Skip to content

Evidence request lists

GLI-33 - Gaming Laboratories International Event Wagering Systems

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

GLI-33: Audit, Significant Event Logging, Information Security, Change Control, Resilience

GLI33-Audit-Logging-InfoSec-ChangeControl
GLI-33 Audit, Significant Event Logging, Information Security, Change Control, Resilience

GLI-33 audit + logging + security + change + resilience. SIGNIFICANT EVENT LOGGING: every regulatorily significant event must be logged with timestamp (regulator-time-source-synced typically via NTP + Stratum-1) + actor + action + outcome + correlated session/wager/transaction; events include logon + logoff + admin actions + wager-acceptance/rejection + settlement + payout + change-control + system-start + system-stop + parameter-change + security-event + integrity-event + responsible-gaming-event + AML-event + KYC-failure + geolocation-failure; logs IMMUTABLE (write-once or signed/hashed) + retained per state regulator (typically 5 years) + accessible to regulator on demand. INFORMATION SECURITY: typically per GLI-27 (Standards for Network Security) + ISO 27001 + NIST CSF; specific GLI-33 requirements include (a) encryption at rest + in transit (TLS 1.2+ + AES-256); (b) access control (

Artefacts an auditor will ask for
  • Significant event log + retention
  • InfoSec program + pentest
  • Change-mgmt + signature verification
  • DR/BCP plan + annual test
Where this commonly fails
  • Significant event logging gaps
  • Pentest cadence inadequate
  • Change-mgmt + signature not enforced
  • DR/BCP not tested

GLI-33: Event Wagering System Architecture, Wager Engine, Transaction Integrity

GLI33-EventWagering-System-Architecture
GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management

GLI-33 Event Wagering System architecture + wager engine + odds + risk. SYSTEM ARCHITECTURE: components include (a) presentation tier (web + mobile apps + retail kiosks + sportsbook lounge terminals); (b) wager acceptance + engine tier (wager validation + odds lookup + limit checks + risk-engine routing); (c) settlement + ledger tier (post-event settlement + account credit + audit); (d) reporting + integrity-monitoring tier; (e) data feeds from sports data providers (typically Sportradar + Genius Sports + IMG Arena + Stats Perform + others); (f) PAM (Player Account Management) integration; (g) payment processor + AML integration; (h) geolocation provider integration; (i) regulatory reporting endpoint. WAGER ENGINE: wager types (single + parlay + teaser + futures + props + live/in-play + same-game parlay + round-robin + box + half-time + period + multi-state); wager validation includes pl

Artefacts an auditor will ask for
  • Architecture documentation
  • Wager log + transaction immutability
  • Odds-engine + risk-engine procedures
Where this commonly fails
  • Architecture gaps
  • Wager log integrity not enforced
  • Odds-change policy missing

GLI-33: Geolocation, Mobile Wagering, Internet Wagering, Session Management, Security

GLI33-Geolocation-Mobile-Internet-Wagering
GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management

GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary; typical implementation uses third-party geolocation provider (GeoComply + Xpoint + Locator-X + IDology Position + others - often GLI-19 certified separately); verification methods include GPS + Wi-Fi triangulation + cell tower + IP + LBS + device sensors + spoof detection (VPN + proxy + emulator + jailbreak + GPS spoofing); CONTINUOUS RE-VERIFICATION typically every 5-15 minutes during active session + at every wager submission; FAILED VERIFICATION must block wager + may suspend session. MOBILE WAGERING SECURITY: app distribution via App Store + Google Play with regulator-approved hash + integrity check + jailbreak/root-detection + emulator-detect

Artefacts an auditor will ask for
  • Geolocation provider + spoof-detection
  • Mobile app integrity + binding
  • Web security + WAF + bot-protection
  • Session policy + MFA
Where this commonly fails
  • Geo-verification gaps
  • Mobile integrity weak
  • Bot-detection absent
  • Session timeouts inadequate

GLI-33: Player Account Management, Identity Verification, KYC, AML, Payments

GLI33-PAM-KYC-AML-Payments
GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle

