Skip to content

What an effective internal audit actually looks like in iGaming

Opinion

This article is an opinion piece by Robert Penfold, Head of Internal Audit at eGaming Integrity.

I recently wrote about why internal audit in iGaming is still misunderstood. The question I’ve heard most often since that was published is this: what does it look like when it’s done well?

It is a fair question, and in my experience, an effective internal audit rests on four things. Risk, process reality, ownership, and follow-through. What matters in practice is whether the audit changes how the business operates or simply becomes another report sitting on a shelf.

That matters because a lot of weaknesses in iGaming only become visible once something has already gone wrong.

The audit starts before the checklist arrives

An effective audit does not begin with a checklist. It begins with asking where the business is most vulnerable today.

In practice, pressure points are usually found wherever the business has moved quickest. That could be a new market launch, a major supplier change, or a new regulation in a core market. Governance rarely catches up straight away when businesses are under pressure to move fast. That is often when the process on paper starts drifting from operational reality.

I have seen operators grow quickly while AML and financial crime controls struggled to keep pace behind the scenes. Customer due diligence and transaction monitoring processes were still in place, along with restrictions around higher-risk customers, but once onboarding pressure increased, they were not always being applied as consistently as people believed. That usually becomes much harder to defend once regulators start asking questions.

That scoping conversation matters as much as anything that follows. Before a review begins, I want to understand what the business has been dealing with over the past 12 months. What is changing now, and what is keeping people awake at night? Frequently, that last question is when people start to say what is actually bothering them. Most already know where the pressure points are.

A well-run internal audit starts by listening to that, not by arriving with a predetermined list of things to check.

The document said it was controlled. The process told a different story

Documentation review is a starting point, not a method.

The most useful information comes from spending time with the people who actually run the processes. I want to see how the work gets done on a normal day, then test what happens when it comes under pressure.

If you only reviewed the paperwork, nothing looked obviously wrong. The procedures were there, and the process had been documented properly enough. Day to day, though, too much relied on one person keeping everything moving in the background. Once they stepped away, the process started unravelling far quicker than anyone expected.

That kind of weakness rarely stays hidden for long in fast-moving businesses. Deadlines get tighter, communication between teams starts slipping, and rushed decisions expose the parts of a process that were never especially stable to begin with. In one instance, a breakdown between marketing and IT led to a rollout failure.

The question I am always testing is whether a control works consistently, not just whether it exists. If a process depends on a specific individual or only holds up when there is time to think, it will not hold up when the business needs it most.

The risks operators outsource but rarely audit

A control environment is only as strong as the third parties embedded within it. In iGaming, that is part of the day-to-day operating reality.

Operators outsource heavily. Payments, KYC and AML tooling, fraud systems, safer gambling technology, platform infrastructure, sportsbook feeds, and game studios. Each of those relationships carries risk. Most operators assume those risks are adequately managed. Many have not tested that assumption in any meaningful way.

What I look for is not whether a contract exists. It is how the relationship is actually managed day to day. Is performance monitored? Do any issues that surface get escalated? Does anyone in the business genuinely own that third-party relationship, or is it assumed to be running on its own?

Most third-party relationships do not fall apart because of a badly written contract. The bigger problems usually appear later. Communication weakens over time, responsibilities become less clear, and smaller issues stop getting escalated before they turn into something more serious.

A contract tells you what was agreed to and what was signed on paper. What it does not tell you is how that relationship is working in practice, who owns it, and how fast issues are identified when something goes wrong. In iGaming, the knock-on effect from that can spread quickly.

The report landed. Nothing changed.

More often, the audit itself is not the issue. The problem starts afterwards, once the findings have been written up and the report stops getting attention.

A lot depends on how those findings are explained. Boards and senior leadership do not need audit terminology. They need to understand what a finding means for them. What regulatory exposure it creates, what reputational risk it carries, and what operational weakness it exposes. Once it is explained in those terms, it becomes much harder to ignore.

Raising issues as they emerge during the audit, rather than saving them for the final report, makes them much easier to address. By the time findings are documented, they should already be understood by the people who need to act on them. There should be no surprises in the report if anything in the process has not worked.

Ownership matters here, too. If nobody is clearly responsible for fixing it, and there is no realistic timescale, the issue usually goes nowhere. The audit has not finished when the report is written. It has finished when the business understands what needs fixing and who is responsible for putting it right.

Culture is a control too

In organisations where internal audit works well, people do not avoid the audit team. They raise issues earlier, ask questions more openly, and bring problems forward before they become harder to manage. That does not happen by accident. It develops over time, depending on whether internal audit is viewed as constructive or just another exercise in paperwork and blame.

Independence does not mean distance. It means being able to tell people when something is not working, even when that is uncomfortable, and not letting commercial pressure get in the way. Boards and senior leaders rarely need reassurance. They need to know where things stand.

Done well, an internal audit gives leadership an honest view of how the business is running before a regulator or an incident brings the issue to the surface. In a sector moving at this pace, with scrutiny only increasing, leadership cannot afford to find out about weaknesses through enforcement action.

In iGaming right now, by the time someone outside the business spots the problem, you are already on the back foot.

 Robert Penfold is Head of Internal Audit at eGaming Integrity. He has extensive experience in internal audit, governance and risk across the gaming and financial services sectors.

The views expressed are those of the author and do not necessarily reflect the views of the SiGMA News editorial team.

Manila’s calling and it’s not whispering. From 31 May to 03 June 2026, SiGMA Asia returns to the undisputed regional heavyweight. With 16,000 delegates, 3,040 operators, and 250+ speakers under one roof, this isn’t just an expo. It’s ignition!