We get a version of the same question in our reader inbox most weeks. It goes like this — *I saw a casino advertise "RTP 96.5%, independently verified," and I want to know if that number is real.* Here is what we tell those readers, and here is what the testing labs themselves publish but almost nobody clicks through to read. Verification is not a vibe check. It is a three-question flowchart, and if any of the three questions fails, the claim is not verifiable and you should treat the number the same way you would treat a number in a brochure. We will walk you through the three questions in order. Get a piece of paper. The flowchart takes about ten minutes.

This is the first fork and the one that kills most claims before any real analysis starts. There are four bodies in the English-language casino market where the certificate is a thing you can actually click on — Gaming Laboratories International, iTech Labs, eCOGRA, and BMM Testlabs. Those four publish certificate directories at `gaminglabs.com/resources/certificates`, `itechlabs.com/certifications`, `ecogra.org/certified-operators`, and `bmm.com/certifications` respectively. Those URLs are the public front doors. If a footer does not name one of them — or at minimum name some body you can look up — there is no certificate to verify. You answer this fork by reading the small print at the bottom of the casino page before you do anything else.

If Yes

Good. You have a starting point. Open the directory for the body the footer names. Search for the operator. Search for the specific game if you can. If the operator is in the directory, open the certificate PDF and take note of three fields — the date it was issued, the audit scope in the body's own words, and the list of games or products covered. Those three fields are what you will use in Question 3. Do not skip them. If the operator is *not* in the directory, do not stop — you have found a gap that Question 2 is designed to handle.

If No

Stop. You are done. A claim that a casino's games are "independently audited" with no named body is the gambling equivalent of a food label that reads "fresh" with no date. There is nothing to test against. We see this pattern most often on operators that do not carry tier-1 permits from the UKGC or the MGA — the operators in our coverage who do carry those permits (Flutter, Entain, Bet365) all run named-body certifications on their certificate pages. If a claim is made without a named body, the most defensible reading is that the claim is marketing language, not a verifiable fact.

Question 2: Is the Operator Actually in the Directory of the Body They Named?

Here is the assumption worth checking — that naming a body is the same as being certified by that body. It is not. And here is where we want to concede the strongest point the skeptical side has, because we owe the concession before we run the teardown.

The testing labs are real. GLI's audit scope is on the public record and it is rigorous — RNG statistical randomness tests using NIST 800-22 protocols, game math verification against paytable specification, and RTP empirical validation across ten million simulated rounds. iTech Labs audits quarterly per deployed game, re-certifies the RNG seed annually, and runs a 48-hour incident re-audit protocol if a player raises a dispute. eCOGRA runs a seal program plus player dispute mediation. BMM tests RNG, RTP, geolocation compliance, and responsible gaming system integration. These are not rubber stamps. These are documented protocols executed by engineers. We concede that the testing layer is real without reservation.

What we do not concede is that the existence of the testing layer means any given footer claim is backed by it.

If Yes

If the body is named and the operator is listed in the public directory, you are in the part of the flowchart where verification is actually possible. Open the certificate and check the date against the body's own cadence. For iTech Labs the published cycle is quarterly per deployed game with annual re-certification of the RNG seed, which means a cert older than a few months is outside the body's own window. For other bodies, check the cadence on the directory before trusting a cert from a prior year. If the certificate in hand is older than the published cadence, the claim is legally alive but materially stale. Proceed to Question 3.

If No

If the body is named but the operator is not in the public directory, you have found the gap. There are two readings. Reading one is that the operator was certified in the past and has since been removed — this happens, and it tells you something about the operator's current compliance posture. Reading two is that the footer is borrowing a body name as marketing decoration without the body having certified the operator for what the footer implies. Both readings mean the same thing for your purposes — do not treat the footer claim as verified. The slow, correct move is to email the body directly through the contact page on their public site. Most readers will not bother. If you are about to deposit real money, bother.

Question 3: Does the Certificate Scope Actually Cover the Game You Are About To Play?

This is the fork where the real work happens and where almost every marketing claim walks into a wall. A certificate has three scope dimensions. The first is the game itself — a specific title, a specific version, a specific math model. The second is the operator deployment — which server, which jurisdiction, which config. The third is the date relative to the body's audit cadence. All three have to match for the footer number to be defensible.

