The decision to build casino operations in-house or hand them to a managed-services partner is rarely just a cost calculation. Regulators and banking partners scrutinise both models closely, and the wrong setup, even a technically compliant one, can stall a licence application, trigger an audit, or cause a payment processor to exit the relationship quietly.
Why the Structural Choice Matters Beyond the Balance Sheet
Licensing authorities across Malta, Gibraltar, the Isle of Man, and Curacao have each tightened their expectations around operational accountability over the past two years. They want to see clear lines of responsibility, documented escalation paths, and evidence that the people making decisions about player risk, bonus exposure, and AML alerts are qualified to do so. Whether those people sit inside your organisation or inside a contracted partner is secondary to whether you can prove the governance structure works.
Banking partners apply a similar lens. A correspondent bank or payment facilitator conducting due diligence on a new iGaming client will request organisation charts, service agreements, and evidence of day-to-day control. Gaps in documentation, or ambiguity about who owns a particular function, raise red flags that are difficult to walk back once the underwriting team has formed an opinion.
What Regulators Look For in an In-House Model
Operators running operations internally must demonstrate sufficient resource depth. Regulators check for:
- Named, qualified personnel for each regulated function, particularly the MLRO role
- Internal policies that are current, tested, and actually used, not shelf documents
- Technology ownership or documented licensing arrangements with platform providers
- Segregation of duties so that, for example, the team approving bonus campaigns is not the same team setting wagering risk limits
- Incident response logs showing that the compliance function has genuinely investigated and resolved alerts
A common failure point for smaller operators running in-house teams is key-person dependency. If the MLRO and the head of operations are the same individual, regulators will note this and may require remediation before issuing or renewing a licence.
What Regulators Look For in an Outsourced Model
Outsourcing does not transfer regulatory responsibility. The operator remains the licensed entity and is accountable for everything the managed-services partner does on its behalf. Regulators therefore focus on the contractual and oversight framework:
- A master services agreement that specifies service levels, data handling obligations, and termination rights
- Evidence that the operator conducts periodic performance reviews of the partner, not just at onboarding
- Audit rights written into the contract, allowing the operator or a third party to inspect the partner's controls
- A documented business continuity plan covering scenarios where the partner becomes unavailable
- Clear confirmation of where player data resides and which jurisdiction's data protection law applies
Regulators are increasingly asking operators to produce records from these oversight reviews during routine inspections. An operator that cannot show it has actively monitored its partner is treated as if it had no compliance programme at all.
Banking Partner Expectations Across Both Models
Payment processors and acquiring banks care about predictability and accountability. Regardless of the operational model, they typically require:
- A written AML and KYC policy signed off by a named officer
- Evidence of transaction monitoring, including how alerts are triaged and closed
- Chargeback ratios below agreed thresholds, with a documented remediation plan if thresholds are breached
- Confirmation that the operator holds a valid licence for every jurisdiction where it accepts players
Where an outsourced model is in place, banking partners often ask for the managed-services agreement so they can confirm which party owns the merchant account relationship and who is liable for chargebacks. Ambiguity here can cause a processor to reclassify the arrangement and apply higher reserve requirements.
Making the Model Work: Practical Steps
At OnlineShine, we work with operators at both ends of this spectrum. The operators who maintain strong regulatory and banking relationships share a common trait: they treat governance documentation as a live asset, not a one-time submission. Policies are reviewed quarterly, service agreements are updated when the operating model changes, and oversight evidence is filed in a format that can be retrieved within hours if a regulator or bank requests it.
Whichever model you choose, the regulator's question is always the same: can you show, with documentation, that someone qualified is responsible for each critical function and that the system has actually been tested?
Operators considering a transition from in-house to outsourced, or the reverse, should conduct a gap analysis against their current licence conditions before making the switch. Changing operational models mid-licence cycle without notifying the authority is itself a compliance event in several jurisdictions.



