A sportsbook, an online casino, and a prediction market all hold the same thing a bank holds: verified identity, payment instruments, transaction history, and a geolocation trail on every customer. Under US law that makes a betting operator a financial institution, a casino and money services business under the Bank Secrecy Act. Under UK, EU, and Australian frameworks, it makes the same operator an obliged entity. The law decided this a few years ago. Most operators' law enforcement request-response function still runs like nobody told it.
Banks had a century to build the compliance departments, the case law, and the muscle memory for answering a subpoena. Betting operators got five years, and the volume arrived faster than the infrastructure did. This page covers what actually shows up in a betting operator's inbox, how the strongest programs verify and produce against it, and what a regulator actually checks. For the full manuscript, see the gated handbook this page is drawn from. For the general mechanics of the function, start with law enforcement data request management.
Revenue found a ceiling. Request volume has not. Everything below is about the distance between those two lines.
Legal process follows the money. No betting operator publishes its request numbers, but the account-based money businesses that do publish show the direction: Kraken reported 4,923 government requests in 2023 and 6,826 in 2024, up 38.6 percent in one year, and Coinbase has fielded over ten thousand a year since 2022. Casinos and card clubs filed roughly 77,000 suspicious activity reports in fiscal 2025. That's the ordinary consequence of a regulated market that expanded from a handful of US states to 39 plus DC, alongside growing licensed footprints in the UK, Europe, and Australia.
The volume often lands on one person. Across account-based money businesses, the entire law enforcement response function is frequently a single staffer, and the intake address is their own inbox because that's where the first subpoena happened to arrive. Where that desk sits varies by company: legal at some operators, compliance or financial crime at others. It works until that person takes a vacation. Subpoenas don't.
This vertical splits into two different jobs, and which one you're doing changes almost everything about how you should build the function.
A US-licensed operator's inbox is dominated by compulsory process: subpoenas, search warrants, and grand jury demands, with a court and a clock behind each one. The job there is throughput against deadlines.
At an internationally licensed group, a large share of volume arrives with no legal compulsion at all: a foreign police force asking without citing any authority, a financial intelligence unit fishing, an agency requesting data it has no power to demand from the entity it contacted. The job there is judgment, because a voluntary disclosure made to the wrong requester is liability to your own customer, not to the requester who asked.
Know which business you're in before you design your intake, your staffing, or your policy. A due-date policy built for subpoenas doesn't help an MLRO deciding whether to comply with a request that carries no legal force behind it.
A law-school list of subpoena, warrant, and court order won't prepare you for what actually lands. The real mix, measured across operators: emergency disclosure requests, in this vertical often geolocation-driven, a missing person or a fugitive who just placed a bet from somewhere, and emergencies are exactly what forgers imitate. Keep-open requests, unique to account-based industries: law enforcement asks you to leave an account live and say nothing to the customer while an investigation runs, which needs a written policy, a review cadence, and a record. Preservation demands: hold everything, produce nothing yet, typically 90 days and renewable. FinCEN 314(a) and 314(b) inquiries, because as a financial institution you're on those distribution lists whether or not your team was set up to receive them. And Canadian production orders, which start arriving the moment an operator serves Ontario.
This is an AML vertical first, and the request types reflect that. FinCEN has published sports-betting-specific laundering typologies, and the crimes that generate legal process against betting operators are the ones the AML program already watches for: laundering, fraud, identity theft, account takeover, proceeds of crime.
Forged legal process is cheap, good, and documented at the federal level. In November 2024 the FBI warned that criminals were using compromised US and foreign government email accounts to send fraudulent emergency data requests to US companies. The sharper threat doesn't forge anything at all: a real account on a real government or police domain, sold by country and agency. The document checks out. The domain checks out. The person behind it is not who they claim to be.
This vertical is a specific target because the data is worth the effort: verified identity, Social Security number, bank accounts, home address, device data, and a complete financial-behavioral history sit in a single production. One fake subpoena returns a full doxxing kit. Manual verification fails against this threat because calling the number printed on the subpoena means verifying the forger with the forger, and a compromised .gov domain passes every manual check you can run against it.
Verifying alone can't close that gap. The stronger position is a network where verification already happened before the requester ever contacts you: on Kodex, 15,000+ government agencies and 140,000+ verified investigators across 180+ countries, verified before your first request from them arrives. Identity gets established once, continuously, across every company a requester touches. For the mechanics of checking a request yourself, see how to verify a law enforcement request, and for the forged-EDR threat specifically, see fraudulent emergency data requests.
