GLI-33 certification lifecycle + audit. CERTIFICATION LIFECYCLE: (a) INITIAL CERTIFICATION - operator submits system + documentation + test data + scoping document to GLI (or other accredited testing laboratory - e.g. BMM Testlabs + Eclipse Compliance Testing + iTech Labs + Quinel + others); GLI conducts source code review + functional testing + security testing + load testing + integration testing; typically 6-12 weeks + scope-dependent; report issued + signed off by state regulator; (b) ONGOING SURVEILLANCE - annual or biennial review + sample-testing + integrity-monitoring; regulator-driven; (c) RE-TESTING ON CHANGE - software changes triggering 'material' scope require re-testing + new certification report; emergency-change handling; change-management notifications; (d) DECOMMISSIONING - data retention + customer-account-transition + regulator-notification. AUDIT FREQUENCY: typically annual full audit + quarterly + monthly internal compliance reviews + continuous integrity-monitoring. AUDITORS: GLI is the primary certification body but state regulators also engage independent auditors for ongoing compliance audits (SOC 2 + ISO 27001 + state-specific gaming audits). CHANGE-MANAGEMENT: change-control board + regulator-notification timelines + GLI re-certification triggers (UI + UX changes typically no re-cert; logic + odds + payment + KYC + AML + responsible-gaming changes typically do; security + crypto + RNG + integrity changes always do). LICENSING + LIABILITY: separately licensed operator + supplier + master license framework; bond + capital requirements + insurance; regulator-mandated annual financial + technical attestation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.