Skip to content
casino.limo
C

Crucial Compliance

Crucial AML is a separately licensable gambling AML module. It builds dynamic customer risk ratings from configurable flags, triggers, bundles, and markers, monitors behavioral and transactional patterns, and routes alerts into cases, audit trails, and regulator-facing reports.

Page updated

Visit website
Company details
Named companyCrucial Compliance Limited
Organization typecompany
Statusactive
Websitewww.crucialcompliance.gi
Research checked
Main categoryiGaming Compliance Providers

Crucial Compliance Limited is the Gibraltar operating company. Its company number, current corporate status, directors, ownership, customer contractor, signatory, invoice issuer, and professional authorizations are undisclosed. The order must resolve the corporate and contracting identity before sensitive application work begins.

Buyer decision brief

Use this summary to decide whether the offer belongs on your shortlist and which terms need a written answer.

Fit and use case

Editorial fit

Gambling operators or platform suppliers that need configurable behavioral and transactional AML monitoring, cases, audit records, and flexible hosting, and can diligence every data provider, jurisdiction, reporting workflow, data role, and contract boundary.

Primary offer: Crucial AML · 3 additional offers below

Primary offer delivery

  • Software license

Integration boundary: Crucial supports SaaS on its AWS environment, deployment in the customer's AWS environment, and on-premise deployment, with APIs into existing systems, CRMs, payment providers, and third-party data sources.

Critical contract questions

Start with unresolved terms, negotiated terms, and dependencies that need a named owner.

8 of 23

Resolve before shortlist

No usable standard answer is available on the public terms.

8 of 14 shown
Jurisdiction, data, and report coverageNot disclosed
Crucial AML · Market and approvals
Jurisdiction and intervention acceptanceNot disclosed
Crucial RG · Market and approvals
Crucial contractor and technology ownerUnresolved
Crucial AML · Contract and supplier
Crucial RG contractor and IP ownerUnresolved
Crucial RG · Contract and supplier
Third-party data and controller rolesNot disclosed
Crucial AML · Operating responsibilities
Data providers and processing rolesNot disclosed
Crucial RG · Operating responsibilities
Model, typology, and alert validationNot disclosed
Crucial AML · Operations and service
Model version and harm-detection validationNot disclosed
Crucial RG · Operations and service

Next buyer step

Ask Crucial Compliance to resolve “Jurisdiction, data, and report coverage” and “Jurisdiction and intervention acceptance” before moving Crucial AML to a commercial shortlist. Then compare the answer with the complete product record below.

Confirm every selected term in the proposal and signed order. No price, market approval, availability, or contracting entity is implied unless it is stated above.

What this provider offers

4 offerings

Crucial AML

Multi ProductMixedAvailability: Standalone and Bundled

Crucial AML is a separately licensable gambling AML module. It builds dynamic customer risk ratings from configurable flags, triggers, bundles, and markers, monitors behavioral and transactional patterns, and routes alerts into cases, audit trails, and regulator-facing reports.

Risk 360 is the modular platform around Crucial's specialist products. It includes CDD/EDD, case management, dashboards, reporting, and API integrations. Crucial AML and Crucial RG can be licensed individually or operated together in a shared customer-risk view.

Crucial owns the software, workflow, and gambling-specific models, while third parties supply parts of the data layer. The PEP, sanctions, identity, payment, and other data providers, ownership, market coverage, update frequency, matching methods, and contractual data responsibilities remain undisclosed.

Products

Crucial AML Monitoring: Configurable flags, triggers, bundles, and markers applied to operator-supplied behavioral and transactional data to create dynamic customer risk ratings and surface gambling-specific typologies for review.
AML Case Management and Reporting: Alerts, configurable urgency, case workflows, audit trails, and audit-ready reporting. SAR preparation does not include electronic filing or transfer to a reporting authority.
Risk 360 CDD/EDD: A shared due-diligence module for risk verification and PEP and sanctions checks. Underlying providers, datasets, matching logic, and jurisdiction coverage remain undisclosed.
Risk 360 Case Management and Dashboards: Shared case management, SLA and escalation workflows, audit trails, business dashboards, and audit exports within the modular Risk 360 platform.
Combined AML and RG View: Optional operation of Crucial AML and Crucial RG side by side in Risk 360; the two specialist modules remain individually licensable and RG is not included by implication in an AML contract.

