Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
GLI-33 · Integrity 17 min read Jul 22, 2026

GLI-33 RNG and Integrity Requirements: What Sportsbooks Must Prove at Certification

GLI-33 v1.1 imposes specific cryptographic RNG, market suspension, void-wager, and settlement obligations on sportsbooks. Here's what your system must demonstrate to certify.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Jul 22, 2026 17 min read Filed GLI Certification

GLI-33: Standards for Event Wagering Systems v1.1 (published May 14, 2019) is the governing technical standard for sportsbook certification across the majority of North American regulated markets and an increasing number of international jurisdictions. Compliance teams that treat GLI-33 as a box-checking exercise discover, usually mid-engagement, that the standard’s integrity and RNG obligations require architectural decisions that cannot be retrofitted at the test stage. This article examines the specific provisions that govern virtual sports RNG, in-play market integrity, market suspension procedures, wager void and cancellation rules, and settlement verification, the sections where certification most commonly stalls.

Scope: Where GLI-33 Integrity Obligations Begin

GLI-33 applies to any Event Wagering System: the hardware, software, and associated infrastructure through which wagers on real or simulated sporting events are accepted, recorded, settled, and reported. The standard’s introductory text is explicit that it is intended to be used by regulatory bodies, operators, and industry suppliers as a compliance guideline for technologies and procedures pertaining to event wagering. It is not a prescriptive one-size-fits-all rulebook, many requirements are qualified by phrases such as “as required by the regulatory body,” meaning jurisdictional overlays can tighten but not relax the baseline.

Operators running both a real-sport sportsbook and a virtual sports product on the same platform face the most complex certification scope. GLI-33 Section 4.5 establishes that virtual event wagering is subject to a discrete set of requirements that are additional to, not a substitute for, the system-level obligations that govern the real-sport wagering stack. The boundary between the two product types also determines which RNG standard applies: virtual events processed by a shared wagering system fall under GLI-33 Section 4.5, while virtual events that play out entirely on a gaming device (where the player makes a wager and the event resolves on their individual machine or a shared multi-player display) fall under GLI-11 Standards for Gaming Devices instead. Misclassifying this boundary is one of the most common scope errors in pre-submission documentation.

Source: GLI-33 Standards for Event Wagering Systems, v1.1, Section 4.5 General Statement and Section 4.5.2.

Virtual Sports RNG: What the Standard Requires

The Cryptographic RNG Mandate

GLI-33 Section 4.5.2 requires that a cryptographic RNG be used to determine virtual event outcomes. The standard defines a cryptographic RNG as one that is resistant to attack or compromise by an intelligent attacker with modern computational resources who has knowledge of the source code of the RNG and/or its algorithm, and which cannot be feasibly “broken” to predict future values. A standard pseudo-random number generator does not satisfy this definition, regardless of how large its period or how complex its seeding algorithm. Operators must submit cryptographic RNG documentation demonstrating compliance with applicable jurisdictional requirements. Where no jurisdiction-specific RNG standard exists, the independent test laboratory applies the RNG requirements chapter of GLI-11 as the reference baseline.

Where more than one RNG drives different aspects of a virtual event, each RNG is evaluated separately. Where the same RNG implementation is instantiated multiple times within the same virtual event (for example, one instance per virtual horse in a race), each instance is separately evaluated. This means that a supplier cannot obtain a single RNG certification and apply it across all virtual event components without independent assessment of each use.

Outcome Determination Rules

Section 4.5.3 sets out the specific rules governing how virtual event outcomes are determined from the RNG output. The standard states that the determination of events of chance resulting in a monetary award shall not be influenced, affected, or controlled by anything other than the values selected by an approved RNG. Six specific constraints follow from this principle:

It shall not be possible to ascertain the outcome of any virtual event prior to its commencement. The virtual event shall not limit the outcomes available for selection except as provided for by design, meaning any artificial truncation of the outcome space requires explicit design documentation and regulatory approval. The virtual event shall not modify or discard outcomes selected by the RNG due to adaptive behavior, and outcomes shall be used as described by the rules of the virtual event without post-selection manipulation.

