Denmark Barred Inpay From Onboarding New iGaming Clients
A financial regulator has just stopped a payment company from signing new gambling clients. It did not issue a fine. It did not point to a single laundered transaction. It found that the company could not explain, on paper, why its iGaming customers were doing what they were doing.
On 19 August 2026, Denmark's Finanstilsynet issued an injunction barring Inpay A/S from establishing new business relationships in the online gaming sector until it can demonstrate that its breaches of the Danish Money Laundering Act have ceased. Existing customers keep processing. New ones cannot be onboarded at all.
The interesting part of this is not what happened to Inpay. It is what your own payment provider is now required to prove about you, and how little of it most operators have ever supplied.
The Finding Was Missing Explanation, Not Missing Money
Finanstilsynet inspected Inpay in March 2026 and cited three deficiencies. The company had not properly applied customer due diligence when a customer's circumstances changed. It had failed to assess the purpose and intended nature of business relationships with iGaming clients carrying high money laundering and terrorist financing risk. And it did not carry out sufficient outgoing monitoring of those clients.
The regulator's own framing is the line worth reading twice. The deficiencies in due diligence and transaction monitoring, it said, create a real and significant risk that the company supports illegal gaming activities.
None of that requires evidence of a crime. There is no allegation that Inpay processed proceeds of crime. The breach is the absence of a documented answer to a simple question: why is this operator, in this market, moving this money through a Danish payment institution?
Finanstilsynet also noted that the deficiencies concerned the majority of Inpay's customer portfolio, that this group accounts for a significant share of total transaction volume, and that most of those customers sit outside Denmark and the wider EU. That combination, offshore clients, high-risk vertical, thin file, is the profile that triggers this outcome. It describes a large portion of the merchants reading this.
An Injunction Costs More Than a Fine
A fine is a number. You provision for it, you pay it, you carry on. An injunction has no number and no end date. It lifts when the regulator is satisfied, which means the supervisor now controls the timetable for an entire revenue line.
Note the sequence. Inpay's board voluntarily halted new iGaming onboarding on 27 July 2026, roughly three weeks before the injunction landed. The self-imposed pause did not prevent the formal order. Finanstilsynet wanted the constraint on the public record and legally enforceable rather than discretionary.
That distinction matters commercially. A voluntary pause is a business decision the firm can reverse on Monday. An injunction is a supervisory finding that follows the firm into every correspondent banking review, every acquiring bank questionnaire, and every enterprise procurement process for years. Inpay's existing book is unaffected and its clients see no interruption, which is the right outcome for those operators. Its pipeline in the vertical is closed.
If you were mid-integration with a provider when something like this lands, you are not a customer. You are a prospect, and prospects are exactly what the order prohibits.
Denmark Has Said This to the Same Firm Before
This is not a first contact. Finanstilsynet published an anti money laundering inspection report on Inpay in 2023 that issued orders on customer due diligence across its Eurogiro segment, including beneficial ownership documentation for both new and existing customers. The same report flagged insufficient understanding of why foreign owned business customers with no connection to Denmark required a Danish payment institution at all. There was a payment services and money laundering inspection in 2021 before that.
Three supervisory cycles, one recurring theme: cross-border clients, high inherent risk, and a file that does not explain the commercial logic. Repeat findings do not stay financial. They escalate into structural limits on what the firm is allowed to sell.
The practical lesson for operators is a question almost nobody asks during provider selection. When was your provider's last AML inspection, what orders came out of it, and have they been closed? In most of Europe those reports are published. A provider that will not discuss its own supervisory history is telling you where it is in the cycle.
Financial Supervisors Are Now Enforcing Gambling Law
Read the regulator's concern again. The risk it identified is that the company supports illegal gaming activities. That is a gambling licensing concern, enforced through an anti money laundering statute, by a financial supervisor, against a payment institution.
This is deliberate and it is spreading. Denmark's gambling authority already blocks unlicensed sites at the domain level, and every European regulator has learned that domain blocking is a game of whack-a-mole. The payment layer is the durable choke point. There are thousands of offshore gambling domains and a few dozen payment institutions that serve them. Supervising the few is cheaper than chasing the many.
The consequence for licensed operators is uncomfortable. Your legitimacy is now assessed indirectly, by a financial regulator you have no relationship with, reading a file your provider wrote about you. You do not get to make your own case. You get whatever your PSP's compliance team managed to record about you eighteen months ago.
If that file is thin, the cheapest fix available to your provider is not to improve the file. It is to remove the customer.
Build the File Your Provider Cannot Write Without You
The specific breach Finanstilsynet cited, failure to assess the purpose and intended nature of the relationship, cannot be remediated by the provider alone. It needs information only you hold. Supply it before you are asked, in a single document you keep current:
- Licences by market, with numbers, issuing authority, and expiry dates. Not a claim that you are licensed. The evidence.
- Geo-blocking proof, showing which markets you exclude and how the block is technically enforced. This is what answers the illegal gaming question directly.
- Corporate structure and ultimate beneficial owners, including where each entity is incorporated and why.
- Jurisdictional logic, meaning a plain explanation of why this entity, in this country, uses this provider. This is the exact gap the 2023 report identified and the 2026 inspection found again.
- Expected volumes, corridors, and currencies, with the commercial basis for the forecast, so that actual flow can be reconciled against a stated expectation.
- Settlement path, showing which accounts receive funds and who controls them.
Then handle the trigger that caught Inpay. The order specifically cites due diligence when a customer's circumstances change. A new market, a new brand, a new shareholder, a licence lapse, a step change in volume, or a shift in traffic sources all reset your risk profile. Most operators tell their provider none of this, because nobody asks. That silence is precisely the deficiency the regulator is now penalising, and it is being penalised on the provider's side of the relationship, not yours. Which means the provider will solve it by cutting you rather than by chasing you.
Send your payment provider an updated relationship file this quarter without waiting to be asked, and ask them for their last published inspection outcome in the same email. If the file takes you more than a day to assemble, your provider does not have it either. If they will not answer the question about their own supervisory history, you already know what the answer is.