Outsourcing & Platform Risk — NGA (NLA)
NFSA & NGA Rules & Guidance / Outsourcing & Platform Risk

Outsourcing & Platform Risk

Guidance for managing third-party reliance, platform dependencies, hosting, game providers, and critical vendors within the NGA framework.

Applies to
NGA Licensees
Focus
Vendors • Platforms • SLAs
Risk area
Availability • Control • Continuity
Status
Active guidance

1. Core principle

accountability

Outsourcing a function does not outsource responsibility. NGA licensees remain accountable for outcomes, records, and user experience, regardless of how many vendors sit in the stack.

Rule of thumb: If a vendor fails, the licensee must still be able to explain what happened.

2. Identify critical outsourced functions

mapping

Maintain a clear inventory of all third parties and classify which are critical.

Function Examples Why critical
Platform core Game engine, wallet logic, transaction processing Failure stops operations entirely
Hosting Cloud infrastructure, data centres, CDN Availability, data integrity, latency
Game providers Third-party games, RNG services Fair play, uptime, settlement accuracy
Payments PSPs, payout partners, processors Funds access and user trust

3. Due diligence & onboarding

before reliance
  • Understand the vendor’s role, limitations, and dependencies.
  • Assess operational maturity, security posture, and continuity planning.
  • Confirm ownership of data, logs, and reports.
  • Ensure exit rights and data portability are documented.

4. Contractual minimums

SLAs & rights
  • Defined service scope and responsibilities.
  • Availability and performance commitments.
  • Incident notification timelines.
  • Access to logs, records, and reports.
  • Termination and transition assistance clauses.
Common contractual gaps

No audit rights, no log access, vague uptime promises, and termination clauses that strand data or users.

5. Ongoing oversight of vendors

continuous
  • Monitor uptime, incidents, and SLA breaches.
  • Review changes in vendor ownership or platform architecture.
  • Reassess risk when volumes, products, or jurisdictions change.
Expectation: Vendor oversight is continuous, not a one-time checklist.

6. Concentration & dependency risk

resilience
  • Identify single-vendor dependencies.
  • Document fallback or contingency options.
  • Understand realistic timelines for switching providers.

7. Evidence to keep ready

oversight-ready
  • Vendor inventory and criticality classification.
  • Executed contracts and SLAs.
  • Incident logs and communications.
  • Business continuity and exit plans.

8. Cross-links

related guidance
Document note: This page provides administrative guidance and operational expectations. It does not replace obligations under applicable Acts, license conditions, or binding instruments.