[codicts-css-switcher id=”346″]

Global Law Experts Logo
macau gaming compliance

Our Expert in Macau

Macau Gaming Compliance in 2026: AML, KYC and Junket Requirements Casino Operators Must Follow

By Global Law Experts
– posted 42 minutes ago

Macau gaming compliance entered a decisive new phase following the substantial 2022 revision of the territory’s Gaming Law and the regulatory framework that has since reshaped the obligations placed on concessionaires, their compliance functions and the intermediaries who feed the VIP economy. For operators, the practical stakes are considerable: strengthened anti-money-laundering controls, sharper customer due diligence expectations, and far closer scrutiny of junket and VIP channels now sit at the centre of every supervisory conversation with the Gaming Inspection and Coordination Bureau (DICJ). This playbook translates the legislative changes into concrete steps a compliance officer can implement, from a 90-day remediation sprint to a 12-month monitoring cycle.

It is written for casino operators, VIP and junket managers, in-house counsel and investors who need to reduce regulatory uncertainty and demonstrate a defensible programme.

TL;DR, what operators must do now:

  • Refresh the enterprise-wide AML/CTF risk assessment against the current Gaming Law framework and DICJ guidance.
  • Rebuild customer due diligence and enhanced due diligence workflows for VIP and high-value players.
  • Re-vet every gaming promoter partner and principal against heightened suitability thresholds and re-paper the contracts.
  • Strengthen board-level oversight, independent testing and record-keeping across the compliance function.

What changed in the reformed gaming law, quick operator summary

The current framework builds on the concession-based regime established by Law No. 16/2001, the Gaming Law, as substantially amended by Law No. 7/2022, which was passed by the Legislative Assembly and published in the Boletim Oficial. The regime is administered by the DICJ under the Government of the Macao SAR. Gambling remains legal in Macau only for those holding a valid gaming concession, and the market is served by a limited number of concessionaires, a structural feature that makes ownership suitability and senior-management accountability central to Macau gaming compliance. The reforms tightened oversight of intermediaries, raised expectations of internal controls, and clarified the chain of operator responsibility for AML failures within their premises.

Each change maps directly to an operational obligation that operators must evidence.

AML and reporting changes

The framework reinforces that a concessionaire’s anti-money-laundering programme must be risk-based, documented and capable of independent testing. Reporting expectations, currency-threshold reporting and suspicious-transaction reporting to the competent authorities, are treated as core supervisory obligations rather than back-office formalities. Macau’s AML regime is anchored in Law No. 2/2006 on the prevention and suppression of money laundering and related administrative regulations, together with sector-specific DICJ instructions for the gaming industry. The practical impact is that operators must be able to demonstrate, on demand, how a transaction was identified, escalated, investigated and reported.

Suspicious transactions are reported to the Financial Intelligence Office (Gabinete de Informação Financeira, GIF), and the Financial Action Task Force (FATF) standards frame the international benchmark against which Macau’s regime is measured through the Asia/Pacific Group on Money Laundering.

Junket and VIP changes

Gaming promoter (junket) and VIP oversight received significant tightening. The reforms increased the suitability scrutiny applied to gaming promoters and their principals, and pushed operators to take direct contractual and operational responsibility for the conduct of intermediaries operating within their casinos. Under the revised regime, gaming promoters may in principle contract with only one concessionaire, and revenue-sharing commission arrangements are more tightly regulated. In practice this means operators can no longer treat gaming promoters as arm’s-length third parties. Where a promoter channel introduces AML risk, the concessionaire is expected to have identified it, controlled it and, where necessary, exited the relationship. This represents a substantial shift in the operator-liability space.

Suitability and tender changes

The reforms also sharpened the suitability review of concessionaires, key shareholders and senior managers, linking ongoing fitness to hold gaming positions with the tender and concession framework. The regime emphasises continuous suitability rather than a one-off admission test: senior managers must remain demonstrably fit and proper throughout the concession term. For operators, this converts governance and conduct into a licensing risk, a compliance failure is not merely a fine, it can become a threat to the concession itself.

Core AML obligations for Macau casino operators, what to implement now

The heart of Macau gaming compliance is a functioning, evidenced anti-money-laundering programme. The obligations below are prioritised as must-have controls; each should map to a named owner, a documented procedure and a monitoring metric so that supervisory examiners can trace the control from policy to practice.

Risk-based AML program and governance

Start with an enterprise-wide ML/TF risk assessment that identifies the operator’s exposure across products, channels, customer types and geographies. The assessment must be refreshed against the current Gaming Law framework and any current DICJ guidance, and it should explicitly rate gaming promoter and VIP channels as elevated-risk. From the risk assessment flows the programme: a written AML/CTF policy approved by senior management, a designated compliance officer with sufficient seniority and independence, and clear escalation lines to the board. Sample controls include a documented risk-scoring model for customers, a defined risk-appetite statement, and a control matrix mapping each identified risk to a mitigating control and a responsible owner.

