Compliance planning for new operators fixes product scope, tax exposure, verification flows and marketing limits long before the first player registers. Sequence decides cost. Teams that settle the licensing question after the platform is built tend to rebuild onboarding twice, once for the regulator and once for the payment provider. Each of the six GICNT certification domains inherits that first decision.
Why the Licensing Decision Comes First
The licence decides more than which flag sits in the footer. It sets which products may be offered, which checks run before a deposit clears, which self-exclusion register the platform queries, and how much of gross gaming revenue leaves as duty. An iGaming compliance roadmap that opens with platform procurement inverts that dependency, and the rework lands on the technical team weeks before launch.
Three variables usually decide the answer: market access, cost of duty, and the weight the licence carries with banks and payment processors. Malta issues a single Gaming Service Licence covering game types 1 to 4 under the Gaming Act 2018, valid for 10 years. Great Britain licenses each activity separately, and Remote Gaming Duty on online casino profit rose from 21% to 40% on 1 April 2026. Curaçao licenses operators directly under the LOK, the Landsverordening op de kansspelen (National Ordinance on Games of Chance), in force since 24 December 2024, with local substance now expected rather than optional.
Those trade-offs sit in the business plan next to the revenue model, which is why comparing licensing jurisdictions belongs at board level and not in a legal annex written after the platform is chosen.
What the Main Regimes Ask of a First-Time Applicant
Requirements a new gambling operator must meet differ less in substance than in sequencing and proof. Each regime wants identifiable owners, a funded balance sheet, tested systems and written policies. What changes is the order of checks and who signs off. Starting an online casino legally in a mature market means clearing a fit and proper assessment on the shareholders before anyone opens the product file. Much of the document pack carries over between regimes, so obtaining a gambling licence in a second market takes less preparation than the first.
| Jurisdiction | Authority | Entry cost and gate before go-live |
|---|---|---|
| Malta | Malta Gaming Authority | EUR 5,000 application fee and EUR 25,000 annual licence fee for a Type 1 or Type 2 B2C licence. The live environment is audited by an MGA-approved auditor at system review stage. |
| Great Britain | Gambling Commission | Application and annual fees banded by gross gambling yield, rising 25% from 1 October 2026. First annual fees stay at 75% of the annual figure. Named senior roles need personal management licences. |
| Curaçao | Curaçao Gaming Authority | Direct application under the LOK. Master and sub-licences no longer exist. Local substance and an appointed MLRO are conditions of the licence. |
| Ontario | AGCO with iGaming Ontario | Registration with the AGCO plus an operating agreement with iGaming Ontario. Participation in the centralised self-exclusion programme is required under Standard 2.14.1. |
| Alberta | AGLC with the Alberta iGaming Corporation | CAD 200,000 in registration and permit fees, then a commercial agreement with the Alberta iGaming Corporation and integration with centralised self-exclusion. |
Alberta opened on 13 July 2026 with 22 operator sites live on day one, and both Canadian markets put self-exclusion integration on the critical path rather than in the backlog.
Building the Compliance Function Before the Platform
Building a compliance function in iGaming starts with named individuals, because most regimes attach personal accountability to roles rather than to the company. Recruiting after submission stalls the file, since the regulator assesses the people alongside the policies.
- Head of compliance or key function holder. Owns the regulatory relationship, the policy library and the reporting calendar. In Malta the role is approved by the authority; in Great Britain it sits under a personal management licence.
- Money laundering reporting officer. Named, reachable and able to file a suspicious activity report without commercial sign-off. Curaçao makes the appointment a licence condition under the LOK.
- Data protection officer. Needed where the scale and nature of player data processing meets the GDPR threshold, and useful well before that point given the volume of identity documents an operator holds.
- Safer gambling lead. Owns intervention thresholds, the interaction log and the escalation route when a player shows markers of harm.
- Technical compliance owner. Manages testing laboratory relationships, game submissions and re-certification after supplier updates.
An outsourced provider can run the monitoring queue or the KYC review desk. The licence holder still answers for the outcome, and auditors ask to see the oversight of the vendor as well as the vendor output.
What GICNT-AML Requires Before the First Deposit
GICNT-AML requires a documented risk assessment, a named MLRO, source of funds verification, enhanced due diligence for politically exposed persons, and transaction monitoring with a recorded escalation path. The domain carries an annual third-party audit, so the evidence has to survive review by someone outside the business.
