Shufti-Sphere-Website-Banner
burger-menu cross-icon-2

Resources

us

216.73.216.37

Turn Malta’s 72-Hour KYC Window Into a Revenue Advantage

malta igaming window

TL;DR

  • Malta requires CDD once a player’s cumulative deposits cross €150.

  • Enhanced due diligence triggers at €2,000 deposits or the first withdrawal, whichever comes first.

  • Verification speed is a revenue metric, and slow KYC sends players to competitors.

  • Operators serve players from 100+ jurisdictions, so document and OCR coverage decides pass rates.

  • New-account fraud rose 31% year-on-year, per Javelin’s 2025 study.

  • Shufti runs CDD, document, face match, and AML screening in one sub-15-second flow.

Our current vendor has a 24-hour turnaround on KYC checks.” A Malta-licensed operator’s compliance lead said that last quarter, the number wasn’t bragging. Twenty-four hours is when a real slice of registrants walks away.

Malta runs the European Union’s most concentrated regulated remote-gaming market. More than 300 MGA-licensed operators compete for player attention in a sector that KPMG Malta puts at over 12% of national GDP, with players arriving from 100+ jurisdictions. 

Each of those players has to clear identity verification under Malta’s anti-money-laundering rules before the first withdrawal, and every minute of friction inside that window shows up in Monday’s revenue numbers.

This piece breaks down what the Malta Gaming Authority (MGA) and Financial Intelligence Analysis Unit (FIAU) actually require at onboarding, why verification speed is a revenue metric, and what a product team should look for when auditing its own stack.

In Malta, player verification sits under two overlapping regimes. The MGA licenses operators under the Gaming Act and sets consumer-protection rules. The FIAU supervises AML/CFT compliance under the Prevention of Money Laundering and Funding of Terrorism Regulations (PMLFTR), which apply to every licensed B2C operator offering Type 1, 2, or 3 games.

Where Malta’s real KYC thresholds sit?

Malta does not publish a single 72-hour KYC rule as a statutory clause. It publishes a set of thresholds and events that, taken together, force operators to move fast. 

Under the FIAU Implementing Procedures Part II for Remote Gaming (2020 revision, still current), customer due diligence (CDD) is required once a player’s cumulative deposits cross €150, and enhanced due diligence (EDD) has to be in place before the first withdrawal or at €2,000 cumulative deposits, whichever comes first. 

The 72-hour window is where commercial reality meets the regulation.

At €150 cumulative deposits, the CDD obligation kicks in, which for most MGA-licensed operators means gathering a government-issued ID, verifying the document’s authenticity, confirming it belongs to the person on the other side of the screen, and storing an audit trail the FIAU can pull during an on-site review. Small-deposit players still have to clear this step. That surprises operators expanding into Malta from jurisdictions where the first-deposit threshold is higher.

EDD triggers at €2,000 cumulative deposits or the first withdrawal request, whichever lands first. It means pulling additional information on the source of funds, understanding the player’s wealth profile, and running politically exposed person (PEP) and sanctions screening against the same identity data. 

Under FIAU guidance, high-risk indicators (high deposit velocity, third-country documents, adverse media hits) can pull the EDD trigger forward. In practice, a well-designed verification flow treats every registration as a potential EDD candidate and captures the data once, rather than asking a player to resubmit when the threshold is crossed.


malta mga and fiau

Why is every minute of verification a revenue decision?

Inside the Maltese licensee set, verification speed is a P&L metric, not a back-office one. Players who hit a queue abandon it. Players who abandon take their next deposit to a competitor on the same island. And because Malta runs the most concentrated MGA-licensed operator set in the European Union, the competitor is usually one URL away. Speed, in other words, is the revenue system that happens to also satisfy the FIAU.

The commercial math is straightforward once you lay it out. The 2025 Identity Fraud Study from Javelin Strategy & Research reported new-account fraud up 31% year-on-year, which means operators face more false positives in the same review queue that holds genuine players. Every extra minute a real player spends waiting, a fraudster’s attempt draws closer to slipping through on a rushed manual review. The two problems compound.

The drop-off curve itself is steep. For an MGA-licensed B2C operator, the funnel from registration to first deposit is where most player revenue either locks in or leaks. 

