GLI-33 - Gaming Laboratories International Event Wagering Systems
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
GLI-33: Audit, Significant Event Logging, Information Security, Change Control, Resilience
GLI-33 audit + logging + security + change + resilience. SIGNIFICANT EVENT LOGGING: every regulatorily significant event must be logged with timestamp (regulator-time-source-synced typically via NTP + Stratum-1) + actor + action + outcome + correlated session/wager/transaction; events include logon + logoff + admin actions + wager-acceptance/rejection + settlement + payout + change-control + system-start + system-stop + parameter-change + security-event + integrity-event + responsible-gaming-event + AML-event + KYC-failure + geolocation-failure; logs IMMUTABLE (write-once or signed/hashed) + retained per state regulator (typically 5 years) + accessible to regulator on demand. INFORMATION SECURITY: typically per GLI-27 (Standards for Network Security) + ISO 27001 + NIST CSF; specific GLI-33 requirements include (a) encryption at rest + in transit (TLS 1.2+ + AES-256); (b) access control (
- Significant event log + retention
- InfoSec program + pentest
- Change-mgmt + signature verification
- DR/BCP plan + annual test
- Significant event logging gaps
- Pentest cadence inadequate
- Change-mgmt + signature not enforced
- DR/BCP not tested
GLI-33: Event Wagering System Architecture, Wager Engine, Transaction Integrity
GLI-33 Event Wagering System architecture + wager engine + odds + risk. SYSTEM ARCHITECTURE: components include (a) presentation tier (web + mobile apps + retail kiosks + sportsbook lounge terminals); (b) wager acceptance + engine tier (wager validation + odds lookup + limit checks + risk-engine routing); (c) settlement + ledger tier (post-event settlement + account credit + audit); (d) reporting + integrity-monitoring tier; (e) data feeds from sports data providers (typically Sportradar + Genius Sports + IMG Arena + Stats Perform + others); (f) PAM (Player Account Management) integration; (g) payment processor + AML integration; (h) geolocation provider integration; (i) regulatory reporting endpoint. WAGER ENGINE: wager types (single + parlay + teaser + futures + props + live/in-play + same-game parlay + round-robin + box + half-time + period + multi-state); wager validation includes pl
- Architecture documentation
- Wager log + transaction immutability
- Odds-engine + risk-engine procedures
- Architecture gaps
- Wager log integrity not enforced
- Odds-change policy missing
GLI-33: Geolocation, Mobile Wagering, Internet Wagering, Session Management, Security
GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary; typical implementation uses third-party geolocation provider (GeoComply + Xpoint + Locator-X + IDology Position + others - often GLI-19 certified separately); verification methods include GPS + Wi-Fi triangulation + cell tower + IP + LBS + device sensors + spoof detection (VPN + proxy + emulator + jailbreak + GPS spoofing); CONTINUOUS RE-VERIFICATION typically every 5-15 minutes during active session + at every wager submission; FAILED VERIFICATION must block wager + may suspend session. MOBILE WAGERING SECURITY: app distribution via App Store + Google Play with regulator-approved hash + integrity check + jailbreak/root-detection + emulator-detect
- Geolocation provider + spoof-detection
- Mobile app integrity + binding
- Web security + WAF + bot-protection
- Session policy + MFA
- Geo-verification gaps
- Mobile integrity weak
- Bot-detection absent
- Session timeouts inadequate
GLI-33: Player Account Management, Identity Verification, KYC, AML, Payments
GLI-33 Player Account Management (PAM) + KYC + AML + payments. PAM REQUIREMENTS: (a) account registration with identity verification + age verification (18+ or 21+ depending on state) + jurisdictional eligibility; (b) account funding via approved payment instruments (debit card + ACH + bank transfer + wire + e-wallet + cash kiosk + sometimes credit card depending on state); (c) account balance ledger + transaction history + audit log; (d) deposit/withdrawal limits + responsible-gaming limits + self-exclusion enforcement; (e) account closure + dormancy + reactivation procedures; (f) one-account-per-player enforcement + duplicate-account detection; (g) authorized-user-only access (no shared accounts); (h) cooling-off + temporary-exclusion + permanent-exclusion features. KYC: typically minimum (a) name + DOB + SSN-last-4 (US) or full national ID + address + email + phone + government-ID doc
- PAM platform + KYC vendor
- AML program + SAR procedures
- PCI DSS compliance for payment
- Crypto-funding policy
- KYC vendor gaps
- AML SAR procedures missing
- PCI DSS lapses
- Crypto-funding policy absent
