Post-Launch Product Approvals Under AGLC: Getting New Games, Features, and Promotions Live
AGLC's three-tier modification framework governs every game, feature, and promotion you ship post-launch. Learn what triggers ATF recertification, what requires only notification, and how to build rollback into your release process.
Every product team working on an AGLC-registered iGaming site faces the same operational question the moment they shift from launch mode to live operations: which changes can ship on the normal release cycle, which need ATF certification first, and which need to reach AGLC before the deploy button is pressed? The AGLC’s Standards and Requirements for Internet Gaming (SRIG), together with the Internet Gaming Go-Live Compliance Guide published in January 2026, answer that question through a structured three-tier modification framework and a Notification Matrix that governs incident and regulatory reporting. Getting the classification wrong carries direct regulatory exposure: deploying a Regulatory change without prior ATF certification is a breach of registration conditions under SRIG Section 4.12.
The Three-Tier Modification Framework
The AGLC Go-Live Compliance Guide defines three modification categories that determine the approval path for every change to games, RNGs, remote gaming servers, and sport and event betting systems. The classification governs deployment sequencing, not just documentation.
Non-Regulatory modifications are cosmetic or minor changes with no bearing on the SRIG Standards. The examples given in the Go-Live Compliance Guide are bug fixes and language updates. No ATF recertification is required. The obligation is to confirm internally that the change is genuinely non-regulatory before it ships. That confirmation must be documented and linkable to the change record, because all gaming system changes must have evidence linked to the change record under the SRIG’s change management requirements.
Regulatory modifications are changes that affect compliance with the SRIG or that address regulatory concerns without urgency. These must be certified by an AGLC-registered Accredited Testing Facility (ATF) before deployment into the Alberta production environment. There is no grace period. A new game title, a new RNG configuration, a new paytable structure, or any feature that alters how the gaming system accepts, processes, determines, displays, or logs player bets falls into this category and cannot go live in Alberta without a valid ATF certification in hand.
Regulatory Fix (Emergency) modifications address regulatory concerns requiring immediate action to correct a live issue. The Go-Live Compliance Guide’s example is a major integrity failure affecting the Standards. Emergency fixes may be deployed immediately without prior certification, but the fixed technology must be submitted to an AGLC-registered ATF for Alberta certification within five business days of release. The operator or Goods or Services Supplier (GSS) submitting the change must maintain records of testing and ATF certification and must provide that documentation to AGLC upon request.
Key Rule: An ATF may not issue a certification contingent on future changes being made. If an ATF determines that a specific feature must be disabled for the technology to comply with the SRIG, the certification will specify that as a condition, and the operator must disable that feature before the technology is deployed in Alberta.
| Modification Category | Examples | ATF Certification Required? | Deployment Timing |
|---|---|---|---|
| Non-Regulatory | Bug fixes, language updates, cosmetic UI changes | No | After internal confirmation of non-regulatory status |
| Regulatory | New games, RNG changes, new paytable, new feature affecting bet processing | Yes, before deployment | Only after ATF certification issued |
| Regulatory Fix (Emergency) | Live integrity failure, Standards breach requiring immediate remediation | Yes, within 5 business days of release | Immediate, certification submitted post-deploy |
What Triggers ATF Recertification for Live Products?
Recertification is required whenever a modification, or a subsequently discovered undetected issue, impacts critical gaming system integrity, fairness, security, or compliance with the SRIG Standards. SRIG Section 4.12 is explicit: the certification requirement covers all games, RNGs, and components of iGaming systems that accept, process, determine, display, and log details about player bets, including slot games, table games, sport and event betting, poker, and other card games.
For live dealer games, the ATF scope extends to physical random number generators with electronic elements and all physical equipment with electronic elements used to determine game outcomes. Physical roulette wheels, dice tables, and card shufflers with electronic components all fall within the ATF scope.
“Be certified before they are deployed in the Alberta market, and not contain a limitation on AGLC’s use of the certification, or purport to disclaim AGLC’s use of the certification.”
Source: AGLC, Standards and Requirements for Internet Gaming (SRIG), Section 4.12: Certification By Accredited Testing Facilities (ATF), issued January 14, 2026, signed by Board Chair.
ATF certifications in Alberta are jurisdiction-specific. Only ATFs registered by AGLC may issue certifications valid for Alberta deployment. A GLI or BMM certification obtained for Ontario, New Jersey, or another jurisdiction does not automatically satisfy AGLC’s requirement. Operators entering Alberta with a game portfolio already certified elsewhere must confirm that their ATF holds AGLC registration before submitting for Alberta certification. For broader context on how GLI technical standards interact with certification pathways, see the comparison of GLI-19 vs GLI-33 certification paths.