Integration: Crucial supports SaaS on its AWS environment, deployment in the customer's AWS environment, and on-premise deployment, with APIs into existing systems, CRMs, payment providers, and third-party data sources. The agreement must define modules, hosting, connected systems, data providers, thresholds, human review, retention, security and data roles, service levels, and exit. The customer API specification and standard contract are unavailable.

Key facts

  • Crucial AML is a distinct gambling AML module with behavioral and transactional monitoring, dynamic risk scoring, cases, audit trails, and reporting
  • Risk 360 includes CDD/EDD, case management, dashboards, Crucial AML, and Crucial RG, with AML and RG available as individual licenses
  • A standard Risk 360 implementation is estimated at 8 to 12 weeks, including mapping, calibration, integration, and training
  • Crucial supports SaaS on Crucial AWS, customer-AWS, and on-premise deployment with integrations to operator systems and third-party data providers
  • PEP, sanctions, SOF, payment, and other third-party data providers, datasets, ownership, territories, refresh schedules, and matching rules remain undisclosed
  • Crucial AML supports SAR preparation; operators retain approval, signature, authority-specific formatting, and electronic filing
  • A product DPA, subprocessor schedule, retention schedule, and settled controller and processor allocation are unavailable
  • This profile maps to Crucial Compliance Limited; its current registry status, company number, ownership, and deployment-specific contracting entity are undisclosed

Delivery options

Software License

Delivery model

A separately licensed Crucial AML deployment using the contracted SaaS, customer-AWS, or on-premise model, connected to the operator's selected data and review workflows.

Operator license
Operator
Merchant of record
Operator
Player data controller
Unknown

Included

  • + Contracted Crucial AML flags, triggers, bundles, markers, and dynamic risk scoring
  • + Behavioral and transactional monitoring against the data feeds defined in the agreement
  • + Configured alerts, cases, audit trails, and reports
  • + Risk 360 CDD/EDD, case management, and dashboards when included in the contracted configuration
  • + The selected hosting model, integration work, calibration, and training stated in the order

Not included

  • ! A gambling license or transfer of the operator's AML, MLRO, board, or reporting duties
  • ! Crucial RG unless it is separately licensed
  • ! Ownership, completeness, or universal availability of PEP, sanctions, SOF, identity, payment, or other third-party data
  • ! Automatic SAR approval, signature, submission, or authority-specific electronic filing
  • ! Unspecified markets, data sources, subprocessors, security controls, retention terms, or controller and processor roles
  • ! A public fixed price, a guaranteed implementation SLA, or an 8-to-12-week promise for every standalone AML deployment
  • ! Validated detection performance, false-positive reduction, or regulatory outcomes
Launch time
A standard Risk 360 implementation is estimated at 8 to 12 weeks, including data mapping, calibration, integration, and training

Procurement record

Current product boundaries and the terms that still have to be fixed in the signed order or service agreement.

Known is usable now. Contract specific changes by order or market. Not disclosed has no usable standard term. Unknown remains unresolved. Outside provider scope is handled by the operator or another supplier.

Contract and supplier

Crucial contractor and technology ownerUnknown
The profile maps to Crucial Compliance Limited, but its company number, registry status, ownership, software ownership, and deployment-specific counterparty are undisclosed. The agreement must establish each role before signature.
Crucial AML versus Risk 360 scopeKnown
Crucial AML is individually licensable. Risk 360 can add CDD/EDD, shared case management, dashboards, and Crucial RG, but those components are not included in an AML order by implication.

