Original research - checked 2026-07-25
Research question
Which components make an online casino operational, and what must a buyer verify beyond the feature list?
Methodology
- Scope: the named product sample or control areas in the evidence matrix below.
- Sources: current official supplier pages, regulators, government standards, open standards, and testing guidance.
- Classification: Yes is explicit support; Partial is incomplete support; Not found is no evidence in the reviewed public source; Unknown is not evaluated.
- Checked: 2026-07-25. This is a point-in-time public-evidence record.
- No inference: a general standard does not prove a supplier implementation, and a missing public disclosure does not prove a missing capability.
Evidence matrix
| Stack component | Primary anchor | Public support | Evidence | Failure or acceptance test | Boundary | Primary source |
|---|---|---|---|---|---|---|
| PAM and identity | GLI-19 and UKGC RTS | Yes | Lifecycle, status, access, session, limit, exclusion, and audit records | Restrict an account across all products | Exact requirements vary by market | Gaming Laboratories International |
| Wallet and ledger | GLI-19 | Yes | Money-event model, references, adjustments, reconciliation, and approvals | Duplicate, delay, fail, retry, and reconcile | Ledger architecture is product-specific | Gaming Laboratories International |
| Payments | PCI DSS | Partial | Flow, scope, PSP roles, tokenization, reconciliation, fraud, and incident ownership | Fail a deposit and withdrawal dependency | PCI applicability follows the actual design | PCI Security Standards Council |
| Games, RNG, and aggregation | GLI-19 and UKGC testing | Yes | Provider, title, version, market, test, approval, configuration, and release ledger | Withdraw and replace an affected version | Game and market assurance differ | UK Gambling Commission |
| KYC and AML | FATF Recommendations | Yes | CDD, risk, monitoring, cases, reporting, recordkeeping, and ownership | Trace normal, high-risk, and exception cases | Local implementation fixes thresholds | FATF Recommendations |
| Bonus and CRM | UKGC RTS | Partial | Eligibility, consent, rules, state, ledger, expiry, suppression, and dispute evidence | Run award through cancellation and complaint | Commercial logic remains product-specific | UK Gambling Commission |
| Reporting and audit | GLI-19 | Yes | Cross-module event dictionary, regulatory outputs, operational metrics, and export records | Reconcile one business day end to end | Report schemas vary by authority | Gaming Laboratories International |
| Application security | OWASP ASVS | Yes | Versioned requirements, threat model, test results, remediation, and exceptions | Run agreed verification on the release candidate | Set the verification level by risk | OWASP |
| Reliability and operations | AWS Reliability Pillar | Yes | SLOs, capacity, dependency map, observability, RTO/RPO, incidents, and drills | Exercise peak load and dependency failure | Guidance is not a supplier SLA | AWS Well-Architected |
| Data and exit | ICO contract and portability guidance | Partial | Roles, instructions, subprocessors, schemas, export, transition, deletion, and audit | Produce a usable bulk export and deletion record | Portability rights and commercial export are not identical | UK ICO |
Findings
1. The product is a system of records and responsibilities
PAM, wallet, payments, games, controls, reporting, and operations need joined identifiers and named owners.
2. A feature list hides failure behavior
Retries, duplicates, partial failure, rollback, correction, reconciliation, and dispute evidence determine whether the stack is operable.
3. Regulated scope is versioned
Entity, jurisdiction, product version, game version, configuration, supplier, and effective date belong in the evidence model.
4. Data exit is broader than a download button
Schemas, history, referential integrity, media, audit data, timing, assistance, deletion, and replacement support must be tested.
How to use the evidence
- Remove fields that are not applicable to the target entity, market, product, and operating model; document why.
- Assign one accountable owner and one evidence artifact or test to every retained field.
- Keep Yes, Partial, Not found, and Unknown separate through RFP, demo, test, reference, and contract review.
- Convert supplier-specific gaps into versioned proposal, implementation, SLA, data, security, and exit schedules.
- Re-check source versions and effective dates before a procurement or launch decision.
Limitations
The map is a buyer evidence framework, not a complete architecture, legal opinion, certification, or implementation estimate. Applicability changes with the target jurisdiction, licence, payment design, data role, suppliers, and product configuration.
