Online Gambling License
A source-reviewed framework for operator and supplier permissions, applicant entities, ownership, application evidence, conditions, variations and surrender.
An online gambling license is permission granted to a named legal person—or, where the authority expressly permits it, a defined group of legal persons—for defined activities under that authority's rules. It is not a product badge, a general sign of quality, or a passport into countries that did not issue or recognize it. The useful licensing question is exact: which entity or covered group member may perform which B2C or B2B activity, for which players, products, brands, domains, channels, systems, and suppliers on the proposed launch date?
This guide explains how to choose an application route and prepare the licensing file. It uses current official material from Great Britain, Malta, Denmark, and the Netherlands to show how operator and supplier roles differ, then keeps those examples separate from the checks required in every target jurisdiction. It does not rank licenses or publish universal prices, application times, or market-access claims because none of those can be stated honestly without the exact route and facts.
By the end, you should have a market and activity memo, applicant and ownership record, key-person map, funding evidence, a consistent application pack, technical and supplier diagrams, testing evidence, an obligations calendar, and a formal change and exit procedure. Any unresolved point stays open until the responsible authority or counterparty supplies the required evidence.
Use the separate gambling-laws-by-country guide for country-by-country legality and market access. Use the start-casino or start-sportsbook guide for vendor selection, system design, production controls, and launch. This page stays focused on the authorization route, application evidence, decision, conditions, changes, and formal license status.
- + Start with player location, product, channel, and regulated activity; do not start by shopping for a jurisdiction.
- + Separate the consumer-facing operator from software, game, host, platform, and other supplier roles before choosing an application route.
- + Identify every applicant and covered licensee entity that will perform regulated activity, then disclose ownership, control, funding, directors, and required key people at the jurisdiction's current scope.
- + Treat an application acknowledgment, portal status, invoice, certificate image, or private register entry as evidence of that narrow status only, not as an issued authorization.
- + Bind system diagrams, suppliers, test reports, policies, payment routes, and data roles to the production configuration the applicant intends to operate.
- + Keep regulator payment disclosures, player-funds treatment, AML controls, privacy, and card-data security as separate evidence streams; license issue closes only the applicable regulator decision.
- + Turn every license condition, report, notification, personal approval, supplier duty, and tested build into an owned operating control after issue.
- + Plan variations, ownership and control changes, surrender, lapse, register updates, and any locally applicable customer or liability steps before launch.
Use the right guide for the next question
These adjacent topics stay on separate pages so licensing, country law, procurement, and launch decisions do not blur together.
Define the market, product, and regulated activity
Freeze the customer and product facts before selecting a license route. Record where the player will be located at registration and play, which entity will contract with that player, the products and bet or game mechanics, the channel, brands and domains, payment flow, equipment locations, marketing route, and every third party that can perform a regulated function. Incorporation and server location are inputs, not shortcuts around the target market's rules.
Jurisdiction boundaries are real. The European Commission's case-law overview states that there is no EU obligation to recognize a gambling authorization issued by another EU country. Great Britain separately requires a Commission license for a foreign business that provides remote gambling facilities to British consumers. Those examples establish why a home-base license cannot be treated as permission to target another country.
| Decision | Question to answer | Required record |
|---|---|---|
| Player marketEU gambling case-law overviewRemote sector guidance | Where is the customer located, and what facts count as offering or targeting the product there? | Accepted, blocked, and conditional territory matrix with a legal owner and recheck trigger. |
| Product and channelRemote sector guidanceWhat types of licenses are available? | Casino, betting, poker, bingo, lottery, exchange, virtual event, live product, or another local category, delivered through which web, app, telephone, retail, or embedded path? | Product and channel register mapped to the exact activity the authority regulates. |
| Legal partiesRemote gambling software licenseGame supplierRemote gambling license questions and answers | Who contracts with the player, supplies software or games, hosts facilities, holds money, makes compliance decisions, and controls data? | Entity-by-activity matrix using registered legal names, contract roles, and current status. |
| Authorization statusPublic RegisterGuidance Note: Application Process | Is the activity unfiled, being prepared, submitted, incomplete, pending, issued, conditioned, suspended, surrendered, or otherwise limited? | Authority correspondence and current official register or decision record without upgrading the status in internal or public copy. |
One jurisdiction never answers another jurisdiction's question
An issued license establishes only the activities, entity, conditions, territory, and status granted under that authority's framework. Re-run the market analysis for every place in which players are located or targeted and for every regulated supplier role in the chain.
