Skip to content

Evidence request lists

UK Gambling Commission - Cyber Resilience Requirements

Evidence request list. 9 controls, 9 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Customer Protection

UKGAMBLE-5
Customer Protection and Anti-Money Laundering

Per LCCP + AML: customer protection including AML + sanctions + safer gambling.

Artefacts an auditor will ask for
  • Gambling evidence for UKGAMBLE-5
Where this commonly fails
  • RTS + safer gambling partial

InfoSec

UKGAMBLE-2
Information Security Management

Per RTS 4.x: Information security policies + Security event reporting + integrate with ISO 27001.

Artefacts an auditor will ask for
  • Gambling evidence for UKGAMBLE-2
Where this commonly fails
  • RTS + safer gambling partial

Resilience

UKGAMBLE-4
Resilience and Incident Response

Per RTS: business continuity + DR + incident response + Gambling Commission reporting.

Artefacts an auditor will ask for
  • Gambling evidence for UKGAMBLE-4
Where this commonly fails
  • RTS + safer gambling partial

Scope

UKGAMBLE-1
Scope and Applicability to Licensees

Per UK Gambling Commission RTS + LCCP: Scope of technical standards + Critical systems definition + Applicability to licensees.

Artefacts an auditor will ask for
  • Gambling evidence for UKGAMBLE-1
Where this commonly fails
  • RTS + safer gambling partial

Technical

UKGAMBLE-3
Technical Security Controls

Per RTS: access control + cryptography + network security + endpoint + monitoring + logging.

Artefacts an auditor will ask for
  • Gambling evidence for UKGAMBLE-3
Where this commonly fails
  • RTS + safer gambling partial

UKGC Remote Technical Standards: Annual Security Audit

RTS Audit-1
Third-party annual security audit

Licensees must undergo an annual security audit by an independent qualified auditor.

Artefacts an auditor will ask for
  • Third party inventory with risk tier
  • Due diligence questionnaires and findings
  • Contract clauses including audit rights
  • Ongoing monitoring evidence per tier
Where this commonly fails
  • Inventory missing fourth parties
  • High risk tier vendors lacking onsite review
  • Right to audit clauses absent
  • Termination and data return clauses weak
RTS Audit-2
Audit scope aligned with ISO 27001

The audit must cover sections of ISO/IEC 27001:2022 Annex A relevant to gambling operations.

Artefacts an auditor will ask for
  • Audit plan covering audit scope aligned with iso 27001
  • Working papers and evidence index
  • Findings register with remediation owners
  • Closure verification reports
Where this commonly fails
  • Findings remediation overdue
  • Scope coverage gaps year over year
  • Independence of reviewer not documented
  • No tracking of repeat findings
RTS Audit-3
Submission of audit reports

Audit reports must be submitted to the Commission within 7 days if requested or if major non-conformities found.

Artefacts an auditor will ask for
  • Audit plan covering submission of audit reports
  • Working papers and evidence index
  • Findings register with remediation owners
  • Closure verification reports
Where this commonly fails
  • Findings remediation overdue
  • Scope coverage gaps year over year
  • Independence of reviewer not documented
  • No tracking of repeat findings
RTS Audit-4
New licensee initial audit

Newly licensed operators must complete their first audit within six months of licence grant.

Artefacts an auditor will ask for
  • Audit plan covering new licensee initial audit
  • Working papers and evidence index
  • Findings register with remediation owners
  • Closure verification reports
Where this commonly fails
  • Findings remediation overdue
  • Scope coverage gaps year over year
  • Independence of reviewer not documented
  • No tracking of repeat findings
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Gambling Commission - Cyber Resilience Requirements framework page.