What the rule does
Regulation GG, 12 CFR Part 233, implements the Unlawful Internet Gambling Enforcement Act’s payment-system requirements. It requires covered participants to maintain reasonably designed written policies and procedures to identify and block, or otherwise prevent or prohibit, restricted transactions. It does not itself make every internet gambling transaction unlawful. The underlying legal activity and payment role matter. [1, 2]
The Federal Reserve’s compliance guide is dated March 1, 2017; it is historical explanatory material, checked alongside the rule’s current published text on September 29, 2026. Do not confuse a longstanding rule with a new restriction.
Coverage follows the rail and the participant
The designated systems include ACH, cards, checks, money transmission and wires, with significant exemptions for particular participants. For example, the guide identifies the beneficiary’s bank for wires and distinguishes ACH debit origination from ACH credit receipt. A bank should map its actual role rather than assuming that every side of every transfer has identical duties. [1]
Analysis: build a product-to-rail inventory before writing detection logic. Merchant acquisition, a consumer card portfolio and commercial treasury services expose different information at different times. A control requiring merchant identity is ineffective where the operational message does not reliably contain it.
Commercial-customer diligence
Section 233.6 provides non-exclusive examples. Its commercial-customer approach scales diligence to risk and includes documentation when a customer operates an internet gambling business, such as legal authority and relevant system certification. It also addresses notification that restricted transactions are prohibited. These examples are not an invitation to substitute a generic customer certification for all risk assessment. [2]
The rule’s role-specific examples also address actual knowledge of restricted activity. Recommended practice is to log the evidence received, the affected relationship, the analysis and the response. A credible escalation should not disappear into an annual review queue simply because account opening was previously approved.
Design a control that reaches the transaction
Analytical control map:
Scroll horizontally to see all columns.
| Stage | Question | Evidence |
|---|---|---|
| Onboarding | What activity and jurisdictions are involved? | Business description, authority and documented assessment |
| Processing | Can the relevant payment be identified? | Rail-specific fields, coding and exception tests |
| Change | Has the business or authority changed? | Customer notification and monitoring evidence |
| Escalation | Who can stop restricted flows? | Decision rights, action log and review of customer impact |
Worked example: the wrong block
Hypothetical: a processor serves a lawful merchant in one jurisdiction but that merchant adds a new online offering elsewhere. A blanket block on the merchant’s entire industry may be overbroad; continuing to rely on the original license may be underinclusive. Investigate the new activity, location controls and payment path, then decide which services can continue within the actual legal scope.
A second failure arises when a card control is copied to ACH using a field that ACH messages do not consistently supply. The policy appears comprehensive while the production rule rarely fires. Test against representative transactions and deliberately malformed or missing identifiers, recording as well as missed restricted activity.
Implications and limits
Analysis: compliance cost comes from understanding the customer and the payment chain, maintaining meaningful data, and resolving exceptions. Automated blocking can reduce exposure, but weak mapping can deny legitimate services without addressing the higher-risk channel. Performance should be assessed by the quality of decisions and evidence, not alert volume alone.
Regulation GG is one layer; sanctions, AML, consumer protection, state gambling law and network contracts may introduce separate requirements. Reassess after a rail, business model or legal-authority change. This article does not determine whether a specific merchant’s offering is lawful or prescribe a universal merchant acceptance policy.
Sources
- 1. Federal Reserve, Regulation GG compliance guide; March 1, 2017Official sourceBack to text: ↑1↑2
- 2. Federal Reserve, 12 CFR 233.6 non-exclusive examples; checked September 29, 2026Official sourceBack to text: ↑1↑2↑3
- 3. Federal Reserve, Regulation GG rule indexOfficial source