UK Gambling Commission - Cyber Resilience Requirements
Evidence request list. 9 controls, 9 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Customer Protection
Per LCCP + AML: customer protection including AML + sanctions + safer gambling.
- Gambling evidence for UKGAMBLE-5
- RTS + safer gambling partial
InfoSec
Per RTS 4.x: Information security policies + Security event reporting + integrate with ISO 27001.
- Gambling evidence for UKGAMBLE-2
- RTS + safer gambling partial
Resilience
Per RTS: business continuity + DR + incident response + Gambling Commission reporting.
- Gambling evidence for UKGAMBLE-4
- RTS + safer gambling partial
Scope
Per UK Gambling Commission RTS + LCCP: Scope of technical standards + Critical systems definition + Applicability to licensees.
- Gambling evidence for UKGAMBLE-1
- RTS + safer gambling partial
Technical
Per RTS: access control + cryptography + network security + endpoint + monitoring + logging.
- Gambling evidence for UKGAMBLE-3
- RTS + safer gambling partial
UKGC Remote Technical Standards: Annual Security Audit
Licensees must undergo an annual security audit by an independent qualified auditor.
- Third party inventory with risk tier
- Due diligence questionnaires and findings
- Contract clauses including audit rights
- Ongoing monitoring evidence per tier
- Inventory missing fourth parties
- High risk tier vendors lacking onsite review
- Right to audit clauses absent
- Termination and data return clauses weak
The audit must cover sections of ISO/IEC 27001:2022 Annex A relevant to gambling operations.
- Audit plan covering audit scope aligned with iso 27001
- Working papers and evidence index
- Findings register with remediation owners
- Closure verification reports
- Findings remediation overdue
- Scope coverage gaps year over year
- Independence of reviewer not documented
- No tracking of repeat findings
Audit reports must be submitted to the Commission within 7 days if requested or if major non-conformities found.
- Audit plan covering submission of audit reports
- Working papers and evidence index
- Findings register with remediation owners
- Closure verification reports
- Findings remediation overdue
- Scope coverage gaps year over year
- Independence of reviewer not documented
- No tracking of repeat findings
Newly licensed operators must complete their first audit within six months of licence grant.
- Audit plan covering new licensee initial audit
- Working papers and evidence index
- Findings register with remediation owners
- Closure verification reports
- Findings remediation overdue
- Scope coverage gaps year over year
- Independence of reviewer not documented
- No tracking of repeat findings
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Gambling Commission - Cyber Resilience Requirements framework page.