The audit cycle GICNT sets for each of its six standards is deliberately different: licensing status is reviewed once a year, player protection twice, fair play at the level of the individual game. The variation is not administrative untidiness. It tracks how quickly the underlying risk changes, and how fast evidence of compliance goes stale between one assessment and the next.
Why the Six Standards Do Not Share One Audit Clock
Audit frequency across iGaming compliance regimes is a risk judgement rather than a scheduling convenience. A licence is a comparatively stable object. It exists, or it has been suspended, surrendered or varied, and each of those events is recorded in a register an auditor can read. A responsible gambling programme behaves differently. Its rules change with every regulatory consultation, its thresholds live in software configuration, and the player population it protects turns over continuously.
Regulators already work this way, even where they never use the word cycle. The Gambling Commission requires an annual security audit against relevant sections of ISO/IEC 27001:2022, yet insists that a new game is tested by an approved test house before release, at no fixed point in the calendar. The Malta Gaming Authority schedules a system review roughly one year after licence issuance, then calls compliance audits according to the risk profile and compliance history of the licensee, with completion required within 90 days of its notice. The Advertising Standards Authority builds its casework on complaints.
The audit cycles GICNT applies mirror that logic across the six compliance domains of the framework. Each domain is assessed at the interval at which its evidence remains meaningful, and no more often, because an assessment repeated faster than the evidence changes produces paperwork instead of assurance.
Review Frequency by Standard
All six domains carry Mandatory status, so a certified operator is never inside one cycle. It is inside six, running in parallel, each with its own trigger for an off-schedule reassessment.
| Code | Domain | Review cycle | What resets the clock early |
|---|---|---|---|
| GICNT-LS | Licensing and legal status | Annual review | Change of licence status, ownership or served jurisdiction |
| GICNT-PP | Player protection and responsible gambling | Bi-annual audit | New player protection rules in a served market, or a change to register integration |
| GICNT-AML | Anti-money laundering and KYC | Annual third-party audit | Material change to the business risk assessment or the payment mix |
| GICNT-FP | Fair play and game integrity | Game-level certification | A new game, or an update that affects fairness |
| GICNT-DS | Data protection and cybersecurity | Annual security assessment | Infrastructure migration, or a reportable security incident |
| GICNT-AM | Advertising and marketing standards | Complaint-triggered review | A substantiated complaint about a campaign, creative or affiliate placement |
The licensing status requirements sit underneath the whole structure. A lapsed or suspended licence makes every other assessment moot, which is why that domain is the one checked on a fixed annual date rather than on an event trigger alone.
What the Annual Licence Status Review Verifies
An annual review of licence status is a re-verification exercise, not a re-reading of the original application. The auditor returns to the primary source, meaning the public register of the issuing authority, and confirms that the entity named on the certificate still holds the licence number, licence type and permitted game verticals recorded twelve months earlier. Where the register lists conditions, those are compared against the conditions on file.
Reporting obligations run on their own clock underneath that annual check. MGA licence conditions require audited financial statements within six months of the financial year end and auditor declarations on player funds and gaming revenue within nine months, so a licensee can be in good standing on the register while being late on a submission that will surface at the next supervisory contact.
Between two annual reviews, the events that most often invalidate the earlier finding are these:
- a change of control, or a new ultimate beneficial owner entering the structure
- entry into a new market, which adds a licence, a local representative or a blocked market to the picture
- a variation of licence conditions imposed by the authority
- an open enforcement matter, including a public consultation on suspension
- the departure of a key person whose approval was tied to the licence
Why Player Protection Carries a Bi-Annual Audit
Audit requirements for responsible gambling controls date faster than any other part of the framework, which is the reason GICNT-PP is assessed twice a year rather than once. Two things move underneath it at the same time: the rules of each served market, and the operator configuration that implements them.
The pace is visible in the primary sources. The Gambling Commission amended licence condition 15.3.1 on 1 July 2024 so that every licensee files regulatory returns quarterly, within 28 days of the quarter end, replacing the mixed annual and quarterly pattern that preceded it. Measures from the 2023 white paper have been introduced in tranches rather than in one commencement date. Ontario is standing up a centralised self-exclusion programme under the Registrar’s standard 2.14.1, which changes what an operator there must connect to and what it must be able to demonstrate.
