Original research - checked 2026-07-25
Research question
Which crypto-specific risks require additional evidence beyond a conventional casino stack?
Methodology
- Scope: the named product sample or control areas in the evidence matrix below.
- Sources: current official supplier pages, regulators, government standards, open standards, and testing guidance.
- Classification: Yes is explicit support; Partial is incomplete support; Not found is no evidence in the reviewed public source; Unknown is not evaluated.
- Checked: 2026-07-25. This is a point-in-time public-evidence record.
- No inference: a general standard does not prove a supplier implementation, and a missing public disclosure does not prove a missing capability.
Evidence matrix
| Risk or control | Primary anchor | Public support | Evidence to retain | Test scenario | Boundary | Primary source |
|---|---|---|---|---|---|---|
| Business risk assessment | FATF virtual assets and UKGC risk guidance | Yes | Products, assets, geographies, channels, counterparties, threats, controls, and residual risk | Re-score a new asset and high-risk corridor | Local implementation and licence rules apply | FATF |
| VASP status and counterparties | FATF virtual assets | Yes | Registration or licensing analysis, counterparty due diligence, and prohibited relationship rules | Onboard and reject representative counterparties | Status varies by service and jurisdiction | FATF |
| Customer due diligence | FATF Recommendations | Yes | Identity, verification, beneficial ownership, purpose, risk, enhanced checks, and review | Trace normal, high-risk, and failed CDD | Thresholds and documents are local | FATF Recommendations |
| Travel rule and transfers | FATF virtual assets | Yes | Originator and beneficiary data, transfer controls, exceptions, and records | Send, receive, reject, and hold test transfers | Technical implementation varies by jurisdiction | FATF |
| Transaction monitoring and reporting | FATF Recommendations | Yes | Rules, alerts, blockchain signals, cases, decisions, reports, and tuning | Replay suspicious and false-positive patterns | Tool output does not replace operator judgment | FATF Recommendations |
| Source of funds and wealth | UKGC crypto guidance | Yes | Risk-triggered evidence, assessment, decision, limits, and review trail | Escalate a high-value volatile-asset case | Great Britain is one regulatory anchor | UK Gambling Commission |
| Custody, volatility, and insolvency | UKGC crypto guidance | Yes | Custody model, key control, conversion, valuation, counterparty, insolvency, and incident plan | Lose a dependency and execute recovery | Technical custody assurance is product-specific | UK Gambling Commission |
| Consumer information | UKGC crypto guidance | Yes | Fees, conversion, volatility, settlement, withdrawal, custody, and complaint disclosures | Verify disclosures across a full transaction | Local consumer rules may add duties | UK Gambling Commission |
| Card-payment boundary | PCI DSS | Partial | Separate card and virtual-asset flows, PCI scope, PSP roles, and segmentation | Trace every account-data path | Only applicable where payment-account data is in scope | PCI Security Standards Council |
| Application and smart-contract security | OWASP ASVS | Partial | Versioned application requirements, code review, test, dependency, key, and remediation evidence | Test auth, access, transaction, and failure controls | Smart contracts need additional specialist assurance | OWASP |
Findings
1. Crypto adds controls; it does not remove them
Virtual-asset status, counterparties, transfer data, chain signals, custody, valuation, and disclosures add to the casino control stack.
2. No-KYC is not a general risk exemption
CDD scope and thresholds are legal and jurisdictional questions; product positioning cannot answer them.
3. Blockchain analytics is evidence input
A risk score or alert requires documented ownership, investigation, decision, reporting, tuning, and retention.
4. Custody and conversion are operational dependencies
Key control, pricing, counterparties, insolvency, reconciliation, incident response, and customer communication require explicit tests.
How to use the evidence
- Remove fields that are not applicable to the target entity, market, product, and operating model; document why.
- Assign one accountable owner and one evidence artifact or test to every retained field.
- Keep Yes, Partial, Not found, and Unknown separate through RFP, demo, test, reference, and contract review.
- Convert supplier-specific gaps into versioned proposal, implementation, SLA, data, security, and exit schedules.
- Re-check source versions and effective dates before a procurement or launch decision.
