Talk to an Expert
Feel free to reach out, and we'll get back to you as soon as possible.
The UK Gambling Commission (UKGC) requires applicable remote gambling and specified remote
lottery licence holders to undergo an annual security audit conducted by an independent and
suitably qualified auditor. The audit assesses compliance with the security requirements of the
Remote Gambling and Software Technical Standards (RTS), which are based on relevant controls from
ISO/IEC 27001:2022.
The UKGC RTS security requirements apply to critical systems that support remote gambling
operations and handle sensitive customer or gambling information. These include systems that record,
store, process, share, transmit or retrieve sensitive customer information, systems that generate or
process random numbers used to determine gambling outcomes, systems that store gambling results or
the current state of a customer's gamble, points of entry to and exit from these systems, and
communication networks that transmit sensitive customer information.
The UKGC RTS security requirements are based on selected controls from ISO/IEC 27001:2022
Annex A and cover areas including information security, access control, authentication, privileged
access, supplier and cloud security, incident management, backup, logging, network security,
cryptography, secure development, security testing, change management, and separation of
development, test and production environments. The annual security audit assesses these applicable
requirements through evidence review, enquiry, observation and appropriate testing of relevant policies, procedures, technical controls and operational practices. The resulting audit report documents the audit, scope, methodology, systems reviewed, evidence examined, findings and management responses, together with the auditor’s opinion on the effectiveness of the relevant security control environment.
he UKGC RTS security requirements are based on specific controls from ISO/IEC 27001:2022 and do not require an organisation to obtain full ISO/IEC 27001 certification solely to meet the RTS requirements. Organisations that already hold ISO/IEC 27001 certification may use relevant existing certification information where the certification scope and supporting evidence adequately cover the applicable RTS security requirements.
Crossbow helps applicable remote gambling organisations assess their security environment against
the UKGC RTS security requirements and relevant ISO/IEC 27001:2022 controls. Our approach
includes defining the audit scope, identifying critical systems, assessing applicable security controls,
reviewing evidence, performing technical security assessments where applicable, identifying gaps and
findings, providing remediation guidance, and preparing the security audit report. Crossbow’s security
and compliance professionals help organisations understand their RTS requirements, prepare
the necessary evidence and address identified security gaps