Audit-ready Operations Checklist
Everything a regulated operator needs logged, connected and defensible before the next audit.
Audits rarely fail on a missing policy
Almost every operator can produce a policy document for almost every obligation they hold. What separates an operator who sails through a regulatory audit from one who does not is rarely whether the policy exists. It is whether the evidence behind it can actually be produced, quickly, in a form that withstands a direct follow up question.
This guide is built around a distinction most compliance checklists skip entirely. Information can be logged, connected, or defensible, and these are three genuinely different bars, not three words for the same thing. Most operators clear the first without realising they have not cleared the other two. This guide sets out exactly what needs to reach all three, category by category, before the next audit arrives rather than during it.
None of what follows is generic advice dressed up as a checklist. Every category below maps to a specific, current obligation, and every item inside it is something an auditor could plausibly ask you to produce on the day, not a nice to have you could reasonably defer.
A note on scope. This guide reflects the UK regulatory position at the time of writing, August 2026. Confirm current detail against Gambling Commission guidance and take your own compliance advice before relying on any point here.
The three bars an audit actually applies
| Bar | What it actually means |
|---|---|
| Logged | The information exists somewhere in the business, in some system or record, even if nobody could locate it quickly |
| Connected | That information can be assembled into a single, coherent account without days of manual cross referencing between systems |
| Defensible | The assembled account survives a specific, pointed follow up question, not just a first glance |
An operator who has only cleared the first bar often feels compliant right up until an actual request arrives. The gap between logged and defensible is exactly where audits go from routine to uncomfortable.
KYC and identity verification
Age and identity verification, name, address and date of birth, has to be completed before a customer can deposit, gamble with real money, or access free to play features, with no grace period and clear upfront disclosure of what identification may be required.
- A record for every customer showing exactly when age and identity were verified, and against what
- Evidence of what identification requirements were disclosed to the customer, and when
- A clear log of any account that was permitted to deposit or play before verification completed, and why
- A record connecting verification outcomes to the specific provider or method used, in case that method is later questioned
AML and financial crime
Casino operators, remote and non-remote, sit directly within the Money Laundering Regulations 2017. Recent changes effective from 30 June 2026 sharpened two specific triggers worth being ready for directly: enhanced due diligence tied to a refined definition of high risk third countries based on FATF’s own call for action list, and enhanced due diligence and ongoing monitoring for any transaction or relationship that is unusually large or unusually complex. Every operator, regardless of MLR status, faces AML expectations under the LCCP and the Proceeds of Crime Act, including suspicious activity reporting.
- A documented money laundering and terrorist financing risk assessment, reviewed and dated, not written once and forgotten
- Enhanced due diligence records for every customer relationship meeting a high risk third country or unusually large or complex transaction trigger
- A clear, timestamped record of every suspicious activity report considered, including those reviewed and not submitted, with the reasoning behind that decision
- Evidence of ongoing monitoring, not just a check performed once at onboarding
How long records actually need to survive
Being audit ready is not just about producing a record. It is about still having it when it is asked for. Under Regulation 40 of the Money Laundering Regulations 2017, customer due diligence documents and transaction records must be kept for at least five years, running from the end of the business relationship or the completion of the transaction, with certain records capped at a maximum of ten years. Once that period passes, personal data obtained for these purposes generally has to be deleted, unless it is genuinely needed for ongoing legal proceedings.
This creates a real, worth naming tension. Data protection principles push toward keeping personal data no longer than necessary. Anti money laundering rules require it to survive a fixed minimum period regardless. Getting this balance wrong in either direction creates exposure, either a record that has vanished before an audit needs it, or personal data retained well past the point it should have been deleted.
Safer gambling and customer interaction
Customer interaction requirements under the Social Responsibility Code cover how an operator identifies and responds to indicators of problem gambling, including specific expectations around VIP and high value customers. Existing light touch financial vulnerability checks sit alongside the incoming, higher tier Financial Risk Assessments, still being introduced in stages at the time of writing.
