Operators Are Failing RG Audits: The Six Control Gaps Regulators Find Most Often
UKGC, MGA, and Spelinspektionen enforcement decisions reveal the same six RG control failures. See what regulators actually find and how to close each gap first.
Across UKGC licence reviews, MGA compliance audits, and Spelinspektionen supervisory investigations, the same deficiencies surface repeatedly. Petfre (Gibraltar) Limited, trading as Betfred online, paid £900,000 in June 2026 after a compliance assessment found it had breached paragraphs 1, 2, 4, 7, and 11 of Social Responsibility Code Provision (SRCP) 3.4.3. Paddy Power Betfair paid £2 million in December 2025 for customer interaction failures involving accounts with sustained high-loss velocity that went unreviewed. QuinnBet agreed a £609,104 settlement in August 2026 covering both social responsibility lapses and AML deficiencies. The pattern is not coincidence. It reflects six structural control gaps that compliance teams can identify, document, and close before a regulator does it for them.
What Regulators Are Actually Testing
The UKGC’s compliance assessments for remote operators centre on SRCP 3.4.3, which came fully into force on 31 October 2023 and mandates that licensees implement effective customer interaction systems embedding three elements: identify, act, and evaluate. The provision is explicit that customer interaction is an ongoing process, not a point-in-time check. The Commission’s formal guidance on remote customer interaction, referenced in paragraph 2 of the code provision, sets out the indicators of harm that systems must be capable of detecting and the standards against which evaluation must be measured.
The MGA tests against the Player Protection Directive (Directive 2 of 2018, most recently amended to version 3 in January 2023), the Compliance Audit Manual (MGA/G/001, August 2018), and the Gaming Act (Cap. 583 of the Laws of Malta). The MGA audit manual lists discrete checkpoint procedures for self-exclusion controls, limits setup, limits applicability, and records retention. Auditors follow mandatory procedures and design additional tests based on risk profile. An operator’s B2B dependencies and white-label arrangements do not transfer accountability.
Spelinspektionen tests against the duty of care obligation, omsorgsplikt, in Chapter 14, Section 1 of the Gambling Act (2018:1138), which requires licensees to take social and health considerations into account to protect players from excessive gambling. Under LIFS 2018:2, the authority’s responsible gambling regulations, licensees must maintain a written handlingsplan (action plan) describing how they will fulfil the duty. Spelinspektionen’s omsorgsplikt guidance document confirms that continuous monitoring of spelmönster (gambling patterns) is a legal prerequisite, not a best practice option.
Source: UKGC, Licence Conditions and Codes of Practice, SRCP 3.4.3 (in force 31 October 2023); MGA, Player Protection Directive (Directive 2 of 2018, v3 January 2023); Spelinspektionen, Gambling Act (SFS 2018:1138) Chapter 14 and LIFS 2018:2.
What Do Regulators Find Most Often in RG Audits?
Published enforcement decisions from UKGC, MGA, and Spelinspektionen between 2024 and 2026 cluster into six recurring deficiencies. All three regulators apply account-level sampling, meaning they select specific customer accounts and trace the full identification, action, and evaluation lifecycle through your system logs. The gaps most likely to surface are failures in automated detection sensitivity, documented evaluation of intervention outcomes, and the calibration of monitoring logic to segment-specific risk indicators.
These are not fringe compliance failures. They appear in settlements involving operators with substantial compliance infrastructure, specialist RG personnel, and automated monitoring platforms. The gaps are systemic, not accidental.
Gap 1: Automated Harm Detection That Cannot Pass a Sensitivity Test
The UKGC’s June 2026 public statement on Petfre (Gibraltar) Limited found that the operator’s automated monitoring lacked “robust automated processes to flag key indicators” including excessive spending, prolonged playtime, and behavioural patterns linked to harm. The statement cited delays and reliance on manual procedures where automation should have operated. Petfre failed paragraphs 1, 2, 4, 7, and 11 of SRCP 3.4.3, almost the full catalogue of the remote customer interaction requirement.
