GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

The GICNT Framework v4.2: Six Compliance Domains

The GICNT framework groups operator assessment into six compliance domains, each with a defined scope, an evidence set and a review cycle. Version 4.2 treats all six as mandatory, so an operator cannot pass five and still carry the mark. That structure is what separates independent certification of iGaming operators from a self-declared compliance statement.

Why the Framework Splits Compliance Into Six Domains

Operators already report to a licensing authority, and that authority looks at the whole business at once. An iGaming compliance framework built for certification works from the opposite direction. It isolates risk areas so that weakness in one place cannot be offset by strength somewhere else, and so that each area is reassessed on a schedule matching how fast its risks move.

The domains cover licensing status, player protection, financial crime controls, game integrity, data security and marketing conduct. All six compliance domains are mandatory for gambling operators seeking the mark, with no optional modules and no partial award. Certification adds independent assurance on top of a licence, and the boundary between certification and licensing matters whenever an operator describes its status to a payment provider, a supplier or a media partner.

GICNT issues no licence and holds no supervisory powers. An operator that loses certification keeps its licence. An operator that loses its licence cannot hold certification at all.

Domain Codes, Scope and Assessment Frequency

Certification standards for online gambling gain little from a single annual sweep. Financial crime controls drift within months, while a licence position changes on the day a regulator publishes a decision. The framework therefore sets the frequency of each operator compliance audit per domain, and audit cycles by standard run on separate clocks.

CodeDomainPrincipal focusAssessment cycle
GICNT-LSLicensing and Legal StatusLicence validity, corporate ownership, market access controlsAnnual Review
GICNT-PPPlayer Protection and Responsible GamblingLimits, self-exclusion, harm detection, intervention recordsBi-Annual Audit
GICNT-AMLAnti-Money Laundering and KYCIdentity verification, source of funds, transaction monitoring, reportingAnnual Third-Party Audit
GICNT-FPFair Play and Game IntegrityRNG certification, RTP disclosure, change control on game buildsGame-Level Certification
GICNT-DSData Protection and CybersecurityData handling, breach response, penetration testing, access controlAnnual Security Assessment
GICNT-AMAdvertising and Marketing StandardsClaim accuracy, targeting rules, affiliate oversightComplaint-Triggered Review

Only GICNT-AM runs on a reactive trigger. Advertising conduct surfaces through what reaches the public, through complaints and through regulator notices, rather than through documents an operator files on schedule.

GICNT-LS Verifies the Licence Behind the Operation

A licence claim is the easiest statement on a gambling site to fabricate and among the easiest to check. GICNT-LS requires the licence to be traceable to the issuing authority’s own register, held by the named corporate entity, and valid for the markets the operator actually serves. The evidence set under licensing and legal status requirements stays documentary throughout:

  • A register entry from the issuing authority, matched to the licensed entity by registered name and company number
  • Ownership and control disclosure covering beneficial owners above the reporting threshold applied by the licensing regime
  • Market blocking evidence showing that restricted territories are enforced at account level rather than stated in terms and conditions
  • A corporate change log, since a change of control or shareholding normally triggers a reporting duty on the operator side

Licence architecture differs enough between jurisdictions that the check cannot run to a single template. The Malta Gaming Authority has issued B2C gaming service licences and B2B critical gaming supply licences under the Gaming Act 2018, with game types 1 to 4 available under one authorisation valid for ten years. Thresholds also move: from 19 March 2026 the Gambling Commission raised the reporting trigger for operator status and relevant persons under LC 15.2.1 from 3% to 5%. An internal reporting matrix has to track changes of that kind rather than restate a figure fixed years earlier.

Player Protection Obligations Under GICNT-PP

GICNT-PP is reassessed twice a year because player protection fails in operations, not in policy documents. A deposit limit that sits in account settings but resets on the operator’s own timetable is a control on paper. Interaction records carry most of the weight: the Gambling Commission’s Social Responsibility Code Provision 3.4.1 obliges licensees to identify customers at risk of harm and to act on what they find, and documentation without intervention has been treated as a failure in its own right. The player protection requirements apply the same test to every market an operator serves.

