Casino News

PAGCOR AML Requirements for Casinos: 2026 Compliance Guide

Jericho
Post by
Jericho

A PHP 5 million covered-transaction benchmark, a separate PHP 500,000 reporting reference, and a five-working-day filing window define only the visible edge of casino AML compliance in the Philippines. The harder issue in 2026 is operational: PAGCOR's risk-review messaging says the casino sector remains high risk for money laundering, so operators must turn static KYC files, source-of-funds checks, sanctions screening, transaction monitoring, and junket oversight into one auditable control system. PAGCOR's 2020 casino AML guidelines established the common baseline. The later PAGCOR regulatory orders show how supervision has moved toward more targeted controls.

Table of Contents

Why PAGCOR Casino AML Compliance Matters in 2026

The 2026 risk-review push changes the question casino compliance teams must answer. The issue is no longer whether an operator has an AML policy, a customer due diligence form, or an STR procedure. The issue is whether those controls identify and escalate risk consistently across the casino floor, online systems, payment activity, redemption events, and junket relationships.

PAGCOR's message requires licensed casinos and gaming support service providers to review and strengthen their AML/CTF frameworks after a sector-wide assessment found the industry remains high risk for money laundering. That finding makes continuous risk recalibration more important than a one-time policy refresh. It also places pressure on boards and senior management to show that risk appetite, staffing, technology, testing, and remediation reflect the regulator's assessment.

The regulatory direction began with the 2020 casino AML framework, approved by PAGCOR's Board of Directors on March 12, 2020. The guidelines apply to casinos within PAGCOR's territorial jurisdiction, including internet-based and ship-based casinos, and require a risk-based approach built around customer due diligence, ongoing monitoring, and suspicious transaction reporting. Operators and affiliates tracking the wider Philippine casino environment should distinguish that common baseline from the deeper controls now expected for higher-risk channels.

What the high-risk finding changes

A credible 2026 program should connect:

Dimension Pre-2026 Baseline 2026 Expectation
Risk assessment Documented AML/CTF framework Re-run and update risk assessments after the high-risk sector finding
Source of funds Obtain information under CDD procedures Strengthen verification and connect evidence to observed activity
Junkets Apply enhanced controls where required Maintain separate documentary traceability and monitoring logic
Monitoring Detect reportable or suspicious activity Recalibrate scenarios for emerging typologies and escalation quality
Governance Demonstrate policy ownership Make board accountability, testing, and remediation visible

The likely business impact is not limited to compliance staffing. Weak integration can delay STR decisions, create inconsistent treatment between land-based and online operations, and leave management unable to demonstrate why an alert was closed or escalated. In 2026, renewal activity should therefore be treated as a rebasing of the control environment, not a routine paperwork exercise.

The Legal Foundation Behind PAGCOR AML Requirements

Philippine casino AML obligations sit on a layered framework. Each layer has a different function, and operators create avoidable gaps when they treat PAGCOR licensing rules and AMLC reporting rules as interchangeable.

The first major step was Republic Act No. 10927, which designated casinos as covered persons under the Anti-Money Laundering Act. The implementing rules took effect on November 4, 2017, and casinos were required to register with the Anti-Money Laundering Council within 90 days from effectivity. The registration requirement matters because it places casino operators inside the national AML reporting system rather than leaving supervision solely within the licensing relationship.

AMLC owns the national AML reporting and covered-person framework. That includes the reporting architecture and applicable transaction thresholds. PAGCOR, by contrast, regulates the casino operator directly and translates AML/CTF expectations into sector-specific operating requirements, supervisory orders, and licensing consequences.

A timeline chart illustrating the PAGCOR AML regulatory stack and legal compliance requirements for casino operators.

How the rules accumulated

PAGCOR's 2020 Anti-Money Laundering/Countering the Financing of Terrorism Guidelines for Casinos created a standardized compliance baseline for land-based, internet-based, and ship-based casinos within its territorial jurisdiction. The framework expects customer due diligence, ongoing monitoring, and suspicious transaction reporting under a unified risk-based model. The later regulatory environment is best understood as an extension of that baseline, not a replacement for it.

The next layer arrived in December 2023, when PAGCOR issued enhanced due diligence requirements for casinos and junket operators. Those requirements must be incorporated into casino-junket agreements and require a Junket Transaction Monitoring Form and a Customer Due Diligence Form for Junket Players. The documentation signals that junket relationships require separate oversight and cannot be treated as ordinary host-led customer acquisition.

The 2026 risk-review messaging adds supervisory urgency. PAGCOR expects operators to update internal risk assessments and strengthen source-of-funds verification, sanctions screening, transaction monitoring, and STR processes. The legal stack therefore moves from statutory coverage, to national reporting, to casino-specific controls, to segment-specific EDD, and finally to continuous risk recalibration.

Customer Due Diligence and KYC Standards

Customer due diligence should operate as a decision system, not a form-collection exercise. The casino needs to know who the customer is, who ultimately controls or benefits from relevant funds, why the customer uses the product or channel, and whether activity remains consistent with the risk profile over time.