Useful key performance indicators are the proportion of high-risk customers subject to enhanced review, the average time to clear an alert, and the percentage of the risk assessment refreshed within the review cycle.

Customer due diligence (CDD) and enhanced due diligence (EDD) for VIPs

Every customer relationship must begin with customer due diligence proportionate to risk. For standard players this means identity verification and basic risk classification; for VIPs and high-value players it means enhanced due diligence. EDD should establish the customer’s identity, understand the nature and purpose of the relationship, and, critically, verify source of funds and source of wealth. In a market where baccarat and high-value VIP play drive substantial turnover, source-of-funds verification is a control regulators test aggressively. Sample controls include a documented EDD trigger list, mandatory senior-management sign-off before onboarding a high-risk VIP, and periodic re-verification of source of wealth for the highest-tier players.

Transaction monitoring and reporting

Transaction monitoring must be capable of detecting unusual patterns, structuring, rapid movement of chips or credits, or transactions inconsistent with a customer’s known profile. When applicable reporting thresholds are met, operators must file large-transaction reports; when a transaction raises suspicion, a suspicious-transaction report must be filed with the competent authorities (the Financial Intelligence Office) in line with DICJ instructions and the AML law. The programme should define, in writing, who investigates an alert, how the decision to report or dismiss is documented, and what timeframe applies. A defensible file shows the analyst’s reasoning, the evidence reviewed and the outcome. Monitoring KPIs include alert-to-report conversion rates, backlog age, and the proportion of alerts closed within the target window.

Record-keeping and retention

Robust record-keeping underpins everything above. Operators must retain customer identification records, due diligence files, transaction records, and the supporting rationale for reporting decisions for the retention period set by the applicable law and regulator guidance. Records must be retrievable quickly during a DICJ inspection. In practice, that means a single, well-indexed compliance record system rather than fragmented files across departments. Retention policy should specify the record categories, the retention period, the storage location, and the destruction protocol, and it should be tested through periodic sampling to confirm records can be produced on request.

Updated KYC rules and procedures, a step-by-step checklist

Know-your-customer procedures are the operational front line of Macau gaming compliance. The checklist below can be adopted as an onboarding and ongoing-monitoring standard operating procedure and scaled to the operator’s size and risk profile.

ID verification and source-of-funds checks

Follow a verification hierarchy: collect and independently verify identity documentation before establishing the relationship, then assess risk, then apply source-of-funds and source-of-wealth checks proportionate to that risk. Sample KYC form fields should capture: full legal name; date of birth; nationality and residence; government-issued identification type and number; occupation and employer; expected level and source of gaming funds; and any relationship to a gaming promoter principal. For high-value onboarding, require documentary evidence of source of funds, not merely a customer declaration, and record who verified it and when.

Ongoing monitoring frequency and triggers

KYC is not a one-time event. Set periodic review cycles calibrated to customer risk, more frequent for VIPs and high-risk profiles, less frequent for standard players, and define event-driven triggers that force an immediate review. Triggers should include a material change in transaction patterns, adverse media, a change in a customer’s gaming promoter relationship, or the customer’s appearance on a sanctions or PEP list. The SOP should state the review frequency for each risk tier, the events that override the schedule, and the escalation path when a review reveals heightened risk.

PEPs and sanctions screening

Screen all customers and relevant counterparties against sanctions lists and politically exposed person (PEP) databases at onboarding and on an ongoing basis. A confirmed PEP relationship should automatically escalate to enhanced due diligence and require senior-management approval before continuing. Sanctions hits must be resolved before any transaction proceeds. Document every screening event, every match assessment, and every disposition so that the audit trail withstands examination.

Regulating gaming promoter partners and VIP channels, contracts, vetting and oversight

Gaming promoter regulation in Macau changed materially under the reformed framework, and this section addresses the operator obligations that flow from that change: vetting, contracting, monitoring, and exit. The core principle is that the concessionaire owns the risk of any intermediary operating within its premises.

Due diligence on gaming promoters and principals

Before entering or renewing any gaming promoter relationship, conduct enhanced suitability due diligence on the operator entity and its principals. Gaming promoters must be licensed by the DICJ, and their principals are subject to suitability review. Due diligence should cover beneficial ownership, source of capital, adverse media, litigation and regulatory history, and any links to previously sanctioned individuals. The heightened suitability thresholds under the reforms mean the analysis must be documented to a standard the DICJ could review. Where a principal cannot satisfy suitability, the relationship should not proceed, irrespective of the commercial revenue at stake.