Exclusion registers stop at the border of the licence that created them, so a multi-market operator connects to several and proves each connection separately.

MarketRegisterOperator duty
Great BritainGAMSTOPCheck every new and existing customer before allowing play
SwedenSpelpausVerify status against the national register, in place since January 2019
NetherlandsCRUKSAutomatic check at registration and at login, mandatory since the KOA regime opened in October 2021
GermanyOASISQuery the central register for both online and land-based play
OntarioCentralized Self-Exclusion ProgramParticipate under Registrar’s Standard 2.14.1 while maintaining the site-level programme under Standard 2.14

Canada has no national scheme. Exclusion works at provincial level, and the Ontario programme set out in Registrar’s Standard 2.14.1 reaches only sites regulated in that province. An operator serving several Canadian provinces cannot describe its coverage as national, and GICNT-PP treats that wording as a misstatement rather than a rounding error.

How GICNT-AML Tests Onboarding and Transaction Controls

Gambling operators sit inside the FATF standards as designated non-financial businesses and professions. Recommendation 22 applies customer due diligence to casinos once a customer’s transactions reach EUR/USD 3,000, and Recommendation 28 requires countries to license and supervise the sector for AML purposes. GICNT-AML tests whether the controls behind those obligations work as a sequence, which is why the domain carries an annual third-party audit instead of a self-assessment. The AML and KYC requirements run in this order:

  1. Identity verification before the first deposit, with the method used recorded against the account
  2. Risk scoring at onboarding, including PEP and sanctions screening, refreshed when account behaviour shifts
  3. Source of funds and source of wealth evidence at defined trigger points, held as documents rather than as customer assertions
  4. Transaction monitoring with written escalation rules and a named decision owner at each step
  5. Suspicious activity reporting to the relevant financial intelligence unit, with an internal timeline that can be reconstructed afterwards

European operators work towards a fixed date. Regulation (EU) 2024/1624 replaces the directive-based regime with a single rulebook binding in all member states from 10 July 2027, and the Anti-Money Laundering Authority in Frankfurt, operational since 1 July 2025, will supervise the highest-risk obliged entities directly. Programmes designed around national transpositions will need rewriting before that date.

Game Integrity Evidence Required by GICNT-FP

Certification here attaches to the game, not to the operator, because a certified operator can deploy an untested title in an afternoon. GICNT-FP asks for the certificate, the build it covers, and the change control connecting the two. Testing carries weight only when the laboratory holds accreditation and the target regulator recognises it. Accreditation to ISO/IEC 17025 is the common baseline, held by Gaming Laboratories International, BMM Testlabs, iTech Labs and eCOGRA among others. The fair play and game integrity requirements accept any laboratory at that standard or equivalent recognition in the licensing jurisdiction, provided four items line up:

  • A certificate identifying the exact build in production, not an earlier release of the same title
  • An RNG test report from an accredited laboratory, current for the software version deployed
  • A published return-to-player figure matching the configuration actually running, where the title supports several
  • A change log showing retesting after any modification to game logic or mathematics

Multiple RTP configurations of a single title remain the most common gap. A certificate covering a 96% build proves nothing about the 92% build running in the same lobby, and the framework treats those as two separate objects for certification purposes.

GICNT-DS Assesses Data Protection and Breach Response

An operator holds identity documents, payment records and behavioural data on every registered customer, which places a gambling platform closer to a financial institution than to an entertainment product in data terms. GICNT-DS runs an annual security assessment, and the data protection and cybersecurity requirements it applies cover the response plan as closely as the controls themselves.

