Run an Online Casino
A live operation is a chain of ledgers, permissions, controls, suppliers, people, and deadlines. The operating job is to keep those records consistent, detect breaks early, assign decisions clearly, and preserve evidence that explains what happened.
This playbook covers remote B2B casino and related online gambling operations. It does not cover land-based casino premises, gaming-machine floors, retail venue management, or consumer gambling recommendations.
Keep three operating records current
The records below provide the common frame for daily work, incidents, supplier reviews, renewals, and change approval.
Authority map
Reconciliation calendar
Change and obligation calendar
Operating control areas
Each area needs records, dependencies, and explicit gates. A dashboard without an owner and an action threshold is only a display.
- Control 1
Payments, player funds, and cash flow
Operate deposits and withdrawals as one controlled money chain. Approval rate matters, but so do net settlement, reserves, chargebacks, conversion, bank timing, withdrawal aging, and the difference between player liability, GGR, defined NGR, and available cash.
Required records
- Daily reconciliations joining the player wallet, payment provider, acquirer or payment rail, bank, refunds, reversals, chargebacks, reserves, fees, and FX.
- Exception queues for unmatched records, duplicates, partial settlement, delayed files, stuck withdrawals, negative balances, and provider or bank cutoff failures.
Inputs and dependencies
- Stable identifiers, timestamps, settlement files, finance ownership, fraud and AML decisions, documented adjustments, current merchant acceptance, reserve terms, and fallback routes.
Acceptance gates
- Every break has a value, age, reason, owner, action, and escalation time; treasury uses actual settlement and reserve timing rather than treating GGR or NGR as cash.
- Control 2
Compliance, risk, and player protection
Run customer verification, sanctions and PEP screening, transaction monitoring, source-of-funds review, safer-gambling controls, complaints, self-exclusion, limits, and reporting as connected account states. Do not leave mandatory decisions inside disconnected vendor portals.
Required records
- Case records that preserve trigger, source data, analyst work, decision, approval, customer action, system restriction, report, and later review.
- Control metrics that separate volume from effectiveness: false positives, aging, override use, missed events, repeat interventions, reopenings, and control failures.
Inputs and dependencies
- Reliable player, platform, payment, game, identity, location, and communication events, plus trained staff, access review, quality assurance, and controlled rule changes.
Acceptance gates
- Restrictions agree across case, account, wallet, payments, product, marketing, and reporting records; missed feeds, outages, backlogs, and overrides trigger a documented fallback.
- Control 3
License conditions and regulatory upkeep
Translate every license condition, approval, filing, fee, audit, certificate, key-person duty, system notification, and material-change rule into a dated obligation with an owner and retained submission evidence.
Required records
- A regulatory register by entity, market, product, domain, approval, condition, renewal date, submission route, evidence location, and accountable reviewer.
- A change screen for ownership, directors, key people, suppliers, games, payment routes, systems, locations, domains, policies, and outsourcing before implementation.
Inputs and dependencies
- Regulator and corporate records, approved application baseline, product and supplier inventories, deployment map, professional advice, and finance and board calendars.
Acceptance gates
- Renewals start from the evidence lead time, and no material change becomes an ordinary software ticket before notification, approval, certification, and contract effects are checked.
- Control 4
Technology, content, and service operations
Operate the platform, wallet, games, integrations, data pipelines, front end, infrastructure, and supplier services as one dependency map. Availability must be measured at critical player and money journeys, not only at an individual server or API.
Required records
- Service maps with owners, environments, data flows, credentials, certificates, queues, limits, monitoring, service levels, recovery targets, maintenance windows, and third-party escalation paths.
- Journey-level monitoring and runbooks for registration, login, verification, deposit, withdrawal, game launch, bet settlement, balance, limits, exclusion, support, and reporting.
Inputs and dependencies
- Synthetic checks, consistent timestamps and identifiers, access controls, current inventories, validated backups, supplier status channels, and on-call stop authority.
Acceptance gates
- Alerts have thresholds, impact, owner, response time, evidence, and closure criteria; recovery exercises prove data integrity, supplier recovery, and reconciliation.
- Control 5
Retention, communications, and player support
Connect CRM, bonuses, loyalty, gamification, messaging, affiliate attribution, and support to consent, eligibility, affordability, exclusion, wallet, and complaint states. Engagement tooling must not become a second uncontrolled customer record.
Required records
- A communication and reward decision map covering audience source, consent, suppression, eligibility, approval, send authority, award posting, reversal, cost, result, complaint, and audit trail.
- Support procedures that join tickets to the authoritative player, transaction, game round, control case, promotion, and decision record without copying sensitive data into uncontrolled channels.
Inputs and dependencies
- Reliable event and identity mapping, channel providers, language and template review, bonus behavior, contact limits, support access, verification, and complaint ownership.
Acceptance gates
- Stale segments, retries, uploads, or disconnected channels cannot reintroduce blocked accounts; outcomes reconcile to spend, awards, complaints, control events, and retained approvals.
- Control 6
Incidents, change, supplier failure, and exit
Use one decision framework for incidents and changes: protect players and funds, preserve evidence, assign authority, control communications, meet notification duties, reconcile recovery, and prevent recurrence. Supplier exit must be rehearsed before a crisis.
Required records
- An incident record with detection, scope, affected markets and players, money exposure, control impact, timeline, decisions, communications, notifications, recovery, reconciliation, root cause, and corrective actions.
- A tested exit pack containing contract notices, data and configuration exports, open balances and cases, credentials, domains, certificates, integrations, records, migration mapping, access revocation, and deletion evidence.
Inputs and dependencies
- Current notice periods, supplier map, regulator thresholds, decision and communication owners, recovery options, and releases with approval, testing, rollback, and reconciliation.
Acceptance gates
- Restoration is not closure: records must reconcile, and supplier exit is not accepted until exports work, access is removed, dependencies are redirected, and residual duties have owners.
The weekly operating review
Review money breaks, control queues, player restrictions, incidents, service health, supplier failures, regulatory deadlines, material changes, complaints, and aged actions from the same authority map. Each exception should carry value or impact, age, owner, decision deadline, evidence, and escalation. The directory can support supplier review, but the operating record must describe the exact live entities, contracts, systems, markets, and responsibilities.