top of page
fnlogo.png

Ontario Regulator Penalises NorthStar Gaming Over AML Control Failures

  • 2 hours ago
  • 7 min read

NorthStar Gaming has been hit with a C$100,000 monetary penalty by Ontario's gaming regulator after failing to apply enhanced anti-money laundering controls to a high-risk customer whose deposits ultimately reached almost C$190,000.


Ontario Regulator Penalises NorthStar Gaming Over AML Control Failures

The Alcohol and Gaming Commission of Ontario found that NorthStar Gaming (Ontario) Inc. did not comply with provincial AML requirements in relation to a single player account that remained active from March 2024 until June 2025. The case has highlighted the importance of ensuring that risk-based AML policies are implemented in practice rather than simply maintained as formal procedures.


The player opened an account with NorthStar in March 2024 and reached C$25,000 in lifetime deposits during the same month. Under the operator's own AML policies, the customer's declared occupation was considered a high-risk indicator. Once the C$25,000 deposit threshold was reached, the account should therefore have been classified as high risk and subjected to enhanced due diligence.


That enhanced due diligence was expected to include verification of the customer's source of funds and an assessment of whether continued betting activity was consistent with the customer's risk profile.


NorthStar did not carry out those measures when they were required.


The customer's deposits instead continued for more than a year. In December 2024 alone, the player deposited more than C$55,000, while total deposits eventually reached approximately C$189,395 by June 2025.


The account was only classified as high risk and terminated in June 2025 after the regulator began making inquiries into the customer's activity. By that point, more than a year had passed since the operator's own AML procedures should have triggered enhanced scrutiny.


The regulatory review was prompted after the customer became the subject of a police investigation. The individual was charged in connection with Project Outsource, a joint law-enforcement operation targeting criminal activity, including alleged extortion and violence within Ontario's towing industry.


The charges against the individual were not the basis for determining that NorthStar itself had engaged in money laundering. Rather, the subsequent law-enforcement information brought the customer's previous gambling activity to the regulator's attention and led to an examination of whether NorthStar had appropriately applied its AML obligations.


The case is particularly significant because the regulator's findings concerned a failure to follow controls that NorthStar had already established internally.


Ontario's regulated gaming framework requires operators to maintain risk-based systems capable of identifying, assessing and responding to potential money-laundering risks. The relevant regulatory standards also require operators to take reasonable measures where indicators of suspicious activity arise.


In this case, the operator's own policies provided a clear escalation mechanism. The customer's occupation was identified as a high-risk factor and the deposit threshold was reached quickly, yet the corresponding risk classification and enhanced due-diligence process were not initiated.


The failure was therefore not simply a matter of an AML policy being insufficient. The regulator's concern centred on the disconnect between the controls NorthStar had designed and the way those controls were actually applied to a customer's account.


The operator's policies also required escalating action when money-laundering indicators were identified. Depending on the circumstances, such measures could include refusing further transactions or excluding a customer from the platform.


Those interventions were not implemented while the customer's deposits continued.


The case provides a clear example of why transaction thresholds should not be treated as purely administrative triggers. A deposit threshold is intended to prompt a broader assessment of the customer, including the source and legitimacy of funds and whether the customer's activity is consistent with their known circumstances.


Reaching a threshold should therefore result in an effective compliance response rather than simply generating an automated notification that is not subsequently investigated.


The prolonged continuation of the account was an important factor in the regulator's findings. The issue was not limited to a single missed review. The customer continued depositing substantial amounts for approximately 15 months after the account should have been subjected to enhanced scrutiny.


This created a significantly larger exposure for the operator and allowed the customer to continue using the platform despite the risk indicators already identified within NorthStar's own procedures.


The penalty also illustrates the increasingly important role of source-of-funds verification within online gambling AML frameworks.


For high-risk customers, understanding where gambling funds originate is essential to determining whether activity is legitimate. A customer's ability to make large deposits does not, by itself, establish that the funds are lawful or consistent with their financial profile.


Source-of-funds checks can involve reviewing evidence such as employment income, business income, investment proceeds, asset sales or other legitimate sources of wealth. The level of evidence required should generally correspond to the customer's risk profile and the scale and nature of the transactions.


The NorthStar case demonstrates the consequences when such checks are not performed despite clear triggers.


It also reinforces the distinction between customer risk classification and transaction monitoring. An operator may have systems capable of identifying unusually large deposits, but those systems must be connected to an effective risk-management process that results in appropriate action.


A large transaction involving a low-risk customer may require a different response from similar activity involving a customer whose occupation, financial circumstances or other characteristics indicate elevated risk.


This is the practical meaning of a risk-based AML framework.


The regulatory action also sends a message about senior management responsibility for AML effectiveness. Compliance systems require appropriate staffing, technology, governance and oversight to ensure that alerts and risk indicators result in timely action.


