A pre-launch compliance checklist for online casino operators exists to answer one question: what has to be finished, evidenced and documented before the first player account opens. Regulators rarely accept intent. They ask for the licence condition met, the audit booked, the policy signed off. The six GICNT domains map that work into gates, each with an owner and a date.
What Licensing and Legal Status Requires Before the Site Opens
Licence application requirements in iGaming differ by regime, but the documentary core repeats: an incorporated entity in the right jurisdiction, ultimate beneficial owners disclosed, the source of founding capital evidenced, key function holders named and cleared, and a technical description that matches the platform that will go live. GICNT-LS treats this as an annual review item, so the file assembled for the application becomes the file maintained afterwards.
The step that catches new entrants sits after approval. Being approved is not permission to trade. Each gambling licence application route carries its own post-approval clock, and missing it can send the whole submission back to the start. In Malta the applicant is invited into a technical environment and has 60 days to complete the rollout and the system audit, after which the application lapses and a fresh one is required.
| Regime | Gate before the first player | Clock that starts after go-live |
|---|---|---|
| Malta, MGA | System audit inside 60 days of technical rollout; Declaration of Go-Live filed at least two days ahead; go live within 90 days of licence issue | Compliance audit completed within 90 days of the MGA notice, the first after year one of operation |
| Great Britain, UKGC | Operating licence, personal management licences and LCCP conditions in the version effective from 19 January 2026 | First RTS security audit within six months of the grant, report emailed within seven days of the due date |
| Ontario, AGCO and iGO | Registration with the AGCO plus an operating agreement with iGaming Ontario | Registrar’s Standards for Internet Gaming, including centralised self-exclusion under Standard 2.14.1 |
| Alberta, AGLC and AiGC | AGLC registration plus a commercial agreement with the Alberta iGaming Corporation, market open since 13 July 2026 | Provincial standards and integration with the centralised self-exclusion programme |
| Curaçao, CGA | Direct B2C or B2B licence under the LOK, in force since 24 December 2024, with the master and sub-licence route closed | Public register entry, AML and CFT supervision, phased local substance obligations |
Two jurisdictional details are worth checking before the plan is signed. Alberta runs a two-step model, so AGLC registration alone does not put an operator in market. Curaçao licences are now issued directly by the Curaçao Gaming Authority and recorded in a public register, which means a legacy sub-licence is no longer a licence.
Operators Must Complete KYC and AML Controls Before the First Deposit
AML programme requirements for online gambling operators are assessed on evidence, not on the existence of a policy document. Most launch delays trace back to KYC onboarding rather than to the licence itself, because verification logic touches payments, the player account and the marketing stack at the same time. GICNT-AML requires an annual third-party audit, so the evidence chain has to exist from the first deposit onwards.
- A business-wide money laundering and terrorist financing risk assessment, approved before launch and owned by a named officer rather than by a department.
- An appointed MLRO and deputy, with a documented escalation route to the financial intelligence unit of the licensing jurisdiction.
- Identity verification that completes before gambling, not before withdrawal. Great Britain requires name, address and date of birth to be verified under licence condition 17.1.1, and age verified before any deposit or free-to-play access.
- Due diligence triggers configured to the applicable threshold. From 10 July 2027 Regulation (EU) 2024/1624 applies a single EUR 2,000 trigger to stakes, winnings and linked transactions across all member states.
- Sanctions and politically exposed person screening at onboarding and on a scheduled rescreen, with the match handling procedure written down before it is needed.
- Transaction monitoring rules with stated thresholds, named alert owners and an escalation path tested against sample data prior to launch.
- Record retention that survives staff turnover. The Authority for Anti-Money Laundering and Countering the Financing of Terrorism has been operational in Frankfurt since 1 July 2025 and is publishing technical standards that will shape how national supervisors read these files.
Which Player Protection Tools Must Be Live at Launch
Requirements for responsible gambling tools are the least portable part of the stack, because two markets can demand opposite defaults. A build tested against a single regime will fail the next one on configuration: the tools exist, the thresholds are wrong. Integration with national and provincial self-exclusion registers is a technical project with its own testing window, and each register sets its own deadline for blocking an excluded player.
| Market | Tool that must work on day one | Threshold or trigger |
|---|---|---|
| Great Britain | Prompt to set a financial limit before the first deposit | In force since 31 October 2025, with a reminder to review every six months |
| Great Britain | Light-touch financial vulnerability check | Above GBP 150 net deposits in a rolling 30 days, reduced from GBP 500 on 28 February 2025 |
| Netherlands | Means test before further deposits are accepted | Net deposits above EUR 300 for ages 18 to 23 and EUR 700 from 24, with deposits blocked if the test cannot be completed |
| Germany | LUGAS limit file, OASIS check and panic button | EUR 1,000 cross-operator per calendar month, panic button triggering a 24-hour exclusion |
| Ontario | BetGuard registry check at login and registration | Live since 14 May 2026, with the operator programme still required under Standard 2.14 |
| Alberta | Centralised self-exclusion integration through the AGLC interface | Completed and tested before go-live on 13 July 2026 |
German stake rules changed on 1 July 2026, replacing the flat cap on virtual slots with a tiered model: EUR 1 per spin below 21, EUR 3 from 21, and EUR 5 for players showing no markers of harm over a 90-day window. The higher tiers are conditional on behavioural monitoring, so they are a player protection obligation before they are a commercial opportunity. GICNT-PP is audited twice a year for that reason.
Certifying Games and RNG Before Any Real-Money Round
RNG certification requirements sit with the supplier in commercial terms and with the operator in regulatory terms. A platform certificate does not cover a title added three weeks after launch, and RNG certification is the domain where scope errors surface first in an audit. GICNT-FP certifies at game level.
