Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
RegTech · Platform Evaluation 17 min read Aug 21, 2026

Build vs. Buy: A Vendor-Agnostic Scoring Framework for iGaming Compliance Management Platforms

Mid-size iGaming operators face a platform decision regulators never specify. Score audit trails, change feeds, and jurisdiction reporting against what UKGC, MGA, and AGCO actually require.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Aug 21, 2026 Updated 9h ago 17 min read Filed Compliance Tools & Resources

The compliance platform decision confronts mid-size iGaming operators at a moment of maximum pressure: they are managing two to ten regulatory jurisdictions simultaneously, each with its own documentation standards, reporting channels, and incident timelines. Every major regulator, the UK Gambling Commission, the Malta Gaming Authority, the Alcohol and Gaming Commission of Ontario, and Alberta Gaming, Liquor and Cannabis, specifies what compliance evidence must look like and when it must be available. None of them specifies which software you should use to produce it. That silence creates the build-vs-buy question, and vendors on both sides of it fill the space with advocacy. This framework fills it with regulatory requirements instead.

What Regulators Actually Require From Your Compliance Infrastructure

Before evaluating any platform, compliance teams must be precise about the underlying obligation they are trying to satisfy. The AGCO’s Registrar’s Standards for Internet Gaming states in Standard 1.10 that “compliance with the Standards and Requirements shall be documented in an organized manner to ensure that the information is capable of being reviewed and audited by an independent oversight function.” The requirement has four minimum sub-requirements: documentation must be reviewed and approved by management, internal and external auditors must have access to all relevant systems and documentation, the Registrar may direct the retention of a third-party auditor whose report goes directly to the Registrar, and internal audit must evaluate control activities on an ongoing basis.

The MGA’s Compliance Audit Manual (MGA/G/001, August 2018, v1) operationalises the same principle differently. It provides approved auditors with a structured checklist that spans corporate governance, AML, player protection, and technical infrastructure in a single review. The manual explicitly states that it is not exhaustive: auditors are expected to design additional procedures based on the specific risk profile of the licensee. The implication for platform selection is significant: a compliance management system that only tracks what is on the checklist will consistently under-document what auditors actually test.

Key requirement: Both the AGCO Registrar’s Standards (Standard 1.10) and the MGA Compliance Audit Manual (MGA/G/001) require that compliance documentation be organized, independently reviewable, and available on demand. Any platform that cannot produce a timestamped, version-controlled evidence file for a specific control on short notice fails this baseline.

The UKGC approach is structured through the Licence Conditions and Codes of Practice. LCCP Condition 15.2.1 requires licensees to report key events to the Commission via its eServices digital platform. These are events the Commission considers likely to have a material impact on the nature or structure of a licensee’s business. The LCCP’s information requirements extend further: AML records under Condition 12.1.1, suspicious activity reports under Conditions 15.1.1 and 15.1.2, and cheating intelligence under Condition 8.1.2 each carry their own channel, format, and timeliness obligation. A compliance platform that treats UKGC reporting as a generic task item rather than a structured regulatory submission workflow will generate errors at exactly the moments when precision matters most.

What Is the Minimum Audit Trail Standard Regulators Will Accept?

The AGCO requires that compliance documentation be organized, management-approved, and immediately accessible to both internal and externally directed auditors under Standard 1.10. The MGA’s Compliance Audit Manual (MGA/G/001) operationalises this by requiring auditors to verify that entity changes were notified in accordance with Regulations 36 and 37 of the Authorisations and Compliance Directive, with a traceable date, actor, and regulatory trigger for every update. A platform that cannot surface this evidence on demand, for any specific control, at any point in time, does not meet either standard.

The Control Activity Matrix as a Platform Stress Test

The Control Activity Matrix is the most operationally demanding compliance artefact a mid-size operator must maintain, and it is the single best diagnostic for whether a compliance management platform is adequate.

AGCO Standard 1.02 requires operators to develop, document, and implement formal control activities, to review them periodically for effectiveness, to communicate substantial changes to the Registrar in a timely manner, and to make them available to the AGCO or its designate at any time. Operators running critical gaming systems must develop a CAM that summarises all controls related to the gaming site, including controls performed by third-party suppliers and platform providers. The CAM must be assessed by an independent oversight function for alignment with the Standards and Requirements.