If verification goes through in seconds, the pass rate stays high, and the conversion is effectively free. If verification stalls for hours, abandonment climbs with every passing marker, and a measurable share of the original registrant base is gone before they ever fund an account.

There is also a compliance cost to being slow. Weak onboarding controls are one of the most common root causes the FIAU identifies in thematic review findings. In 2024, the FIAU issued 109 administrative measures and handled 9,430 suspicious transaction reports (STRs) across the economy, with remote gaming remaining the leading sector for STR volume. Slow, manual verification creates gaps in the audit trail that become findings the next time FIAU is on site.


malta igaming drop off

Turn KYC speed into conversion

Shufti runs CDD, document, face match, and AML screening as one parallel flow that resolves in under 15 seconds.

See Malta-ready KYC

How do Malta’s iGaming operators verify players from 100+ jurisdictions?

The document problem is the specific one Malta’s operators deal with every day. A single MGA-licensed B2C platform typically serves players from more than 100 jurisdictions, arriving with national ID cards, passports, driving licences, residence permits, and regional identity documents in dozens of languages and scripts. The verification flow has to handle the variety without punting to a manual reviewer, and the gaming industry in Malta has to do it at the same speed players expect from every other app on their phone.

The operators who keep pass rates high invest in three specific parts of the stack. Document coverage has to be broad because a Malta-licensed operator’s typical player base spans the European Union, the Gulf states, Southeast Asia, Latin America, and an increasing share of African markets. 

Optical character recognition (OCR) behind the capture has to handle non-Latin scripts, since Arabic, Cyrillic, Devanagari, and Mandarin characters all turn into a support ticket when the engine was trained on European ID sets. Liveness and face-match have to work on mobile-quality photos. 

A pipeline tuned for broadband-connected desktop users collapses under compression artifacts, off-angle selfies, and variable lighting, which is what real players actually send in.

On top of those three parts, an AML screening pass has to run in parallel with the biometric step, not after it. Running the screen after face-match doubles the player’s wait without adding diagnostic value. The operators who move fastest in Malta run CDD, document verification, face match, and an initial sanctions and PEP scan as one concurrent pipeline, then surface a single result to the player inside the session.

For a player with a non-Latin-script national ID, the sequence looks like this in practice. Upload the document from a phone, see a live-feedback prompt if the capture is poor, complete a selfie in under fifteen seconds, and land on the deposit page without reading a message that starts with “Thank you for your patience.” That is the bar Malta’s post-greylisting compliance culture has set, and it is the one an FIAU thematic review will eventually measure an operator against.

How does Shufti help MGA operators verify global players inside the 72-hour window?

Malta’s combination of thresholds, player-base diversity, and concentrated competition is the exact workload Shufti was built for. Shufti’s identity verification pipeline covers documents from 220+ countries and runs OCR across 150+ languages, which removes the non-Latin-script gap that trips up European-trained stacks. 

Behind that, document verification handles 10,000+ document types from every common player-origin market, with authenticity checks built to resist the tampering patterns that actually show up in live iGaming fraud.

The same pipeline runs liveness-backed face match inside the session, with the liveness engine holding iBeta Level 3 conformance under ISO/IEC 30107-3, alongside a sanctions and PEP screen that surfaces hits in the same decision rather than a secondary queue. For a Maltese operator serving 100+ player-origin countries, that single-flow design is the difference between a 15-second KYC and a 15-minute one.

For a Maltese operator, the combined pipeline lands inside the 72-hour practical window without forcing a trade-off between pass rate and audit depth. A full Maltese KYC workflow run takes under 15 seconds when the pipeline is hardware-accelerated, and every decision, whether pass, fail, or escalate, generates the timestamped evidence trail the FIAU expects during a thematic review. 

For more on how Shufti handles these unique challenges, visit our Malta Country Page.

For Malta-licensed gaming operators, the distance between a compliant KYC and a revenue-positive KYC is measured in minutes, and that distance shows up in every monthly conversion report. Shufti’s approach to the MGA and FIAU rulebook, the 100+ country document problem, and the 72-hour commercial window is documented in the Malta operator playbook for teams already building their evaluation shortlist.