The grounding on this is not speculative. NetEnt publishes a slots RTP range of 94.00 to 96.70 percent. Play'n GO publishes 94.20 to 96.50. Pragmatic Play publishes 94.00 to 97.00. The range is the point. When a casino footer quotes "96.5%" as the headline number and that number happens to sit near the top of the studio's published range, you are looking at the best-case deployment, and you cannot verify that your specific version on your specific operator is running that variant unless the certificate names the operator, names the game, names the deployment jurisdiction, and was issued inside the audit window.

Live dealer works the same way with different numbers. Evolution's live blackjack publishes an RTP of 99.28 percent. Evolution's European roulette publishes 97.30 percent. Those figures are game-math numbers for Evolution's own live tables, not per-operator certificates. A casino that cites those numbers under a "verified" header without a cert covering that specific deployment is pointing at a real studio-level math claim dressed up as an operator-level audit. The difference is the whole article.

If Yes

If the certificate scope matches the specific game, the specific operator, and sits inside the body's published audit window, you have done the work a compliance analyst would do before writing about this operator. The RTP number is a real number backed by a documented protocol. Treat it as one datum, not the whole picture. It tells you the long-run mathematical edge built into the game across millions of rounds. It does not tell you anything about your next hundred spins, and it does not override the ordinary variance of a short session. Verification and prediction are different jobs. You have done verification. Do not mistake it for prediction.

If No

If the scope does not match — the certificate is for a different version of the game, a different operator deployment, a different jurisdiction, or was issued outside the body's own audit cadence — the footer is making a claim the certificate does not support. This is rarely outright dishonest. It is almost always imprecise in a direction that favors the operator. The casino is pointing at a real cert on a real body's directory and letting the reader assume the cert covers what the reader is about to play. It often does not. The correct reading of this outcome is that the number on the footer is a studio-level claim worn as an operator-level claim, and you should price it accordingly when you decide whether to deposit.

If You Answered Everything

Here is the recap you can write on the back of an envelope and keep next to your laptop. There are four answer combinations and each one maps to a specific recommendation.

Q1 yes, Q2 yes, Q3 yes — the RTP claim is verifiable and you have verified it. Treat the number as a real long-run edge figure. It is not a prediction of your session and nothing on this flowchart makes it one.

Q1 yes, Q2 yes, Q3 no — the certificate is real but the scope does not cover what the footer implies. This is the most common outcome we see in practice and it is where the bulk of operator marketing lives. The claim is technically true at the studio level and materially misleading at the operator level. You can still play, but do not tell yourself the number has been audited against your specific deployment, because it has not.

Q1 yes, Q2 no — the body is named but the operator is not in the public directory. This is a gap. Email the body through the contact page on their public site. If you are not willing to email the body, treat the claim as unverified and make your deposit decision on that basis.

Q1 no — the footer does not name a body. There is nothing to verify. Do not treat the claim as factual. This is not a judgment on whether the operator is trustworthy overall. It is a judgment on this specific claim, which is unbacked, and the operator could fix it on the next site deploy if they chose to.

A note on where this flowchart breaks down, because the reason the reader has to run a flowchart at all is that the primary documents are scattered. The testing labs publish their directories. The listed operators publish their annual reports — Entain's 2024 annual report is on the public record at `entaingroup.com/media/rxvjyk42/entain-plc-ar24.pdf`, filed on 6 March 2025, showing group revenue of £4,833m and 28m active customers. Flutter's equivalent sits at `flutter.com/investors/results-centre`, filed on 4 March 2025. These filings tell you the operator is big, profitable, and regulated. They do not tell you whether the RTP number on the footer of a specific game is backed by a current certificate covering that specific deployment. That link does not exist in the filings and it does not exist in any regulator register we have been able to find.

We would reverse our position on this entire flowchart if the UKGC, the MGA, or any of the four tier-1 English-language regulators published an operator-by-operator, game-by-game, date-stamped RTP register that aggregated every recognized test house's output into one searchable public directory. Until that register exists — and right now it does not — the burden of verification sits with the reader. The labs have done their part. They publish directories. They publish protocols. They publish audit cadences. What nobody has built is the public layer above them that maps every footer claim on every licensed operator to the specific certificate that backs it. Until that layer exists, the three questions above are the flowchart. Work it top to bottom. If any fork fails, the claim is not verifiable, and you should read the number the same way you would read a number in a press release.