Alberta’s SRIG (Standards and Requirements for Internet Gaming, version dated 2026-03-17) mirrors this requirement and adds a pre-launch audit gate: the CAM must be independently audited before the operator goes live, with the audit results submitted as part of the go-live package. The SRIG specifies that the independent audit “must be carried out by a unit or function within the Operator’s organization that was not involved in developing the CAM (e.g., internal audit) or by a designated external auditor.” The audit results, confirming compliance, must be included with the CAM submission.

“Registered Operators must provide the Control Activity Matrix (CAM) as a summary of the Operators’ processes and controls related to the iGaming site. The required controls must be in place in advance of going live in Alberta’s iGaming market. CAMs must be independently audited to ensure the controls have been designed to ensure compliance with the Standards and Requirements.”, AGLC SRIG 2026-03-17

A platform that cannot version-control the CAM, flag third-party control gaps, and attach audit evidence to individual control activities will force compliance teams to maintain a parallel manual record. That duplication is both a resource cost and a source of inconsistency that auditors will identify.

Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), 2026-03-17, CAM Requirements section, AGCO, Registrar’s Standards for Internet Gaming, Standard 1.02.

The Five-Dimension Scoring Framework

The framework below scores both build and buy options across five dimensions that directly correspond to regulatory obligations. Each dimension is scored on a 1, 5 scale, where 5 represents full regulatory adequacy with minimal manual overhead, and 1 represents significant compliance risk requiring substantial manual mitigation. The scoring is vendor-agnostic: it applies to any commercial platform or any internally developed system.

Dimension What regulators require Build score range Buy score range Key risk if inadequate
Audit trail integrity Timestamped, tamper-evident, immediately available (AGCO 1.10, MGA MGA/G/001) 2, 5 3, 5 Evidence gaps during directed audit
Regulatory change feeds LCCP amendments, MGA supervisory updates, AGCO Notification Matrix revisions 1, 4 2, 5 Missed obligation cycles, stale controls
CAM version control Living document with change history, third-party mapping, audit attachment (AGCO 1.02, AGLC SRIG) 2, 5 2, 4 Non-compliant go-live submission
Jurisdiction-specific reporting modules Separate channels for UKGC eServices, MGA SBRM, AGCO iAGCO, AGLC Notification Matrix 1, 4 3, 5 Wrong format or wrong channel, missed deadlines
Third-party and supplier mapping Supplier list available to Registrar on request, CAM covers third-party controls (AGCO 1.19, 1.20) 2, 5 2, 4 Incomplete accountability chain during B2B review

Audit Trail Integrity: The Non-Negotiable Baseline

The audit trail requirement is the hardest to retrofit after a platform is deployed. The MGA Compliance Audit Manual specifies that auditors will check whether entity changes have been notified in accordance with Regulations 36 and 37 of the Authorisations and Compliance Directive, and whether the Authority holds current information across a detailed list of items including registered address, key persons, board composition, UBOs, and player bank accounts. Every update to any of these items must be traceable with a date, an actor, and the regulatory trigger that prompted the change.

For a UKGC licensee, the audit trail must extend into AML. LCCP Condition 12.1.1 places a direct obligation on licensees to implement policies, procedures, and controls to prevent money laundering and terrorist financing. Those controls must themselves be documented and reviewable. The Evolution AB settlement in 2026, in which Evolution agreed to pay £4.75 million to the UKGC following a 19-month review, illustrated what inadequate supply chain oversight looks like in practice: outdated AML risk assessments, insufficient monitoring of third-party operators, and games appearing on six unlicensed websites. The investigation identified that Evolution’s controls had not kept pace with the audit trail obligations the LCCP imposes on the licensee for the actions of its downstream clients.

A build solution can achieve a strong audit trail if it is architected correctly from the start. The practical failure mode is that internal builds prioritise current-state records over change history. Tamper-evidence and immutability are often afterthoughts. A commercial platform that has been tested against regulatory audit scenarios will typically have resolved these problems ahead of a bespoke build, but “tested against regulatory audit scenarios” is a claim that needs to be verified through a structured evaluation, not accepted from marketing materials.

