Payment providers close channels first. They ask who the customer is, where the money came from, and whether anyone is watching transactions. When those three answers are thin, the account gets limited and the channel quietly stops working. By the time a regulator writes to you, the money moving part of your business has usually already taken the hit.

Game and virtual goods companies hit this wall later than banks did, and that delay creates the surprise. A studio that sees itself as selling entertainment discovers it is running a value transfer business the moment its items acquire a cash price outside the game. This article sets out where that line sits, what regulators have published about it, what breaks when nobody owns it, and what a defensible setup looks like in practice.


Why in-game value attracts money laundering

In-game value has three properties that make it useful to someone moving illicit money.

It moves. Items and currency can be transferred between accounts, across platforms, and across borders in seconds. Transfers happen inside your systems, which means you hold the record of them.

It converts. An item priced in your store becomes cash on a third-party marketplace, a trading site, or a direct player-to-player sale. The conversion point sits outside your platform, so the cash-out link is often invisible to you.

Its price is opaque. Who decides what a rare item is worth? If the answer is "the market," then a seller can set any price and a buyer can pay it without either number looking strange on its own. Opaque pricing is what makes value insertion and withdrawal hard to spot after the fact.

FATF described exactly this structure in September 2026. In its report on the sector, it recorded that payment methods used in gaming and gambling include cash, e-wallets, mobile money and virtual assets, and that platform ecosystems depend on related services including social media platforms, digital marketplaces and software developers. It noted that some of these actors fall outside existing AML/CFT frameworks (FATF, Risks of Gaming and Gambling, September 2026).

FATF President Giles Thomson stated the risk in plain terms when the report launched: "Without robust safeguards, these sectors can be attractive gateways for fraudsters, professional money launderers and organised criminal networks" (FATF news release, 9 September 2026).

Two abuse techniques matter most for virtual goods businesses, because both leave traces in ordinary transaction logs:

  1. Placing value into the game and withdrawing it without real use. FATF flagged criminals using platforms to move money without actually gambling or playing, including through multiple small transactions kept below detection thresholds ("smurfing") (FATF news release, September 2026). In a virtual goods context this looks like a funded account, minimal play, then a transfer out or a high-value item moved onward.
  2. Identity fragmentation. FATF lists the use of multiple accounts and payment methods under different identities, and discrepancies between customer information and payment information, among its indicators of abuse (FATF news release, September 2026).

Whether this matters commercially comes down to one question: can value leave your platform and become money somewhere else?

What this looks like in your logs

A worked example helps, because the individual events look ordinary.

A player registers one Tuesday with an email address and a card held in one name. Over the following three weeks the account receives top-ups from four different payment instruments, three of which carry names that do not match the registered one. The account spends small amounts on consumables and one large amount on a single rare item. Nine days after purchase, the item transfers to an account opened eleven days earlier. That second account has played under three hours in total. Within a fortnight the receiving account lists the item on an external marketplace, where it sells for a price roughly four times the store price the operator charged.

Read each line alone and nothing crosses an obvious line. Read them together and you have the pattern FATF describes as moving money without meaningful play, combined with payment methods under different identities. The operator saw all six events as they happened. Nobody correlated them, because no control was watching for that sequence.

The gap here sits with correlation, which is the piece most game companies find hardest. Identity data lives in one system, payment data in another, item movement in game telemetry, and marketplace activity somewhere you cannot see at all. A monitoring setup that reads only one of those four streams will produce exactly this result: every event recorded, the pattern invisible.


Where the regulatory line sits

Three documents define most of what you will be asked about.

The FATF virtual asset definition

The FATF Standards apply to virtual assets, defined broadly as a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes. Recommendation 15 requires countries to identify virtual asset service providers, bring them under AML/CFT regulation, and license or register them (FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers, October 2021).

The 2021 update clarified the definitions of virtual assets and VASPs, along with guidance on stablecoins, peer-to-peer transfers, licensing and registration, and the travel rule. The practical test for a game operator is whether the activity is conducted as a business on behalf of customers and actively facilitates value transfer. Whether your studio falls inside your jurisdiction's definition of an obliged entity is a question for counsel in that jurisdiction, and the answer varies by country (FATF guidance, October 2021).

The European exclusion, and why it disappears

The Fifth Anti-Money Laundering Directive carved out one specific case. Its recital states that virtual currencies should not be confused with, among other things, "in-games currencies, that can be used exclusively within a specific game environment" (Directive (EU) 2018/843, recital 10).