New Games: The Submission Workflow
A new game title is always a Regulatory modification. It must be certified by an AGLC-registered ATF before it is made available to players. The ATF certification instrument must include the legal name of the AGLC-registered ATF issuing the certification, the legal name of the operator or GSS requesting certification, the date of issuance, and a unique identifier for AGLC tracking and follow-up. That identifier links the certification to AGLC’s compliance records and to the submitting party’s own change record documentation.
The submission workflow for a new game should follow this sequence: obtain ATF certification scoped to the game, RNG, and any relevant system components, link the certification to the change record in the operator’s change management system, confirm the certification does not carry any feature-disabling condition that is incompatible with the intended Alberta game configuration, then deploy. The certification document must be retained and produced to AGLC upon request. The SRIG’s broader records retention requirement mandates that security and event logs be retained for at least one year online and seven years in archive.
Operators sourcing games from a platform provider or content aggregator must confirm that the third-party GSS has obtained ATF certification for the Alberta market. The SRIG’s third-party management provisions make registered operators responsible for the compliance of their third-party suppliers. The operator’s Internal Control Matrix must identify where third-party suppliers are involved, including platform providers, and those entries should map directly to the ATF certification status of each supplier’s product set.
Game Management Changes: In-Session and Between-Session Rules
The SRIG sets a specific and operationally relevant constraint on changes to terms governing play. Under SRIG Section 4.8 (Game Management), terms governing play must not be changed during a game session unless the player is made aware of the change before placing any further wagers in the game. This applies to paytable updates, RTP adjustments, and any modification to the rules that govern how the game pays out.
Between-session changes to game rules or paytables that affect the SRIG’s compliance criteria require ATF recertification under the Regulatory modification path before they go live. A UI-only update, such as changing a game’s visual theme without altering any mechanic, bet range, or outcome logic, falls under Non-Regulatory, provided the operator can document that the change has no compliance impact.
The SRIG also requires that games operate according to their game specifications and that outcomes be determined in accordance with the terms governing play and prevailing payouts as described to the player. Any update that changes the relationship between what the player is shown and how outcomes are actually determined is a Regulatory modification requiring ATF certification.
New Payment Methods and Financial Feature Changes
Adding a new payment method or modifying the withdrawal verification workflow is a change to the operator’s control environment. The SRIG requires that substantial changes to the operator’s control environment be communicated to AGLC in a timely manner. The SRIG does not define a fixed notice period for “timely,” which means operators must treat the communication to AGLC as a concurrent obligation alongside any internal change management approvals, not something done after go-live.
The SRIG imposes a hard prohibition on cryptocurrency. The relevant provision states explicitly that cryptocurrency is not legal tender and must not be accepted. This is not a configuration choice or a feature flag: it is a structural prohibition. Any payment integration that routes funds via cryptocurrency rails, even as an intermediate step before fiat settlement, must be assessed against this requirement. Operators should consult qualified legal counsel before integrating any blockchain-adjacent payment technology into their Alberta-facing product.
Withdrawals in Alberta must be verified and authorized to ensure the withdrawal is being made by the account holder and is being transferred to an account of which the player is a legal holder. A change to the withdrawal workflow that alters those verification steps is a change to a compliance-relevant process and must be handled under the SRIG’s internal controls framework and the change communication requirement.
UI Changes, T&C Edits, and Notification Obligations
Not every product change requires pre-deployment ATF certification, but the SRIG’s internal controls framework requires that all gaming system changes be reviewed, risk assessed, tested, approved, and verified, with evidence linked to the change record. The phrase “gaming system” covers the full technological stack of the iGaming operation, not just the game client.
UI changes that have no bearing on bet processing, game outcome determination, or player account management are Non-Regulatory. A revised colour scheme, a restructured navigation menu, or an updated help text block does not trigger recertification. The change still must be documented, risk-assessed, and linked to the change record. Emergency changes deployed outside the normal release cycle because of a live production incident must be followed by a documented post-implementation review within two business days under the SRIG’s change management requirements.
Terms and Conditions changes present a compliance-sensitive area. A T&C edit that modifies the terms governing play, for example an update to bonus wagering requirements, withdrawal conditions, or game eligibility rules, affects what players are shown about how their bets and winnings work. That class of T&C change must be assessed against the Game Management provisions in Section 4.8 and, where it touches certified game parameters, against the ATF recertification triggers in Section 4.12. A T&C change limited to contact details, complaints handling, or platform policies that have no bearing on game outcomes or bet processing is Non-Regulatory.