- A record of every vulnerability or risk indicator identified for a customer, and the action taken in response
- Evidence that VIP or high value customers received the additional scrutiny this status requires, not just standard treatment
- A clear account of how marketing and promotional activity was handled once a risk indicator was identified for a customer
- Readiness evidence for Financial Risk Assessments as they roll out, even before your firm falls within an active stage
Key events, reportable events and ownership
| Event type | Reporting deadline |
|---|---|
| Investigation by a regulatory or government body into the licensee or a key position holder | Five working days from becoming aware |
| Criminal investigation involving the licensee or a key position holder | Five working days from becoming aware |
| Change in ownership or control, including 5% or more of voting rights or dividend entitlement | As set out under the current licence condition, via eServices |
| Personal licence holder’s own reportable key events | Must be reported by the individual themselves, not delegated to a colleague |
All key events and other reportable events are submitted through the Commission’s eServices digital portal. Ownership and control notification thresholds changed to 5% of voting rights or dividend entitlement from March 2026, replacing the previous 3% threshold in most cases. It is worth checking this specific detail is reflected in your current internal process, since a threshold change like this is easy to miss if nobody owns updating the policy document that references it.
Why disconnected systems fail the second bar
Every category above can be, and often is, logged somewhere. The point at which operators visibly struggle during an actual audit is rarely a missing record. It is the moment they are asked to produce a single, coherent account that pulls from several systems at once, a customer’s verification history alongside their transaction pattern alongside their vulnerability flags, and discover that assembling it requires several people, several exports, and considerably longer than the regulator’s patience allows.
The mistakes that surface first in a real audit
Policies that describe a process nobody actually follows
A written procedure that has quietly drifted from daily practice is worse than no procedure at all, because it invites the regulator to ask why the two do not match.
Evidence that exists but cannot be dated
A record with no clear timestamp showing when a check happened, or when a decision was made, is difficult to rely on however complete it otherwise looks.
Personal licence holders relying on someone else to report for them
Key events tied to an individual must be reported by that person directly. A well meaning colleague filing on their behalf does not satisfy the requirement, however promptly it happens.
A threshold or rule that changed without the policy catching up
Regulatory detail shifts, ownership thresholds move, reporting windows get adjusted, and a policy document written before the change quietly becomes inaccurate until someone notices.
Signs you already have an evidence gap
Worth an honest answer before the regulator asks
- Nobody could produce a complete customer record inside an hour without contacting several other people first
- Different teams would describe the same compliance process slightly differently if asked separately
- The last policy review predates the most recent change to a relevant threshold or deadline
- Personal licence holders are not fully aware they must report certain events themselves
- Nobody has actually rehearsed producing evidence under time pressure before being asked to for real
None of these signs alone guarantees a difficult audit. Together, they describe exactly the kind of gap that stays invisible until the moment it is tested.
A practical path to audit ready
- Map where each category of evidence actually livesList every system holding KYC, AML, safer gambling and key event records, and be honest about which ones do not currently connect to each other.
- Time a real retrieval before the regulator doesPick a genuine customer case and measure how long it actually takes to assemble a complete, defensible account today.
- Assign clear ownership per categoryName who is accountable for each category above being genuinely audit ready, not just logged somewhere in principle.
- Automate the connection, not just the loggingBuild the link between systems that currently requires manual assembly, so a complete record can be produced in minutes, not days.
- Rehearse a full response before you need oneRun a mock request through the same process a real audit would use, and fix whatever it reveals while there is no regulator watching.
What audit ready actually feels like
Operators who reach this standard describe audits as a formality rather than a fire drill. A request for a specific customer’s record produces a complete, coherent account in minutes, pulled automatically from systems that were built to connect in the first place. Compliance staff spend the audit period answering questions, not assembling evidence under pressure the night before. And every one of the three bars, logged, connected and defensible, is cleared as a matter of routine, not as a last minute scramble triggered by a letter from the regulator.
None of that requires a larger compliance team. It requires treating the connection between your systems as seriously as the records sitting inside each one, and revisiting that connection every time a threshold, a deadline or a code of practice quietly moves. That standard is available to any operator willing to test their own evidence before a regulator does it for them.
Want the PDF?
You’ve just read the whole thing. If you’d like the formatted version to keep or pass on, tell us where to send it.
Please enter a valid email address.
bots for that needs the contact information you provide to send you resources and contact you about our products and services. You may unsubscribe from these communications at any time.
