The contract is an operating decision, not a line item
A supplier contract in iGaming rarely stays a procurement line for long. Platform, aggregator, payment, CRM, KYC and sportsbook partners set your learning speed, your margin, the player experience and your regulatory exposure long after launch. The real test is narrow: can a provider run the operating model you expect to keep for the next 12-24 months without manual workarounds? A low setup fee turns expensive the moment data is locked away, reports refuse to reconcile, or every small change needs a support ticket.
Weighting shifts by category, but four linked questions decide approval for every supplier. Can it deliver the promised experience at the scale and in the GEOs you actually target? Does contribution margin survive fees, bonuses, taxes, payment costs and support effort? Will your teams own the data, controls and decisions needed to improve the product? And can it withstand a regulatory inquiry, an outage, a fraud event or a change of strategy? A vendor that passes only the first is not approval-ready: it can demo a flawless lobby and still fail the other three.
Write the operating problem first
Answering those four questions is impossible until you name your own problem. Generic RFPs invite generic claims (configurable bonuses, broad game access, real-time reporting, dedicated support) and none of them proves your constraint is solved. Name the constraint before you book a demo. A new casino may need a fast licensed-market launch, local payment methods, controlled bonus eligibility and dependable withdrawal messaging; an incumbent may need independent lobby ranking and player-level data; a sportsbook may need in-play availability and settlement accuracy far more than another thousand pre-match markets.
Then write the operating model down: GEOs, products, licences, traffic shape, internal capabilities, decision rights, non-negotiable controls and the economics that actually matter. Doing so exposes false comparisons. A single-market casino vendor may not fit a multi-brand plan, and a lower revenue share can lose to a pricier option that lifts deposit success. "Choose a platform" is not a decision; "choose a provider for our licensed mobile casino launch that preserves data access and a defined withdrawal SLA" is.
Match diligence gates to provider type
With the operating model written down, the gates can be tailored to it. A master template helps, but each category needs its own gate, because the dependencies differ.
| Provider category | Primary diligence question | Hidden failure mode |
|---|---|---|
| Platform or PAM | Can teams configure product and operations without queues? | Customisation becomes a permanent services bill |
| Game aggregator | Does the catalog improve discovery and margin in target GEOs? | Catalog size masks weak availability or provider terms |
| Payments partner | Can deposits and withdrawals perform by method and market? | Approval rates hide costly routing or delayed payouts |
| CRM or CDP | Can the operator segment, suppress, test and measure? | Events and consent records are incomplete |
| KYC or AML vendor | Can checks meet obligations without blocking valid players? | Manual-review backlog undermines activation |
| Sportsbook supplier | Can it hold availability, pricing and settlement trust? | Market depth fails under live-event stress |
Score every feature against that operating model and give it an operational owner: product wants lobby control, finance wants daily reconciliation, compliance wants immutable audit trails, support wants clear withdrawal and KYC status. Promotional tooling is not bonus-cost control unless CRM can limit offers by GEO, payment method, player value, responsible-gambling status and fraud score.
Where demos mislead
Owners assigned, the next risk is trusting what you are shown. Demos show the happy path. Ask every vendor to run the awkward scenarios instead: an interrupted deposit, a disputed settlement, a failed KYC, a duplicate-account flag, a game outage, a bonus complaint, an account-closure request. Finance should follow one transaction from payment request through the ledger, PSP settlement and operator report; compliance should see case history, rules and evidence export; support should see exactly what a player is told while a withdrawal is pending.
Test elapsed time and ownership, not just capability. "The provider can configure it" means little without who does it, your approval rights, the lead time and out-of-hours handling. Discount any sandbox for its clean data and absent third-party latency, then ask for production incident reports and references in comparable markets. Turn each claim into an acceptance criterion: a "personalised lobby" means you set ranking objectives, exclusion rules, experiment groups and player-level event exports without waiting on a vendor release.
Reading margin behind the rate card
Capability tested, the economics decide whether it is worth it. Rate cards charge revenue share on GGR or NGR, or a fee per transaction, active player, game round or managed-service hour, often with minimum commitments. On top sit payment routing, game fees, data-access charges, support tiers, custom development and exit fees. Model contribution margin on your expected mix, never assume two vendors define NGR the same way, and settle every metric (GGR, bonus cost, payment fees, tax, chargebacks, NGR) so that provider, finance and BI reconcile before launch rather than after the first dispute.
Read the clauses that move the number: the minimums and their triggers; any exclusivity, preferred-supplier or volume-routing terms; the fees for extra GEOs, brands, currencies, extracts or API calls; the change-request rates and where configuration ends and custom work begins; and the termination assistance, data export, transition support and residual fees. A minimum makes sense only when committed resource replaces internal cost; it harms you when it penalises delay or forces volume through a weak supplier. Compare contribution margin by cohort and GEO, not the quoted percentage, and confirm in writing your right to export raw events, player history, ledgers and configuration both during the contract and at termination: "access" too often turns out to mean a dashboard or a slow extract.
