VendorLens

    For iGaming operators

    An operator due-diligence checklist for iGaming software suppliers

    A structured checklist and a lightweight vendor risk scoring model for reviewing studios, platforms, payments and infrastructure suppliers before integration and at renewal.

    No signup required. Same template used across the iGaming cluster.

    The review checklist

    Four areas to work through with a new supplier, and to revisit on a set cadence afterward. Adjust depth by the supplier's access to player data and systems.

    Company and legal review

    • Confirm legal entity, registered address and corporate structure
    • Confirm licensing status relevant to the markets you operate in
    • Review the master services agreement and liability terms
    • Confirm insurance coverage where your policy requires it

    Security and technical review

    • Request ISO/IEC 27001 or equivalent certification evidence
    • Request the latest penetration-test executive summary
    • Review encryption, access-control and logging practices
    • Review architecture and integration documentation

    Privacy and data-handling review

    • Review the data processing agreement and lawful-basis position
    • Review the subprocessor list and notification process for changes
    • Confirm data-residency and cross-border transfer mechanisms

    Resilience and ongoing monitoring

    • Review business-continuity and disaster-recovery commitments
    • Confirm incident-notification expectations and escalation contacts
    • Set a review cadence for re-checking evidence after go-live

    A lightweight vendor risk scoring model

    This is a qualitative starting point, not a certified methodology. Use it to sort suppliers into "review now" versus "monitor" buckets, then apply your own formal risk framework where one exists.

    FactorLower-risk signalHigher-risk signal
    Independent security attestationCurrent ISO/IEC 27001 or SOC 2 report available on requestNo independent attestation, or evidence is significantly out of date
    Access to player or personal dataNo direct access, or access is narrowly scoped and documentedBroad or unclear access to player data with no documented controls
    Subprocessor transparencySubprocessor list published and kept currentNo subprocessor list, or list is not maintained
    Incident-response readinessDocumented policy with named escalation contactsNo documented policy or unclear escalation path
    Business continuityDocumented recovery objectives and tested continuity planNo documented continuity or recovery plan

    Requesting evidence from a supplier

    Where a supplier publishes a VendorLens trust center, public information such as company overview, markets served and certifications held is visible immediately. Restricted documents — audit reports, penetration-test summaries, architecture detail — sit behind a request that the supplier's team reviews and approves manually before releasing a time-limited, watermarked file, with the release recorded in their audit log.

    That workflow speeds up assembling evidence for the checklist above; it does not replace your review of what the evidence shows.

    What VendorLens does not do

    VendorLens helps present, request and control access to evidence that suppliers and operators already maintain. It does not issue licences, certify games, perform security audits, score risk on your behalf, provide legal advice, or replace regulatory submissions or your internal due-diligence process. Document access requests are reviewed and approved manually by the publishing organisation, there is no per-section visitor analytics, and each account publishes one trust page.

    Questions about operator due diligence