Contract clauses and control points

Re-paper gaming promoter agreements so that compliance obligations are contractually enforceable. Recommended clauses include: suitability warranties from the promoter and its principals; ongoing disclosure obligations; audit and inspection rights for the operator; mandatory AML/KYC cooperation and information-sharing; clear allocation of responsibility for customer due diligence; controls on commission arrangements consistent with the current regime; and a termination-for-regulatory-risk clause allowing immediate suspension or exit where the promoter poses a compliance threat. Each clause should map to an operational control point the compliance function can actually exercise.

Operational monitoring and suspension/exit plans

Contracts are only as strong as the monitoring behind them. Establish continuous operational monitoring of promoter-introduced play, transaction patterns, commission usage, and the profile of introduced customers, with defined escalation and suspension procedures. Prepare an exit plan in advance so that, if suitability fails or an AML concern crystallises, the operator can suspend the relationship, ring-fence affected accounts, preserve records, and notify the regulator without disruption. The ability to exit cleanly is itself a supervisory expectation.

Gaming promoter obligations, earlier regime versus reformed regime

Issue Earlier regime Reformed regime (operator impact) Implementation action
Vetting and suitability Limited operator-level due diligence on promoter principals Enhanced suitability assessment expected; operator accountable for the intermediary’s fitness Run documented beneficial-ownership and adverse-media checks before onboarding and renewal
Commission and revenue-sharing transparency Commercial terms often opaque to compliance Commission arrangements more tightly regulated; greater transparency expected Document commercial terms, capture them in contract, and disclose where required
Operator oversight Promoters treated as arm’s-length third parties Operator responsible for conduct of intermediaries on its premises Implement continuous monitoring of promoter-introduced play
Liability for promoter customers’ AML breaches Responsibility frequently diffuse Clearer chain of operator responsibility for AML failures Embed audit rights, CDD allocation and termination-for-risk clauses in contracts

For a fuller legislative treatment, consult primary sources and qualified Macau gaming counsel for the contract templates that operationalise the table above.

Governance, internal controls and the Macau gaming compliance program roadmap (90–365 days)

A defensible programme requires governance that reaches the board. This roadmap converts the obligations above into a sequenced Macau gaming compliance implementation plan.

90-day remediation checklist:

  1. Refresh the enterprise ML/TF risk assessment against the current Gaming Law framework and DICJ guidance.
  2. Confirm a suitably senior, independent compliance officer is appointed with a written mandate.
  3. Gap-assess CDD/EDD, transaction monitoring and reporting against current expectations.
  4. Re-vet all active gaming promoter relationships and flag any that fail heightened suitability.
  5. Verify record-keeping systems can retrieve customer and transaction files on demand.

6–12 month programme:

  1. Re-paper gaming promoter contracts with enforceable compliance clauses.
  2. Roll out role-based AML/KYC training across gaming and VIP staff.
  3. Implement or tune transaction-monitoring technology and reduce alert backlogs.
  4. Commission independent testing of the programme.
  5. Establish quarterly board reporting on compliance metrics and remediation status.

Board and senior management responsibilities

The board and senior management must own the compliance culture, approve the AML policy and risk appetite, and receive regular, meaningful reporting. Because the reformed regime ties continuous suitability to the concession, directors and senior managers carry personal exposure for programme failures. A quarterly board reporting template should cover the risk assessment status, alert and report volumes, promoter suitability outcomes, training completion, and open audit findings.

Compliance function resourcing and technology

Resource the compliance function proportionately to gaming revenue and risk. Under-resourcing is a recurring examination finding, so define a defensible staffing model, invest in transaction-monitoring and screening technology, and ensure the compliance function has authority to halt onboarding or suspend a promoter relationship. A compliance charter should set out the function’s mandate, independence, reporting lines and escalation rights.

Independent audit and regulator engagement

Independent testing, whether internal audit or an external reviewer, validates that controls operate as designed. Findings should feed a tracked remediation plan with owners and deadlines. Engage constructively with the DICJ: proactive dialogue, timely responses to information requests, and self-reporting of material issues are consistently viewed more favourably than concealment.

Practical enforcement risks and penalties, where regulators will focus

Enforcement under the reformed framework is expected to prioritise the areas where the reforms raised the bar: gaming promoter suitability, source-of-funds verification for VIPs, transaction-monitoring adequacy, and the sufficiency of board oversight. Because suitability is now continuous and linked to the concession, the most serious consequence of a compliance failure is not merely a discrete penalty but the threat it can pose to the concession and to senior managers’ fitness to serve.

Typical breaches and remedial steps

Common breaches include inadequate EDD on high-value players, weak or undocumented source-of-funds checks, deficient promoter vetting, late or missing reports, and poor record retention. The remedial pattern is consistent: identify the root cause, remediate the specific gap, test that the fix holds, and document the entire cycle. Operators should treat every finding as an opportunity to strengthen the evidenced audit trail rather than as a one-off fix.