GLI-33: Responsible Gaming, Self-Exclusion, Integrity Monitoring, Anti-Fraud, Collusion
GLI-33 responsible gaming + integrity + anti-fraud. RESPONSIBLE GAMING (RG): MANDATORY FEATURES including (a) deposit limits (daily + weekly + monthly + per-transaction); (b) wager limits + loss limits; (c) session-time limits + cool-off periods; (d) self-exclusion (typically 1 year + 5 year + permanent + irrevocable for some periods); (e) reality-check pop-ups during session; (f) age-verification + minor-account-prevention; (g) account-suspension on responsible-gaming-flagged behavior; (h) RG resources (problem-gambling-helpline + counseling links + state-specific). SELF-EXCLUSION REGISTRY INTEGRATION: state-regulator-maintained self-exclusion lists (e.g. New Jersey + Pennsylvania + Illinois multi-state) + national NCPG + GamStop UK + others; pre-wager check + ongoing-sweep + cross-operator-coordination; account-blocking + funds-return procedures + no-promotional-contact. INTEGRITY MONI
- RG features + limits + self-exclusion
- Self-exclusion registry sync + audit
- Integrity alerts + integrity-officer
- ML anomaly detection + investigation
- RG features absent
- Self-exclusion gaps
- Integrity alerts not actioned
- Anti-fraud weak
GLI-33 sports event data + provider certification + regulatory reporting. SPORTS EVENT DATA INTEGRITY: source-of-truth for events (start time + end time + scores + outcomes + voiding events + abandonment + suspension + result-correction); typically OFFICIAL DATA from leagues (NFL + MLB + NBA + NHL + MLS + UEFA + FIFA + ATP + WTA + NASCAR + etc.) or regulator-approved data providers (Sportradar Official + Genius Sports + IMG Arena + Stats Perform + Lowy Solutions); 'OFFICIAL LEAGUE DATA' mandates in some states (Illinois + Tennessee + Michigan + Maryland + Virginia + DC + Connecticut + others) require purchase of official data from leagues for certain bet types (in-play + props + same-game parlay). DATA-FEED INTEGRITY: redundant feeds + reconciliation + dispute resolution; suspended-event handling; under-protest result handling; bet-voiding policies; settlement timing windows + delayed se
- Data-provider contracts + redundancy
- Official-data evidence per state
- Regulatory report templates + filing
- AML SAR + tax reporting
- Data-provider gaps
- Official-data not used (where required)
- Regulatory reports missing
- AML SAR + tax filings late
GLI-33: Standard Scope, GLI Certification Model and Coordination with GLI-19, GLI-21, GLI-27
GLI-33 Standards for Event Wagering Systems scope + GLI certification model. SCOPE: event wagering systems (sports betting + fixed-odds wagering + pool wagering + pari-mutuel wagering + fantasy sports + in-play wagering + same-game parlays + futures + props + esports + emerging variants). EVENT WAGERING SYSTEM defined as the suite of components (hardware + software + procedures + networks + interfaces) used by a regulated operator to (a) accept wagers from authenticated players; (b) compute settlements; (c) maintain player balances; (d) issue payouts; (e) report to regulators; (f) integrity-monitor + anti-fraud-detect. GLI CERTIFICATION MODEL: GLI is an INDEPENDENT testing laboratory (ISO/IEC 17025 + ISO 9001 + A2LA accredited) - tests against the standard + issues certification report to operator + state regulator; certifications typically valid for 1-3 years + require re-certification
- Certification + scope documentation
- GLI family alignment evidence
- Certification report retention
- Scope unclear
- Multi-standard coordination gaps
- Certification report missing
GLI-33: State Regulator Adoption, Certification Lifecycle, 2024-2025 Update Pipeline and Coordination
GLI-33 certification lifecycle + audit. CERTIFICATION LIFECYCLE: (a) INITIAL CERTIFICATION - operator submits system + documentation + test data + scoping document to GLI (or other accredited testing laboratory - e.g. BMM Testlabs + Eclipse Compliance Testing + iTech Labs + Quinel + others); GLI conducts source code review + functional testing + security testing + load testing + integration testing; typically 6-12 weeks + scope-dependent; report issued + signed off by state regulator; (b) ONGOING SURVEILLANCE - annual or biennial review + sample-testing + integrity-monitoring; regulator-driven; (c) RE-TESTING ON CHANGE - software changes triggering 'material' scope require re-testing + new certification report; emergency-change handling; change-management notifications; (d) DECOMMISSIONING - data retention + customer-account-transition + regulator-notification. AUDIT FREQUENCY: typically
- Certification + audit reports
- Change-mgmt procedure + re-cert evidence
- SOC 2 + ISO 27001 reports
- Licensing + bond + insurance
- Certification gaps
- Change-mgmt re-cert gaps
- SOC 2 + ISO 27001 missing
