An operator's cross-regulator suspension history is the most honest document the company publishes about itself. Every annual report is edited. Every marketing page is staged. The sanction register is not. If you are new to reading iGaming companies as companies — rather than as brands — start with the fines. Year one, you will not understand half the vocabulary. That is fine. The vocabulary is what this glossary is for. Read it once, then go pull the registers yourself.
Licensee Entity
A licensee entity is the specific legal subsidiary that actually holds the gambling license — not the consumer-facing brand, not the parent PLC, not the ticker symbol.
Why it matters: when a regulator sanctions an operator, it sanctions the licensee, not the marketing name. If you search for "Flutter UKGC fine" you will find nothing useful. You have to search for "Sky Betting and Gaming" or the Hillside entity or whatever the subsidiary is actually called. The marketing and the licensee almost never share a name, which is how "I thought they had a clean record" keeps happening to readers who searched the wrong string.
Concrete example: the £1.17m UKGC penalty dated 2 March 2023 that we count against Flutter Entertainment plc was issued to "Flutter UKI" as the licensee — Sky Betting and Gaming was the brand named in the scope. Same group. Different name on the enforcement notice. Bet365's UK licensee is Hillside (Shared Services) Ltd, not "Bet365". Both on the public record, both filed under names a casual reader never searches.
License Tier
A license tier is a shorthand for how much enforcement weight a regulator carries — how often it sanctions, how much it fines, how binding its rules are cross-border.
Why it matters: Tier 1 regulators (UKGC, MGA, NJDGE, AGCO Ontario in our dataset) actually move money. Tier 2 regulators exist. They publish registers. They issue licenses. What they rarely do is hit a major operator with a multi-million-pound settlement that changes compliance spending next quarter. If an operator's only license is Tier 2, the sanction history you are reading is the sanction history of a regulator that does not sanction much, which is a very different document from a genuinely clean record.
Concrete example: Entain holds UKGC (Tier 1), MGA (Tier 1), and Gibraltar GGC (Tier 2). Bet365 holds UKGC (Tier 1), MGA (Tier 1), Gibraltar GGC (Tier 2). The fines in our data — £17,000,000 and £582,120 respectively — are both UKGC actions. The Gibraltar column is empty. That is not because those books are clean. It is because the shelf does not get looked at.
Sanction Register
A sanction register is the published, searchable list a regulator maintains of enforcement actions taken against its licensees.
Why it matters: this is the primary document. The operator's annual report will summarise fines in their "regulatory matters" footnote with soft language. The regulator's register will show the amount, the date, and the scope of the failure in declarative English. The operator's summary is PR. The regulator's register is evidence. You need to read both, and when they disagree in emphasis, the register wins.
Concrete example: three Tier-1 UKGC actions sit in our dataset for operators we track. Entain, 17 August 2022, £17,000,000. Bet365 (Hillside), 12 December 2022, £582,120. Flutter UKI, 2 March 2023, £1,170,000. Three operators, one regulator, an eight-month window. Every line item is on the public record at the UKGC news URL. If you are evaluating an operator and the register lists nothing, that is useful. If it lists something, you open it and read the scope.
Regulatory Settlement
A regulatory settlement is the UKGC enforcement format in which an operator agrees to pay a penalty in lieu of a contested licensing review.
Why it matters: it is not a fine in the criminal sense and it is not a court judgment. It is a negotiated administrative action. That is what "settlement" means. The operator accepts the findings as published, pays the sum, and implements whatever action plan the Commission prescribes. There is no appeal, and there is rarely an admission of specific individual wrongdoing beyond the systems language in the notice itself. You are reading a concession, not a confession.
Concrete example: the £17m Entain action in 2022 was published by the UKGC as a "regulatory settlement for Ladbrokes and Coral" — the licensee brands, not "Entain plc" the PLC. The notice sits at gamblingcommission.gov.uk/news/article/17m-regulatory-settlement-for-ladbrokes-coral. We read the URL. You should too. The register tells you the format of the action before you even open the document, which tells you what kind of finding you are about to read.
Enforcement Scope
Enforcement scope is the specific set of failings the regulator names in the published action — the "what did they actually get fined for" line.
Why it matters: the amount tells you how much. The scope tells you why. You want to know whether the action is about anti-money-laundering plumbing (serious, systemic, hard to fix), about social-responsibility customer-interaction failures (serious, behavioural, addressable with staffing), or about something narrower like affiliate-marketing compliance. Scope is how you tell a one-off slip from a structural problem that will recur.
Concrete example: the Entain 2022 settlement was scoped by the UKGC as "failed to carry out sufficient customer interactions with high-risk players; failed to adequately identify players showing signs of problem gambling; AML controls inadequate for customers with unusual deposit patterns." Three failings, two categories (social responsibility and AML), both structural. Compare that with Flutter UKI's 2023 action, scoped as "Sky Betting and Gaming failures in social responsibility and anti-money laundering controls." Same categories. Smaller amount. Eight months later. The pattern is industry-wide, not operator-specific — which is itself a finding.
