Online casino operators licensed in New Zealand will need independent certification of their games and platforms within six months of receiving a licence, and at least once a year after that, under draft technology rules from the Department of Internal Affairs (DIA).
The DIA released the discussion draft, Testing and Monitoring Requirements for Online Casino Gambling Technology, in the same week it opened the auction for up to 15 online casino licences on 29 September. The document sets out how operators will be tested, certified and monitored under the Online Casino Gambling Act 2026.
Auction follows the EOI stage
The auction follows an Expression of Interest (EOI) stage that ran from 17 July to 14 August 2026, in line with the DIA’s plan to start licensing in July 2026. The DIA describes the format as an ascending clock auction.
No single operator can hold more than three licences, and Entain has said it is targeting three. Licences run for an initial term of up to three years, with one renewal of up to five years.
Winning bidders then move to a full application. It must include a business plan and separate strategies for advertising and marketing, consumer protection, harm prevention and minimisation, and compliance.
Certification before the licence
The technology draft adds a pre-licence checkpoint. Applicants must submit a Game and RNG Register showing that every game they plan to offer, live dealer titles included, and every Random Number Generator (RNG) has been tested by an approved independent laboratory.
The draft names three approved labs: GLI Australia, Quality Assurance Laboratories and BMM Australia.
Certification from other regulated markets can count. Testing already carried out elsewhere may be accepted for existing games, RNGs, live dealer operations and underlying platform systems, if it gives enough assurance against New Zealand’s requirements. The draft names testing done for the United Kingdom and Ontario, Canada, as potentially applicable.
Applicants must also disclose their critical technology providers and the locations of their data centres or cloud hosting. They need evidence of ISO 27001 certification or equivalent assurance. ISO 27001 is the international standard for information security management systems.
Executive sign-off at launch
When a licence commences, the operator must file an updated Game and RNG Register. Its CEO or Chief Compliance Officer must then confirm that the operator’s technology complies with the requirements.
That confirmation covers third-party technology, infrastructure, operating systems, databases and gaming software. Operators running white-label platforms or aggregated content from several B2B suppliers will need assurance from each provider before an executive signs.
Ongoing monitoring and change control
The draft requires ongoing monitoring of operators’ systems and Return to Player (RTP) performance, the share of stakes a game pays back to players over time. Operators must keep documentation of all testing carried out and run periodic vulnerability scans and penetration tests on their platforms.
Any new game or RNG added after launch needs external testing. Existing games and RNGs must be retested when a change affects, or may affect, fairness.
Changes that do not affect fairness can generally be tested in-house, provided the operator keeps strong development, testing and release controls. The draft lists six:
- source-code security
- version control
- access controls
- segregation of duties
- peer review
- separate development, testing and production environments
What comes next
The requirements remain a discussion draft. For bidders, the technology costs come on top of the community funding requirement the government announced for online casino operators in December 2025.
Once the auction closes, winning bidders move to full applications, and the six-month certification deadline runs from the date each licence is granted. The DIA expects the regulated system to be fully operational in 2027.
Source: Department of Internal Affairs
