Here is the thing we went looking for, and the thing we did not find. The query is clean: how often do UKGC-licensed operators re-run Customer Due Diligence on existing customers, and where is that cadence disclosed in their 2024/2025 annual reports? We pulled the filings. We read the responsible-gambling sections line by line.
The cadence is not in there. Not as a number. What operators disclose instead is a constellation of softer metrics — deposit-limit adoption, reality-check defaults, levy contributions — and the actual re-verification clock lives somewhere the marketing copy never goes: the enforcement register. This piece walks that gap, with a Greek-market detour, because the Hellenic Gaming Commission tells the same story in a different accent.
Do UKGC operators actually disclose a CDD renewal cadence in their annual reports?
No. And we want to be precise about the concession here, because the strongest version of the opposing view is real: operators *do* disclose customer-protection metrics, and some of them are specific. Flutter's 2024 filing reports a 47% UK deposit-limit adoption rate and a 60-minute default reality-check interval — those are concrete numbers, pulled straight from the results centre.
That is the concession. Now the teardown. None of those metrics is a Customer Due Diligence *renewal* cadence. A deposit limit is a tool the player sets. A reality check is a clock the software runs. CDD renewal — the schedule on which an operator re-verifies source of funds, identity, and affordability for an *existing* high-value customer — is an internal compliance process, and listed operators treat it as operational detail, not an investor-disclosure line. You will find risk-factor language about "regulatory compliance costs." You will not find "we re-run enhanced due diligence every N months." The number simply is not a reported KPI.
What does Entain's 2024 annual report tell us about customer checks?
It tells us the framing, not the frequency. Entain reports that 88% of its revenue now comes from regulated markets, and that figure sits at the centre of its 2024 annual report as a proxy for compliance maturity. The logic operators want you to follow: more regulated revenue means more supervised customer checks, therefore better due diligence.
It is a reasonable narrative. It is also not a cadence. Twenty-eight million active customers across 27 brands, and the report describes its player-protection *architecture* — interaction models, risk flags, markers of harm — without committing to a re-verification interval anyone could audit. This is the pattern across the listed operators. The annual report is a document written for shareholders, and shareholders are sold the shape of the control environment, not its tick rate. The cadence is real. It is governed by the operator's AML risk assessment under the 2007 Money Laundering Regulations. It is just not the number on the page.
Why does the enforcement register say more than the annual report?
Because the register is where the cadence becomes visible — by its absence. When an operator's due-diligence clock runs too slow, the UKGC writes down exactly what went wrong, and that document is public. The UKGC public register and enforcement notices are, functionally, the only place the renewal-cadence question gets answered with specifics — retroactively, and in the negative.
Think about what that means. An annual report says "we take player protection seriously." An enforcement notice says "this operator allowed a customer to deposit unusual sums across a sustained period without an adequate source-of-funds review." The second sentence contains the cadence the first sentence hides. One regulator, 2,420 total licensees on the register, and a steady cadence of settlements that read like reverse-engineered process audits. We read enforcement notices the way a forensic accountant reads a restatement: the correction tells you what the original number concealed.
What did the Ladbrokes and Coral £17m settlement reveal about due diligence timing?
It revealed the failure mode directly. In August 2022 the UKGC published a £17m regulatory settlement against Entain's Ladbrokes and Coral brands for social-responsibility and anti-money-laundering failings. The specific findings are the cadence, stated as deficiency: the operator failed to carry out sufficient customer interactions with high-risk players, failed to adequately identify players showing signs of problem gambling, and ran AML controls inadequate for customers with unusual deposit patterns.
Read that as a timing document. "Failed to carry out sufficient interactions" is a statement about frequency — the renewal clock was too slow, or not running at all, for the customers who most needed it. The settlement is the public record of an operator whose due-diligence cadence drifted out of regulatory tolerance. Flutter's Sky Betting and Gaming subsidiary drew its own £1.17m penalty in March 2023 on materially the same grounds. Bet365's Hillside arm: £582,120 in December 2022. Same theme, three operators, one register.
How does the Greek market under the HGC compare on disclosure?
The Hellenic Gaming Commission operates on the same principle with less listed-company noise. Greece licenses online operators under Law 4002/2011, as amended in 2019, and had issued 24 licences as of 2024. The HGC maintains its own enforcement and licensing register, and — critically — enforces against unlicensed supply through DNS blocking of operators serving Greek residents without a Greek licence.
The disclosure gap is structurally identical. OPAP, the largest Greek operator and a listed company on the Athens exchange, reports the metrics a shareholder wants. Stoiximan, Novibet, and Winmasters operate under HGC supervision with AML obligations transposed from EU anti-money-laundering directives. None of them publishes "we re-run CDD every N months" either. The Greek twist is the partial-monopoly history: OPAP's incumbency means its compliance posture is scrutinised politically as well as regulatorily. A fieldnote from the register: the HGC's published licence list is shorter and easier to read end-to-end than the UKGC's 2,420-line ledger. Smaller market, same blind spot.
What can a Greek player at OPAP or Stoiximan actually verify?