Verification answers whether the requester is real. Production answers a separate question: does this paper actually compel this data, from this entity? What legal process asks for follows from what the business holds: identity and KYC records, payment and transaction data, wagering and session activity, and customer communications. Kodex's recommendation is to define a small set of standard production packages around your own data model before the requests arrive, so most production decisions reduce to which package and which date range.
Push back on fishing expeditions. "Everything on this customer" isn't a request. The overbroad ask is usually a first offer, and a stated scope policy gets tested far less often than operators fear: send it back and ask for a proportionate request. And match production to the entity that was actually served: the Spanish request gets the Spanish entity's data, never the group's. For requests carrying no legal compulsion, the safest default is no production at all unless a written policy says otherwise, because the liability from an unforced voluntary disclosure lands on you, not on the agency that asked.
Map your entities before the requests arrive, not while one is sitting in your queue. Groups that grew by acquisition can operate dozens of brands, and process routinely arrives addressed to the public parent when the license-holding entity is someone else entirely. Decide which door each entity answers, and route by entity from intake. A US operator's defensible service perimeter is usually the US and Canada, in writing; a licensed international group's perimeter is its licensing map.
On speed: subpoenas arrive with return dates chosen by whoever drafted them, and the default in an undesigned function is whatever the paper says. Mature operators set their own due-date policy and hold it, and the right length is decided by your worst day, because several subpoenas can land at once. Requesting agencies accept a stated, consistent deadline far more readily than operators expect. What burns trust is variance, not length.
State gaming commission AML examinations have moved from asking whether a program exists to testing whether it works: examiners sample case files and read for a coherent, timestamped story from intake to resolution. Programs that already keep this record as a byproduct of doing the work answer that examiner in an afternoon. The broader picture points the same direction everywhere: FinCEN's effectiveness framework is moving from "have a program" to "prove it works," the UK Gambling Commission's enforcement ledger keeps growing, AUSTRAC has multiple major operators in or exiting enforcement simultaneously, and Nevada's Reg 5 amendments put AML responsibility on a named, personally licensed individual. Separately, any vendor touching this workflow at a US operator may need state gaming-vendor licensure, New Jersey and Pennsylvania in particular, which is worth confirming before evaluating a tool.
One regulation regularly gets cited to this industry that likely doesn't apply: the EU's e-Evidence Regulation, with its 8-hour emergency clocks. Gambling sits inside that regulation's financial-services carve-out for its core service, so the honest read is that it almost certainly doesn't reach a betting operator's core business, worth confirming with counsel if an operator also runs adjacent messaging or community features.
Programs in this vertical fall along a common line. At the early end, the intake address is a person, the tracker is a spreadsheet, and verification means a Google search. In the middle, there's a shared alias, written procedures, and a fixed default deadline, which withstands routine volume but not much fraud. The strongest programs combine verified intake, network-based requester verification, self-set SLAs that hold for months, entity-aware production, and continuity that survives someone's vacation. Most operators sit earlier on that line than they'd guess, and moving up it doesn't require rebuilding the function from scratch.
Kodex is the network where legal requests get handled the way they should: every requester verified before a human reads the request, every request structured and routed to the right entity, every response produced and delivered with a complete audit trail.
Yes, and the legal basis differs by geography. In the US, licensed operators are casinos and money services businesses under the Bank Secrecy Act, which brings SAR filing obligations and standing distribution lists like FinCEN 314(a). In the UK, EU, and Australia, licensed operators are obliged entities under their respective AML frameworks. Compulsory legal process, like a subpoena or warrant, carries its own separate response deadline set by the court or agency that issued it.
A compulsory request, a subpoena, warrant, or grand jury demand, carries legal force: a court or statute backs it, and there's a deadline. A voluntary request has no such backing; an agency is asking, not compelling. At internationally licensed groups, a meaningful share of incoming volume falls into this second category, and producing data against one of these requests when it turns out to be unauthorized creates liability to the customer whose data was disclosed, not to the requester who asked for it.
Almost certainly not for the core betting or gaming service. The regulation carves out financial services, and gambling operators sit inside that carve-out for their core product. It's worth confirming with counsel if an operator also runs adjacent messaging or community features that fall outside the core service.
Inspecting the document and calling a phone number won't catch a compromised government email account, since the domain and the document both check out. The more reliable path is verifying requester identity against a network where agencies and investigators are already known before they first contact you, and where requester behavior is watched across every company on the network. See how to verify a law enforcement request for the full checklist.
Fast enough to survive your worst week, not just your average one. Set a deadline you can hold on a day when several subpoenas land at once, state it consistently to requesting agencies, and never miss it. The number matters less than picking one deliberately and holding it; what burns trust is variance, not length.
We use cookies to keep the site running, understand how it's used, and measure our marketing. You choose what to allow — read more in our Privacy Policy.