Implementation

Hosted, customer-cloud, or on-premises deliveryKnown
Deployment can use Crucial-hosted SaaS, the customer's AWS environment, or on-premises infrastructure with APIs into systems, CRMs, payments, and data providers. Infrastructure, integrations, recovery, security, and support ownership must match the selected route.
Risk 360 implementation estimateKnown
A standard Risk 360 implementation is estimated at 8–12 weeks and includes data mapping, calibration, integration, and training. It is not a guaranteed SLA or a standalone Crucial AML delivery commitment.

Operating responsibilities

Third-party data and controller rolesNot disclosed
PEP, sanctions, source-of-funds, identity, payment, and other providers are unnamed, and controller, processor, subprocessor, retention, hosting, and model-training roles are not settled. The order must define every input and purpose.
MLRO and filing responsibilityKnown
Crucial supplies risk ratings, alerts, cases, audit records, reports, and SAR preparation. The operator, MLRO, and board retain investigation conclusions, filing approval, authority formatting, electronic submission, deadlines, and regulator communication.

Operations and service

Model, typology, and alert validationNot disclosed
Accuracy, bias, false positives, false negatives, typology coverage, case workload, alert latency, and regulator acceptance are not established for a named model version, threshold set, and player population.
Security, incidents, and continuityNot disclosed
A product DPA, subprocessor list, retention schedule, API specification, security certificate, incident notice, recovery objective, service-level schedule, and customer exit package are not established.

Commercial terms

AML and Risk 360 chargesNot disclosed
Implementation, hosting, module, data-provider, transaction, case, user, environment, minimum, overage, training, support, model change, and combined Risk 360 charges are not established.

Market and approval scope

Jurisdiction, data, and report coverageNot disclosed
The complete market matrix, dataset coverage, regulatory reporting formats, electronic-submission routes, language coverage, data residency, and gambling-regulator acceptance are not established.

Exit and portability

Rules, alerts, cases, and audit exportNot disclosed
Export formats for rules, thresholds, scores, alerts, cases, attachments, reports, and audit history are not established, nor are transition help, deletion timing, deletion evidence, and third-party data rights.
Best for: Gambling operators or platform suppliers that need configurable behavioral and transactional AML monitoring, cases, audit records, and flexible hosting, and can diligence every data provider, jurisdiction, reporting workflow, data role, and contract boundary.

Strengths

  • + Crucial AML and Crucial RG are separate, individually licensable products.
  • + The AML module includes gambling-specific monitoring logic, cases, audit trails, reports, and multiple deployment options.
  • + Risk 360 has a concrete modular boundary that includes CDD/EDD, case management, dashboards, and optional combined AML and RG operation.
  • + The implementation estimate includes mapping, calibration, integration, and training rather than implying instant activation.

What to verify in procurement

  • ! PEP, sanctions, SOF, identity, payment, and other third-party data providers, ownership, coverage, refresh cadence, and matching logic remain undisclosed.
  • ! Crucial AML supports SAR preparation; operators retain approval, signature, authority-specific formatting, and electronic filing.
  • ! Customer API documentation, an MSA, product DPA, subprocessor schedule, retention schedule, security certification, and settled data-role allocation are unavailable.
  • ! The 8-to-12-week figure is a standard Risk 360 estimate, not a guaranteed SLA or standalone Crucial AML delivery time.
  • ! Model accuracy, false-positive reduction, typology coverage, regulator acceptance, and customer-outcome benchmarks are unavailable.
  • ! This profile maps only to Crucial Compliance Limited; its current registry status, company number, ownership table, contracting entity, and regulatory authorization are undisclosed.
  • ! The operator, MLRO, and board retain final AML decisions, reporting duties, data governance, and license accountability.

Crucial Gambling Compliance Consultancy

Multi ProductCompliance and RegulatoryFirst PartyAvailability: Standalone

Crucial Compliance currently operates separate consulting practices for gambling operators, platform suppliers, and regulators. Its operator scope includes audits, policies and governance, regulatory support, interim MLRO or PML cover, training, and mentoring.

Platform work covers compliance architecture, software assessment, data mapping, workflow design, integration support, gap analysis, and RG or AML model configuration. Regulator work covers policy, supervision, licensing frameworks, model review, reporting, and capability building.

