Skip to main content
AGCO Standards for Internet Gaming

All 114 Ontario standards,
organised by risk theme

A searchable, filterable index of every AGCO Standard for Internet Gaming. Grouped by the five regulatory risk themes, tagged for the player-protection categories our editorial team tracks most closely, with the exact standard text, sub-requirements, and AGCO guidance notes attached to each card.

114 Standards
5 Risk Themes
34 Player-flagged
5 Categories
Showing all 114 standards
1
Risk Theme 1

Entity Level

Ensure regulated entities maintain sound control environments, organizational structures promoting good governance, accountability, oversight, and transparency with AGCO.

22 standards 5 player-flagged
23%
flagged
Regulatory risks this theme addresses
  • Lack of appreciation for critical control environment elements
  • Undefined Board mandate and independent oversight gaps
  • No wrong-doing reporting mechanisms
  • Inadequately documented management policies
  • Poor ethical behavior understanding
  • Opaque decision-making processes
  • Individual non-compliance knowingly occurring
S1.01

Commitment to Character, Integrity and High Ethical Values

There shall be a commitment to character, integrity and high ethical values demonstrated through attitude and actions.

Requirements
  • Adhere to all applicable laws and regulations
  • Respond timely to matters identified in auditor letters and Registrar findings
  • Create and maintain code of conduct addressing conflicts of interest and transparency in Registrar dealings; ensure employee compliance and regularly review
Management in this Standard refers to executives and senior-level management with day-to-day business responsibility.
S1.02

Develop, Document, Implement Formal Control Activities

Operators and gaming-related suppliers shall develop, document and implement formal control activities to address regulatory risks and achieve regulatory objectives.

Requirements
  • Establish periodic review process for control effectiveness; document and remedy deficiencies
  • Communicate substantial control environment changes timely to Registrar
  • Make control activities available to AGCO for regulatory assurance
  • Develop control activity matrix summarizing all controls (including third-party suppliers)
  • Have control activities assessed by independent oversight function for Standards alignment
S1.03

Document and Report Management Overrides

Management overrides of control activities shall be clearly documented and made available upon request.

Requirements
  • Require approval from at least two senior managers to override any control; report each override to Board
S1.04

Financial Reporting Controls

Operators must establish, implement and maintain controls to support preparation of financial reports complying with all applicable accounting standards, rules and good practices.

S1.05

Personnel Security Screening

A personnel security screening process shall be in place for any director, officer, employee, agent or consultant at a level appropriate for their organizational role.

S1.06

Employee Competence and Training

Employees must have competence, skills, experience and training required to execute relevant control activities.

Requirements
  • Train control-performing employees on control environment, regulatory risks controls mitigate, and regulatory objectives reflected in Standards
S1.07

Organizational Structures Promoting Sound Controls

Organizational structures shall be designed to promote sound control environments and proper segregation of duties minimizing collusion and unauthorized activities.

Requirements
  • Give employees documented authority and responsibility subject to supervision
  • Regularly review segregation of duties adequacy (player protection, game integrity, asset protection)
  • Maintain updated organizational chart showing key reporting lines; make available to Registrar on request
S1.08

Management Accountability and Authority Understanding

Management clearly understands its accountability and authority for the control environment.

Requirements
  • Train management on control environment, regulatory risks, and regulatory objectives
S1.09

Information and Compliance Log Retention

Information, including logs, related to compliance with law, Standards, Requirements and/or control adherence shall be retained minimum three (3) years, unless otherwise stated.

S1.10

Document Compliance in Organized Manner

Compliance with Standards and Requirements shall be documented in organized manner enabling review and audit by independent oversight function.

Requirements
  • Review and analyze documentation for Standards compliance; approve by management
  • Grant internal and external auditors access to all relevant systems, documentation and resources
  • Where directed, retain independent Registrar-acceptable auditor for Registrar-required audits; provide audit report copies to Registrar
  • Have internal and external auditors account for Registrar expectations when reviewing controls
S1.11

Primary Board Accountability for Compliance

Primary compliance accountability resides with Board or other governance structure, with evidence the Board has carried out this responsibility.