Primary sources
- Gaming Laboratories International - GLI-19 Interactive Gaming Systems v3.0 - A public interactive-gaming system control reference covering accounts, games, transactions, reporting, security, and operational controls.
- UK Gambling Commission - Remote gambling and software technical standards - Great Britain remote gambling software controls and current technical-standard verification questions.
- UK Gambling Commission - Testing strategy for remote gambling software - Testing, release, audit, change-control, and independent-assurance expectations for relevant Great Britain licensees.
- FATF Recommendations - Risk-based AML/CFT, customer due diligence, monitoring, recordkeeping, reporting, and country-implementation questions.
- PCI Security Standards Council - PCI DSS - Payment-account data security requirements for relevant merchants, processors, service providers, and connected systems.
- OWASP - Application Security Verification Standard - Versioned and testable web-application security requirements that can be used in procurement and verification.
- AWS Well-Architected - Reliability Pillar - Reliability design, failure recovery, change management, capacity, testing, and dependency-management questions.
- UK ICO - Contracts and liabilities between controllers and processors - Controller-processor contract fields, instructions, confidentiality, security, sub-processors, assistance, audit, and end-of-contract provisions.
- UK ICO - Right to data portability - Structured, commonly used, machine-readable personal-data export principles within the right's defined scope.
Frequently asked questions
Does a Yes classification prove that a supplier complies?
No. Yes means the cited primary source explicitly supports the control or disclosure field. Supplier implementation still requires current product evidence and buyer verification.
Does Not found mean a capability is absent?
No. It means the reviewed public sources did not expose the evidence. Authenticated documentation, tests, proposals, or contracts may change the classification.
Can the CSV be used as an RFP starting point?
Yes, after adapting applicability, ownership, evidence, tests, and legal requirements to the target entity, jurisdiction, product, and operating model.
Concept map
Related concepts and decision guides
- Online Casino Software Research
- Use dated primary-source crosswalks and downloadable evidence matrices to turn software claims into buyer-owned verification tasks.
- casino software solutions
- Learn the systems, decisions, and launch paths behind an online casino.
- Online Casino Software Components
- Map the core and optional modules in an operator stack.
- Online Casino Software Learning Path
- Learn the operator modules in sequence, from player identity and games to payments, compliance, mobile UX, and administration.
- KYC AML
- Understand verification, monitoring, limits, and operator accountability.
Evidence layer
Primary references and verification limits
Sources were checked on . They support the standards and verification questions used in this guide. They do not prove a supplier-specific price, market eligibility, implementation result, or private product claim; buyers should request current, versioned evidence for those points.
- Gaming Laboratories International - GLI-19 Interactive Gaming Systems v3.0 Testing-laboratory standard. A public interactive-gaming system control reference covering accounts, games, transactions, reporting, security, and operational controls.
- UK Gambling Commission — Remote gambling and software technical standards Regulator. Remote gambling software controls, security requirements, player-facing technical controls, and jurisdiction-specific verification questions.
- UK Gambling Commission — Testing strategy for remote gambling software Regulator. Testing, release control, audit evidence, change management, independent review, and production assurance questions.
- FATF Recommendations Intergovernmental standard setter. Risk-based AML/CFT controls, customer due diligence, monitoring, recordkeeping, and country-specific implementation questions.
- PCI Security Standards Council — PCI DSS Industry standards body. Payment account data security requirements for merchants, processors, service providers, and systems that can affect the cardholder data environment.
- OWASP - Application Security Verification Standard Open application-security standard. Versioned and testable web-application security requirements that can be used in procurement and verification.
- AWS Well-Architected - Reliability Pillar Cloud architecture guidance. Reliability design, failure recovery, change management, capacity, testing, and dependency-management questions.
- UK ICO - Contracts and liabilities between controllers and processors Data-protection regulator. Controller-processor contract fields, instructions, confidentiality, security, sub-processors, assistance, audit, and end-of-contract provisions.
- UK ICO - Right to data portability Data-protection regulator. Structured, commonly used, machine-readable personal-data export principles within the right's defined scope.
- OWASP Application Security Verification Standard Open application-security standard. Testable web-application security requirements and procurement-ready verification criteria.