Consultancy is available without buying Crucial software. Advice, an audit, or an interim resource does not make Crucial the operator, license holder, regulator, merchant of record, or permanent owner of the client's statutory duties.

Services

Audit and gap analysis: RG, AML, affordability, governance, marketing, LCCP, payment-provider, and business-risk reviews with reports and action plans.
Policies and governance: Policy packs, procedures, reporting structures, Player Protection Forums, compliance committees, and change or risk-management processes.
MLRO and regulatory support: Regulatory submissions, license applications, investigation support, interim MLRO or PML cover, mentoring, and reporting-framework design.
Training and capability building: Board, compliance-team, customer-facing, platform, and regulator training tied to the agreed cases, controls, and jurisdictions.
Platform and regulator consultancy: Compliance architecture, integration support, supervision programs, licensing frameworks, model reviews, and reporting design.

Engagement: The statement of work must name Crucial Compliance Limited, the licensed client, consultants, qualifications, regulated approvals, decision rights, deliverables, conflicts, and handover. Software, legal advice, independent assurance, and interim MLRO or PML work require separate duties and accountability. Team, fees, schedule, liability, and data roles remain engagement-specific.

Key facts

  • Crucial Compliance Limited is the Gibraltar operating company
  • Services span audits, policies and governance, regulatory support, interim MLRO or PML work, training, platform integration, and regulator advisory
  • Crucial's regulator consultancy can be purchased without its technology platform
  • Named client or partner statements include William Hill Retail, BoyleSports, DAZN Bet, and eyeDP
  • No standard consultancy rate card or delivery timetable is available

Engagement models

Advisory Engagement

Engagement model

Project consultancy, audit, training, regulatory support, or implementation advice delivered under an engagement-specific statement of work.

Included

  • + The agreed audit, gap-analysis, policy, governance, or training scope
  • + Regulatory and license-application support when contracted
  • + Platform or regulator workstreams named in the engagement
  • + Defined reports, action plans, workshops, and handover

Not included

  • ! A gambling license, regulator decision, certification, or automatic approval
  • ! Transfer of the operator's board, license, AML, or player-protection accountability
  • ! Regulated legal advice unless separately supplied by an authorized professional
  • ! Crucial software unless separately licensed
  • ! Unspecified third-party services or guaranteed regulatory outcomes
  • ! A universal public price or delivery schedule

Interim Management

Engagement model

Temporary MLRO, PML, or compliance leadership subject to the named jurisdiction's approval, delegated-authority rules, and the licensed operator's continuing accountability.

Operator license
Operator
Merchant of record
Unknown
Player data controller
Unknown

Included

  • + The named interim role and approved duties
  • + Documented authority, access, escalation, reporting, and availability
  • + Regulator or key-person approval support where required
  • + A replacement and handover plan to the operator's permanent role holder

Not included

  • ! Transfer of the operator's license, board, AML, or player-protection accountability
  • ! Merchant-of-record status, custody of player funds, or platform ownership
  • ! Regulated legal advice unless separately supplied by an authorized professional
  • ! Permanent staffing, Crucial software, or duties not named in the appointment
Best for: Operators, platform suppliers, or regulators that need gambling-specific audits, governance work, implementation support, interim compliance capacity, or training with software procurement kept as a separate decision.

Strengths

  • + Operator, platform, and regulator consulting are separate service tracks.
  • + The operator practice covers multiple substantive audit, governance, regulatory, and training workstreams.
  • + Consultancy can stand alone without a software purchase.
  • + Deliverables cover audits, governance, regulatory support, training, platform workflows, and interim compliance roles.

What to verify in procurement

  • ! No complete delivery roster maps credentials to engagement roles, so the proposal must name the assigned personnel.
  • ! Interim MLRO or PML support cannot bypass operator governance, personal-license rules, statutory accountability, or regulator approval.
  • ! Serving both operators and regulators creates potential independence and information-conflict issues. Require conflict disclosure, information barriers, and restrictions on client-data reuse.
  • ! An MSA, DPA, subprocessor schedule, professional-indemnity evidence, fee basis, and standard timetable remain unavailable.
  • ! Named client relationships do not establish measured outcomes or a guaranteed scope.