In the QuinnBet settlement, the UKGC identified that social responsibility systems were “not sensitive enough to identify indicators of harm,” with specific evidence that a customer deposited £12,000 during a 15-day period before any review was triggered. The Commission’s position is unambiguous: detection thresholds must be calibrated to the risk profile of the customer population, not set conservatively to minimise operational load on review teams.
The UKGC’s guidance on remote customer interaction requires licensees to take into account problem gambling rates for the relevant gambling activity as published by the Commission, “in order to check whether the number of customer interactions is, at a minimum, in line with this level.” A detection system generating fewer reviews than the statistical prevalence of problem gambling in the relevant vertical is not defensible.
In practice, compliance teams should document the calibration rationale for every detection threshold in their monitoring systems. A regulator reviewing your controls will expect to see evidence that thresholds were set by reference to harm indicators and reviewed against outcomes, not inherited from a prior system configuration.
Gap 2: Failing to Act on Identified Triggers Within a Defensible Timeframe
Detection and action are tested separately. The Paddy Power Betfair settlement, published December 2025, described a customer who staked £86,000 over a 16-day period, losing £6,000, with no manual review despite the high velocity of spend. A separate customer had a 7-hour-46-minute session over a 17-day period in which they placed over 300 bets amounting to £20,000, with interaction only triggered after a loss threshold was crossed rather than on the basis of the session behaviour itself.
The structural problem in these cases is not that the operators failed to monitor. Their action protocols were loss-threshold-only rather than multi-indicator. SRCP 3.4.3 paragraph 4 requires licensees to act on the output of their monitoring systems in a way that reflects the individual customer’s circumstances. A loss-only trigger will systematically miss high-frequency bettors, session-time patterns, and deposit velocity.
Under the Spelinspektionen omsorgsplikt guidance, when a player does not respond to contact, the licensee must take a different form of action until the desired protective effect is achieved. The guidance is explicit that escalation, not repetition of the same outreach, is required. An automated email series that generates no response and triggers no further step is not compliant with Swedish law.
Gap 3: Self-Exclusion Systems With Process Gaps at Critical Junctures
Self-exclusion failures appear in enforcement records across all three regulators and take different forms depending on jurisdiction. In the UK, Hollard Park Leisure was fined £150,000 in 2026 for failing to participate in a multi-operator self-exclusion scheme, a mandatory requirement for all licensed operators whether online or offline. The UKGC’s Director of Enforcement stated explicitly: “These are not optional requirements.” The operator had not integrated with a recognised multi-operator self-exclusion scheme until its licence was suspended in October 2025.
The MGA Compliance Audit Manual (MGA/G/001) sets out specific checkpoint procedures auditors must apply. Procedure 6.10.7 checks whether non-registered users are presented with the right to request self-exclusion and whether controls are in place to reject registration requests from previously excluded users. Procedure 6.10.8 checks that records of self-exclusion are retained for the duration of the exclusion plus a further six months. The Player Protection Directive (Directive 2 of 2018) prohibits any attempt to persuade or induce a self-excluding player to set a lesser timeframe than requested, and bars reopening an account during the exclusion period except at the player’s own request once the exclusion has expired.
Under the Gambling Act (2018:1138) and the upgraded Spelpaus API requirements in SIFS 2026:3 (effective August 2026), Swedish licensees must conduct real-time verification against the Spelpaus national self-exclusion database using regulator-issued Actor IDs and API keys. Spelpaus registrations exceeded 134,500 individuals as of mid-2026. A verification check that runs on login but not on session initiation after a gap represents a documented weakness in audit terms. The specific API and verification architecture required under SIFS 2026:3 is detailed in Spelinspektionen’s Spelpaus API requirements for Swedish licensees.
Pre-audit check: Map every point at which a self-excluded player could theoretically access gambling activity, registration, login, bonus claim, session start, and document the control in place at each point. Regulators test the seams between systems, not just the existence of a self-exclusion list.