Regulatory Change Feeds: Where Build Solutions Consistently Underperform

How does your compliance management system know when a regulatory obligation has changed?

This is the dimension where the build-vs-buy calculus most consistently favours commercial platforms, but with significant qualification. The UKGC amends the LCCP on a rolling basis and has an active consultation programme that produces binding changes on timelines that are not always predictable in advance. The MGA published supervisory engagement priorities in March 2026 that reoriented its compliance programme toward continuous engagement and risk-aligned testing rather than a fixed annual audit cycle. In Ontario, the AGCO Notification Matrix is a versioned document (version 1.9 is the current reference in the iGaming compliance framework) that is updated as obligations change. Alberta’s AGLC operates its own notification matrix under the SRIG framework, and the design pattern differences between the two Canadian frameworks are material: Ontario’s matrix reads as a more granular versioned control artefact, while Alberta’s is framed as a standards-based judgment tool linked to the broader SRIG document.

A compliance platform that subscribes to generic regulatory news aggregators and surfaces changes via keyword alerts will miss the document-level specificity that matters. The MGA’s May 2025 update on changes to the System Audit, System Review, and Compliance Audit procedures was not a headline-grabbing enforcement action. It was a procedural clarification that changed what approved auditors are expected to do during a review. Any operator whose change feed did not surface that update and route it to the person responsible for audit preparation missed a material change in their regulatory exposure.

Build solutions in this dimension face a structural problem: maintaining current feeds into each regulator’s primary publication channel requires ongoing human curation. A team that is simultaneously managing UKGC eServices submissions, MGA Licensee Portal updates, AGCO iAGCO notifications, and AGLC reporting will not have spare capacity to monitor regulatory websites for changes. Commercial platforms that embed compliance feeds as a product feature distribute this curation cost across their client base.

Jurisdiction-Specific Reporting Modules

The AGCO Notification Matrix defines three categories of information that registrants must provide on an ongoing basis: incident-based notifications, scheduled reports of data indicators, and other regulatory submissions. Operators use two secure channels to submit these: iAGCO for incident notifications and regulatory submissions, and a separate secure data exchange mechanism for scheduled data. The MGA uses its own Suspicious Betting Reporting Mechanism (SBRM), which requires betting data in a specific spreadsheet format (.xls), submitted via the Licensee Portal, with the relevant Key Compliance contact designated as the receiving party. The UKGC routes reporting through eServices, with specific form types for different LCCP conditions.

These are not interchangeable. A reporting obligation that belongs in the AGCO’s incident-based category triggers its own timeline and review process. An MGA suspicious betting report under Regulation 43 of Directive 3 of 2018 that is submitted in the wrong format or to the wrong channel is not treated as submitted. Ahead of the 2026 FIFA World Cup, the MGA issued a directive explicitly reminding operators of their obligations under Directive 3 of 2018 and the specific submission path through the SBRM, and separately required operators to appoint a designated Sports Integrity Point of Contact. An operator whose compliance platform does not distinguish these submission categories by jurisdiction and channel will either miss deadlines or submit to the wrong mechanism.

The AGCO Notification Matrix defines three distinct submission categories, incident-based, scheduled, and other regulatory, each with its own channel and review process. A generic task tracker cannot manage this without custom configuration that must itself be maintained as the matrix is versioned.

For an operator licensed in both the UK and Malta, the reporting obligations are structurally different in another important way. UKGC reporting runs through a single eServices platform, but the obligation to report exists under multiple LCCP conditions simultaneously: AML under 12.1.1, key events under 15.2.1, suspicious activity under 15.1.1, and cheating intelligence under 8.1.2. An MGA licensee managing sports betting must simultaneously operate within the SBRM for sports integrity reports, the Licensee Portal for corporate and compliance notifications, and the FIAU framework for AML reports under Malta’s Prevention of Money Laundering Act. The MGA audit preparation framework covers these overlapping obligations in detail, and a compliance platform must accommodate them as parallel, not sequential, reporting tracks.

