Back to Blog
Blog8 min read

UKGC's Information Security Audit Requirements: A Deep Dive

A

Alexander Sverdlov

Security Analyst

7/20/2026
UKGC's Information Security Audit Requirements: A Deep Dive

If you hold a remote operating licence in Britain, the security audit is not an optional badge you chase for marketing. It is a condition of keeping your doors open. The UK Gambling Commission (UKGC) treats the protection of customer data and the integrity of gaming outcomes as licensing matters, and it has the power to fine, suspend, or revoke. I have sat on the operator side of enough regulated security programmes to know where these audits go smoothly and where they turn into a scramble, so this is the practical version of what the UKGC expects and how to prepare for it.

One clarification first, because the name trips people up constantly. The regulator is the Gambling Commission, not the "Gaming Commission." That precision matters, because the same precision is what an assessor will apply to your controls, your evidence, and your remediation.

UK Gambling Commission information security audit scope covering customer data, transactions, and game integrity

Why the UKGC cares so much about security

An online gambling operator is, from an attacker's point of view, an unusually attractive target. You hold verified identity documents, dates of birth, home addresses, and payment credentials on large numbers of people, and you move real money at speed. That combination of rich personal data and live financial flows is exactly what criminal groups look for.

The Commission's licensing conditions and codes of practice require operators to keep customer information secure and to run games fairly. A serious security failure is therefore not just an IT incident; it is a potential breach of your licence conditions and, where personal data is involved, a matter for the Information Commissioner's Office under UK GDPR as well. The information security audit is how the Commission gains assurance that you are actually meeting those obligations rather than simply claiming to.

The recognised standard behind the requirement

The UKGC does not ask operators to invent a bespoke security framework. Its security audit expectations are anchored to a recognised information security standard, and in practice that means an ISO/IEC 27001-aligned approach to your information security management system. Assessments are expected to be carried out by suitably qualified, independent security testers rather than self-certified by the operator, and the scope must cover the parts of your estate that touch customer data and gambling transactions.

If you are already building toward certification, you are most of the way there. Aligning your programme with ISO 27001 readiness gives you the management-system backbone the Commission looks for, and it means one body of evidence serves both the regulator and your commercial customers.

Scope: what the audit actually covers

The scope defines the breadth and depth of the assessment. For a gambling operator, it typically covers four connected areas.

  • Customer data protection: How personal and financial data is collected, encrypted in transit and at rest, access-controlled, retained, and disposed of. Assessors look for evidence that only the people who need data can reach it, and that you can prove who accessed what.
  • Transaction security: The secure processing of deposits, withdrawals, and wagers. Because operators handle large volumes of money, payment flows must be free of the vulnerabilities that allow tampering, fraud, or double-spending. If you take card payments directly, this overlaps heavily with PCI DSS obligations.
  • Game and system integrity: The systems that determine play outcomes, including random number generation, must be tamper-proof and demonstrably fair. This is where gambling audits go beyond a normal corporate security review.
  • Network and infrastructure security: The platform must be defended against intrusion, denial-of-service attacks, and lateral movement. Segmentation, hardening, and monitoring all fall under this heading.

The technical controls assessors expect to see

A UKGC-oriented information security audit is multi-faceted. These are the controls that come up in almost every assessment, and the ones I would make sure are solid before an assessor arrives.

  • Penetration testing: Independent testers attempt to exploit real weaknesses in your platform, APIs, and infrastructure, simulating how an actual attacker would behave. This is the single most revealing part of the exercise. A credible programme runs penetration testing on a regular cadence and after significant changes, not once a year as a checkbox.
  • Vulnerability management: Continuous identification, prioritisation, and remediation of weaknesses across your estate. A one-off vulnerability assessment tells you where you stand today; a managed process keeps you there.
  • Patch and update discipline: Outdated software is a predictable entry point. Gaming platforms and their third-party components need timely, tracked updates with a documented process.
  • Strong authentication: Multi-factor authentication for administrative and privileged access, so a single stolen password does not hand an attacker the keys. This applies to your staff and your infrastructure, not just to customers.
  • Logging and monitoring: You need to detect suspicious activity as it happens and reconstruct events afterward. Assessors want evidence that logs exist, are retained, and are actually reviewed.
  • Incident response plan: Prevention fails eventually. The Commission expects a documented, tested plan that sets out how you contain, investigate, report, and recover from a breach, including your regulatory notification obligations.

