What gets verified, and when
KYC confirms two things: that the player is who they claim to be, and that they are legally allowed to bet in Brazil. At registration, the platform collects the national ID number (CPF), date of birth, and basic data, and SPA/MF Ordinance No. 722/2024 requires facial biometric verification at that same step — under Annex I, item 10, identity verification "must perform facial recognition and be carried out before a bettor has a registered account," and the account can only be activated once age and identity checks, including CPF validity and facial recognition, have been completed successfully. There is no relaxation of that requirement at signup. That is a stricter starting point than markets where full verification only happens close to the first withdrawal: in regulated Brazil, most of KYC has to be resolved before a player can place a bet at all.
The second layer runs through the payment flow: before the first withdrawal, the platform checks that the bank account or PIX key belongs to the same person as the verified account, so funds cannot leave to a different CPF than the one that placed the bets.
The same ordinance sets out re-authentication in three separate rules that are often collapsed into one. After 30 minutes of inactivity on a device, the system must require a fresh authentication, with no bet or financial transaction allowed until it completes — the rule does not require multi-factor here (Annex I, item 14). For that fresh authentication on the same device, the system may offer biometric access, tested by a certifying body accredited by the SPA — an option, not an obligation (item 15). What the ordinance does make mandatory is multi-factor authentication at least once every 7 days or on the first access after more than 7 days of inactivity (item 16).
| Stage | When it happens | What gets confirmed |
|---|---|---|
| Registration | Before the account exists | CPF, legal age (18+), facial biometrics (mandatory) |
| Pre-withdrawal | Before the first payout | Bank/PIX ownership matches the verified account |
| Fresh authentication | After 30 min of device inactivity | The player authenticates again; biometrics optional (item 15) |
| Multi-factor authentication | Every 7 days, or first access after 7+ days idle | Two or more factors (item 16) |
What regulated Brazil requires beyond identity
Law No. 14,790/2023, Art. 26, expressly bars anyone under 18 (item I) and "a person diagnosed with gambling disorder, by report of a qualified mental health professional" (item VI) from betting. That wording matters: the bar is not triggered by a player's own declaration, but by a formal diagnosis issued by a qualified professional.
The restriction on social-program beneficiaries now has two parts with different legal standing. SPA/MF Ordinance No. 2,217/2025 added beneficiaries of the Bolsa Família program and of the BPC continuous cash benefit to the list of people barred from betting, and SPA/MF Normative Instruction No. 22/2025 set out how it works in practice: a CPF query against the SIGAP "Módulo de Impedidos" (barred-persons module) at account opening, on the first login of each day, and at least every fifteen days across the whole player base. The ban on new registrations is in force — registration must be refused when SIGAP returns "Impedido - Programa Social." The obligations to block and close existing accounts, however, were partially suspended by Justice Luiz Fux in ADI 7721 on 19 December 2025, with the merits still pending. Because the case is ongoing, operators should confirm the current status with the SPA before triggering account closures.
To meet this set of requirements, the KYC flow has to do more than accept a scanned document — it needs to validate CPF against an official database and query the SIGAP barred-persons module, not just take a photo of an ID card.
Slow KYC costs conversion. Where is the balance?
A registration flow with too many manual steps kills conversion — every extra screen between the ad click and the first deposit is a drop-off point, and mandatory facial biometrics at signup already adds friction that has to be executed well or it costs signups. The fix is not skipping steps, because that exposes the operation to fraud and regulatory sanction; it is automating: CPF validation against an official database, document checks and biometrics handled by technology, with manual review reserved for cases the automation flags as uncertain.
On the other side, overly strict fraud rules generate false positives — legitimate players blocked or forced to resubmit documents — which drives support tickets and is a common cause of churn in the first days of an account. The balance point is measuring both rates, friction-driven drop-off and fraud that slips through, and tuning the flow from those two numbers instead of an arbitrary choice between rigor and conversion. When KYC works this way, it stops being pure compliance cost and starts protecting the operation from fraudulent or third-party accounts — the same type of account that later turns into an AML problem.