Payment provider compliance just stopped being someone else's problem
Denmark's financial regulator barred payments firm Inpay from taking on new iGaming customers this week, citing anti-money laundering failures, and the marketing lesson buried in that story matters more than the compliance one.
By Katie Delaney · 2026-08-23 · 12 min read
The morning a deposit campaign froze#
Picture a Tuesday morning at a mid-market sportsbook's growth team. The dashboard that usually ticks up in steady, boring increments has gone flat by 9am. Creative hasn't fatigued. Bids haven't collapsed. The media buyer checks the obvious levers first, because nobody thinks to check the payment rail underneath a campaign that has run cleanly for eighteen months. By lunchtime someone finally traces it: the e-money institution processing new deposits has quietly stopped accepting new customer agreements overnight, on the order of a regulator neither the media buyer nor the creative lead had ever heard of. The campaign is still live. The budget is still spending. The rail it depends on for new business simply isn't there any more.
This is not a hypothetical. On 18-19 August 2026, Denmark's Financial Supervisory Authority, Finanstilsynet, barred the Copenhagen payments firm Inpay from entering into new customer agreements with iGaming operators, citing serious anti-money laundering failings uncovered in a March 2026 inspection (iGaming Business, 2026). Inpay isn't a niche player: it powers roughly a quarter of iGaming's Power50 operators for withdrawals, with named clients including 888, Betsson, NetBet, Lottoland, LiveScore and Delasport (Inpay, 2026). For any marketing team running a deposit drive through one of those brands, payment provider compliance just stopped being someone else's problem and became the single biggest threat to a campaign's return on ad spend that nobody had on the risk register.
folkfox works across fintech and iGaming, two categories where the product is trust before it is anything else, and the pattern here is depressingly familiar. Payment provider compliance sits invisible in a marketing plan right up until the moment it isn't, and by then the damage is already showing up in a dashboard nobody thought to watch.
What Finanstilsynet actually found#
The specific failings#
The injunction itself is narrow on paper and blunt in practice. Finanstilsynet's order covers new iGaming customer onboarding only: Inpay's existing business customers, in gaming and every other sector, keep operating exactly as before (Gaming Intelligence, 2026). What triggered it was a pattern the regulator found running through the majority of Inpay's iGaming portfolio: insufficient customer due diligence when a client's circumstances changed, a failure to properly assess the purpose and intended nature of business relationships with high-risk gaming clients, and inadequate outgoing monitoring of transactions once those relationships were live (iGaming Business, 2026).
Finanstilsynet was unambiguous about the stakes: “The deficiencies in the company's customer due diligence procedures and transaction monitoring entail a real and significant risk that the company supports illegal gaming activities” (iGaming Business, 2026). The regulator went further on why the violation counted as serious rather than routine: “The Danish FSA assesses that the violations are serious, and the extent, type of customer, including the complexity of ownership structures and activities across many countries, are aggravating factors for how significant the violation is” (Gaming Intelligence, 2026).
Inpay's board had already moved on 27 July 2026, three weeks before the formal decision, voluntarily halting new iGaming onboarding rather than wait for Finanstilsynet to force the point (AlienWP, 2026). It is a sensible instinct for a company founded in 2008 and named one of Denmark's fastest-growing firms by the Financial Times as recently as 2022 (AlienWP, 2026). But instinct and institutional memory are two different things, and that gap is where the story gets more interesting for anyone doing aml payment compliance due diligence rather than just reading headlines.
A regulator that has been here before#
Finanstilsynet has inspected Inpay's AML controls repeatedly before 2026, and each report reads like a rough draft of the next one. A 2021 inspection found inadequate AML risk assessment and policy, weak internal controls, insufficient investigation of suspicious transactions and gaps in board governance and whistleblower protections (Finanstilsynet, 2021). A 2023 follow-up issued formal directives on customer due diligence for the Eurogiro segment and a reprimand over one client's inadequate onboarding checks (Finanstilsynet, 2023).
None of that was a secret. All of it was sitting in a public regulatory archive for anyone willing to look before signing a payment-processing contract. That is the uncomfortable part of payment provider compliance: the evidence is rarely hidden, it is just never where the marketing team is looking, and few teams think to hunt through a regulator's back catalogue before a campaign brief gets signed off (SCCG Management, 2026).
