Skip to content
iGaming Platform Provider
B2B control and responsibility model

Responsible gambling is an operating system, not a feature list

A platform can supply states, limits, workflows, integrations, and audit records. The licensed operator still has to configure the right control, assign decisions, test failure paths, operate interventions, and prove that every downstream system follows the result.

Last materially updated August 12, 2026.

This page is for B2B diligence
This site does not offer gambling. If you need help with your own gambling, use the confidential player-support services near the end of this page rather than a software-provider checklist.

From obligation to evidence

Four layers have to reconcile

Procurement should reject a bare capability answer. A control is ready only when the required outcome, exact configuration, witnessed operation, and ongoing assurance describe the same scope.

01
Requirement

Define the market, licence holder, product, player population, required outcome, timing, retention, and reporting boundary.

02
Configured control

Turn the requirement into explicit states, thresholds, dependencies, permissions, failure behaviour, and human ownership.

03
Witnessed operation

Run normal, boundary, failure, recovery, and override scenarios against the proposed configuration and integration path.

04
Operational assurance

Monitor the control, reconcile exceptions, retain evidence, train staff, govern changes, and prove that downstream systems obey it.

Acceptance model

Control, owner, and test must stay together

The matrix is deliberately implementation-specific. It identifies what the platform must enforce, what the operator must operate, and what the buyer should witness before accepting the proposed scope.

Swipe horizontally to view all columns.
Responsible-gambling control ownership and acceptance matrix
ControlConfigured scopePlatform responsibilityOperator responsibilityAcceptance evidence
Age and identityRegistration gates, verification states, retry and manual-review paths, account restrictions, and re-verification triggers.Persist the verification state, enforce restrictions consistently, expose immutable decision events, and keep integrations observable.Select the approved services and thresholds, staff exceptions, resolve mismatches, and prevent play before the required checks pass.Test minors, document mismatch, service outage, duplicate identity, manual review, re-verification, and restricted-account paths.
Financial and time limitsDeposit, loss, spend, wager, session, and time controls with increase delays and clearly defined calculation windows.Calculate against the correct ledger and timezone, block at the right transaction boundary, and retain every setting and change event.Choose the controls and defaults required for each market, explain them accurately, and prevent manual workarounds.Test boundary amounts, concurrent sessions, pending transactions, daylight-saving changes, decreases, delayed increases, and refunds.
Cool-off and self-exclusionBrand, operator, market, and central-scheme exclusions with effective times, scope, renewal rules, and return-to-play gates.Propagate the exclusion across login, wagering, deposits, withdrawals, CRM, affiliates, and linked accounts without unsafe delay.Register exclusions correctly, reconcile central schemes, suppress marketing, manage remaining funds, and control reinstatement.Witness cross-brand propagation, queued campaigns, affiliate suppression, active sessions, pending bets, withdrawals, and reinstatement.
Risk detection and interventionDefined indicators, observation windows, severity levels, intervention routes, case ownership, and outcome states.Produce complete events, apply rules deterministically, preserve model or rule versions, and provide a reviewable case timeline.Own thresholds and policy, review alerts, contact players, record outcomes, escalate cases, and monitor false positives and misses.Replay representative histories, verify alert timing and evidence, test unreachable players, repeat alerts, overrides, and escalation SLAs.
Marketing suppressionEligibility, consent, exclusion, risk, channel, campaign, affiliate, and jurisdiction rules evaluated before every send or display.Expose a current suppression state and event stream; prevent stale caches, exports, and downstream tools from bypassing it.Control audiences and vendors, reconcile suppression lists, monitor affiliates, and stop active campaigns when status changes.Test scheduled and triggered messages, exported audiences, bonus surfaces, push, SMS, email, affiliates, and status changes mid-campaign.
Audit and reportingEvent definitions, actor identity, timestamps, reason codes, retention, regulator extracts, corrections, and access controls.Keep append-only decision history, stable identifiers, reproducible reports, export integrity, and a documented correction path.Reconcile reports, control access, investigate exceptions, retain case evidence, and submit the correct market-specific returns.Trace a complete player journey from source events to case history and regulatory output, including late data and corrected records.

Do not transfer an outcome between parties

Operator accreditation is not supplier accreditation

TitanPlay in Ontario has RG Check accreditation through June 2029. The result belongs to the named operator site. It provides a bounded operational outcome for the TitanPlay deployment, but it does not accredit Delasport, transfer to another customer, or replace any supplier registration, product approval, or operator obligation.

What the case establishes
One operator, one site, one term.
  • Operator: Shark77 Limited
  • Site: TitanPlay in Ontario
  • Accreditation term recorded through June 2029
  • No supplier-wide certification inferred

Procurement questions

Ask for the operating proof, not a feature screenshot

Scope and authority

Which entity, brand, market, vertical, channel, wallet, and player population does the control cover? Who can configure, approve, override, and revoke it?

Failure behaviour

What happens when identity, self-exclusion, risk, CRM, payment, or reporting dependencies are delayed, unavailable, duplicated, or contradictory?

Evidence and reconciliation

Which immutable events, reason codes, identifiers, exports, reports, and dashboards prove the decision and reconcile downstream execution?

Change and incident control

How are rule versions, threshold changes, model changes, access, releases, exceptions, incidents, corrections, and post-incident reviews governed?

Confidential support for players

Gambling should not be treated as a way to make money. If it is causing harm, stop gambling and contact a confidential support service. In the United States, call or text 1-800-MY-RESET or use the NCPG help page. In the United Kingdom, call 0808 8020 133 or use GamCare. International support is available through Gambling Therapy.

These are support and referral services, not emergency services. Contact the appropriate local emergency service if someone is in immediate danger.

Carry the controls into architecture and contract diligence