AGLC SRIG and GLI Certification: How Alberta’s ATF Framework Works for Internet Gaming
Alberta's SRIG requires ATF certification from AGLC-registered labs before any gaming system goes live. See exactly how GLI-19 and GLI-33 satisfy those obligations, and where they fall short.
The AGLC Standards and Requirements for Internet Gaming (SRIG), issued by the AGLC Board Chair on 14 January 2026 and updated 17 March 2026, mandates Accredited Testing Facility (ATF) certification for all games, random number generators, and critical system components before they are deployed in the Alberta market. That certification obligation sits within Section 4.12 of the SRIG, and it is the primary technical gateway through which GLI-19 and GLI-33 certifications operate. Understanding precisely what those certifications cover, what the SRIG requires of the ATF itself, and what obligations sit entirely outside any GLI certificate is the practical question every compliance officer and supplier technical team must answer before submitting a go-live package to the AGLC iGaming Compliance Branch.
The ATF Framework Under SRIG Section 4.12
The SRIG does not simply accept any independent testing laboratory (ITL) certificate. ATF certifications must be issued only by ATFs that are registered by AGLC. A GLI certificate issued for another jurisdiction, including an Ontario AGCO registration, a UKGC approval, or an MGA technical audit, does not automatically satisfy the Alberta ATF requirement. The ATF must hold its own AGLC registration, and the SRIG requires that AGLC’s Standards and Requirements for Internet Gaming be added to the ATF’s scope of ISO accreditation within one year of the ATF being registered as an iGaming Goods or Services Supplier in Alberta, within the next accreditation audit schedule.
The scope of mandatory certification under Section 4.12 covers all games, RNGs, and components of iGaming systems that accept, process, determine outcome, display, and log details about player bets. This includes slot games, table games, Sport and Event Betting, poker, and other card games. For live dealer games, the certification must specifically address physical RNGs with electronic elements and similar physical equipment used to determine game outcome, explicitly including physical wheels (roulette), physical dice tables, and card shufflers with electronic components.
“ATF certifications must ensure technology is certified for all games, random number generators and components of iGaming systems that accept, process, determine outcome, display and log details about player bets.”
Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), Section 4.12 Certification By Accredited Testing Facilities, issued 14 January 2026, authority: Board Chair.
A certificate must not contain a limitation on AGLC’s use of the certification, and must not purport to disclaim AGLC’s use of the certification. This is an explicit prohibition in the SRIG that operators must verify when reviewing ATF instruments obtained for other purposes. An ATF may issue a certificate specifying that one or more features must be disabled for the technology to comply with the relevant Standards, but the ATF may not issue a certification contingent on any future changes or modifications to the technology.
The mandatory content of every ATF certification instrument under the SRIG is prescribed precisely. The instrument must include the AGLC-registered name of the ATF completing the certification, the AGLC-registered name of the operator or Goods or Services Supplier requesting certification, the date of issuance, and a unique identifier for AGLC tracking and follow-up. Any certificate missing these elements fails the Section 4.12 requirement, regardless of its technical depth.
Does a GLI Certificate from Another Jurisdiction Satisfy the AGLC ATF Requirement?
No. A GLI-19 or GLI-33 certificate obtained for the Ontario, UKGC, or MGA markets does not satisfy AGLC’s ATF requirement. The issuing ATF must be independently registered with AGLC, the certification instrument must reference the Alberta SRIG, and the document must contain the SRIG-mandated fields described in Section 4.12. Suppliers should confirm with their ATF whether an Alberta-specific certification can be issued on the basis of an existing test package, or whether new testing is required for Alberta-specific SRIG provisions.
How GLI-19 v3.0 Maps to AGLC’s Interactive Gaming Obligations
GLI-19: Standards for Interactive Gaming Systems version 3.0 (revised 17 July 2020) is the benchmark standard used by AGLC-registered ATFs for the certification of casino games, RNG systems, and online gaming platforms. Its scope encompasses server-side game logic, RNG requirements and statistical validation, game client presentation, account management, and financial transaction controls, all areas that SRIG Section 4 directly addresses.
For RNGs, GLI-19 Chapter 3 sets detailed requirements that align with SRIG Section 4.7 (Determination of Game Outcomes). Software-based RNGs must satisfy cycle-length requirements, pass statistical testing suites, and implement state compromise extension attack protections requiring periodic modification of the RNG state through external entropy. Hardware-based RNGs must implement dynamic output monitoring with statistical testing that disables game play when malfunction or degradation is detected. Mechanical RNGs require data collection of at least 10,000 game outcomes as a baseline, with the certificate clearly stating the amount of data used.