Why this is marketing's problem, not just legal's#
Most iGaming and fintech marketing teams treat the payment stack the way they treat the server room: a technical detail somebody else owns, invisible right up until it breaks. That division of labour made sense when payment providers rarely made the news. It stops making sense the moment a regulator can freeze new-customer onboarding at a rail an entire acquisition funnel depends on, with zero warning to the operator running campaigns on top of it. A deposit campaign driving traffic to a frozen rail is not an edge case any more; it is a predictable outcome of treating payment provider compliance as someone else's checklist.
The commercial logic is blunt. Media spend buys attention and intent. If the payment rail behind the call to action cannot actually onboard the customer that attention converts into, the spend is not underperforming, it is wasted outright, and wasted spend on a live campaign costs far more than a delayed launch ever would. folkfox's position, developed across fintech and iGaming accounts, is that payment provider compliance belongs on the same pre-launch checklist as licensing jurisdiction, reviewed before a campaign brief is signed off, not audited after a regulator has already acted.
That means giving the payment stack the same due-diligence rigour a licensing review already gets. Below is folkfox's own directional ranking of the checks worth running on any payment provider before it carries a live deposit campaign: our own assessment of relative risk, not a measured industry benchmark, just the order we would work through the list ourselves.
None of this replaces legal or compliance sign-off. It sits alongside it, on the same brief, reviewed by the same people who approve the media plan, because a fintech digital marketing agency that treats payment risk as somebody else's department is gambling with its client's budget whether it means to or not.
The wider EU compliance landscape#
Inpay is not operating in a regulatory vacuum, and neither is any payment provider serving European iGaming or fintech clients. The EU's Anti-Money Laundering Package, anchored by Directive (EU) 2024/1640 of 31 May 2024, treats payment institutions and e-money institutions as obliged entities under the same customer due diligence and ongoing monitoring duties that apply to banks (EUR-Lex, 2024). Member states must extend beneficial-ownership register access by 10 July 2026 and transpose the bulk of the directive by 10 July 2027, with a new EU-level anti-money laundering authority taking on direct supervision of the highest-risk cross-border firms over the same window (eucrim, 2026).
For a marketing team, the practical read is simpler than the legislative detail: aml payment compliance is tightening across the EU on a fixed timetable, not loosening, and a payment provider's home regulator is about to matter more than its marketing deck does. Payment provider compliance, in that light, is not a one-off audit; it is a moving target that needs rechecking as often as the media plan itself.
Set against that timetable, a single enforcement action against one payment provider looks less like an isolated incident and more like an early example of how the next four years of EU payment provider compliance is going to be enforced: quietly, at the level of individual customer relationships, with the commercial consequences landing on whoever built a campaign on top of the rail in question.
| Year | Finding | Regulatory action |
|---|---|---|
| 2016 | High inherent AML/terrorist-financing risk flagged relative to sector average | Assessment published |
| 2021 | Weak AML risk assessment, internal controls and suspicious-transaction investigation | Multiple compliance directives issued |
| 2023 | Customer due diligence gaps in the Eurogiro segment, one onboarding failure | Formal directive and reprimand |
| 2026 | CDD and monitoring gaps across the majority of the iGaming portfolio | New iGaming customer agreements barred |
Building payment provider compliance into the brief#
The fix is not a bigger compliance department; most agencies and in-house teams don't have one to grow. It is moving payment provider compliance three steps earlier in the workflow, from a post-launch audit item to a pre-brief question sat next to licensing jurisdiction and creative sign-off.
Every payment rail the funnel will touch gets listed alongside every ad platform and every licensing jurisdiction.
Each rail's regulator, licence type and public enforcement history gets checked before a media buy is approved, not after.
Deposit messaging and bonus terms are built against a rail that has already cleared vetting, not one still pending review.
The campaign goes live with a documented sign-off trail, the same paper trail a licensing review would already demand.
Payment provider compliance is reviewed on a fixed cadence, not left until the next regulator headline forces the question.
This is where a fintech digital marketing agency earns its keep on the fintech side of the business too: not just building the campaign, but insisting the brief includes the question of what happens to this rail if the regulator moves, before a single euro of media spend goes out the door. It is a small addition to a brief template and a large reduction in the odds of a frozen funnel three months into a launch.
