The sources behind each compliance domain are listed here so that any requirement in the framework can be traced back to the instrument, ruling or study it was drawn from. Three families of material qualify: binding legal instruments, published supervisory guidance, and peer reviewed research. Nothing else carries weight in standards development, and a requirement that cannot be traced to one of them does not survive review.
What Counts as a Source for a Compliance Standard
A standard is not an opinion about good practice, so the material behind it has to be capable of being checked by someone who disagrees with the conclusion. That rules out a great deal of what circulates as industry wisdom.
Legal instruments set the floor, since no certification requirement may sit below what a licence already demands. Supervisory guidance shows how an authority reads its own rules in practice, which frequently matters more than the text. Research decides where a requirement should sit above the legal floor, because prevalence and effectiveness are empirical questions rather than drafting choices. Where these three disagree, the disagreement is documented in the standard rather than resolved silently, and the shape of that reasoning is set out across the six compliance domains.
The Instruments Behind the Licensing Standard
GICNT-LS assesses whether an operator holds a valid licence and whether the issuing regime carries meaningful supervision. The primary texts below define both halves of that question.
| Jurisdiction | Instrument | What it settles |
|---|---|---|
| United Kingdom | Gambling Act 2005 and the Licence Conditions and Codes of Practice | Licence categories, conditions and the three licensing objectives |
| Malta | Gaming Act 2018 and the accompanying regulations | B2C and B2B licences and the game type classification |
| Germany | Glücksspielstaatsvertrag 2021 | The federal permission regime and the supervisory role of the joint authority |
| Netherlands | Wet Kansspelen op afstand | Remote licensing and the duty of care attached to it |
| Sweden | Spellagen 2018:1138 | Licence types and the conditions attached to commercial online gambling |
| Australia | Interactive Gambling Act 2001 | Prohibited services and the enforcement powers behind them |
| Ontario | Registrar’s Standards for Internet Gaming | Operator conduct standards within the provincial model |
Each of these is read in its current consolidated form rather than as first enacted, because amendment is constant in this area. The way the framework maps them onto assessable criteria is described in the licensing and legal status requirements.
Player Protection Draws on Public Health Research
GICNT-PP is the domain where legal text alone is least useful, since duty of care obligations are often written in general terms and the question of what actually reduces harm is empirical. The following are the principal published sources.
- Wardle, H. et al., The Lancet Public Health Commission on gambling, Lancet Public Health 9(11), e950 to e994, published 24 October 2024. Estimates that 46.2% of adults gambled in the preceding year and that gambling disorder affects 15.8% of adults using online casino or slot products against 8.9% of those betting on sport
- Tran, L. T. et al., The prevalence of gambling and problematic gambling, a systematic review and meta-analysis, Lancet Public Health 9(8), e594 to e613, 2024
- Ukhova, D., Marionneau, V., Nikkinen, J. and Wardle, H., Public health approaches to gambling, a global review of legislative trends, Lancet Public Health 9(1), e57 to e67, 2024
- Accreditation criteria published by the Responsible Gambling Council under its RG Check programme, used as a reference point for how harm prevention measures are assessed rather than merely declared
The product level difference in those figures is the reason GICNT-PP does not apply a single uniform requirement across all verticals, and why the player protection requirements escalate with product risk instead of treating a slot portfolio and a sportsbook alike.
The AML Domain Follows the FATF Chain for Casinos
Gambling operators enter the FATF framework as designated non-financial businesses and professions rather than as financial institutions, which changes which recommendations apply and in what order.
- Recommendation 22 extends the customer due diligence and record keeping duties in Recommendations 10, 11, 12, 15 and 17 to casinos, triggered by financial transactions at or above the designated threshold
- The interpretive note sets that threshold at USD or EUR 3,000, counting a single operation or several that appear to be linked
- Recommendation 23 carries across the remaining measures, including suspicious transaction reporting
- Recommendation 28 places licensing, ownership vetting and risk based supervision on the state rather than the operator
Reading the chain this way matters because citing customer due diligence alone omits the linked transaction rule, which is where most threshold controls fail in practice. The resulting obligations are set out in the anti-money laundering requirements.
Game Integrity Rests on Testing Standards Rather Than Opinion
Fair play is the one domain where the underlying question is settled by measurement, so the sources are accreditation and technical standards rather than policy documents.
- ISO/IEC 17025, the competence standard that testing laboratories are accredited against, which is what makes one laboratory report comparable with another
- Technical standards published by individual regulators for random number generation, return to player verification and game recall
- Published methodology from independent testing houses, used where it is public and reproducible and disregarded where it is not
An operator relying on a certificate that names no accreditation body and no test methodology has not demonstrated anything, which is the distinction drawn in the fair play and game integrity requirements.
Data Security Reuses Existing Information Security Standards
There is no reason for a gambling specific security standard to be invented where mature general ones exist, so GICNT-DS is built on top of them.
- ISO/IEC 27001, referenced as the structure for an information security management system
- The General Data Protection Regulation, including the 72 hour supervisory notification window
- The Personal Information Protection and Electronic Documents Act, which requires notification as soon as feasible rather than within a fixed period
The gap between those last two is deliberate and worth stating plainly, because a fixed window and a best efforts obligation are not the same duty. How the framework resolves it is covered in the data protection and cybersecurity requirements.
Advertising Standards Are Read From Codes and Rulings
Advertising rules are unusually dependent on adjudication, since the codes are short and the meaning sits in how they have been applied.
- The UK advertising codes together with published adjudications, which show where the line on appeal to under eighteens actually falls
- Decreto Dignità, the Italian advertising prohibition, read alongside how the supervising authority has extended it to affiliate marketing
- Royal Decree 958/2020 in Spain, governing commercial communications and their permitted formats
- The advertising standards applying to Ontario registered operators
Codes converge on paper and diverge in enforcement, which is why the advertising and marketing standards are written against rulings rather than against the text alone.
What Inclusion in This List Does Not Mean
This page records what was consulted. It makes no claim about the people and organisations named, and the limits are worth stating explicitly rather than leaving to inference.
- Naming a researcher records that their published work was read and used. It does not indicate that they advise, review, endorse or are otherwise associated with GICNT
- Individuals appear here only as authors of cited work, with the citation given so the reader can go to the original
- Citing a regulator or a standards body is not a claim of recognition, accreditation or membership by that body
- None of the authors or organisations listed has reviewed the framework, and none is responsible for the conclusions drawn from their work
- Anyone who considers their work mischaracterised here can ask for the entry to be corrected or removed, and such a request is acted on rather than argued with
Common Questions About Sourcing and Attribution
Does citing a regulator mean GICNT is recognised by it?
No. The instruments and guidance published by an authority are public documents, and reading them creates no relationship with the body that issued them. GICNT holds no recognition, accreditation or delegated function from any gambling regulator, and certification does not substitute for a licence issued by one.
How is a research finding turned into a certification requirement?
A finding establishes that a risk exists and how it is distributed, which is what determines where a requirement should sit above the legal minimum. The prevalence gap between product types is the clearest example, since it is the reason requirements escalate with product risk rather than applying uniformly.
What happens when a cited source is superseded?
The affected requirement is reviewed rather than left standing on a withdrawn source. Where a legal instrument is amended, the consolidated text governs and the previous position is marked as superseded. Where research is retracted or substantially revised, any requirement resting on it is reopened.
Can an author ask to be removed from this page?
Yes, and the request is honoured without requiring a justification. Since no entry here implies any relationship beyond a citation, removing one costs nothing except the citation itself, and the underlying requirement is then re-sourced or reconsidered.