Requirements
  • Establish independent compliance oversight function
  • Establish internal audit function regularly auditing control environment and compliance framework
  • Grant compliance oversight and internal audit functions direct, unrestricted Board access
  • Board establishes committee(s) overseeing compliance and audit functions
  • Board members and committee members understand business operations, initiatives, major transactions, and possess requisite skills, training, experience and independence
S1.12

Independent Whistleblowing Process

There shall be independent 'whistleblowing' process allowing employees to anonymously report control environment deficiencies, non-compliance incidents with controls, Standards, Requirements, or law.

Requirements
  • Ensure whistleblowing-raised issues are addressed and communicated to Board timely
S1.13

Transparent Registrar Engagement

Registrants shall engage with Registrar in transparent way.

Requirements
  • Report incidents/matters affecting gaming integrity or public confidence per notification matrix
  • Report non-compliance incidents with law, Standards, Requirements or controls per notification matrix
  • Make available any Registrar-requested data, information and documents
S1.14

Investigator Game Access

The Operator shall ensure that investigators (OPP or Registrar) are able to monitor and participate in games.

S1.15

Player Contact Mechanism for Issues and Complaints

Player Rights

A mechanism shall be in place allowing players to contact Operator in timely fashion with issues/complaints relating to player account, funds management, game play or Standards/Requirements compliance. Registrar shall be notified per notification matrix.

S1.16

Record and Address Player Complaints, Disputes and Inquiries

Player Rights

Player complaints, disputes and inquiries must be recorded and addressed in timely, fair, transparent and appropriate manner.

Requirements
  • Maintain clear service standards; make available to players
  • Resolve disputes under Ontario and Canadian law
S1.17

AGCO Information Display

Player Rights

Relevant AGCO information shall be displayed and easily accessible to the player.

S1.18

Contract Only with Reputable Suppliers

Operators and gaming-related suppliers shall only contract with reputable suppliers.

S1.19

Operator Responsibility for Third Party Actions

Affiliate Rules

Operators are responsible for third party actions and must require third parties to conduct themselves as if bound by same laws, regulations, and standards.

S1.20

Maintain Supplier List

Operators and gaming-related suppliers shall maintain supplier list providing goods/services relating to lottery schemes; make available to Registrar on request.

S1.21

Independent Third Party Marketing Restrictions

Affiliate Rules

Operators must ensure independent third parties engaged in direct-to-consumer marketing, promotion, or player referral services under contract do not undertake such activities for unregistered AGCO online gaming sites.

This Standard covers 'affiliates' or 'marketing affiliates'—entities paid or compensated to refer customers through direct-to-consumer marketing.
S1.22

Cease Unregulated Activities; Prohibit Unregistered Service Agreements

Operators and gaming-related suppliers must cease unregulated activities if those same activities require registration under GCA to conduct in regulated scheme. Operators shall not enter agreements with unregistered persons providing goods/services if provision would require registration under GCA.

2
Risk Theme 2

Responsible Gambling

Ensure gaming provision minimizes potential harm and promotes responsible environment.

27 standards 22 player-flagged
81%
flagged
Regulatory risks this theme addresses
  • Inappropriate advertising targeting minors
  • False, misleading or deceptive advertising
  • Advertising promoting excessive play
  • Players permitted excessive play
  • Responsible gaming controls not designed into environment/product
  • Players unaware of problem gambling risks and self-control options
S2.01

Implement and Follow Responsible Gambling Policies

RG Critical

Operators shall implement and follow policies/procedures identifying, preventing and minimizing gaming harm risks. All staff including senior management shall be trained.

Requirements
  • Integrate RG policies/procedures into control activities
  • Provide manager/staff training supplementing control activity training; regularly evaluate programs
  • As part of regular review, consult stakeholders (players, RG practitioners/researchers)
  • Assess staff understanding of policies, RG concepts, problem gambling and job duty impacts
S2.02

OLG and iGaming Ontario Responsible Gambling Policies

The OLG and iGaming Ontario shall implement and follow policies/procedures ensuring their activities facilitate and support gaming harm identification, prevention and minimization.