A walk-in mass-market player may enter through standard identification and ordinary transaction monitoring. That customer still needs a reliable identity record, but the operator shouldn't treat the initial check as the end of the relationship. A rated VIP, by contrast, may require deeper information about occupation, business interests, expected activity, wealth, and the source of funds supporting play.

Junket players create a distinct control problem. The junket operator may introduce or service the customer, but the licensed casino remains responsible for understanding the player and the relationship. Reliance on a junket-provided identity without independent verification leaves a break in the audit trail, particularly when funding, gaming activity, and redemption records sit in different systems.

Applying tiered CDD

Enhanced due diligence becomes especially important when the customer is a politically exposed person, uses complex ownership structures, presents unexplained wealth, or arrives through a higher-risk channel. A PEP introduced by a host shouldn't receive reduced scrutiny because the relationship is commercially valuable. The operator should identify the person, establish the source of wealth and source of funds, obtain the required approvals, and monitor activity continuously.

CDD Level Player Scenario Required Identification BO and SOF Treatment
Standard CDD Walk-in mass-market player Verify identity and retain the customer record Record relevant ownership or funding information when applicable and monitor activity
Risk-based CDD Rated VIP with higher-value or unusual activity Expand identity and profile information Obtain proportionate source-of-funds and source-of-wealth evidence
Enhanced CDD PEP, complex ownership, unusual funding, or elevated geography risk Apply deeper verification and management approval Establish beneficial ownership and corroborate the source of wealth and funds
Junket CDD Player routed through a junket operator Complete the casino's own customer file and the applicable junket form Link the player, junket agent, funding, gaming, and redemption records

The Customer Due Diligence Form and Customer Due Diligence Form for Junket Players should feed the same customer risk record. Beneficial ownership isn't a one-time field that can remain unchanged while the customer's funding pattern shifts. A material change in activity, ownership information, or source-of-funds explanation should trigger review and, where appropriate, enhanced due diligence.

Operators also need clear handoffs. Front-of-house staff can identify and pause an incomplete onboarding event, the cage or cashier can capture funding and payout evidence, the AMLCO can assess risk and escalation, and investigations staff can document the rationale. Payment and compliance teams reviewing the broader gaming transaction environment should ensure payment controls don't sit outside the casino's AML case workflow.

STR, CTR, and Covered Transaction Reporting

Reporting obligations contain two different tests. A covered transaction report is driven primarily by the applicable threshold and transaction rules. A suspicious transaction report is driven by reasonable suspicion, so a transaction can require an STR even when it doesn't reach a covered-transaction threshold.

The principal benchmark is PHP 5 million for covered transactions, including applicable single or aggregated activity, while separate reporting guidance refers to PHP 500,000 for certain casino transaction codes and payment, funding, or release events. Operators should configure the reporting engine against the applicable AMLC and PAGCOR instructions rather than assume that one threshold governs every casino event. The PAGCOR transaction-reporting and compliance-submission guidance should be treated as the control reference for the relevant coding and submission process.

Filing deadlines and decision points

Casinos must file covered and suspicious transactions with the AMLC within five working days, unless the AMLC sets another period that cannot exceed 15 working days. Suspicious transactions must be reported promptly after detection, so an operator shouldn't wait for a threshold event when the facts already support suspicion. The casino implementing rules on reporting provide the relevant filing framework.

Report Type Trigger Threshold Filing Window Regulator / Format
Covered transaction report PHP 5 million benchmark, subject to applicable aggregation rules Five working days, unless AMLC sets a period not exceeding 15 working days AMLC submission under applicable casino reporting guidance
Certain casino-coded transactions PHP 500,000 reference for specified transaction, payment, funding, or release events Apply the applicable reporting instruction AMLC submission using the required transaction coding
Suspicious transaction report Suspicion, regardless of whether a threshold is reached Promptly after detection, within the applicable filing period AMLC STR submission with supporting facts and rationale
AMLC registration Casino covered-person status and implementing-rule effectivity Within 90 days from effectivity of the casino implementing rules AMLC registration evidence retained by the operator

A resilient workflow starts at the event level. Cage staff capture cash buy-ins, chip exchanges, and redemptions. Table operations record relevant gaming activity. Online cashiers feed deposits, withdrawals, and account events into the same reporting queue. The AML function then reviews linked activity, applies aggregation logic, records the determination date, and preserves the evidence supporting the filing or closure.

The operator must protect confidentiality and avoid tipping off the player. A report isn't complete merely because a form was submitted. The file should show the underlying transactions, customer profile, risk indicators, investigative analysis, decision-maker, and submission confirmation. Operators monitoring local online payment journeys should verify that cashier data reaches the same queue as land-based casino events.

Recordkeeping, Monitoring, and Junket Controls

A casino's audit trail should allow a reviewer to reconstruct the customer relationship without asking staff to fill historical gaps from memory. Identity documents, transaction records, supporting evidence, investigation notes, approval records, and report submissions need controlled retention and reliable retrieval. Casino teams should apply the applicable five-year retention rule to player identity, transaction, and supporting documents, while reconciling the retention schedule with BIR and casino-specific obligations.

