We have the certificate scope in front of us. It is the Gaming Laboratories International certificate index, and the RNG scope line reads: statistical randomness tests under NIST 800-22, game math verification against paytable specification, and RTP empirical validation across 10M simulated rounds. That is what a GLI RNG certificate actually covers, on the public record. The vendor pitch that opens this piece — a jackpot aggregation tool "taking all the needs" of a licensed operator — sits above that scope. The gap between the marketing claim and the primary document is where the buyer's due diligence has to live. Three questions, in order, decide the outcome.

Question 1: Does the Tool's Certification Scope Match the Marketing Claim?

Here is the thing nobody in the vendor's Malta booth will tell you. A GLI certificate does not certify a "jackpot aggregator." It certifies an RNG. It certifies specific game math against a specific paytable specification. It certifies RTP across a fixed simulation count. The scope is narrow because that is how testing labs write scope — narrowly, so their liability is bounded.

When a founder tells you their product "takes all the needs" of the operator, the first move is to ask which needs the certificate actually covers. Not the sales deck. Not the trade-press quote. The stamped scope line on the PDF the lab published.

We have written before that certification scope is where the story lives. It is worth repeating because operators keep buying integration on the strength of a logo rather than the strength of the scope note under the logo.

If Yes: The certificate scope matches the pitch

You are in the rare case. The vendor has a certificate that names the jackpot mechanic, the pooled prize distribution logic, and the operator-side reporting layer. That is the shape of a scope that supports a "one tool, all needs" claim in the narrow sense of provable game integrity.

Even here, do not stop. The certificate covers the math. It does not cover payments, KYC handoff, session-limit enforcement, self-exclusion register integration, or the specific German cross-operator deposit tracking that the GGL published on the public record. Those are separate compliance surfaces. "All needs" as a phrase is doing a lot of work. Buy on the certified layer. Contract separately for the rest.

If No: The certificate scope is narrower than the pitch

This is the common case. The certificate covers a subset — usually RNG and RTP on a specific list of games — and the marketing claim covers the operator's entire jackpot lifecycle from configuration through payout reconciliation.

Here is what we recommend. Ask the vendor, in writing, for the exact certificate reference number, the issuing lab, and the scope wording. If the answer takes longer than a business day, that is signal. Reputable labs publish their scope wording; the vendor should be able to send you the PDF within an hour. When the scope does not cover a piece of what the tool does, you own that gap. Your regulator will read it that way in an incident review.

Question 2: Does the Operator's Own License Tier Actually Permit the Tool's Feature Set?

This is where operators lose money without knowing they are losing it. You buy a tool that is technically compliant with the vendor's Malta license and you integrate it under your UK license, and eight months later the UKGC publishes a settlement that says your social-responsibility interaction cadence did not meet the operator obligation. The tool did what it was sold to do. Your license did not permit you to run it that way.

The UKGC public register lists 268 licensed online operators. Every single one of those permits carries a specific set of Licence Conditions and Codes of Practice attachments. When the Commission fined the Ladbrokes and Coral brands £17m in August 2022, the settlement statement was blunt about the mechanic. The failures, on the public record, included insufficient customer interactions with high-risk players and inadequate identification of players showing signs of problem gambling. The technology existed. The permit required its active use. The operator's implementation did not close the gap.

A jackpot aggregator that lets a player chase a pooled progressive across sessions is a features that raises the interaction threshold under a UKGC permit. It does not raise the same threshold under a Curacao license. Same tool. Different obligations. The permit decides.

If Yes: Your permit covers the feature set the vendor is offering

Read your LCCP attachments and the vendor's technical spec side by side. If the spec includes forced session breaks, deposit-limit propagation, and reality-check triggers at the 60-minute default cadence that Flutter documents in its annual report, and your permit's Social Responsibility Code Provision requires all three, you are aligned.

The tool is doing the work your permit requires. The vendor's marketing claim survives this layer of the pass. Move to Question 3.

If No: Your permit requires more than the tool provides

Then the "all needs" claim breaks here, not at the certification layer. And this is worse for the operator, because the shortfall is enforceable against your license, not the vendor's.