Read that word carefully: exclusively. The exclusion holds while your currency cannot leave the game environment. The moment players convert items into money, that qualifier fails, and the carve-out goes with it. An exemption that depends on your players' behaviour, leaving your own design untested, deserves a second look during your next product review.

Where the sector sits now

FATF's September 2026 report marked its first detailed examination of risks associated with online and illegal gambling, drawing on input from more than 80 jurisdictions, written comments from 29 jurisdictions, and consultation with industry bodies and researchers. It explicitly covered online video and mobile gaming alongside casinos, betting and lotteries (FATF, Risks of Gaming and Gambling, September 2026).

On the virtual asset side, FATF's seventh targeted update found that 83% of surveyed jurisdictions had passed legislation implementing the travel rule, up from 73% in 2025, with 11 more reporting that implementation was under way. The update covers jurisdictions representing approximately 97% of the global virtual asset market (FATF news release, 16 July 2026).

Taken together, these three sources tell you what your bank already assumes: the perimeter around digital value is tightening, and gaming sits inside it.


What happens when you leave it unmanaged

The sequence rarely starts with a regulator.

Step one: the explanation gap. The underlying problem is that nobody can explain who the money came from. Player identity is an email address, funding arrives through a mix of cards, wallets and third-party top-ups, and item histories sit in game logs, which bear little resemblance to a financial record. You cannot answer the question "where did this money come from" with evidence.

Step two: the questions arrive. Your payment provider's risk team notices patterns it cannot resolve: deposits from accounts in different names, funding sources switching rapidly, withdrawal destinations unrelated to deposit origins. It raises a request. FATF's indicator list describes precisely these signals, including multiple payment methods in different names associated with the same account and discrepancies between customer and payment information (FATF news release, September 2026).

Step three: the account and the channel. The provider limits the account or terminates the relationship. Correspondent banking relationships upstream apply their own filters, and losing one processor often removes access to several at once. Because most operators concentrate their acquiring with one or two providers, this step happens faster than teams expect.

Step four: operations stall. Revenue collection stops. Payouts to players and suppliers stop with it. Studio partners and platform stores begin asking questions of their own, because their agreements pass the obligation down to you.

Two consequences run alongside this. Investors conducting diligence ask for evidence of AML controls, and a missing or thin programme stalls financing and partnership discussions. Take the question of entity and director liability to local counsel, because the answer varies by jurisdiction and guessing carries its own cost (FATF guidance, October 2021).


What a defensible setup looks like in practice

Five steps, each with a pass criterion you can test. The order matters, because each step depends on the one before it. Working cash-out paths is pointless before you know which cash-out paths exist, and building monitoring scenarios before you have a risk model produces alerts nobody can triage. Teams that skip step one tend to rebuild their programme within twelve months.

One caveat on resourcing. None of these five steps require a large team. They require that someone owns each of them by name, that decisions get written down when they are made, and that the written version matches what the system does. Reviewers find the second part where written policy and live configuration have drifted apart.

1. Map every cash-out path you did not build

List every route by which in-game value becomes money: third-party marketplaces, direct player trading, gift cards, reseller arrangements, account sales, cross-title wallets, and anything your community uses to settle trades. Interview your player support and anti-fraud teams, because they already know which paths are real.

Pass criterion: a written inventory covering every path, each marked with whether you can observe it, and where you cannot, why.

2. Score customers continuously after signup

Static onboarding checks expire. Move to a model where risk updates when behaviour changes: spending velocity shifts, funding instruments multiply, devices or locations change, withdrawals diverge from deposits. FATF cautions that a single indicator is not itself evidence of illicit activity, but several appearing together justify examination (FATF, Risks of Gaming and Gambling, September 2026).

Pass criterion: a documented list of behavioural triggers, each mapped to a defined action, with evidence that triggers fire inside production systems and stay active beyond policy documents.

3. Monitor transactions for gaming patterns, using gaming typologies

Financial services monitoring scenarios were designed for accounts and wires. They miss the patterns that matter here: value entering and leaving with minimal play, third-party funding of a single account, rapid transfers to unrelated beneficiaries, and structuring below your thresholds. FATF specifically named structuring of deposits below reporting thresholds and withdrawals disproportionate to actual activity among the behaviours it documented (FATF news release, September 2026).

