Shared accounts: the compliance blind spot iGaming keeps missing
KYC confirms who opened the account. It usually does not confirm who is actually playing on it later. That gap is where shared accounts live, and for PSPs, acquirers, and operators in iGaming, it creates a very practical compliance problem: age checks, self-exclusion controls, and fraud monitoring can all be bypassed after onboarding.
- Shared accounts are not the same thing as identity theft or synthetic identity. In identity theft, someone uses another person’s data without consent. In synthetic identity, the “customer” is partly fabricated. In a shared account, the identity is real and verified, but the credentials are later used by someone else, sometimes with the original holder’s knowledge and sometimes not.
- The thing is, most compliance stacks treat approval as a one-time event. Once the account passes onboarding, the system often assumes every later session belongs to the same person. There is usually no built-in mechanism that keeps checking whether the player behind the login is still the same verified user.
- For iGaming, the most sensitive risk is minors using an adult’s verified account, often a parent’s or relative’s. That bypasses the age verification completed at signup, because the platform never re-checks who is actually sitting behind the session.
- Self-excluded users also use shared accounts to get around their own blocks, whether the exclusion was triggered on the same operator or on competitors. On paper the account is compliant; in practice the excluded player is back through a different login.
- There is also a commercial side to the loophole: verified accounts can be rented or resold and then used for money laundering, bonus abuse through multi-accounting, or spreading risk across activities a single identity would not support on its own.
The gap opens because traditional verification is designed to confirm onboarding, not to keep re-confirming identity throughout the customer journey. For high-risk operators, that means session-level signals such as simultaneous logins from different devices, abrupt geolocation changes, or gameplay that does not fit the account history matter just as much as the original KYC file.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!