Home  /  News  /  Operations
OperationsJuly 27, 2024

In-House vs Outsourced Casino Ops: What Regulators and Banks Expect

Operators choosing between in-house and outsourced casino operations must satisfy regulators and banking partners. Here is what both models require.

In-House vs Outsourced Casino Ops: What Regulators and Banks Expect

The decision to build casino operations in-house or hand them to a managed-services partner is rarely just a cost calculation. Regulators and banking partners scrutinise both models closely, and the wrong setup, even a technically compliant one, can stall a licence application, trigger an audit, or cause a payment processor to exit the relationship quietly.

Why the Structural Choice Matters Beyond the Balance Sheet

Licensing authorities across Malta, Gibraltar, the Isle of Man, and Curacao have each tightened their expectations around operational accountability over the past two years. They want to see clear lines of responsibility, documented escalation paths, and evidence that the people making decisions about player risk, bonus exposure, and AML alerts are qualified to do so. Whether those people sit inside your organisation or inside a contracted partner is secondary to whether you can prove the governance structure works.

Banking partners apply a similar lens. A correspondent bank or payment facilitator conducting due diligence on a new iGaming client will request organisation charts, service agreements, and evidence of day-to-day control. Gaps in documentation, or ambiguity about who owns a particular function, raise red flags that are difficult to walk back once the underwriting team has formed an opinion.

What Regulators Look For in an In-House Model

Operators running operations internally must demonstrate sufficient resource depth. Regulators check for:

  • Named, qualified personnel for each regulated function, particularly the MLRO role
  • Internal policies that are current, tested, and actually used, not shelf documents
  • Technology ownership or documented licensing arrangements with platform providers
  • Segregation of duties so that, for example, the team approving bonus campaigns is not the same team setting wagering risk limits
  • Incident response logs showing that the compliance function has genuinely investigated and resolved alerts

A common failure point for smaller operators running in-house teams is key-person dependency. If the MLRO and the head of operations are the same individual, regulators will note this and may require remediation before issuing or renewing a licence.

What Regulators Look For in an Outsourced Model

Outsourcing does not transfer regulatory responsibility. The operator remains the licensed entity and is accountable for everything the managed-services partner does on its behalf. Regulators therefore focus on the contractual and oversight framework:

  • A master services agreement that specifies service levels, data handling obligations, and termination rights
  • Evidence that the operator conducts periodic performance reviews of the partner, not just at onboarding
  • Audit rights written into the contract, allowing the operator or a third party to inspect the partner's controls
  • A documented business continuity plan covering scenarios where the partner becomes unavailable
  • Clear confirmation of where player data resides and which jurisdiction's data protection law applies

Regulators are increasingly asking operators to produce records from these oversight reviews during routine inspections. An operator that cannot show it has actively monitored its partner is treated as if it had no compliance programme at all.

Banking Partner Expectations Across Both Models

Payment processors and acquiring banks care about predictability and accountability. Regardless of the operational model, they typically require:

  • A written AML and KYC policy signed off by a named officer
  • Evidence of transaction monitoring, including how alerts are triaged and closed
  • Chargeback ratios below agreed thresholds, with a documented remediation plan if thresholds are breached
  • Confirmation that the operator holds a valid licence for every jurisdiction where it accepts players

Where an outsourced model is in place, banking partners often ask for the managed-services agreement so they can confirm which party owns the merchant account relationship and who is liable for chargebacks. Ambiguity here can cause a processor to reclassify the arrangement and apply higher reserve requirements.

Making the Model Work: Practical Steps

At OnlineShine, we work with operators at both ends of this spectrum. The operators who maintain strong regulatory and banking relationships share a common trait: they treat governance documentation as a live asset, not a one-time submission. Policies are reviewed quarterly, service agreements are updated when the operating model changes, and oversight evidence is filed in a format that can be retrieved within hours if a regulator or bank requests it.

Whichever model you choose, the regulator's question is always the same: can you show, with documentation, that someone qualified is responsible for each critical function and that the system has actually been tested?

Operators considering a transition from in-house to outsourced, or the reverse, should conduct a gap analysis against their current licence conditions before making the switch. Changing operational models mid-licence cycle without notifying the authority is itself a compliance event in several jurisdictions.

FAQ

Frequently asked questions

Does outsourcing casino operations transfer regulatory responsibility to the service provider?

No. The licensed operator retains full regulatory responsibility regardless of which functions are delegated to a managed-services partner. Regulators treat the operator as accountable for every action taken on its behalf, which means the operator must maintain oversight of the partner through documented reviews, audit rights, and service-level agreements.

What documentation do banking partners typically require from outsourced iGaming operations?

Banking partners and payment processors generally request the master services agreement between the operator and its partner, a current AML and KYC policy signed by a named officer, evidence of transaction monitoring activity, and confirmation of the licensed jurisdictions where the operator accepts players. They also want clarity on which entity owns the merchant account and bears liability for chargebacks.

What is the most common compliance failure in in-house casino operations?

Key-person dependency is the most frequently cited issue. When a single individual holds both the MLRO role and a senior operational role, regulators view this as a structural weakness because the segregation of duties required for effective compliance oversight cannot be maintained. Licensing authorities may require the operator to hire additional qualified personnel before granting or renewing a licence.

What should an operator do before switching from in-house to outsourced operations during a licence cycle?

An operator should conduct a gap analysis against its existing licence conditions and notify the relevant licensing authority before making the transition. Changing the operational model without prior notification is treated as a reportable compliance event in several jurisdictions and can trigger a formal review or suspension of the licence.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.