What AML monitors
While KYC confirms who a player is, AML watches what that person does with their money after they are inside the platform. The legal basis combines Law No. 9,613/1998 (Brazil's anti-money-laundering statute), which applies to fixed-odds betting operators as an obligated sector, with Article 25 of Law No. 14,790/2023, which requires transaction monitoring mechanisms and reporting to COAF (Conselho de Controle de Atividades Financeiras) of any operation carrying well-founded suspicion.
The rule that gives that obligation practical shape is SPA/MF Ordinance No. 1,143/2024, which sets out the AML/CFT policies, procedures, and internal controls betting operators must adopt. It is where the deadlines live: the analysis procedure must close within 30 days of the bet or associated transaction (Art. 26, § 2), and the report to COAF must be filed by the business day following the conclusion of that analysis (Art. 27, § 3). Filing goes through SISCOAF, and Art. 29 bars the operator from sharing any information about the report with third parties — including the reported player.
In practice, this means keeping a full history of deposits, bets, and withdrawals available for audit, and running rules that automatically flag behavior outside the expected pattern for a given player's profile — not just storing data, but continuously analyzing it.
Typical red flags in betting
A handful of patterns show up often enough to become standard monitoring rules at any operation:
| Signal | Why it matters |
|---|---|
| Deposit followed by an almost-immediate withdrawal, with little or no betting in between | Suggests the platform is being used as a pass-through for transferring funds |
| Multiple accounts sharing the same device, IP address, or bank details | Possible mule-account network used to split or obscure the source of funds |
| Deposits broken into smaller amounts that add up to a significant total | Attempt to stay under thresholds that would trigger extra verification |
| Withdrawal to a third party's account or PIX key, different from the verified account holder | Breaks the traceability between who placed the bets and who received the funds |
| Betting volume inconsistent with the player's declared financial profile | Suggests a source of funds that does not match the player's stated activity |
None of these signals alone proves money laundering — human review exists precisely to separate legitimate behavior from a suspicious pattern before deciding on a report.
Do KYC and AML answer the same question?
No, and treating them as interchangeable is a common mistake. KYC answers "who is this person, and are they allowed to bet?" — a check that runs mainly at registration and pre-withdrawal. AML answers "what is this person doing with their money, and does it make sense?" — a continuous analysis that runs for the life of the account, long after identity was already confirmed.
| KYC | AML | |
|---|---|---|
| Question it answers | Who is the player? | What are they doing with the money? |
| When it runs | Registration and pre-withdrawal | Continuously, for the life of the account |
| Main legal basis | Law No. 14,790/2023 + SPA/MF Ordinance 722/2024 | Law No. 9,613/1998 + Law No. 14,790/2023, Art. 25 + SPA/MF Ordinance 1,143/2024 |
| Typical outcome | Account approved, rejected, or pending documents | Normal operation, or a report to COAF |
An operation with strong KYC and weak AML correctly identifies each player, but misses when a legitimate account starts behaving like a pass-through for someone else's funds. The reverse fails too: without reliable KYC, AML is analyzing patterns tied to an identity that may not even be real. The two controls only work as regulatory protection when they run together, feeding the same account history.