Licenses
QuinnBet to Pay £609,104 After UK Gambling Commission Finds AML and Safer-Gambling Failures
QuinnBet (Gibraltar) Limited, the operator behind quinnbet.com, will pay £609,104 after a UK Gambling Commission investigation found anti-money-laundering and social-responsibility failures spanning March 2023 to August 2025, the regulator announced on August 20, 2026.
The operator, which serves UK customers under a remote licence issued to its Gibraltar entity, reached a regulatory settlement with the Commission, meaning the money is paid in lieu of a financial penalty rather than imposed as a fine after a contested licence review. The case began with a compliance assessment of QuinnBet’s remote operating licence and escalated into a formal regulatory review under the Commission’s statutory review powers, the regulator’s public statement on the case shows.
The review found breaches of the anti-money-laundering conditions attached to QuinnBet’s UK licence, of the social-responsibility code governing remote customer interaction, and of the financial-vulnerability-check requirement that came into force on August 30, 2024.
John Pierce, the Commission’s director of enforcement, said in the announcement:
> “This case highlights the serious consequences of relying on systems and controls that are unable to identify and respond to indicators of harm and financial crime quickly enough. We expect operators to ensure their safeguards are effective in practice to protect consumers and keep crime out of gambling.”
Pierce said QuinnBet recognised the issues and took immediate action to strengthen its systems, including improvements to its anti-money-laundering policies and to how it identifies and responds to indicators of harm.
What the Commission Found at QuinnBet
The failings documented in the public statement fall into three groups, and several trace back to a single operational event: QuinnBet’s migration to a new platform.
On the money-laundering side, investigators found the operator’s controls were too slow to identify customers whose spending was disproportionate to their known means. In one case, a customer whose payslips showed monthly earnings of around £2,000 was able to deposit and lose £9,000 in four days. In another, a customer deposited roughly £120,000 and withdrew £111,000 in under three months; QuinnBet assumed the funds were recycled winnings but never sought evidence to confirm it, and neither the bank statement nor the tax return the customer provided showed any transactions with the operator. The Commission also found suspicious-activity reports were not always submitted as soon as practicable once the threshold for suspicion had been met, and that 194 customers were able to deposit beyond intended limits after human and software errors during the platform migration disabled two deposit-limit controls on some accounts.
The social-responsibility findings are more granular. QuinnBet had set lower deposit limits for customers aged 18 to 24, whom it recognised as more vulnerable to gambling harm, but applied those limits through a manual process that could take hours to activate. One young adult deposited eight times the intended monthly limit before it took effect and lost the entire amount within a day. The operator’s real-time loss-limit alert was configured so it only triggered when a customer made a further deposit after exceeding the limit, letting balances above the limit be played through unflagged. Its monitoring algorithm failed to capture high deposits, high-velocity sessions, increasing stakes, bet counts and turnover for manual review: one customer placed approximately 4,800 bets in a day and 7,000 the next without being flagged, and another staked more than £215,000 in a single day, including multiple wagers above £5,000, that surfaced only in a report produced the following morning. Account reviews, when they happened, tended to focus on the customer’s financial position rather than the markers of harm observed, and staff did not routinely check whether earlier interventions had changed behaviour.
On the financial-vulnerability checks, QuinnBet itself reported the problem. During the platform migration, some customers who met the relevant threshold were not checked at the intended times. When the checks were eventually run, 41 of those customers would have failed outright and 136 would have required account restrictions.
What the Settlement Requires of QuinnBet
The settlement consists of the £609,104 payment, which includes a disgorgement of £193,118 and will be directed to the UK government’s Consolidated Fund, along with QuinnBet’s agreement to the publication of the statement of facts and a payment towards the Commission’s investigation costs.
The Commission weighed both sides of the operator’s conduct in reaching that figure. The aggravating factor on record is that the regulator had previously issued public statements about similar failings at other operators. In mitigation, the Commission recorded that QuinnBet had never before faced regulatory enforcement action, self-reported some of the failings early and voluntarily, co-operated fully with the investigation, accepted the failings at an early stage, voluntarily gave up funds it had accrued as a result of some of them, and swiftly put an action plan in place to remedy them.
The pattern is one the Commission has applied through the summer: earlier this week it fined retail operator Holland Park Leisure £150,000 over a self-exclusion failure, a smaller case but the same enforcement route of published findings tied to licence conditions.
The Rules Behind the Case
The vulnerability-check requirement at the centre of one breach is one of the newer obligations in the Commission’s rulebook. In force since August 30, 2024, it obliges remote operators to run a public-records check on customers whose net deposits pass a set threshold in a rolling 30-day period, screening for signs of financial distress such as bankruptcy orders and county court judgments. The threshold stood at £500 until February 27, 2025, when it dropped to £150, the level that has applied since February 28, 2025. QuinnBet’s breach period for that requirement ran from February 2025 to May 2025, squarely across the threshold change.
The broader customer-interaction code the operator breached requires licensees to identify risk, act on it and evaluate whether the action worked, as an ongoing cycle. It also requires that strong indicators of harm be handled through automated processes rather than manual ones alone. The Commission found QuinnBet’s own policies treated certain behaviours as strong indicators warranting immediate account suspension, but the process depended on manual reviews and manual suspensions.
The Commission closed its public statement with a set of questions it expects every licensed operator to ask of its own systems, covering source-of-funds evidence, the timeliness of suspicious-activity reporting, deposit-limit enforcement, algorithm testing and automation of harm interventions. It specifically asked operators changing IT infrastructure whether they have checked, before and after implementation, that their controls still function as intended, the precise point where QuinnBet’s failings began.











