The Certification Process
A structured 5-phase engagement — streamlined for iGaming operations.
- 1
Phase 1
Planning & Risk Assessment
We map your platform, data flows and key risks, then agree the testing approach.
- Review platform architecture, data flows, and key IT processes
- Identify risks: access management, data integrity, crypto custody, transaction processing
- Define testing approach (full-population analytics vs. sampling)
- Obtain read-only access/export of core datasets
- 2
Phase 2
IT General Controls Review
Assessment of the foundational IT controls that keep your platform secure and reliable.
- Access Management: user provisioning, role-based access, privilege reviews
- Change Management: release management, testing, approvals, segregation of duties
- Backup & Recovery: DR/BCP readiness assessment
- Monitoring & Logging: audit logs, alerting, incident handling
- 3
Phase 3
Application & Platform Controls
Deep review of the gaming-specific logic and integrations running your business.
- Review transaction processing (bets, wins, cancels, payouts)
- Evaluate RNG controls, payout percentages, reporting integrity
- Assess crypto custody and wallet reconciliation
- Verify KYC, AML, and regulatory compliance integrations
- 4
Phase 4
Data Analytics & Substantive Testing
Evidence-based testing across your transaction data to confirm integrity.
- Full-population transaction testing (where feasible)
- Gap/duplicate detection in transaction IDs
- Suspicious pattern detection (negative balances, abnormal wagers)
- Journal-entry analytics and on-chain vs. off-chain reconciliation
- Independent reperformance of settlement and fee calculations
- 5
Phase 5
Reporting & Certificate Issuance
Clear findings, practical recommendations and your Certificate of Compliance.
- IT Audit Workpapers Pack (mapped to ISA standards)
- Control Deficiencies Report with remediation recommendations
- Issuance of CyberB2B Certificate of Compliance (12 months validity)
Final Deliverables
- Audit Plan & Risk Assessment Memo
- Completed IT Audit Checklist with evidence references
- Data Analytics Results Summary
- Control Deficiency and Recommendation Report
- CyberB2B Certificate of Compliance (12 months)
Confidentiality
CyberB2B maintains strict confidentiality of all information obtained during the engagement. No data or results are disclosed to third parties without the client's written consent, except where required by law or regulatory authorities.