Gap 4: Interaction Logs That Record Contact but Not Evaluation
SRCP 3.4.3 paragraph 7 requires licensees to evaluate the effectiveness of their customer interaction. Paragraph 11 requires them to be able to demonstrate the outcomes of that evaluation to the Commission. These two provisions together create an evidential standard that many operators fail to meet, not because they do not conduct interactions, but because their logging captures what was done, not whether it worked.
An interaction log that records “email sent” and “no response” does not satisfy paragraph 7. An evaluation requires evidence that the licensee assessed the customer’s subsequent behaviour, compared it against the pre-interaction baseline, reached a conclusion about whether the interaction had a protective effect, and took further action if it did not. The UKGC’s compliance assessment approach involves sampling specific customer accounts and tracing the full interaction lifecycle: identification, action, and documented evaluation. The absence of evaluation documentation converts a procedurally correct interaction into an evidential gap.
The Spelinspektionen omsorgsplikt guidance addresses the follow-up obligation in parallel terms: if prior measures were not sufficient to protect the player, the licensee must take further action. The guidance requires a written handlingsplan that is specific to the licensee’s customer segments and products. A generic template copied across licensees in the same group will not satisfy the requirement to have procedures relevant to the actual risk profile of the operation.
Gap 5: High-Loss and Young-Player Monitoring Without Segment-Specific Calibration
Spelinspektionen’s March 2025 supervisory review of Roar Vegas (LeoVegas) sampled 12 customer accounts specifically drawn from the highest-loss players in two age bands: 18, 24 years and 25+. Three accounts had monthly deposit limits between SEK 100,000 and SEK 300,000 with indicators of excessive activity including rapid deposit and loss cycles and prolonged session durations. The authority alleged insufficient assistance to these players under the omsorgsplikt. Although the Administrative Court in Linköping ultimately overturned the SEK 8 million fine in June 2026, finding that Roar Vegas’s automated alerts and manual follow-ups had materially reduced gambling activity in the flagged accounts, the supervisory methodology signals the regulator’s audit approach clearly: highest-loss cohorts and young adults aged 18, 24 are the primary sampling targets.
Spelinspektionen’s omsorgsplikt guidance identifies previous self-exclusions and player age (18, 24) as explicit elevated-risk factors requiring heightened follow-up. Licensees must submit biannual aggregated data on specific gambling behaviours to the authority under LIFS 2018:2 sections 21, 22. A monitoring system that does not stratify by age band and prior exclusion history does not align with the indicators the regulator uses to select accounts for review.
The QuinnBet settlement raised an analogous issue in the UK context: the operator’s systems exceeded age-based deposit limits and failed to detect problem gambling patterns. The UKGC expects monitoring systems to treat demographic risk factors as inputs into detection logic, not as background information held in the CRM.
| Regulator | Primary Rule | High-Risk Cohort Focus | Enforcement Consequence |
|---|---|---|---|
| UKGC | SRCP 3.4.3 (LCCP) | Loss velocity, high-frequency play, VIP accounts | Financial penalty / regulatory settlement |
| MGA | Player Protection Directive 2 of 2018 | Self-excluded players, high-value accounts | Licence conditions, cancellation proceedings |
| Spelinspektionen | Gambling Act (2018:1138) Ch. 14, LIFS 2018:2 | 18, 24 age band, highest-loss quartile | Pecuniary penalty up to 10% of annual turnover |
Gap 6: Inadequate Action Plans and Governance Documentation
The requirement for a written action plan, a handlingsplan, under Chapter 14, Section 1 of the Gambling Act (2018:1138) and LIFS 2018:2 is one of the clearest structural compliance obligations in any European gambling regime. The plan must describe how the duty of care will be fulfilled, must be calibrated to the licensee’s customer segments and products, and must give personnel clear direction on what action to take in different risk situations. Spelinspektionen’s guidance document explicitly states that the handlingsplan functions as an internal routine relevant to all customer-facing staff.
In MGA audits, the Compliance Audit Manual (MGA/G/001) requires auditors to verify that responsible gambling policies are documented, accessible, and operationally implemented. The disconnect auditors most frequently find is between the policy as written and the system behaviour as tested: a policy may describe a correct multi-indicator approach to harm identification while the underlying platform runs a simpler loss-threshold trigger.
