed entity and the payment flow don’t match

This is probably the most common one. The website terms name Operator A. The merchant account is under Operator B. The IBAN is held by Holding Company C. Then someone says, “But they’re all in the same group.”

Nope.

From a compliance view, group ownership doesn’t magically fix a broken funds chain. If the player contracts with one entity, but another entity receives or controls the money without a clean documented role, you’ve created a mismatch that banks and regulators hate. And honestly, suppliers hate it too.

If you’re still choosing structure, sort that before launch. A clean setup often starts with the right entity map and account ownership. If you’re at that stage, company formation in multiple jurisdictions should be driven by licensing and payment logic, not just tax chatter or where your friend set up his last affiliate business.

2. “Segregated” means an internal ledger, not an actual segregation method

Some operators say funds are segregated because their back office tracks player liabilities separately. That’s useful, sure. But an internal ledger is not the same thing as proper operational separation.

If all money lands in the same live account and gets used for general business expenses, your accounting entries won’t save you. The system may show a customer balance, but the cash itself has already been exposed to business risk.

You need a real-world control setup. Separate account arrangements where possible. Restricted payment flows. Approval controls. Written rules on transfers. Daily or frequent reconciliation. Not fancy. Just real.

3. Reconciliations are late, manual, or weirdly inconsistent

This one sounds boring until it kills a banking review.

If your player liability report says one thing, your PSP settlement report says another, and your bank balance says something else entirely, you don’t have segregation – you have wishful thinking. Most operators leave reconciliation design too late because it feels operational, not strategic. Then the monthly close becomes a frantic patch job with CSV exports and guesswork.

Fix it early. Decide who owns the process, what data sources are authoritative, and how exceptions are escalated. If a withdrawal batch fails or a chargeback lands late, there needs to be a rule for that. Not a Slack thread. A rule.

And while we’re here, customer risk and fund flow controls overlap more than people think. If your deposit patterns and withdrawal behaviour aren’t tied into risk logic, you create blind spots fast. This piece on customer risk scoring is worth reading because banks increasingly look at the whole control environment, not just whether you’ve labelled an account “player funds”.

4. Nobody documents insolvency treatment or customer disclosure properly

Founders hate this part because it feels abstract. But regulators care. A lot.

You need to be clear, internally and externally, on what protection customers actually have. Are funds held in a way that reduces insolvency risk? Are they merely separated operationally? Are players told the truth about that? If your website implies stronger protection than your actual setup provides, that can turn into a nasty issue later.

Don’t oversell it. Say what the arrangement is. Make sure terms, policies, licence application materials, and banking explanations all say the same thing. Sounds obvious. Still gets missed alot.


What a usable setup looks like

There isn’t a single model that fits every operator, but the healthy setups tend to share the same bones:

  1. A licensed or contracting entity that clearly matches customer-facing terms
  2. Payment accounts opened in the right entity name, with a documented purpose
  3. A defined split between player funds and operating funds
  4. Reconciliation routines that actually happen, not just policy text
  5. Access controls so finance staff can’t improvise transfers without oversight
  6. AML review hooks for unusual deposit and withdrawal behaviour

That last point matters more than people expect. Player funds segregation is not separate from AML. If you’ve got payment routes nobody really understands, fragmented PSPs, or pooled collections coming in from multiple channels, your suspicious activity detection gets weaker. The money trail goes fuzzy.

For operators building the setup from scratch, this is usually where external help makes sense – especially around account design and PSP alignment. A lot of gambling businesses need a joined-up payment strategy and banking access plan because the issue isn’t just opening an account, it’s making sure settlements, reserves, withdrawals, and safeguarding logic all fit the licence model.


Cross-border operators get caught out more often

If you’ve got one licence, one brand, one market, life is easier. Not easy. Easier.

But many operators aren’t built like that. You may have a marketing company in one country, B2B tech in another, IP somewhere else, and a licensed B2C entity taking bets under a separate structure. Add a few PSPs, a crypto on-ramp, maybe a local payment collector in a target market, and suddenly your “simple” segregation model has six points where customer money can be mishandled or misdescribed.

Sound familiar?

This is where founders start relying on verbal explanations no compliance reviewer will accept. “It all gets swept at the end of the week” is not a framework. “Our finance team keeps track of it” is not a control. You need flowcharts, account lists, entity roles, and written treasury rules. Slightly tedious, yes. Still cheaper than trying to repair a damaged bank relationship.


Don’t leave the MLRO or compliance lead out of this

Another common miss: segregation gets designed by finance, while AML sits in a seperate lane. Then months later the MLRO finds out customer withdrawals are being funded through an account they can’t properly monitor, or a PSP is settling multiple products into one pool with poor reference data.

That’s how weak controls hide in plain sight.

Your MLRO or compliance lead should be involved early, especially if the business is changing jurisdiction, adding payment methods, or preparing for licence review. If that function is still thin, read what an MLRO actually does. A good one won’t just file reports and update policies. They’ll spot where the money flow story doesn’t hold together.


What to do this week

If you’re not sure your setup is clean, don’t start with legal memos. Start with the facts.

Pull these four things:

  • a list of every entity in the group and what each one does
  • a list of every bank account, EMI account, wallet, and PSP account receiving or paying customer money
  • a simple flowchart showing where deposits land and where withdrawals are paid from
  • your player balance reconciliation for a recent period

Then compare that against your customer terms, licence position, and AML procedures. If those don’t line up, you’ve found the real work.

Honestly, this is one of those areas where founders try to save time and end up creating a much bigger mess. Player fund segregation isn’t glamorous. But if you get it wrong, it bleeds into licensing, banking, and trust all at once. And once a regulator or bank loses confidence in how you handle customer money, getting it back is hard.

Best fix? Keep the structure boring. Clear entity. Clear account ownership. Clear reconciliations. Clear disclosure.

Boring wins here. Every time.

More insights