A six-month cadence is short enough to catch the things that a twelve-month one would miss:
- deposit and loss limit logic that was altered during a platform release and never re-tested
- reality check intervals silently reset to a supplier default after a migration
- integration with national self-exclusion registers that fails on a subset of accounts, typically duplicate or legacy records
- interaction records that exist as free text and cannot be sampled by an auditor
- a new market launched between audits with the responsible gambling configuration of the previous market
The AML Cycle Rests on an External Auditor
GICNT-AML requires an annual AML audit of online gambling operators performed by a third party, and the choice of an external reviewer matters as much as the interval. Statute is usually looser on both points. Regulation 21 of the UK Money Laundering Regulations 2017 requires an independent audit function where that is appropriate to the size and nature of the business, without naming a frequency, which in practice produces intervals ranging from annual to every two or three years, decided by the firm itself.
Fixing the interval at twelve months and the reviewer outside the compliance function removes both variables. The scope an external reviewer is expected to cover under this domain includes:
- the business risk assessment, tested for currency against the markets, products and payment methods actually live
- customer due diligence and enhanced due diligence files, sampled rather than accepted on policy alone
- screening for politically exposed persons at onboarding and on an ongoing basis
- scenario tuning, alert volumes and false positive rates in transaction monitoring escalation
- the quality and timeliness of suspicious activity reporting, and the record of decisions not to report
- the standing of the money laundering reporting officer, including reporting lines and the record of escalations to senior management
An audit that reviews policies without sampling files does not satisfy the requirement. The evidence an auditor needs is the record of a decision made on a real customer, with a date and a named decision maker attached.
Fair Play Certification Attaches to the Game, Not the Calendar
GICNT-FP is the one domain with no periodicity at all, because RNG testing and certification for games is event-driven everywhere it is regulated seriously. A random number generator and a maths model do not degrade with time. They change when code changes, so the trigger is the change, not the anniversary.
The Gambling Commission model is the clearest published statement of this. New games and RNGs must be tested by an approved test house and the report supplied before release. Updates are classified as major or minor, where a major update is any software change that may affect the fairness of a game, including changes to the RNG, to scaling and mapping, or to the underlying maths and rules. Where a platform or RNG change affects many games at once, a representative sample spanning game types and generations must be retested before the updated component goes live. Ontario takes a comparable position by requiring games and critical gaming systems to be certified by an independent testing laboratory before go-live.
| Event | Testing consequence | Evidence retained |
|---|---|---|
| New game or new RNG | Full external test before release | Test report with certificate reference, RTP and digital signature |
| Update affecting maths, rules or RNG | External retest as a major change | Updated report referencing the superseded version |
| Cosmetic or display-only update | Internal testing under change control | Change record with the classification and its justification |
| Platform or RNG migration | Integration testing on a representative sample of games | Single test report covering the sample and its scope |
| New delivery channel for an existing game | Limited external test of the player interface | Report cross-referenced to the original game test |
What does run annually in this domain is the audit of the process rather than of the game. Under the Commission testing strategy, an approved test house samples major and minor classifications, checks change control, confirms the live games list and reviews live return to player monitoring, with submission deadlines staggered across four pools and due four weeks after the audit period ends. The RNG certification obligations recognised under this standard cover eCOGRA, iTech Labs, BMM Testlabs or equivalent accredited laboratories.
How the Annual Security Assessment Under GICNT-DS Is Scoped
An annual security assessment of gambling operators has a settled shape in regulated markets, and GICNT-DS follows it. The Gambling Commission requires remote licensees to undergo an annual security audit by an independent and suitably qualified auditor against the security requirements of the remote technical standards, which are based on relevant sections of ISO/IEC 27001:2022. A newly licensed operator must complete a first audit within six months of the licence grant. Reports stay on file unless requested, but a major non-conformity must be reported without delay, and the full report supplied within 7 days.
Certification against the ISO standard is not the same instrument. An ISO/IEC 27001 certificate runs on a three-year cycle: initial certification, surveillance audits sampling a subset of controls in years one and two, then recertification in year three. A valid certificate therefore proves that a management system passed a sampled review, not that a full assessment happened in the last twelve months, and an auditor asked for evidence of an annual assessment will want the surveillance report and its scope, not the certificate alone.
The breach clock is where this domain is stricter than one of the laws it maps to. GICNT-DS sets a single 72-hour notification window for every certified operator. That mirrors the GDPR deadline, and it exceeds what Canadian law requires: PIPEDA obliges an organisation to report a breach of security safeguards creating a real risk of significant harm as soon as feasible, with no fixed hour count. Operators serving both regions should treat 72-hour breach notification as a certification requirement rather than as a restatement of local law.
Advertising Review Under GICNT-AM Starts With a Complaint
A complaint-triggered review is the standard model for advertising oversight, and it works because a complaint carries the one thing a scheduled audit lacks: a specific artefact, seen by a specific person, at a known time. Scheduled review of a marketing function tends to inspect approval policy. A complaint puts the creative itself on the table.