S2.03

Advertising Shall Not Target High-Risk, Underage or Self-Excluded Persons

RG Critical Affiliate Rules

Advertising, marketing materials and communications shall not target high-risk, underage or self-excluded persons.

Requirements
  • Must not use themes or language appealing primarily to minors
  • Must not appear adjacent to schools or youth-oriented locations
  • Must not use cartoon figures, celebrities, or influencers likely appealing to minors
  • Must not use active/retired athletes except for responsible gambling advocacy
  • Must not use individuals who are or appear to be minors
  • Must not appear in media/venues directed primarily to minors
  • Must not exploit susceptibilities of high-risk persons
  • Must not entice or attract high-risk players
S2.04

Marketing Shall Be Truthful and Not Mislead

Affiliate Rules Bonus Ads

Marketing, including advertising and promotions, shall be truthful, shall not mislead players or misrepresent products.

Requirements
  • Must not imply gaming fulfills family/social obligations or solves personal problems
  • Must not promote gaming as employment alternative or financial security source
  • Must not contain celebrity endorsements suggesting gaming contributed to their success
  • Must not encourage play as a means to recover losses
  • Must not make false promises or present winning as a probable outcome
  • Must not imply winning chances increase with longer play or higher spending
  • Must not condone socially irresponsible gaming behavior
  • Must not suggest gaming provides escape from personal problems
  • Must not portray gaming as a life priority over family, friends, or career
  • Must not suggest gaming enhances personal qualities
  • Must not suggest peer pressure to gamble
  • Must not link gaming to sexual success or enhanced attractiveness
  • Must not portray gaming in a context of toughness
  • Must not suggest gaming is a rite of passage
  • Must not offer products not reasonably attainable without substantial losses
S2.05

Inducement, Bonus and Credit Advertising Prohibition Outside Gaming Site

Bonus Ads Affiliate Rules

Advertising and marketing materials communicating gambling inducements, bonuses and credits are PROHIBITED, except on operator's gaming site and through direct advertising/marketing after receiving active player consent.

This standard prohibits all public advertising including targeted and algorithm-based ads. Direct marketing includes direct messaging via social media, emails, texts, and phone calls.
S2.06

Permitted Inducement/Bonus/Credit Advertising Requirements

Bonus Ads

Permitted advertising and marketing materials communicating gambling inducements, bonuses and credits must disclose all material conditions and limitations.

Requirements
  • Disclose all material conditions and limitations at first presentation on gaming site; other conditions/limitations no more than one click away
  • Must not describe offers as 'free' unless truly free
  • Must not describe as 'risk-free' if player incurs loss or risks own money
S2.07

Player Opt-in for Direct Inducement/Bonus/Credit Marketing

Bonus Ads

Players must be provided opt-in process whereby they actively consent to receiving direct advertising/marketing of inducements, bonuses and credits, and must be provided method to withdraw consent at any time.

S2.08

Systematic Approach to Support Informed Decision Making

RG Critical

A systematic approach is used to support, integrate, and disseminate information enabling players to make informed decisions and encourage safer play.

Requirements
  • Make RG materials and help information available and visible to all players
  • Make financial and time-based gaming limit information available
  • Make self-exclusion program information available
  • Include RG message in advertising/marketing materials
  • Regularly review/update all RG information
  • Periodically measure player awareness; address gaps
S2.09

Registration Page and Player Account Responsible Gambling Displays

RG Critical Player Rights

The registration page and pages within player account shall prominently display responsible gambling statement, online link, Connex Ontario number, and provide link to RG materials and resources for problem gaming persons.

S2.10

Monitor Player Risk Profiles and Behaviors

RG Critical

A mechanism shall be in place to monitor player risk profiles and behaviours for detecting signs of players potentially experiencing harm.

