Online casino game testing checks whether a defined software version implements its rules, mathematics, random-number generation and displayed payouts correctly. An approved laboratory may review documentation and source code, run statistical and game simulations, test rare outcomes manually, and issue a report before regulated release.

This guide is for operators, suppliers, compliance teams, analysts and players who need to understand what casino certification can and cannot prove. It uses the Gambling Commission process in Great Britain as a detailed example. Requirements, approved laboratories and submission rules differ by jurisdiction, product and licence type.

What online casino game testing covers

Regulatory game testing compares a defined product against technical standards and its own approved design. In the British model, the scope can cover game mathematics, artwork, player-facing rules, theoretical RTP, source-code implementation, actual RTP from testing, and the scaling or mapping that converts raw random values into game outcomes.

The Gambling Commission testing procedure requires the licensee and its chosen test house to agree a scope that is sufficient for the relevant standards. This matters because test reports are not generic endorsements. The report should name the licensee, game, software number, digital signature, platform version, client channels, methods, result and any earlier game version it supersedes.

Testing also follows jurisdictional scope. A laboratory approved for one product or standard is not automatically approved for every other category. The official British approved test-house list, updated on 4 September 2026, tells licensees to choose a test house whose approval covers the facilities they plan to provide.

The casino game testing process step by step

A practical pre-release testing flow based on the British regulatory procedure
RoleWhat it meansWhere to verify
1. Freeze the productIdentify the game version, rules, maths, paytable, RTP configuration, RNG, platform and player channels.Version manifest, software number, digital signature and change record.
2. Set the scopeMap the product to the applicable technical standards and decide which checks require an approved third party.Jurisdiction, licence type, product category and test-house approval scope.
3. Test the RNGReview design and source code, check known weaknesses and analyse raw, scaled or shuffled output statistically.RNG report, version, algorithm or hardware description, tests, limitations and result.
4. Verify the gameCheck maths, rules, artwork, paytable, theoretical RTP, mapping and implementation in a live-like environment.Maths files, source code, simulation, emulation and manual test evidence.
5. Resolve findingsReport non-compliance to the supplier, correct it and retest the affected areas before sign-off.Issue log, corrected build, retest evidence and final result.
6. Submit before releaseComplete the report and provide it to the regulator where the applicable process requires submission.Signed report, certificate reference, submission record and release approval.
7. Monitor productionTrack actual RTP, faults, complaints and changes so the live version remains within the tested control boundary.RTP alerts, incident records, change log and annual audit evidence.

This sequence is not a universal certificate workflow. Some regulators require additional security, integration, platform or responsible-design tests. The reliable method is to start with the target market and licence, then connect every report field to the exact live product rather than treating one laboratory document as worldwide approval.

How RNG testing differs from game testing

An online casino RNG produces values used to determine outcomes. RNG testing examines the design, implementation and statistical output of that generator. The British RTS 7 requirement says the output and game results must be demonstrably acceptably random and prohibits adaptive behaviour, sometimes called a compensated game.

Game testing checks what happens after random values enter the game. Mapping may turn an integer into a reel stop, card, wheel position or other event. The laboratory must verify that the mapping, rules and prize calculation produce the designed probabilities and payouts. A statistically sound RNG cannot correct an incorrect paytable, missing symbol, biased mapping rule or faulty jackpot trigger.

The test report should therefore identify both dependencies. For an RNG it records the version, use, digital signature, test scope and technical limitations. For a game it records the game and platform versions, RTP, channels and results. Reusing a tested RNG does not remove the need to test each new game's maths and implementation where the rules require it.

How mathematics and RTP are checked

Game mathematics defines the probability of each outcome and the prize attached to it. A reviewer can calculate theoretical RTP from the complete outcome model, then compare the software with that model. Our separate RTP explainer shows why theoretical RTP is a long-run design property rather than a promise for one session.

The British procedure names three execution methods. Simulation runs a high number of automated games and compares actual return with the expected range. Emulation forces rare states such as jackpot triggers, special features and maximum prizes. Manual play checks visible behaviour, common wins, pay lines and whether the rules shown to a player match the implemented game.

