KYC is real, mandatory, and boring. It is also the single most common costume worn by a payout that an operator does not want to make.
What is legitimate
Under anti-money-laundering law, a licensed operator must establish who you are and, above certain thresholds, where your money came from. That means:
- Photo ID
- Proof of address, usually dated within three months
- Proof of ownership of the payment method
- Source of funds at higher thresholds: payslips, bank statements, a deed of sale
These are lawful requests. Refusing them will not get you paid, and an operator that skipped them would be the bigger red flag.
What is not legitimate
The abuse is never in the documents. It is in the timing and the open-endedness.
- Verification demanded only after a win, never at deposit
- The same document requested a third time, each time "unclear"
- New categories of document appearing each time you satisfy the last
- No stated deadline for the operator's own review — your clock runs, theirs does not
- Source-of-funds requests on a $400 withdrawal from a $50 deposit
The tell is simple: an operator that verifies at deposit is running compliance. An operator that verifies only at withdrawal is running a filter.
Protect yourself
- 01Complete KYC before you deposit. Most sites let you. This removes the excuse entirely.
- 02Keep the exact files you sent, and the date you sent them.
- 03Log every request: date, document, the operator's reason.
- 04When the operator has had your documents for longer than its own published SLA, that log is a complete evidential record — take it to the Tribunal.
A verification clause with no deadline on the operator's side is an unfair term, and it costs points on the TrustAudit Index.