GLI-19 Chapter 4 addresses game outcome evaluation and directly supports SRIG Section 4.7’s requirement that determination of game outcomes be certified. The standard requires that game selection processes not limit the outcomes available for selection except as provided by game design, and that games not modify or discard RNG outcomes due to adaptive behaviour. These requirements map precisely to the SRIG’s certification scope for games that determine, display, and log player bet outcomes.
For player account management and responsible gambling controls relevant to SRIG Sections 3 and 4.4, GLI-19 Section 2.5.5 addresses limitations and exclusions. The standard requires that self-imposed limitations set by a player do not override more restrictive operator-imposed limitations, and that the more restrictive limitations take priority. This architecture supports the AGLC’s centralized self-exclusion mandate, though actual CSE API integration is an AGLC infrastructure obligation that sits outside GLI-19’s scope entirely.
GLI-19 Appendix A covers player protection information requirements, mandating that systems provide players with information on potential risks of excessive gaming, available protective measures including self-imposed exclusion, and mechanisms for reporting complaints. The standard also addresses PII security, requiring designated staff responsibility for data security procedures and breach notification protocols. These provisions support but do not discharge SRIG Section 5’s IT and security obligations, which impose Alberta-specific requirements that GLI-19 does not address.
How GLI-33 v1.1 Maps to AGLC’s Sport and Event Betting Obligations
GLI-33: Standards for Event Wagering Systems version 1.1 (revised 14 May 2019) governs Sport and Event Betting systems. Under the SRIG, Section 4.6 addresses Sports and Event Betting, and the Go-Live Compliance Guide confirms that certification scope for event wagering systems specifically includes the standards relevant to sport and event betting systems being tested.
GLI-33 Chapter 2 sets system clock requirements mandating time-stamping of all transactions and events, a direct operational necessity for SRIG Section 4.11 (Internal Controls) and the SRIG’s records retention requirement of a minimum of three years for compliance-related logs. Chapter 2 also mandates control program authentication, requiring that each critical control program component have a method to be verified via an independent third-party verification procedure operating independently of any process or security software within the system.
GLI-33 Chapter 4 sets wagering rules and requirements covering wagering period close enforcement (no wagers permitted once the wagering period has closed), dynamic wagering information display, and results and payment handling. The standard requires that comprehensive wagering rules be posted for all markets and event types currently offered. This supports SRIG Section 4.6, though the SRIG separately prohibits wagering on political events, events involving human suffering or animal cruelty, and financial market instruments. These prohibitions are AGLC-specific and are not addressed within GLI-33 itself.
GLI-33’s two certification appendices are operationally significant for Alberta suppliers. Appendix A covers an Operational Audit including review of bet processing procedures, voiding and cancellation practices, player account management, and any objectives established by the regulatory body. Appendix B covers an Operational Audit of Technical Security Controls, including an information security system assessment, review of operational processes critical to compliance, penetration testing of external and internal infrastructure, and review of applications transferring, storing, and processing player data. The Appendix B penetration testing requirement overlaps with but does not replace the SRIG’s own Section 5 requirement for independent security vulnerability assessments and penetration testing of Alberta production infrastructure.
Scope clarity: GLI-33 certification covers event wagering system compliance. SRIG-specific prohibitions on betting markets (political events, financial instruments) are regulatory obligations that exist outside GLI-33 and must be implemented independently by operators and verified through the SRIG Section 4.6 compliance process.
What Does GLI Certification Not Cover?
GLI-19 and GLI-33 certifications are necessary conditions for AGLC market entry, but they are not sufficient. Several categories of SRIG obligation sit entirely outside GLI certification scope, and compliance teams must treat them as parallel workstreams rather than downstream consequences of a successful ATF engagement. For a broader view of how Alberta’s certification framework compares to Ontario’s equivalent structure under the AGCO Registrar’s Standards for Internet Gaming, the AGLC standards explorer maps requirements side by side.
Section 5: IT and Security Requirements
SRIG Section 5 imposes a structured IT security framework that GLI standards do not cover. A recognized industry standard framework must be used to manage the IT control environment. Access privileges must be reviewed and certified by data owners on a quarterly basis, with least-privilege and separation-of-duties confirmations. Administrative and privileged accounts must be protected by phishing-resistant multi-factor authentication.
For data centres and remote gaming servers, SRIG Section 5 requires AGLC approval, including data residency designation, cross-border transfer assessment, and encryption key residency review. All remote access methods must be secure and centrally managed using zero-trust principles, device posture checks, MFA, and session recording for third-party access. Wireless communication requires industry-standard encryption, central management, and prior AGLC approval.