Two primary documents matter for the compare. Entain's 2024 annual report discloses that 88 percent of group revenue comes from regulated markets — that is the operator side saying, in the audited filing, that they cannot afford compliance drift. The UKGC's own enforcement notice against Flutter's UKI licensee, a £1.17m settlement on 2 March 2023, cites Sky Betting and Gaming failures in social responsibility and anti-money laundering controls. Both documents are operative. The annual report says compliance is a fiduciary duty. The enforcement notice says the Commission will price the failure. You do not want to be the third document that links them.

If your permit demands more than the tool provides, you either negotiate the vendor into building the gap into the spec — with a written amendment — or you split procurement. One vendor for the jackpot math. Another for the compliance overlay. It is more expensive. It is also the version that survives an audit.

Question 3: Does the Vendor's Compliance Layer Survive a UKGC-Style Interaction Audit?

This is the question most operators skip because it is the hardest to answer without breaking the sale. The pitch presents a compliance layer as a bullet in the deck. The audit asks whether that layer would survive the same reading the Commission gave Sky Bet in early 2023 or Ladbrokes Coral in August 2022.

Here is what a UKGC-style interaction audit actually looks like. Regulators pull sample player accounts flagged by internal risk scoring. They read the interaction log against the risk marker. They look for the specific evidence that a human intervened, that the intervention was appropriate to the risk signal, and that the outcome was documented. When the regulator finds the interaction cadence too low, or the intervention too generic, or the outcome under-documented, the settlement follows. The mechanism is boring. It is also the whole game.

For a jackpot aggregation tool, the risk-signal question is specific. Progressive jackpots produce chase behaviour. A player who was betting at £2 stakes for six months, hits a losing sequence on a progressive, and doubles to £4 to catch a top-tier trigger is showing a pattern the risk model should catch. If the vendor's compliance layer does not surface that pattern to the operator's SRC team in real time, the operator carries the gap.

Ask the vendor to walk you through, on a screen share, exactly how their tool surfaces a session where the player's stake velocity exceeds their 30-day baseline by 200 percent. If the answer is "we log it in the reporting layer, and the operator's team reviews it in the daily batch," that is not a UKGC-grade interaction. That is a paper trail. The Commission has fined operators for exactly this cadence gap.

If Yes: The compliance layer produces real-time risk surfacing

Then you have a tool that can hold up under the audit shape the Commission actually runs. The vendor's "all needs" claim starts to earn the phrase — not because the tool covers every operator need in the abstract, but because it covers the ones the regulator will price on your permit.

Even in this branch, verify. Ask for two things in writing. First, the vendor's own incident register — how many times has the compliance layer surfaced a high-risk pattern to an operator client, and how did that operator respond? Second, whether any of the vendor's operator clients have appeared on the UKGC public register enforcement section in the last 24 months. If yes, that is not automatically damning. What the vendor tells you about how they iterated after that client's settlement — that is the signal.

If No: The compliance layer is a report, not an intervention

Then the "all needs" claim fails at the third layer, and this is the failure that is most likely to end in an enforcement notice against you rather than against the vendor.

The recommendation here is uncomfortable. Do not sign. Or if commercial pressure demands you sign, split the compliance overlay to a specialist vendor whose product exists specifically to raise the interaction cadence to real-time. The specialist vendor will cost you a mid-five-figure annual fee. The absence of one will, on the pattern of the last four years of UKGC settlements, cost you a mid-seven-figure regulatory settlement plus the reputational tail.

If You Answered Everything

Here is the routing table. Read across your three answers. The recommendation cell is the honest read.

Q1: Cert scopeQ2: Permit fitQ3: Compliance layerRecommendation
YesYesYesSign. Document the certificate reference numbers and permit alignment in your procurement file.
YesYesNoSign the game-integrity layer only. Contract a specialist compliance overlay separately.
YesNoYesNegotiate a written spec amendment closing the permit gap before signing. Otherwise walk.
YesNoNoDo not sign. The permit gap plus the compliance gap is a two-front audit exposure.
NoYesYesAsk for the exact certificate scope PDF. If it arrives and matches, sign narrow. If not, walk.
NoYesNoDo not sign. The certification gap alone is enough; the compliance layer is the second reason.
NoNoYesDo not sign. Two failures on the primary layers cannot be fixed by a strong compliance overlay.
NoNoNoWalk. The pitch survives none of the three questions.