GLI-33 Player Account Management (PAM) + KYC + AML + payments. PAM REQUIREMENTS: (a) account registration with identity verification + age verification (18+ or 21+ depending on state) + jurisdictional eligibility; (b) account funding via approved payment instruments (debit card + ACH + bank transfer + wire + e-wallet + cash kiosk + sometimes credit card depending on state); (c) account balance ledger + transaction history + audit log; (d) deposit/withdrawal limits + responsible-gaming limits + self-exclusion enforcement; (e) account closure + dormancy + reactivation procedures; (f) one-account-per-player enforcement + duplicate-account detection; (g) authorized-user-only access (no shared accounts); (h) cooling-off + temporary-exclusion + permanent-exclusion features. KYC: typically minimum (a) name + DOB + SSN-last-4 (US) or full national ID + address + email + phone + government-ID doc

Artefacts an auditor will ask for
  • PAM platform + KYC vendor
  • AML program + SAR procedures
  • PCI DSS compliance for payment
  • Crypto-funding policy
Where this commonly fails
  • KYC vendor gaps
  • AML SAR procedures missing
  • PCI DSS lapses
  • Crypto-funding policy absent

GLI-33: Responsible Gaming, Self-Exclusion, Integrity Monitoring, Anti-Fraud, Collusion

GLI33-ResponsibleGaming-Integrity-AntiFraud
GLI-33 Responsible Gaming, Self-Exclusion, Integrity Monitoring, Anti-Fraud and Collusion Detection

GLI-33 responsible gaming + integrity + anti-fraud. RESPONSIBLE GAMING (RG): MANDATORY FEATURES including (a) deposit limits (daily + weekly + monthly + per-transaction); (b) wager limits + loss limits; (c) session-time limits + cool-off periods; (d) self-exclusion (typically 1 year + 5 year + permanent + irrevocable for some periods); (e) reality-check pop-ups during session; (f) age-verification + minor-account-prevention; (g) account-suspension on responsible-gaming-flagged behavior; (h) RG resources (problem-gambling-helpline + counseling links + state-specific). SELF-EXCLUSION REGISTRY INTEGRATION: state-regulator-maintained self-exclusion lists (e.g. New Jersey + Pennsylvania + Illinois multi-state) + national NCPG + GamStop UK + others; pre-wager check + ongoing-sweep + cross-operator-coordination; account-blocking + funds-return procedures + no-promotional-contact. INTEGRITY MONI

Artefacts an auditor will ask for
  • RG features + limits + self-exclusion
  • Self-exclusion registry sync + audit
  • Integrity alerts + integrity-officer
  • ML anomaly detection + investigation
Where this commonly fails
  • RG features absent
  • Self-exclusion gaps
  • Integrity alerts not actioned
  • Anti-fraud weak
GLI33-Sports-Integrity-DataProviders-Compliance
GLI-33 Sports Event Data Integrity, Provider Certification and Regulatory Reporting

GLI-33 sports event data + provider certification + regulatory reporting. SPORTS EVENT DATA INTEGRITY: source-of-truth for events (start time + end time + scores + outcomes + voiding events + abandonment + suspension + result-correction); typically OFFICIAL DATA from leagues (NFL + MLB + NBA + NHL + MLS + UEFA + FIFA + ATP + WTA + NASCAR + etc.) or regulator-approved data providers (Sportradar Official + Genius Sports + IMG Arena + Stats Perform + Lowy Solutions); 'OFFICIAL LEAGUE DATA' mandates in some states (Illinois + Tennessee + Michigan + Maryland + Virginia + DC + Connecticut + others) require purchase of official data from leagues for certain bet types (in-play + props + same-game parlay). DATA-FEED INTEGRITY: redundant feeds + reconciliation + dispute resolution; suspended-event handling; under-protest result handling; bet-voiding policies; settlement timing windows + delayed se

Artefacts an auditor will ask for
  • Data-provider contracts + redundancy
  • Official-data evidence per state
  • Regulatory report templates + filing
  • AML SAR + tax reporting
Where this commonly fails
  • Data-provider gaps
  • Official-data not used (where required)
  • Regulatory reports missing
  • AML SAR + tax filings late

GLI-33: Standard Scope, GLI Certification Model and Coordination with GLI-19, GLI-21, GLI-27

GLI33-Scope-GLI-CertModel
GLI-33 Scope, Gaming Laboratories International Certification Model, GLI-19/21/27 Coordination

