UK Gambling Regulator Puts Operators’ Vulnerability Checks Under the Microscope
The Gambling Commission will examine 2025 to 2026 checks, testing whether operators treated debt signals proportionately.
Remote casino, betting and bingo operators serving Great Britain will face a new evidence test in October 2026. The Gambling Commission will ask how they applied financial vulnerability checks during the 2025 to 2026 financial year.
This is not a new customer-check requirement. It is a data-gathering exercise. Operators will have three weeks to respond, and the findings could shape future customer-protection oversight.
What the Commission wants to know
The regulator will examine how operators applied the checks, how many customer accounts were affected and what action followed when financial vulnerability was identified.
The Commission’s previous data collection covered operators representing about 90% of Great Britain’s remote gambling consumers. The sample included both larger and smaller businesses.
- How operators applied the checks.
- How customers were affected.
- What operational problems or unintended consequences emerged.
- Whether operators took proportionate action when risk indicators appeared.
These checks are not affordability assessments
Under Licence Condition 3.4.4 of the Licence Conditions and Codes of Practice, operators must use customer-specific public records to identify significant signs of financial vulnerability.
The information can include:
- Bankruptcy orders.
- County Court Judgments.
- Individual Voluntary Arrangements.
- High Court judgments.
- Administration orders or decrees.
- Debt Relief Orders.
The checks are separate from financial risk assessments. They do not give operators access to a customer’s bank account, salary or private credit file as part of the vulnerability check.
The current trigger applies when deposits minus withdrawals exceed £150 in a rolling 30-day period. The threshold fell from £500 on February 28, 2025.
Why the data matters
The Commission’s May 14, 2026 review found that implementation was not fully consistent. Some operators appeared unclear about what data a vulnerability check could contain.
The regulator also warned that an automated response to a single County Court Judgment could create unnecessary friction. A CCJ may involve serious debt, but it may also concern a smaller amount or a disputed bill.
The practical question is not simply whether a risk flag exists. It is what the operator does with that information, and whether the response matches the level of risk.
What could change after October
The October request will not change licence conditions by itself. It could give the Commission a stronger basis for future guidance, compliance action or changes to how operators record and review decisions.
Operators must already consider vulnerability information alongside other customer information, take proportionate action and record the reason for that action.
Licence breaches can lead to:
- A licence review.
- Suspension.
- Revocation.
- A financial penalty.
The process applies to remote businesses licensed for the Great Britain market. Northern Ireland has a separate gambling framework and is not regulated by the Gambling Commission in the same way.
A wider regulatory push
The data exercise arrives as the Commission develops separate financial risk assessments for a much smaller group of high-spending customers. In July 2026, the regulator said those assessments would be introduced in stages after consultation and pilot work.
That distinction matters. The October request tests an existing public-record check. It does not mean that the wider financial risk assessment system has been imposed on every online casino customer.
For operators, the next test is administrative as much as technical. They will need to show that checks were run, staff understood the limits of the data and decisions were recorded clearly.
The central issue is proportionality. A debt marker can signal financial difficulty, but it is not automatically proof of gambling harm.