Finance

The Second Licence Nobody Budgets For: Your Gaming Approval Also Makes You an AML Obliged Entity

Article 4(2) point 10 makes gaming operators obliged entities, and Article 66(1) sets their reporting threshold at €2,000 — not €15,000 or €100,000.

Rohat Kahraman· 5 September 2026Updated · 5 September 2026
Abstract cover for a guide to AML obligations of Montenegrin gaming operators

Operators planning a Montenegrin entry model the gaming approval — the capital, the location decisions, the monthly fees. The compliance obligation that arrives with it sits in a different statute, applies from the first day of trading, and carries a reporting threshold roughly fifty times lower than the one banks work to.

Article numbers below are from the Zakon o sprečavanju pranja novca i finansiranja terorizma, published in "Službeni list CG" br. 110/2023, 65/2024, 24/2025, 41/2026 — a decision of the Constitutional Court of Montenegro — and 59/2026, read from the ministry-published consolidated text on 5 September 2026.

One point about that chain, stated rather than smoothed over. The entry at 41/2026 is a Constitutional Court decision, not an ordinary amending act. A Constitutional Court decision removes or alters provisions rather than adding them, and the consolidated copy we read does not, on its face, identify which provision it touched. We are not going to guess. Where a specific provision below is load-bearing for a decision, it is worth confirming against the decision itself.

You are on the list

Article 4(2) lists the obliged entities, and point 10 is short: priređivači igara na sreću — organisers of games of chance. There is no turnover qualifier, no start-up grace period and no exemption for small operators on the face of that point.

Article 6 point 39 then defines the term more widely than the gaming statute alone would: an organiser of games of chance is an organiser within the meaning of the law governing games of chance, as well as an organiser holding the competent authority's consent to organise those games via the internet or other telecommunications means. An online-only operator is squarely inside the definition.

For context, Article 4(2) point 12 puts crypto-asset service providers on the same list, and Article 4(2) point 1 covers credit institutions. The obligations differ by category, but the status does not.

The threshold that changes the compliance build

Article 66(1) requires an obliged entity to deliver accurate and complete customer due diligence data to the financial intelligence unit without delay and at the latest within three working days of the transaction being carried out, or of learning that it was carried out. The trigger amounts differ sharply by category:

Obliged entityReporting trigger under Art. 66(1)
Any obliged entity — non-cash transaction€100,000 or more
Credit institutions and other payment service providers — cash€10,000 or more
Crypto-asset service providers and certain Art. 4(2) point 13 activities — occasional cash transactions€3,000 or more but under €10,000
Organisers of games of chance (Art. 4(2) point 10)€2,000 or more — for every transaction

Read the last row carefully. It is not limited to cash. It is not an occasional-transaction rule. It is every transaction of €2,000 or more, with a three-working-day reporting clock attached.

Article 66(3) adds a separate trigger that catches cross-border play: every transaction of €20,000 or more carried out on accounts of legal or natural persons in high-risk third countries, or involving such countries, must be reported on the same basis.

The practical consequence is architectural rather than procedural. A €2,000 per-transaction threshold on a betting or online book means the reporting obligation is a systems requirement, not a compliance-officer requirement. It has to be built into the transaction layer before launch, because a manual process will not survive the volume.

What a casino has to do at the door

Article 30(1) point 1 requires the obliged entity to identify the client on the client's entry into the premises where casino games are organised — not at the table, not at a cash threshold, but at the door.

Article 30(2) specifies what that identification involves for casinos: obtaining a photocopy of the client's identity document in accordance with Article 22(3), and a written statement in which the client declares, under material and criminal liability, that they participate in the casino games for their own account and in their own name.

That written declaration is the provision most foreign operators have no equivalent of at home. It is not a tick-box on a membership form; it is a statement carrying stated liability, and it exists to close the nominee-player route into the casino floor.

Article 30(3) allows the parallel obligation for safe-deposit access to be satisfied by electronic identification card, personal access code, video identification or biometric means — a flexibility the casino-entry limb does not carry.

The exemption that stops short of casinos

Article 4(6) gives the Government a power to exempt operators of certain games of chance from all or some of the measures under the Act, in a defined part of their business, where a completed risk assessment establishes a lower money-laundering and terrorist-financing risk.

