The processor terminates the relationship first. Your bank follows, because it asks the same question and gets the same answer you gave the processor. When a payment provider asks who owns customer due diligence on your players, "the processor handles that" ends the conversation, and it ends it in your disfavour.

This question reaches game and virtual goods companies at a predictable moment: during onboarding with a new provider, during a renewal review, or during the week after an existing provider sends a questionnaire. It reaches you because the provider has to answer the same question to its own supervisor. This article sets out where the responsibility actually sits, why the ambiguity exists, and how to close it in writing.

For the wider perimeter around tradable game value, see In-Game Items and AML Obligations for Game Operators.


Why this argument starts in the first place

The dispute has a structural cause, so it recurs with every integration.

Player onboarding for a game runs through a checkout page built by the processor or by an orchestration layer. The processor collects the name, the document, sometimes a selfie, and returns a pass or fail. Your systems record the outcome, and in many setups they do not retain the underlying data. Both parties now hold part of the picture and neither holds a complete customer file.

Two incentives pull in opposite directions. The processor wants to control the flow, because its own licence depends on it and because a failed check costs it money. The operator wants the flow to convert, because every additional step costs players. Both parties can honestly describe themselves as doing due diligence while producing a file that neither can produce on request.

FATF documented this shape of problem at sector level in September 2026. It recorded that gaming and gambling platforms depend on a wide range of related services, including social media platforms, digital marketplaces and software developers, and noted that these actors may fall outside existing AML/CFT regulatory frameworks (FATF, Risks of Gaming and Gambling, September 2026).

When a chain has four participants and only two of them are regulated, the responsibility question gets answered differently depending on who is asking. That inconsistency is the actual risk. It is resolved against whichever party cannot produce evidence.


What the standard says about relying on someone else

The FATF Recommendations address third-party reliance directly. Recommendation 17 permits countries to let institutions rely on third parties to perform elements of customer due diligence, subject to four conditions, and closes with the sentence that addresses responsibility when reliance is permitted: "Where such reliance is permitted, the ultimate responsibility for CDD measures remains with the financial institution relying on the third party" (FATF, The FATF Recommendations, as amended June 2026).

The four conditions attached to that permission are worth reading closely, because each one is a test you can run on your own setup:

  • The relying party must immediately obtain the necessary information covering identity, beneficial owner, and the purpose and intended nature of the relationship
  • The relying party must be able to get copies of identification data and other relevant documentation from the third party on request, without delay
  • The relying party must satisfy itself that the third party is regulated, supervised or monitored for, and has measures in place for compliance with, CDD and record-keeping requirements
  • Country risk is a factor when deciding which countries an acceptable third party can sit in

Two things follow for a game operator. First, the principle is that responsibility for customer due diligence is not transferable by agreement, so a clause stating that the processor owns KYC does not move the underlying exposure. Second, whether your entity is an obliged entity under your jurisdiction's implementation of the FATF standard is a question for counsel in that jurisdiction, and the answer determines which obligations attach to you directly (FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs, October 2021).

The practical test in the first bullet catches most operators. Can you obtain the underlying identity data immediately, on request, today? If your integration stores only a pass or fail flag, the answer is no, and the second condition fails with it.


What happens when nobody owns the file

Step one: the request arrives and produces nothing. A processor or bank asks for a customer file on a specific player, or for evidence of your due diligence on a sample. You have the transaction record and the KYC outcome. You contact the processor for the underlying documents and wait.

Step two: the wait is itself the answer. FATF's condition requires immediate access, without delay. A two-week turnaround reads as absence of control. Reviewers record it as an inability to produce records on request, which is a finding on its own, separate from the quality of the underlying checks.

Step three: the relationship is reassessed. Payment providers and banks make portfolio decisions on the basis of merchant risk. An operator that cannot evidence customer due diligence is a merchant that creates reporting obligations the provider cannot discharge. The provider terminates or declines renewal, and it cites its own obligations when it does.

Step four: collection stalls. Losing an acquirer means losing the ability to take money. Because most operators run one or two acquiring relationships, recovery takes weeks to months, and every replacement provider asks the same question at onboarding. FATF's indicator list describes the underlying patterns that trigger these reviews, including discrepancies between customer information and payment information, and multiple payment methods in different names associated with one account (FATF news release, 9 September 2026).