The UKGC’s broader framework also carries a documentation obligation. SRCP 3.4.3 paragraph 14 requires licensees to take account of published problem gambling rates in order to verify that their interaction volumes are, at minimum, in line with statistical prevalence. This creates an obligation to maintain records showing not just individual interactions but the aggregate rate at which the system generates reviews, documentation that many compliance teams do not currently maintain in a form the regulator can interrogate directly.
Regulators don’t sanction operators for failing to care about player protection, they sanction them for failing to prove it with documented, effective controls.
The June 2026 Betfred settlement is instructive on this point. The compliance assessment was conducted between May and June 2024, nearly a year before the public statement was issued. The UKGC reviewed the period from 31 October 2023, the date SRCP 3.4.3 came fully into force, through the assessment date. Operators who updated their policies to reflect the new code provision but did not update their system configuration or documentation at the same time are exposed to exactly this type of retrospective review.
Building a Pre-Audit Readiness Framework
Compliance teams operating across UKGC, MGA, and Spelinspektionen regulated markets should maintain a single control matrix that maps each jurisdiction’s RG obligations to the specific system behaviour, documentation, and governance evidence that satisfies them. The matrix is not a compliance checklist. It is an audit evidence index. Each row should specify the rule, the control, the system or process that executes the control, the log or record that proves it, the review cadence, and the owner.
For UKGC purposes, the matrix must address every numbered paragraph of SRCP 3.4.3 individually. Paragraph 1 (effective systems), paragraph 2 (guidance adherence), paragraph 4 (acting on outputs), paragraph 7 (evaluating effectiveness), paragraph 11 (demonstrating outcomes to the Commission), and paragraph 14 (interaction rate vs. prevalence) each require distinct evidential artefacts. Operators who treat SRCP 3.4.3 as a single obligation rather than a set of numbered requirements will have documentation gaps. The full text of the LCCP, including SRCP 3.4.3, is available through the UKGC LCCP explorer.
For MGA purposes, pre-mapping the Compliance Audit Manual checkpoint list against your system configuration before an audit is the most direct form of readiness preparation. The manual is public. Every procedure it lists, from self-exclusion records retention to limits applicability across all games within the same website, is a testable fact, not a judgment call.
For Spelinspektionen, the handlingsplan must be a live document, not a filing-cabinet artefact. When the authority requests it, the version produced should reflect the operator’s current customer mix, product range, and risk indicators, not the configuration at licence application. Operators should treat the biannual data submission obligation under LIFS 2018:2 sections 21, 22 as a forcing function: the aggregated behavioural data submitted must be consistent with the monitoring approach described in the handlingsplan.
For compliance teams managing dual or multi-jurisdiction exposure, the Responsible Gambling Compliance hub maps the self-exclusion, deposit limit, and customer interaction frameworks across seventeen regulated markets, including the national register models in Sweden (Spelpaus), the UK (GAMSTOP), and Germany (OASIS) versus the operator-level models applicable under MGA and in US state markets.
Counsel note: The application of RG obligations to specific customer account circumstances involves judgment calls that vary by jurisdiction. Compliance teams should take qualified legal advice on their specific system configuration and customer interaction protocols in each licensed market before concluding that current arrangements satisfy regulatory requirements.
Key Resources
UKGC Licence Conditions and Codes of Practice (SRCP 3.4.3): gamblingcommission.gov.uk
UKGC Public Statement, Petfre (Gibraltar) Limited (June 2026): gamblingcommission.gov.uk
MGA Player Protection Directive (Directive 2 of 2018, v3 January 2023): mga.org.mt
MGA Compliance Audit Manual (MGA/G/001, August 2018): mga.org.mt
Spelinspektionen Omsorgsplikt Guidance (Gambling Act 2018:1138, Chapter 14 / LIFS 2018:2): spelinspektionen.se
UKGC Remote Customer Interaction Formal Guidance: gamblingcommission.gov.uk
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.
The Tuesday brief, every week.
One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.
Unsubscribe with one click. We'll never share your address.