What does non-intrusive monitoring mean for iGaming operators?

By Chantelle Turton, Regulatory Compliance Manager
Chantelle Turton explains how non-intrusive monitoring works and what operators can learn about supplier risk without disrupting the relationship.
Operators need to know what is happening across their supplier relationships after the initial due diligence is complete. Getting that information does not always require another questionnaire or another request for documents.
That is where non-intrusive monitoring comes in.
Non-intrusive monitoring checks information already available for changes, without needing to contact the supplier. It forms part of ongoing monitoring and helps establish whether anything has changed since the last review.
Because the iGaming sector is predominantly centred on online activity, a substantial proportion of due diligence and ongoing monitoring can be done through publicly available information. That might include licensing or regulatory status, company information, sanctions or adverse media.
If those checks identify a change that needs further explanation, the operator can then go back to the supplier for confirmation or supporting evidence.
Supplier oversight doesn’t always need another questionnaire
Questionnaires have a place in supplier oversight, particularly when an operator needs information that only the supplier can provide. They add less value when they are sent routinely just to check whether anything has changed.
Operators may routinely ask suppliers to confirm a number of things that can often be checked independently first. Company registries may provide ownership and directorship information, while licensing information can often be checked directly with the relevant regulator. Sanctions, PEP and adverse media screening can also be carried out independently.
These checks may identify changes in ownership or management, licensing status, regulatory action, sanctions exposure or other information that could affect the supplier’s risk profile.
That does not mean the operator will have everything it needs to complete the relevant compliance checks. If a company registry shows that a new director or shareholder has been appointed, the change can be identified independently, but the operator may still need due diligence documents for the new individual. A change in ownership may also require an updated register of members and supporting documents.
The supplier still needs to be contacted where information is not publicly available or where the circumstances behind a change need to be understood. A change in business model, a move into a new jurisdiction or a new product may all require the supplier to explain what has changed and provide evidence of the controls it has in place.
When supplier contact is actually needed
Having independent information can make the conversation with the supplier much more focused. Where a specific change is identified, the operator can ask for clarification or documents around that point rather than sending a general request for an update.
If a company registry shows that a shareholder has sold their shares, for example, simply asking for an updated ownership structure may not tell the whole story. The operator may also want to understand why the shares were sold, who acquired them and whether the outgoing shareholder still has any influence or effective control over the business.
A supplier may need to confirm that there have been no material changes or provide evidence that cannot be obtained elsewhere.
That gives both sides a clearer reason for the conversation. The supplier knows what is being asked for and why, while the operator can focus on the information it actually needs.
Assessing the impact on supplier risk
When you identify a change, the wider context matters. The operator needs to consider what the change relates to, how recent it is, whether it can be clearly linked to the supplier or an associated individual, and whether it has any relevance to the services or jurisdictions involved.
For example, if adverse media appears against someone with the same name as a director, that should not automatically be treated as an adverse finding. Other identifiers such as date of birth, nationality, location and company associations can help establish whether the information relates to the same individual.
The same principle applies to licensing. If a supplier’s licence appears to have expired, the first step is to establish whether it has been renewed, is under renewal or whether the supplier has obtained a licence elsewhere.
The operator needs to work out what the information actually means for the supplier and whether it changes the risk assessment once the wider context is understood.
Non-intrusive does not mean passive
There is a risk that “non-intrusive” could be misunderstood as meaning less monitoring, when it is more about how the information is obtained. The level of oversight should still be based on the supplier's risk and the services it provides. Suppliers should also be expected to provide information or documentation where required as part of compliance reviews.
Active oversight also means having processes in place to identify and act on trigger events rather than simply waiting until the supplier’s next scheduled review.
Non-intrusive monitoring forms part of the wider supply chain assurance process. Onboarding establishes the initial risk, ongoing screening helps identify changes as they arise, non-intrusive monitoring provides an independent review of the supplier’s current position, and direct communication allows the operator to obtain information that cannot be independently verified.
Together, these provide a more complete picture of the supplier and allow the level of assurance to remain proportionate to the risk.