After a virtual event commences, no further actions or decisions may be made that change the behavior of any element of chance within the event, other than player decisions where the rules provide for them. Events of chance shall be independent and shall not correlate with any other events within the same virtual event, or with events within previous virtual events, except as explicitly provided for by the virtual event rules. Any associated equipment connected to the Event Wagering System shall not influence or modify the RNG or its random selection process except as authorized by design.

Section 4.5.3 further requires that virtual event outcomes shall not be affected by the effective bandwidth, link utilization, bit error rate, or other characteristics of the communications channel between the Event Wagering System and the Wagering Device. This is a common failure point for suppliers who route virtual event outcome data across shared network infrastructure without adequate isolation. Critically, the standard states that wagering software shall not contain any logic used to generate the result of any virtual event. All critical functions including the generation of any virtual event outcome must be generated by the Event Wagering System, independent of the Wagering Device.

“Wagering Software shall not contain any logic utilized to generate the result of any virtual event. All critical functions including the generation of any virtual event shall be generated by the Event Wagering System and be independent of the Wagering Device.”

Source: GLI-33 Standards for Event Wagering Systems, v1.1, Section 4.5.3 Virtual Event Selection Process.

Physics Engines as a Special Case

GLI-33 Section 4.5.4 (Wagering Display requirements) and the related provisions on physics engines address the increasingly common practice of rendering virtual event outcomes through a physics simulation layer, common in virtual football, horse racing, and motor racing products. The standard acknowledges that a physics engine may utilize the random properties of an RNG to impact virtual event outcomes, but requires that a physics engine be designed to maintain consistent play behaviors and virtual event environment unless an indication is otherwise provided to the player by the virtual event rules. The independent test laboratory will evaluate physics engine implementations on a case-by-case basis. Operators deploying physics-based virtual sports must budget additional time in the certification schedule for this evaluation, which typically involves providing detailed documentation of the physics model and its interaction with the RNG seeding process.

In-Play Wagering Integrity Obligations

Real-sport in-play wagering presents a different set of integrity risks from virtual sports, and GLI-33’s requirements reflect that distinction. The standard does not specify a mandatory latency figure for in-play wager acceptance, but Section A.5.1 (Wagering Rules and Content) requires operators to disclose in their published rules that updates of displayed information may put a player at a disadvantage compared to others with more up-to-date information, and that there may be delays incorporated in the registered time of an in-play wager to prevent past-post wagers and cancellations.

The past-post wager, a wager placed after the relevant event or market has concluded but before the system has closed the market, represents one of the highest-integrity-risk scenarios in live sports wagering. GLI-33 Section A.2.3 (Risk Management) requires that internal controls include a description of the method to prevent past-post wagers from being placed. This is a documented control, not merely a technical one: the certification audit will examine whether the documented procedure matches the system’s actual behavior, and whether the system logs attempted past-post placements.

The standard’s requirement that operators reserve the right to refuse any wager or part of a wager, to accept a wager at other than posted terms, and to close wagering periods at their discretion must be stated explicitly in the published rules, it cannot be buried in boilerplate or implied. Regulators in jurisdictions that have adopted GLI-33 as their baseline standard, including Ontario under the AGCO’s Registrar’s Standards for Internet Gaming, cross-reference wagering rules disclosure requirements against this provision during supervisory reviews.

Market Suspension Requirements

GLI-33 Section A.6.3 establishes a procedural and audit-log obligation around market suspension. The requirement is direct: there shall be established procedures for suspending markets or events, defined in the standard as stopping the acceptance of wagers for that market or markets associated with that event. When wagering is suspended for an active event, an entry shall be made in an audit log that includes the date and time of suspension and its reason.

The audit log requirement is not a post-incident obligation. The log entry must be made at the time of suspension, capturing the triggering reason. A suspension implemented by a trading desk without a logged reason does not satisfy the standard, regardless of whether the suspension was commercially justified. In practice, operators should configure their trading system so that every suspension action, whether automated or manual, writes a timestamped, reason-coded entry to a tamper-evident audit log.