Crucial Compliance License Application Support

Multi ProductFirst PartyAvailability: Standalone

Crucial Compliance offers operator consultancy covering license applications, regulatory submissions, operational and control audits, policy work, and governance support. This module covers application readiness and submission assistance rather than the wider software, regulator, or interim compliance practice.

The useful distinction is between preparing an applicant and issuing a license. Crucial can assess controls, organize evidence, draft or support submissions, and help remediate gaps, but the client remains the applicant and the public regulator retains every approval, condition, key-person, and enforcement decision.

A jurisdiction matrix, standard application package, lawyer roster, fee schedule, outcome record, and delivery timetable remain undisclosed. Speed and success cannot be ranked and must be resolved in the statement of work.

Products

License-readiness audit: Assessment of governance, AML, responsible gambling, marketing, player protection, payment controls, business risk, policies, and evidence against the selected application scope.
Regulatory submission support: Preparation, review, issue tracking, and coordination for application and regulator-request documents assigned in the engagement.
Policy and governance remediation: Policies, procedures, reporting structures, action plans, and governance work needed to address identified application gaps.
Interim application support: Temporary compliance or licensing capacity where local approval, personal-license, delegated-authority, and handover requirements are documented.

Integration: The statement of work should name Crucial Compliance Limited, the applicant and licensee, regulator, license class, products, markets, named consultants and qualifications, independent legal counsel, regulator-portal authority, key persons, control and evidence baseline, data access, documents and policies, deliverables, acceptance criteria, milestones, official and professional fees, assumptions, dependencies, conflicts, software boundary, third parties, privilege, data roles, liability, rejection and remediation scope, continuing support, and handover. Jurisdiction coverage, fees, approval time, success rates, and legal-advice model remain engagement-specific.

Key facts

  • Crucial Compliance Limited is the disclosed Gibraltar operating company
  • The current operator consultancy explicitly includes license applications, regulatory submissions, audits, policies, governance, investigation support, and interim compliance work
  • Crucial separately advises regulators on licensing frameworks and supervision, while operator application support remains a client-side service
  • A customer MSA, DPA, subprocessor schedule, standard rate card, and application timetable are unavailable

Delivery options

Managed Service

Delivery model

A scoped application-readiness, regulatory-submission, and remediation engagement delivered alongside the applicant's legal, operational, and technical owners.

Operator license
Operator
Merchant of record
Operator
Player data controller
Unknown

Included

  • + The agreed licensing-readiness audit and action plan
  • + Application or regulator-response documents assigned to Crucial
  • + Policy, governance, training, or remediation work expressly ordered
  • + Reporting, workshops, and handover deliverables named in the scope

Not included

  • ! The gambling license, regulator decision, certification, or guaranteed result
  • ! Legal advice unless a qualified authorized professional is separately named
  • ! Crucial software, interim statutory roles, or continuing compliance unless separately contracted
  • ! Transfer of board, key-person, AML, player-protection, or market-access accountability
  • ! Unspecified third parties, fees, jurisdictions, or application deadlines
Best for: Operators or suppliers that already have identified legal counsel and a target regulator but need gambling-specific control testing, policy remediation, evidence preparation, and submission project support.

Strengths

  • + The operator consultancy covers concrete application, audit, policy, governance, and regulatory work rather than a generic license promise.
  • + Crucial can connect application preparation to the compliance controls that the licensed business must operate after approval.
  • + Licensing support is separable from the company's software platform and broader regulator consultancy.

What to verify in procurement

  • ! Jurisdiction coverage, local-counsel model, standard application package, fee basis, and timetable remain undisclosed. Do not assume coverage from general regulatory language.
  • ! Crucial serves operators, platforms, and regulators. Require matter-specific conflict disclosure, information barriers, and restrictions on reuse of confidential application material.
  • ! Interim MLRO or personal-license work can require regulator approval and does not transfer statutory accountability from the applicant's board or approved people.
  • ! Keep legal opinions, independent audit or certification, software licensing, and application consultancy in separate scopes when their independence or responsibility differs.

