Hungary Tightens AML Rules for Gambling Operators: Compliance Checklist

Hungary has expanded the anti-money-laundering rules that apply to casinos, card rooms, betting businesses, remote-gambling operators and online casinos. The changes require more structured internal risk assessments, a broader country-risk analysis, specific high-risk triggers and better-documented enhanced due diligence and management approvals.

The amendments were made by Decree 8/2026 (VIII. 17.) SZTFH, published in the Hungarian Gazette on 17 August 2026. The gambling AML provisions took effect on 20 August 2026, the third day after publication. They amend Decree 4/2021 (X. 21.) SZTFH, which contains sector-specific implementation rules under Hungary’s AML framework.

This article explains what changed and turns the new text into an implementation checklist. It is general information only. Operators should test their policies and systems against the current Hungarian text and obtain legal advice for their own licence, products, channels and risk profile.

Who is in scope?

The amended sectoral decree applies to operators of:

  • gaming casinos;
  • card rooms;
  • betting that is not classified as remote gambling;
  • remote gambling; and
  • online casino games.

The amendments do not replace the wider duties in Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing. They add and refine requirements for this regulated gambling sector, including how the operator’s internal risk assessment and enhanced procedures should work.

What changed at a glance

Area Practical change from 20 August 2026
Country risk “Country of origin” now covers citizenship, residence and place of stay of the customer or beneficial owner, plus certain significant links to a high-risk third country
Internal risk assessment Operators must assess seven specified risk groups and support the assessment with two calendar years of operating data
Risk methodology The assessment must identify relevant typologies, score risk groups, determine the level for each licensed game, record controls and set the next review date
Automatic high-risk trigger A customer is high risk when a single transaction uses at least HUF 4 million in cash or virtual currency, or when 365-day deposits exceed the operator’s documented threshold
Cross-product consistency An operator with several covered licences must apply the same – or highest – risk level to the same player across all covered operations and propagate a change within two days
Enhanced monitoring Enhanced procedures apply to the specified high-risk triggers and repeated requests for payment to another person
Source of funds Internal rules must set documented thresholds for requesting source-of-funds evidence and define the response to inconsistencies or refusal
Senior approval Certain third-party payouts and relationships or transactions involving a high-risk factor require approval by the designated responsible manager, with an auditable record

1. Expand the meaning of country of origin

The new definition is wider than a simple nationality field. For AML purposes, “country of origin” includes the country or countries of the customer’s or beneficial owner’s:

  • citizenship;
  • residence; and
  • place of stay.

It also includes a high-risk third country with strategic deficiencies where, following a risk-sensitive assessment, the operator can identify a connection to the customer or beneficial owner that is significant from a money-laundering or terrorist-financing perspective.

Compliance action

Review customer and beneficial-owner data fields. A single nationality value may no longer be enough to support the required geographic-risk assessment. The operating model should be able to capture multiple relevant countries, the basis of each link, the source used to verify it and the resulting risk decision.

The system should not automatically treat every remote or historic connection as equally important. The decree uses a risk-sensitive test for the additional high-risk-country link. The operator should document why a connection is material, who made the decision and which evidence supported it.

2. Rebuild the internal risk assessment around seven groups

The amended rules list seven minimum risk groups that must be considered:

  1. The operator’s own characteristics, including size, staffing levels and adequacy, ownership structure and relevant group or other connections.
  2. Products and services, including game mechanics, winning probability, payout ratio and the extent to which game outcomes can be influenced.
  3. Business relationships and occasional transactions, especially customer identification and the ability to link financial movements to a customer.
  4. Distribution and service channels, including online or offline delivery, type and number of sales points, intermediaries and distribution partners.
  5. Customer traffic and customer characteristics, including legal-person status, politically exposed person status, low- or high-risk country classification, EU or UN financial sanctions exposure and other reasons for high-risk classification.
  6. Geographic exposure, including the location of sales points, gambling servers and online-casino studios, plus cross-border services and payment mechanisms.
  7. Cash exposure, including the volume and proportion of cash and the available deposit and withdrawal methods.

This is not satisfied by a generic matrix with “customer, product, geography” as headings. The assessment should show how the listed features affect the operator’s actual games, channels and financial flows.

