QuinnBet (Gibraltar) Limited Public Statement
Our public statements make reference to breaches of the Licence Conditions and Codes of Practice (LCCP) requirements which were in effect at the time of the breach. In some cases, the requirements have since been updated.
Operators are expected to consider the issues outlined below and review their own practices to identify and implement improvements in respect of the management of customers’ accounts.
Introduction
Licensed gambling operators have a legal duty to ensure their gambling facilities are provided in compliance with the Gambling Act 2005 (opens in new tab)(the Act), and the conditions of their licence, and in accordance with the licensing objectives, which are to:
- prevent gambling from being a source of crime or disorder, being associated with crime or disorder or being used to support crime
- ensure that gambling is conducted in a fair, safe and open way
- protect children and other vulnerable people from being harmed or exploited by gambling.
Operators are expected to consider the issues outlined below and review their own practices to identify and implement improvements in respect of the management of customers’ accounts.
QuinnBet (Gibraltar) Limited Executive Summary
A regulatory review under section 116 of the Act was commenced following a Compliance Assessment of the remote operating licence of QuinnBet (Gibraltar) Limited (hereafter referred to as QuinnBet), licence number 000-061011-R-335683-004.
The review is being concluded by way of a regulatory settlement.
The review found failings in QuinnBet’s Anti-Money Laundering / Counter Terrorism Financing (AML/CTF) and Social Responsibility (SR) controls.
QuinnBet failed to comply with the following Licence Conditions and Codes of Practice (LCCP):
- paragraphs 2 and 3 of licence condition (LC) 12.1.1 relating to the prevention of money laundering and terrorist financing
- paragraphs 1, 3, 5 (a, b and c), 7, 8, 9, 11 and 13 of Social Responsibility Code Provision (SRCP) 3.4.3 relating to remote customer interaction
- paragraph 1 of SRCP 3.4.4 relating to financial vulnerability checks.
In line with our Statement of Principles for Licensing and regulation, QuinnBet will make a payment in lieu of a financial penalty of £609,104. Details of this are set out under the heading Regulatory Settlement.
QuinnBet (Gibraltar) Limited Findings
A Commission compliance assessment and subsequent regulatory review found:
Breach of paragraphs 2 and 3 of Licence Condition 12.1.1
LCCP 12.1.1 paragraphs 2 and 3 require:
"Following completion of and having regard to the risk assessment, and any review of the assessment, licensees must ensure they have appropriate policies, procedures and controls to prevent money laundering and terrorist financing.
Licensees must ensure that such policies, procedures and controls are implemented effectively, kept under review, revised appropriately to ensure that they remain effective, and take into account any applicable learning or guidelines published by the Gambling Commission from time to time."
We found that, between March 2023 and August 2025, QuinnBet failed to ensure it had appropriate policies, procedures and controls to prevent money laundering and terrorist financing, and that these were implemented effectively.
We found QuinnBet:
- had insufficient controls to act in a timely manner to identify and mitigate the risk posed by customers who were displaying disproportionate spend.
For example, a customer whose payslips showed monthly earnings of circa £2,000 was able to deposit, and lose, £9,000 in four days.
- was over-reliant on Source of Wealth (SoW) in some circumstances, and, on occasion, assumed that winnings were being recycled. Some customers were able to deposit significant funds without the Source of Funds (SoF) being established to evidence that the monies were from a legitimate source.
For example, a customer deposited around £120,000 and withdrew £111,000 in a little under three months. Although a bank statement and tax return were provided, neither showed transactions with QuinnBet. QuinnBet had assumed that the customer was recycling funds, but no evidence was sought, or provided, to evidence that.
had insufficient controls to ensure that Suspicious Activity Reports were submitted as soon as practicable after the information came to it.
allowed 194 customers to deposit and potentially lose funds in excess of intended limits. The mistake was the result of human and software update errors during migration to a new platform and a consequent failure of two deposit limit controls on some customer accounts.
Failure to comply with paragraphs 1, 3, 5 (a, b and c), 7, 8, 9, 11 and 13 of SRCP 3.4.3
Compliance with a SRCP is a condition of the licence by virtue of section 82(1) of the Act.
We found that between October 2023 and August 2025 QuinnBet failed to comply with the following requirements relating to remote customer interaction.
SRCP 3.4.3 paragraph 1 requires:
"Licensees must implement effective customer interaction systems and processes in a way which minimises the risk of customers experiencing harms associated with gambling. These systems and processes must embed the three elements of customer interaction – identify, act and evaluate – and which reflect that customer interaction is an ongoing process as explained in the Commission’s guidance (see paragraph 2)."