Player notification is required for certain account-level changes. Under SRIG Section 4.4, changes to contact details, credentials, authentication factors, payout or banking information, or security settings must trigger a notification sent to the player’s last known verified contact point. Compliance teams implementing new account features must design notification workflows into any change that touches those fields at the specification stage, not as an afterthought during QA.
Promotions and Affiliate Creative: The Structural Constraints
Alberta’s advertising and promotions framework does not operate through a per-campaign pre-approval ticket workflow with AGLC. The SRIG Section 4.1 and the associated advertising standards codified by AGLC ahead of the July 13, 2026 market launch establish structural constraints that govern every promotional communication an operator sends. Product teams and marketing functions must design their promotional infrastructure to be compliant by default, because the obligation runs to the format and channel of delivery, not to the content of individual campaigns.
Advertising bonuses, inducements, and promotions is prohibited through general broadcast channels. Bonus and promotion communications are only permitted via direct opt-in channels, meaning the player must have actively consented to receive that category of communication. The AGLC’s advertising rules, closely modelled on Ontario’s framework, also prohibit the use of athletes or celebrities to promote gambling products: their use is restricted to responsible gambling messaging only. Any creative featuring athlete endorsements for a product or bonus offer is non-compliant regardless of how it is delivered.
“Registered Operators must ensure that no independent third parties that engage in direct-to-consumer marketing, direct-to-consumer promotions or player referral services for the Operator” conduct themselves as if they were not bound by the same rules as the operator.
Affiliate creative falls under the operator’s responsibility. The SRIG makes registered operators responsible for the actions of third parties they contract with for any aspect of their Alberta-facing business. An affiliate running creative that promotes a sign-up bonus through a general-audience channel creates a compliance exposure for the registered operator, not only for the affiliate. Operators must require affiliates to conduct themselves as if bound by the same SRIG standards, and must maintain a list of suppliers, including marketing and affiliate partners, available for AGLC inspection upon request.
Land-based casino promotion of iGaming products carries an additional layer of restriction. According to Canadian Gaming Business, AGLC guidance issued in June 2026 prohibits land-based casino licensees from advertising specific inducements such as sign-up bonuses on behalf of online operators, and prohibits tying existing retail loyalty programmes to online sportsbook or iGaming promotions. Operators with retail casino affiliates in Alberta must ensure those channels are operating within these boundaries from day one of market launch.
Designing Feature Flags for a Compliant Rollback Architecture
The SRIG’s change management requirements have a direct implication for how product teams should architect feature releases. The requirement that all gaming system changes be reviewed, risk assessed, tested, approved, and verified with evidence linked to the change record, combined with the obligation to detect and prevent unauthorized or unintentional changes to the gaming system, means that a release strategy involving undifferentiated code pushes creates structural compliance risk. A feature that goes live unintentionally because it lacked a gating mechanism is precisely the scenario the SRIG’s change management framework is designed to prevent.
Feature flags satisfy the SRIG’s intent at multiple levels. A flag-controlled release can be scoped to a defined player segment for testing before broad activation, which satisfies the testing requirement. The flag state (enabled or disabled per environment and segment) is a piece of evidence linkable to the change record. A rejected change, whether rejected by AGLC, by the ATF, or by an internal compliance review, can be rolled back by disabling the flag without a new code deployment, which eliminates the risk of an unauthorized or unintentional live state persisting while a hotfix is prepared.
The practical architecture for an Alberta-compliant feature flag system should assign each flag to the modification category of the feature it controls. A flag controlling a new paytable variant is a Regulatory-category flag: it must not be enabled in the Alberta production environment until ATF certification for that variant is in hand. A flag controlling a UI layout experiment is Non-Regulatory and may be enabled after internal confirmation and documentation. Emergency fix flags, where a feature is disabled to remediate a live issue, should automatically trigger the five-business-day ATF submission clock in the change management system.
Practical Requirement: Emergency changes deployed outside the normal release process must be followed by a documented post-implementation review within two business days. Feature flag systems should log activation and deactivation events with timestamps to generate this audit trail automatically.
The Notification Matrix and Regulatory Reporting Workflow
The AGLC Internet Gaming Notification Matrix governs what operators and GSSs must report and through which channel. The Go-Live Compliance Guide identifies two types of obligations under the Matrix: incident-based notifications and regular regulatory submissions. These are distinct workflows and must not be conflated in internal compliance tracking.
Incident-based notifications, including security breaches, gaming irregularities, suspected illegal activity, and unresolved customer disputes that require escalation to AGLC, are submitted to the AGLC iGaming Compliance Branch at iGamingCompliance@aglc.ca. Suspicious activity must also be reported to AGLC’s Customer Care Centre at 1-800-561-4415. Changes to ownership structure, financial interest, or key employees are routed to AGLC’s Due Diligence Unit at DueDiligence@aglc.ca. AML and financial reporting submissions go to AiGC, not to AGLC directly.
