By NHI Mgmt Group Editorial TeamBased on SumSub: “Curaçao Sets 2027 Deadline for Full Compliance With New Crypto Gambling Policy” (June 25, 2026)

TL;DR: Curaçao’s Gaming Authority has given B2C crypto gambling licensees until June 2027 to meet new rules covering wallet segregation, blockchain analytics, transaction monitoring, due diligence, and recordkeeping, with earlier action possible where material risks appear, according to SumSub. The policy turns crypto activity into a governance problem that spans payments, AML/CFT, and identity-linked controls rather than a narrow treasury task.


At a glance

What this is: Curaçao has set a phased crypto gambling compliance regime that forces licensed operators to separate wallets, monitor transactions, and apply AML/CFT obligations to crypto activity.

Why it matters: For IAM, PAM, and NHI practitioners, this is a reminder that regulated value flows increasingly depend on identity-linked controls over wallets, counterparties, and service providers rather than finance teams alone.


Context

Curaçao’s new crypto gambling policy turns wallet handling into a governance problem. Operators are no longer being asked only to process cryptocurrency payments; they must prove who controls wallets, how funds move, and whether counterparties create unacceptable risk across the licensed operation.

The policy applies in phases from June 2026 and sets a June 2027 compliance deadline for B2C licensees. That timeline matters because it makes identity, AML/CFT, and recordkeeping controls part of the operating model, with earlier implementation possible where material risks are identified.


Key questions

Q: What breaks when crypto gambling operators do not segregate player, operational, and treasury wallets?

A: Without wallet segregation, operators lose clear provenance over funds, make reconciliation harder, and weaken their ability to show that regulated gambling activity stayed inside licence conditions. The result is not only a compliance gap but also a weaker defence against suspicious flows that move across business purposes.

Q: Why do blockchain analytics and transaction monitoring matter for crypto gambling compliance?

A: They provide the evidence layer for tracing funds, screening counterparties, and supporting source-of-funds checks. In regulated crypto gambling, monitoring is valuable only when it connects to case handling and documented decisions, otherwise it records activity without proving that risk was managed.

Q: What do compliance teams get wrong about wallet screening in regulated crypto operations?

A: A common mistake is treating wallet screening as a one-time onboarding check rather than an ongoing governance control. In practice, counterparties, asset types, and transaction paths can change the risk profile after approval, so screening has to stay tied to monitoring and escalation.

Q: Should operators prioritise wallet segregation over broader AML tooling in crypto gambling?

A: Yes, when the current wallet model mixes player, treasury, and operational flows, segregation is the first control that makes the rest of AML tooling defensible. Monitoring, due diligence, and recordkeeping are much less effective if the underlying wallet structure cannot separate regulated activity cleanly.


Technical breakdown

Wallet segregation as a control boundary

The policy requires player, operational, and treasury wallets to remain separate, which turns wallet structure into a control boundary rather than a convenience choice. When funds from different purposes share the same wallet, it becomes harder to prove provenance, reconcile transactions, or demonstrate that gambling-related activity stayed within licence conditions. Segregation also reduces the chance that a compromised wallet, payment path, or counterparty can contaminate the whole flow. In practice, wallet architecture and governance have to be treated together, because the control is only effective if ownership, purpose, and permitted use are explicit.

Practical implication: Map every wallet to a specific purpose and owner, then block mixed-use patterns that break traceability.

Blockchain analytics and transaction monitoring in compliance operations

The policy requires blockchain analytics and transaction-monitoring capability to trace funds, screen deposit and withdrawal wallets, risk-score transactions, identify high-risk exposure, and support source-of-funds checks. That means monitoring is not just about detecting suspicious activity after the fact; it becomes the evidence layer for whether the operator can explain asset origin, destination, and counterparty risk. For compliance teams, the important shift is that wallet intelligence must connect to due diligence, sanctions exposure, and escalation workflows. Without that linkage, the organisation may know a transaction occurred but still be unable to justify whether it should have been accepted.

Practical implication: Connect chain analytics to AML/CFT case handling so wallet risk scoring drives action, not just reporting.

Counterparty controls for virtual asset service providers and prohibited wallets

The policy prohibits sanctioned wallets, mixers, prohibited crypto assets, personal or UBO-linked wallets, and operators acting as exchanges, payment service providers, or virtual asset service providers. It also requires due diligence on virtual asset service providers and additional assessment before accepting privacy coins, meme coins, or wrapped tokens with unclear origins. This is a governance model for counterparties, not just coins. The operator has to know who is on the other side of the transaction, what role they play, and whether the relationship changes the licence holder’s risk exposure. That makes third-party oversight and wallet provenance inseparable.

Practical implication: Build counterparty screening and third-party due diligence into onboarding before any wallet can transact.