Separate the B2C operator from every B2B supplier
B2C and B2B are responsibility boundaries, not just sales labels. A B2C operator normally provides the regulated gambling service to the customer. A B2B supplier may provide games, software, a control system, hosting, or another material function. Whether that supplier needs its own permission, what the permission is called, and what remains with the operator differ by jurisdiction and activity.
Do not infer the answer from a group structure or bundle. The same company group can contain a consumer operator, software owner, game supplier, payment company, and service entity, while a white-label contract can add another brand without moving the regulator-facing responsibility. Map each legal person and activity separately, then confirm how the relevant authority classifies the actual production setup.
| Jurisdiction example | Consumer-facing role | Supplier role | Procurement consequence |
|---|---|---|---|
| Great BritainRemote sector guidanceRemote gambling software license | Activity-specific remote operating permissions cover providing gambling facilities to British consumers. | Manufacturing, supplying, installing, or adapting remote gambling software is a separate software activity; hosting can create another operating role. | Verify the operator, software supplier, host, activity, domains, and current register status separately. |
| MaltaWhat types of licenses are available?Who can apply for a licence? | The Gaming Service license is the B2C category for offering or carrying out a gaming service. | The Critical Gaming Supply license is the B2B category for material game elements or software and control systems that process essential regulatory records. | Classify the product and data function, then decide whether the applicant uses the standalone or Malta-specific corporate-group route and record every covered entity and the nominal holder. |
| DenmarkGame supplier | The customer-facing operator needs the relevant Danish betting or online-casino permission. | A game-supplier license covers supplying games and services that operate and settle bets to licensed operators. | An operator permission does not replace the in-scope supplier permission, and the supplier permission can be used only with licensed Danish operators. |
| NetherlandsRemote gambling license questions and answers | Only the provider of online games of chance applies for the Dutch Koa operator permission. | The Ksa states that it does not issue Koa permissions to B2B companies such as software developers, while the licensed operator remains responsible for outsourced operations addressed by the framework. | Do not invent a Dutch Koa supplier license, but do contract for operator access, oversight, data, testing, and regulator inspection rights where required. |
White label does not rewrite public law
In Great Britain, the Commission states that responsibility for operating white-label sites remains with the license holder and cannot be transferred. Apply that statement only to the British framework; elsewhere, identify the host, operator, brand, player counterparty, merchant, data roles, and local rule from primary sources.
Define the applicant, covered entities, owners, and key people
Identify the legal entity applying and every legal person expected to perform licensed activity. Do not assume every framework is a single-company route. The MGA states that a corporate applicant may apply for itself or for its corporate group; under the group route, each covered member is deemed a licensee and the members are jointly and severally responsible. That is a Malta-specific option, not a general group passport. In every route, build the corporate record from each in-scope entity to its direct and indirect owners and ultimate natural-person controllers, and map the group companies that supply funding, software, people, intellectual property, or regulated services.
Ownership percentages and personal-approval triggers are jurisdiction-specific. Current Great Britain application guidance requires its own named ownership and controller disclosures, while Malta's application guidance requires personal declarations from UBOs, directors, and key people and examines shareholders, UBOs, relevant key people, source of funds, and source of wealth. Those examples are useful file-design inputs, not thresholds to copy into another application.
Key roles must be real operating roles. Great Britain's PML guidance covers specified senior responsibilities such as overall management, gambling operations, finance, compliance, gambling IT and security, and responsibility for the licensee's anti-money-laundering and counter-terrorist-financing measures, subject to the framework's exceptions. A nominee on paper is not a substitute for a competent person with authority, time, access, and evidence of the decisions they own.
- 1Confirm the applicant and covered entities
Match the applicant, every proposed covered entity, constitutional powers, addresses, contracts, people, and production activity to the license category and market memo. If a group route is used, record its eligibility, covered members, nominal holder, reporting responsibility, and liability model.
Sources:What you need to send us when you apply for an operating licenseWho can apply for a licence?Guidance Note: Application ProcessMalta Gaming Authority Fact Sheets 2025 - 2Trace ownership and control to natural persons
Record every direct and indirect holding, voting right, controller, trust role, nominee, option, loan, and other control path, then apply the authority's current disclosure and personal-filing rules.