Statistics and line service feeds are addressed in the preceding provisions of Appendix A. When an incident or error results in a loss of communication with statistics or line services, that incident must be recorded in a log along with the date and time of occurrence, its duration, nature, and a description of its impact on system performance. This information must be maintained for 90 days, or as otherwise specified by the regulatory body. The same retention period applies to surveillance recording of wagering areas, which must cover defined wagering areas in sufficient detail to identify any discrepancies, be captured in a way that precludes interference or deletion, and remain available for regulatory review in the event of a player complaint or dispute.

Integrity Obligation GLI-33 Reference Key Requirement Retention Period
Virtual RNG type Section 4.5.2 Cryptographic RNG mandatory N/A (architectural)
Virtual outcome independence Section 4.5.3 No correlation, no adaptive behaviour, client cannot generate outcomes N/A (architectural)
Market suspension log Section A.6.3 Date, time, and reason logged per suspension 90 days minimum
Stats/line service outage log Section A.6.2 Date, time, duration, nature, and impact recorded 90 days minimum
Wager record information Section 2.8.2 Full wager lifecycle data including status and result 5 years minimum
Complaint/dispute records Section A.4.4 All correspondence maintained 5 years minimum
Surveillance recording Section A.7.4 Continuous, tamper-evident, regulatory-reviewable 90 days minimum

Wager Void and Cancellation: The Regulatory Pre-Approval Rule

The wager cancellation provisions in GLI-33 Section A.6.4 contain one of the most operationally consequential requirements in the entire standard, and one that operators frequently underestimate during pre-certification internal audits.

Wagering transactions cannot be modified except to be voided or cancelled as provided for in the operator’s published cancellation policy. A cancellation grace period may be offered to players, but the provision on operator-initiated cancellations carries the critical constraint: an operator shall not void or cancel any wager without the prior approval of the regulatory body.

“An operator shall not void or cancel any wager without the prior approval of the regulatory body.”

This requirement eliminates discretionary operator-side wager cancellation as a routine trading tool. It applies to both partial cancellations and full voids. Where an operator-initiated cancellation does proceed, following regulatory approval, the operator must provide a reason to the affected player. The standard cites past-post as one example of a legitimate reason, but the provision is not limited to that scenario.

For parlays and other multi-event wagers, the handling of cancelled legs is addressed in Appendix A, which requires established procedures for handling voided or withdrawn selections within wagers involving multiple events, including providing refunds to players who were not automatically refunded by the system. Operators who process anonymous wagers face a heightened procedural burden here, since the refund must reach a player who has not necessarily created an account.

The interaction between this provision and the external wagering system requirements is equally demanding. GLI-33 Section 4.6 addresses configurations where an Event Wagering System acts as either a host or guest system in a multi-operator network. Where a cancellation request originates from a guest wagering system, the player is not to be credited by the guest system until final confirmation of the cancellation is received from the host wagering system, including the confirmed amount of the voided or cancelled wager. Operators running white-label or aggregated wagering arrangements must ensure their inter-system cancellation confirmation architecture satisfies this flow.

Settlement Verification and Wager Record Integrity

GLI-33 Section 2.8.2 establishes the minimum data elements that must be maintained and backed up for each individual wager. The list is comprehensive and includes the date and time the wager was placed, all player choices including market and line postings, wager selection (athlete or team name and number), and any special conditions. The result field must remain blank until confirmed. Total amounts wagered and won must be recorded separately, along with commission or fees collected, the date and time any winning wager was paid to the player, a unique identification number, user identification or unique Wagering Device ID, relevant location information, event and market identifiers, and the current wager status.

The wager status field is particularly important for certification: the system must support a defined set of status states including active, cancelled, unredeemed, pending, void, invalid, redemption in progress, and redeemed. A system that uses a simplified binary or ternary status model will fail this requirement. The status must be updated in the database during each phase of the redemption process: whenever the wager record status changes, the system shall update the database accordingly. This is an explicit audit-trail requirement, not merely a recommended practice.

