RNG certification for an online casino game is issued by a testing laboratory, not by the operator that runs it. That split does not move the obligation. Licensing authorities hold the licensee accountable for making sure every game, random number generator and platform component behind it carries valid evidence of testing, and for recognising the moment that evidence stops being valid.
What an RNG Certification Report Must Contain
A certificate is worth only as much as the fields it names. The Gambling Commission sets minimum contents for both RNG and game test reports in its testing strategy, updated on 31 October 2025, and that list works as a template in markets that publish no equivalent guidance. The fair play requirements under GICNT-FP treat a report missing these fields as incomplete evidence rather than as proof that testing happened.
An RNG report should name:
- the test house, including the supervisor who signed the testing off
- the licensee, the date of testing and a certificate reference
- the RNG itself: a description, its version, whether it is hardware or software, and its digital signature
- the scope and approach, with every test applied described
- the platform supplier and platform version
- any limitations on use, such as the acceptable degrees of freedom, suitability for selection with or without replacement, and dependency on operating system functionality like Java SecureRandom
- the results
A game report adds the game name, the theoretical return to player, the software number and digital signature, the channels covered by testing, and details of any game versions the tested build supersedes. Where scope was narrowed because only part of an existing game changed, the updated report has to reference the original one, the changes made, the testing completed and the new digital signatures.
British licensees submit these reports through eServices before release, never after. A B2C licensee that takes content from a supplier still maintains its own games register covering everything offered under its licence.
Game Testing and RNG Testing Answer Different Questions
The game testing requirements that apply to gambling operators split into layers, and each layer has its own trigger for re-examination. Confusing them is how operators end up holding a valid certificate that covers the wrong thing.
| Layer | What the laboratory examines | What triggers a fresh look |
|---|---|---|
| Random number generator | Documentation review, research into publicly known weaknesses in the algorithm or hardware, source code review against the documentation, statistical testing of raw output and of scaled or shuffled deck data | Any change to the RNG |
| Game maths and rules | Design verification covering the maths, the artwork, the player-facing rules and the theoretical RTP | Changes to pay tables, symbol distribution or feature rules |
| Game software | Simulation over a volume of play set by the volatility of the game, emulation of rare outcomes such as jackpot triggers, manual play, and verification of scaling and mapping | Changes to how the rules are implemented in code |
| Platform or remote gaming server | Integration testing on an environment that reflects the intended live one | An RGS or RNG update that could affect the games it serves |
| Channel or game client | The user interface and player display, typically a manual test of how results are shown | Porting an existing game to a new client |
| Live dealer studio | Equipment quality, croupier training records, supervision, video coverage of the gaming area, game logs | A new studio or a material change to its procedures |
All of this usually sits inside one commercial engagement, which is why the scope agreed with the laboratory does more work than the choice of laboratory. A narrow scope is the most common reason a certificate cannot answer the question an auditor is actually asking.
eCOGRA, GLI, BMM and iTech Labs: What Separates the Laboratories
Reputation matters less than jurisdictional approval. The Gambling Commission publishes a list of approved test houses and updates it periodically; the version dated 2 March 2026 names BMM Testlabs (South Africa), BMM Spain Testlabs SL, eCOGRA Limited, Gaming Associates Europe, several GLI entities, Global Lab, iTech Global, Nick Farley & Associates, Quinel and RiskCherry. Approval is granted by area, so a house cleared for the remote technical standards is not automatically cleared for gaming machine categories. Every approved house must hold full accreditation to BS EN ISO/IEC 17025, plus selected requirements from ISO/IEC 17065 and ISO/IEC 27002.
ITL certification in Ontario works on the same principle with a different list. Only laboratories registered with the AGCO may issue certifications the Registrar recognises, and games, random number generators and the system components that accept, process, determine, display and log player bets cannot be deployed in the province without one, assessed against the AGCO Registrar’s Standards.
| Laboratory | Origin | Position in the market |
|---|---|---|
| eCOGRA | Founded 2003, United Kingdom | Online gambling specialist, accredited under ISO/IEC 17025 and also under ISO/IEC 17021-1:2015, which covers third party certification of information security management systems |
| GLI | Founded 1989, Lakewood, New Jersey | Publishes GLI-19 for interactive gaming systems and GLI-33 for event wagering systems; version 3.0 of GLI-19 was issued in 2020 and covers platform, RNG and game requirements |
| BMM Testlabs | Operating since the early 1980s | Appears on the British list through separate national entities whose approvals differ, so the approval attaches to the entity rather than to the brand |
| iTech Labs | Founded 2004, Australia | A wholly owned subsidiary of GLI Australia since May 2023, still operating under its own brand and its own jurisdictional licences |
The practical failure mode is appointing a well known laboratory and discovering later that it holds no approval for the product category or the market in question. Where a jurisdiction publishes no list at all, GICNT-FP looks for one of the recognised houses or an equivalent laboratory holding comparable accreditation.
Certification Attaches to the Game, Not to the Operator
An operator is not certified. A product, a version and a platform combination is certified, and the operator holds the paperwork. That distinction drives several obligations that compliance teams routinely misallocate:
- The AGCO does not prescribe who requests certification. In practice the game provider does, which means the operator inherits a document it never commissioned and has to read closely enough to know what it covers.
- A certificate names a specific build on a specific platform. Move the same game to a different RNG or a different remote gaming server and the tested combination no longer exists.
- Where an RGS or RNG update touches hundreds of games at once, a representative sample must be retested before the updated component goes live. The sample has to span each game type and generation, not just titles with similar characteristics.
- A B2C licensee relying on a supplier receives a games register reference and uploads it to its own register. The reference is not a substitute for the register.
