How to Build a Lottery Operator AML/CFT Risk Assessment
A practical preparation method connecting lottery business exposure to control evidence, residual-risk decisions, named owners and change-driven review.
A useful lottery AML/CFT risk assessment connects the actual business model to evidence, controls and management decisions. Define the product, customers, markets and money flows; assess exposure before controls; then record how well each control works, what risk remains and who owns the response.
This is a preparation method, not a legal assessment of a particular lottery. AML/CFT obligations depend on the product, legal entity and relevant markets. Casino guidance should not be treated as a universal set of online-lottery requirements.
Define the business before scoring it
Start with the lottery operating model. Describe whether the service conducts draws, sells tickets, acts as an intermediary, offers instant games or involves wagering on external outcomes. Record the customer contract, prize obligation, payment collection, refunds and any account balance. These differences influence what evidence and controls the assessment needs, even before qualified advisers determine the legal perimeter.
List the entities, intended markets, channels, suppliers and outsourced functions included in the assessment. Separate today’s approved scope from proposed expansion. Record the data period and whether each input comes from live operations, a forecast or a documented launch scenario. Lack of data is an uncertainty to address, not a reason to label exposure low.
Build a reproducible risk-and-control matrix
Use clear descriptions rather than an unexplained colour score. This editorial matrix helps organise the work; it is not a prescribed regulatory scoring model.
| Dimension | Questions to investigate | Possible evidence |
|---|---|---|
| Customer and access | Who uses the service, through which channels, and how are risk changes identified? | Customer segments, verification outcomes, linked-account reviews and exceptions |
| Product and prizes | How do purchases, entries, refunds and prize fulfilment work? | Product rules, transaction histories and reconciliation records |
| Markets and entities | Where does the business operate and which entity is responsible? | Market-scope decisions, contracts and access configurations |
| Payments | Which providers and instruments move value, and what information reaches the operator? | Funds-flow diagrams, settlement records and provider data specifications |
| Channels and partners | Do agents, affiliates or intermediaries change the operator’s visibility? | Partner contracts, onboarding records and oversight findings |
| Control effectiveness | Do controls work in practice, including failure and exception paths? | Case samples, integration reconciliations, override logs and test evidence |
Distinguish inherent risk, control effectiveness and residual risk
Inherent risk describes exposure before the selected controls. Control effectiveness considers both whether the design addresses that exposure and whether the control operates reliably. Residual risk is the reasoned assessment after those controls. Keeping the stages separate prevents a policy document from becoming proof that a risk has disappeared.
Define the scoring scale, evidence standard and confidence level before assessing individual risks. Explain any weighting. If information is incomplete, state the limitation and assign a data-improvement action. Management should be able to follow why two products or channels received different ratings without having to reverse-engineer a spreadsheet.
Use the operation’s data to challenge assumptions
Look beyond total sales or average customer value. Review relevant distributions of registrations, purchases, refunds, payouts, payment instruments, disputes, manual decisions and linked accounts. Compare source systems with the operator ledger. Talk to payments, support, fraud and compliance owners: the same weak handoff can look like a technical issue to one team and an unresolved risk to another.
The payment-stack guide helps identify the information needed across collection and settlement. During platform procurement, ask what evidence can be exported, what remains with a vendor and how a failed feed is detected. Do not assume that a feature name proves control coverage.
Turn material findings into decisions
For each material risk, record the preventive and detective controls, accountable owner, operating evidence, exception route and known gaps. Link missing controls or unreliable data to an action, dependency, target date and interim measure. Any decision to accept residual risk should identify the person or body with the appropriate authority and the conditions of that acceptance.
Prepare a short approval summary containing the highest exposures, uncertainties, outstanding actions and proposed limits. Keep the full evidence model behind it. The governance checklist can help clarify oversight and decision records; it does not replace specialist assessment of AML obligations.
Scenario: a new payment route is proposed
Suppose a provider offers a new collection route after the launch assessment is approved. Reopen the affected payment, customer, market and data-visibility sections before enabling it. Map provider responsibilities, settlement, refunds, screening information and records available to investigators. Determine whether existing controls still address the changed flow.
If essential data or oversight is missing, document the gap and decide through the authorised process whether the route should be delayed or narrowed. Do not reuse the earlier residual-risk conclusion for a materially different system. Carry relevant dependencies into the go-live checklist.
Assessment checklist
- Define products, entities, markets and included channels.
- Map customer, funds, data and prize flows.
- Explain the scoring method and confidence in the inputs.
- Assess inherent exposure before control effectiveness.
- Link every material risk to evidence, an owner and a decision.
- Set review triggers for changes, incidents and new operating data.
Frequently asked questions
Can a pre-launch operator prepare a risk assessment?
Yes. Use documented scenarios and forecasts, clearly label their limitations and set a plan to replace assumptions with operating evidence. Preparation is not proof that controls will work after launch.
Does a low score remove due-diligence requirements?
No. A score is a management tool. Applicable legal requirements and licence conditions remain controlling; the permitted approach must be established for the actual product, entity and markets.
When should the assessment change?
Define a review cycle and event triggers. Product expansion, new markets or payment routes, significant incidents and unreliable control evidence are practical reasons to revisit the relevant sections.
Source history and scope
The FATF Recommendations are international standards implemented through national measures. They do not establish this particular operator’s duties. This guide gives no thresholds, reporting deadlines, guarantee of compliance or claim that WhiteLotto holds a relevant authorisation.
Connect the assessment to platform requirements
Use the risk-and-control matrix to identify necessary data, integrations, access controls and evidence exports. Keep legal applicability and risk acceptance with the responsible operator and appropriately qualified specialists.
Discuss lottery platform requirements