Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/Travel & Hospitality: how the sector works/Regulation, major laws and compliance/Money in, money out: anti-money-laundering and tax rules that shape deals
5/5+150 XP

Regulation, major laws and compliance

10Who is flying the plane: aviation's alphabet soup of regulators+15011The passenger's rights: compensation rules that bite+15012Rooms, fire exits and inspectors: hotel safety law in practice+15013Your data, their booking: privacy law across the guest journey+15014Money in, money out: anti-money-laundering and tax rules that shape deals+150

Money in, money out: anti-money-laundering and tax rules that shape deals

# Money in, money out: anti-money-laundering and tax rules that shape deals

A guest walks into a Miami hotel and pays cash for a two-week stay, upfront, no questions asked, or so it seems. Behind the desk, that transaction is quietly triggering compliance obligations the guest never sees: identity checks, reporting thresholds, and a paper trail that regulators can pull years later. Travel and hospitality moves enormous sums across borders, in cash, cards, and crypto, which makes it a natural target for money laundering and a priority for tax authorities. Understanding these rules is not a back-office detail. It shapes how deals get priced, structured, and approved.

Why travel and hospitality attracts AML scrutiny

Anti-money laundering (AML) refers to the laws and controls designed to stop criminals from disguising illegally obtained money as legitimate income. Hotels, casinos, tour operators, and travel agents are attractive laundering vehicles for three reasons:

  • High cash volumes: resorts, casino-hotels, and currency exchange desks handle large cash flows that can mask illicit funds.
  • Cross-border movement: international bookings, multi-currency payments, and offshore ownership structures make tracing money harder.
  • Bundled services: a single transaction (room, spa, gaming chips, tour package) can blend legitimate and illegitimate funds.

This is why casino-hotels in the US are classified as "financial institutions" under the Bank Secrecy Act (BSA) of 1970, the foundational US AML law. That means casinos must file

Currency Transaction Reports (CTRs)
for cash transactions over $10,000, and
Suspicious Activity Reports (SARs)
when something looks off, regardless of dollar amount. The regulator enforcing this is the
Financial Crimes Enforcement Network (FinCEN)
, part of the US Treasury.

KYC: the practical front line

Know Your Customer (KYC) is the set of identity-verification procedures that businesses run before or during a transaction. In hospitality, KYC shows up as:

  • Passport or ID checks at check-in, especially for cash payments or long stays.
  • Source-of-funds questions for large advance deposits (common at luxury resorts and destination wedding venues).
  • Enhanced due diligence for politically exposed persons (PEPs), individuals in prominent public roles who carry higher corruption risk.

Europe's equivalent framework runs through the EU Anti-Money Laundering Directives (AMLD), now consolidated into the 2024 AML Regulation (AMLR) and a new supervisory body, the Anti-Money Laundering Authority (AMLA), which becomes operational from 2025 and ramps up through 2026. AMLR extends due diligence obligations to sectors handling high-value goods and large cash sums, which pulls in luxury travel operators and high-end hospitality groups that were previously loosely covered. See the European Commission's AML/CFT overview for the current framework.

Practical effect on deal structuring: a boutique hotel group planning a cash-heavy loyalty or timeshare-style prepayment scheme will now budget for compliance staff, KYC software, and reporting infrastructure before launch, not after a regulator inquiry.

Tourist taxes: small line items, big pricing effects

Tourist taxes (also called occupancy taxes, city taxes, or lodging taxes) are levies charged per night or per stay, collected by hotels on behalf of local or national governments. They are not AML tools, but they shape pricing architecture the same way tax rules always do: through compliance burden and disclosure requirements.

Examples as of 2025-2026 (estimates, rates change frequently and vary by city/season):

  • Venice charges a day-tripper access fee (separate from its overnight tourist tax) that has expanded since its 2024 pilot.
  • Barcelona layers a municipal tax on top of a regional Catalan tourist tax, both charged per night.
  • New York City hotel guests face a mix of state sales tax, city tax, and a flat "hotel unit fee."

For operators, the compliance burden is real: each jurisdiction has its own remittance schedule, exemption rules (children, disability, length-of-stay caps), and audit requirements. A hotel chain operating in ten European cities may be filing tourist tax remittances under ten different local rule sets. This is why online travel agents (OTAs) like Booking.com and Expedia now itemize these taxes separately at checkout: it is often a legal disclosure requirement, not just transparency marketing.

VAT and cross-border payments: where deal structuring gets technical

Value Added Tax (VAT) is a consumption tax applied at each stage of the supply chain, standard across the EU and UK, absent at the federal level in the US (where sales tax applies instead, state by state).

