PDF · 10 pages

Audit-ready Operations Checklist

Everything a regulated operator needs logged, connected and defensible before the next audit.

Audits rarely fail on a missing policy

Almost every operator can produce a policy document for almost every obligation they hold. What separates an operator who sails through a regulatory audit from one who does not is rarely whether the policy exists. It is whether the evidence behind it can actually be produced, quickly, in a form that withstands a direct follow up question.

This guide is built around a distinction most compliance checklists skip entirely. Information can be logged, connected, or defensible, and these are three genuinely different bars, not three words for the same thing. Most operators clear the first without realising they have not cleared the other two. This guide sets out exactly what needs to reach all three, category by category, before the next audit arrives rather than during it.

None of what follows is generic advice dressed up as a checklist. Every category below maps to a specific, current obligation, and every item inside it is something an auditor could plausibly ask you to produce on the day, not a nice to have you could reasonably defer.

A note on scope. This guide reflects the UK regulatory position at the time of writing, August 2026. Confirm current detail against Gambling Commission guidance and take your own compliance advice before relying on any point here.

The three bars an audit actually applies

Bar What it actually means
Logged The information exists somewhere in the business, in some system or record, even if nobody could locate it quickly
Connected That information can be assembled into a single, coherent account without days of manual cross referencing between systems
Defensible The assembled account survives a specific, pointed follow up question, not just a first glance

An operator who has only cleared the first bar often feels compliant right up until an actual request arrives. The gap between logged and defensible is exactly where audits go from routine to uncomfortable.

KYC and identity verification

Age and identity verification, name, address and date of birth, has to be completed before a customer can deposit, gamble with real money, or access free to play features, with no grace period and clear upfront disclosure of what identification may be required.

  • A record for every customer showing exactly when age and identity were verified, and against what
  • Evidence of what identification requirements were disclosed to the customer, and when
  • A clear log of any account that was permitted to deposit or play before verification completed, and why
  • A record connecting verification outcomes to the specific provider or method used, in case that method is later questioned

AML and financial crime

Casino operators, remote and non-remote, sit directly within the Money Laundering Regulations 2017. Recent changes effective from 30 June 2026 sharpened two specific triggers worth being ready for directly: enhanced due diligence tied to a refined definition of high risk third countries based on FATF’s own call for action list, and enhanced due diligence and ongoing monitoring for any transaction or relationship that is unusually large or unusually complex. Every operator, regardless of MLR status, faces AML expectations under the LCCP and the Proceeds of Crime Act, including suspicious activity reporting.

  • A documented money laundering and terrorist financing risk assessment, reviewed and dated, not written once and forgotten
  • Enhanced due diligence records for every customer relationship meeting a high risk third country or unusually large or complex transaction trigger
  • A clear, timestamped record of every suspicious activity report considered, including those reviewed and not submitted, with the reasoning behind that decision
  • Evidence of ongoing monitoring, not just a check performed once at onboarding

How long records actually need to survive

Being audit ready is not just about producing a record. It is about still having it when it is asked for. Under Regulation 40 of the Money Laundering Regulations 2017, customer due diligence documents and transaction records must be kept for at least five years, running from the end of the business relationship or the completion of the transaction, with certain records capped at a maximum of ten years. Once that period passes, personal data obtained for these purposes generally has to be deleted, unless it is genuinely needed for ongoing legal proceedings.

This creates a real, worth naming tension. Data protection principles push toward keeping personal data no longer than necessary. Anti money laundering rules require it to survive a fixed minimum period regardless. Getting this balance wrong in either direction creates exposure, either a record that has vanished before an audit needs it, or personal data retained well past the point it should have been deleted.

Worth checking directly. Whether your current data retention schedule actually reflects these specific periods, rather than a generic policy written before anyone worked through the detail.

Safer gambling and customer interaction

Customer interaction requirements under the Social Responsibility Code cover how an operator identifies and responds to indicators of problem gambling, including specific expectations around VIP and high value customers. Existing light touch financial vulnerability checks sit alongside the incoming, higher tier Financial Risk Assessments, still being introduced in stages at the time of writing.

