
New Zealand online casino operators will be required to obtain independent game and platform certification within six months of receiving a license and at least annually thereafter, under draft technology requirements released as the country moves into the auction stage for 15 online casino licenses.
The Department of Internal Affairs (DIA) has published a discussion draft of its Testing and Monitoring Requirements for Online Casino Gambling Technology, setting out the proposed testing, certification, and monitoring framework for operators under the Online Casino Gambling Act 2026.
The draft comes as the licensing process advances to a two-week “silent auction,” which began Tuesday, September 29. New Zealand recently launched the Expression of Interest (EOI) stage of the application process for the 15 online casino licenses expected to be issued later this year.
Under the proposed framework, testing previously carried out for other regulated jurisdictions could be accepted for existing games, Random Number Generators (RNGs), live dealer operations, or underlying platform systems if it provides sufficient assurance against New Zealand requirements. The draft specifically identifies testing and certification conducted in the United Kingdom and Ontario, Canada, as potentially applicable.
Before receiving a license, applicants must submit a Game and RNG Register demonstrating that every game they intend to offer, including live dealer games, and every RNG has been tested by an approved independent laboratory. The DIA draft identifies GLI Australia, Quality Assurance Laboratories, and BMM Australia as the three approved independent test labs.
Prospective licensees must also disclose their critical technology providers and the locations of their data centers or cloud-hosting infrastructure. Evidence of ISO 27001 certification or equivalent assurance will also be required.
Once a license commences, an operator must provide an updated Game and RNG Register together with confirmation from its CEO or Chief Compliance Officer that its technology complies with the requirements. That confirmation must cover third-party technology, infrastructure, operating systems, databases, and gaming software.
The proposed regime also requires ongoing monitoring of operators’ systems and Return to Player performance, while operators must retain documentation relating to testing that has been conducted. Periodic vulnerability scanning and penetration testing of platforms will be required as part of the security measures outlined in the draft.
Any new game or RNG introduced after operations begin must undergo external testing. Existing games or RNGs must also be retested when a change affects or may affect fairness.
Changes that do not affect fairness can generally be addressed through internal testing, provided operators maintain robust development, testing, and release controls. These include source-code security, version control, access controls, segregation of duties, peer review, and separate development, testing, and production environments.