The Third-Party and Supplier Mapping Obligation

AGCO Standard 1.19 states that operators are responsible for the actions of third parties with whom they contract for any aspect of the operator’s business related to gaming in Ontario, and must require those third parties to conduct themselves as if they were bound by the same laws, regulations, and standards. Standard 1.20 requires operators to maintain a list of suppliers providing goods or services in relation to lottery schemes and make it available to the Registrar on request. Standard 1.02 requires the CAM to cover controls performed by third parties, including platform providers.

This creates a documentation challenge that a compliance platform must accommodate structurally. Third-party supplier lists are not static: suppliers are added, removed, or change the scope of their services during the licence period. Each change is a potential notification event. The CAM must reflect third-party controls as they currently operate, not as they were described in the original go-live submission. Any operator relying on a white-label B2C platform, a B2B gaming supplier, or a managed SOC arrangement needs the platform to track supplier-specific controls as a distinct module that updates when the supplier relationship changes, not just when the operator’s internal processes change.

This is a dimension where neither build nor buy solutions consistently score well out of the box. Commercial platforms frequently offer supplier registers but do not link supplier records to specific controls in the CAM, which means the independence of the audit evidence chain is broken. Build solutions typically treat supplier management as a separate system entirely. The evaluation question for this dimension is: can the platform surface, for any given control activity, the third-party supplier responsible for operating it, the most recent assurance evidence for that supplier’s control, and the date on which the supplier relationship was last reviewed?

Build: When It Makes Regulatory Sense

A build decision is defensible under a specific set of conditions. An operator licensed in a single jurisdiction with a stable, well-understood compliance programme may achieve a higher score on the CAM version control and audit trail dimensions with a build solution, because it can be architected precisely around the regulatory artefacts that jurisdiction requires without the overhead of supporting multi-jurisdiction features. A UK remote gambling licensee whose compliance programme is entirely LCCP and RTS-driven will have well-defined documentation requirements, a single reporting channel, and a regulatory change cycle that, while active, is manageable by a dedicated team monitoring UKGC publications. For context on the full scope of UKGC obligations that system must support, the UKGC licence requirements profile maps the complete LCCP and RTS framework a build solution would need to cover. For that single-jurisdiction operator, a purpose-built internal system can outperform a generic commercial platform that was not designed with LCCP specificity.

The build case collapses when the operator holds licences in three or more jurisdictions simultaneously. The Ontario-Alberta pairing alone illustrates the problem: as the design pattern analysis of the AGCO and AGLC notification matrices confirms, these two frameworks are structurally different even though they regulate the same product in the same country. An internal system built for Ontario will need meaningful reconfiguration for Alberta, and that reconfiguration must itself be managed as a change control event reportable to both regulators if it affects the control environment. Multiply that by adding UKGC and MGA, and the maintenance cost of a build solution begins to exceed its initial development cost within two to three regulatory change cycles.

Buy: What the Evaluation Must Cover

Purchasing a commercial compliance management platform does not transfer regulatory accountability. The MGA Technical Infrastructure guidelines for Remote Gaming state explicitly that “the responsibility for the attainment of the established and desired standards on these regulatory principles will remain that of the licensee at all times.” That principle applies to compliance platforms as much as it applies to gaming systems and hosting infrastructure.

The evaluation of a commercial platform must address six specific points. Does the platform’s audit trail produce timestamped, tamper-evident records that satisfy the format the AGCO, MGA, and UKGC will accept during a directed audit? Does the regulatory change feed ingest primary-source amendments from each regulator’s own publication channels, or does it rely on secondary news aggregation? Does the CAM module support independent audit attachment, version history, and third-party supplier mapping at the control level? Does the jurisdiction-specific reporting module distinguish between submission categories within each regulator’s framework and route submissions to the correct channel? Can the platform be configured to reflect the specific standards applicable to the operator’s licence types, rather than a generic iGaming compliance checklist? And does the vendor’s update cycle align with the pace of regulatory change across the operator’s licence portfolio?