Threat narrative

Attacker objective: The practical objective in this environment is to move value through an operator with insufficient wallet and counterparty scrutiny, reducing traceability and increasing the chance that illicit funds or prohibited assets pass through undetected.

  1. Entry occurs when a gambling operator accepts crypto activity through wallets, tokens, or counterparties that have not been adequately screened for provenance or sanctions exposure.
  2. Escalation occurs when player, operational, and treasury flows are not separated, making it harder to trace source of funds and isolate suspicious activity.
  3. Impact is regulatory and operational, because weak traceability, prohibited counterparties, or poor recordkeeping can put the licence holder out of compliance and obscure AML/CFT issues.
  • Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Wallet segregation is now a licensing control, not an accounting preference: Curaçao’s policy treats separate player, operational, and treasury wallets as a requirement for proving control over regulated value flows. That matters because mixed-purpose wallets blur custody, provenance, and accountability in ways that compliance teams cannot easily unwind after the fact. The governance lesson is that wallet design now sits inside the control framework, not outside it. Practitioners should treat segregation as part of operating licence evidence, not back-office hygiene.

Crypto gambling compliance has become identity-linked governance: The policy links AML/CFT obligations to wallet screening, source-of-funds checks, due diligence, and staff training, which makes identity controls central to the compliance model. Operators have to know which wallet belongs to which purpose, which counterparties are acceptable, and which assets introduce elevated risk. That shifts the problem from transaction processing to governed identity and entitlement over value flow. The implication is that access, ownership, and approval chains now matter as much as monitoring output.

Counterparty risk is the real boundary condition: The prohibition on sanctioned wallets, mixers, UBO-linked wallets, and operator roles as exchanges or payment providers shows that compliance now depends on the nature of the other party in the flow. This is a governance model for trusted participation, not just suspicious transaction review. Where the counterparty cannot be explained, the control has already degraded. Practitioners should read this as a signal that provenance, role clarity, and relationship vetting are becoming first-class controls in regulated crypto.

Transaction monitoring is only useful when it is operationally actionable: The policy’s emphasis on risk scoring, tracing, reconciliation, and audit-ready records shows that regulators want evidence that can be defended, not analytics in isolation. If blockchain analytics does not feed case management, exception handling, and record retention, the control remains observational rather than governing. For identity and compliance teams, the practical benchmark is whether a suspicious wallet can be traced through to an accountable decision. That is where governance either holds or fails.

What this signals

Wallet provenance is becoming a governance test: Regulated operators will need to show not only that a wallet moved funds, but that the wallet’s purpose, owner, and counterparties were known and approved. That is a useful signal for any programme where value flows intersect with identity, sanctions exposure, or third-party risk.

The practical shift is from monitoring isolated transactions to governing the relationships behind them. Once wallet provenance, due diligence, and recordkeeping are linked, compliance teams can answer the regulator’s real question: who was allowed to move what, and why was that decision defensible?


For practitioners

  • Separate wallet roles by design Assign player, operational, and treasury wallets to distinct purposes and owners, then prevent mixed-use patterns that break provenance and reconciliation.
  • Screen counterparties before activation Require due diligence on virtual asset service providers, sanctioned wallets, mixers, and personal or UBO-linked wallets before any transaction is permitted.
  • Operationalise chain analytics Link blockchain analytics to transaction monitoring, source-of-funds checks, case handling, and escalation so risk scores drive documented decisions.
  • Prepare audit-ready evidence packs Retain wallet mapping, reconciliation outputs, policy approvals, and exception records so compliance can be demonstrated within the regulator’s timeline.

Key takeaways

  • Curaçao’s policy makes crypto gambling compliance depend on identity-linked controls, not just payment processing.
  • Wallet segregation, transaction monitoring, and counterparty due diligence are now part of the regulated operating model for B2C licensees.
  • Operators that cannot prove provenance and accountability across wallet flows will struggle to meet the new requirements within the regulator’s timeline.

Key terms

  • Wallet Segregation: Wallet segregation is the practice of keeping different crypto wallets separate by business purpose, ownership, and approval path. In regulated environments, it reduces ambiguity in who can move funds, improves traceability, and makes reconciliation and audit evidence more reliable when different transaction types are handled by different operational teams.
  • Transaction Monitoring: Transaction monitoring is the process of detecting, reviewing, and escalating activity that may indicate fraud, money laundering, or other financial crime. It combines rules, investigation workflows, and documentation so organisations can explain why a case was flagged and what was done next.
  • Source of Funds: Source of funds is the evidence used to show where the money in a transaction or relationship originated. In AML governance, it helps distinguish legitimate value from proceeds that may be tied to laundering, fraud, sanctions evasion, or other illicit activity.
  • Virtual Asset Service Provider: A virtual asset service provider is a business that offers services involving crypto assets, such as exchange, transfer, custody, or related intermediated activity. In practice, VASP classification matters because it determines who must participate in regulated information exchange and which controls govern transfer approval.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org