GLI-33 Standards for Event Wagering Systems scope + GLI certification model. SCOPE: event wagering systems (sports betting + fixed-odds wagering + pool wagering + pari-mutuel wagering + fantasy sports + in-play wagering + same-game parlays + futures + props + esports + emerging variants). EVENT WAGERING SYSTEM defined as the suite of components (hardware + software + procedures + networks + interfaces) used by a regulated operator to (a) accept wagers from authenticated players; (b) compute settlements; (c) maintain player balances; (d) issue payouts; (e) report to regulators; (f) integrity-monitor + anti-fraud-detect. GLI CERTIFICATION MODEL: GLI is an INDEPENDENT testing laboratory (ISO/IEC 17025 + ISO 9001 + A2LA accredited) - tests against the standard + issues certification report to operator + state regulator; certifications typically valid for 1-3 years + require re-certification

Artefacts an auditor will ask for
  • Certification + scope documentation
  • GLI family alignment evidence
  • Certification report retention
Where this commonly fails
  • Scope unclear
  • Multi-standard coordination gaps
  • Certification report missing

GLI-33: State Regulator Adoption, Certification Lifecycle, 2024-2025 Update Pipeline and Coordination

GLI33-CertificationLifecycle-OngoingAudit
GLI-33 Certification Lifecycle, Annual Audit, Re-Testing on Change

GLI-33 certification lifecycle + audit. CERTIFICATION LIFECYCLE: (a) INITIAL CERTIFICATION - operator submits system + documentation + test data + scoping document to GLI (or other accredited testing laboratory - e.g. BMM Testlabs + Eclipse Compliance Testing + iTech Labs + Quinel + others); GLI conducts source code review + functional testing + security testing + load testing + integration testing; typically 6-12 weeks + scope-dependent; report issued + signed off by state regulator; (b) ONGOING SURVEILLANCE - annual or biennial review + sample-testing + integrity-monitoring; regulator-driven; (c) RE-TESTING ON CHANGE - software changes triggering 'material' scope require re-testing + new certification report; emergency-change handling; change-management notifications; (d) DECOMMISSIONING - data retention + customer-account-transition + regulator-notification. AUDIT FREQUENCY: typically

Artefacts an auditor will ask for
  • Certification + audit reports
  • Change-mgmt procedure + re-cert evidence
  • SOC 2 + ISO 27001 reports
  • Licensing + bond + insurance
Where this commonly fails
  • Certification gaps
  • Change-mgmt re-cert gaps
  • SOC 2 + ISO 27001 missing
  • Licensing + financial obligations missed
GLI33-Crosswalk-PCI-NIST-ISO-StateStandards
GLI-33 Crosswalk to PCI DSS, NIST CSF, ISO 27001, State Technical Standards

GLI-33 crosswalk to adjacent standards + state-specific technical standards. PCI DSS (Payment Card Industry Data Security Standard) v4.0 - applies to card-not-present payments in event wagering systems; required for any operator handling cards directly; tokenization + scope-reduction common. NIST CSF 2.0 - voluntary cybersecurity framework + commonly used by US-based operators for governance + identify + protect + detect + respond + recover; coordinates with GLI-27 (Standards for Network Security) which is more prescriptive. ISO/IEC 27001:2022 (Information Security Management System) - commonly certified by larger operators alongside GLI-33 certification; auditors may map GLI-27 + GLI-33 controls to ISO 27001 Annex A controls + ISO 27002 implementation guidance. ISO/IEC 27017 (Cloud Security) + 27018 (Privacy in Cloud) + 27701 (Privacy Information Management) - applicable to cloud-hosted

Artefacts an auditor will ask for
  • Multi-framework certification
  • State technical standards filing
  • Integrity-monitoring participation
  • Multi-state privacy + AML compliance
Where this commonly fails
  • Multi-framework alignment gaps
  • State technical standards filing gaps
  • Integrity participation gaps
  • Multi-state compliance issues
GLI33-Implementation-Roadmap-Roles-Tooling
GLI-33 Implementation Roadmap, Organizational Roles, Tooling and Metrics