The thresholds underneath come from the FATF Recommendations. Recommendation 22 places casino customer due diligence at USD/EUR 3,000 for a single financial transaction or a linked series. The EU baseline for gambling services sits at EUR 2,000, and Regulation (EU) 2024/1624 replaces national variation with one rulebook from 10 July 2027. AMLA, the EU anti-money laundering authority in Frankfurt, has been operational since 1 July 2025 and took over the AML mandates previously held by the European Banking Authority on 1 January 2026. A programme designed in 2026 has roughly twelve months of runway before that single rulebook applies.
Two weaknesses recur in audit findings: monitoring rules lifted from a payments provider without tuning to iGaming typologies, and escalation that ends in a spreadsheet with no decision owner. An AML programme aligned with FATF expectations records why each alert closed and who closed it.
Player Protection Tools Have to Work on Day One
Market entry compliance for online gambling fails fastest on player protection, because these obligations are technical integrations with fixed go-live dependencies rather than policies a lawyer drafts in a week. Each register has its own onboarding queue, test environment and sign-off.
| Market | Self-exclusion integration | Further day-one controls |
|---|---|---|
| Great Britain | GAMSTOP participation under SR Code 3.5.5 | Slot stake caps of £5 per spin for players aged 25 and over since 9 April 2025 and £2 for ages 18 to 24 since 21 May 2025. Deposit limit prompt at registration since 31 October 2025. Statutory levy of up to 1.1% of gross gambling yield for remote operators since 6 April 2025. |
| Ontario | BetGuard, live since 14 May 2026, under Standard 2.14.1 | Operator-level self-exclusion under Standard 2.14 stays in force. Exclusion terms run from six months to five years. |
| Alberta | Centralised self-exclusion from market launch | AGLC registration and an agreement with the Alberta iGaming Corporation, with technology certified by an accredited testing facility. |
| Netherlands | CRUKS query before a player starts a session | Net deposit limits of EUR 300 for ages 18 to 24 and EUR 700 above that age since 1 October 2024, with a means test before any increase. |
| Germany | OASIS query before play | Cross-operator monthly deposit limit of EUR 1,000, with the definition of affordability for increases still under review by the GGL. |
| Sweden | Spelpaus query before play | One bonus offer per player and a local representative requirement. |
Coverage differs more than the labels suggest, and national self-exclusion registers vary in whether they reach land-based venues, lotteries or the grey market. GICNT-PP requires integration where a register exists and an operator scheme of equivalent effect where none does, reviewed twice a year.
Game Testing and RTP Disclosure Under GICNT-FP
GICNT-FP certifies at the level of the individual game rather than the operator. A certificate covers a specific build, and a material change to the mathematics or the RNG integration calls for a fresh test. Operators tend to learn this when a studio ships an update a fortnight before launch and the compliance file no longer matches the live lobby.
Accepted laboratories include eCOGRA, iTech Labs and BMM Testlabs, or an equivalent accredited facility. Certificates issued to a studio do not transfer by themselves, so RNG certification obligations follow the game onto each platform that hosts it. Alongside the certificate, the domain requires published return to player figures for each title and full disclosure of bonus and wagering terms before a player accepts an offer, which puts part of the work on the front-end team rather than the compliance desk.
Data Protection Groundwork That GICNT-DS Assesses
An operator holds identity documents, payment records and behavioural data on every registered player, which makes the security assessment one of the heavier evidence exercises in the first certification cycle.
- Retention against minimisation. AML rules require KYC records to be kept, commonly for five years after the relationship ends, while GDPR requires data to be held no longer than necessary. Reconciling GDPR and PIPEDA obligations belongs in the retention schedule, with a stated purpose and clock for each data category.
- Breach notification within 72 hours. GDPR Article 33 sets 72 hours for notifying the supervisory authority. Canada’s PIPEDA fixes no such deadline and requires reporting as soon as feasible. GICNT-DS applies the 72-hour clock to every certified operator, which is stricter than Canadian law rather than a restatement of it.
- Transport encryption. A floor of 256-bit SSL or TLS on player-facing traffic, with certificate management assigned to a named owner.
- Annual penetration test. Independent, scoped to include the player account area and payment flows, with findings tracked to closure rather than logged and left.
- Incident response plan. Names who contacts the regulator, the payment partners and affected players, and gets tested before launch instead of during the first incident.
