NorthStar Got Fined CA$100K for AML Failures – That Is Not Even the Worst Part

Key Points

  • Player crossed NorthStar’s CA$25,000 risk level in the first month. The account remained active for 15 months before the player made any deposits amounting to CA$189,395.
  • NorthStar did not object to AGCO’s findings, paid CA$80,000 and took full responsibility.
  • The fine comes after 10 days of a change in its top management with its CEO, CFO stepping down and a new VP of Compliance being appointed.

A single player account sat open for fifteen months. The operator’s own policies flagged the risk within the first thirty days. No enhanced checks were run. No source-of-funds review was opened. No escalation happened. By the time Ontario’s gaming regulator stepped in, that account had taken in CA$189,395.

That is the story the AGCO published on 27 August 2026 when it issued a CA$100,000 monetary penalty against NorthStar Gaming (Ontario) Inc. for anti-money laundering control failures. Read it once and the case looks contained, one bad account, one fine, one lesson learned. Read the full picture behind it and the story becomes considerably harder to dismiss.

How a CA$25,000 Threshold Became a CA$189,395 Problem?

The player opened a NorthStar Bets account in March 2024. Within that same month, their lifetime deposits crossed the CA$25,000 threshold that NorthStar’s own AML policies identified as the trigger for enhanced due diligence, including mandatory source-of-funds verification and a formal high-risk classification.

That threshold was crossed. Nothing followed.

Deposits kept coming. December 2024 alone saw the player push CA$55,000 into the account, well over two times the threshold that should have locked in review months earlier. By June 2025, cumulative deposits reached approximately CA$189,395, more than seven times the internal escalation trigger. NorthStar only classified the account as high risk and shut it down after the AGCO made direct inquiries, which were themselves prompted by police charges against the player linked to Project Outsource, a joint law enforcement operation targeting alleged extortion and violence in Ontario’s towing industry.

The regulator was unambiguous. “Operators are the first line of defence against criminal activity in Ontario’s gaming market,” said AGCO Registrar and CEO Dr Karin Schnarr. “Anti-money laundering controls must be more than policies on paper. When risk indicators are triggered, operators are required to take active steps.”

It is worth noting that the regulator’s order did not allege that NorthStar knowingly handled criminal proceeds. The finding was narrower and in some ways more instructive: NorthStar had the policies, had the data, and still failed to act.

NorthStar Settled for CA$80,000 and Did Not Fight the Finding

Most outlets reported the CA$100,000 headline figure. Fewer noted that NorthStar did not dispute the AGCO’s finding and agreed to settle the matter for CA$80,000, co-operating fully throughout the investigation.

CEO Corey Goodman issued a public statement accepting responsibility. “We take our AML obligations seriously and we accept responsibility for the matters identified in this Order,” he said. “The conduct at issue is confined to a specific period that is now behind us. We have invested significantly in our compliance program since then and we are committed to meeting the highest standards expected of us as a licensed internet gaming operator in Ontario.”

Goodman was confirmed as permanent CEO on 17 August, ten days before the penalty was published. On the same date, NorthStar announced the resignation of CFO Chin Dhushenthen, the appointment of Ben Powell as interim CFO, and the naming of Krisztina Kalla as the company’s new Vice President of Compliance. Three senior positions changed hands in a single announcement, and the AML penalty landed shortly after.

The Compliance Fine Sits Inside a Much Larger Governance Problem

Here is where the story gets broader. NorthStar’s shares have been suspended on the Toronto Stock Exchange since May 2026 after the company failed to file audited financial statements. KPMG resigned as auditor on 29 May 2026. NorthStar subsequently appointed Davidson and Company LLP to complete outstanding audits for three consecutive fiscal years: 2023, 2024 and 2025, all simultaneously, with completion targeted for later in 2026.

An operator managing a suspended share listing, three years of overdue audits and a simultaneous AML enforcement action is carrying a compliance load that goes well beyond one poorly monitored player account. The CA$100,000 fine is the most visible item. The rest of the picture is considerably more concerning.

This Is NorthStar’s Third Regulatory Strike Since 2022

The AML penalty is serious on its own. Placed against NorthStar’s recent regulatory history, it becomes part of a pattern worth examining carefully.

The AGCO fined NorthStar a CA$30,000 penalty in October 2024 due to its failure to ensure that NorthStarBets.ca was only available to gamers from within the jurisdiction of Ontario. Moreover, NorthStar was unable to deliver required information to the AGCO in time. After some time, the penalty was partially overturned due to the fact that NorthStar managed to deliver information in time, thus proving that it did not violate the geolocation standard.

Three enforcement actions in roughly two years, across three distinct categories: geolocation controls, document disclosure, and now AML. Each one alone could be read as an isolated compliance gap. Together, they suggest a company that has consistently struggled to meet the AGCO’s operational standards across multiple functions at the same time.

The AGCO Is Raising the Bar Across the Entire Market

NorthStar is not the only operator under pressure. The AGCO fined FanDuel Canada a record CA$350,000 in January 2026 for failing to identify and report suspicious betting activity. TheScore received a CA$105,000 penalty in October 2025 for failing to intervene with a high-risk player who lost CA$230,000 over eight months. The regulator is clearly working through the market category by category, testing whether operators’ systems actually function under real conditions.

The iGaming industry in Ontario is not insignificant. In the year ended March 2025, it achieved gross gaming revenue of CA$2.9 billion, through 50 licensed operators and about 2.6 million customer accounts. To that extent, AML breaches by even a single operator have implications for the public interest which go well beyond just the operator alone.

Expert Analysis: The Real Problem Is Not the Policy Gap – It Is the Silence

We find the most revealing detail in this case is not that NorthStar lacked a policy. It had one. The player’s occupation was flagged. The CA$25,000 threshold was a defined internal trigger. The company had the data it needed to act within the first month of the relationship.

What NorthStar apparently lacked was a system that connected that data to a decision. The policy existed on paper; the operational mechanism that should have converted it into action did not fire. That is a different category of failure, and arguably a more dangerous one, because it is invisible. An absent policy is at least detectable. A policy that exists but silently fails can run for fifteen months without surfacing in any internal review, which is precisely what the evidence here suggests happened.

We think the industry should be genuinely unsettled by that possibility. A regulator can audit policies. What it cannot easily audit is whether those policies are generating real responses in real time across thousands of active accounts. NorthStar’s case is a public illustration of the gap between a written compliance framework and an operational one, and given the broader enforcement trend the AGCO is demonstrating, it will not be the last operator to find that gap examined under a regulator’s spotlight.