The Go-Live Compliance Guide (last updated January 2026) translates Section 5 into a specific cyber-security documentation package. Operators must provide a SOC 2 Type 1 attestation at market launch for all iGaming sites named on their registration. Within two years following market launch, operators must obtain SOC 2 Type 2 or ISO 27001, or an equivalent approved by AGLC. Certification-granting firms for SOC 2 Type 1 and 2 must be peer-reviewed and members of the American Institute of Certified Public Accountants (AICPA). Third-party data centre and cloud providers must each supply a current SOC 2 report or ISO 27001 certification.
Penetration testing must be completed before market launch and annually thereafter. Vulnerability remediation timescales are prescribed: critical issues with a Common Vulnerability Scoring System (CVSS) score of 9 or above must be resolved within 48 hours, those scoring below 7 must be resolved within 30 days. Management responses detailing risk assessment, remediation plans, and compensating controls must be documented, and remediations must be verified through a follow-up scan.
Centralized Self-Exclusion API Integration
AGLC operates a Centralized Self-Exclusion (CSE) system. Integration via API is mandatory for all operators and is a separate step in the AGLC registration process, distinct from both ATF certification and the AiGC commercial agreement. The CSE covers both online and land-based gaming: a player self-excluded through the CSE is inadmissible to any gaming facility in Alberta, whether online or land-based. The three exclusion options are: excluding from all registered iGaming platforms, from all land-based casinos and racing entertainment centres, or from both. All three must be implemented by operators through the API integration.
Neither GLI-19 nor GLI-33 certification addresses the CSE API integration. GLI-19 Section 2.5.5 requires that the Interactive Gaming System be able to correctly implement limitations and exclusions, which creates a technical pre-condition, but the AGLC CSE is a province-managed system requiring a specific data connection that must be tested in AGLC’s User Acceptance Testing environment before market launch.
Architecture and Infrastructure Approval
SRIG Section 5 requires operators and Goods or Services Suppliers to submit a gaming site diagram as part of their go-live documentation package. The gaming system architecture and all its related components must demonstrate security in depth. All gaming systems and devices must validate inputs before processing, and the gaming system must display the minimum information about the system to unauthorized users and during malfunctions. Only dedicated and specific accounts may be used to make changes in technical environments, and all changes must be logged to support both software and hardware related modifications.
Goods or Services Suppliers must adhere to data security standards and data requirements as published for the Application Programming Interfaces (APIs). This obligation applies to all API connections to the operator’s gaming site and is separate from the GLI certification of games hosted on the platform.
Change Management: The Three-Category Classification System
Post-launch, the SRIG and Go-Live Compliance Guide establish a three-category modification framework that determines when re-certification is required. This framework applies to all operators and Goods or Services Suppliers running critical gaming systems.
| Modification Category | Definition | Certification Requirement |
|---|---|---|
| Non-Regulatory | Cosmetic or minor changes unrelated to the SRIG (e.g. bug fixes, language updates) | No recertification required, confirm changes are non-regulatory |
| Regulatory | Changes affecting compliance or addressing regulatory concerns without urgency | Must be certified by AGLC-registered ATF before deployment |
| Regulatory Fix (Emergency) | Urgent fixes for live issues impacting integrity or the SRIG (major integrity impact) | Deploy immediately, submit to ATF for Alberta certification within 5 business days of release |
Re-certification is also required when any modification or subsequent discovery of an undetected issue impacts critical gaming system integrity, fairness, security, or compliance. When an ATF identifies issues in certified games or game systems that materially impact the certification, the SRIG requires the ATF to suspend any issued certifications and notify the affected registered iGaming Supplier. The submitting party must maintain records of testing and ATF certification and provide this documentation to AGLC upon request.
“The fixed technology can be deployed immediately but must be submitted to an ATF for Alberta certification within five business days of release.”
Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), Section 4.12 / AGLC Internet Gaming Go-Live Compliance Guide, January 2026.
What Does the Go-Live Certification Package Require?
The Go-Live Compliance Guide assembles the SRIG’s disparate technical obligations into a single submission framework. The core documentation package for operators and Goods or Services Suppliers running critical gaming systems includes a Control Activity Matrix (CAM) summarising all gaming site controls, including those provided by third-party platform providers. The CAM must be accompanied by an independent audit (internal audit or external auditor acceptable to AGLC), with audit results submitted alongside the CAM. A Standards and Requirements gap analysis must also be submitted, mapping the operator’s or supplier’s systems against each applicable SRIG provision.
ATF certifications are required for all in-scope technologies, covering games, RNGs, remote gaming servers, and sport and event betting systems, before deployment. The Go-Live Guide is explicit that certification scope is not all SRIG Standards, but only those relevant to the specific games, RNGs, remote gaming servers, and event wagering systems being tested. ATFs receive AGLC guidance on likely applicable standards, but final determination occurs after reviewing the specific technology. Operators cannot simply present a GLI-19 or GLI-33 certificate and treat all SRIG technical requirements as covered, the ATF’s scope determination is a separate step in the certification engagement.