The audit report and remediation

The audit produces a report that gives the Commission a clear, honest picture of your security posture. A useful report is not a pass or fail sticker; it is a working document. Expect it to set out:

Report element What it captures
Findings Specific vulnerabilities identified, from minor issues to serious gaps.
Impact assessment What each weakness could realistically lead to if exploited.
Remediation steps The concrete actions required to close each finding.
Timeline A prioritised schedule for fixes, with the highest-risk items first.

The Commission understands that not every fix is instant, but it does expect prompt, evidenced action on the serious items. A report that identifies critical findings and is followed by silence is worse than no report at all, because it demonstrates awareness without response.

Where operators lose time preparing

The audit itself rarely surprises a well-run operator. What causes the scramble is preparation, and the same few gaps come up again and again.

  • No clear scope boundary. Operators often cannot say with confidence which systems process customer data and which do not. If you cannot draw that line, the assessor draws a wider one, and the audit grows. Map your data flows before anyone tests you.
  • Evidence that lives in people's heads. "We do patch regularly" is not evidence. A ticketing history, a patch report, and a documented process are. Assessors score what you can show, not what you assert. Assume every control needs a paper trail.
  • Third parties treated as out of scope. Payment processors, game providers, KYC vendors, and cloud hosts all touch regulated data. Their weaknesses become your findings. You need contracts, assurance reports, and a supplier risk process that covers them.
  • Privileged access sprawl. Old admin accounts, shared credentials, and standing access for developers into production are among the most common serious findings. Tighten and document who can reach what before the test, not after.
  • Untested incident response. A plan that has never been rehearsed tends to fall apart under a real assessor's questions. Run a tabletop exercise so your team can describe, from memory, exactly what happens in the first hour of a breach.

Fixing these before the assessor arrives is far cheaper than remediating them under a regulatory deadline. Most of them are process and documentation problems, which means they take lead time rather than money, and lead time is the one thing a looming audit does not give you.

Ongoing monitoring, not a one-off event

A single audit is a snapshot. The threat landscape moves daily, new vulnerabilities surface, and every code deployment can introduce new weaknesses. That is why a mature operator treats security as a continuous programme: regular audit cycles, ongoing monitoring, penetration testing after major changes, and a vulnerability management process that runs all year. Being reactive is not enough; the Commission rewards operators who are demonstrably proactive.

For many mid-sized operators, the hard part is not knowing this, it is owning it internally. There is often no single person accountable for the whole security and regulatory picture. That is precisely the gap a virtual CISO fills, giving you senior security leadership that can run the audit programme, manage remediation, and speak the Commission's language without the cost of a full-time hire. When you want an independent, assessor-grade view of where you stand today, a focused IT security audit is the right starting point.

Frequently Asked Questions

Who has to complete a UKGC security audit?

Operators holding a remote gambling licence from the UK Gambling Commission are subject to its security requirements. In practice, any business that runs online gambling for the British market and handles customer data and transactions needs to meet these expectations and be able to evidence them through independent assessment.

Does the UKGC require ISO 27001 certification specifically?

The Commission anchors its security audit expectations to a recognised information security standard, and an ISO/IEC 27001-aligned information security management system is the standard route to satisfying them. Building toward ISO 27001 gives you the management-system structure and evidence base the Commission looks for, and the same work supports your commercial due diligence too.

How often does the audit need to happen?

Treat it as a recurring programme rather than a single event. Security audits are expected on a regular cycle, and serious operators supplement them with ongoing monitoring, vulnerability management, and penetration testing after significant platform changes. Threats and code both change constantly, so a once-and-done approach does not hold up.

Can we run the audit ourselves?

No. The value and the credibility of the assessment come from independence. The Commission expects testing to be carried out by suitably qualified, independent security professionals rather than self-certified by the operator. Internal reviews are useful preparation, but they do not replace an independent audit.

What happens if the audit finds serious problems?

Findings are normal; what matters is your response. The report will set out each weakness, its potential impact, the remediation required, and a prioritised timeline. The Commission expects prompt, evidenced action on high-risk items. Ignoring critical findings is the outcome that puts a licence at risk, not the existence of the findings themselves.

How does this relate to PCI DSS and UK GDPR?

They overlap. If you process card payments, PCI DSS governs how that cardholder data is handled, and it sits inside the transaction-security part of your gambling audit. UK GDPR governs the personal data you hold on customers, so a data breach can trigger obligations to both the Gambling Commission and the Information Commissioner's Office. A well-scoped security programme addresses all three with one coherent set of controls.

Preparing for a UKGC information security audit? Atlant Security has run security assessments for regulated operators and can help you scope, test, and remediate against the Commission's expectations. See our IT security audit or book a discovery call.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

UKGC Information Security Audit Requirements | Atlant Security