GICNT-FP is the only domain in the framework assessed at the level of an individual game rather than on a calendar, which is why it sits apart from the other certification audit cycles. Nothing about it displaces testing required by a licensing authority. It assesses whether the operator’s evidence holds together.
When a Game Update Forces External Retesting
Game recertification after an update is where classification decisions quietly become licensing decisions. Two mature markets handle the same problem with different vocabulary.
| Great Britain | Ontario | |
|---|---|---|
| Classification | Major or minor | Non-regulatory, regulatory, or regulatory fix |
| Threshold | Major means any software change that may affect fairness: the RNG, scaling and mapping, or the game rules, including how the software processes them | Regulatory means related to compliance with the Standards, including a design change that could touch a standard |
| Before deployment | Major changes need external retesting by an approved test house before release | Regulatory modifications must be certified before deployment |
| Emergency route | None. Testing precedes release | An emergency fix to a live integrity issue may be deployed first, then submitted to a registered ITL within 5 business days |
| Records | Change ID, product identifier, delivery channels, description, classification with justification, and the authorisation of a personal management licence holder | Classification records retained by the supplier and produced to the AGCO on request |
| Oversight | An annual games testing audit by an approved test house samples major and minor calls, confirms the live games list and reviews RTP monitoring | The Registrar may call for records, and an invalid prior certification cannot be relied on |
British guidance draws the line at implementation, not intent. A fix for inefficient logging that changed how game symbol arrays were constructed counts as major, because the software implementation of the rules changed even though the rules themselves did not. Sound format changes for a mobile operating system update, or a character’s hat colour changing because image rights expired, stay minor.
Getting this wrong is not a development problem. Non-compliance with the technical standards is a breach of the LCCP licence conditions and reportable as an event notification, and the annual audit exists specifically to test whether classifications were honest. Audit periods run in four staggered pools, with submission due four weeks after the period ends.
Operators Must Make RTP Available Before the Player Commits
Disclosure requirements for RTP vary more than most operators expect, and the British rule is looser than its reputation suggests. RTS requirement 3C asks that information enabling an informed decision about the chance of winning be easily available before the customer gambles, and accepts any one of four things: a description of how the game works and how winners are determined, the house edge or margin, the RTP percentage, or the probability of winning events occurring. A numeric figure is one route among four. Where a progressive jackpot is involved, the jackpot RTP must be shown under the same requirement, either combined with the base game or broken out, and players ineligible for the jackpot must be told so along with their own theoretical return.
| Jurisdiction | Minimum RTP | Disclosure rule |
|---|---|---|
| Great Britain | None set | Any one of four items easily available before the gamble, under RTS 3C |
| Malta | 85% average for online games using repetitively generated random selection, lowered from 92% in 2021 | Game rules displayed in full no more than one click from the page where the game is played |
| Italy | 90% of stakes returned as winnings for fixed odds games of chance and card games against the house | Platform and game certified by an accredited conformity body before ADM authorisation |
| Ontario | None set | Games and RNGs certified by an AGCO registered ITL before deployment |
The Maltese floor sits in Article 22 of the Player Protection Directive rather than in the MGA licence types themselves, which is why it survives changes to licence structure. GICNT-FP takes the narrower position across all six domains: the theoretical figure is published for every certified game, and a house edge statement or a probability table is not accepted as a substitute.
What GICNT-FP Expects in the Certification File
Auditors do not assess games. They assess whether an operator can produce, on request, a coherent chain of documents linking every live title to a valid test report. The file that satisfies GICNT-FP contains:
- a current certificate for every live game, naming the version and the platform it was tested on
- the published theoretical RTP for each game, matching the figure in the report
- bonus and wagering terms disclosed to the player before the offer is accepted, not after
- a change log classifying each update, with the reasoning behind each classification and the name of the person who authorised it
- evidence that the issuing laboratory holds approval in each licensed jurisdiction, or comparable accreditation where the jurisdiction publishes no list
- live RTP monitoring output comparing actual against expected, measured at a frequency matched to volume of play and disaggregated by channel and market so that a fault in one client does not vanish into an average
Most of this is assembled once and maintained thereafter. Operators preparing for a first audit will find the same material sitting in the pre-launch compliance checklist, because the evidence a certification body asks for after launch is the evidence a licensing authority asks for before it.
Common Questions About Game Certification
Does an operator need its own RNG certificate if every game comes from a supplier?
No, but it needs the evidence and the register. Under the British model the supplier issues a games register reference that the licensee uploads to its own register, which has to cover every game offered under the licence whether served directly or through a B2B. The obligation to hold and produce the record never transfers to the supplier.
How long does an RNG certificate stay valid?
Certificates are not usually dated to expire. They lapse when the thing they describe changes. Ontario states this explicitly: a modification, or the later discovery of an undetected fault affecting integrity, fairness or security, renders the previous certification invalid. In practice the expiry date is the next material change to the game, the RNG or the platform underneath them.
Is a certificate issued in one jurisdiction accepted in another?
Partly, and never automatically. An ITL certification for Ontario must state whether any part of it relied on testing done for another jurisdiction. Laboratories can often examine only the differences rather than repeating a full evaluation, which shortens multi market releases, but the receiving authority decides what it will accept.
Does porting a game to a new channel require retesting?
Yes, with narrow scope. A new channel must be tested by an approved test house, generally limited to the user interface and how results are displayed, with the report referencing the original test. Where the backend design and functionality are untouched, those elements are not retested. Browser and mobile operating system updates are different again and are usually handled by the licensee’s own testing.
Who is responsible for live RTP monitoring when the games come from a B2B?
Usually the B2B, because it holds the aggregated gaming transactions across all the operators it serves. Contracts have to state who carries the obligation, and the B2C must be told when a game offered under its licence needs to be taken offline. For British licensees, the monitoring process itself is examined in the annual games testing audit.