When Governance Fails – Skiild Insights

When Governance Fails: What Every Casino Can Learn from Recent AML Enforcement Actions Issued by FinCEN

The $3 billion enforcement action against TD Bank sent a clear message to regulated industries across the United States: regulators are not evaluating anti-money laundering (AML) programs solely by reviewing policies, procedures, transaction monitoring systems, or suspicious activity reporting metrics.

They are evaluating something much broader — they are evaluating governance.

In October 2024, TD Bank entered into resolutions with the U.S. Department of Justice, the Financial Crimes Enforcement Network (FinCEN), and other regulators following significant Bank Secrecy Act (BSA) and AML deficiencies. While the size of the penalty captured headlines, the more important lesson was the underlying cause of the failures: regulators determined that leadership failed to ensure the organization maintained an AML program that was appropriately designed, adequately resourced, and capable of addressing the risks associated with the institution’s size and business activities.

For gaming operators, this should be a significant point of reflection.

Gaming operators used to have regulatory frameworks which differed drastically from banks, however, throughout the years — with updates, penalty assessments, and case law — the lines are becoming more blurry and expectations are increasingly similar. Gaming regulators, FinCEN, and law enforcement agencies expect casino operators to demonstrate that compliance is embedded throughout the organization. This expectation runs top-down: from the Board of Directors and executive leadership team to the cage, surveillance, finance, and compliance departments.

Lesson #1: Known Compliance Weaknesses Must Be Addressed

One of the most significant patterns throughout the enforcement action was that the institution had identified deficiencies within its AML program but failed to remediate those issues in a timely and effective manner. Regulators determined that the bank did not invest sufficient resources to address known weaknesses, allowing significant risks to continue. For gaming operators, the parallel is clear.

Every gaming organization receives audit findings, internal review recommendations, quality control observations, regulatory observations or insights, and operational improvement opportunities. The question is not whether weaknesses exist, because every organization will have them. The appropriate question is: what did leadership do after learning about them?

A finding that remains unresolved for months or even years can evolve from an operational issue into a governance issue.

Boards and executive leadership teams need to understand:

  • Which AML risks have been identified;
  • Who owns remediation efforts;
  • Whether corrective actions are appropriately prioritized; and
  • Whether sufficient resources have been dedicated to resolving the issue.

Lesson #2: Growth Cannot Outpace Compliance

Another significant theme from TD Bank was the failure to ensure that compliance capabilities grew alongside the business. Regulators found that the organization expanded its operations while AML resources, systems, and controls failed to keep pace with its risk profile. This resulted in backlogs and outdated programs.

Gaming operators face similar challenges today. Compliance is often seen as a cost center, not a penalty reducer.

The industry continues to evolve, and each innovation creates opportunities — but also new risks.

A compliance program designed for a traditional casino environment may not be sufficient for modern gaming ecosystems. Leadership must continually evaluate whether staffing, technology, training, and governance structures remain appropriate as the business changes.

Lesson #3: Compliance Culture Is Created by Leadership

Perhaps the greatest lesson from TD Bank is the reminder that regulators are examining culture. This has been a long-standing topic in AML enforcement. Organizations cannot demonstrate an effective compliance culture simply by having an AML policy or hiring a compliance officer. Regulators look at whether leadership actions demonstrate that compliance is treated as a business priority. Gaming is no exception.

Between 2015 and 2017, FinCEN assessed more than $115 million in penalties against casinos and card clubs, all pointing to AML deficiencies involving program failures, high-risk customers, KYC failures, insufficient monitoring or investigatory processes, unfiled CTRs and SARs, and more. The lesson was not that these casinos lacked sophisticated or profitable programs to know their customers and reward them properly for their amount of play. The lesson was that revenue generation cannot override risk management and compliance responsibilities.

The Board’s Role in Protecting the Organization

The future of AML compliance in gaming will increasingly involve Board-level oversight.

Boards and executives should be asking:

  • Is our AML program appropriately funded?
  • Are compliance risks incorporated into strategic decisions?
  • Are audit and regulatory findings being resolved promptly?
  • Does management receive meaningful reporting?
  • Are operational departments engaged in identifying and mitigating risk?

The strongest AML programs are not built by compliance departments alone. They are built by organizations where leadership understands that compliance protects the integrity, reputation, and long-term success of the business.

Final Thoughts

Recent penalties, including the action against TD Bank, are not simply enforcement actions. They are lessons in governance and the expectations established by federal regulators.

Gaming operators should view this as a stark and sobering reminder that regulators are looking beyond technical compliance requirements. They are evaluating whether organizations have created the structure, culture, accountability, and leadership commitment necessary to manage financial crime risk effectively.

Every gaming operator should not just be asking, “Do we have an AML Program?” The better question is: “Would our governance structure demonstrate to regulators that we are actively managing the risks we know exist?”


Five Questions Every Board Member Should Be Asking Their Leadership Teams — and, More Importantly, the BSA Officer

1. Do We Understand Our Current AML Risk Profile?

Has leadership received a clear explanation of the organization’s highest-risk areas, including cash activity, VIP programs, sports betting, digital payments, international customers, junket relationships, and emerging gaming products?

An effective risk assessment should not sit on a shelf. It should influence staffing, technology investments, training priorities, and operational decisions.

2. Are We Providing Adequate Resources to Manage Our Risks?

Does the compliance department have the personnel, technology, and support necessary to perform effective monitoring, investigations, reporting, and testing?

A compliance program cannot be evaluated separately from the resources provided to operate it.

3. Are Known Issues Being Resolved Quickly and Effectively?

When internal audit, independent testing, regulators, or compliance personnel identify weaknesses, does leadership have a clear remediation plan?

A known deficiency that remains unresolved becomes more than an operational issue — it becomes a governance issue.

4. Does Compliance Have a Voice in Business Decisions?

Are compliance and risk teams involved early when the organization introduces new products, payment methods, loyalty initiatives, marketing programs, or customer acquisition strategies?

The strongest organizations do not ask compliance to evaluate risk after a decision has already been made. They include compliance as part of the decision-making process.

5. Would Our Program Withstand Regulatory Scrutiny?

If regulators reviewed our AML program tomorrow, could we demonstrate:

  • Effective Board and executive oversight;
  • Appropriate risk-based controls;
  • Adequate staffing and technology;
  • Meaningful training; and
  • A culture that encourages escalation and accountability?

The goal is not simply to pass an examination. The goal is to demonstrate that the organization understands its risks and actively manages them.

Join Us in 2027

San Diego AML Conference

January 25–27, 2027 · Hilton San Diego Airport/Harbor Island AML Essentials + AML for Casinos — three days of practical compliance training built for gaming and hospitality professionals.

Three Day All Access$1,295

Secure Your Spot