Requirements
  • Include high-risk player harm profile in player risk profile system
S2.11

Readily Available and Systematically Provided Assistance

RG Critical Player Rights

Assistance for players experiencing gaming harms is readily available and systematically provided.

Requirements
  • All player-interacting employees knowledgeable about help resources
  • Provide contact information for at least one Ontario organization dedicated to treating/assisting gaming-harm-experiencing persons
  • Develop and implement RG policies and training for harm assessment/detection
  • Periodically review RG policies for effectiveness
  • Make live customer support available 24/7
S2.12

Employee Responsible Gambling Understanding

RG Critical

Employees shall understand responsible gambling importance, job impacts on player protection, and fundamental responsible/problem gambling concepts.

Requirements
  • Provide all employees mandatory training refreshed regularly
  • Provide player-interacting employee training to identify and respond to problem gambling signs
  • Ensure employee understanding of operator's RG commitment
  • Ensure employee understanding of gaming harms and prevention/mitigation concepts
S2.13

Break in Play Option

RG Critical

Individuals shall have the option to take a break in play, in addition to a formal self-exclusion program.

Requirements
  • Users shall have option to initiate short-term break
  • Operators shall provide 1 day, 1 week, 1 month, 2 month, or 3 month break options
  • Once break initiated, individuals unable to place further wagers during break period
S2.14

Voluntary Self-Exclusion Program

RG Critical Player Rights

Operators shall provide a voluntary self-exclusion program for their site.

Requirements
  • Promote self-exclusion programs and make easily accessible
  • Self-exclusion registration process shall be efficient and support-oriented
  • Clearly word self-exclusion terms/conditions
  • Define clearly term lengths including 6 month, 1 year and 5 year options
  • Immediately log out self-excluded individuals
  • Take all reasonable steps preventing marketing materials reaching self-excluded individuals
  • End wagers upon self-exclusion
  • Maintain excluded persons register
  • Actively identify self-excluded persons breaching exclusion agreements
  • Establish mechanism for unused funds return
S2.15

Game Designs and Features Clarity

Game designs and features shall be clear and shall not mislead the player. This Standard does not apply to sport and event betting products.

Requirements
  • Game design shall not give perception that speed of play or skill affects outcomes when it does not
  • After outcome selection, games shall not make variable secondary decisions affecting displayed result
  • Where game requires predetermined pattern, winning spot locations shall not change during play
  • Games shall not display unachievable amounts or symbols
  • Free-to-play games shall not misrepresent winning likelihood
  • Clearly display each credit denomination
S2.15.1

Sport and Event Betting Bet Method Clarity

The method of making bets in sport and event betting must be straightforward and understandable.

Requirements
  • Identify parlays as parlays
  • Inform player whether selected bet has or has not been accepted
  • Where odds change prior to bet confirmation, provide player option to confirm or withdraw
  • Where operators offer automatic bet change acceptance, player must manually opt in
  • Inform player of betting period
  • Free-to-play games must not mislead regarding odds
  • Express all bets and payouts in Canadian currency
S2.15.2

Available Sport and Event Bet Information Access Without Betting

Players must be able to access information regarding available sport and event bets without having to place a bet.

S2.15.3

Reputable and Legitimate Data Sources for Bet Outcomes

Reputable and legitimate data source(s) must be used determining bet outcomes.

S2.16

Game Designs Preventing Extended, Continuous and Impulsive Play

RG Critical Game Design

Game designs and features shall help prevent extended, continuous and impulsive play.

Requirements
  • Games shall not encourage chasing losses, wagered-amount increases, or continued play after indicated stopping desire
  • Games shall not provide auto-play features for slots
  • Game play initiated only after player places wager and activates play
  • Player should commit to each game individually through start button action
S2.17

Prohibition on Multiple Simultaneous Slots Game Functionality

RG Critical Game Design

The gaming system must not offer functionality which facilitates playing multiple slots games simultaneously. This includes split screen or multi-screen functionality.