  • A record of every vulnerability or risk indicator identified for a customer, and the action taken in response
  • Evidence that VIP or high value customers received the additional scrutiny this status requires, not just standard treatment
  • A clear account of how marketing and promotional activity was handled once a risk indicator was identified for a customer
  • Readiness evidence for Financial Risk Assessments as they roll out, even before your firm falls within an active stage

Key events, reportable events and ownership

Event type Reporting deadline
Investigation by a regulatory or government body into the licensee or a key position holder Five working days from becoming aware
Criminal investigation involving the licensee or a key position holder Five working days from becoming aware
Change in ownership or control, including 5% or more of voting rights or dividend entitlement As set out under the current licence condition, via eServices
Personal licence holder’s own reportable key events Must be reported by the individual themselves, not delegated to a colleague

All key events and other reportable events are submitted through the Commission’s eServices digital portal. Ownership and control notification thresholds changed to 5% of voting rights or dividend entitlement from March 2026, replacing the previous 3% threshold in most cases. It is worth checking this specific detail is reflected in your current internal process, since a threshold change like this is easy to miss if nobody owns updating the policy document that references it.

Why disconnected systems fail the second bar

Every category above can be, and often is, logged somewhere. The point at which operators visibly struggle during an actual audit is rarely a missing record. It is the moment they are asked to produce a single, coherent account that pulls from several systems at once, a customer’s verification history alongside their transaction pattern alongside their vulnerability flags, and discover that assembling it requires several people, several exports, and considerably longer than the regulator’s patience allows.

A record that exists is not the same as a record you can produce. The distance between those two things is exactly where audits become uncomfortable.

The mistakes that surface first in a real audit

Policies that describe a process nobody actually follows

A written procedure that has quietly drifted from daily practice is worse than no procedure at all, because it invites the regulator to ask why the two do not match.

Evidence that exists but cannot be dated

A record with no clear timestamp showing when a check happened, or when a decision was made, is difficult to rely on however complete it otherwise looks.

Personal licence holders relying on someone else to report for them

Key events tied to an individual must be reported by that person directly. A well meaning colleague filing on their behalf does not satisfy the requirement, however promptly it happens.

A threshold or rule that changed without the policy catching up

Regulatory detail shifts, ownership thresholds move, reporting windows get adjusted, and a policy document written before the change quietly becomes inaccurate until someone notices.

Signs you already have an evidence gap

Worth an honest answer before the regulator asks

  • Nobody could produce a complete customer record inside an hour without contacting several other people first
  • Different teams would describe the same compliance process slightly differently if asked separately
  • The last policy review predates the most recent change to a relevant threshold or deadline
  • Personal licence holders are not fully aware they must report certain events themselves
  • Nobody has actually rehearsed producing evidence under time pressure before being asked to for real

None of these signs alone guarantees a difficult audit. Together, they describe exactly the kind of gap that stays invisible until the moment it is tested.

A practical path to audit ready

  1. Map where each category of evidence actually livesList every system holding KYC, AML, safer gambling and key event records, and be honest about which ones do not currently connect to each other.
  2. Time a real retrieval before the regulator doesPick a genuine customer case and measure how long it actually takes to assemble a complete, defensible account today.
  3. Assign clear ownership per categoryName who is accountable for each category above being genuinely audit ready, not just logged somewhere in principle.
  4. Automate the connection, not just the loggingBuild the link between systems that currently requires manual assembly, so a complete record can be produced in minutes, not days.
  5. Rehearse a full response before you need oneRun a mock request through the same process a real audit would use, and fix whatever it reveals while there is no regulator watching.

What audit ready actually feels like

Operators who reach this standard describe audits as a formality rather than a fire drill. A request for a specific customer’s record produces a complete, coherent account in minutes, pulled automatically from systems that were built to connect in the first place. Compliance staff spend the audit period answering questions, not assembling evidence under pressure the night before. And every one of the three bars, logged, connected and defensible, is cleared as a matter of routine, not as a last minute scramble triggered by a letter from the regulator.

None of that requires a larger compliance team. It requires treating the connection between your systems as seriously as the records sitting inside each one, and revisiting that connection every time a threshold, a deadline or a code of practice quietly moves. That standard is available to any operator willing to test their own evidence before a regulator does it for them.

Want the PDF?

You’ve just read the whole thing. If you’d like the formatted version to keep or pass on, tell us where to send it.

bots for that needs the contact information you provide to send you resources and contact you about our products and services. You may unsubscribe from these communications at any time.

← All guides