Operators evaluating platforms should also test the vendor’s response to a concrete scenario: “Show me how your platform would manage the AGCO’s Notification Matrix submission for an incident-based notification, including the correct submission channel, the timeline from trigger to submission, and the evidence record retained after submission.” If the answer is a demonstration of a generic task management workflow, the platform has not been built for the specific regulatory obligation it is claiming to address.

For operators navigating the specific requirements of Ontario’s regulated market, the compliance lessons from Ontario’s first three years provide concrete context on how the AGCO’s risk-and-outcomes-based approach translates into audit expectations on the ground.

The Mid-Size Operator’s Practical Decision Frame

Mid-size operators, defined here as those holding two to ten active licences across regulated jurisdictions, face a distinct version of the build-vs-buy question because their compliance complexity is high enough to strain a pure build solution, but their headcount is typically insufficient to absorb the maintenance overhead that multi-jurisdiction builds generate.

The practical decision frame runs as follows. An operator holding licences in one or two jurisdictions with stable, well-mapped compliance programmes can sustain a build solution if it is architected with version control and audit trail integrity from the start, and if a dedicated person is assigned to monitor regulatory change feeds for each jurisdiction. An operator holding licences in three or more jurisdictions, or entering new markets on a rolling basis, should treat a commercial platform with verified jurisdiction-specific modules as the lower-risk choice, provided it is evaluated against the six criteria above and not on the basis of vendor claims alone. An operator holding both an AGCO registration and an AGLC registration simultaneously must resolve the notification matrix design pattern difference between those two frameworks in the platform configuration before go-live, not after the first missed submission deadline.

The detailed comparison of AGCO and AGLC standards provides the operational specifics on where Ontario and Alberta diverge across their compliance frameworks, which directly informs the configuration requirements for any platform serving operators in both markets.

Practical note: Regardless of build or buy, the compliance management platform itself is a component of the operator’s control environment. Any substantial change to the platform, a vendor migration, a major version upgrade, or a configuration change that affects reporting workflows, is a potential notification event under AGCO Standard 1.02 (substantial changes to the control environment must be communicated to the Registrar in a timely manner) and under the equivalent AGLC SRIG provision. Operators should consult qualified legal counsel before implementing platform changes that could constitute material changes to the documented control environment.

Key Resources

AGCO Registrar’s Standards for Internet Gaming, Standards 1.02, 1.10, 1.12, 1.19, 1.20, and 6.01 are the primary references for documentation, audit, and third-party management obligations in Ontario. Available at agco.ca.

AGLC Standards and Requirements for Internet Gaming (SRIG), 2026-03-17, The CAM requirements section and the notification and reporting provisions under Section 5 are the primary references for Alberta go-live and ongoing compliance documentation. Available at aglc.ca.

MGA Compliance Audit Manual (MGA/G/001, August 2018, v1), Defines the procedures approved auditors will follow during a Malta compliance audit, covering governance, AML, player protection, and technical infrastructure in a single review. Available at mga.org.mt.

MGA Directive 3 of 2018, Gaming Authorisations and Compliance Directive, Regulation 43 governs suspicious betting reporting obligations and the SBRM submission process. Available at mga.org.mt.

UKGC Licence Conditions and Codes of Practice, Conditions 12.1.1, 15.1.1, 15.1.2, and 15.2.1 govern the primary reporting and documentation obligations for remote gambling licensees. The eServices platform is the mandatory submission channel for key events. Available at gamblingcommission.gov.uk.

AGCO Internet Gaming Notification Matrix (version 1.9), The operational control document defining the three categories of required ongoing submissions for Ontario-registered operators and gaming-related suppliers. Available at agco.ca.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged Compliance Tools & Resources

Browse all →

Compliance Tools & Resources

Compliance Monitoring Software for iGaming: How to Evaluate Vendor Claims Before You Sign

Sep 7 · 17 min read

Compliance Tools & Resources

Building a Regulatory Change Management System for Multi-Jurisdiction iGaming Operators

Jul 27 · 15 min read

Compliance Tools & Resources

GeoComply vs Xpoint: Selecting a Geolocation Vendor for US iGaming Compliance

Jul 2 · 15 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.