Payment rail risk, in other words, is cheapest to price in at the brief stage and most expensive to discover mid-campaign. Treat it as a line item, not an afterthought, and the rest of the workflow barely changes.
What to do now, not after the next headline#
If a payment provider your campaigns touch has ever quietly avoided a mention in a pitch deck, that omission is worth chasing. Ask the account manager for the regulator's name, the licence type and the date of the most recent inspection. A provider with a clean answer will give it in one email. A provider that stalls has already told you something a media plan alone never would, and that is payment provider compliance doing its job before a euro of spend is at risk.
For iGaming operators specifically, Inpay's own numbers make the stakes concrete: a firm processing withdrawals for roughly a quarter of the Power50 just lost the ability to sign a single new iGaming customer, anywhere, until Finanstilsynet is satisfied the fix has actually worked (Inpay, 2026). That is not a footnote for a growth team planning next quarter's content and brand calendar around a specific market launch. It is a live constraint on which markets, and which payment rails, that calendar can safely assume.
Regulators rarely announce the next Inpay in advance, but they do leave a paper trail for anyone willing to follow the scent before the story breaks rather than after. The real quarry here isn't Inpay, it is the blind spot in the brief that let a frozen rail go unnoticed until the dashboard did the telling. folkfox builds that habit into every fintech and iGaming brief we write, because a campaign built on a rail nobody vetted is a campaign built on borrowed time, and payment provider compliance is the cheapest insurance policy most media plans never buy.
Whether the next enforcement action lands in Denmark, Malta or anywhere else on the folkfox client map, the underlying discipline stays the same: check the rail before you brief the campaign, not after the dashboard goes quiet.
Frequently asked questions#
What happened between Denmark's Finanstilsynet and Inpay in August 2026?
Denmark's Financial Supervisory Authority, Finanstilsynet, barred payments firm Inpay from entering new customer agreements with iGaming operators, citing serious anti-money laundering failings found in a March 2026 inspection. The order covers new iGaming customer onboarding only; existing customers in gaming and other sectors are unaffected. It is a textbook case of payment provider compliance breaking a rail overnight, with no warning to the operators built on top of it.
What are the compliance requirements for payments providers serving regulated iGaming operators?
Payment and e-money institutions operating in the EU must run customer due diligence, assess the purpose of each business relationship, monitor transactions on an ongoing basis, and hold a valid payment institution or e-money licence from their home regulator. Finanstilsynet's action against Inpay shows what happens when any of those slip.
What does aml payment compliance actually involve for a company like Inpay?
In practice, aml payment compliance means proving, with evidence rather than policy documents, that customer due diligence happens at onboarding and again whenever a client's circumstances change, that high-risk relationships are properly assessed, and that outgoing transactions are monitored, not just logged.
How do you assess payment rail risk before routing a deposit campaign through a new provider?
Check the provider's regulator, licence type, and public enforcement history before the media plan is finalised, not after. A clean answer takes one email; a stalling one is itself a signal. Payment rail risk is cheapest to catch before launch, not after a campaign is already spending.
Why would a fintech digital marketing agency care about a regulator's AML decision?
Because a campaign is only as good as the rail it converts on. A fintech digital marketing agency that ignores payment provider compliance risks building a deposit drive on a provider that cannot legally sign the customer it just persuaded to convert.
How fast can a payment provider compliance failure affect a live marketing campaign?
As fast as the next customer tries to sign up. Finanstilsynet's order against Inpay took effect immediately for new business, meaning any campaign built to acquire new customers through that rail stopped converting the moment the injunction landed, not weeks later.
Read more on this topic#
Fintech AML requirements just got a €2.6 million reminder
bunq's AML fine is the last time a compliance failure this size hit fintech marketing's radar, until now.
Read the pieceThe FTC dropped a theory, and fintech's targeting risk shrank with it
A different regulator, a different risk, the same lesson: compliance shifts change what a marketing team can safely plan.
Read the pieceOpen banking's free front door just grew a price tag
Another rule change quietly reshaping what a fintech funnel can assume about its own infrastructure.
Read the pieceWhite-label casino launch: ADR, KYC, and complaints checklist
The iGaming operator's side of due diligence, built for launch briefs rather than regulatory post-mortems.
Read the piece
Ready to put payment provider compliance on the brief?
folkfox builds fintech and iGaming campaigns that survive contact with a regulator, not just a launch date.