Use operating data, not only narrative

The assessment must also be supported by data for the previous two calendar years. The decree specifies at least:

  • total headcount;
  • the number of staff performing AML tasks;
  • annual customer and visitor counts broken down by the customer-risk group, including new players and, for online gambling, players by game type;
  • the number of players on record at 31 December;
  • average values per visitor or player, including monthly average stakes and average net gaming revenue; and
  • cash deposits and payouts, together with cash’s proportion relative to other payment methods.

Compliance action

Create a controlled data pack for the annual risk assessment. Reconcile it to finance, player-account and customer-risk systems. Define owners for every field and preserve the extraction date, query logic and approval trail. If a required metric is not currently available, record the gap and implement a reliable capture method rather than estimating silently.

3. Make the risk methodology explicit

The revised framework requires the internal assessment to identify:

  • relevant money-laundering and terrorist-financing methods, patterns and techniques for the gambling service;
  • risk factors and supporting information for each risk group;
  • a low, average or high assessment for each risk group;
  • the risk level of each licensed game based on those assessments;
  • the mitigating measures used for each group; and
  • the planned review date.

This structure should be visible in the approved document. A useful implementation is a traceable chain from evidence to inherent risk, controls, residual risk and review timing for every licensed game.

Compliance action

Map each licensed activity to its products, channels, payment methods and customer segments. Avoid copying one risk score across casino, card-room and remote products without evidence. Where a product uses agents, cross-border payments, virtual currency or significant cash, state how those characteristics change monitoring and customer-due-diligence controls.

4. Configure the new high-risk triggers

The amended decree requires a customer to be treated as high risk in either of two cases:

  1. the customer uses cash or virtual currency with a value of HUF 4 million or more in a single transaction; or
  2. during a 365-day period, the customer deposits more to the player balance than the threshold set in the operator’s internal risk assessment.

The operator may set a lower threshold than HUF 4 million on a risk-sensitive basis. The 365-day player-balance threshold is not a universal number supplied by the decree: the operator must set and justify it. To support that threshold, the internal assessment must record how many players exceeded it during the previous calendar year and what proportion they represented of the players active during that year.

Compliance action

Test whether transaction monitoring can:

  • identify cash and virtual-currency use at or above HUF 4 million in one transaction;
  • aggregate deposits to the same player balance over a rolling 365-day window;
  • apply any lower internal trigger;
  • distinguish a regulatory high-risk classification from an alert awaiting review; and
  • retain the evidence supporting the classification and subsequent actions.

Do not divide a single economic event into smaller technical records in a way that prevents the control from recognising the relevant transaction. Review linked and attempted transactions under the wider AML framework as well.

5. Align the same player across all covered operations

Where an operator has more than one licence for gambling activity covered by the AML Act, the same player must have the same risk level across every casino, card room, online casino and remote-gambling operation run by that operator. If systems produce different levels, the highest level applies.

A change in the player’s risk level must be transferred to every affected customer register within two days.

Compliance action

Establish a reliable master customer identifier. Define how duplicate accounts, name variations and shared identity documents are resolved. Test the update process across retail and online systems and retain evidence that a change was propagated within the required period.

This rule applies across the same operator’s covered operations. Group-wide sharing between separate legal entities still requires a distinct legal, data-protection and governance analysis.

6. Update enhanced monitoring and source-of-funds procedures

Enhanced ongoing monitoring is required, in addition to the cases already set by the AML Act, where the customer:

  • regularly asks the operator to pay another person – meaning at least three different occasions within one year; or
  • is high risk because of the HUF 4 million cash or virtual-currency trigger or the 365-day player-balance threshold.

During the enhanced procedure, the operator obtains additional information about the customer, source of funds and the purpose of the planned or completed transaction. Information may come from public databases and other available sources and, on a risk-sensitive basis, from customer declarations. The information obtained must be checked.

For customers captured by the new threshold-based high-risk rules, the operator must obtain a source-of-funds declaration and verify the information. Documentary source-of-funds proof is required where the declared source is inconsistent with the size of the customer’s transactions or where information obtained by the operator contradicts the declaration.

The internal policy must also set risk-based thresholds at which documentary source-of-funds proof is requested for:

  • a single transaction; and
  • deposits to a player balance during a 365-day period.

The basis for those thresholds must be supported by the prior year’s numbers and proportions of players or visitors crossing them. The policy must state what the operator will do when documents do not fit the transaction size or the customer refuses to provide a declaration or documentary proof.