S2.18

Minimum 2.5 Second Inter-Game Interval and Start Button Requirements

RG Critical Game Design

It must be a minimum of 2.5 seconds from game start until next game cycle commencement. It must always be necessary to release and then depress the 'start button' or take equivalent action.

S2.19

Slots Games Result Presentation Time Restriction

RG Critical Game Design

For slots games, the gaming system must not permit customers to reduce time until result presentation.

Requirements
  • Features such as turbo, quick spin and slam stop are NOT permitted
S2.20

Slots Games Auditory/Visual Win Effect Restrictions

RG Critical Game Design

For slots games, the gaming system must not use auditory or visual effects associated with wins for returns less than or equal to last total amount wagered.

S2.21

Slots Game Session Net Position Display

RG Critical Player Rights

For slots games, gaming sessions must clearly display customer's net position (total winnings minus losses since session start), in Canadian dollars.

S2.22

Time Passage Tracking Means

RG Critical

Players shall have means to track time passage.

S2.23

Gaming Limits Setting Provision

RG Critical Player Rights

Players shall be provided with easy and obvious way to set gaming limits (financial and time-based) upon registration and at any time after registration.

Requirements
  • Provide players option to set loss and deposit limits during registration
  • Offer players options setting limits on deposit limits and loss limits
  • Offered period/duration must include 24 hours, 7 days and one month
  • Make financial and time limit functions easy to find anytime after registration
S2.24

Cooling-Off Period for Gaming Limit Relaxation/Elimination

RG Critical Player Rights

Where a gaming limit has been previously established by a player, a request by the player to relax or eliminate that limit shall only be implemented after a cooling-off period of at least 24 hours.

Requirements
  • Operator must not relax/eliminate gaming limit without player request and only after cooling-off period expiry
  • Gaming system must enforce gaming limits
3
Risk Theme 3

Prohibiting Access & Player Accounts

Protect public interest and game integrity by ensuring prohibited individuals cannot participate and schemes conduct within Ontario per Criminal Code.

23 standards 4 player-flagged
17%
flagged
Regulatory risks this theme addresses
  • Prohibited individuals gaining access
  • Product sales outside jurisdiction
S3.01

Only Eligible Individuals May Access Gaming

Player Rights

Only eligible individuals are permitted to create a player account, and only individuals who hold valid player account are permitted to log on and gamble.

Requirements
  • Ineligible: Under 19 years of age; self-excluded individuals; individuals restricted via court order
  • Ineligible: Officers/board members of Operator; executives/staff of trade unions; employees of registered suppliers
  • Ineligible: AGCO members or employees; OLG or iGaming Ontario officers/employees
  • Ineligible individuals are not eligible for prizes
S3.01.1

Prohibited Betting Activities

Operators shall not knowingly permit individuals with non-public information or sport-connected persons to bet on related events.

Requirements
  • Persons with non-public information about events are prohibited from betting on those events
  • Athletes, coaches, managers and owners are prohibited from betting on their own sport
  • Operators must make reasonable efforts informing entities with information-sharing relationships if prohibited activity found
S3.02

Games Provided Only Within Ontario

Games on gaming sites shall be provided only within Ontario, unless conducted in conjunction with another province government.

Requirements
  • Implement mechanisms detecting and dynamically monitoring player location; block unverified play attempts
  • Implement mechanisms detecting circumvention-capable programs
S3.03

Re-Verify Player Eligibility Upon Prohibited/Excluded Individual List Changes

If the list of prohibited and excluded individuals changes, all registered player information shall be re-verified.

S3.04

Collect, Save and Validate Relevant Player Information

Relevant player information shall be collected and saved upon registration. Minimum information required at registration:

Requirements
  • Name
  • Date of birth
  • Address
  • Log-on identification method
  • Player contact information
  • Information required by Proceeds of Crime (Money Laundering) and Terrorist Financing Act
S3.05

Player Affirmation of Information Completeness and Accuracy

Before a player account is created, players shall affirm that all player information provided upon registration is complete and accurate.