We found that QuinnBet had not always ensured that its policies, procedures and controls had been effectively implemented.
Whilst there was not a broad systemic failure of the controls there were examples (detailed below) of QuinnBet not having effective processes for identifying, acting and evaluating customer interactions to minimise harms.
For example, the temporary failure of the Licensee’s deposit limit controls caused by its platform migration.
SRCP 3.4.3 paragraph 3 requires:
"Licensees must consider the factors that might make a customer more vulnerable to experiencing gambling harms and implement systems and processes to take appropriate and timely action where indicators of vulnerability1 are identified. Licensees must take account of the Commission’s approach to vulnerability as set out in the Commission’s Guidance."
QuinnBet recognised that young adults (aged 18 to 24 years) are vulnerable to gambling harm and had lower deposit limits for these customers.
However, prior to its platform migration it had a manual process for applying these limits, meaning there could be a delay of several hours before they were active. During this time customers could deposit over their intended limit. Even when the limit was applied, it did not prevent customers from losing the funds they had deposited (including funds over the deposited limit).
For example, a young adult was able to deposit eight times the intended monthly deposit limit before it was applied. They went on to lose the entire amount within one day.
SRCP 3.4.3 paragraph 5 (a, b and c) requires:
"Licensees must use a range of indicators relevant to their customer and the nature of the gambling facilities provided in order to identify harm or potential harm associated with gambling.
These must include:
- customer spend
- patterns of spend
- time spent gambling"
We found QuinnBet’s controls were not always effective as in certain circumstances they did not flag behaviours which could have indicated potential harms, or they could be circumvented. We found:
- the real time alert for loss limits was ineffectively configured. It was only triggered when customers made a further deposit after losses exceeded (not reached) the limit. Where a customer deposited amounts exceeding the loss limit these remaining monies could still be played through without generating a loss limit alert until a further deposit was made. As a consequence, some customers would not have been sufficiently protected by the alert as they could lose significantly more than the limit intended.
For example, a customer made an initial (net) deposit of six times the loss limit. The limit only triggered when they had lost double the intended amount.
- the algorithm behind some of QuinnBet’s controls was ineffective in identifying some potential harms associated with customer spend. For example, high deposits, short high velocity sessions, increasing stakes, number of bets and high turnover were not captured and flagged for manual review.
For example, a customer was able to place approximately 4,800 bets in one day, and 7,000 bets the following day without this being identified and flagged.
SRCP 3.4.3 paragraph 7 requires:
"A licensee’s systems and processes for customer interaction must flag indicators of risk of harm in a timely manner for manual intervention, and feed into automated processes as required by paragraph 11."
We found that QuinnBet’s controls did not always flag indicators of risk of harm in a timely manner for manual intervention or automated processes.
The majority of indicators fed into a report which was not produced in real-time, rather it was produced the morning of the following day. The featured accounts were manually reviewed that day (the day after the activity that triggered the report), but on rare occasions (i.e. due to short term staffing issues) a small number of accounts might not be reviewed until the following day (two days after).
For example, following a large win, a customer’s stakes escalated to the point where over £215,000 was staked in a day with multiple wagers over £5,000. This was not identified until a report was produced the following day.
SRCP 3.4.3 paragraphs 8 and 9 require:
"Licensees must take appropriate action in a timely manner when they have identified the risk of harm.
Licensees must tailor the type of action they take based on the number and level of indicators of harm exhibited. This must include, but not be limited to, systems and processes which deliver:
- tailored action at lower levels of indicators of harm which seeks to minimise future harm
- increasing action where earlier stages have not had the impact required
- strong or stronger action as the immediate next step in cases where that is appropriate, rather than increasing action gradually
- reducing or preventing marketing or the take-up of new bonus offers where appropriate
- ending the business relationship where necessary."
We found that appropriate action was not always taken in a timely manner and it was not always appropriately tailored.
Although reviews of customer accounts were taking place at the intended points, the reviews were not always sufficiently detailed and did not consider all of the information available (as detailed in QuinnBet’s policy and procedures). Often focus would be on the customer’s financial position rather than the maker of harm observed and the action taken was not always appropriately tailored.
Further, agents did not routinely review and analyse previous reports, previous reviews, or whether previous interactions had been impactful on the customers behaviour.