Sources:What you need to send us when you apply for an operating licenseGuidance Note: Application ProcessThe FATF Recommendations, as amended June 2026 - 3Build the funding evidence chain
Reconcile source of wealth, source of application and operating funds, loan and investment agreements, bank movement, forecasts, and ownership records without treating a bank transfer as proof of the underlying source.
Sources:What you need to send us when you apply for an operating licenseGuidance Note: Application ProcessMalta Gaming Authority Fact Sheets 2025 - 4Assign required key roles
Name the person, public approval or filing route, employment or service relationship, authority, conflicts, deputies, access, reporting line, and evidence owned for every key function.
Sources:Personal Management License guideGuidance Note: Application ProcessMalta Gaming Authority Fact Sheets 2025
Use current local thresholds
Great Britain and Malta publish different ownership and personal-declaration mechanics. Never turn an example percentage, role name, or filing document into a universal UBO or key-person rule.
Assemble a consistent application file
A good application file describes one business consistently across corporate documents, funding, forecasts, policies, contracts, systems, people, markets, and products. The Great Britain supporting-document guidance asks remote applicants for an operational model showing system and activity providers, equipment locations, third parties, and system relationships. The MGA process reviews applicant suitability, funding, business viability, policies, technical documentation, implementation, and a staged system audit. The exact forms differ, but both examples expose the same failure mode: a narrative that does not match the real production chain.
Control the file at field level. Give every statement an owner, source, date, entity, jurisdiction, document version, translation status, and update trigger. Resolve contradictions before submission. A regulator request for clarification should update the master record and every affected attachment, not create an isolated answer that conflicts with the business plan or system diagram.
| Workstream | Minimum controlled content | Consistency test |
|---|---|---|
| Activity and market scopeRemote sector guidanceGuidance Note: Application Process | Applicant, license activity, products, channels, player locations, brands, domains, equipment, suppliers, and intended launch configuration. | Every public offer and production path fits the applied-for activity and the target-market memo. |
| Corporate and personal fileWhat you need to send us when you apply for an operating licensePersonal Management License guideGuidance Note: Application Process | Constitution, group and ownership charts, controllers, directors, key people, personal declarations, history, conflicts, and supporting records. | Names, percentages, control rights, roles, addresses, dates, and personal filings agree across every document. |
| Funding and business planWhat you need to send us when you apply for an operating licenseGuidance Note: Application Process | Source of wealth and funds, investment and loan agreements, bank evidence, forecasts, assumptions, capital, products, markets, staffing, distribution, and downside cases. | Cash movement and legal agreements reconcile to the ownership record and the operating plan can fund the stated obligations. |
| Policies and decision flowsWhat you need to send us when you apply for an operating licenseOnline License Conditions and Codes of Practice | AML, player protection, complaints, fair and open play, supplier oversight, security, privacy, incidents, records, changes, and other route-specific controls. | Each policy names the real system, data, people, thresholds, approvals, evidence, escalation, and fallback used in production. |
| Technical and supplier modelWhat you need to send us when you apply for an operating licenseGuidance Note: Application Process | End-to-end registration, gambling, wallet, payment, withdrawal, reporting, data, hosting, equipment, software, game, and manual-operation diagrams. | The diagram agrees with contracts, data schedules, supplier status, test scope, staging, and the release candidate. |
Attach system, supplier, and testing evidence
The application, supplier records, and technical assurance must describe the same proposed system. Record the software and game suppliers, legal entities, regulated functions, versions, hosting and equipment locations, material data flows, and staged configuration at the level the selected authority requires. Then map each item to the local supplier-permission, testing, audit, submission, and change rule. A group-level supplier claim or unscoped test badge is not application evidence.
The examples differ. Great Britain's current remote technical standards apply to covered remote operating and gambling-software licensees, while its testing strategy defines which remote products need particular testing and when independent assurance is required. Malta's application process includes technical-document review and a system audit of the staged environment against submitted policies and procedures. Denmark separately licenses in-scope game suppliers. None of those examples establishes the test or supplier rule in another market.
