Anti-Money Laundering & Counter-Terrorist Financing (AML/CTF) Policy

Policy ownerSuperSubBetting (sole trader)
Effective date1 January 2025
Version1.0
Review frequencyAnnually

1. Purpose

This policy sets out SuperSubBetting's approach to anti-money laundering (AML) and counter-terrorist financing (CTF). It documents the business's risk assessment, the controls applied and the escalation procedure.

2. Legal context — what applies to a digital publisher

Important: scope of AML legislation for this business

  • The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs 2017) apply to businesses operating in specific "regulated sectors". These include financial institutions, accountants, solicitors, estate agents, casinos and certain other categories.
  • Digital publishing is not a regulated sector under the MLRs 2017. SuperSubBetting is therefore not a supervised entity under those Regulations and is not required to register with an AML supervisory body (such as HMRC or the FCA) on the basis of its publishing activities.
  • SuperSubBetting does not operate a casino or accept gambling payments and is therefore not subject to UKGC AML requirements applicable to licensed operators.
  • The Proceeds of Crime Act 2002 (POCA) and the Terrorism Act 2000 apply to all persons in the UK. SuperSubBetting is subject to the general law obligations not to engage in, facilitate or conceal money laundering or terrorist financing, and to make a Suspicious Activity Report (SAR) where required under those Acts (see section 7 below).

3. Scope

This policy applies to:

  • Contractual business payments received from operators.
  • Any payments made to freelancers, contractors or service providers.
  • The business's own bank account and financial transactions.

It does not apply to end-user gambling transactions, which are processed exclusively by licensed operators.

4. Responsibilities

The sole trader is personally responsible for AML/CTF compliance. There is no separate Money Laundering Reporting Officer (MLRO). All AML obligations rest with the sole trader.

5. Risk assessment

SuperSubBetting's ML/TF risk is assessed as low for the following reasons:

  • The business accepts contractual payments only from identified gambling operators. Licensed operators conduct their own customer due diligence on end users.
  • The business does not handle customer funds, accept bets or process gambling deposits.
  • Business payments are made by bank transfer from known counterparties. Payment sources are transparent and traceable.
  • The business has no cash transactions.
  • There are no complex corporate structures or opaque ownership arrangements.

6. Practical controls

  • Know Your Counterparty: The sole trader verifies that any new operator counterparty is an identified business before entering into a commercial relationship and checks applicable regulatory authorisation.
  • Payment transparency: Business payments are received via named bank transfer from identified counterparties. Unusual payment methods (e.g. cryptocurrency or third-party payments from unknown sources) are not accepted.
  • Freelancer payments: Any payments to freelancers are made to named UK bank accounts. The sole trader does not pay individuals in cash or via anonymous payment services.
  • Transaction monitoring: The sole trader reviews bank statements regularly and flags any unusual or unexpected payments for further investigation.

7. SAR reporting — when and how

When a SAR is required

Under POCA 2002 (sections 330 and 338), any person — including a sole trader outside the regulated sector — who knows or suspects that a person is engaged in, or attempting, money laundering must submit a SAR to the National Crime Agency (NCA) via the UKFIU online portal as soon as practicable. Failure to do so is a criminal offence under section 330 POCA 2002 for those in the regulated sector; for those outside it, the "failure to disclose" offence under s.330 does not apply, but the "concealing", "arranging" and "acquisition" offences under ss.327–329 still do.

When escalation to the operator or payment provider is more appropriate

In practice, SuperSubBetting's most likely encounter with potential money laundering is an unusual payment instruction from an operator or third party. In such cases:

  1. Do not proceed with the transaction.
  2. Contact the operator's compliance team directly to flag the concern before submitting a SAR where appropriate.
  3. If the concern relates to the operator itself, or the operator does not respond satisfactorily, submit a SAR to the NCA.
  4. If fraud is suspected, report to Action Fraud (0300 123 2040).
  5. If there is an immediate risk, contact the police.

8. Tipping-off

Where a SAR has been submitted, or the sole trader is aware that a SAR is being considered, it is a criminal offence under POCA 2002 (section 333A) to tip off the subject of the report that a disclosure has been or may be made. No information about a SAR or a suspicion should be shared with the relevant party.

9. Record-keeping

  • Risk assessment documented annually.
  • Records of operator due diligence checks retained for six years.
  • Any SAR submitted and all related records retained for five years from submission.
  • Bank statements retained for six years in line with HMRC requirements.

10. Training

The sole trader maintains awareness of AML/CTF obligations through annual self-review of this policy and review of NCA, UKGC and HMRC guidance relevant to small businesses.


Due-diligence summary table

This table summarises which controls apply to SuperSubBetting as a small digital publisher.

QuestionAnswerJustification
Data Protection / GDPR including breach reportingYESUK GDPR and DPA 2018 apply; a documented policy and breach procedure are in place.
Records ManagementYESA retention schedule covering financial, contractual and personal-data records is documented and applied.
Modern Slavery / Human TraffickingYESA policy is in place as best practice; the section 54 MSA 2015 transparency statement obligation does not apply (turnover below £36m threshold), but the business has zero tolerance and documented controls.
WhistleblowingYESA whistleblowing policy and external escalation routes are documented; PIDA employer obligations do not apply (no employees), but the policy exists for due diligence and good governance.
AML / CTFYES — proportionateThe business is not in a regulated sector under MLRs 2017 and is not AML-supervised, but is subject to POCA 2002 general law obligations; a risk assessment and controls are documented.
Financial Crime Controls / SARsYES — proportionateThe business documents when SAR reporting is and is not directly required, with clear escalation routes to operators, banks and the NCA where applicable.
Anti-Bribery & CorruptionYESThe Bribery Act 2010 applies to the business; a zero-tolerance policy and proportionate controls are documented.
Information SecurityYESAn information security policy covering access controls, passwords, patching, backups and incident response is documented.
Mandatory regulatory Information Security reviewNOT APPLICABLENo mandatory regulatory IS review applies to a digital publisher of this size; the business conducts an annual self-review of its information security controls as best practice.