# Money in, money out: anti-money-laundering and tax rules that shape deals
A guest walks into a Miami hotel and pays cash for a two-week stay, upfront, no questions asked, or so it seems. Behind the desk, that transaction is quietly triggering compliance obligations the guest never sees: identity checks, reporting thresholds, and a paper trail that regulators can pull years later. Travel and hospitality moves enormous sums across borders, in cash, cards, and crypto, which makes it a natural target for money laundering and a priority for tax authorities. Understanding these rules is not a back-office detail. It shapes how deals get priced, structured, and approved.
Anti-money laundering (AML) refers to the laws and controls designed to stop criminals from disguising illegally obtained money as legitimate income. Hotels, casinos, tour operators, and travel agents are attractive laundering vehicles for three reasons:
This is why casino-hotels in the US are classified as "financial institutions" under the Bank Secrecy Act (BSA) of 1970, the foundational US AML law. That means casinos must file
Know Your Customer (KYC) is the set of identity-verification procedures that businesses run before or during a transaction. In hospitality, KYC shows up as:
Europe's equivalent framework runs through the EU Anti-Money Laundering Directives (AMLD), now consolidated into the 2024 AML Regulation (AMLR) and a new supervisory body, the Anti-Money Laundering Authority (AMLA), which becomes operational from 2025 and ramps up through 2026. AMLR extends due diligence obligations to sectors handling high-value goods and large cash sums, which pulls in luxury travel operators and high-end hospitality groups that were previously loosely covered. See the European Commission's AML/CFT overview for the current framework.
Practical effect on deal structuring: a boutique hotel group planning a cash-heavy loyalty or timeshare-style prepayment scheme will now budget for compliance staff, KYC software, and reporting infrastructure before launch, not after a regulator inquiry.
Tourist taxes (also called occupancy taxes, city taxes, or lodging taxes) are levies charged per night or per stay, collected by hotels on behalf of local or national governments. They are not AML tools, but they shape pricing architecture the same way tax rules always do: through compliance burden and disclosure requirements.
Examples as of 2025-2026 (estimates, rates change frequently and vary by city/season):
For operators, the compliance burden is real: each jurisdiction has its own remittance schedule, exemption rules (children, disability, length-of-stay caps), and audit requirements. A hotel chain operating in ten European cities may be filing tourist tax remittances under ten different local rule sets. This is why online travel agents (OTAs) like Booking.com and Expedia now itemize these taxes separately at checkout: it is often a legal disclosure requirement, not just transparency marketing.
Value Added Tax (VAT) is a consumption tax applied at each stage of the supply chain, standard across the EU and UK, absent at the federal level in the US (where sales tax applies instead, state by state).
Travel has a special EU regime: the Tour Operators' Margin Scheme (TOMS), which taxes VAT only on the *margin* a tour operator earns, not the full package price, when they buy and resell travel services (flights, hotels, transfers) in their own name. This exists because tour packages often bundle services from multiple countries with different VAT rates, and taxing gross revenue would create absurd double-taxation problems. TOMS is why many European tour operators structure contracts carefully around whether they are "acting as principal" (buying and reselling, TOMS applies) versus "acting as agent" (booking on behalf of the client, standard VAT rules apply). That single legal distinction changes the tax base and, often, the deal's profitability.
Cross-border payment regulation adds another layer. The EU's Payment Services Directive 2 (PSD2), in force since 2018 and still the operative framework in 2026, requires Strong Customer Authentication (SCA), multi-factor verification, for most online card payments. This affects how OTAs and hotel booking engines design checkout flows: friction added for security must be balanced against booking abandonment risk.
In the US, cross-border card payments and remittances fall under FinCEN's broader AML rules plus card network rules (Visa, Mastercard), rather than a single payments directive. There is no US equivalent to PSD2's mandatory SCA, which is part of why EU checkout flows often look "clunkier" than US ones, that's compliance, not bad design.
Worked example: A UK-based tour operator sells a €1,200 package (flight + hotel in Spain) it purchased for €1,000. Under TOMS, VAT applies only to the €200 margin, not the full €1,200. At a simplified 20% rate, VAT owed is €40, not €240. This materially changes whether the deal is worth doing at that price point.
Vérification des acquis
1. Why are travel and hospitality businesses particularly attractive vehicles for money laundering compared to many other industries?
2. Under the Bank Secrecy Act, why are US casino-hotels specifically classified as 'financial institutions'?
3. A hotel guest pays cash for a large bill that itself is under the reporting threshold, but the front desk staff notices unusual behavior suggesting the payment may be linked to illegal activity. What is the appropriate action under AML rules?
4. Select ALL correct answers about why cross-border and bundled transactions in hospitality create AML challenges.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers describing the roles of key AML mechanisms discussed in the lesson.
Sélectionnez toutes les réponses correctes.
A quick mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.Voir la définition complète → of who enforces what:
| Body | Jurisdiction | Focus |
|---|---|---|
| FinCEN | US | AML/BSA enforcement, SARs, CTRs |
| AMLA | EU (from 2025-2026) | Direct supervision of high-risk AML entities |
| HMRC | UK | VAT, tourist-adjacent tax enforcement |
| National tax authorities | EU member states | VAT/TOMS administration, tourist tax collection |
| FATF | Global | Sets AML/CFT standards states adopt into law |
The Financial Action Task Force (FATF) is worth knowing even though it has no direct enforcement power: it sets the global AML standards that national laws (BSA, AMLR) are built around, and it publishes "grey list" and "black list" countries with weak controls, see the FATF public statements for current listings. A hotel group expanding into a grey-listed jurisdiction should expect enhanced due diligence demands from banks and payment processors.
Put together, these rules quietly steer decisions well beyond the compliance department: