Operators planning a Montenegrin entry model the gaming approval — the capital, the location decisions, the monthly fees. The compliance obligation that arrives with it sits in a different statute, applies from the first day of trading, and carries a reporting threshold roughly fifty times lower than the one banks work to.
Article numbers below are from the Zakon o sprečavanju pranja novca i finansiranja terorizma, published in "Službeni list CG" br. 110/2023, 65/2024, 24/2025, 41/2026 — a decision of the Constitutional Court of Montenegro — and 59/2026, read from the ministry-published consolidated text on 5 September 2026.
One point about that chain, stated rather than smoothed over. The entry at 41/2026 is a Constitutional Court decision, not an ordinary amending act. A Constitutional Court decision removes or alters provisions rather than adding them, and the consolidated copy we read does not, on its face, identify which provision it touched. We are not going to guess. Where a specific provision below is load-bearing for a decision, it is worth confirming against the decision itself.
You are on the list
Article 4(2) lists the obliged entities, and point 10 is short: priređivači igara na sreću — organisers of games of chance. There is no turnover qualifier, no start-up grace period and no exemption for small operators on the face of that point.
Article 6 point 39 then defines the term more widely than the gaming statute alone would: an organiser of games of chance is an organiser within the meaning of the law governing games of chance, as well as an organiser holding the competent authority's consent to organise those games via the internet or other telecommunications means. An online-only operator is squarely inside the definition.
For context, Article 4(2) point 12 puts crypto-asset service providers on the same list, and Article 4(2) point 1 covers credit institutions. The obligations differ by category, but the status does not.
The threshold that changes the compliance build
Article 66(1) requires an obliged entity to deliver accurate and complete customer due diligence data to the financial intelligence unit without delay and at the latest within three working days of the transaction being carried out, or of learning that it was carried out. The trigger amounts differ sharply by category:
| Obliged entity | Reporting trigger under Art. 66(1) |
|---|---|
| Any obliged entity — non-cash transaction | €100,000 or more |
| Credit institutions and other payment service providers — cash | €10,000 or more |
| Crypto-asset service providers and certain Art. 4(2) point 13 activities — occasional cash transactions | €3,000 or more but under €10,000 |
| Organisers of games of chance (Art. 4(2) point 10) | €2,000 or more — for every transaction |
Read the last row carefully. It is not limited to cash. It is not an occasional-transaction rule. It is every transaction of €2,000 or more, with a three-working-day reporting clock attached.
Article 66(3) adds a separate trigger that catches cross-border play: every transaction of €20,000 or more carried out on accounts of legal or natural persons in high-risk third countries, or involving such countries, must be reported on the same basis.
The practical consequence is architectural rather than procedural. A €2,000 per-transaction threshold on a betting or online book means the reporting obligation is a systems requirement, not a compliance-officer requirement. It has to be built into the transaction layer before launch, because a manual process will not survive the volume.
What a casino has to do at the door
Article 30(1) point 1 requires the obliged entity to identify the client on the client's entry into the premises where casino games are organised — not at the table, not at a cash threshold, but at the door.
Article 30(2) specifies what that identification involves for casinos: obtaining a photocopy of the client's identity document in accordance with Article 22(3), and a written statement in which the client declares, under material and criminal liability, that they participate in the casino games for their own account and in their own name.
That written declaration is the provision most foreign operators have no equivalent of at home. It is not a tick-box on a membership form; it is a statement carrying stated liability, and it exists to close the nominee-player route into the casino floor.
Article 30(3) allows the parallel obligation for safe-deposit access to be satisfied by electronic identification card, personal access code, video identification or biometric means — a flexibility the casino-entry limb does not carry.
The exemption that stops short of casinos
Article 4(6) gives the Government a power to exempt operators of certain games of chance from all or some of the measures under the Act, in a defined part of their business, where a completed risk assessment establishes a lower money-laundering and terrorist-financing risk.
It contains an express carve-out: except casinos. A casino cannot be exempted under that provision at all.
Article 4(7) constrains the assessment itself — it must be based on the nature, manner of performance, payment methods and volume of the entity's business. So the exemption is not a category relief available on application; it is a Government act resting on a risk assessment against stated criteria.
Article 4(5) runs the other way: the Government may designate additional obliged entities where the nature of an activity presents a higher risk. The list in Article 4(2) is a floor, not a ceiling.
The records a gaming operator has to keep are different
Article 117(1) sets out the general content of the customer due diligence record — identification data, the manner in which identification was carried out (physical presence, electronic or video-electronic identification), the video-audio recording where video identification was used, the purpose and nature of the relationship and transaction, the source of the assets and funds, and a long list of transaction data including whether the transaction was cash, non-cash or crypto-asset, and the deposit addresses of the sender and recipient of crypto-assets.
For gaming, Article 117(1) point 6 adds something specific: the record must carry the date and time of entry into the casino or of access to a safe-deposit box.