The limits of a purely reactive model are also on the record. The Advertising Standards Authority now supplements complaints with proactive sweeps, capturing 1,845 organic Instagram posts from 18 gambling operators through its active ad monitoring system and reviewing content from August 2025 to March 2026, with a parallel desk review of posts on X. It upheld complaints on 27 May 2026 against Betway and Cyan Blue Odds, trading as Oddschecker, over Instagram posts featuring current footballers, finding the ads likely to be of strong appeal to under-18s and therefore irresponsible. A CAP enforcement notice followed, with active monitoring from 11 June 2026, alongside monitoring of app store listings from 26 May 2026.
For an operator, the practical consequence is that a reactive cycle only functions if the underlying records survive long enough to answer a complaint months later. Under the advertising and marketing standards of the framework, the retained set should cover:
- every creative variant published, with placement, channel and live dates
- targeting parameters, including exclusions applied to protect minors and self-excluded players
- the approval record, naming who signed off and against which code
- affiliate creatives, treated as the material of the operator rather than of the partner
- the bonus terms visible at the point the promotion ran, not the terms currently on the site
What Operators Must Evidence Between Scheduled Audits
Nothing in a periodic cycle suspends the underlying obligations, and most audit findings concern the gap between two assessments rather than the state of things on audit day. The continuous controls below are what an auditor reconstructs after the fact.
| Control | Operating cadence | What the auditor asks for |
|---|---|---|
| Licence register verification | Monthly and on any corporate event | Dated register extract for each licence held |
| Self-exclusion register synchronisation | As the market requires, in several regimes before each session | Synchronisation logs, including failures and their resolution |
| Transaction monitoring alerts | Daily | Alert queue with disposition, reviewer and timestamp |
| Live return to player monitoring | Rolling, scaled to volume of play | Variance reports against theoretical RTP per game and channel |
| Game change control | Per release | Change record with major or minor classification and justification |
| Marketing approval log | Per campaign | Creative, approver, code referenced and live dates |
| Incident register | Continuous | Timeline from detection to notification, with the decision on reportability |
For operators approaching certification for the first time, the same list doubles as a readiness test, which is why it overlaps heavily with the pre-launch compliance checklist for the six domains.
Mapping the Cycles Onto a Twelve-Month Calendar
Six parallel cycles collapse into a workable plan once each one is anchored to a fixed month and to an owner. A common arrangement across a compliance year looks like this:
- Q1: player protection audit, first pass. Reconcile every served market against rule changes made in the previous six months.
- Q2: annual licence status review, aligned with statutory financial reporting so that register checks and auditor declarations move together.
- Q3: external AML audit, scheduled after the annual refresh of the business risk assessment rather than before it.
- Q4: security assessment and penetration testing, then the player protection audit, second pass, closing the year on the fastest-moving domain.
- Continuous: game certification on release, and advertising review whenever a complaint or a monitoring hit lands.
Operators building this schedule from nothing usually sequence it in the order set out in compliance for new operators, starting with the domains whose evidence takes longest to accumulate. An external AML audit cannot sample twelve months of files that do not yet exist, so the first cycle in a new operation is always the thinnest one, and the framework treats the second as the first meaningful test.
Frequently Asked Questions About GICNT Audit Cycles
How often is a certified operator reassessed overall?
There is no single interval. Licensing status, AML and data security are assessed annually, player protection twice a year, and advertising on a complaint trigger, while fair play is certified per game and per fairness-affecting update. In practice a certified operator has at least one assessment activity open in most quarters.
Does a licence change between annual reviews need to be reported?
Yes. A change of licence status, of ownership or of served jurisdiction resets the GICNT-LS finding, because the annual review recorded a position that no longer holds. The same applies to a variation of licence conditions imposed by the issuing authority.
Is a third-party AML audit the same as a regulator compliance audit?
No. A regulator audit tests compliance with the conditions of a specific licence and is called at the discretion of that authority. The GICNT-AML audit tests the programme against the certification standard on a fixed annual interval, and both can find issues the other does not, since their scopes and triggers differ.
Does every game update require new certification?
Only updates that can affect fairness. Changes to the random number generator, to scaling and mapping, or to the maths and rules require external retesting before release. Display, sound and interface changes are handled under internal change control, with the classification and its justification documented for later review.
Does an ISO 27001 certificate satisfy the annual security assessment?
Not on its own. The certificate covers a three-year cycle in which years one and two are sampled surveillance audits. Evidence of a current assessment means the surveillance or recertification report and its scope, showing that the systems in scope for certification were actually examined during the last twelve months.