Following the period covered by the regulatory order, NorthStar says it has significantly strengthened its AML and compliance programme. The company has appointed a new Vice President of Compliance, expanded its compliance team and enlarged its Compliance Committee with additional experienced industry members.


The operator has also completed an independent external review of its compliance effectiveness and made material changes to its risk-scoring and player-classification systems. Its escalation procedures have also been formalised.


These measures are significant because the regulatory findings relate directly to weaknesses in the practical application of risk classification and escalation procedures.


Improving automated risk scoring can help identify customers who require enhanced scrutiny, but technology alone cannot guarantee compliance. Operators need clear procedures for reviewing alerts, obtaining supporting documentation, escalating concerns and deciding when transactions or accounts should be restricted.


The case also highlights the importance of independent testing of AML systems. An external effectiveness review can help identify weaknesses that may not be apparent from internal reporting and can test whether policies operate as intended across real customer accounts.


NorthStar has not disputed the regulator's findings and has cooperated with the investigation. The company has acknowledged responsibility for the matters covered by the regulatory order and stated that the conduct relates to a specific historical period.


There is, however, a discrepancy between the regulator's headline penalty and the amount NorthStar has agreed to settle.


The AGCO announced a C$100,000 monetary penalty, while NorthStar's own disclosure states that it has agreed to settle the matter for C$80,000. The company nevertheless confirmed that it does not dispute the regulator's findings.


The regulatory action comes during a period of increased enforcement activity in Ontario's regulated online gambling sector. The AGCO has recently taken action against other operators and suppliers over failures involving player protection and compliance requirements, demonstrating that the regulator continues to apply financial penalties where licensed businesses fail to meet prescribed standards.


For operators, the development reinforces the importance of maintaining a compliance framework that is capable of adapting to individual customer circumstances.


AML controls must operate throughout the customer relationship rather than only during onboarding. A customer's risk profile can change as deposits increase, new information becomes available or external intelligence emerges.


Continuous monitoring is therefore particularly important for online gambling businesses, where customers can transact rapidly and potentially generate significant deposit volumes over relatively short periods.


The case also illustrates the importance of integrating external information into customer-risk assessments. The customer's eventual involvement in a police investigation was identified after the relevant activity had already taken place, but the existence of such information demonstrates why adverse media, law-enforcement information and other risk intelligence can be important components of ongoing monitoring.


Operators cannot reasonably predict every future development involving a customer, but they can ensure that new information is assessed promptly when it becomes available.


For compliance professionals, one of the most important lessons from the case is that policies must be measurable and operational. If a policy states that a particular occupation represents a high-risk indicator and that reaching a specific deposit threshold triggers enhanced due diligence, the operator needs systems capable of reliably identifying both conditions and ensuring that the required review takes place.


Gambling License

The same applies to escalation procedures. Where a policy requires transactions to be refused or an account to be restricted once particular risk indicators are present, those requirements must be supported by clear decision-making procedures and adequate staff authority.


The case also demonstrates why AML testing should examine actual customer files rather than simply confirming that written policies exist. A compliance programme can appear comprehensive on paper while failing at the point where customer activity needs to be reviewed.


For Ontario's regulated gambling sector, the regulator's message is consequently broader than the specific NorthStar case. Risk-based AML controls are expected to operate as active safeguards against the misuse of licensed gaming platforms, not merely as documentation maintained for regulatory purposes.


The penalty is also a reminder that the financial-crime risks associated with online gambling extend beyond traditional concerns about anonymous cash transactions. Digital betting platforms can process substantial volumes of deposits electronically, making effective customer identification, source-of-funds verification, risk scoring and transaction monitoring essential.


Operators therefore need to understand both the customer's identity and the financial context surrounding their gambling activity.


NorthStar's subsequent investment in its compliance infrastructure indicates that the company is seeking to address those weaknesses and strengthen its ability to identify high-risk customers at an earlier stage.


The wider significance of the enforcement action lies in the regulator's emphasis on implementation. Having an AML policy is not sufficient if the operator fails to act when its own risk indicators are triggered.


For licensed gaming businesses, the practical lesson is straightforward: customer risk classifications must be accurate, deposit thresholds must trigger meaningful reviews, source-of-funds checks must be completed when required and escalation procedures must operate without unnecessary delay.


The NorthStar case demonstrates the potential consequences when those elements fail to work together. A single customer account resulted in prolonged exposure, almost C$190,000 in deposits and ultimately a significant regulatory penalty.


As Ontario continues to develop its regulated online gambling market, effective AML controls will remain a central component of licensing and regulatory compliance. The latest action reinforces that operators are expected to identify financial-crime risks proactively and take meaningful action when those risks emerge, rather than waiting for law-enforcement intervention or regulatory inquiries to expose weaknesses in their systems.

By fLEXI tEAM

Comments


bottom of page