Denmark's financial regulator has barred payments firm Inpay A/S from taking on new iGaming clients. Finanstilsynet, the Danish FSA, said a review in March found "serious violations of the Money Laundering Act" in how Inpay handled its gaming customers. For operators the case is a plain reminder: crypto payments for igaming and old-fashioned bank wires answer to the same rules, and when a payment partner fails its checks, the regulator comes for the payments company first.
What happened at Inpay
Inpay is an e-money institution licensed under the Danish Payments Act. It moves money across borders as an alternative to SWIFT wire transfers, and its customers include corporate clients, financial institutions, crypto businesses and online gaming companies. The March inspection looked at its internal anti-money laundering procedures. Finanstilsynet's conclusion: Inpay could not show the required level of customer due diligence on its iGaming book.
The regulator spelled out what that meant in practice. Inpay failed to identify the purpose and intended nature of flagged business relationships. It failed to carry out proper assessments of business customers classed as high risk for money laundering and terrorist financing. Until Inpay can prove the violations are fixed, it is restricted from entering new business agreements with online gaming companies. The firm has reportedly agreed to pause new gaming clients voluntarily while it prepares the documentation.
Why the regulator zeroed in on gaming clients
Finanstilsynet called the violations serious and was blunt about why. The scope, the type of customer, complex ownership structures and activity across many countries were aggravating factors. Then came the detail that matters most: the violations concern the majority of the company's portfolio, because most of Inpay's clients sit in online gaming. Those customers operate in an industry with an increased risk of money laundering, and most are based outside Denmark, often outside the EU. In plain terms, many of them may not hold the gambling licenses that would put them under the same financial protection rules as licensed operators. That is exactly the profile supervisors worry about.
Why operators should care
This is the kind of enforcement operators tend to ignore until it touches their own bank account. Regulators have spent years pushing gambling compliance down the chain. They audit operators, they audit game suppliers, and increasingly they audit the companies that move the money. A payment provider that loses its right to take new gaming clients creates a real problem for every operator that was about to sign with it, and a reputational question for every operator already using it. The logic is the same in every regulated market, Ontario included: the compliance burden lands on whoever holds the relationship, and payment providers are now part of the regulated chain.
For operators mid-launch or about to sign a payments deal, the practical change is simple: payment due diligence now has to cover the provider, not just the player. Five years ago it was normal to pick a gateway on price and speed. The Inpay case is part of a pattern where supervisors treat the payment provider as a compliance gate, and operators inherit the consequences when that gate fails.
What this means for crypto payments for igaming
The crypto angle is where this gets specific. Crypto payments for igaming are usually chosen because they are fast and cheap, and they are often treated by operators as a grey zone where the rules bend. The Inpay case cuts against that reading. Inpay's own customer base included crypto enterprises, and the failures Finanstilsynet found were not about a particular payment rail. They were about basic due diligence: knowing who the customer is, what the relationship is for, and whether that customer is high risk. A crypto casino payment gateway has to answer the same questions, and most supervisors apply the same standards to crypto and fiat alike.
What to check before you sign
So what should an operator check before routing cash flows through a payment partner? Five questions, based on this case rather than any provider's brochure:
- Who regulates the provider? An e-money or payment institution license means a supervisor can inspect the books and act. An unregulated processor has nobody watching.
- Does the AML program cover your segment? Ask how transactions are monitored, how business customers are screened, and whether gaming companies are treated as high risk.
- What happens to high-risk customers? This is where Inpay failed: no proper assessment of customers classed as high risk for money laundering.
- Where is your business registered, and does the provider care? Offshore operators are exactly the segment that turned Inpay's violations into a majority-of-portfolio problem.
- Can you see the remediation? A provider under a regulatory restriction should tell you in writing what it is fixing and when.
None of this is an argument against payment partners. Every licensed operator needs one, and most markets offer a handful of workable rails. What separates a safe provider from a cheap one is whether it can show working AML controls, not the size of the fee. That test applies to a crypto casino payment gateway exactly as it does to a traditional bank-transfer processor. Get the payment layer right and it stops being a risk; it becomes one item in a launch plan that an igaming software solutions partner can manage end to end.
The takeaway
I keep coming back to one line in the Danish statement: the violations concerned the majority of the company's portfolio. That is not a rogue account manager missing a checkbox. It is a business model that quietly depended on gaming clients most supervisors would flag as high risk. The lesson for operators is uncomfortable but simple: if your payment provider's compliance is a mystery to you, you are carrying its risk. The Inpay case is the latest proof that regulators find that risk eventually, and the operator on the receiving end rarely picks the timing. For crypto payments for igaming, the takeaway is identical: the compliance bar is set by the regulator, not by the payment rail you choose.