Limitations
This crosswalk is not legal advice, a country-by-country rules matrix, or a product certification. FATF standards require local implementation, and gambling, payments, sanctions, tax, consumer, and virtual-asset rules vary by jurisdiction and entity.
Primary sources
- FATF - Virtual assets - Risk-based virtual-asset controls, licensing or registration, CDD, recordkeeping, reporting, supervision, and travel-rule principles.
- FATF Recommendations - Risk-based AML/CFT, customer due diligence, monitoring, recordkeeping, reporting, and country-implementation questions.
- UK Gambling Commission - Blockchain technology and crypto-assets - Great Britain risk, source-of-funds, volatility, custody, insolvency, and consumer-information considerations for crypto-assets.
- UK Gambling Commission - Emerging money-laundering and terrorist-financing risks - Current Great Britain risk indicators and operator risk-assessment considerations, including crypto-related exposure.
- PCI Security Standards Council - PCI DSS - Payment-account data security requirements for relevant merchants, processors, service providers, and connected systems.
- OWASP - Application Security Verification Standard - Versioned and testable web-application security requirements that can be used in procurement and verification.
Frequently asked questions
Does a Yes classification prove that a supplier complies?
No. Yes means the cited primary source explicitly supports the control or disclosure field. Supplier implementation still requires current product evidence and buyer verification.
Does Not found mean a capability is absent?
No. It means the reviewed public sources did not expose the evidence. Authenticated documentation, tests, proposals, or contracts may change the classification.
Can the CSV be used as an RFP starting point?
Yes, after adapting applicability, ownership, evidence, tests, and legal requirements to the target entity, jurisdiction, product, and operating model.
Concept map
Related concepts and decision guides
- White-Label and Crypto Casino Research guide
- Use dated primary-source crosswalks and downloadable evidence matrices to turn software claims into buyer-owned verification tasks.
- White-Label Casino Launch Evidence Crosswalk 2026
- Define the evidence a white-label or turnkey casino buyer needs across licence scope, responsibilities, testing, AML, payments, data, reliability, and exit.
- crypto casino software
- Scope: This page explains the technology infrastructure used to build cryptocurrency-enabled iGaming platforms, including software architecture, security, and compliance capabil...
- Crypto Casino Payment Gateway
- Compare custody, settlement, asset coverage, compliance tooling, and integration.
- White Label Bitcoin Casino
- Evaluate crypto payment support, custody model, game delivery, and operating controls.
Evidence layer
Primary references and verification limits
Sources were checked on . They support the standards and verification questions used in this guide. They do not prove a supplier-specific price, market eligibility, implementation result, or private product claim; buyers should request current, versioned evidence for those points.
- FATF - Virtual assets Intergovernmental standard setter. Risk-based virtual-asset controls, licensing or registration, CDD, recordkeeping, reporting, supervision, and travel-rule principles.
- FATF Recommendations Intergovernmental standard setter. Risk-based AML/CFT controls, customer due diligence, monitoring, recordkeeping, and country-specific implementation questions.
- UK Gambling Commission - Blockchain technology and crypto-assets Regulator. Great Britain risk, source-of-funds, volatility, custody, insolvency, and consumer-information considerations for crypto-assets.
- UK Gambling Commission - Emerging money-laundering and terrorist-financing risks Regulator. Current Great Britain risk indicators and operator risk-assessment considerations, including crypto-related exposure.
- PCI Security Standards Council — PCI DSS Industry standards body. Payment account data security requirements for merchants, processors, service providers, and systems that can affect the cardholder data environment.
- OWASP - Application Security Verification Standard Open application-security standard. Versioned and testable web-application security requirements that can be used in procurement and verification.
- OWASP Application Security Verification Standard Open application-security standard. Testable web-application security requirements and procurement-ready verification criteria.
- NIST Cybersecurity Framework 2.0 Government standards body. Cybersecurity governance, risk management, protection, detection, response, and recovery outcomes.
- UK Gambling Commission — Remote gambling and software technical standards Regulator. Remote gambling software controls, security requirements, player-facing technical controls, and jurisdiction-specific verification questions.
- UK Gambling Commission — Testing strategy for remote gambling software Regulator. Testing, release control, audit evidence, change management, independent review, and production assurance questions.