Mechanisms demonstrating that installed software is ATF-certified and that the integrity of deployed software is verified must also be documented. For third-party software running on the platform, operators must be able to show that the specific version deployed in Alberta is the certified version, a practical requirement that demands robust version control and certificate linkage across the full game content catalogue.
Records Retention and Compliance with SRIG Section 4
SRIG Section 4 requires that information, including logs, related to compliance with the law, the SRIG, and adherence with Control Activities be retained for a minimum of three years, unless otherwise stated. Attestations supporting quarterly access privilege reviews must be retained for at least two years. These retention periods apply to all certification-related documentation, including ATF certification instruments, CAM submissions, penetration testing results, and remediation records.
Under SRIG Section 4.9, operators and suppliers running peer-to-peer games must ensure there are no conflicts of interest in performing their role, explicitly including acting as an operator or oddsmaker. This requirement has particular relevance for suppliers who both operate systems and hold positions that could influence outcomes, and it represents an AGLC-specific governance obligation that sits alongside but is separate from GLI-19’s peer-to-peer game session requirements in Chapter 4.
Practical Implications for Operators and Goods or Services Suppliers
The certification workstream for Alberta entry has at least four parallel tracks that must be completed before any go-live authority is obtained from AiGC. ATF certification of games and systems addresses the SRIG Section 4.12 obligation. IT security documentation, covering SOC 2 Type 1, penetration testing, and architecture diagram, addresses Section 5. CSE API integration addresses Section 3.5. The AiGC commercial agreement, which governs operating authority itself, is separate from all of the above.
Suppliers that have already obtained GLI-19 or GLI-33 certifications for the Ontario market under the AGCO Registrar’s Standards for Internet Gaming have a material head start, but the certification cannot simply be transferred. The ATF must be AGLC-registered, the certificate must reference the Alberta SRIG, and the certification instrument must contain the SRIG-mandated fields including the AGLC-registered names of both the ATF and the requesting party. Suppliers should confirm with their ATF whether an Alberta-specific certification can be issued on the basis of the Ontario test package, or whether new testing is required for Alberta-specific SRIG provisions.
For operators aggregating third-party game content from multiple suppliers, the version control and certificate linkage requirement carries significant operational weight. Each game deployed in Alberta must have a corresponding ATF certification in place before deployment. Where a supplier pushes an update that falls into the Regulatory category, that update cannot be deployed in Alberta until the updated version has been certified, regardless of whether the same update has already been live in other jurisdictions for weeks. The five-business-day window for Regulatory Emergency Fixes is the only exception, and it requires the submission process to begin immediately on deployment.
Compliance officers should treat the AGLC iGaming Compliance Branch as the primary point of contact for certification questions. The branch can be reached at igamingcompliance@aglc.ca and provides guidance to registered ATFs on likely applicable Standards, though as the Go-Live Guide notes, such guidance cannot be definitive in advance of a substantive review of the gaming equipment software under review for certification. Operators and suppliers requiring jurisdiction-specific legal advice on Alberta SRIG obligations should consult qualified legal counsel practising in Alberta gaming law.
For a detailed comparison of how Alberta’s certification framework differs from Ontario’s equivalent AGCO structure, see our analysis of AGCO vs AGLC key differences. For a deeper technical comparison of the two GLI standards themselves and how to choose a certification path, see GLI-19 vs GLI-33: choosing the right standard for your certification path.
Key Resources
AGLC Standards and Requirements for Internet Gaming (SRIG), issued 14 January 2026, updated 17 March 2026, aglc.ca/igaming. The primary compliance document governing all registrants.
AGLC Internet Gaming Go-Live Compliance Guide (last updated January 2026), available via aglc.ca/igaming. Translates SRIG obligations into a concrete pre-launch submission checklist.
GLI-19: Standards for Interactive Gaming Systems v3.0 (revised 17 July 2020), Gaming Laboratories International (gaminglabs.com). The benchmark standard for RNG and interactive gaming platform certification.
GLI-33: Standards for Event Wagering Systems v1.1 (revised 14 May 2019), Gaming Laboratories International (gaminglabs.com). The benchmark standard for sport and event wagering system certification.
Gaming, Liquor and Cannabis Act (Alberta, consolidated) and iGaming Alberta Act, aglc.ca. The enabling statutory framework for the SRIG and all operator and supplier obligations.
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.
The Tuesday brief, every week.
One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.
Unsubscribe with one click. We'll never share your address.