NGA LICENSING STANDARD / TECHNOLOGY

Every game and transaction must be traceable.

NGA examines the production path from authorised provider to player screen, and from player instruction to wallet and settlement. A certificate without reproducible evidence does not pass.

Authentic, authorised and version-controlled.

The operator must maintain provider and aggregator contracts, authoritative catalogues, production identifiers, approved delivery routes and applicable laboratory or RNG evidence. Supplier names, game titles and certificates must correspond to the production game actually delivered.

Absolute prohibition

No counterfeit, cloned, reskinned, falsely attributed or unauthorised game. No operator mechanism may alter outcomes, probabilities, round records, wallet messages, wins, refunds, rollbacks or settlement.

01

Transaction integrity

Unique and idempotent transaction handling, atomic balance changes, immutable round linkage, duplicate protection, reconciliation, exception queues and complete bet-win-refund-rollback traceability.

02

Identity and access

Least privilege, MFA for privileged access, controlled service accounts, secure secrets, segregation of duties, joiner-mover-leaver controls and periodic entitlement review.

03

Secure engineering and change

Reviewed code, protected deployment paths, dependency and vulnerability management, environment separation, approved emergency change and evidence linking production versions to tested releases.

04

Logging and detection

Tamper-evident and time-synchronised logs for authentication, administration, wallet, game, payment, exclusion, configuration and security activity, with alerting and controlled retention.

05

Testing and vulnerability management

Independent penetration testing at least annually and after material change, continuous remediation, attack-surface management and verification that Critical and Major findings are closed.

06

Incident and resilience

Defined severity, containment and notification; tested backups, restoration and failover; credible RTO/RPO; supplier continuity; and an evidence-preserving response to compromise or data loss.

07

Payment and player funds

Secure payment ownership checks, callback authentication, settlement and chargeback controls, daily player-liability reconciliation, aged-withdrawal monitoring and restricted administrative adjustment.

08

Supplier assurance

Due diligence, contracts, access boundaries, data responsibilities, incident duties, change notification, performance oversight and exit arrangements for every critical provider.

Evidence is reproduced, not merely received.

Testing may include controlled accounts and payments, provider-origin verification, network and application observation, catalogue and certificate comparison, round and wallet reconciliation, negative-path tests, log sampling, configuration inspection and interviews with accountable engineers.

1Declared architecture
2Authoritative source
3Controlled production journey
4Transaction and log reconciliation
5Finding and verified closure

Current licence verification may show dated integrity checks for the licensed scope. A check describes the tested evidence and time; it is not a permanent guarantee of every future transaction.

Game manipulation or counterfeit delivery puts the mark at immediate risk.

Confirmed manipulation, falsified provider evidence, concealed privileged access, material player-balance corruption, obstruction of testing or deliberate incident concealment may result in immediate invalidation of the integrity mark, interim suspension and revocation proceedings.