Crucial RG

Multi ProductFirst PartyAvailability: Standalone and Bundled

Crucial RG is a separately licensable responsible-gambling module from Crucial Compliance. Its Markers of Harm logic analyzes submitted player patterns such as spend, session time, deposits, and safer-gambling-tool use, assigns dynamic risk scores, segments players, and routes configured interactions, marketing suppression, cases, and audit records.

The same module can be deployed inside Crucial Risk 360, a modular platform with CDD/EDD, case management, and dashboards. Crucial RG and Crucial AML can be licensed individually or together.

Crucial RG covers player-risk scoring, segmentation, configured interventions, marketing suppression, cases, and audit records. Accuracy, regulatory sufficiency, a universal intervention policy, and harm-reduction outcomes are unavailable for the proprietary Markers of Harm model. The operator must approve inputs, thresholds, automation, human review, customer contact, account actions, decision-record retention, and market-specific controls.

Products

Crucial RG: Behavioral player-risk scoring, segmentation, configured interventions, marketing suppression, case creation, and decision logging based on the operator's agreed data and workflows.
Crucial Risk 360 deployment: A modular combined platform route in which Crucial RG can operate alongside Crucial AML, CDD/EDD, case management, and dashboards without making every component mandatory for a standalone RG license.

Integration: Crucial supports hosted SaaS, customer-managed AWS, and on-premises installation, with APIs connecting operator data, CRM systems, and agreed third-party providers. The implementation must define inputs, thresholds, automated and human actions, hosting and data roles, retention, model changes, incident handling, and jurisdiction-specific responsibility. The 8-to-12-week estimate applies to a standard Risk 360 implementation, not a standalone Crucial RG SLA.

Key facts

  • Crucial RG is a separately licensable responsible-gambling module for operators and platform suppliers
  • The workflow includes behavior-pattern analysis, dynamic scores, player segmentation, configured interactions, marketing suppression, case creation, and audit logging
  • Risk 360 is a modular combined platform with CDD/EDD, case management and dashboards, while Crucial RG and Crucial AML can be licensed individually
  • A standard Risk 360 implementation is estimated at 8 to 12 weeks, including data mapping, calibration, integration, and training
  • GiG integrated Crucial Compliance for AML and responsible-gaming capabilities in 2025
  • Validation results for the current Markers of Harm model are unavailable

Delivery options

Software License

Delivery model

A separately licensed Crucial RG module deployed through Crucial-hosted SaaS, customer-controlled AWS, or on-premises infrastructure and integrated with agreed player-data and CRM flows.

Operator license
Operator
Merchant of record
Operator
Player data controller
Unknown

Included

  • + The contracted Crucial RG software and configured Markers of Harm workflow
  • + The agreed player-data mapping, risk segments, thresholds, cases, actions, and audit records
  • + The contracted hosted, customer-AWS, or on-premises deployment route
  • + Training and integration work expressly included in the order

Not included

  • ! The operator's gambling license, safer-gambling policy, statutory accountability, and final player decision
  • ! Crucial AML, CDD/EDD, third-party checks, or the full Risk 360 bundle unless separately contracted
  • ! Model validation covering accuracy, bias, false positives, false negatives, or harm reduction
  • ! Unapproved automatic communication, limits, suspension, closure, self-exclusion, or treatment referral
  • ! A universal data-controller allocation, market approval, public price, or guaranteed implementation SLA

Procurement record

Current product boundaries and the terms that still have to be fixed in the signed order or service agreement.

Contract and supplier

Crucial RG contractor and IP ownerUnknown
Crucial Compliance Limited is the supplier identity used for the product. The current contracting company, company number, software owner, invoice entity, processor, and liability allocation must be fixed before signature.
Standalone RG and Risk 360 boundaryKnown
Crucial RG can be licensed individually. Risk 360 can add CDD/EDD, case management, dashboards, Crucial AML, and shared reporting, but those components are not included in a standalone RG order by implication.