Spin up a test flow through the self-service portal to run real player documents against the full KYC pipeline before a single commercial call.


Frequently Asked Questions

What are Malta's KYC requirements for iGaming operators?

MGA-licensed B2C operators must run customer due diligence when a player's cumulative deposits reach €150, under the FIAU Implementing Procedures Part II for Remote Gaming (2020 revision). Enhanced due diligence is required at €2,000 cumulative deposits or at the first withdrawal request, whichever comes first. Verification is mandatory before any funds leave the platform.

When does enhanced due diligence (EDD) trigger for MGA-licensed platforms?

EDD triggers at €2,000 cumulative deposits or when the player submits a first withdrawal request, whichever arrives first. Higher-risk indicators (high deposit velocity, third-country documents, PEP matches, adverse media hits) can pull the EDD trigger forward under FIAU guidance, meaning an MGA operator should be ready to run EDD at registration for some players.

Why do iGaming players drop off during KYC verification?

Most abandonment clusters are at the document capture and manual review queues. Poor-quality photos, unsupported document types, and delayed back-office reviews all send players to a competitor's platform. MGA operators that keep pass rates high run document coverage across 100+ countries, automated anti-spoofing, and parallel AML screening, so the full KYC resolves in the original session.

How do Malta operators handle players with non-Maltese ID documents?

Players from 100+ countries arrive with passports, national IDs, residence permits, and driving licences in every script. MGA operators need document libraries covering all of them, OCR that reads non-Latin characters, and a face-match step that tolerates mobile photo quality. Verification flows that punt these cases to manual review bleed conversion in Malta's concentrated, competitive market.



Related Posts

Blog

How Malta’s iGaming Operators Can Put an End to Synthetic Identity Fraud

How Malta’s iGaming Operators Can Put an End to Synthetic Identity Fraud

Explore More

Blog

Turn Malta’s 72-Hour KYC Window Into a Revenue Advantage

Turn Malta’s 72-Hour KYC Window Into a Revenue Advantage

Explore More

Blog, Identity & KYC

Identity Verification Pricing: How Pricing Models Work and What to Look For?

Identity Verification Pricing: How Pricing Models Work and What to Look For?

Explore More

Blog

Best Background Verification Companies in 2026

Best Background Verification Companies in 2026

Explore More

Blog

The Real Cost of Identity Verification (And 5 Ways to Reduce It)

The Real Cost of Identity Verification (And 5 Ways to Reduce It)

Explore More

Blog, Identity & KYC

What Sets Top Identity Verification Providers Apart

What Sets Top Identity Verification Providers Apart

Explore More

Blog, Identity & KYC

Identity Verification for Neobanks: Process, Regulation, and What Goes Wrong at Scale

Identity Verification for Neobanks: Process, Regulation, and What Goes Wrong at Scale

Explore More

Blog

How Malta’s iGaming Operators Can Put an End to Synthetic Identity Fraud

How Malta’s iGaming Operators Can Put an End to Synthetic Identity Fraud

Explore More

Blog

Turn Malta’s 72-Hour KYC Window Into a Revenue Advantage

Turn Malta’s 72-Hour KYC Window Into a Revenue Advantage

Explore More

Blog, Identity & KYC

Identity Verification Pricing: How Pricing Models Work and What to Look For?

Identity Verification Pricing: How Pricing Models Work and What to Look For?

Explore More

Blog

Best Background Verification Companies in 2026

Best Background Verification Companies in 2026

Explore More

Blog

The Real Cost of Identity Verification (And 5 Ways to Reduce It)

The Real Cost of Identity Verification (And 5 Ways to Reduce It)

Explore More

Blog, Identity & KYC

What Sets Top Identity Verification Providers Apart

What Sets Top Identity Verification Providers Apart

Explore More

Blog, Identity & KYC

Identity Verification for Neobanks: Process, Regulation, and What Goes Wrong at Scale

Identity Verification for Neobanks: Process, Regulation, and What Goes Wrong at Scale

Explore More

Take the next steps to better security.

Contact us

Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

Contact us

Request demo

Get free access to our platform and try our products today.

Get started