Compliance, AML & RG B07 / 03

Source of Funds in iGaming: Definition, How Operators Verify It and Why It Matters for High-Value Customers

Source of Funds (SOF) is the documented evidence of where a customer's gambling money comes from: salary, business income, investments, inheritance, savings, property sale or other legitimate sources. SOF verification is required by AML and affordability frameworks for higher-value…

iGaming Glossary · Category: Compliance, AML & RG · Relevant for: Compliance, MLRO, VIP Management

iGaming GlossaryComplianceMLROVIP Management

TL;DR

Source of Funds (SOF) is the documented evidence of where a customer's gambling money comes from: salary, business income, investments, inheritance, savings, property sale or other legitimate sources. SOF verification is required by AML and affordability frameworks for higher-value customers and is one of the operational frontlines where compliance pressure meets commercial commercial pressure most directly. Done well, SOF protects both the operator and the player. Done poorly, it is the failure mode behind some of the largest regulatory fines in iGaming history.

Mechanics 02

How it works

Source of Funds verification typically involves customer-provided documentation reviewed by the operator's compliance team. Common SOF documentation:

  • Salary verification: payslips, tax returns, employment contracts.
  • Business income: company accounts, dividend records, business tax returns.
  • Investment income: portfolio statements, dividend records, investment account documents.
  • Inheritance or gifts: probate documents, gift letters, source documentation from the giver.
  • Property sale: sale documents, completion statements, solicitor confirmations.
  • Savings: bank statements showing accumulated savings consistent with claimed sources.
  • Cryptocurrency: detailed exchange records, wallet history, source of original purchase.

SOF requests are typically triggered by deposit thresholds, customer behaviour patterns or risk-flag events. The customer is asked to provide documentation, the compliance team reviews it for authenticity and consistency with the customer's profile, and decisions are documented for audit. SOF is distinct from Source of Wealth (SOW), which examines the broader origin of the customer's overall wealth rather than specific gambling funds.

Business context 03

Why it matters in iGaming

SOF verification is one of the most operationally challenging compliance processes. It requires customer documentation submission, expert review, judgment calls on adequacy and decisions that may result in account restriction or closure. The friction is real: customers often resist SOF requests and may close accounts rather than comply. This commercial pressure has historically led some operators to under-enforce SOF requirements, which has produced some of the most prominent AML enforcement cases.

Different teams have different SOF responsibilities:

  • Compliance teams design SOF policy, review documentation and make decisions.
  • VIP management teams handle customer-facing communications when SOF is requested.
  • MLRO maintains personal accountability for SOF framework adequacy.
  • Risk and AML teams use SOF outcomes as inputs to ongoing customer monitoring.

SOF also has affordability implications. A customer providing salary documentation showing 40,000 EUR annual income but depositing 200,000 EUR per year creates an affordability concern even if the SOF documentation is authentic. SOF verification should be evaluated alongside affordability assessment, not as a separate isolated process. Operators that verify SOF without affordability framing miss these signals systematically.

Failure modes 04

Common mistakes and how operators get SOF wrong

Trigger thresholds set too high. Operators that wait for customers to deposit hundreds of thousands of euros before requesting SOF documentation expose themselves to clear regulatory criticism. Risk-based triggers should fire at meaningful but reasonable deposit and behaviour thresholds.

Documentation accepted without verification. SOF documentation that is reviewed only for presence ("customer provided a payslip") rather than authenticity and adequacy fails the compliance test. Verification depth should include authenticity checks and consistency with customer profile.

Commercial pressure driving SOF outcomes. Operators where VIP managers can override compliance decisions on SOF face significant regulatory exposure. Several major AML cases have specifically cited compliance independence failures in SOF processes.

Documentation gaps not closed. Customers sometimes provide partial SOF documentation that doesn't fully cover their gambling activity. Operators that accept partial documentation rather than requesting completion miss the regulatory standard.

No ongoing review. SOF documentation accepted at one point may become outdated or contradicted by subsequent customer behaviour. Periodic re-verification at meaningful triggers prevents documentation that aged out from supporting current risk decisions.

Cryptocurrency complexities mishandled. Crypto-funded gambling activity requires specific SOF approaches different from fiat money. Operators applying fiat-only SOF frameworks to crypto deposits often miss material red flags.

What good looks like 05

What good looks like

SOF practices observed in well-run operators:

  • Risk-based triggers at deposit and behavioural thresholds appropriate to jurisdiction.
  • Independent compliance authority for SOF decisions, with clear escalation paths.
  • Documentation verification including authenticity checks, not just presence.
  • Cross-checking SOF against affordability assessment for consistency.
  • Ongoing review of SOF documentation as customer behaviour evolves.
  • Crypto-specific SOF frameworks accommodating cryptocurrency-funded activity.
  • Documented audit trail for all SOF decisions, including rejected or escalated cases.
Gamblitude 07

How Gamblitude supports SOF workflows

Gamblitude does not store or process SOF documentation, which sits in dedicated compliance systems. What Gamblitude provides is the behavioural context that informs SOF decisions: deposit patterns, wagering activity, customer profile changes and cross-checks against affordability frameworks. Compliance teams use Gamblitude analytics to identify customers warranting SOF requests, evaluate consistency between behaviour and documented sources and surface anomalies for review. Insight Radar surfaces patterns that may warrant SOF re-verification at customer level.

Explore AI for iGaming ↗
Questions 08

FAQ

When triggers defined in your AML and affordability framework fire. Common triggers include cumulative deposit thresholds, single high-value deposits, behaviour inconsistent with customer profile, jurisdictional risk factors and time-based re-verification. Specific thresholds vary by market and licence conditions; operators should align with regulator expectations for their jurisdiction.

It depends on the claimed source. Salary income typically requires payslips and tax returns. Business income requires company accounts and tax filings. Investment income requires portfolio statements. Property sale requires completion documents. Whatever documentation is requested, it must be authenticated and consistent with the customer's overall profile. Standardised SOF questionnaires help ensure consistent treatment.

Generally no, and this is increasingly regulator-emphasised. Compliance independence on SOF decisions is essential. Operators where commercial functions can override compliance face significant regulatory exposure. Several major AML cases have specifically cited compliance independence failures in SOF processes.

Closely. SOF documentation establishes where money comes from. Affordability assessment evaluates whether the customer can afford to lose what they're depositing. The two should be cross-checked: a customer with documented 40,000 EUR salary but 200,000 EUR annual deposits has both an SOF anomaly and an affordability concern. Operators that treat them as separate processes miss these connections.

Crypto SOF requires specific treatment. Documentation should establish the original source of fiat used to purchase the cryptocurrency, the chain of custody through wallets and exchanges and consistency with the customer's overall profile. Crypto-only documentation (showing the crypto transactions without fiat origin) is generally inadequate. Operators accepting crypto deposits without crypto-specific SOF frameworks often miss material red flags.

Explore next 09

Further reading

Keep the glossary useful

Found a mistake or want a term added to the iGaming Glossary? Let us know.

Browse the complete glossary or see how governed definitions work across dashboards, reports, alerts and AI answers.