For event-level data, GLI-33 requires that the Event Wagering System maintain records showing the lines and odds available throughout the duration of a market (time-stamped) and the confirmed result for each market. Total winnings paid, total wagers voided or cancelled, commission or fees collected, event status, and event and market identifiers must all be stored. Data retention at the wager record level is five years, or as otherwise specified by the regulatory body.

Settlement verification is supported by the system’s requirement to provide a mechanism to export data for the purposes of data analysis and auditing, in standard formats such as CSV or XLS. The system clock must be used for all time-stamping, and the clock must reflect the current date and time to provide timestamping of all transactions and events. Any discrepancy between the system clock and a reliable external time source will be flagged during the certification technical audit.

Restricted Players and Insider Integrity Controls

GLI-33 Appendix A, Section A.2.3 (Risk Management) requires that operator internal controls describe the method to prevent players from wagering on events in which they might have insider information. The standard specifies two categories of restricted person explicitly:

Players identified as employees, subcontractors, directors, owners, and officers of an operator, as well as those within the same household, shall not place wagers on any event except in private pools where their association with the operator is clearly disclosed. Players identified as professional or collegiate athletes, team employees and owners, coaches, managers, handlers, athletic trainers, league officials and employees, referees, umpires, sports agents, and employees of a player or referee union, as well as those within the same household, shall not place wagers on any event in the sport in which they are involved.

These categories must be documented in the operator’s internal controls as a named process, not merely referenced as a policy principle. The certification audit will examine the process documentation and, where technically feasible, the system controls enforcing it. Given that identification of individuals within these categories typically depends on disclosure at account registration rather than automated verification, the procedural side of this control receives particular scrutiny. Operators should consult qualified legal counsel on how the specific categories in their jurisdiction’s sporting-integrity legislation interact with the GLI-33 control requirement, since some markets impose broader or more specifically defined restricted-person categories than the standard’s baseline.

The collusion and fraud monitoring provisions in Section A.8.1 require that operators take measures designed to reduce the risk of collusion or fraud, including maintaining procedures for identifying and refusing to accept suspicious wagers, conducting due diligence checks on wagers that exceed regulatory thresholds, and applying AML reporting obligations where applicable. The interaction between the sports integrity controls and the AML compliance framework embedded in Section A.2.3, which explicitly requires internal controls to include a description of AML compliance standards and procedures for detecting structuring to avoid reporting requirements, means that suspicious wagering patterns with integrity implications may simultaneously trigger AML reporting obligations.

System Security: The Technical Audit Appendix

GLI-33 Appendix B covers the Operational Audit of Technical Security Controls, which forms the second major component of a full certification engagement alongside the operational audit in Appendix A. The Appendix B scope includes an information security system assessment, a review of operational processes critical to compliance, and penetration testing covering both external and internal infrastructure as well as applications that transfer, store, or process player data and sensitive information.

The penetration testing requirements specify both external and internal vulnerability assessments. The external assessment targets network devices and servers accessible by a third party via public IP addresses. The internal assessment targets internal-facing servers within the DMZ or internal LAN. The standard mandates that each security domain on the internal network be tested separately, and specifies a range of scanning techniques including UDP/TCP port scanning, stack fingerprinting, TCP sequence prediction, web scanning using HTTP and HTTPS vulnerability scanners, and router scanning using BGP and SNMP. These are not suggested techniques, they represent the minimum scope of the assessment.

All data communications critical to wagering or player account management must employ encryption and authentication. Communications over internet or public networks must protect player data, sensitive information, wagers, results, financial information, and player transaction information from incomplete transmissions, misrouting, unauthorized modification, disclosure, duplication, and replay. Communication on the secure network shall only be possible between approved system components that have been enrolled and authenticated as valid. No unauthorized communications to components or access points are allowed.

Critical control program components, which include executables, libraries, wagering or system configurations, operating system files, components controlling required system reporting, and database elements affecting system operations, must use a hash at least 128 bits in length for integrity authentication. Each critical control program component must have a method of verification via an independent third-party procedure that operates independently of any process or security software within the system. The independent test laboratory must approve the integrity check method prior to system approval.