The framework sets a 72-hour breach notification standard. That matches Article 33 of the GDPR, which requires notification to the supervisory authority without undue delay and within 72 hours where feasible. It sits above Canadian law: PIPEDA requires reporting of breaches posing a real risk of significant harm as soon as feasible, with no fixed hour count attached. Operators active in both regimes gain nothing from tracking two clocks, so the stricter figure becomes the internal standard.

  • Information security management aligned to ISO/IEC 27001:2022, with the statement of applicability available for review
  • Penetration testing at least annually and after significant infrastructure change, evidenced by remediation status rather than the report alone
  • Encryption and access control over identity documents collected during onboarding, with retention limits enforced in the system
  • A tested incident response plan naming who notifies the gambling regulator, the data protection authority and affected customers

Marketing Claims Reviewed Under GICNT-AM

GICNT-AM carries no fixed calendar. Review starts from a complaint, a regulator action, or a referral out of another domain assessment. Advertising rules also diverge more sharply than any other area of gambling regulation, so a compliant campaign in one market can breach the law in the next.

  • Italy bans gambling advertising and sponsorship across media under the Dignity Decree (Law No. 96/2018), with penalties reaching 20% of the value of the deal or a minimum of EUR 50,000
  • Germany confines broadcast advertising for virtual slots, online casino and poker to the 21:00 to 06:00 window under the Glücksspielstaatsvertrag 2021, the interstate gambling treaty, and bars active athletes from appearing
  • Spain limits gambling advertising on television, radio and video platforms to the 01:00 to 05:00 window under Royal Decree 958/2020
  • Great Britain applies the LCCP alongside the CAP and BCAP codes, with content rules on appeal to under-18s and on associating gambling with financial success

Affiliate conduct is where liability usually lands back on the operator. Italian regulators hold the licensee responsible for what partners publish, and the advertising and marketing standards apply the same attribution: the operator owns every claim made on its behalf, including claims it never drafted.

What an Operator Should Have Ready Before a First Assessment

Most first assessments stall on evidence retrieval rather than on control design. The compliance audit requirements an online casino must meet assume that records exist in a form someone outside the business can read without a guided tour. Operators preparing for market entry tend to assemble this set alongside licence application work, and a pre-launch compliance checklist covers the sequencing in more depth.

  1. A current licence register entry and a corporate ownership chart naming beneficial owners
  2. Written policies for AML, responsible gambling, data protection and marketing, each carrying a version date and a named owner
  3. Twelve months of player interaction records, escalation decisions and their outcomes
  4. Game certificates matched to the builds running in production
  5. The most recent penetration test with remediation status, not the raw findings
  6. An affiliate list with contracts and the monitoring evidence behind each relationship

Questions Operators Ask About the GICNT Framework

Can an operator be certified in some domains but not others?

No. Version 4.2 marks all six domains as mandatory, and certification is awarded against the full set. An operator that fails one domain is not certified, regardless of performance elsewhere. Partial or domain-specific claims misrepresent the framework.

Does GICNT certification replace a gambling licence?

No. GICNT is not a regulator or a licensing authority and grants no permission to offer gambling. Certification assesses an operator that already holds a valid licence, and it is withdrawn if that licence lapses.

How often is each domain reassessed?

Cycles differ by domain: annual review for GICNT-LS, twice-yearly audit for GICNT-PP, annual third-party audit for GICNT-AML, certification at game level for GICNT-FP, annual security assessment for GICNT-DS, and complaint-triggered review for GICNT-AM.

Which testing laboratories are accepted for game integrity evidence?

Any laboratory accredited to ISO/IEC 17025, or holding equivalent recognition from the operator’s licensing regulator, including Gaming Laboratories International, BMM Testlabs, iTech Labs and eCOGRA. The certificate has to cover the software build actually deployed.

Does the 72-hour breach notification standard apply outside the European Union?

Yes. GICNT-DS applies the same deadline everywhere, which means it exceeds local law in several markets. Canadian operators, for example, face no fixed hour count under PIPEDA but still report within 72 hours to remain certified.