How to respond to regulator inquiries

When the DICJ inquires or inspects, respond promptly, honestly and completely. Assemble a coordinated response team, preserve all relevant records, and provide requested documents within the stated timeframe. Where a genuine issue emerges, controlled self-reporting accompanied by a credible remediation plan is the stronger position. Never destroy or alter records once an inquiry is under way.

Implementation tools, sample clauses, checklists and KPIs

To operationalise this playbook, operators should build and maintain a small set of practical assets, customised to their size and risk profile:

  • One-page implementation checklist. A combined 90-day and 12-month action list with owners and deadlines, drawn from the roadmap above.
  • Gaming promoter contract clause pack. Suitability warranties, ongoing disclosure, audit and inspection rights, AML/KYC cooperation, commission controls, and termination-for-regulatory-risk.
  • KYC form and reporting pointers. Standardised onboarding fields, an EDD trigger list, and a documented decision template for reporting.
  • KPI dashboard. Metrics including high-risk customer coverage, alert-to-report conversion, backlog age, promoter suitability outcomes and training completion.

Each asset should be version-controlled and reviewed at least annually or whenever regulator guidance changes. For detailed working documents, engage qualified Macau gaming counsel.

Comparison: Macau versus other major jurisdictions

Requirement Macau (earlier regime) Macau (reformed regime) Nevada Singapore
AML/CTF programme Required, risk-based Reinforced, board-owned, independently tested Mandatory federal AML programme Mandatory statutory AML/CTF programme
Promoter/intermediary oversight Lighter operator responsibility Enhanced suitability; operator accountable; single-concessionaire contracting No junket model; direct casino relationships Strict controls; junket presence limited
VIP source-of-funds Expected for high risk Emphasised; documentary verification tested Required under risk-based rules Rigorous source-of-funds scrutiny
Suitability of senior managers Admission-focused Continuous, linked to concession Ongoing licensing suitability Ongoing fitness and probity checks

Next steps, building a defensible Macau gaming compliance program

The reformed gaming law framework has raised the operational and licensing stakes across every element of Macau gaming compliance, from AML and KYC through to gaming promoter oversight and continuous suitability. Operators who act now, refreshing their risk assessment, rebuilding due diligence workflows, re-papering promoter contracts and strengthening board oversight, will be best placed to withstand DICJ scrutiny and protect their concessions. Use the 90-day remediation and 12-month monitoring roadmap in this playbook as your baseline, calibrate the tools to your size and risk, and document every control so it can be evidenced on demand. For tailored implementation, consult qualified Macau gaming counsel before making regulatory filings or suitability submissions.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Pedro Cortés at Lektou, a member of the Global Law Experts network.

Sources

  1. Gaming Inspection and Coordination Bureau (DICJ), Macau SAR
  2. Government of the Macao SAR, Official portal
  3. Boletim Oficial da Região Administrativa Especial de Macau (Official Gazette)
  4. Legislative Assembly of Macao (Assembleia Legislativa)
  5. Autoridade Monetária de Macau (Macau Monetary Authority, AMCM)
  6. Financial Intelligence Office (Gabinete de Informação Financeira, GIF)
  7. Financial Action Task Force (FATF)

FAQs

Is gambling legal in Macau?
Yes. Macau operates a concession-based legal gambling regime under Law No. 16/2001, the Gaming Law, as amended (notably by Law No. 7/2022). Operators must hold a valid concession and comply with the rules and guidance issued by the DICJ.
Operators must maintain a risk-based AML programme, perform CDD and EDD for VIPs, conduct transaction monitoring, file large-transaction and suspicious-transaction reports with the competent authorities, and keep retrievable records, all in line with the AML law, DICJ instructions and international FATF standards.
Yes. The reforms require enhanced suitability assessment of gaming promoters and their principals and place direct oversight responsibility on the operator. Promoters must be licensed by the DICJ and, under the current regime, may generally contract with only one concessionaire.
Triggers include large or unusual transactions, PEP status, opaque source of funds, frequent high-value gaming activity, and relationships with gaming promoter principals. Any trigger should escalate the customer to EDD with senior-management sign-off.
Engage a Macau-qualified gaming lawyer or use the Global Law Experts Macau gaming practice-area listing and lawyer directory. Counsel can conduct a compliance audit, prepare suitability submissions and coordinate regulatory filings.
foreigners buying property south africa
By Global Law Experts

posted 2 hours ago

mortgage enforcement tanzania
By Global Law Experts

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Macau Gaming Compliance in 2026: AML, KYC and Junket Requirements Casino Operators Must Follow

Send welcome message

Custom Message