VGCCC Fines Keno Vic $75,000 After Self-Excluded Customer Gambled
A barred customer opened a second account and gambled before checks caught up. The regulator sent the bill to the operator.
The Keno self-exclusion fine handed down in Victoria is not a story about a broken policy. It is a story about a policy that worked everywhere except the one place it needed to. Keno Vic Pty Ltd has been fined $75,000 by the Victorian Gambling and Casino Control Commission after a self-excluded customer opened a second online account and gambled, exposed by a systems gap that let a familiar name pass as a new one. It is not the first time the VGCCC has come down hard on self-exclusion failures either. The regulator recently had its findings against Okebet confirmed at tribunal over self-exclusion and inducement breaches, a sign that this is a pattern of enforcement, not a one-off.
How the Keno self-exclusion fine happened
The sequence is worth walking through, because the failure sits in the detail.
In April 2024, a customer self-excluded from Keno Vic’s products. Six months later, in October, that same person opened a second online account. The account did not sail through unchecked. It failed the automatic identity verification and was placed on a restricted play period, which is exactly what the control is designed to do.
Then it fell apart. During that restricted window, the customer was still able to deposit funds and gamble before a manual verification could be completed. The duplicate was only caught when the person contacted Keno Vic to finish the manual process, gave their real name to claim winnings, and the system finally recognised the match.
By then, the barred player had already gambled.
Why the systems gap matters more than the breach
Victorian rules prevent anyone from holding more than one account with a single gambling provider. That rule existed. The self-exclusion register existed. What failed was the layer connecting them: name-matching that could not recognise a variation of a customer already on the list.
This is the part operators should sit with. The harm-prevention architecture was present and, on paper, sound. It was the identity-resolution engine underneath that let a person the system had already flagged create a fresh account and play.
Regulators know the difference now. And they are auditing the execution, not the intention. That direction of travel is deliberate. Victoria has been pushing a broader package of reforms aimed at safer gambling, and tighter expectations on operator systems are part of the same agenda.
What the regulator actually said
VGCCC CEO Suzy Neilan framed self-exclusion as a practical tool that helps people block access, remove temptation, and support lasting change. But her sharper point was about responsibility. Even acknowledging that the customer tried to get around the verification process, Neilan said the responsibility remains with the major licensee to have systems that can identify or flag self-excluded individuals and stop them gambling during a restricted play period.
Read plainly, that is a warning to the wider market. “The customer was actively evading us” is no longer a shield. If the systems can be evaded, the systems are the problem, and the licensee owns them.
The operator implication
For any operator running self-exclusion across multiple products or brands, this is a direct prompt to test one thing: would your own matching have caught this customer? A slightly altered name, a second registration attempt, a restricted-play window that allows deposits before manual review clears. Those are not exotic edge cases. They are common failure points.
The decision this affects is a budget one. It moves fuzzy-matching, duplicate detection, and the tightness of restricted-play controls from a compliance line item to a board-level risk. The cost of getting it wrong is now visible, and it has a number attached.
The mitigating side
It is worth being fair about the penalty itself. The Commission acknowledged Keno Vic’s clean compliance history, its cooperation with the investigation, and its remediation. Those factors tempered the fine. Neilan described the outcome as consistent with a strategic focus on proportionate, risk-based regulation and deterrence.
So this was not a punitive strike. It was calibrated. Which arguably makes it more instructive, because it shows how a well-behaved operator with a single systems flaw still ends up $75,000 lighter.

Future outlook
Expect self-exclusion enforcement to keep drifting toward the technical layer over the next six to twelve months. Registers and restricted-play periods are now table stakes. The scrutiny is shifting to whether the matching and verification behind them can withstand a determined attempt to slip through, including duplicate accounts under name variants.
Operators who treat this as a Victorian anomaly are reading it wrong. The question the regulator asked here is the question the whole market will be asked to answer.
Source: VGCCC