- Certificates from an accredited laboratory for the RNG implementation and for each game. eCOGRA, BMM Testlabs and iTech Labs appear on most approved lists, as does GLI or an equivalent accredited facility.
- Published return to player figures that match the certified build rather than the supplier brochure.
- A change control log that triggers recertification when mathematics, RNG or build changes. Germany requires certificate numbers to be registered and only approved games to be offered.
- Supplier evidence collected before contract signature. Alberta requires registered suppliers to hold technology certification from an accredited testing facility.
- Jurisdictional game restrictions configured in the lobby and enforced by the platform. German virtual slots prohibit autoplay and jackpots and impose a minimum spin duration of five seconds.
Security Assessment, Breach Notification and Payment Card Controls
GICNT-DS is assessed annually, and the pre-launch question is whether the operator can produce audit evidence on the day it is asked for. Requirements for player funds segregation belong here as much as in the licensing file, since the control is financial and the proof is operational. Scheduling penetration testing and incident response work late is the most common reason a launch date moves.
- The British remote technical standards sit under licence condition 2.3.1 and mirror a subset of ISO/IEC 27001 controls. A newly licensed remote operator must complete and provide the first security audit within six months of the grant, and the full report goes to the Commission within seven days of the due date set for it.
- PCI DSS v4.0.1 is the only active version of the card data standard. The 51 previously future-dated requirements have been mandatory since 31 March 2025, and payment page script inventory and tamper detection are where assessments most often fail.
- Breach notification clocks stated per market. Article 33 of the GDPR allows 72 hours from awareness. PIPEDA sets no equivalent deadline and requires reporting as soon as feasible, so the 72-hour standard applied by GICNT-DS is stricter than Canadian law rather than a restatement of it.
- A penetration test run against the production build, with remediation evidence attached to the report.
- An incident response plan with named roles and a tabletop exercise completed once before the first player registers.
- Player funds held separately from operating funds, with the level of protection disclosed to customers where the regime requires that disclosure.
How Advertising and Affiliate Controls Are Checked Under GICNT-AM
Gambling advertising compliance is reviewed reactively under GICNT-AM, which makes the approval trail the deliverable. If a complaint arrives in month two, the operator needs to show who signed off the creative and when. Affiliate compliance needs a named owner before the first campaign goes out, because liability for partner output attaches to the licensee in every major regime.
- Promotional mechanics rebuilt to the current British rules. Since 19 December 2025 social responsibility code 5.1.1 caps wagering requirements at 10 times the bonus funds and prohibits incentives spanning more than one gambling product.
- Significant conditions presented at the point of the offer, in the same view as the headline number.
- Marketing consent captured by product and by channel, with an audited suppression list covering self-excluded players.
- An affiliate register, a contractual right to audit, a creative approval queue and a takedown route that works within hours.
- Market-specific advertising rules mapped before campaigns are booked. Ad Standards began accepting complaints under the Canadian Code for Advertising of Gambling on 1 January 2026, and the Netherlands has prohibited untargeted gambling advertising since July 2023.
The Consolidated Checklist Across Six GICNT Domains
The table below sets out what the file should hold for each domain. Teams building this from scratch tend to start with the wider compliance for new operators roadmap and then work down into per-domain evidence. Each line needs a document, an owner and a date before the first player account is opened.
| Domain | Evidence held before the first player | Review cycle after launch |
|---|---|---|
| GICNT-LS | Licence, ownership and control file, key function appointments, list of domains and brands covered | Annual review |
| GICNT-PP | Tool configuration per market, self-exclusion integration test logs, player interaction policy with defined markers of harm | Bi-annual audit |
| GICNT-AML | Risk assessment, MLRO appointment, screening configuration, monitoring rules with escalation, retention schedule | Annual third-party audit |
| GICNT-FP | Certificates per game and per RNG, published RTP, change control procedure with recertification triggers | Game-level certification |
| GICNT-DS | Security audit or booked audit date, penetration test with remediation evidence, incident plan, card data assessment | Annual security assessment |
| GICNT-AM | Promotional terms reviewed against market rules, affiliate register, creative approval log, suppression lists | Complaint-triggered review |
Common Pre-Launch Questions from Operator Compliance Teams
How Early Should a Licence Application Start Before the Planned Launch?
Work backwards from the post-approval clocks rather than from the desk review. A Maltese applicant still needs to complete a technical rollout and system audit inside 60 days of the invitation and to go live within 90 days of licence issue. A British licensee has six months from the grant to deliver a first security audit. Two to three quarters of runway is a realistic planning assumption for a single regime.
Does GICNT Certification Replace a Gambling Licence?
No. GICNT is an independent certification body, not a regulator or a licensing authority, and certification confers no authorisation to offer gambling anywhere. The six domains assess whether controls exist and function. A licence from the competent authority in each target market remains the precondition for accepting players.
When Must a New Remote Licensee in Great Britain Complete Its First Security Audit?
Within six months of the licence being granted, by a due date the Commission sets, with the full report provided within seven days of that date. The obligation applies whether or not trading has started, although a licensee that has not commenced operations may apply to complete the first audit within six months of doing so.
What AML Evidence Should Already Exist Before the First Deposit?
A signed business-wide risk assessment, an appointed MLRO with a deputy, screening and monitoring rules configured and tested, and a documented escalation route for suspicious activity. Policies drafted after launch count as remediation, which is a weaker position in any audit or enforcement conversation.
Do Responsible Gambling Tools Need Different Settings in Each Market?
Yes, and the differences are structural rather than cosmetic. Germany enforces a cross-operator monthly deposit ceiling of EUR 1,000 through a central limit file, the Netherlands requires a means test above net deposits of EUR 300 or EUR 700 depending on age, and Great Britain requires a limit-setting prompt before the first deposit. One configuration cannot satisfy all three.