For iGaming operators
A structured checklist and a lightweight vendor risk scoring model for reviewing studios, platforms, payments and infrastructure suppliers before integration and at renewal.
No signup required. Same template used across the iGaming cluster.
Four areas to work through with a new supplier, and to revisit on a set cadence afterward. Adjust depth by the supplier's access to player data and systems.
This is a qualitative starting point, not a certified methodology. Use it to sort suppliers into "review now" versus "monitor" buckets, then apply your own formal risk framework where one exists.
| Factor | Lower-risk signal | Higher-risk signal |
|---|---|---|
| Independent security attestation | Current ISO/IEC 27001 or SOC 2 report available on request | No independent attestation, or evidence is significantly out of date |
| Access to player or personal data | No direct access, or access is narrowly scoped and documented | Broad or unclear access to player data with no documented controls |
| Subprocessor transparency | Subprocessor list published and kept current | No subprocessor list, or list is not maintained |
| Incident-response readiness | Documented policy with named escalation contacts | No documented policy or unclear escalation path |
| Business continuity | Documented recovery objectives and tested continuity plan | No documented continuity or recovery plan |
Where a supplier publishes a VendorLens trust center, public information such as company overview, markets served and certifications held is visible immediately. Restricted documents — audit reports, penetration-test summaries, architecture detail — sit behind a request that the supplier's team reviews and approves manually before releasing a time-limited, watermarked file, with the release recorded in their audit log.
That workflow speeds up assembling evidence for the checklist above; it does not replace your review of what the evidence shows.
VendorLens helps present, request and control access to evidence that suppliers and operators already maintain. It does not issue licences, certify games, perform security audits, score risk on your behalf, provide legal advice, or replace regulatory submissions or your internal due-diligence process. Document access requests are reviewed and approved manually by the publishing organisation, there is no per-section visitor analytics, and each account publishes one trust page.
Continue exploring related solutions, industries and comparisons.