| Evidence item | Scope to record | What it does not prove |
|---|---|---|
| Supplier authorizationRemote gambling software licenseGame supplier | Legal supplier, activity, product, market, status, conditions, effective dates, and production contract route. | Consumer-operator permission, every product in the supplier catalog, or acceptance in another jurisdiction. |
| Technical standardRemote gambling and software technical standards | Authority, license activity, standard and version, system and feature scope, effective date, and known exclusions. | Conformance of an untested build, third-party system, payment flow, operating procedure, or market outside the standard. |
| Test report or certificateTesting strategy for compliance with remote gambling and software technical standards | Test house, legal customer, product and build, platform and RNG dependencies, environment, methods, results, limitations, date, and submission status. | Every later version, integration, configuration, game, security control, or the complete operator setup. |
| System auditGuidance Note: Application Process | Applicant, staged environment, submitted policies and procedures, systems reviewed, auditor, findings, corrections, and final decision record. | A future production change, outside supplier, payment approval, data-law conclusion, or another authority's acceptance. |
Attach money-flow, AML, and player-funds evidence
Keep the regulator-facing money flow precise. Record which applicant or covered entity receives and holds player money, the bank and payment providers and accounts represented in the application, the path from deposit through gambling to payout, the applicable player-funds treatment, reconciliation ownership, and any approval or notification required when that setup changes. This is licensing evidence; it is not proof of a separate payment counterparty's commercial acceptance or of payment-data security.
Use the applicable rule for AML and player funds. FATF provides an international risk-based standard covering customer and beneficial-owner due diligence, ongoing monitoring, records, and related controls, but jurisdictions implement it through their own law. Malta's current reporting page gives a concrete license-specific example: it distinguishes B2B compliance reports and requires player-funds reporting from B2Cs and B2Bs that manage pooled jackpots. That is not a universal reporting template.
| Application file | Licensing question | Evidence boundary |
|---|---|---|
| Regulator-facing payment routeWhat you need to send us when you apply for an operating licenseReporting Requirements | Which applicant or covered entity receives and holds money, which providers and accounts appear in the approved model, and what changes, reconciliations, or player-funds reports apply? | Application and decision record, end-to-end money-flow diagram, provider and account references, applicable approval or notification, ledger mapping, and reconciliations. |
| Player and jackpot fundsReporting Requirements | Which balances fall into the applicable local category, where are they held, who controls them, how are they reconciled, and what must be reported or disclosed? | Local legal analysis, account and ledger evidence, reports, supporting statements, exception ownership, and insolvency or exit treatment. |
| AML and financial crimeThe FATF Recommendations, as amended June 2026 | Which entity owns risk assessment, CDD, beneficial-owner checks, screening, source review, ongoing monitoring, investigation, reporting, and records? | Current local policy, data and rule inventory, complete cases, approvals, quality review, reports, and audit trail. |
Keep the regulator decision narrow
License issue answers the authority's licensing question. It does not replace separate payment-counterparty, privacy, security, tax, or production-readiness decisions covered by the linked launch and provider guides.
Manage obligations after approval
License issue starts an operating obligation; it does not finish the project. Convert conditions, codes, approved activities, key people, supplier duties, technical standards, reports, notifications, funds rules, complaints, player protection, AML, and record requirements into a calendar and responsibility matrix. Attach each obligation to a source, applicable entity and activity, trigger, due event, system data, preparer, approver, evidence file, fallback, and escalation route.
Current public examples show why generic compliance calendars fail. Great Britain's LCCP version effective April 6, 2026 is divided among operating conditions, code provisions, and personal-license conditions across several subject areas. Malta publishes different reports and notifications for B2B and B2C licensees, player and jackpot funds, outsourcing, go-live, security incidents, and suspicious betting. The actual calendar must be rebuilt for the selected route and kept current after every rule or business change.
Outsourcing does not remove the license holder's need for control. In Great Britain, licensees remain responsible for contracted third parties involved in licensed activities, must obtain information needed for reporting, and must have termination rights tied to relevant breaches. Contracts should therefore provide access, audit, change approval, incident evidence, continuity, and exit rights that make regulator-facing oversight possible in practice.
- 1Create the obligations register
Record every condition, report, notification, fee event, approval, register check, test, audit, training, reconciliation, and retained record by entity and licensed activity.
Sources:Online License Conditions and Codes of PracticeReporting Requirements - 2Operate third-party oversight
Run due diligence, performance and compliance monitoring, sample review, access checks, incident escalation, change review, audit, and exit exercises for every material provider.
Sources:Licensees' responsibilities for third parties - 3Control people and corporate changes
Review ownership, funding, directors, key functions, group entities, products, markets, domains, suppliers, systems, and policies before a change is implemented or publicly announced.