- Licensing + financial obligations missed
GLI-33 crosswalk to adjacent standards + state-specific technical standards. PCI DSS (Payment Card Industry Data Security Standard) v4.0 - applies to card-not-present payments in event wagering systems; required for any operator handling cards directly; tokenization + scope-reduction common. NIST CSF 2.0 - voluntary cybersecurity framework + commonly used by US-based operators for governance + identify + protect + detect + respond + recover; coordinates with GLI-27 (Standards for Network Security) which is more prescriptive. ISO/IEC 27001:2022 (Information Security Management System) - commonly certified by larger operators alongside GLI-33 certification; auditors may map GLI-27 + GLI-33 controls to ISO 27001 Annex A controls + ISO 27002 implementation guidance. ISO/IEC 27017 (Cloud Security) + 27018 (Privacy in Cloud) + 27701 (Privacy Information Management) - applicable to cloud-hosted
- Multi-framework certification
- State technical standards filing
- Integrity-monitoring participation
- Multi-state privacy + AML compliance
- Multi-framework alignment gaps
- State technical standards filing gaps
- Integrity participation gaps
- Multi-state compliance issues
GLI-33 implementation roadmap. ROLES: (a) HEAD OF COMPLIANCE or CHIEF COMPLIANCE OFFICER (CCO) - strategic regulator-relationship + multi-state + multi-jurisdiction; (b) HEAD OF SPORTS BOOK + RISK MANAGEMENT + ODDS - operational platform ownership; (c) HEAD OF PLAYER ACCOUNT MANAGEMENT (PAM) + KYC + AML - customer lifecycle; (d) INTEGRITY OFFICER - integrity-monitoring + alerts + sports-leagues coordination; (e) CISO + SECURITY ENGINEERING - InfoSec + GLI-27 + PCI DSS + ISO 27001; (f) DATA-PROTECTION OFFICER (DPO) - state privacy + customer-data; (g) RESPONSIBLE GAMING OFFICER - RG features + problem-gambling-prevention + self-exclusion-registry liaison; (h) RG VENDOR PROGRAM MANAGER - third-party RG technology (deposit-limits + self-exclusion + reality-check); (i) AUDIT + INTERNAL AUDIT - certification audit-readiness; (j) HEAD OF MARKETING + ADVERTISING - state-specific advertising com
- Role inventory + RACI
- Tooling adoption + vendor list
- Metrics + KPI dashboard
- Annual cycle documentation
- Roles undefined
- Tooling fragmented
- Metrics gaps
- Annual cycle ad-hoc
GLI-33 state regulator adoption + multi-state mobile. STATE ADOPTION (US): GLI-33 is commonly incorporated by reference by state gaming regulators including (a) NEW JERSEY DGE (Division of Gaming Enforcement) - Internet Gaming Technical Standards + sports wagering technical bulletins; (b) NEVADA GCB (Gaming Control Board) - Regulation 5 + Internet wagering + 2018 SCOTUS Murphy v NCAA legalisation; (c) PENNSYLVANIA PGCB - Sports Wagering Technical Standards; (d) MICHIGAN MGCB - online wagering + Sports Betting Act; (e) INDIANA IGC - Sports Wagering Rules; (f) ILLINOIS IGB - Sports Wagering Act; (g) IOWA IRGC; (h) TENNESSEE TSGC - Tennessee Sports Wagering Council + Sports Betting Act + Sports Betting Council 2021 transition; (i) MASSACHUSETTS MGC - Sports Wagering Act 2022 effective 2023; (j) COLORADO DOR; (k) ARIZONA ADG; (l) VIRGINIA VLOG; (m) MARYLAND LCC; (n) DC OLG; (o) CONNECTICUT D
- State-by-state certification per regulator
- Multi-state legal-opinion + tech-architecture
- International market entry compliance
- Tribal compact compliance
- State adoption fragmented
- Multi-state legal issues
- International expansion gaps
- Tribal compact gaps
GLI-33 2024-2025 status + update pipeline + global market. UPDATE PIPELINE: GLI continues to maintain + update GLI-33 reflecting industry evolution; emerging update areas include (a) IN-PLAY WAGERING + MICRO-BETTING (every play + every pitch + every possession) + same-game parlay + cash-out + edit-bet features; (b) CROSS-PLATFORM + OMNICHANNEL retail + mobile + web + in-venue kiosk + sports lounge interoperability; (c) AI/ML INTEGRATION - odds-making + risk-engine + responsible-gaming-detection + integrity-monitoring + anti-fraud + customer-experience; (d) CRYPTOCURRENCY-FUNDED ACCOUNTS - increasing operator + regulator attention to crypto deposits + withdrawals + wallet-integration + tax-reporting + AML implications; (e) FANTASY + ESPORTS + DFS - daily fantasy sports + esports wagering + skill-game variants requiring distinct framework; (f) SAME-GAME PARLAY + EXOTIC wagers + props + fut
- Update-pipeline + impact assessment
- Brazil + international market readiness
- AI + crypto + esports + DFS readiness
- RG advertising compliance
- Pipeline not tracked
- International readiness gap
- AI + crypto + DFS readiness gap
- RG advertising violations
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GLI-33 - Gaming Laboratories International Event Wagering Systems framework page.