Advertising Rules Bite Before the First Campaign
GICNT-AM is reviewed on complaint rather than on a calendar, which makes it the domain most often deferred to launch week. The codes diverge sharply. Ontario’s Registrar’s Standards have prohibited the use of athletes in iGaming advertising since 28 February 2024, except where the message advocates responsible gambling, and restrict celebrities likely to appeal to minors. Italy bans gambling advertising outright under the Decreto Dignità, and the regulator treats partner output as the operator’s responsibility. Great Britain restricts content with strong appeal to under-18s.
Two obligations repeat across the codes. Bonus terms have to be visible where the promotion appears, not one click away. And the operator answers for what its affiliates publish, so creative approval and a takedown route need to exist before the first partner signs. Mapping gambling advertising codes market by market before the media plan is signed costs less than pulling creative after a complaint reaches the regulator.
Preparing Evidence for the First Certification Audit
Auditors ask for artefacts with dates and authors. A policy with no version history reads as unimplemented, and a control with no log reads as absent. The cadence differs by domain, and GICNT audit cycles follow the risk profile of each area rather than one annual calendar.
| Domain | Review cadence | Evidence to have ready |
|---|---|---|
| GICNT-LS | Annual Review | Licence certificate, public register entry, corporate structure and beneficial ownership records |
| GICNT-PP | Bi-Annual Audit | Self-exclusion integration logs, deposit limit configuration, reality check settings, player interaction records |
| GICNT-AML | Annual Third-Party Audit | Risk assessment, MLRO reports, CDD and EDD files, monitoring rules, escalation and reporting records |
| GICNT-FP | Game-Level Certification | Test certificates per title, published RTP, bonus and wagering terms archive |
| GICNT-DS | Annual Security Assessment | Penetration test report, remediation log, incident response plan, breach register |
| GICNT-AM | Complaint-Triggered Review | Creative approvals, affiliate agreements, marketing consent records, takedown log |
A Realistic Timeline From Incorporation to First Player
An operator launch compliance timeline runs longer than most business plans assume, and two items sit on the critical path: the fit and proper assessment of the shareholders, and the audit of a live technical environment. Malta is commonly quoted at six to twelve months for a well prepared B2C file, and complex ownership pushes that out rather than in.
| Stage | Indicative window | What blocks progress |
|---|---|---|
| Corporate setup and ownership documentation | Months 1 to 2 | Missing police certificates, unclear ownership chains, unnamed beneficial owners |
| Application submission | Months 2 to 4 | Business plan, financial projections, source of funds for the share capital |
| Fit and proper and financial review | Months 4 to 7 | Regulator queries on shareholders, directors and funding |
| Policy and systems build | Runs in parallel | AML programme, RG tooling, KYC vendor integration, register onboarding queues |
| System or technical audit | Months 6 to 9 | Environment not final, late supplier changes, untested self-exclusion feed |
| Certification readiness | Before the first deposit | Evidence gaps across the six domains |
Running a pre-launch compliance checklist at month three, rather than month nine, surfaces those gaps while they are still cheap to close.
Questions New Operators Ask About Certification and Licensing
How long does it take a new operator to get a gambling licence?
Six to twelve months is a reasonable planning assumption for a tier-one regime with a clean file. The determining factors are the clarity of the ownership structure and the readiness of the technical environment for audit, not the speed of the regulator. Applications with layered holding companies or unverified source of funds run longer.
Can a new operator outsource the MLRO role?
Outsourced and shared MLRO arrangements exist, and some regimes accept them for smaller operators. The named officer still has to be reachable, informed about the business and able to file reports independently. Curaçao makes the appointment a condition under the LOK, and auditors test whether the officer has real access to transaction data.
Does GICNT certification replace a gambling licence?
No. GICNT is an independent certification body, not a regulator or a licensing authority, and the certification mark carries no legal authorisation to offer gambling. A certified operator still holds a licence from the regulator in each market it serves. Certification attests that the operator meets the framework requirements across the six domains.
When should transaction monitoring go live?
Before the first deposit, not after the first month of trading. GICNT-AML expects monitoring rules, thresholds and escalation to be documented and operating from launch, and the annual third-party audit looks at decisions taken in the earliest weeks. Retrofitting monitoring leaves a gap in the record that cannot be closed later.
Which market should a first-time operator target?
The answer follows the funding and the product. A regime with lower duty and faster licensing suits an operator testing a proposition, while a tier-one licence opens banking and supplier relationships that offshore licences do not. Weigh duty, the cost of the compliance function and the reputational value of the licence together, since a cheap licence with poor payment access is expensive in practice.