Sources:Personal Management License guideGuidance Note: Application Process - 4Reconcile public and internal status
Compare the authority's register and decisions with internal systems, contracts, websites, apps, domains, license copy, key-person records, and supplier lists, then correct any mismatch.
Sources:Public Register
Read the decision, conditions, and effective scope
Submission, acceptance as complete, approval, issue, and effective permission are different statuses. Record only the status shown by the authority and do not describe an application acknowledgment, invoice, portal entry, successful audit, or draft document as an issued license. Once issued, read the complete decision, conditions, activities, covered entities, products or verticals, domains, personal approvals, effective dates, and any action still required.
Verify the issued status through the authority's register where one is available. The UKGC public register exposes business and activity detail, while the MGA application process includes technical review and a staged system audit and its reporting page separately describes a go-live declaration. Each record establishes its own scope. Production readiness is a separate operator decision covered in the start guides.
| Status | What it establishes | Evidence to retain |
|---|---|---|
| Submitted or under reviewGuidance Note: Application Process | The authority has received or is reviewing the application at the status it records; no permission is implied. | Dated application record, submission inventory, questions and responses, change log, and unresolved-item owner. |
| Issued authorizationRemote sector guidancePublic Register | The named holder or covered group has the stated activity and effective scope subject to the complete conditions and limitations. | Authority decision, complete license and conditions, current register check, and legal scope memo. |
| Open condition or pre-launch filingOnline License Conditions and Codes of PracticeGuidance Note: Application ProcessReporting Requirements | A required audit, declaration, supplier approval, personal approval, product approval, or other condition remains a separate open item until its own evidence is complete. | Condition owner, authority source, due trigger, submission, response, and the exact activity blocked while it remains open. |
Pending is not licensed, and licensed is not launch-ready
Keep application, issue, and launch as separate status fields with separate evidence and approvers. If a dependency is pending, describe it as pending and block the activity that depends on it.
Handle variations, surrender, and final status
A license is tied to facts that can change: ownership, control, funding, directors, key people, products, markets, domains, suppliers, equipment, systems, data locations, and policies. Put a licensing-impact review before each material change. The review should decide whether the change needs prior approval, a variation, notification, a new application, new personal filings, retesting, updated contracts, or a revised launch decision under the selected framework.
Business closure and formal surrender are also separate events. Current Great Britain guidance gives an active consumer-operator example covering customer communication, open or later-settling bets, customer funds, complaints and ADR access, registration cutoff, regulatory returns, and surrender. A B2B supplier, inactive license, insolvency event, partial surrender, or another jurisdiction may have a different process and no player-facing steps.
- 1Trigger change review before implementation
Compare the proposed corporate, product, market, people, supplier, technology, payment, and data change with the license, conditions, application record, testing, and notification calendar.
Sources:Online License Conditions and Codes of PracticeGuidance Note: Application Process - 2Identify applicable consumer obligations
For an active B2C operation, identify the selected framework's requirements for notices, registration and gambling cutoffs, funds, open activity, complaints, outstanding returns and records. Do not impose that checklist on a role with no players.
Sources:Closing a Gambling Commission licensed gambling businessReporting Requirements - 3Confirm formal status
Retain the authority's decision or acknowledgment where one is issued, record any status that occurs by operation of law, and verify that the official register, websites, apps, suppliers, payment partners, and internal systems no longer claim a broader permission.
Sources:Public RegisterClosing a Gambling Commission licensed gambling business
A surrender form answers only the license-status question
The filing does not by itself settle customer liabilities, outstanding returns, records, supplier contracts, payment relationships, or insolvency duties. Resolve the locally applicable items, then reconcile the authority record and every public license claim.
FAQ
Do gambling software and game suppliers need their own license?+
It depends on the jurisdiction and exact activity. Great Britain licenses specified remote gambling-software activity, Malta has a B2B Critical Gaming Supply category, and Denmark licenses suppliers of games and services that operate and settle bets for licensed operators. The Dutch Ksa states that it does not issue Koa operator permissions to B2B companies such as software developers. Classify the actual legal entity, product, control, contract, and market instead of assuming one global B2B rule.
Sources:Remote gambling software licenseWhat types of licenses are available?Game supplierRemote gambling license questions and answersDoes a white-label arrangement remove the need to map license responsibility?+
No. Identify the license holder, brand, player counterparty, merchant, funds holder, platform and game suppliers, data roles, and operating decisions. In Great Britain, the Commission states that responsibility for operating white-label sites stays with the license holder and cannot be transferred. That British rule should not be presented as the answer for another jurisdiction without checking its own framework.