Compliance action

Prepare a source-of-funds playbook that defines acceptable evidence by source type, such as salary, business income, investment proceeds, inheritance or asset sale. It should specify escalation rules, transaction restrictions, reporting consideration and exit decisions. “Document received” is not the same as “source reasonably established”; reviewers need criteria for plausibility, authenticity, ownership and consistency.

7. Put the correct cases before the designated responsible manager

Beyond approvals required by the AML Act, the amended decree requires approval by the designated responsible manager for:

  • a payout to someone other than the player who placed the bet, including a payout of a deposit to a person authorised by that player; and
  • establishing a business relationship or executing an occasional transaction where a high-risk factor emerges during customer-due-diligence measures.

Every decision must be documented in a way that is retrievable and auditable.

Compliance action

Configure a hard workflow stop where approval is mandatory. The approval record should identify the customer, transaction, high-risk factor, evidence reviewed, decision, conditions, approving manager and timestamp. Avoid approvals in email or chat that cannot be linked reliably to the customer and transaction record.

8. Check related timing and policy references

The decree also replaces a reference to “48 hours” with “two working days” in one provision concerning the sectoral screening-system rules. Operators should search policies, procedures, training and system specifications for the old wording and ensure that the correct deadline is used in the correct context.

This is a good reminder that translating legal time limits into system timers requires care. “Two days” and “two working days” are not interchangeable.

30-day implementation checklist

Governance

  • [ ] Confirm which licences, venues, websites and legal entities are in scope.
  • [ ] Assign an accountable owner for the Decree 8/2026 remediation programme.
  • [ ] Obtain legal confirmation of the effective provisions and any filing or approval requirement for amended internal rules.
  • [ ] Record management approval of the remediation plan and residual gaps.

Risk assessment

  • [ ] Add all seven mandatory risk groups.
  • [ ] Score each group as low, average or high using documented evidence.
  • [ ] Determine a risk level for each licensed game.
  • [ ] Record relevant typologies, controls and next review date.
  • [ ] Build and reconcile the required two-calendar-year data pack.

Customer and geographic data

  • [ ] Capture citizenship, residence and place of stay for customers and beneficial owners where applicable.
  • [ ] Create a documented process for significant links to high-risk third countries.
  • [ ] Review sanctions and politically exposed person inputs within the customer-risk model.

Monitoring and source of funds

  • [ ] Implement the HUF 4 million single-transaction cash and virtual-currency trigger.
  • [ ] Define and justify the rolling 365-day player-balance deposit threshold.
  • [ ] Decide whether a lower single-transaction threshold is required by the operator’s risk profile.
  • [ ] Set documentary source-of-funds thresholds and evidence standards.
  • [ ] Define actions for inconsistent evidence, refusal or non-response.
  • [ ] Test repeated third-party payout detection over a one-year period.

Systems and approvals

  • [ ] Apply the highest player risk level across all covered operations of the operator.
  • [ ] Test propagation of a risk-level change within two days.
  • [ ] Enforce designated-manager approval for the specified third-party payouts and high-risk cases.
  • [ ] Make the decision record searchable, timestamped and auditable.
  • [ ] Update the relevant timer from 48 hours to two working days where the amended provision applies.

Training and assurance

  • [ ] Train customer-facing, payments, fraud, AML and responsible managers on the new triggers.
  • [ ] Run test cases across cash, virtual currency, rolling deposits and third-party payouts.
  • [ ] Sample source-of-funds files for consistency and quality.
  • [ ] Have internal audit or compliance assurance verify implementation and evidence retention.

What management should ask now

Management should be able to answer five questions clearly:

  1. Can we identify one customer across every covered gambling operation we run?
  2. Can our systems detect both the single-transaction and rolling 365-day triggers?
  3. Can we explain and reproduce every threshold in our internal risk assessment?
  4. Do source-of-funds reviewers assess plausibility, not just document presence?
  5. Can we retrieve a complete approval and decision trail for any high-risk case?

If any answer is “not yet”, the gap should be assigned an owner, deadline and interim control. A policy update without data, workflow and testing changes is unlikely to be enough.

Westbridge Consulting can support businesses with compliance-gap assessment, implementation planning and coordination with qualified Hungarian legal advisers. Contact Westbridge Consulting to discuss the appropriate scope.

Official sources

Last reviewed: 14 September 2026. This article is for general information and does not constitute legal or regulatory advice.