It contains an express carve-out: except casinos. A casino cannot be exempted under that provision at all.

Article 4(7) constrains the assessment itself — it must be based on the nature, manner of performance, payment methods and volume of the entity's business. So the exemption is not a category relief available on application; it is a Government act resting on a risk assessment against stated criteria.

Article 4(5) runs the other way: the Government may designate additional obliged entities where the nature of an activity presents a higher risk. The list in Article 4(2) is a floor, not a ceiling.

The records a gaming operator has to keep are different

Article 117(1) sets out the general content of the customer due diligence record — identification data, the manner in which identification was carried out (physical presence, electronic or video-electronic identification), the video-audio recording where video identification was used, the purpose and nature of the relationship and transaction, the source of the assets and funds, and a long list of transaction data including whether the transaction was cash, non-cash or crypto-asset, and the deposit addresses of the sender and recipient of crypto-assets.

For gaming, Article 117(1) point 6 adds something specific: the record must carry the date and time of entry into the casino or of access to a safe-deposit box.

Article 117(2) goes further for gaming operators and safe-deposit providers. In addition to the identification data, the record for natural persons must contain data on what the person actually did, according to the type of obliged entity — entry into the premises where games are organised, access to games via the internet or other telecommunications means, access to the cash desk, access to other places or locations where transactions are carried out according to the type of game, or access to the safe-deposit box.

That is an event-level logging obligation. For an online operator it means the session and access layer is part of the AML record, not only the payment layer.

How this sits with the gaming approval

The two regimes are issued by different authorities, on different criteria, and neither substitutes for the other. The approval under the gaming statute answers whether you may organise the games; the obliged-entity status answers what you must do while organising them. We set out the approval side — including the abolition of the concession model, the capital thresholds and the monthly online fee — in Montenegro's 2025 gaming act.

The overlap that matters commercially is the banking one. An obliged entity that cannot evidence its own AML framework has a harder time being onboarded by a bank, and that sequencing problem is the one that most often decides timing in these files, as we set out in why a crypto company cannot get a bank account.

The cash ceiling that names gaming winnings

Article 65(1) prohibits legal persons, companies, entrepreneurs and natural persons from receiving a payment, or making a payment or paying out winnings, in cash of €10,000 or more. The reference to winnings is express, which puts the provision directly into the gaming cash desk rather than leaving it as a general commercial rule.

Article 65(2) applies the same ceiling where the payment is made in two or more linked transactions totalling €10,000 or more, including loan arrangements — so structuring a payout across several visits does not avoid it. Article 65(3) then states the only permitted route for an amount at or above that level: payment or transfer to a transaction account opened with a credit institution in Montenegro.

Article 65(4) gives supervision over persons who are not obliged entities to the tax administration, and Article 65(5) exempts deposits with credit institutions and other payment service providers — with Article 65(6) requiring those institutions to enforce the cash restriction in relation to defined categories of obliged entity.

What the Act requires you to build internally

Article 14 requires the obliged entity to establish policies, controls and procedures for managing money-laundering and terrorist-financing risk, and to verify those internal policies and procedures, proportionately to the scope and nature of its business. The policies are adopted by the competent management body or a senior manager.

The same article then requires the obliged entity, again proportionately to the scope and nature of the business, to appoint an authorised person for the prevention of money laundering and terrorist financing at a management position — not at any level of the organisation, but at management level. Article 11(1) point 5 carries the parallel duty to appoint that person and a deputy and to secure the conditions for their work.

Article 15 provides that the criteria for the risk-analysis guidelines are set by regulation, and Article 14 requires the policies to be prepared on the basis of the supervisory authority's guidelines and the National Risk Assessment. The internal framework is therefore not a free-form document; it is written against published guidance.

The penalties, and who pays them

Article 137(1) sets the general range for a legal person at €8,000 to €80,000 for the offences it lists, which run to well over a hundred numbered items and include the Article 66(1) reporting failure at item 135. Article 137(2) raises the range to €10,000 to €80,000 for obliged entities under Article 4(2) points 1, 2 and 3 — credit institutions and the financial-sector entities.