S3.06

Keep Player Information Complete and Accurate

Player information shall be kept complete and accurate.

S3.07

Player Fitness Affirmation Prior to Game Play

Prior to participating in game play, players must affirm that they are fit for play.

S3.08

Uniquely Identifiable Player Accounts

All player accounts shall be uniquely identifiable.

S3.09

One Account Per Gaming Site

Players may have only one player account per gaming site.

S3.10

Auditable Account Event Trail

There shall be an auditable trail of events that is logged and available relating to account creation and activation, account deactivation and account changes.

S3.11

Player Contract Terms Acknowledgment and Acceptance

Players shall acknowledge and accept the contract terms governing player account and game play prior to account creation and shall acknowledge and accept any subsequent material term changes when logging in.

S3.12

Player Authentication Prior to Account Access and Gambling

All players shall be authenticated prior to accessing their player account and being permitted to gamble. Third parties are not permitted to access a player's account.

Requirements
  • Give players option to use multi-factor authentication when logging in
S3.13

Record and Log All Player Account Transactions

All player account transactions shall be recorded and logged in an accurate and complete manner.

S3.14

Readily Available Player Account Information

Player Rights

Player account information shall be made readily available to the player.

S3.15

Readily Available and Clear Player Account Transaction Information

Player Rights

Information about player account transactions shall be made readily available and clear to the player. Gaming System Shall Give Players Access To:

Requirements
  • Deposit and withdrawal history, and current balance
  • Method and funds source used for transactions
  • Date and time of previous login
  • Gaming event and transaction history
  • Total monies wagered for session and/or period
  • Total monies won or lost for session and/or period
  • Account balance at session start and end
S3.16

Uniquely Identifiable and Traceable Player Account Transactions

All player account transactions shall be uniquely identifiable and traceable to a unique individual player account.

S3.17

Inform Players of Dormant Account Remaining Funds

Reasonable efforts shall be made to inform players of player funds remaining in dormant accounts.

S3.18

Player Account Deactivation Election

Players may elect to deactivate their player account at any time and, once the election is made, the account is deactivated.

S3.19

Operator-Initiated Account Deactivation

Where necessary, a player account may be deactivated by the Operator.

S3.20

Registrar-Directed Account Deactivation

A player account shall be deactivated if requested by the Registrar.

S3.21

Removed Player Information Retention

If player information is removed, it must be retained in accordance with Standard 1.09 or other applicable records retention requirement.

S3.22

Recover Dormant or Deactivated Account Balance

Player Rights

Where an account becomes dormant or is deactivated by a player or another authorized individual, the player shall be able to recover the balance of their account owing to them.

4
Risk Theme 4

Game Integrity & Player Awareness

Ensure Ontario gaming conducts with honesty and integrity and players have sufficient informed-decision-making information.

39 standards 3 player-flagged
8%
flagged
Regulatory risks this theme addresses
  • Inability to regulate all components
  • Related parties winning at higher percentages than public
  • Insufficient player information for informed choices
  • Game and system integrity lack
  • Game procedures non-compliance
  • Game and system failures
  • Betting market compromise through insider betting or game manipulation
S4.01

Fair, Honest and Independently Verifiable Conduct

All gaming activities and financial transactions shall be conducted fairly and honestly, and must be independently verifiable.

S4.02

Appropriate, Accurate and Complete Records

There shall be appropriate, accurate and complete records of transaction and game state and play information kept.

S4.03

Compensating Manual Controls if Logging Interrupted

There shall be a mechanism in place to ensure that if logging is interrupted, compensating manual controls are used, where reasonable.

S4.04

Custom and On-Demand Registrar Reports

The gaming system shall be capable of providing custom and on-demand reports to the Registrar.

S4.05

Documented Game Specifications

Game specifications must be documented that clearly indicate: objectives of the game, wagers that may be made, how the game is operated and played, odds of winning for each available prize, the advantage of the operator in relation to each wager.