Implementation

Hosted, customer-AWS, or on-premises routeKnown
Delivery can use hosted SaaS, customer-managed AWS, or on-premises installation with APIs into operator data, CRM, and selected providers. Infrastructure, integrations, backups, recovery, security, and support ownership must match the selected route.
Risk 360 delivery estimateKnown
A standard Risk 360 implementation is estimated at 8–12 weeks. The figure covers a combined platform route and is not a guaranteed contractual SLA or a standalone Crucial RG timetable.

Operating responsibilities

Data providers and processing rolesNot disclosed
Third-party inputs, controller and processor roles, subprocessors, hosting regions, retention, model-training use, transfer routes, and special-category-data treatment are not established. The order must map every player field and downstream purpose.
Automated actions and operator oversightKnown
Crucial RG can trigger interactions, marketing suppression, cases, and decision logs. The operator must approve thresholds, lawful basis, human oversight, exceptions, player contact, limits, suspension, closure, self-exclusion, referral, and final recorded decisions.

Operations and service

Model version and harm-detection validationNot disclosed
Risk360 does not disclose a named harm-model version, training and validation cohorts, threshold performance, segment-level error rates, calibration, drift tolerances, or measured link between alerts and harm outcomes. Buyers need those measures and independent validation before automated intervention.
Action, case, and model-change auditContract specific
The order must define score and reason fields, threshold versions, automated and human actions, marketing suppression, case states, intervention links, audit exports, model-change notice, validation, approval, and rollback.
Security, incidents, and continuityNot disclosed
A product DPA, subprocessor schedule, complete API reference, security certificate, penetration-test package, incident-notice term, recovery objectives, service levels, retention schedule, and deletion commitment are not established.

Commercial terms

RG, action, and Risk 360 chargesNot disclosed
Implementation, hosting, player or event volume, model, communication, case, user, environment, third-party data, minimum, overage, training, support, change, and combined Risk 360 charges are not established.

Market and approval scope

Jurisdiction and intervention acceptanceNot disclosed
The complete market matrix, languages, input coverage, profiling notices, automated-decision limits, intervention duties, marketing-suppression rules, data residency, and gambling-regulator acceptance are not established.

Exit and portability

Scores, actions, cases, and audit handoverNot disclosed
Player inputs, scores, reasons, thresholds, actions, interventions, cases, model versions, and audit records lack an established full export, including transition support, post-termination access, retention, and deletion evidence.
Best for: Operators or platform suppliers that need a configurable RG monitoring and case-workflow module, can define and validate the player data and thresholds, and will retain ownership of human review, interventions, account actions, and jurisdiction-specific duties.

Strengths

  • + Crucial RG has its own product and deployment boundary instead of requiring the full AML bundle.
  • + The workflow connects risk segmentation to configured cases, actions, suppression, and audit records.
  • + Hosted, customer-AWS, and on-premises routes allow different infrastructure and data-residency choices.
  • + GiG has a current integration of Crucial responsible-gaming and AML capabilities.

What to verify in procurement

  • ! Accuracy, bias control, false positives, false negatives, and harm reduction vary by model version and player population. Test both before deployment.
  • ! Automated interactions, marketing suppression, case creation, and other actions require operator-approved thresholds, lawful basis, human-oversight rules, exception handling, and market-specific governance.
  • ! Risk 360's 8-to-12-week figure is an estimate for a standard combined implementation, not a guaranteed contractual SLA or standalone RG timetable.
  • ! A product DPA, subprocessor schedule, complete API reference, security-certification record, universal controller allocation, fixed price, and full market matrix remain unavailable.
  • ! The order must identify each included third-party data source, CDD/EDD check, communication channel, case workflow, and dashboard; Risk 360 components are not automatically part of Crucial RG.
  • ! The operator remains responsible for player interaction, limits, suspension, closure, self-exclusion, referral, record quality, and the defensibility of every final decision.
Reference documents7

More providers with similar products