Skip to content
iGaming Times

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Lesson 7 of 7 · 14 min

Governance, Measurement and Culture

Why technically good programmes still produce enforcement cases: unresolved incentive conflict, a function without authority, and reporting that measures effort instead of effect.

In this lesson

  • Apply the three-lines model so the second line has real authority and the first line carries safer gambling objectives
  • Replace activity reporting with measures of behaviour change, recurrence and the flagged-and-not-restricted tail
  • Identify the incentive structures that reliably produce enforcement findings, and the remedies that address them
  • Read a published enforcement notice for the structural failure rather than for the penalty figure

Why good programmes fail

An operator can have accurate detection, trained agents, well-designed tools and a defensible financial risk framework, and still produce an enforcement case. The reason is almost always structural rather than technical.

Three structural failures account for most of it.

The conflict was never resolved. The same people, or the same reporting line, were responsible for growing a customer's value and for reducing their play. One of those objectives has a number attached to it and a bonus behind it. The other has a policy.

The function had no authority. The safer gambling team could recommend, escalate and document, but could not restrict an account without agreement from someone whose target the restriction would damage. Every individual decision looked reasonable. The aggregate was a customer who lost for two years while the file grew.

Nobody measured effect. Activity was reported upwards, monthly, in increasing volume. Alerts, interactions, tools promoted. The board received evidence of effort and concluded it had evidence of protection.

This lesson is about the arrangements that prevent those three, because they are what separate a programme that works from one that documents its own failure in great detail.

The three lines, applied properly

The three-lines model is standard in financial services and transfers directly.

First line: the business. Product, marketing, CRM, VIP management and customer support own the risks they create. This is the line most often treated as though it had no responsibility at all, which is exactly backwards: the decisions that create risk are made here. A product manager removing a decision point, a CRM manager designing a reactivation campaign, and an account manager offering a bonus are all making safer gambling decisions whether or not they know it.

Second line: the safer gambling and compliance function. Sets policy, defines thresholds, monitors, challenges, and holds authority to restrict. Independent of revenue, reporting to someone who is not accountable for revenue, with its own budget and its own voice at board level.

Third line: internal audit. Tests whether the first two lines are doing what they claim, independently, on a defined cycle, reporting to the audit committee rather than to management.

Two details determine whether this is real or decorative. The second line must be able to act without first-line agreement, and the path of any disagreement must be documented and visible to the board. And the first line must have safer gambling objectives in its own measures, because a function that is asked to constrain a business which is measured purely on growth will lose every contested decision and will eventually stop contesting.

Accountability at the top

Regulatory expectation in mature markets is that responsibility sits with a named individual at or reporting to board level, not with a department.

That has practical consequences. There is a person whose name is on it. That person receives information they can act on rather than a summary of activity. They have the authority to stop something. And they are the person a regulator interviews.

Board reporting is where most of this either works or does not. A board pack containing alert volumes, interaction counts and tool promotions is a board pack that cannot support a decision. A useful one contains a small number of things: how many customers were identified as at risk and what happened to them, how many were restricted and how many of those were reversed and why, what the flagged population's behaviour did after intervention, where the programme is not working and what is being done, and what the safer gambling consequences are of the product and marketing changes shipped this quarter.

The last of those is the item most often missing and the one that turns the board from a recipient into a decision-maker.

The incentive problem, stated plainly

This is the part of the subject that industry training usually avoids, and avoiding it is why so many programmes fail.

Revenue in online gambling is concentrated in a small share of customers. A subset of those customers is experiencing harm. Therefore a meaningful share of revenue is derived from harm, and reducing harm reduces revenue in the short term. Anyone who tells you otherwise is either uninformed or managing you.

The incentive structures that follow from this are where the damage happens.

VIP and account management. Historically the most consistent source of enforcement findings across mature markets. An account manager remunerated on the value of their customers, in contact with the highest-spending accounts, is the person best placed to spot harm and the person with the strongest reason not to. Published cases describe hospitality, gifts and bonuses given to customers displaying clear harm indicators. The remedies are now well established: remove commission linked to individual customer losses, require independent safer gambling sign-off before a customer enters a VIP scheme and periodically thereafter, separate the safer gambling assessment from the commercial relationship entirely, and require documented affordability evidence before high-value hospitality.

Reinvestment and bonusing. Automated systems that target offers by value will target the highest-losing customers, because that is what they are built to do. Unless the suppression list is enforced at the point of send, and unless it is tested, a restricted customer will receive a reactivation offer. This is a systems integration problem with a regulatory consequence and it should be tested like one.

Marketing suppression. The single most common technical failure in the whole field is a suppression that does not hold across every system, brand and channel, including third-party affiliate lists and re-imported segments after a migration. Test it deliberately, with a seeded account, on every channel, after every platform change.

Product incentives. Teams measured on engagement, session length and conversion are measured on exactly the things that also describe escalation. Nobody needs bad intent for this to produce harm; the metrics do it unaided.

The structural answer is not to remove commercial objectives. It is to place a hard constraint ahead of them, held by someone who does not carry them, and to make the constraint unarguable at the individual-decision level.

Measurement that means something

The measurement problem in this field is that the thing you want to measure, harm avoided, is a counterfactual you cannot observe.

That is not a reason to measure activity instead. It is a reason to be deliberate.

Reject activity as evidence. Alerts raised, interactions completed, tools promoted, training delivered. These belong in an operational report and they are not evidence of protection.

Measure behaviour change against the customer's own baseline. After an intervention, what did deposits, session length, stake and frequency do over a defined window compared with the equivalent window before? This is computable, it is honest, and almost every operator has the data.

