1. Core principle
accountability
Outsourcing a function does not outsource responsibility. NGA licensees remain accountable for outcomes, records, and user experience, regardless of how many vendors sit in the stack.
Rule of thumb: If a vendor fails, the licensee must still be able to explain what happened.
2. Identify critical outsourced functions
mapping
Maintain a clear inventory of all third parties and classify which are critical.
| Function | Examples | Why critical |
|---|---|---|
| Platform core | Game engine, wallet logic, transaction processing | Failure stops operations entirely |
| Hosting | Cloud infrastructure, data centres, CDN | Availability, data integrity, latency |
| Game providers | Third-party games, RNG services | Fair play, uptime, settlement accuracy |
| Payments | PSPs, payout partners, processors | Funds access and user trust |
3. Due diligence & onboarding
before reliance
- Understand the vendor’s role, limitations, and dependencies.
- Assess operational maturity, security posture, and continuity planning.
- Confirm ownership of data, logs, and reports.
- Ensure exit rights and data portability are documented.
4. Contractual minimums
SLAs & rights
- Defined service scope and responsibilities.
- Availability and performance commitments.
- Incident notification timelines.
- Access to logs, records, and reports.
- Termination and transition assistance clauses.
Common contractual gaps
No audit rights, no log access, vague uptime promises, and termination clauses that strand data or users.
5. Ongoing oversight of vendors
continuous
- Monitor uptime, incidents, and SLA breaches.
- Review changes in vendor ownership or platform architecture.
- Reassess risk when volumes, products, or jurisdictions change.
Expectation: Vendor oversight is continuous, not a one-time checklist.
6. Concentration & dependency risk
resilience
- Identify single-vendor dependencies.
- Document fallback or contingency options.
- Understand realistic timelines for switching providers.
7. Evidence to keep ready
oversight-ready
- Vendor inventory and criticality classification.
- Executed contracts and SLAs.
- Incident logs and communications.
- Business continuity and exit plans.
8. Cross-links
related guidance
Document note: This page provides administrative guidance and operational expectations.
It does not replace obligations under applicable Acts, license conditions, or binding instruments.