For example, despite a customer’s activity being flagged for time spent playing, the reviews undertaken focussed on the financial position with the outcome of ‘continue to monitor’. No bespoke or escalating action were taken.
SRCP 3.4.3 paragraph 11 requires:
"Licensees must ensure that strong indicators of harm, as defined within the licensee’s processes, are acted on in a timely manner by implementing automated processes. Where such automated processes are applied, the licensee must manually review their operation in each individual customer’s case and the licensee must allow the customer the opportunity to contest any automated decision which affects them."
We found that although QuinnBet’s policies and procedures specified behaviours that should be considered strong indicators of harm, and which required immediate suspension of accounts, the process was reliant on manual reviews and manual account suspension – it was not automated.
SRCP 3.4.3 paragraph 13 requires:
"Licensees must take all reasonable steps to evaluate the effectiveness of their overall approach, for example by trialling and measuring impact, and be able to demonstrate to the Commission the outcomes of their evaluation."
We found there were errors within QuinnBet’s internal quality assurance function meaning that it did not correctly identify all issues.
Failure to comply with paragraph 1 of SRCP 3.4.4
We found that between February 2025 and May 2025 QuinnBet failed to comply with the following requirement relating to financial vulnerability checks.
SRCP 3.4.4 paragraph 1 requires:
"Licensees must undertake a financial vulnerability check for customers that meet the relevant threshold."
QuinnBet proactively reported to the Commission that when it migrated its operations onto a new platform an error occurred whereby some customers who met the relevant threshold were not subject to financial vulnerability checks at the intended time(s).
When the checks were run it was established that although most would have passed the check, 41 customers would have failed and 136 would have required account restrictions. The failure meant that some customers spent more than they should have been permitted to.
QuinnBet (Gibraltar) Limited Regulatory Settlement
This regulatory settlement consists of:
- a payment in lieu of a financial penalty of £609,104, which includes a disgorgement of £193,118. The money will be directed to the UK Government’s Consolidated Fund
- agreement to the publication of a statement of facts in relation to this case
- payment towards the Commission’s costs of investigating the case.
In considering an appropriate resolution to this investigation, the Commission had regard to the following aggravating and mitigating factors:
Aggravating factors
- the Commission previously issued public statements regarding similar issues which it has observed in relation to other operators.
Mitigating factors
QuinnBet:
- has not previously been subject to regulatory enforcement action
- swiftly devised and put in place an appropriate action plan designed to remedy the failings, provided frequent updates
- fully co-operated with the investigation and provided information by agreed deadlines
- made early and voluntary reports of some of the failings to the Commission
- voluntarily and proactively divested itself of funds had been accrued as a result of some of the failings
- accepted the failings at an appropriately early stage in the investigation.
Good practice
Gambling operators should take account of the failings identified in this investigation to ensure industry learning. Operators should consider the following questions and take remedial action where required:
- are your policies, procedures and controls and staff training sufficient to identify where a customer’s spend is disproportionate, and take appropriate action to mitigate potential risks?
- are your AML controls sufficient to ensure you establish Source of Funds at appropriate times? Amongst other things, do you ask for evidence that funds deposited are recycled winnings at appropriate points or do you merely assume they are?
- do you have sufficient controls in place to ensure that Suspicious Activity Reports are made as soon as practicable after the information comes to you?
- when making changes to IT infrastructure have you taken all reasonable precautions to ensure that controls continue to function as intended? Do you have robust methods to check this both before and after implementation?
- do you apply intended deposit limits in a timely manner to ensure that customers cannot exceed them?
- if you rely on an algorithm to detect potential gambling related harms, is it effectively configured to ensure it functions as intended? Have you undertaken sufficient testing and do you monitor its effectiveness? Does your algorithm include all of the indicators relevant to your customers and the nature of gambling you provide? (specified in SRCP 3.4.3, paragraph 5)
- do your safer gambling systems flag indicators of risk of harm in a timely manner for manual intervention and feed into automated processes, or is there an avoidable delay?
- when you identify a risk of gambling related harm do you take appropriate and timely action? Do you consider the specific marker(s) of harm displayed or do you focus on the customer’s financial position? When you review customer accounts do you ensure that you consider previous behaviours, reviews and interactions to ensure that the action you take is appropriately tailored?
- do you have automated processes that act in a timely manner when you detect strong indicators of harm or are you still reliant upon manual actions?
- do you have a robust Quality Assurance process to identify potential issues and areas for improvement? How have you assured yourself that it is functioning as intended?