ISO 27001 for online casinos: how to pass a PSP security review
PSP security reviews are not a one-time gate - they are a recurring obligation. This guide explains the evidence pack an online casino must maintain to satisfy PSP, scheme, and regulator demands across the relationship lifecycle.
By Kellwick Team · July 31, 2026 · 6 min read
Online casinos learn quickly that acquiring payment service providers do not treat security reviews as a one-time onboarding formality. A PSP security review can land at the start of a relationship, at annual renewal, after a security incident anywhere in the payments ecosystem, after a scheme (Visa, Mastercard) audit cycle update, or simply because the PSP's own compliance team has updated its questionnaire. For a casino operator that has not maintained a live evidence pack, each of these events is a scramble.
ISO 27001 certification - or a credible readiness posture working toward certification - provides the most robust foundation for satisfying these rolling demands. It also narrows the scope of what a PSP can legitimately ask for, because the certification demonstrates that an independent third party has already assessed the controls in question. But the certification alone is not the answer. PSPs want to see the evidence underneath it.
Why PSP security reviews are different from a standard vendor questionnaire
A standard vendor security questionnaire asks whether controls exist. A PSP security review frequently asks for proof that they operate as described, and does so with a level of specificity that reflects the PSP's own scheme compliance obligations.
The PSP is not just managing its own risk. It is satisfying a scheme requirement - typically PCI DSS at the acquiring side - that obligates it to perform due diligence on merchants in higher-risk categories. Online gambling is almost always in that category. This means the PSP's questions about access controls, incident response, and fraud monitoring are not generic: they reflect the scheme's requirements mapped back onto the merchant's environment.
The implication for a casino operator is that the evidence pack needs to address not just ISO 27001 controls but the practical security outcomes those controls produce: who has access to payment data, how incidents are detected and reported, how fraud controls are tuned, and how the casino's suppliers (payment aggregators, KYC providers, wallet integrators) are themselves assessed.
The access control evidence layer
Access to payment-related systems is the first area a PSP review will probe. The questions typically cover: who can access the casino's payment administration panel, how those accounts are provisioned and de-provisioned, whether multi-factor authentication is enforced, and when the access list was last reviewed.
The evidence expected includes an access control record for payment admin systems (role, individual, provisioning date, last review date), an MFA configuration screenshot or policy extract, and a de-provisioning log showing that leavers' access was removed promptly. For operators using a payment orchestration layer or a shared PSP dashboard, the evidence needs to cover access to those interfaces as well as to any internal systems that connect to them.
A common gap is access to production credentials - API keys, webhook secrets, payment gateway credentials - that live in a shared password manager or, worse, in a configuration file in a code repository. The access evidence needs to account for these credentials as well as user accounts.
Supplier assurance: the PSP wants to see your supply chain
An online casino's payment flow typically involves multiple parties beyond the acquiring PSP: a payment orchestration layer, one or more alternative payment method providers, a KYC/AML engine, and potentially a fraud scoring service. The PSP will ask how the casino assesses the security of these suppliers.
The evidence expected is a supplier register that identifies each supplier touching payment or player data, a classification of each supplier by criticality and data type, and a record showing that due diligence was performed - either by reviewing the supplier's own certification (ISO 27001, SOC 2, PCI DSS) or by sending a questionnaire with a dated response on file.
For game providers and aggregators connected directly to the platform - an area covered in depth separately - the same logic applies: each supplier that can influence the integrity of player funds or personal data needs a due-diligence record.
Incident response: what the PSP needs to see before an incident happens
PSPs typically require confirmation that the casino has an incident response plan and that it includes notification obligations to the PSP itself. The evidence layer here includes the incident response policy (referencing the PSP as an external stakeholder to be notified), a test or exercise record showing the plan was tested in the last 12 months, and a notification matrix identifying who within the casino and within the PSP organisation is contacted in the event of a payment-related security incident.
The notification matrix is frequently missing. Operators often have a generic incident response plan that references "relevant stakeholders" without naming the PSP contact or specifying the timeframe. PSPs - particularly those with scheme-mandated incident notification obligations - want to see their own notification requirements reflected explicitly.
A representative evidence pack for the incident section includes: the incident response policy with a PSP notification clause, the last table-top exercise agenda and outcome summary, and the external notification contact list with named PSP contacts and agreed notification timescales.
Fraud monitoring evidence: operational controls the PSP wants confirmed
A PSP onboarding an online casino will typically ask about fraud monitoring: what transaction monitoring is in place, how thresholds are set, who reviews alerts, and how often the configuration is reviewed. This sits partly in a payments fraud domain and partly in the ISO 27001 world of A.8.16 (monitoring activities) and A.5.25 (assessment and decision on information security events).
The evidence expected includes: a description of the transaction monitoring tool or rules engine in use, a record showing that alert thresholds were last reviewed and by whom, and a log of fraud-related alerts or cases reviewed in a recent period. For casinos with high transaction volumes, a summary report rather than the full alert log is typically sufficient, provided it is dated and shows that review activity occurred.
Maintaining the evidence pack as a live asset
The challenge for casino operators is not building the initial evidence pack - it is keeping it current. PSP reviews arrive at unpredictable intervals, and the evidence pack assembled for onboarding 18 months ago will not reflect the current access control state, the current supplier list, or the updated incident response contacts.
A practical approach is to treat the evidence pack as a section of the ISMS document set with its own review cadence - quarterly for access lists and supplier registers, annually for the full pack - rather than as a one-off deliverable. The same review cycle that satisfies ISO 27001 surveillance audit requirements will, if structured correctly, also keep the PSP evidence pack current.
Specific items that decay fastest between reviews: leaver access that was removed in the directory but not yet reflected in the access register; API credentials rotated without updating the credential inventory; new suppliers added without going through the due-diligence process; and incident response contacts at the PSP that have changed without anyone notifying the casino's security team.
Where Kellwick fits
Kellwick advises online casino operators as an independent ISO 27001 readiness advisory - not a certification body - helping operators build and maintain the evidence pack that PSP reviews, scheme audits, and certification assessments all draw from the same source. Kellwick works through the evidence layer practically, identifying gaps before a PSP review surfaces them. If your operator needs a structured readiness review ahead of a PSP onboarding or renewal, our iGaming readiness service is the starting point.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.