S4.06

Pre-Bet Player Information for Informed Decisions

Player Rights

Prior to placing a bet or wager, the player shall be provided with sufficient information to make informed decisions about betting or wagering based on chances of winning, the way the game is played, and how prizes and payouts are made.

Requirements
  • Provide easily-located comprehensive and accurate information including game rules and how to play pages
  • Provide winning outcome descriptions, odds of winning, payout information, and prize value units
  • Where interaction speed affects winning chances, inform players
  • Provide cash-out options and win redemption information
  • Provide information on circumstances where game can be declared void
S4.07

Non-Misleading Pre- and During-Play Information

Information provided to players prior to and during game play shall not mislead players or misrepresent games.

Requirements
  • Shall not describe unachievable outcomes
  • Shall not encourage play as loss recovery
  • Shall not make false promises or present winning as probable
  • Shall not imply winning increases with longer play
  • Shall not use language suggesting outcome is 'due', 'overdue', or 'ready to hit'
S4.08

Game and System Component Approval or Certification

All igaming games, random number generators and igaming system components must be approved by the Registrar or certified by an independent testing laboratory registered by the Registrar.

S4.09

Gaming System and Supply Provision, Installation, Configuration, Maintenance

Gaming systems and gaming supplies shall be provided, installed, configured, maintained, repaired, stored, and operated in a way that ensures integrity, safety and security.

S4.10

Game or System Fault Response

Where there are suspected game or system faults that may impact game integrity or fairness, Operators shall make the game unavailable to players until resolution.

S4.11

Logically Separated Production, Testing and Development Systems

Production, testing and development systems shall be logically separated.

S4.12

Game Outcome and Sport/Event Betting Transaction Recoverability

Game outcomes and sport and event betting transactions shall be recoverable, where technically possible, so that player bets can be settled appropriately.

S4.13

Game or System Fault Resolution Policies

In any case where there is a game or system fault, the Operator shall have clearly defined policies and processes in respect of treating the player fairly when resolving the player's transactions. These policies and processes shall be made available to players.

S4.14

Game Recreation to Last Communicated State

Mechanisms shall be in place to allow a game to be recreated up to and including the last communicated state to the player.

S4.15

Bet and Game Outcome Display

A player's bet and the outcome of the game shall be clearly displayed, easy to understand, and available for a sufficient length of time for the player to review.

S4.16

Accurate, Complete and Timely Game Payouts

Player Rights

Games shall pay out accurately, completely and within a reasonable time of winning, subject to checks and verifications.

S4.17

Collusion and Cheating Deterrence, Prevention and Detection

Operators shall have mechanisms in place to appropriately deter, prevent and detect collusion and cheating.

S4.18

Log All Collusion and Cheating Detection Activities

All relevant activities related to the detection of collusion and cheating shall be logged.

S4.19

Player-Accessible Collusion and Cheating Reporting Process

Players shall be provided with clear information on the process to report activities related to collusion and cheating, including suspected use of bots. The process must be simple to use and readily accessible.

S4.20

Interaction Speed Disadvantage Prevention

Where speed of interaction has an effect on the player's chances of winning, the Operator shall take reasonable steps to ensure the player is not unfairly disadvantaged due to gaming system related performance issues.

S4.21

Service Interruption Player-Fair Response

Player Rights

Service interruptions shall be responded to and dealt with in a way that does not disadvantage players.

Requirements
  • Inform players that connection or processor speed may have an effect
  • Recover from failures causing game interruptions in timely fashion
  • Where appropriate, void bets
  • Retain sufficient information to restore pre-failure events
  • Pay players the amount won to that point, or return bets to players where game cannot continue after interruption, whichever provides better player outcome
S4.22

Bot Use and Unfair Advantage Prevention

In peer-to-peer games, Operators must implement measures intended to deter, prevent and detect the use by players of software programs to automatically participate in game play (bots).

S4.23

Fair Player Treatment in Games

Games must be conducted in a manner that ensures players are treated fairly and not unfairly disadvantaged by other players.