Measure recurrence. What share of intervened customers trigger again within six months? A high rate says the intervention is not working. A very low rate, combined with continued play, may say the customer learned which behaviours trigger alerts, which is a different and worse finding.

Measure the tail. What happened to the customers who were flagged and not restricted? This is the population an enforcement action will examine, and an operator that has not looked at it will be seeing it for the first time in a regulator's letter.

Construct counterfactuals where it is ethical to do so. Staged rollouts, randomised assignment between two active intervention designs, and natural experiments created by platform changes all permit causal claims. Withholding protection to create a control group is not acceptable; comparing two genuine attempts to protect is, and it is under-used.

Report revenue derived from intervened customers. Very few operators do this and it is the number that makes the trade visible. A board that cannot see it is not making an informed decision about the programme's budget.

Testing what you believe

A programme's beliefs should be tested the way any other production system is tested.

Seed a test account and run it through the marker set to confirm alerts fire as documented. Self-exclude it and confirm, on every channel and every brand, that marketing stops and that reactivation does not occur automatically. Set a limit and attempt to raise it, confirming the cooling-off holds and that no interface prompts the increase at the moment the limit binds. Attempt to open a second account with matched identity attributes and see whether it is linked. Ask for the audit trail on a closed alert and read what an agent actually wrote.

Each of these is a test an internal audit function can run in a day, and each has been the subject of a published finding somewhere.

Culture, and how to tell whether you have one

Culture is the residue of what an organisation does when the policy is silent, and there are observable signs rather than sentiments.

Escalation happens without consequence. Staff raise concerns about customers and about commercial decisions, and nothing bad happens to them afterwards. If nobody has escalated anything upward in a quarter, that is information.

Decisions to continue are documented as decisions. Where a customer was flagged and not restricted, there is a named person and a reason, not an absence.

Product and marketing bring risk questions themselves. The safer gambling function finds out about a new mechanic or campaign before launch rather than after.

Uncomfortable numbers get reported. Revenue concentration, revenue from intervened customers, and the size of the flagged-and-not-restricted population are visible internally.

The language is accurate. Nobody in the organisation describes an ineffective interaction as a success, and nobody says "the customer confirmed they could afford it" as though it settled something.

The counter-signs are equally observable: safer gambling reported only as compliance activity, no record of a commercial decision being overturned on safer gambling grounds, and a function that has never said no to anything.

Reading an enforcement notice properly

Published regulatory decisions are the best free training material in the sector, and most people read them for the penalty figure.

Read them instead for five things. What the operator's own systems detected, and when. What the operator did in response. How long the gap between detection and effective action was. What the operator said in its defence and why it failed. And which structural feature, incentive, authority or measurement, allowed the gap to persist.

Done consistently, this produces a specific and unglamorous conclusion. The failures are rarely about not knowing. They are about knowing, acting inadequately, recording the inadequate action as complete, and having nobody positioned to notice that the customer kept losing. Every structural arrangement in this lesson exists to close one of those steps.

Where the sector actually is

It is worth ending with an honest assessment, because both the triumphant and the despairing versions are wrong.

Detection has improved substantially. Most significant operators in mature markets now run behavioural models that would have been unusual a decade ago, and the data infrastructure behind them is real.

Interaction has improved less. The gap between identifying a customer and changing what happens to them remains the weakest link, and it is where enforcement continues to concentrate.

Evaluation has barely started. Very few operators can demonstrate, with evidence a sceptic would accept, that their interventions change outcomes. That is the frontier, and the operators who get there first will have both the regulatory argument and the commercial one, because a programme that can prove it works is a programme that can be defended, funded and scaled.

Governance is the constraint on all three. An operator with excellent detection, a conflicted commercial structure and activity-based reporting will keep producing the same case. One with adequate detection, a genuinely independent second line and effect-based measurement will not.

Key terms

Three lines model
Business ownership of risk, an independent second-line function with authority to constrain it, and internal audit testing both. Decorative unless the second line can act without first-line agreement.
Revenue concentration
The pattern in which a very small share of customers generates a very large share of revenue, which places the commercial interest squarely on the accounts most likely to contain harm.
Effect-based measurement
Measuring change in the flagged behaviour after an intervention, recurrence, and what happened to customers flagged but not restricted, rather than counting alerts and interactions.
Suppression testing
Deliberately verifying with a seeded account that marketing stops across every brand, channel and third-party list after exclusion, and after every platform change.
Flagged and not restricted
The population identified as at risk on whom no restriction followed. The group an enforcement action examines first, and the one most operators have never looked at.

Key takeaways

  • The failures are rarely about not knowing. They are about knowing, acting inadequately, recording the act as complete, and having nobody positioned to notice the customer kept losing.
  • The second line must be able to restrict an account without first-line agreement, and disagreements must be visible to the board.
  • Account management remunerated on customer value is the most consistent source of enforcement findings across mature markets.
  • Report revenue derived from intervened customers. Very few operators do, and it is the number that makes the trade visible to a board.
  • Detection has improved substantially, interaction less so, and evaluation has barely started. That last gap is where both the regulatory and the commercial advantage now sit.

Check your understanding

3 questions · answer them all, then check.

  1. 1. A board receives monthly reporting on alerts raised, interactions completed and tools promoted. What is the problem?

  2. 2. Which remedy most directly addresses the VIP incentive conflict?

  3. 3. When reading a published enforcement notice, which detail is most instructive?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

Governance, Measurement and Culture - Learning hub | iGaming Times