The problem changes shape at scale
One licensed market is a project. Eight are an operating model, and the failure modes are different.
With one market, the compliance function knows everything about it. With eight, nobody holds the whole picture, the reporting calendar has something due most weeks, the key persons are spread thin, and a change in one market's rules arrives while three other things are in flight. Operators that scale badly do so by repeating the single-market approach eight times, which produces eight policy sets, eight reporting builds and a compliance team that is entirely reactive.
What follows is the structure that makes the eighth market cheaper than the second.
Policy architecture: core plus overlay
The single most valuable structural decision is to stop writing a policy per market.
The core policy states the group's position on a subject: the standard applied everywhere, the principles, the roles, the escalation, the record-keeping. It is written once and it is usually stricter than the least demanding market, because a single group standard that meets the highest common requirement is cheaper to operate than eight different ones.
The market overlay states only what that jurisdiction requires in addition or in variation: thresholds, timescales, registers to check, reports to file, local terminology and the local regulator's specific expectations. It should be short, and if an overlay is longer than the core, either the core is too thin or that market is genuinely exceptional.
Two benefits follow. A change in the group standard propagates once. And an auditor or a regulator asking how a control works in their market gets a two-document answer rather than an archaeology exercise.
The failure to avoid is a core policy so general that the overlays carry all the content. That is eight policies with a shared cover page.
The compliance calendar
Every market brings recurring obligations: duty returns, regulatory data submissions, licence fee payments, annual returns, key person attestations, policy review dates, audit cycles and certification renewals.
At eight markets this is dozens of dated obligations a year, and missing one is a finding regardless of how minor it is. Late filing is the most avoidable enforcement outcome in the sector.
A functioning calendar has, for each obligation: the market, the obligation, the legal basis, the deadline, the owner by name, the preparer, the reviewer, the system it comes from, and the evidence of completion. It is reviewed weekly. Ownership is a person, not a team.
This sounds administrative because it is, and it is also the first thing a supervisor tests when they want to know whether a compliance function is in control.
Regulatory change monitoring
Rules change constantly: tax rates, advertising restrictions, product limits, reporting requirements, responsible gambling obligations. Most changes arrive with a consultation, a decision and an implementation window, and the window is usually short.
A monitoring function needs four things.
Sources. Regulator publications and newsletters, official gazettes, local counsel, trade associations, and industry press. For markets where you have material revenue, local counsel on a retainer is cheaper than discovering a change late.
Triage. Someone assesses each change for materiality and routes it. Most changes need no action; the ones that do need an owner immediately, because the implementation window has already started.
An implementation route. A change that requires a product, platform or reporting change needs to reach the engineering backlog with a regulatory deadline attached, and it needs to outrank commercial work. Operators without that route discover, repeatedly, that the deadline arrived and the change did not.
A record. What changed, when, what was assessed, what was done, and by whom. This is the evidence that the function is operating, and it is what you produce when asked why a control changed.
The highest-value extension is horizon scanning: watching consultations rather than only decisions, which converts a three-month implementation problem into a twelve-month one and occasionally lets the operator contribute to the outcome.
Centralise or localise
Every function has to be placed somewhere, and the trade-off is consistency and cost against local knowledge and responsiveness.
Centralise well: platform and product engineering, data and reporting infrastructure, the core policy framework, financial crime analytics, group risk assessment, and the certification relationship. These benefit from a single implementation and suffer from duplication.
Localise well: the regulator relationship, customer support, marketing and affiliate management, complaints and local dispute resolution, statutory filing and local audit, and interpretation of local rules. These depend on language, relationships and context that do not travel.
Genuinely contested: responsible gambling interaction, which needs local language and local rules but benefits from a consistent standard and shared analytics; and AML case review, where local knowledge helps and consistency of decision-making matters more.
The failure modes are symmetrical. Over-centralisation produces a group standard that is wrong in six markets and an escalation queue nobody local can resolve. Over-localisation produces eight incompatible implementations, no comparability, and a group that cannot tell which market has a problem.
Key persons and the load problem
Licences attach personal responsibility to named individuals, and the same individual frequently holds roles in several markets.
That creates a real constraint. A nominated officer responsible for financial crime across six jurisdictions is personally exposed in six, has six sets of rules to know and six regulators to answer to, and has a finite amount of attention. Regulators have become noticeably less willing to approve individuals with heavy multi-market loads, and an individual's departure can jeopardise licences in several markets simultaneously.
The structural answers are deputies approved in advance, documented succession, and a deliberate decision about how many markets one person can properly cover. The last is a judgement, and the honest version is that it is fewer than most groups assume.
Group-level data
Two capabilities separate a group that can manage its portfolio from one that manages eight separate businesses.
Identity resolution across brands and markets. One person may hold accounts across several of the group's brands, and every control computed per account sees a fragment. This is entirely within the group's own power to fix, it is a data engineering problem rather than a regulatory one, and it is unresolved at more operators than anyone would like to admit. It affects responsible gambling, financial crime and fraud simultaneously.
Comparable metrics across markets. The same definitions for revenue, customers, intervention rates, alert volumes, complaint rates and closure quality, so that a market performing badly is visible. Where each market defines its own numbers, the group cannot rank its own problems.
Portfolio management
The final discipline is treating markets as a portfolio rather than a collection of commitments.
Review each market periodically against the case that justified entering it: revenue, contribution after local costs, compliance load, regulatory trajectory and strategic value. Classify each as invest, maintain, or exit, and hold the classification to evidence.
Exit is the decision groups find hardest, for reasons that are human rather than analytical. Somebody championed the entry. Somebody built the team. The sunk cost is visible and the ongoing cost is diffuse. Meanwhile the compliance burden of a small market is close to the burden of a large one, so a marginal market consumes attention out of all proportion to its contribution, and attention is the scarce resource in a multi-market compliance function.
The operators who scale well are not the ones who enter the most markets. They are the ones who built the structure that makes each additional market cheap, and who were willing to leave the ones that were not working while it was still a decision rather than a rescue.