One consequence runs alongside. Institutional investors conducting diligence ask for AML evidence. A programme that depends entirely on a processor's checks withers under that scrutiny, because the question is what you can demonstrate, and the demonstration belongs to the party holding the data.


How to settle it in writing

Four steps, each with a pass criterion.

1. Establish which party holds the underlying data

Read the integration as it runs today, not as the contract describes it. Identify every field collected at checkout, where it is stored, who can retrieve it, and how fast.

Pass criterion: a one-page data map showing each CDD field, its storage location, its owner, and retrieval time. Any field you cannot retrieve the same day goes on the remediation list.

2. Fix the retrieval gap before anything else

Where the processor holds documents you cannot access, obtain contractual retrieval rights with a defined service level, plus a technical path to exercise them. A contractual right with no technical path has the same value as no right at all.

Pass criterion: a tested retrieval. Pull ten historical customer files end to end and record how long each one took.

3. Decide what you run yourself, and write the decision down

Choose which checks you perform directly, which you delegate, and why. The reasoning belongs in your risk assessment, because a reviewer tests whether delegation decisions follow from documented risk, and a decision traceable to convenience fails that test.

Pass criterion: a written allocation decision, dated, cross-referenced to your risk assessment, with a named owner.

4. Verify the processor once, then periodically

FATF's third condition requires you to satisfy yourself that the third party is regulated, supervised or monitored for CDD compliance. That is a recurring obligation, evidenced by periodic review.

Pass criterion: a dated due diligence file on each processor, refreshed on a schedule you have set, recording its regulatory status and any enforcement history.


The questions to put to your processor

Ask these in writing. Written answers become evidence, and silence on any of them tells you where your exposure sits.

  1. Which CDD elements do you perform on our players, and which do you expect us to perform?
  2. Can we obtain the underlying identity data and documents on request, and within what timeframe?
  3. Will you provide records to us for regulatory requests and for our own audits?
  4. Are you regulated, supervised or monitored for AML/CFT purposes, and by which authority?
  5. What do you expect us to hold when you escalate a player for review?
  6. What happens to our access to historical records if the relationship ends?

Question six is the one teams skip, and it is the one that matters most. Access to historical CDD records after termination is rarely covered, and its absence is what turns a provider change into a compliance gap.


FAQ

Does using a payment processor transfer our KYC responsibility?

No. A processor may perform parts of customer due diligence, but the operator must understand which obligations attach to it under the applicable jurisdiction and must be able to evidence the checks it relies on. Contract wording alone does not solve an inaccessible customer file.

What should a game operator be able to retrieve from its processor?

At minimum, the identity information, beneficial-owner information where relevant, purpose and intended nature of the relationship, and supporting identification documents needed to evidence the due diligence performed. The retrieval path and service level should be tested on historical files.

How often should a processor's AML controls be reviewed?

Set a recurring review based on your documented risk assessment. The review should cover the processor's regulatory status, supervision, CDD and record-keeping controls, enforcement history, access to historical records, and any changes to the integration or data flow.

A low-cost next step

If your processor performs player checks and you cannot retrieve the underlying documents today, that gap is worth closing before anyone asks you to produce them.

Send us the KYC clause in your processor agreement along with your onboarding flow. We will mark where responsibility is unclear and what would close each gap. One review, feedback within two working days, no commitment beyond it.

UWAY implements identity verification, business verification and transaction monitoring for gaming, virtual goods, payments and online entertainment companies, covering process design, system integration, rule configuration and ongoing monitoring. We do the customer due diligence and transaction monitoring part, and we do it deeply.

Licence applications and company formation sit outside our scope.


資料來源

All links accessed 2026-09-27.

  1. FATF (2026), The FATF Recommendations, as amended June 2026, Recommendation 17 (Reliance on third parties). https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
  2. FATF (2026), Risks of Gaming and Gambling, September 2026, Paris. https://www.fatf-gafi.org/en/publications/Methodsandtrends/risks-of-gaming-and-gambling.html
  3. FATF (2026), "FATF warns of emerging risks in gaming and gambling and publishes new risk indicators", news release, 9 September 2026. https://www.fatf-gafi.org/content/fatf-gafi/en/news/risks-of-gaming-and-gambling-2026.html
  4. FATF (2021), Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers, October 2021, Paris. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html