The licence, the regulator, and the enforcement history — not the cadence. A Greek resident can confirm that Stoiximan (the Kaizen Gaming brand) and Novibet hold active HGC licences, that the operator is therefore bound to Greek AML and player-protection rules, and that an unlicensed competitor would be DNS-blocked rather than supervised. That is a real verification, and it is more than most players ever do.
What the player cannot verify is when their own enhanced due diligence will next trigger. That clock is set by the operator's internal risk assessment and surfaces only if it fails — at which point it appears in an HGC enforcement action, after the harm. The asymmetry is the whole point of this piece. The disclosure you can check (licence status) is not the disclosure you actually need (re-verification timing). Mediterranean market, UK market, identical wall between the two.
Is GAMSTOP a substitute for CDD renewal?
No — and conflating the two is a common error worth dismantling. GAMSTOP is a national self-exclusion register that automatically covers every UKGC-licensed online operator; a single registration blocks deposits across all brands for a user-selected 6 months, 1 year, or 5 years. Around 0.42 million people are registered, with annual registrations up roughly 35%.
That is a player-initiated wall, not an operator-initiated check. GAMSTOP fires when the *customer* decides to exclude. CDD renewal is supposed to fire when the *operator's* risk model flags a customer who has not asked for anything — the high-deposit player who never self-excludes precisely because they do not see a problem. The two mechanisms protect different people at different moments. Greece's equivalent self-exclusion infrastructure under the HGC works the same way: useful, binding, and entirely orthogonal to the question of how often an operator proactively re-verifies source of funds. A self-exclusion register is not a due-diligence cadence. They are not interchangeable.
So what number should you actually read?
Stop looking in the annual report. Start reading the enforcement register, and read it as a frequency document. The annual report gives you the operator's self-portrait — 88% regulated revenue, 47% deposit-limit adoption, a 60-minute reality check. The register gives you the operator's failures, dated and quantified, and each failure is a statement about a due-diligence clock that ran too slow.
The cadence you want is not published as a forward-looking commitment. It is published backwards, as penalty.
Ladbrokes and Coral: £17m, August 2022, insufficient customer interactions with high-risk players. Sky Betting and Gaming: £1.17m, March 2023. Hillside (Bet365): £582,120, December 2022. Three settlements, one regulator, all on the public register, none of them in the annual report. That is the disclosure. It speaks for itself.
FAQ
Where is Customer Due Diligence renewal frequency disclosed for UKGC operators in 2025?
It is not disclosed as a forward-looking metric in operator annual reports. Filings from Flutter and Entain report adjacent figures — deposit-limit adoption, reality-check defaults, regulated-revenue percentages — but no committed re-verification interval. The closest thing to a published cadence appears retroactively in UKGC enforcement notices, which describe, with dates and penalties, where an operator's due-diligence timing fell below regulatory tolerance.
Does Entain's annual report state how often it re-checks customers?
No. Entain's 2024 annual report emphasises that 88% of revenue comes from regulated markets and describes its player-protection architecture across 28 million active customers, but it does not commit to a CDD re-verification interval. The renewal cadence is governed by the operator's internal AML risk assessment under UK money-laundering regulations, which is an operational process rather than an investor-disclosure KPI.
What does a UKGC enforcement settlement reveal about due diligence timing?
It reveals the failure as a timing problem. The £17m Ladbrokes and Coral settlement of August 2022 cited insufficient customer interactions with high-risk players and AML controls inadequate for unusual deposit patterns. Translated, the operator's re-verification clock ran too slowly for the customers who needed it most. The notice is effectively a reverse-engineered audit of a cadence that drifted out of tolerance.
How does the Greek HGC handle this compared to the UKGC?
Structurally the same, at smaller scale. The Hellenic Gaming Commission licenses operators under Law 4002/2011 (amended 2019), had issued 24 licences as of 2024, and DNS-blocks unlicensed operators serving Greek residents. Operators like OPAP, Stoiximan, Novibet, and Winmasters carry AML obligations but do not publish re-verification intervals either. As in the UK, the cadence only surfaces through enforcement actions after a failure.
Can a player check when their next due-diligence review will happen?
No. A player can verify an operator's licence status, regulator, and enforcement history — all public on the UKGC or HGC registers. The actual re-verification trigger is set by the operator's internal risk model and is invisible to the customer until it activates, or until its absence appears in an enforcement notice. The verifiable disclosure is not the one a player most needs.
Is GAMSTOP self-exclusion the same as CDD renewal?
No. GAMSTOP is a player-initiated national self-exclusion register covering all UKGC-licensed online operators, blocking deposits for 6 months, 1 year, or 5 years across roughly 0.42 million registered users. CDD renewal is an operator-initiated check triggered by a customer's risk profile, not their request. The two protect different people at different moments and are not interchangeable mechanisms.
Why don't operators just publish their CDD renewal cadence?
Because annual reports are written for shareholders, who are sold the shape of the control environment rather than its tick rate. A specific re-verification interval would also become an auditable commitment a regulator could hold against the operator. The incentive runs toward describing architecture — markers of harm, interaction models — while keeping the precise frequency inside the internal AML risk assessment, where it is harder to measure against.