There is no responsible universal answer to how many spins prove a game fair. The required sample depends on the mathematics and volatility of the product. A test house needs a sample and tolerance suitable for that design. Exact simulations should be documented, and tester-generated data is generally preferred unless another controlled method is required.

Why rules, artwork and channels are part of testing

Fair maths is not enough if the customer sees the wrong rules or payout information. The Gambling Commission's RTS 3 requires accurate, understandable rules and information about prizes and the likelihood of winning before a customer commits to gamble. A test house therefore compares player-facing text and artwork with the underlying maths and game behaviour.

The player channel is also part of the identified scope. An HTML5 browser client and a native mobile application may share a backend but display results differently. The British procedure requires a new channel for an existing game to be tested by an approved test house, usually with a narrower focus on the interface when the backend design has not changed.

A browser or operating-system update does not normally require external retesting by itself, but the licensee should confirm that existing games still work. Changes to the iGaming platform, remote gaming server or RNG can be more material because they may affect hundreds of games and can trigger representative integration testing.

What a game test report should contain

A useful report is an identity and scope record as much as a pass result. The British procedure lists the minimum fields for games: test-house details and supervisor, licensee, test date, certificate reference, game name, RTP, software number, digital signature, test methods, platform and version, channels, result and any superseded versions.

  • Match the game name to a software number or other stable identifier.
  • Match the reported RTP and ruleset to the configuration offered in the target market.
  • Match the platform version, RNG dependency and client channel to production.
  • Confirm the test house was approved for that product and scope on the relevant date.
  • Check whether the report covers a full test or a limited retest linked to an earlier report.
  • Verify the digital signature or build identifier against the released software where the evidence is available.

These fields help separate a casino game provider from the licensee responsible for offering the game. A supplier may commission or hold technical evidence, while the gambling operator must still maintain the records and controls required under its own licence.

What certification does not prove

Claims a test report can support, and claims that need separate evidence
RoleWhat it meansWhere to verify
The report can supportA named build passed the stated tests against the listed requirements on the recorded date.Report scope, methods, result, version and signatures.
The report cannot prove aloneThe same build is live at every operator, in every market, channel and RTP configuration.Production manifest, integration evidence, market configuration and current game register.
The report cannot guaranteeNo defect will appear after release or that later code and platform changes preserve the tested behaviour.Monitoring, incident history, complaint review, change control and retest records.
The report does not replaceAn operating or software licence for the relevant legal entity and market.Official regulator register and current licence conditions.

A test report is not a regulator licence and does not make a game legal everywhere. Use the official register to check the gambling licence and follow the BETTIMES licence-verification process. Then match the licensed entity, domain, product, report and production build as separate records.

When a game needs retesting

Under the British approach, a major update is a change that may affect game fairness. The major and minor update annex names changes to the RNG, scaling, mapping or game rules as fairness-sensitive examples. A code optimisation can still be major if it changes how rules are implemented, even when the visible rules stay the same.

Minor changes can be handled without external retesting only when they do not affect fairness and the licensee meets its change-control duties. The classification, reasons, internal test evidence and authorisation should be recorded. If a limited retest relies on an earlier full test, the updated report should reference the earlier document, changed elements, completed tests and new digital signatures.

The in-house release guidance also calls for separate development and test environments, review by staff independent from the original change, and documented approval before migration. These controls make version matching possible after the release date.

Why testing continues after launch

Pre-release testing samples defined behaviours. Production monitoring observes the real game across customer devices, integrations and volumes. The Commission's live RTP monitoring guidance says licensees should compare actual RTP with expected RTP often enough for the game's volume, include volatility in the tolerance and avoid aggregation that hides a channel-specific defect.

A simple example is a game designed for 95% theoretical RTP. Actual RTP is calculated from wins divided by turnover for the chosen live dataset. The result can move above or below 95% through normal variation, so alerts need a statistically suitable tolerance. Repeated or material exceptions require investigation rather than an assumption that the original certificate settles the issue.