Controls that stay with the operator
Whatever the margin looks like, some responsibilities never move to the supplier. Outsourcing never transfers your accountability for player protection, data, AML, marketing or records. Working with legal and compliance counsel, map regulatory-readiness evidence to each licence and GEO, then validate role permissions, audit trails, retention, interventions and evidence preservation. Responsible-gambling limits, time-outs, self-exclusion, marketing suppression and risk markers have to propagate across every system; a delay or mismatch here is a safety and compliance failure, not a cosmetic bug.
| Risk area | Control to validate | Failure to avoid |
|---|---|---|
| Responsible gambling | Cross-system suppression, audit logs, intervention ownership | Promotional contact after restriction or exclusion |
| KYC and AML | Evidence capture, case workflow, escalation records | Review queue hidden by pass-rate reporting |
| Fraud | Explainable signals and manual review | Automated declines blocking valid high-value players |
| Data privacy | Processing agreement, subprocessor register, deletion support | Data retained after contract end |
| Operational resilience | Tested incident and communication plan | No owner for player-facing outage messages |
One caution: do not ask a vendor to reveal the fraud rules that protect its own defences. Ask instead for governance evidence, false-positive management, review ownership and anonymised incident examples, enough to test the controls without writing an abuse manual.
Service quality after go-live
A smooth launch does not prove an operating partner. Pressure-test the weekend payment incident, the major sporting event, game downtime, compliance escalations and withdrawal backlogs. Demand measured evidence with definitions attached: an uptime figure means little if it quietly excludes degraded functions, unavailable payments or repeated market suspensions. SLAs should track player harm and commercial damage, because delayed reporting is not the same failure as a broken withdrawal, a dead lobby or a self-exclusion that did not fire. Pin down severity levels, response and restoration targets, service credits and post-incident review, then confirm support coverage, languages and configuration knowledge. An acknowledgement can satisfy a first-response SLA while the problem stays live, so measure meaningful-resolution time, recurrence, and the hours your own team spends chasing cases.
Score evidence, weight the gates
All that testing has to resolve into one comparable view. Weighted scoring should record evidence, not manufacture precision. Give each criterion an owner, a source, a confidence rating and a red flag, and make licensing, privacy, responsible-gambling, financial-viability, security and exit-right controls pass/fail, so a strong low-risk feature can never offset a failed gate. Score five kinds of fit separately, so a strong showing in one can never quietly cover a gap in another:
- Commercial fit: contribution margin that survives the real mix of fees, bonuses, taxes and support effort.
- Data fit, where your teams own raw events, history and configuration instead of renting them back through a dashboard.
- Product depth in the exact GEOs you target, rather than an impressive aggregate catalog.
- Operational fit: can routine changes ship without joining a support queue?
- Service quality under stress, tested on the weekend outage and the disputed settlement, not the clean demo.
Then challenge those assumptions in a decision meeting.
Run a red-team review led by someone outside the selection, tasked with attacking the forecasts, the roadmap promises and the subcontractors behind them. Match references to your GEO, vertical, regulation, scale and maturity (a small social-casino reference does not validate a regulated real-money launch) and make a point of speaking with a customer who migrated away, not only a new one, because departures are what reveal whether exit support and portability actually work.
Prove the choice in 90 days
After signing, test the agreed controls against production conditions and record any unmet acceptance criteria. The first 90 days run as a fixed sequence:
- Before go-live, assign owners, baselines, review dates and escalation paths for the whole period.
- Track payment success by method and GEO, withdrawal completion, cost per successful transaction, failure reasons and complaints; configuration time, launch defects, data latency and support resolution; and, for CRM, control-group lift, bonus-to-GGR, incremental NGR and suppression accuracy.
- Compare cohorts by source, payment method, first product and lifecycle stage instead of judging on GGR alone, since RTP variance, campaign timing, VIP activity and temporary bonuses all distort a short window. A better FTD paired with worse second-deposit conversion is not sustainable value.
- Hold a monthly review on incidents, SLAs, reconciliation, roadmap and complaints, and escalate repeat breaches before the workarounds harden into permanent cost.
Turn assurances into a signed register
The strongest provider is rarely the one with the longest feature list or the slickest demo. It is the partner whose product, economics, evidence and service fit your strategy while leaving you able to control the experience, protect customers, reconcile money and change course. Before approval, your executives should be able to state the dependency they are accepting, the margin after every deduction, the data they can retrieve, the controls they can audit and the exit route they can use. Where sales assurances still stand in for contractual rights and tested evidence, the diligence is not finished.
Convert each promise into a signed acceptance register: requirement, evidence, owner, deadline, measurement method and remedy. It protects the launch, fixes accountability, and gives supplier management something to stand on long after the ink dries.