S4.24

Game Operation Per Specifications and Outcome Determination

Games must operate according to their game specifications and the outcomes must be determined in accordance with the terms governing play and prevailing payouts as they are described to the player.

S4.25

Bets Committed Before Game Outcome Determination

Bets shall be committed before the determination of game outcomes. Any wager received after the determination of game outcomes shall be voided and returned to the player.

S4.25.1

Sport and Event Betting Settlement Fairness

In sport and event betting, bets must be settled fairly and in accordance with the terms of the bet placed by the player and any applicable betting rules.

S4.25.2

Sporting Event Results Provision

The results of bets on sporting or other events must be provided to players making bets on the events. Any change of results must be made available.

S4.25.3

Sport and Event Results Data Controls

Sport and event betting operators shall have controls in place to ensure the accuracy and timeliness of sport and event results data.

S4.26

Random Game Element Selection Mechanism

A mechanism shall be in place to randomly select game elements used to determine game outcomes. Not applicable to sport and event betting.

Requirements
  • Select and use initial values to seed random selection process ensuring outcome randomness
  • Not influence selected game elements by amount wagered or play style unless clearly disclosed
  • Make selection mechanism impervious to outside influences
  • Not alter or manipulate selected game elements through secondary game program decisions
S4.27

Game Element Selection Mechanism Monitoring and Inspection

Mechanisms used to select game elements must be capable of being monitored and inspected to ensure integrity and randomness of generated outcomes.

S4.28

Unchanging Game Session Terms

Terms governing play must not be changed during a game session unless the player is made aware of the change before the player places any wagers.

S4.29

Secured and Authenticated Game Sessions

Game sessions must be appropriately secured and checked for authenticity.

S4.30

Player Activity Inactivity Time-Out

There shall be a player activity time-out that automatically logs the player out or ends the player's session after a specified period of inactivity.

S4.31

Critical Function Generation by Gaming System

All critical functions, including the generation of the outcome of any game, shall be generated by the gaming system, independent of the end player device.

S4.32

Betting Integrity Risk Mitigation Measures

Sport and event betting operators shall have risk management measures in place to mitigate the betting integrity risk, including insider betting and event manipulation.

S4.33

Operator Response to Suspicious Activity Reports

An operator receiving a report of suspicious activity may suspend or cancel sport and event betting on events related to the report or withhold associated customer funds. The Operator's decision must be fair, reasonable, and made in good faith.

S4.34

Sport and Event Betting Product Criteria

Operators offering sport and event betting products shall ensure bets meet criteria including: outcome can be verified, outcome not affected by placed bet, majority of participants 18+, event supervised by sport governing body. Prohibited: bets on financial markets, bets exposing players to losses greater than amount wagered, bets on minor league sports in Canada including CHL.

S4.35

Live Dealer Gaming Supply Access Restriction

Access to live dealer gaming supplies shall be restricted to individuals with a business need.

S4.36

Live Dealer Game Integrity Controls

Operators must have controls in place to ensure live dealer game presenters do not compromise the integrity of a game.

5
Risk Theme 5

Information Security & Asset Protection

Ensure assets (gaming equipment and systems) are protected and customer information and funds are safeguarded.

3 standards
0%
flagged
Regulatory risks this theme addresses
  • People are not safe
  • Assets and customer information are not safeguarded
  • Unauthorized individuals have access to prohibited areas
S5.01

Recognized Industry Standard Framework for IT Control Environment

A recognized industry standard framework shall be used to manage the information technology (IT) control environment to support compliance with the Standards and Requirements.

S5.02

User Access Based on Business Need

Users shall be granted access to the gaming system based on business need.

Requirements
  • Grant, modify and revoke access privileges based on employment status and job requirements; log all associated activities
  • Independently review and confirm access privileges on periodic basis
S5.03

Gaming Information System Access Monitoring and Logging

Access to gaming information systems shall be monitored, logged and shall be traceable to a specific individual.