Sources:Remote sector guidanceLicensees' responsibilities for third partiesWhich owners and managers must be disclosed?+
Use the selected authority's current rules. Great Britain publishes its own ownership, controller, trust, Annex A, and PML mechanics. Malta's application guidance covers shareholders, UBOs, directors, relevant key people, personal declarations, source of funds, and source of wealth; the MGA also permits an eligible corporate applicant to apply for itself or for a defined corporate group. Do not copy a percentage, group route, or role title from either jurisdiction into a different application.
Sources:What you need to send us when you apply for an operating licensePersonal Management License guideWho can apply for a licence?Guidance Note: Application ProcessThe FATF Recommendations, as amended June 2026Can an application be filed before the platform and suppliers are fixed?+
Only the authority's current process can answer what may remain provisional. The application still needs an accurate scope. Great Britain asks remote applicants for an operational model and named gambling-software suppliers, while the MGA process reviews technical documentation, implementation, and a staged system audit. If the platform, supplier, product, ownership, or market changes, update the authority and application record as required instead of assuming the first filing still describes the business.
Sources:What you need to send us when you apply for an operating licenseGuidance Note: Application ProcessDoes a game certificate or system audit prove that the operation can launch?+
No. Record the entity, product, build, platform and RNG dependencies, environment, standard, methods, limitations, date, findings, and submission status. Great Britain's testing strategy and Malta's system-audit stage each have defined scopes. Neither proves payment acceptance, data-law compliance, staffing, every supplier, market permission outside its framework, or the operator's complete production readiness.
Sources:Remote gambling and software technical standardsTesting strategy for compliance with remote gambling and software technical standardsGuidance Note: Application ProcessWhat application status can be described publicly?+
Use only the status the authority records. Preparing, submitted, incomplete, under review, and approved are different states, and none should be upgraded in public copy. After issue, retain the complete decision and conditions and verify the holder and activity in the official register where one is available.
Sources:Public RegisterGuidance Note: Application ProcessWhat continues after the license is issued?+
The operator or supplier must operate every applicable condition, report, notification, key-person duty, supplier control, test, player-funds rule, AML process, data obligation, complaint route, and change requirement. Great Britain's current LCCP and Malta's reporting pages illustrate different obligation sets. Build the control calendar from the selected license and current rules, not from this summary.
Sources:Licensees' responsibilities for third partiesOnline License Conditions and Codes of PracticeReporting RequirementsHow should an operator leave a licensed market?+
Treat operational closure and formal license status as separate questions. For an active B2C operation, identify the selected framework's applicable requirements for customer communication, gambling cutoffs, funds, open activity, complaints, returns and records. Retain the authority decision or acknowledgment where one is issued, record any status that occurs by law, and reconcile the official register and public claims. The detailed UKGC closure page is a Great Britain example, not a universal process.
Sources:Public RegisterClosing a Gambling Commission licensed gambling businessReporting RequirementsSources reviewed
A linked source establishes only the scope described in its note. It does not validate unrelated claims by the same publisher.
- government2026-07-12European Commission: EU gambling case-law overview
Current European Commission overview used for the EU-specific statement that gambling authorizations are not subject to mandatory mutual recognition. It does not decide a particular national application or non-EU market.
- regulator2026-07-12UK Gambling Commission: Remote sector guidance
Current Great Britain source for the consumer-location rule and activity-specific remote operator, host, software, betting, casino, bingo, and related routes. It does not cover Northern Ireland or another market.
- regulator2026-07-12UK Gambling Commission: Remote gambling software license
Current Great Britain source for manufacturing, supplying, installing, or adapting remote gambling software and for the separate host boundary. A software permission is not consumer-facing operating permission.
- regulator2026-07-12UK Gambling Commission: What you need to send us when you apply for an operating license
Current Great Britain supporting-document guidance used for ownership and control records, funding, policies, management, suppliers, operational maps, systems, and end-to-end flows. Its percentages and forms are not universal requirements.
- regulator2026-07-12UK Gambling Commission: Personal Management License guide
Updated July 6, 2026. Used for Great Britain key-management activities, application coordination with the operating license, suitability records, and the small-scale-operator boundary. It is not a global key-person list.
