SWR7
Home/Insights/Compliance · UKGC
Compliance · UKGC

UKGC RTS security requirements: the annual security audit, explained

Great Britain does not ask remote operators for a penetration test. It asks for something broader and less glamorous: an annual, independent audit of 43 named controls on your critical systems. Here is the requirement as the Commission writes it.

SWR7 teamPublished 4 min read
Scope noteThis page summarizes public Gambling Commission documents as of September 2026 and links to each source. It is not legal advice; the licence conditions and the RTS as published by the Commission prevail.

Where the obligation comes from

Licence condition 2.3.1 Technical standards of the LCCP requires licensees to "comply with the Commission's technical standards and with requirements set by the Commission relating to the timing and procedures for testing" (LCCP 2.3.1). The technical standards are the Remote gambling and software technical standards (RTS); the information-security part is RTS section 4, "Security requirements" (RTS, full text).

What section 4 requires

The Commission "has based the security requirements on the relevant sections of Annex A to the ISO/IEC 27001:2022 standard", which replaced the 2013 edition. Section 4 lists 43 Annex A controls — organizational (e.g. 5.1, 5.15–5.26, 5.28, 5.35), people (6.3, 6.5, 6.7, 6.8), physical (7.8, 7.10, 7.14) and technological (8.1–8.3, 8.5, 8.7, 8.13, 8.15, 8.17, 8.18, 8.20–8.22, 8.24–8.27, 8.29–8.33). Since the 2024 changes, "all security audits conducted after 1 November 2024 must be conducted against the controls listed in the updated RTS", and 5.23 (cloud services) was added (consultation response, proposal 7).

The controls apply to critical systems: systems that record, store, process, share, transmit or retrieve sensitive customer information; systems that generate, transmit or process the random numbers that determine game outcomes; systems that store results or the current state of a customer's gamble; points of entry to and exit from those systems; and the networks that carry sensitive customer information (security requirements summary).

The annual security audit

The Commission's security audit advice sets the mechanics:

  • Who. Holders of remote casino, remote game host, remote general betting (other than telephone-only or trading-rooms-only), remote betting host, remote pool betting, remote betting intermediary, remote bingo, and external lottery manager / society lottery licences above the stated sales threshold. The trigger is the licence type, not revenue — the lottery sales threshold is the one exception. The audit advice as published lists operating licences; holders of gambling software (B2B) licences are bound by the RTS for the software they supply and should check their own licence conditions for the audit duty.
  • By whom. An auditor "both independent and suitably qualified" and "independent of the licence holder". Certifications the Commission names as able to demonstrate suitability: ISO 27001 Lead Auditor, CISA, CISM, CISSP. There is no accreditation-body requirement, and ISO 27001 certification of the operator is not required and is not stated to replace the audit.
  • When. Newly licensed operators must complete and provide the first audit within 6 months of the licence being granted; subsequent audits are annual by the set due date and retained on file. The Commission requests confirmation by email, to be answered within 7 days.
  • What must be sent. The Commission "must be informed without any delay when an audit report identifies any major non-conformities, and a full copy of the report shall be submitted without delay". Findings are graded fully compliant / observation / minor non-conformity / major non-conformity, with management remediation plans.

Where a penetration test fits — and where it does not

The RTS does not mandate a standalone penetration test or vulnerability scan. The audit advice lists, among the areas from which the auditor gathers evidence, "reviews of any externally conducted penetration testing and vulnerability assessments performed" — alongside security settings of networks, databases, operating systems and gambling applications, user access controls, change control, physical access, audit-log reviews, backups, staff interviews and training records. In other words: a pentest is evidence the auditor reviews, not the audit itself. Of the 43 controls, only 8.29 ("Security testing in development and acceptance") concerns testing directly.

Two adjacent duties are easy to miss. Changes that affect fairness (RNG, scaling or mapping, game rules) are "major changes" that need external re-testing by an approved test house under the Testing strategy. And "any security breach to the licensee's environment that adversely affects the confidentiality of customer data" is a key event under LCCP 15.2.1, to be reported within five working days (LCCP 15.2.1).

What this means for your security program

The audit is a yearly photograph of 43 controls. The controls themselves — access control, logging (8.15, 8.17, 8.18), network security (8.20–8.22), cryptography and secure development (8.24–8.27), security testing, environment separation and change management (8.29–8.33) — describe an operating state, and a state drifts between two audits. The operators who pass cleanly are the ones who can show the auditor evidence that the state was maintained all year: configuration that did not silently change, exposure that was noticed and fixed, tests reviewed when they were done rather than reconstructed in the week before the audit.

Where SWR7 fitsSWR7 is not an auditor and does not certify RTS compliance. What it gives you is the year-round evidence the auditor asks for: continuous, non-destructive detection of exposure and configuration drift on your public-facing critical systems, a remediation for each finding, a dated record of what was tested and what was found, and — when you want depth — controlled and intrusive tests on staging under signed Rules of Engagement, with reports you can hand the auditor as externally conducted testing to review — it is the auditor who decides what counts as evidence.

Frequently asked questions

Does the UKGC require an annual penetration test?

No. The RTS requires an annual independent security audit against 43 ISO/IEC 27001:2022 Annex A controls. Penetration tests and vulnerability assessments, where performed, are evidence the auditor reviews — not a standalone obligation.

Do we need ISO 27001 certification to hold a remote licence?

No. The requirements are based on Annex A controls, but certification of the operator is not required and does not replace the audit.

Who can perform the RTS security audit?

An auditor independent of the licensee and suitably qualified; the Commission cites ISO 27001 Lead Auditor, CISA, CISM and CISSP as certifications that may demonstrate suitability. No specific accreditation body is required.

When is the first audit due for a new licensee?

Within 6 months of the licence being granted; subsequent audits are annual by the due date the Commission sets, with the report retained on file and submitted on request or when a major non-conformity is found.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call