Liability does not stop at the company. Article 137(3) fines a member of the management or another responsible person in the legal person, a natural person, a natural person performing an activity, and a notary €1,000 to €8,000. Article 137(5) fines an entrepreneur €1,000 to €20,000. And Article 137(4) does something unusual: where a penalty is imposed on the obliged entity under Article 131a(2), a member of the collegial management body responsible for implementing the Act is fined six to twelve gross monthly salaries or fees received in the month preceding the month in which that penalty was imposed — a personal exposure calculated from the individual's own pay.

Article 137(1) also allows a prohibition on performing the profession, activity or duty to be imposed on a legal person for those offences.

One inconsistency in the consolidated text

Reading Article 66(1) against the penalty provision that enforces it produces a discrepancy worth flagging rather than resolving. Article 66(1) sets the cash-transaction reporting trigger for credit institutions and other payment service providers at €10,000 or more. Item 135 of Article 137(1), which penalises the failure to report under Article 66(1), describes the same trigger as €15,000 or more.

Both figures appear in the same consolidated edition. One of them has not been updated to match the other, and we cannot tell from the text which. The gaming figure — €2,000 under Article 4(2) point 10 — is stated identically in both places, so the point does not affect the threshold this page is about. It does mean that anyone relying on the credit-institution cash figure should check it against the amending acts directly.

Before you model the compliance budget

If you are assessing a Montenegrin gaming entry, or you already hold an approval and have not mapped the Act against your transaction layer, send us the verticals, the payment flows and the customer journey — including how players are identified at entry or at registration — and we will identify which Article 4(2) obligations attach, what the Article 66(1) €2,000 threshold means for your reporting architecture, whether anything in your model could support an Article 4(6) exemption, and what Article 117(2) requires your systems to log. The general obliged-entity framework is in AML obligations for businesses, the crypto version in you're on the register, now you're an obliged entity, and how we run licensing files sits with our fintech, crypto and financial licensing practice.

Frequently asked questions

Are gaming operators AML obliged entities in Montenegro?

Yes. Article 4(2) point 10 of the Zakon o sprečavanju pranja novca i finansiranja terorizma lists organisers of games of chance among the obliged entities, without a turnover qualifier or a start-up exemption on the face of that point.

Does this apply to an online-only operator?

Yes. Article 6 point 39 defines an organiser of games of chance as an organiser within the meaning of the gaming legislation, as well as one holding the competent authority's consent to organise those games via the internet or other telecommunications means.

What is the reporting threshold for a gaming operator?

Article 66(1) sets it at €2,000 or more for every transaction, with the data to be delivered to the financial intelligence unit without delay and at the latest within three working days. That compares with €100,000 for non-cash transactions generally and €10,000 for cash transactions by credit institutions and payment service providers.

When does a casino have to identify a customer?

Article 30(1) point 1 requires identification on the client's entry into the premises where casino games are organised. Article 30(2) requires a photocopy of the identity document and a written statement in which the client declares, under material and criminal liability, that they play for their own account and in their own name.

Can a gaming operator be exempted from the AML rules?

Only partly, and never a casino. Article 4(6) allows the Government to exempt organisers of certain games of chance — expressly except casinos — from all or some of the measures, in a defined part of the business, where a risk assessment establishes lower risk. Article 4(7) requires that assessment to rest on the nature, manner, payment methods and volume of the business.

What has to be logged?

Article 117(1) sets the general record content, including the manner of identification and the date and time of entry into a casino. Article 117(2) adds, for gaming operators, data on the person's actual conduct — entry into the premises, access to games via the internet or other telecommunications means, access to the cash desk, access to other transaction locations, or access to a safe-deposit box.

Is there a special rule for high-risk countries?

Yes. Article 66(3) requires reporting of every transaction of €20,000 or more carried out on accounts of legal or natural persons in high-risk third countries, or where the transaction involves such countries, on the same three-day basis.

Which version of the AML Act is current?

The chain is "Službeni list CG" br. 110/2023, 65/2024, 24/2025, 41/2026 and 59/2026. The entry at 41/2026 is a decision of the Constitutional Court of Montenegro rather than an ordinary amending act, and the consolidated text does not identify on its face which provision it affected — a point to confirm against the decision where a specific provision is load-bearing.