Article 117(2) goes further for gaming operators and safe-deposit providers. In addition to the identification data, the record for natural persons must contain data on what the person actually did, according to the type of obliged entity — entry into the premises where games are organised, access to games via the internet or other telecommunications means, access to the cash desk, access to other places or locations where transactions are carried out according to the type of game, or access to the safe-deposit box.
That is an event-level logging obligation. For an online operator it means the session and access layer is part of the AML record, not only the payment layer.
How this sits with the gaming approval
The two regimes are issued by different authorities, on different criteria, and neither substitutes for the other. The approval under the gaming statute answers whether you may organise the games; the obliged-entity status answers what you must do while organising them. We set out the approval side — including the abolition of the concession model, the capital thresholds and the monthly online fee — in Montenegro's 2025 gaming act.
The overlap that matters commercially is the banking one. An obliged entity that cannot evidence its own AML framework has a harder time being onboarded by a bank, and that sequencing problem is the one that most often decides timing in these files, as we set out in why a crypto company cannot get a bank account.
The cash ceiling that names gaming winnings
Article 65(1) prohibits legal persons, companies, entrepreneurs and natural persons from receiving a payment, or making a payment or paying out winnings, in cash of €10,000 or more. The reference to winnings is express, which puts the provision directly into the gaming cash desk rather than leaving it as a general commercial rule.
Article 65(2) applies the same ceiling where the payment is made in two or more linked transactions totalling €10,000 or more, including loan arrangements — so structuring a payout across several visits does not avoid it. Article 65(3) then states the only permitted route for an amount at or above that level: payment or transfer to a transaction account opened with a credit institution in Montenegro.
Article 65(4) gives supervision over persons who are not obliged entities to the tax administration, and Article 65(5) exempts deposits with credit institutions and other payment service providers — with Article 65(6) requiring those institutions to enforce the cash restriction in relation to defined categories of obliged entity.
What the Act requires you to build internally
Article 14 requires the obliged entity to establish policies, controls and procedures for managing money-laundering and terrorist-financing risk, and to verify those internal policies and procedures, proportionately to the scope and nature of its business. The policies are adopted by the competent management body or a senior manager.
The same article then requires the obliged entity, again proportionately to the scope and nature of the business, to appoint an authorised person for the prevention of money laundering and terrorist financing at a management position — not at any level of the organisation, but at management level. Article 11(1) point 5 carries the parallel duty to appoint that person and a deputy and to secure the conditions for their work.
Article 15 provides that the criteria for the risk-analysis guidelines are set by regulation, and Article 14 requires the policies to be prepared on the basis of the supervisory authority's guidelines and the National Risk Assessment. The internal framework is therefore not a free-form document; it is written against published guidance.
The penalties, and who pays them
Article 137(1) sets the general range for a legal person at €8,000 to €80,000 for the offences it lists, which run to well over a hundred numbered items and include the Article 66(1) reporting failure at item 135. Article 137(2) raises the range to €10,000 to €80,000 for obliged entities under Article 4(2) points 1, 2 and 3 — credit institutions and the financial-sector entities.
Liability does not stop at the company. Article 137(3) fines a member of the management or another responsible person in the legal person, a natural person, a natural person performing an activity, and a notary €1,000 to €8,000. Article 137(5) fines an entrepreneur €1,000 to €20,000. And Article 137(4) does something unusual: where a penalty is imposed on the obliged entity under Article 131a(2), a member of the collegial management body responsible for implementing the Act is fined six to twelve gross monthly salaries or fees received in the month preceding the month in which that penalty was imposed — a personal exposure calculated from the individual's own pay.
Article 137(1) also allows a prohibition on performing the profession, activity or duty to be imposed on a legal person for those offences.
One inconsistency in the consolidated text
Reading Article 66(1) against the penalty provision that enforces it produces a discrepancy worth flagging rather than resolving. Article 66(1) sets the cash-transaction reporting trigger for credit institutions and other payment service providers at €10,000 or more. Item 135 of Article 137(1), which penalises the failure to report under Article 66(1), describes the same trigger as €15,000 or more.
Both figures appear in the same consolidated edition. One of them has not been updated to match the other, and we cannot tell from the text which. The gaming figure — €2,000 under Article 4(2) point 10 — is stated identically in both places, so the point does not affect the threshold this page is about. It does mean that anyone relying on the credit-institution cash figure should check it against the amending acts directly.
Before you model the compliance budget
If you are assessing a Montenegrin gaming entry, or you already hold an approval and have not mapped the Act against your transaction layer, send us the verticals, the payment flows and the customer journey — including how players are identified at entry or at registration — and we will identify which Article 4(2) obligations attach, what the Article 66(1) €2,000 threshold means for your reporting architecture, whether anything in your model could support an Article 4(6) exemption, and what Article 117(2) requires your systems to log. The general obliged-entity framework is in AML obligations for businesses, the crypto version in you're on the register, now you're an obliged entity, and how we run licensing files sits with our fintech, crypto and financial licensing practice.




