bet365 CasinoLicensed by the UK Gambling Commission- Wager-free winnings
- Apple / Google Pay
Financial vulnerability checks start at £500 of net deposits in 30 days from 30 August 2024 and £150 from 28 February 2025. What is looked at, and what you are not asked to hand over.
A licensed gambling operator's request for payslips, bank statements, or other financial evidence is not a random invasion of privacy. It is a compliance action required under the Gambling Commission's customer-interaction and financial-vulnerability framework. Since 31 October 2023, remote operators have been legally bound to interact with customers in ways that minimise gambling-related harm, and this includes identifying vulnerability indicators and acting on them promptly.
bet365 CasinoLicensed by the UK Gambling Commission
Betway CasinoLicensed by the UK Gambling Commission
Spin CasinoLicensed by the UK Gambling Commission
10bet CasinoLicensed by the UK Gambling CommissionThe Gambling Commission's Social Responsibility Code provision 3.4.3, which governs customer interaction for remote licensees, imposes a clear obligation: they must interact with customers in a way that reduces the risk of gambling harms, identify those at risk or already experiencing harm, and understand whether their interventions actually work. This is not optional guidance. Operators must build systems that spot vulnerability signals and respond with appropriate, timely action.
The Commission's customer-interaction guidance for remote gambling licensees, which took effect on 31 October 2023, requires operators to consider factors that might make a customer more vulnerable to gambling harms and to establish processes that trigger when those indicators appear. The regulator emphasises that these systems must be effective—not merely present. An operator that spots warning signs but fails to act promptly would be in breach of its licence conditions.
What this means in practice is that the decision to request financial documentation sits with the operator, not with a player's bank. The Commission has not published any rule suggesting that banks initiate these requests. The operator assesses behaviour patterns, deposit velocity, session characteristics, and other markers against its own compliance framework, then decides what level of intervention is warranted.
The regulator has established specific thresholds for financial vulnerability checks, and these have shifted significantly in recent months. From 30 August 2024, the higher threshold was set at £500 in net deposits over a rolling 30-day period. This was lowered to £150 net deposits per 30-day rolling period from 28 February 2025. These are Commission-mandated figures, not operator discretion.
The Commission states that these checks are designed to identify significant financial vulnerability early enough to support customers who are "significantly or particularly financially vulnerable." Importantly, the checks rely on publicly available data. They do not involve credit reference bureau data. This distinction matters because it shapes what information an operator can access without customer consent, and what gaps might prompt a direct request for documentation.
The Commission's final decision on financial vulnerability checks was that they would focus solely on publicly available information and would not require gambling businesses to consider personal details such as postcode or job title. This limits the automated data available to operators and helps explain why a payslip request sometimes follows: when public data is insufficient to assess vulnerability, operators may seek direct evidence of financial circumstances.
The Commission itself has warned that describing these checks as "affordability" assessments is often inaccurate. Its pilot of frictionless financial risk assessments—sometimes labelled affordability checks in industry discussion—uses credit reference data for a different purpose entirely. The pilot tests whether data sharing through credit reference agencies could help support high-spending customers who are financially vulnerable, and will inform a final decision on whether to introduce such assessments more broadly.
This creates confusion that affects customers directly. A player who receives a document request may assume it relates to this credit-reference pilot, when in fact it stems from the established vulnerability framework. The Commission has been explicit: the financial vulnerability checks now in force do not use credit bureau data. Any request for payslips or bank statements is coming from the operator's own compliance obligations under the Social Responsibility Code, not from a credit reference check.
The mislabelling matters because it shapes customer expectations. Someone who believes their operator has accessed credit data may not understand why additional documentation is needed. The reality is simpler and more intrusive in some ways: the operator has spotted behavioural or deposit patterns that meet its vulnerability thresholds, and public data alone cannot resolve the concern.
The Gambling Commission has not published direct guidance distinguishing financial vulnerability checks from anti-money-laundering identity and source-of-funds checks in the specific terms needed for a clean separation. What is clear from the regulator's materials is that vulnerability checks are rooted in the Social Responsibility Code's harm-minimisation duty, not in the Prevention of Money Laundering and Terrorist Financing regulations.
AML checks typically verify identity and establish that funds come from legitimate sources. Financial vulnerability checks assess whether a customer can afford their gambling without harm, regardless of whether the money itself is clean. An operator might request documents for either purpose, or both. Without clear Commission guidance mapping the distinction, customers cannot always tell which framework has triggered a request. What the regulatory materials do confirm is that the vulnerability framework stands on its own statutory basis, with its own thresholds and objectives.
Once an operator identifies vulnerability indicators, it must take appropriate and timely action. The Commission's guidance does not prescribe a single response ladder—whether on-screen message, deposit limit prompt, information request, or account restriction—but it does require that the action be proportionate and timely. Operators build their own graduated response frameworks within these parameters.
A customer who declines to provide requested financial evidence faces consequences determined by that operator's compliance framework. The Commission has not published a standardised customer-choice script setting out the precise options: comply, accept a mandatory limit, or withdraw and close. What the licence conditions do require is that the operator act on identified vulnerability. Refusal to provide information that would resolve a vulnerability concern will typically lead to restrictions—deposit limits, account suspension, or closure—because the operator cannot satisfy its regulatory duty to protect that customer from harm.
The Commission's framework aims to identify financial vulnerability early and support affected customers. That support, however, is not optional for either party. The operator must intervene; the customer must engage or face constrained access. The payslip request is where that regulatory logic meets individual circumstance.
Read next: Safer gambling for the rest of this section, or our review of Betway to see how these rules read on one site.
Licences are read off the Gambling Commission public register; bonus terms, payment lists and withdrawal rules come from the operator’s own pages. We do not hold accounts with the operators we write about, so nothing here is presented as a personal play session. Updated .