Alberta’s notification matrix is framed as a standards-based judgment tool rather than a granular, version-controlled checklist. Operators familiar with Ontario’s more prescriptive AGCO notification matrix must note this distinction: Alberta’s framework requires the operator to assess whether a development falls within the matrix’s notification triggers by reference to the SRIG Standards themselves, not just by matching the development against a checklist item. This places more interpretive weight on the operator’s compliance function. For a detailed side-by-side comparison of how Ontario and Alberta handle this and other operational requirements, see AGCO vs AGLC: Key Differences in Ontario and Alberta Internet Gaming Regulation.
The Annual Technology Compliance Confirmation
Beyond the event-driven change management obligations, registered operators must submit an annual Technology Compliance Confirmation (TCC) signed by the CEO, CCO, or an equivalent position. The TCC must confirm that the operator’s technology is compliant with the applicable SRIG Standards and must cover the entire technological solution for the Alberta iGaming operation, including the platform and underlying infrastructure, operating systems and databases, network devices, gaming software and other applications, all affiliated GSS providers (accompanied by a list of entity names), and third-party technology integrations.
The TCC is an annual obligation. Any change introduced to the technology stack during the year, such as a new gaming platform component, a new GSS integration, or a new data centre provider, must be accurately reflected in the next TCC submission. Product and compliance teams should maintain a running technology inventory that maps each component to its ATF certification status and SRIG compliance basis, so that the annual TCC can be assembled from verified records rather than reconstructed from memory. GSSs running critical gaming systems must confirm their Control Activity Matrix (CAM) compliance before go-live, though the CAM submission itself is only required when requested by AGLC.
Common Rejection Patterns and How to Avoid Them
The most common source of ATF certification rejection in comparable frameworks is a mismatch between the technology as tested and the technology as deployed. ATF certifications in Alberta are issued for a specific version of the technology and may specify features that must be disabled for the certification to be valid. An operator that enables a feature the ATF required to be disabled is operating non-certified technology in Alberta’s production environment, which is a breach of SRIG Section 4.12 regardless of whether the feature itself would have passed a separate certification.
The second common failure point is misclassification of a modification as Non-Regulatory when it affects a compliance-relevant component. A change described as a “display update” to a game’s information screen that also modifies how bet limits are presented to the player is not cosmetic if the SRIG requires that bet limit information be presented in a specific way. Compliance teams reviewing modification classifications must interrogate every change against the SRIG’s requirements for game outcomes, game management, player account management, and the player-facing display obligations, not merely against an internal “cosmetic vs functional” heuristic.
Third-party supplier changes are a frequently underestimated trigger. When a platform provider or content aggregator updates a system component, the registered operator inherits the compliance obligation for that change. A supplier patch that the aggregator classifies as a Non-Regulatory bug fix still requires the operator to confirm that classification is accurate for Alberta purposes, because the operator bears responsibility to AGLC for the integrity of the gaming system. Operators should build contractual triggers into their GSS agreements that require advance notice of any system modification, so that the Alberta classification review can happen before the change reaches production.
Compliance officers building Alberta product teams from scratch should consult the full SRIG alongside the Go-Live Compliance Guide and engage qualified legal counsel in Alberta to map the specific technology stack against the modification categories before establishing release management procedures. The SRIG bulletin published on January 13, 2026 confirmed that AGLC’s iGaming Compliance Branch remains the primary point of contact for compliance queries at iGamingCompliance@aglc.ca. For the foundational framework underlying all of these post-launch obligations, see Alberta iGaming Market Opening: What Registered Operators Must Know About the AGLC SRIG Framework.
Key Resources
AGLC Standards and Requirements for Internet Gaming (SRIG), version dated March 17, 2026, issued under authority of the AGLC Board Chair. Available at aglc.ca/igaming. Primary compliance reference for all registered operators and GSSs.
AGLC Internet Gaming Go-Live Compliance Guide, last updated January 2026. Defines the three ATF modification categories and the Technology Compliance Confirmation requirements. Available at aglc.ca/igaming.
AGLC Internet Gaming Notification Matrix. Governs incident-based and regulatory submission obligations. Registrants must review this document before going live. Available at aglc.ca/igaming.
AGLC iGaming Bulletin, SRIG Publication Notice, January 13, 2026. Confirms the SRIG structure and directs compliance enquiries to iGamingCompliance@aglc.ca.
Matt Denney
Editorial · gamingcompliance.io
Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.
The Tuesday brief, every week.
One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.
Unsubscribe with one click. We'll never share your address.