- regulator2026-07-12UK Gambling Commission: Licensees' responsibilities for third parties
Great Britain source for license-holder oversight of contracted parties, information and termination controls, and the nontransferable responsibility for operating white-label sites. Other jurisdictions require separate analysis.
- regulator2026-07-12UK Gambling Commission: Remote gambling and software technical standards
Current Great Britain technical-standard framework, updated for changes effective June 30, 2026. Used only to establish the technical and security scope for covered remote operator and software licensees.
- regulator2026-07-12UK Gambling Commission: Testing strategy for compliance with remote gambling and software technical standards
Current Great Britain strategy for the timing, scope, procedures, independent assurance, game and RNG reports, security audits, and change treatment of covered remote products. It is not a universal test rule or product approval.
- regulator2026-07-12UK Gambling Commission: Online License Conditions and Codes of Practice
Current online LCCP version effective April 6, 2026. Used to show the breadth of continuing Great Britain operating, code, and personal-license obligations, not to state another market's controls.
- official register2026-07-12UK Gambling Commission: Public Register
Official Great Britain register entry point for licensed businesses, individuals, and regulatory actions. A record must still be inspected for the correct entity, activity, status, dates, domains, and limitations.
- regulator2026-07-12UK Gambling Commission: Closing a Gambling Commission licensed gambling business
Updated January 15, 2026. Great Britain example for orderly closure, customer communication, open bets, funds, complaints, returns, contact, insolvency events, and surrender. Its suggested periods are intentionally not generalized here.
- regulator2026-07-12Malta Gaming Authority: What types of licenses are available?
Current Malta source distinguishing the B2C Gaming Service license from the B2B Critical Gaming Supply license for material game elements and essential regulatory-record systems.
- regulator2026-07-12Malta Gaming Authority: Who can apply for a licence?
Current Malta source for EU or EEA applicant eligibility and the option for a body corporate to apply for itself or for its corporate group. Under the group route, each covered member is deemed a licensee and the members are jointly and severally responsible; this is not generalized outside Malta.
- regulator2026-07-12Malta Gaming Authority: Guidance Note: Application Process
Official seven-page Malta guidance checked for B2B and B2C application stages, UBO, director and key-person declarations, fit and proper and funding review, business and policy review, technical setup, system audit, major application changes, and issue status. The PDF is dated February 2023 and must be read with current MGA instruments and portal requirements.
- regulator2026-07-12Malta Gaming Authority: Malta Gaming Authority Fact Sheets 2025
Official 2025 MGA fact sheet visually reviewed for the B2C Gaming Service and B2B Critical Gaming Supply boundary, UBO, director and key-person declarations, fit-and-proper and funding review, business-plan and policy review, technical setup, system audit, product types, and the application flow. It supplements rather than replaces the current detailed forms and instruments.
- regulator2026-07-12Malta Gaming Authority: Reporting Requirements
Current Malta source for B2B, player-funds, financial, go-live, outsourcing, information-security incident, ADR, and suspicious-betting reports and notifications. Applicability differs by license and activity.
- regulator2026-07-12Danish Gambling Authority: Game supplier
Current Denmark source for the supplier-license boundary covering games and services that operate and settle bets for licensed betting and online-casino operators. It does not authorize consumer-facing gambling.
- regulator2026-07-12Kansspelautoriteit: Remote gambling license questions and answers
Current Dutch-language Ksa guidance used for the Koa operator-only boundary, the absence of Koa permissions for B2B software companies, and operator responsibility for addressed outsourced arrangements. The Dutch source controls over this English summary.
- standards body2026-07-12Financial Action Task Force: The FATF Recommendations, as amended June 2026
International AML, CFT, and proliferation-financing standard last updated in June 2026, used here for the risk-based approach, beneficial ownership, CDD, ongoing monitoring, records, and supervision boundary. It takes effect through jurisdiction-specific law and is not a gambling license.
This guide is a licensing and application framework, not legal, tax, regulatory, corporate, AML, payment, privacy, testing, security, accounting, or insolvency advice. Gambling and supplier rules vary by jurisdiction, player location, entity, product, channel, equipment, contract, data flow, money flow, and date. Confirm the current law, authority guidance, forms, registers, conditions, technical instruments, and qualified professional advice for the exact proposed facts before applying, marketing, supplying regulated technology, accepting players or funds, changing the business, or surrendering an authorization.