Supplier assurance for game providers and aggregators under ISO 27001
Game providers, KYC engines, and payment aggregators all sit in the supplier risk perimeter of an iGaming ISMS. This guide covers how to classify critical vendors, set a due-diligence cadence, and produce the evidence an auditor expects.
By Kellwick Team · August 3, 2026 · 6 min read
For an online casino or sports betting operator, the supplier list is not a peripheral concern. Game providers render content inside the operator's platform, often with deep API integration. KYC and AML engines process player identity data. Payment aggregators touch transaction flows. Affiliate platforms receive marketing data and player referral records. Each of these relationships represents a risk transfer point - data or control leaves the operator's perimeter - and ISO 27001 requires that transfer to be governed.
Annex A control A.5.19 through A.5.22 cover information security in supplier relationships. The standard requires a policy, a process for classifying and assessing suppliers, contractual security requirements, and monitoring. In an iGaming context, the supplier landscape is large, varied in criticality, and frequently changes as operators add content providers or swap KYC vendors. The evidence challenge is building a supplier assurance process that can absorb that churn without falling apart between annual audits.
Classifying suppliers: the foundation of proportionate due diligence
Not every supplier warrants the same level of scrutiny, and treating all suppliers identically - either by demanding full questionnaires from a minor SaaS tool or by applying the same light-touch review to a game aggregator processing live player funds - misallocates effort and creates evidence gaps in the wrong places.
A practical classification model for iGaming operators uses two axes: data sensitivity (what player or financial data does the supplier touch?) and integration depth (how deeply is the supplier embedded in the platform?). A supplier that sits entirely outside the data perimeter and cannot influence platform integrity - for example, a social media scheduling tool used by the marketing team - is low criticality. A game aggregator with a direct API connection into the casino backend, serving real-money game sessions, is high criticality regardless of its public security reputation.
Typical high-criticality supplier categories for an online casino include: game content providers with direct RGS (Remote Gaming Server) integration; payment service providers and acquirers; KYC, identity verification, and AML screening engines; responsible gambling tools with access to player behaviour data; and any managed service provider with administrative access to production infrastructure.
Medium-criticality suppliers typically include affiliate platforms, CRM systems holding player contact data, customer support tooling, and fraud analytics platforms that receive transaction data but do not process payments directly.
Due diligence for game providers: what the evidence needs to show
Game providers present a specific challenge. A major content aggregator may supply hundreds of game titles under a single contract, and the aggregator itself sources content from dozens of studios. The ISO 27001 question is not just "have we assessed the aggregator?" but "does our assessment of the aggregator give us sufficient assurance about the studios behind the content?"
Practical due diligence evidence for a game provider or aggregator includes: a copy of the supplier's current ISO 27001 certificate or equivalent (PCI DSS AOC, SOC 2 Type II report), confirmation that the certificate scope covers the services being provided (a certificate covering only the aggregator's corporate network does not cover the RGS infrastructure), and a review record noting the certificate expiry date and any significant scope limitations.
Where a supplier does not hold a recognised certification, the due diligence record needs to include a completed security questionnaire with a dated response, a risk assessment note documenting the identified gaps, and any mitigating controls the operator has put in place (contractual security requirements, right-to-audit clauses, enhanced monitoring).
The contractual evidence layer matters as well. Auditors will ask whether supplier contracts include information security requirements. A supplier contract that contains a data processing agreement under GDPR but no reference to security breach notification timescales or the supplier's obligation to maintain security controls is a gap.
KYC and AML engine due diligence: data sensitivity at the highest tier
KYC and AML engines receive some of the most sensitive data in the iGaming supply chain: passport scans, proof of address documents, source of wealth documentation, and PEP/sanctions screening results. These suppliers sit at the highest criticality tier, and the due diligence cadence and evidence standard needs to reflect that.
Annual due diligence is the minimum for KYC suppliers. Evidence should include the supplier's current ISO 27001 or SOC 2 certification, a data processing agreement that meets GDPR Article 28 requirements and specifies sub-processor obligations, and a record of any security incidents the supplier reported in the preceding 12 months with confirmation of how those incidents were resolved.
For operators subject to UK Gambling Commission or MGA requirements, the regulatory expectation around KYC supplier governance aligns closely with the ISO 27001 supplier assurance requirement. A well-constructed supplier assurance record for a KYC vendor can serve both the ISO 27001 evidence need and the regulatory audit requirement simultaneously, provided it is structured to address both sets of questions.
Affiliate platforms: the under-assessed category
Affiliates and affiliate management platforms are frequently the lowest-priority item on the supplier assurance list, yet they receive player referral data, marketing click data, and sometimes deposit bonus tracking data that links directly to player accounts. A breach at an affiliate platform can expose player email addresses and account identifiers at scale.
The due diligence standard for affiliate platforms does not need to match the standard applied to payment processors, but it cannot be zero. A minimum evidence record includes: classification of the affiliate platform as medium-criticality, a data processing agreement confirming the platform's GDPR obligations, a review of the platform's publicly available security documentation (privacy policy, security page, any available certifications), and a note on the data fields shared with the platform and the basis for sharing them.
For operators using large affiliate networks (those aggregating hundreds of individual affiliate relationships), the due diligence record for the network itself needs to address how the network manages its own affiliate partners' data handling.
Setting a due diligence cadence that holds up under audit
The most common finding in supplier assurance reviews is not that initial due diligence was never done - it is that the due diligence was done at onboarding and then not repeated. An auditor asking "when did you last review this supplier's security posture?" expects an answer measured in months, not years.
A cadence that works for most iGaming operators: high-criticality suppliers reviewed annually, with a triggered review if the supplier announces a significant security incident, acquires or is acquired by another business, or materially changes the scope of the services provided. Medium-criticality suppliers reviewed every 18 to 24 months. Low-criticality suppliers reviewed at contract renewal.
The evidence for the cadence is a supplier register with columns for classification, last review date, next scheduled review date, and review outcome. The register itself is reviewed by the ISMS owner at least annually and sign-off is documented in the management review record.
The supplier register as a live document
Supplier registers decay. Operators add new game providers without going through the due-diligence process because the commercial relationship moved faster than the security team. A new KYC vendor is onboarded in a hurry to satisfy a regulatory deadline and the supplier assurance questionnaire is marked as "pending." Six months later an auditor finds a high-criticality supplier with no due-diligence record.
The fix is process rather than documentation: the supplier assurance step needs to be a gate in the procurement or vendor onboarding workflow, not a retrospective exercise. A simple approval requirement - no new supplier contract signed until the security team has completed a classification and either collected a certificate or issued a questionnaire - creates the paper trail and prevents the backlog.
For iGaming operators with a high volume of game provider additions (common on aggregator platforms), a tiered shortcut is reasonable: if a new studio publishes content exclusively through an already-assessed aggregator and the aggregator's contract covers sub-supplier security obligations, the operator can document reliance on the aggregator assessment rather than conducting a full independent review of each studio.
Where Kellwick fits
Kellwick provides independent ISO 27001 readiness advisory to iGaming operators, working through supplier assurance as part of a structured ISMS gap assessment. Kellwick reviews the full Annex A supplier control set in the context of the operator's actual supplier landscape, not a generic template. If your supplier register needs a structured review before your next audit or PSP assessment, our iGaming readiness service is the place to start.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.