Travel has a special EU regime: the Tour Operators' Margin Scheme (TOMS), which taxes VAT only on the *margin* a tour operator earns, not the full package price, when they buy and resell travel services (flights, hotels, transfers) in their own name. This exists because tour packages often bundle services from multiple countries with different VAT rates, and taxing gross revenue would create absurd double-taxation problems. TOMS is why many European tour operators structure contracts carefully around whether they are "acting as principal" (buying and reselling, TOMS applies) versus "acting as agent" (booking on behalf of the client, standard VAT rules apply). That single legal distinction changes the tax base and, often, the deal's profitability.

Cross-border payment regulation adds another layer. The EU's Payment Services Directive 2 (PSD2), in force since 2018 and still the operative framework in 2026, requires Strong Customer Authentication (SCA), multi-factor verification, for most online card payments. This affects how OTAs and hotel booking engines design checkout flows: friction added for security must be balanced against booking abandonment risk.

In the US, cross-border card payments and remittances fall under FinCEN's broader AML rules plus card network rules (Visa, Mastercard), rather than a single payments directive. There is no US equivalent to PSD2's mandatory SCA, which is part of why EU checkout flows often look "clunkier" than US ones, that's compliance, not bad design.

Worked example: A UK-based tour operator sells a €1,200 package (flight + hotel in Spain) it purchased for €1,000. Under TOMS, VAT applies only to the €200 margin, not the full €1,200. At a simplified 20% rate, VAT owed is €40, not €240. This materially changes whether the deal is worth doing at that price point.

Knowledge check

1. Why are travel and hospitality businesses particularly attractive vehicles for money laundering compared to many other industries?

2. Under the Bank Secrecy Act, why are US casino-hotels specifically classified as 'financial institutions'?

3. A hotel guest pays cash for a large bill that itself is under the reporting threshold, but the front desk staff notices unusual behavior suggesting the payment may be linked to illegal activity. What is the appropriate action under AML rules?

MULTIPLE CHOICE

4. Select ALL correct answers about why cross-border and bundled transactions in hospitality create AML challenges.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL correct answers describing the roles of key AML mechanisms discussed in the lesson.

Select all the correct answers.

Regulatory bodies to know

A quick mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.View full definition → of who enforces what:

| Body | Jurisdiction | Focus |

|---|---|---|

| FinCEN | US | AML/BSA enforcement, SARs, CTRs |

| AMLA | EU (from 2025-2026) | Direct supervision of high-risk AML entities |

| HMRC | UK | VAT, tourist-adjacent tax enforcement |

| National tax authorities | EU member states | VAT/TOMS administration, tourist tax collection |

| FATF | Global | Sets AML/CFT standards states adopt into law |

The Financial Action Task Force (FATF) is worth knowing even though it has no direct enforcement power: it sets the global AML standards that national laws (BSA, AMLR) are built around, and it publishes "grey list" and "black list" countries with weak controls, see the FATF public statements for current listings. A hotel group expanding into a grey-listed jurisdiction should expect enhanced due diligence demands from banks and payment processors.

How this shapes real deals

Put together, these rules quietly steer decisions well beyond the compliance department:

  • M&A due diligence: acquiring a hotel with a history of large unbanked cash transactions means inheriting AML exposure; buyers now demand AML audit trails as standard deal documentation.
  • Pricing architecture: bundling versus unbundling (room-only versus package) can shift VAT treatment and margin exposure under TOMS-style regimes.
  • Market entry: expanding into jurisdictions with new tourist taxes or FATF grey-list status raises both operational cost and reputational risk, often pushing entry timelines back by months.
  • Payment tech investment: PSD2-style SCA requirements mean checkout infrastructure is now a compliance cost center, not just a UX choice.

Key Takeaways

  • AML rules (BSA in the US, AMLR/AMLA in the EU) treat cash-heavy hospitality businesses, especially casino-hotels, as high-risk, requiring KYC, CTRs, and SARs.
  • Tourist taxes are jurisdiction-specific and multiply compliance complexity fast for multi-city operators; they are a disclosure and remittance burden, not just a guest-facing fee.
  • VAT treatment in travel hinges on legal structuring (principal versus agent), with the EU's TOMS taxing only margin, not gross package price, materially changing deal economics.
  • Cross-border payment rules like PSD2's Strong Customer Authentication add friction and cost to booking flows in the EU, with no direct US equivalent.
  • FATF sets global AML standards; a country's grey-list or black-list status directly affects due diligence costs and market entry timing for hospitality investors.

Previous

Your data, their booking: privacy law across the guest journey