GLI-33 implementation roadmap. ROLES: (a) HEAD OF COMPLIANCE or CHIEF COMPLIANCE OFFICER (CCO) - strategic regulator-relationship + multi-state + multi-jurisdiction; (b) HEAD OF SPORTS BOOK + RISK MANAGEMENT + ODDS - operational platform ownership; (c) HEAD OF PLAYER ACCOUNT MANAGEMENT (PAM) + KYC + AML - customer lifecycle; (d) INTEGRITY OFFICER - integrity-monitoring + alerts + sports-leagues coordination; (e) CISO + SECURITY ENGINEERING - InfoSec + GLI-27 + PCI DSS + ISO 27001; (f) DATA-PROTECTION OFFICER (DPO) - state privacy + customer-data; (g) RESPONSIBLE GAMING OFFICER - RG features + problem-gambling-prevention + self-exclusion-registry liaison; (h) RG VENDOR PROGRAM MANAGER - third-party RG technology (deposit-limits + self-exclusion + reality-check); (i) AUDIT + INTERNAL AUDIT - certification audit-readiness; (j) HEAD OF MARKETING + ADVERTISING - state-specific advertising com

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Tooling adoption + vendor list
  • Metrics + KPI dashboard
  • Annual cycle documentation
Where this commonly fails
  • Roles undefined
  • Tooling fragmented
  • Metrics gaps
  • Annual cycle ad-hoc
GLI33-StateRegulator-Adoption-Multistate
GLI-33 State Regulator Adoption, Multi-State Mobile, International Adoption

GLI-33 state regulator adoption + multi-state mobile. STATE ADOPTION (US): GLI-33 is commonly incorporated by reference by state gaming regulators including (a) NEW JERSEY DGE (Division of Gaming Enforcement) - Internet Gaming Technical Standards + sports wagering technical bulletins; (b) NEVADA GCB (Gaming Control Board) - Regulation 5 + Internet wagering + 2018 SCOTUS Murphy v NCAA legalisation; (c) PENNSYLVANIA PGCB - Sports Wagering Technical Standards; (d) MICHIGAN MGCB - online wagering + Sports Betting Act; (e) INDIANA IGC - Sports Wagering Rules; (f) ILLINOIS IGB - Sports Wagering Act; (g) IOWA IRGC; (h) TENNESSEE TSGC - Tennessee Sports Wagering Council + Sports Betting Act + Sports Betting Council 2021 transition; (i) MASSACHUSETTS MGC - Sports Wagering Act 2022 effective 2023; (j) COLORADO DOR; (k) ARIZONA ADG; (l) VIRGINIA VLOG; (m) MARYLAND LCC; (n) DC OLG; (o) CONNECTICUT D

Artefacts an auditor will ask for
  • State-by-state certification per regulator
  • Multi-state legal-opinion + tech-architecture
  • International market entry compliance
  • Tribal compact compliance
Where this commonly fails
  • State adoption fragmented
  • Multi-state legal issues
  • International expansion gaps
  • Tribal compact gaps
GLI33-Status-2024-2025-Pipeline-Brazil-AI
GLI-33 2024-2025 Update Pipeline, Brazil Market Entry, AI Anti-Fraud, Cryptocurrency

GLI-33 2024-2025 status + update pipeline + global market. UPDATE PIPELINE: GLI continues to maintain + update GLI-33 reflecting industry evolution; emerging update areas include (a) IN-PLAY WAGERING + MICRO-BETTING (every play + every pitch + every possession) + same-game parlay + cash-out + edit-bet features; (b) CROSS-PLATFORM + OMNICHANNEL retail + mobile + web + in-venue kiosk + sports lounge interoperability; (c) AI/ML INTEGRATION - odds-making + risk-engine + responsible-gaming-detection + integrity-monitoring + anti-fraud + customer-experience; (d) CRYPTOCURRENCY-FUNDED ACCOUNTS - increasing operator + regulator attention to crypto deposits + withdrawals + wallet-integration + tax-reporting + AML implications; (e) FANTASY + ESPORTS + DFS - daily fantasy sports + esports wagering + skill-game variants requiring distinct framework; (f) SAME-GAME PARLAY + EXOTIC wagers + props + fut

Artefacts an auditor will ask for
  • Update-pipeline + impact assessment
  • Brazil + international market readiness
  • AI + crypto + esports + DFS readiness
  • RG advertising compliance
Where this commonly fails
  • Pipeline not tracked
  • International readiness gap
  • AI + crypto + DFS readiness gap
  • RG advertising violations
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GLI-33 - Gaming Laboratories International Event Wagering Systems framework page.