Monitoring design should reflect how casino value moves, not how a generic financial institution categorizes payments. Scenario logic should cover cash buy-ins, chip exchanges, wire transfers, voided transactions, rapid redemption, third-party funding, and activity that appears structured to avoid attention. The 2026 risk-review push makes calibration especially important because the operator must be able to explain why thresholds, alert rules, and escalation routes remain appropriate for a sector assessed as high risk.

Building an auditable monitoring chain

Sanctions and PEP screening should occur at onboarding and at defined change points, including material customer updates, new funding relationships, and relevant list changes. Re-screening controls should produce evidence, not just a system status. A reviewer should see the screening date, data used, match disposition, escalation path, and approval where a potential match required investigation.

The junket agent is a risk-bearing intermediary, not a substitute for casino oversight. The operator should underwrite the agent through due diligence, understand the agent's ownership and control, document contractual responsibilities, and monitor whether the agent's behavior matches the approved risk profile.

A process flow chart outlining recordkeeping, monitoring, and junket controls for casino compliance and risk mitigation.

The Junket Transaction Monitoring Form and the Customer Due Diligence Form for Junket Players should connect to the player's main record. A separate spreadsheet held by the junket team isn't enough if investigators can't reconcile the player's identity, source of funds, gaming pattern, and redemption activity.

Audit standard: A PAGCOR reviewer should be able to trace an alert from the original event to the customer file, supporting documents, analyst decision, escalation, and final report or closure without relying on undocumented verbal explanations.

Governance, Training, and Post-2026 Risk-Review Actions

The high-risk sector finding should produce visible governance changes. The board needs a written AML risk appetite statement, regular reporting on material exposure and control failures, and evidence that management funds the program according to identified risks rather than historical headcount.

The AMLCO should have a direct reporting route to senior management and sufficient authority to escalate issues. The operator should maintain a written ML/TF risk assessment and refresh it at least annually or after a material change, then test both physical casino controls and online gaming systems through independent review.

Turning findings into remediation

Training should begin within 30 days of hire, include a refresher at least annually, and add targeted sessions when staff miss red flags. Those completion records should identify the employee, course, date, assessment, and any remedial action. Junket hosts, cage staff, customer service teams, payment personnel, investigators, and technology administrators need role-specific instruction because each group sees different risk signals.

PAGCOR's supervisory direction also means remediation can't stop at a finding log. Management should assign an owner, define the control failure, preserve evidence of corrective action, validate the fix through testing, and report overdue items to the appropriate governance level. Publicized regulatory directives, license-condition riders, and monitoring-related requirements indicate that operators should expect compliance weaknesses to affect commercial and supervisory relationships, not remain internal observations.

Operator Checklist for PAGCOR AML Readiness

The following checklist assigns practical ownership and evidence to the obligations that matter during a post-2026 review.

  1. Board and AMLCO: Maintain the risk appetite statement, AMLCO appointment, reporting line, and board minutes. Cadence: quarterly governance review. Evidence: approved policy, minutes, management reports, and escalation records.
  2. CDD team: Verify player identity, PEP and sanctions screening, beneficial ownership, and source-of-funds evidence. Cadence: daily onboarding and event-driven refresh. Evidence: completed CDD files, screening results, approvals, and supporting documents.
  3. Junket management: Complete the Customer Due Diligence Form for Junket Players and Junket Transaction Monitoring Form, and underwrite the junket agent. Cadence: onboarding, transaction review, and monthly relationship review. Evidence: agreement, agent due diligence, player forms, and monitoring records.
  4. Cage and online cashier teams: Feed deposits, buy-ins, transfers, redemptions, and relevant voids into the central reporting queue. Cadence: daily reconciliation. Evidence: transaction logs, exception reports, and reconciliation sign-off.
  5. AML investigations: Assess covered transactions and suspicion, file within applicable deadlines, and protect against tipping off. Cadence: daily alert review. Evidence: case notes, determination date, filing confirmation, and closure rationale.
  6. Records management: Preserve identity, transaction, and supporting records under the applicable five-year rule. Cadence: weekly retrieval and integrity checks. Evidence: retention register, access logs, and restoration test.
  7. Internal audit: Test floor, cashier, online, junket, screening, and reporting controls independently. Cadence: annual testing, with targeted reviews after material findings. Evidence: audit scope, samples, findings, remediation validation, and PAGCOR B2B provider compliance records.
  8. Learning and development: Deliver induction, annual refresher, and targeted red-flag training. Cadence: within 30 days of hire, annually, and after missed alerts. Evidence: attendance, assessments, course materials, and remediation logs.

A PAGCOR operator checklist outlining essential steps for AML readiness and regulatory compliance in the gaming industry.

Operators should use the checklist to assign named owners next Monday, test whether each evidence item can be retrieved, and document the gaps before a regulator finds them. For continuing analysis of Philippine gaming regulation, compliance teams can follow Top 1 Rank, the global iGaming intelligence publication, and use its regulatory coverage to keep governance decisions aligned with the market's changing expectations.