Complaints matter too. The guidance says a higher-than-normal level of fairness complaints should be investigated and warns that errors can evade testing. Responsibility for monitoring must be clear when a B2B supplier holds aggregated transactions for games offered by several B2C operators.

Annual game testing audits

Some British licensees must complete an annual games testing audit through an approved test house. The annual testing rules require a random sample of major and minor updates so the auditor can check whether each change was classified correctly and whether external testing was obtained when required.

The Commission uses four submission pools with 12-month audit periods beginning on 1 July, 1 October, 1 January or 1 April. The report is due four weeks after the relevant period ends. Not every remote licensee has the same annual-audit obligation, so the licence type and testing responsibility need to be checked before applying this rule.

A certificate verification checklist

Use this checklist when assessing a game-testing claim. It is a research process, not a substitute for access to the original technical report or advice on a specific licence:

  1. Name the regulator, jurisdiction, technical standard and applicable licence type.
  2. Confirm the test house appears on the regulator's approved list for the required scope.
  3. Obtain the complete report or verifiable certificate reference instead of relying on a marketing badge.
  4. Match game name, software number, digital signature, RTP, ruleset, platform, RNG and channels.
  5. Check the test date, superseded versions, limitations and any linked limited-scope retest.
  6. Compare the tested identifiers with the production game and current market configuration.
  7. Review later major changes, incident history, live RTP monitoring and annual audit evidence.

How BETTIMES reviewed the process

BETTIMES compared nine Gambling Commission sources accessed on 6 September 2026. We mapped the general explanation to the current testing strategy, used RTS 3 and RTS 7 for the underlying requirements, and treated the approved-test-house list as a dated registry rather than a permanent endorsement of every laboratory scope.

We did not inspect a confidential game report, source-code repository, live operator configuration or laboratory accreditation file. We therefore describe what the British process requires and how evidence should be matched, not whether any named game has passed. Other markets may use different standards, report formats, retest triggers and approval lists.

Frequently asked questions

Who tests online casino games?

Game suppliers and operators perform internal quality assurance, but regulated fairness testing may require an independent laboratory approved for the relevant jurisdiction and product. In Great Britain, the licensee must choose a Gambling Commission-approved test house with the right scope. The regulator publishes the list, while the test house performs the specified technical work.

How do laboratories test casino RNGs?

A laboratory can review the RNG design and documentation, research known weaknesses, compare source code with the documented implementation and run statistical tests on raw and transformed output. It also records the RNG version, digital signature, platform dependency and limitations. RNG analysis does not replace verification of each game's mapping, rules and payouts.

How many spins are needed to test a slot game?

There is no universal valid number. The required sample depends on the game's mathematics, volatility, features and the confidence and tolerance required by the test method. Simulation can run a high volume of plays, while emulation targets rare states. A credible report explains its sample and why the method fits that game.

Does a casino game certificate prove the live game is fair?

It supports a narrower claim: the identified version passed the stated tests within the report's scope and date. It does not alone prove that the same build, RNG, RTP setting, platform and client are live. Production matching, change control, live RTP monitoring, complaint investigation and current licensing provide the remaining evidence.

Do casino games need retesting after an update?

Yes when the change may affect fairness under the applicable rules. Changes to the RNG, scaling, mapping, game rules or their software implementation are common triggers. A minor change may avoid external retesting only when fairness is unaffected and the licensee records the classification, internal tests, justification and authorised release controls.

The reliable way to read a testing claim

Online casino game testing is an evidence chain, not a badge. Start with the jurisdiction and standard, identify the approved laboratory, read the scope and methods, and match the report's game, build, platform, RNG, RTP and channels to production. Then check what changed and how the live game is monitored.

That sequence answers the question a certificate alone cannot: whether the currently offered game still sits inside the tested boundary. BETTIMES will refresh this guide when the Gambling Commission materially changes its testing strategy or approved test-house framework.

Why this record matters

BETTIMES links this publication to structured company, market and source records. Material changes can therefore be checked and refreshed without detaching the article from its original evidence.