Pass criterion: at least three monitoring scenarios specific to your product's cash-out mechanics, with alert volumes tuned low enough that analysts actually work them.

4. Write down what a good source of funds answer looks like

For high-spending players, source of funds will be asked. Define in advance what evidence satisfies you at each exposure level, what the escalation path is, and who has authority to decline a relationship.

Pass criterion: a tiered evidence standard documented and applied, with declined cases recorded.

5. Get outside eyes on the whole thing once

Programmes drift. Written policy, live configuration, and actual practice diverge within a year. An independent test tells you where.

Pass criterion: a completed review with dated findings, owners assigned, and remediation tracked.


What your payment provider will ask before it keeps you

Expect these requests, and prepare answers before they arrive. Each one maps to a question the provider's own supervisor will ask it, which is why they arrive in this shape:

  • Your written AML policy, dated and approved by someone named. Asked because an undated policy with no owner signals that nobody owns the outcome.
  • Evidence that customer due diligence actually runs, including sample outputs. Asked because a policy document demonstrates intent, and sample outputs demonstrate operation.
  • Threshold values and the reasoning behind them. Asked because unexplained thresholds are indistinguishable from arbitrary ones during a supervisory review.
  • Alert volumes, review turnaround time, and escalation records. Asked because an untouched alert queue is the standard finding in enforcement actions.
  • The accountable owner, with a named deputy. Asked because single-person dependencies are treated as control weaknesses.

The fastest way to lose a processor is to send a policy document and nothing else. Processors want to see the outputs of your system, because outputs demonstrate operation where policy only demonstrates intention.


FAQ

We sell cosmetic items only. Does any of this apply?

Ask whether the items can be traded or sold outside your environment. Cosmetics trade actively precisely because their supply is constrained, and scarcity is what makes a cash price possible. The item's function inside the game has no bearing on its value outside it.

Our terms of service prohibit account trading. Is that enough?

Prohibition written into terms establishes a rule. It does not establish that nobody breaks it, and it gives you no data when someone does. Regulators and payment providers ask what you detected and how you responded, because enforcement records carry weight where policy text carries little.

Do we need a licence?

Licensing and registration obligations differ by jurisdiction and by activity, and they sit with your counsel and your regulator. This article addresses customer due diligence and transaction monitoring obligations, which attach to obliged entities and flow through commercial relationships regardless of your licensing position.

How much monitoring counts as adequate?

Adequacy is judged against your own documented risk assessment. Start by writing down the cash-out paths and typologies that apply to your product, then design scenarios against them. A programme built from a generic template fails an examination in the same way a missing one does, because reviewers test whether controls match stated risks.

A provider closed our account last month. What now?

Recovery starts with evidence. Assemble your written policy, sample due diligence outputs, monitoring records and escalation history, then approach replacement providers with that package prepared. Approaching a new provider with nothing changes the outcome, because the second review asks the same questions the first one did.


A low-cost next step

If your items can leave your platform, someone will eventually ask you to describe how you know who your players are. That question is easier to answer now than during a review.

Send us your current customer due diligence flow. We will point out where it is most likely to be challenged, and what evidence would close each gap. One review of your existing process, feedback within two working days, no commitment beyond that.

UWAY implements identity verification, business verification and transaction monitoring for gaming, virtual goods, payments and online entertainment companies, covering process design, system integration, rule configuration and ongoing monitoring. We do the customer due diligence and transaction monitoring part, and we do it deeply.

Licence applications and company formation sit outside our scope.


Sources

All links accessed 2026-09-26.

  1. FATF (2026), Risks of Gaming and Gambling, September 2026, Paris. https://www.fatf-gafi.org/en/publications/Methodsandtrends/risks-of-gaming-and-gambling.html
  2. FATF (2026), "FATF warns of emerging risks in gaming and gambling and publishes new risk indicators", news release, 9 September 2026. https://www.fatf-gafi.org/content/fatf-gafi/en/news/risks-of-gaming-and-gambling-2026.html
  3. FATF (2021), Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers, October 2021, Paris. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html
  4. FATF (2026), "FATF calls for closing of regulatory gaps as virtual asset illicit finance risks become more complex", news release, 16 July 2026. https://www.fatf-gafi.org/en/news/targeted-updated-va-vasps-2026.html
  5. European Union, Directive (EU) 2018/843 of 30 May 2018 amending Directive (EU) 2015/849, recital 10. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32018L0843