This article is an opinion piece by Robert Penfold, Head of Internal Audit at eGaming Integrity.
Internal audit has been part of iGaming for years, yet it is still not used as the practical management tool it should be. In fast-moving businesses, it is often treated as something to complete, rather than something to rely on when decisions are being made.
As Head of Internal Audit at eGaming Integrity, which works with regulated operators on internal audit and governance, my experiences tell me that when an internal audit is conducted properly, it gives boards and senior leadership a clear view of how the business actually operates, where risks are developing, and whether controls will stand up when the pressure is on.
When business grows faster than its governance
Most issues I have seen in regulated gaming businesses do not arise because people set out to do the wrong thing. They arise because controls drift over time, responsibilities blur, or the business grows faster than its governance. By the time a regulator becomes involved, the problem has usually been there for a while. An internal audit earns its value by surfacing those issues early. That makes it easier to address problems before they affect reputation.
One reason I see internal audit struggling to gain traction in some organisations is that it is seen as theoretical or a block to doing business. Auditors review policies, map frameworks, and draw conclusions without enough attention to the practical workings of the business. In iGaming, that approach rarely holds up. iGaming moves fast. Many operators also rely heavily on third parties. Scrutiny is increasing around areas such as player protection, anti-money laundering and governance. Controls that look reasonable on paper fail quickly when no one embeds them properly or takes clear ownership.
What I look for in an internal audit is a focus on reality, not documentation. I focus on how people make decisions, how teams raise and handle risk, and whether the right information reaches the right people at the right time. This tests whether controls operate consistently, not just whether they exist. If a process only works when certain individuals are involved, or only works when there is time to think, it is not robust.
Focusing on what carries the greatest exposure
In practice, the most effective internal audits are rooted in risk and focused on what carries the greatest exposure. That means spending time with the people who run key processes, walking through how work is done day to day, and testing whether controls operate as intended when they are under pressure. Reviews that rely too heavily on documentation or frameworks rarely surface where risk truly sits.
Risks most often sit within fast-growing operations due to the failure to identify errors within the development cycle. If these errors are identified prior to release, then the impact would be primarily restricted to the cost of rework and potential delays in reaching the market. Where failures go unnoticed, this could potentially cause both reputational and regulatory issues.
In my experience, transparency makes a real difference. Internal audit works best when people don’t see it as a surprise or a scoring exercise. Raise issues and discuss as they emerge. Don’t save them for the end of a review. Teams should already agree on what they have identified and why it matters before documenting findings.
Raising issues with team members as the audit progresses allows the audit team to ensure that it has fully understood the issue, as well as allowing management to consider early solutions.
‘Tough conversations’
Independence is essential. Internal audit only adds value when it can speak plainly, including when conclusions are uncomfortable. In practice, that means acknowledging commercial realities without allowing them to dilute findings. Boards and senior leaders rarely need reassurance. They need an honest picture of where things stand. An audit function that avoids tough conversations quickly loses its purpose.
Used well, an internal audit does not slow organisations down. It helps management stay in control as businesses grow and change. Operators who take it seriously tend to spot problems sooner. That makes regulatory issues easier to handle when they arise.
Internal audit is about understanding how the business really works. It also means challenging assumptions and making sure governance and controls keep pace as organisations grow. In iGaming, pace and scrutiny leave little room for weak controls or unclear ownership.
— Robert Penfold is Head of Internal Audit at eGaming Integrity. He has extensive experience in internal audit, governance and risk across the gaming and financial services sectors.
The views expressed are those of the author and do not necessarily reflect the views of the SiGMA News editorial team.
Stay ahead of iGaming’s biggest stories with SiGMA’s Top 10 News countdown. The world’s biggest iGaming community brings you weekly insights and subscriber-only offers. Join HERE today.