Certification planning note: GLI-33 certification engagements for operators offering both traditional and virtual sports betting typically require separate evaluation tracks for the real-sport wagering system, each virtual event product, and each RNG implementation. Operators should confirm scope delineation with their chosen independent test laboratory before submitting pre-certification documentation, as scope changes after submission can reset the technical review timeline.

Jurisdictional Adoption and Layered Requirements

GLI-33 v1.1 has been adopted or referenced as a baseline by a range of regulated markets, including multiple US states, the Ontario market under the AGCO’s Registrar’s Standards for Internet Gaming, and various offshore jurisdictions. The standard’s baseline represents a floor: jurisdictions frequently impose additional or more prescriptive requirements through their own minimum internal control standards (MICS) or supplementary technical guidance, which override or supplement the GLI-33 baseline where they are more stringent.

In Ontario, the AGCO’s Registrar’s Standards are structured around themes that map broadly to GLI-33’s chapters, and GLI-33 certification is one of the technical evidence pathways available to demonstrate system compliance. Operators registered in Ontario who have not completed a full GLI-33 engagement should review the alignment between the AGCO’s specific standards and the GLI-33 provisions covered in this article, particularly around wager record retention, cancellation procedures, and the treatment of virtual sports products within the platform scope. For operators navigating both the AGCO and AGLC frameworks, which share structural similarities, the AGCO vs AGLC compliance comparison provides a side-by-side reference for where the two Canadian regimes diverge on technical standards obligations.

The GLI-33 standard’s qualifier language, “as required by the regulatory body” and “as otherwise specified by the regulatory body”, appears throughout the document. This means that a GLI-33 certification obtained for one jurisdiction does not automatically satisfy the requirements of a second jurisdiction whose MICS impose higher standards. Operators expanding from one regulated market to another should engage their test laboratory to identify any delta assessment required. For a foundational understanding of how GLI-33 and GLI-19 partition the certification scope for a combined sportsbook and casino product, the GLI-19 vs GLI-33 standard selection analysis covers those architectural decision points in detail.

The sports integrity dimensions of the standard, restricted player controls, collusion monitoring, suspicious wager procedures, intersect increasingly with the broader legislative landscape for sporting integrity. The Council of Europe’s Macolin Convention, which has been adopted by 43 states, and ongoing US legislative debate around a federal sports betting integrity framework, according to iGamingBusiness reporting from July 2026, both point toward tightened reporting obligations at the operator level that will flow down into technical standards updates over time. Compliance teams should monitor both the GLI-33 revision pipeline and jurisdictional MICS amendments for integrity-related additions.

Key Resources

GLI-33: Standards for Event Wagering Systems, v1.1, Gaming Laboratories International (May 14, 2019). The primary technical standard. Available through GLI’s standards portal at gaminglabs.com.

GLI-11: Standards for Gaming Devices, Gaming Laboratories International. Referenced by GLI-33 Section 4.5.2 as the RNG requirements baseline where no jurisdiction-specific RNG standard exists, and as the applicable standard for virtual events conducted entirely on a gaming device.

AGCO Registrar’s Standards for Internet Gaming, Alcohol and Gaming Commission of Ontario. The Ontario technical framework that references GLI-33 as an evidence pathway for system certification. Available at agco.ca.

Council of Europe Macolin Convention on the Manipulation of Sports Competitions, The principal international legal instrument on match manipulation, adopted by 43 states, directly relevant to the sports integrity controls required under GLI-33 Appendix A.

To prepare your compliance program, review the specific GLI-33 requirements that apply to your jurisdiction and product scope, then engage your independent test laboratory to conduct a delta assessment between your current system configuration and the certified baseline for your market.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged GLI Certification

Browse all →

GLI Certification

AGLC SRIG and GLI Certification: How Alberta’s ATF Framework Works for Internet Gaming

Jul 15 · 15 min read

GLI Certification

AGCO Technical Standards and GLI Certification: What Ontario Market Access Actually Requires

Jul 8 · 15 min read

GLI Certification

MGA Technical Standards and GLI-19: How Certification Maps for Malta Licensing

Jul 1 · 15 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.