Deferred Prosecution Agreement
A deferred prosecution agreement, or DPA, is a separate legal instrument from a gambling-commission settlement. It is an agreement with a prosecutor — in the UK, the Crown Prosecution Service — to pause a criminal prosecution in exchange for payment, cooperation, and remediation.
Why it matters: this is where primary documents contradict each other in a way that matters to you as a reader. The UKGC register will show one set of Entain actions. The CPS announcements will show another. Both are operative simultaneously. Entain's 17 August 2022 UKGC settlement at £17m covers UK-licensed conduct. The 5 December 2023 DPA with the UK CPS at £585m covers the Turkey-facing business of Headlong Limited — a subsidiary Entain sold in 2017, a jurisdiction Entain never held a UK license for.
Two primary documents. Two different regulators. Two different scopes. Neither document alone explains the full picture. Read separately, they look like different companies. Read together, they are the same operator's international footprint over a decade. This is on the public record, but only if you read both shelves.
Gray Market Exposure
Gray market exposure is the percentage of an operator's revenue coming from jurisdictions where it does not hold a full local license, but has not been explicitly blocked either.
Why it matters: gray-market revenue is the single most predictive indicator we have for future sanction risk. An operator with 0% gray-market exposure has nothing to be surprised by. An operator with 20% is running a negotiation with jurisdictions that haven't decided yet how hard to push. The DPA category we just walked through is the endpoint of that negotiation going badly.
Concrete example: our dataset shows FanDuel and DraftKings at 0.0% gray-market exposure — both are US-only, fully regulated. Flutter at the group level is 5.0%. Entain is 12.0%. Bet365 is 22.0%. Bet365 serves 170 countries from Stoke-on-Trent. Flutter operates FanDuel across 22 US states plus European Tier-1 markets. The gap in gray-market exposure between the two is not an accident. It is a strategic choice with a sanction-register tail that has not finished unspooling yet.
Cross-Operator Scope
Cross-operator scope describes a regulatory mechanism that binds every licensed operator in a jurisdiction at once, not just the operator a player happens to use.
Why it matters: the default assumption — especially if you are new — is that sanctions and consumer protections apply operator by operator. Sometimes they do. Often they don't. The mechanisms that actually protect players at scale are the cross-operator ones, because a single-operator exclusion can be defeated by opening an account at a sibling brand, and sibling brands are everywhere.
Concrete example: GAMSTOP is the UK cross-operator self-exclusion scheme. A single registration blocks deposits across every UKGC-licensed online operator automatically for the user-selected period of six months, one year, or five years. 0.42 million UK users are currently registered. Portugal's RSA register, run by SRIJ, binds every SRIJ-licensed brand simultaneously. Germany's GGL system tracks combined monthly deposits across all German-licensed operators — €1,000 is the cross-operator cap, not a per-operator cap. Cross-operator scope is what gives responsible-gambling mechanisms teeth. Without it, the mechanism is a slogan.
Regulated-Markets Share
Regulated-markets share is the percentage of an operator's revenue that comes from jurisdictions where they hold a full local license. It is the counter-reading to gray-market exposure and often the number you should be looking at first.
Why it matters: an operator can report large group revenue while most of that revenue originates somewhere the regulator in your country has no visibility into. The headline number in the annual report is designed to look impressive. The regulated-markets-share number is designed to survive a regulator's cross-examination. They are rarely the same number, and the smaller one is usually the one the investor deck buries.
Concrete example: Entain's 2024 annual report puts regulated-markets revenue at 88.0% of the £4,833m group total. That leaves 12.0% from elsewhere, which reconciles with the gray-market-exposure number we cited two terms ago — same number, two directions. Flutter's reading is more complex: the group reports that 52.0% of global iGaming GGR comes from regulated markets industry-wide, not that 52.0% of Flutter's own revenue is regulated. Read the footnote carefully. Two different claims, same annual report section.
Cumulative Footprint
Cumulative footprint is the full cross-regulator, multi-year picture of an operator's sanction history — every licensee, every jurisdiction, every DPA, every settlement, read as a single biography.
Why it matters: this is the term the whole glossary has been building toward. An individual fine is noise. A pattern across years and regulators is signal. The UKGC register alone will give you one angle. Adding the CPS DPAs gives you another. Adding the MGA, NJDGE, and AGCO Ontario registers would tell you whether the operator's compliance failures cluster in one jurisdiction or run across every license they hold. Cumulative footprint is what lets you stop arguing about any one line and start reading the shape.
Concrete example: Flutter, Entain, and Bet365 all show UKGC actions in our dataset within a fifteen-month window. None of them show sanctions recorded against their MGA, NJDGE, or AGCO Ontario licenses in the same dataset. Entain carries the separate £585m CPS DPA on top. That is a specific cumulative shape: dense in UK, silent elsewhere, with one criminal-track action tied to a disposed-of subsidiary. We would revise this reading if the MGA or AGCO published enforcement registers with scope language matching the UKGC's — cross-regulator parity of disclosure. Until those registers exist with equivalent detail, the UK is where the cumulative footprint is visible, and the other Tier-1 shelves are dark. We read what we can read.