One paragraph of context on the table. Rows where Q1 and Q2 both fail are terminal — those combinations exist in the market because founders sell aspirationally and buyers under-read the certificate scope. The rows that matter for negotiation are the mixed cases. Yes on certification with a permit gap is the most common shape a real vendor will walk you into, and it is the one where a written spec amendment can rescue the deal. Insist on the amendment. Insist on the exact scope wording. Both belong in your regulator-facing procurement file, because they are what an enforcement register review will read first.

What This Piece Does Not Cover

This is the honest scope note. This piece does not address the specific commercial terms of jackpot pool contribution splits between operator and vendor, which is a separate negotiation that turns on player-fund treatment and jurisdictional tax residency. It does not cover the German GGL cross-operator deposit tracking mechanic in the depth that a live integration requires — the €1,000 monthly cap is documented in the primary source but the technical integration path deserves its own case study. And it does not cover the GAMSTOP scheme integration requirement for a UKGC-licensed jackpot aggregator, which is a specific 420,000-user register the operator must consult on every deposit attempt. Each of those is a separate piece.

FAQ

What is a jackpot aggregator in the sense the vendor is using it?

A jackpot aggregator pools progressive prize funds across multiple operators or game providers so that a top-tier prize accumulates faster than a single-operator progressive could sustain. The vendor's marketing typically claims the tool handles game integration, prize-pool math, payout reconciliation, and compliance surfacing in one platform. The scope of what any specific product covers depends on its certification and the operator's own licensing obligations, not on the pitch.

Why does the certification scope matter so much?

Because the scope is what a regulator will read after an incident. A GLI RNG certificate covers statistical randomness testing under NIST 800-22, game math verification, and RTP simulation. It does not cover payment orchestration, KYC, or session-limit enforcement. If the vendor sells the tool as covering "all needs" and the certificate covers only the RNG layer, the operator inherits every gap between those two positions. That is a compliance exposure priced in mid-seven-figure enforcement settlements, on the public record.

How do I read a UKGC enforcement notice for procurement due diligence?

Focus on three sections. First, the specific control failures cited — the 2022 Ladbrokes Coral settlement named customer interaction cadence and AML controls, not brand-level negligence in the abstract. Second, the remediation the Commission required. Third, the settlement figure as a percentage of the operator's regulated-markets revenue. Reading these three lines tells you which control gaps the Commission will price, and by how much. Then you check the vendor's tool against those same three gaps.

If the certificate scope is narrow, is the vendor lying?

Not necessarily. Vendors describe their product in commercial language because that is how sales works. A narrow certificate with a broad marketing claim is a signal to do more diligence, not automatically evidence of misrepresentation. The test is whether the vendor will put the scope wording in writing when asked. If yes, you can negotiate around the gap. If the answer stalls, that is when the pattern starts to look like something the public register would want to know about.

Does an MGA license substitute for a UKGC license for the same tool?

No. The MGA and UKGC operate different licensing frameworks with different technical standards, different social-responsibility codes, and different enforcement postures. A tool certified for MGA deployment may not meet UKGC LCCP requirements for the same operator category. Cross-jurisdictional integration requires the vendor's spec to be tested against each permit separately. This is why 88 percent of Entain's regulated revenue, in the group's 2024 filing, sits across multiple jurisdictional stacks — each of which is contracted separately.

What is a written spec amendment and why does it matter?

A written spec amendment is a signed addendum to the vendor contract that adds specific capabilities to the delivered product, with acceptance criteria the operator can test. It matters because verbal assurances from a vendor sales team do not survive a regulator's document request. When the Commission asks how the operator ensured the tool met the LCCP requirement for real-time interaction cadence, the answer needs to be a paragraph and an appendix, not a memory.

How often should I re-audit the vendor's certification?

Match the audit frequency to the vendor's lab cadence. Some labs run quarterly per deployed game and annual re-certification for RNG seed, with 48-hour incident re-audit if a dispute is raised. If your vendor's lab cadence is materially slower than that, the gap is your procurement risk. Ask for the cadence in writing before signing, and diarise the renewal dates in your compliance calendar.

What happens if I sign and the vendor's tool fails a UKGC audit?

The permit sits with you, not the vendor. The Commission's settlement will be against your operating company, priced against your revenue, and disclosed on the public enforcement register with your brand named in the notice. You may have contractual recourse against the vendor, but the enforcement action lands on you first and the recourse recovery is a separate multi-year commercial dispute. This is why the three questions in this piece are worth asking before the signature, not after.