BLOG

Gaming Cybersecurity Regulations in the US and Canada: What Operators Must Meet

Gaming cybersecurity regulations across the US and Canada: AGCO, state gaming boards, FINTRAC, and FinCEN

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 25, 2026

Key Takeaways

  • Canadian gaming is overseen by provincial regulators including AGCO in Ontario and AGLC in Alberta, with BC and Quebec gaming conducted by the Crown corporations BCLC and Loto-Quebec; FINTRAC AML obligations apply across all provinces.
  • US gaming operators are regulated at the state level by bodies such as the Nevada Gaming Control Board, New Jersey Division of Gaming Enforcement, and Pennsylvania Gaming Control Board, with FinCEN Title 31 AML requirements applying federally.
  • Both jurisdictions require documented controls over gaming system integrity, patron data protection, payment security, and AML technology.
  • PCI DSS applies to all gaming operators processing cardholder data through deposits, withdrawals, or cage operations, in both Canada and the US.
  • Incident notification to gaming regulators is a licensing condition in most jurisdictions, with timelines that are tightening and that require a documented response plan in place before an incident occurs.

The Canadian Gaming Regulatory Framework

Provincial Gaming Authorities

In Canada, gaming regulation is a provincial matter. Each province with legal gaming operations has its own arrangements for regulating and operating casinos, iGaming platforms, and lottery corporations. Ontario’s Alcohol and Gaming Commission of Ontario is among the most active regulators, having overseen the expansion of the province’s private iGaming market since 2022. AGCO standards for iGaming operators include technical standards for game fairness, platform security, responsible gambling controls, and AML programme requirements.

Alberta Gaming, Liquor and Cannabis regulates casino and gaming operations in Alberta, including land-based casinos operated by private operators under gaming site agreements. British Columbia’s gaming is conducted and managed by the British Columbia Lottery Corporation (BCLC), and Quebec’s by Loto-Quebec, each operating within its province’s regulatory framework. Operators holding licences or registrations in multiple provinces must align to each applicable set of technical and security standards.

The common thread across provincial gaming authorities is an expectation of documented controls over gaming system integrity, patron data protection, AML programme support, and incident response. The specific standards and audit mechanisms vary, but the cybersecurity programme that satisfies AGCO expectations in Ontario covers the substantive requirements of the other provincial authorities.

FINTRAC: AML Obligations for Canadian Casinos

The Financial Transactions and Reports Analysis Centre of Canada treats casinos as reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. Canadian casinos are subject to FINTRAC reporting obligations for large cash transactions, suspicious transactions, and casino disbursements above defined thresholds.

FINTRAC expects casinos to maintain AML programmes with written compliance policies, an appointed compliance officer, a risk assessment, an ongoing training programme, and an effectiveness review. The technology controls that support AML compliance, including access management on transaction monitoring systems, audit logging of patron transaction activity, and integrity of KYC data, are within scope of both the AML programme and the cybersecurity programme. A breach or manipulation of these systems creates simultaneous AML and cybersecurity regulatory exposure.

The US Gaming Regulatory Framework

State Gaming Control Boards

In the United States, gaming regulation is state-level, and the requirements vary significantly across jurisdictions. Nevada, which regulates the largest volume of commercial gaming in the US, is governed by the Nevada Gaming Control Board and Gaming Commission. New Jersey, home to a major commercial casino market and one of the earliest regulated online gaming markets, is governed by the Division of Gaming Enforcement. Pennsylvania, Michigan, and New Jersey have the most active regulated iGaming markets and correspondingly active regulatory programmes around platform security and AML controls.

State gaming boards increasingly address cybersecurity explicitly. Nevada’s Gaming Commission Regulation 5.260, which took effect on January 1, 2023, requires covered licensees to run cybersecurity risk assessments and adopt recognized best practices, and it was amended in 2026 to shorten the incident-notification window to the Board from 72 hours to 24 hours after becoming aware of a cybersecurity incident, followed by a fuller initial report within five days and updates every 30 days. That change was a direct response to the 2023 attacks on MGM Resorts and Caesars Entertainment. The New Jersey DGE’s technical standards for internet gaming include specific requirements around platform security, patron authentication, and data protection, and Pennsylvania’s gaming regulations include provisions around system security and integrity controls. Operators holding licences in multiple states must understand and align to each state’s specific technical requirements.

A cybersecurity incident that affects gaming system integrity or patron data at a licensed US operator will typically trigger a reporting obligation to the applicable state gaming control board. The timelines and thresholds vary by state, but the expectation of prompt notification and demonstrated incident response capability is consistent across major gaming jurisdictions.

FinCEN and Title 31: AML for US Casinos

US casinos above defined revenue thresholds are subject to the Bank Secrecy Act and its implementing regulations, administered by the Financial Crimes Enforcement Network. Under Title 31, casinos must file Currency Transaction Reports for cash transactions above $10,000, Suspicious Activity Reports for transactions suggesting money laundering or illegal activity, and maintain records of patron identification and transactions meeting defined thresholds.

FinCEN’s AML programme requirements for casinos parallel FINTRAC’s in their structure: written policies and procedures, a designated compliance officer, an independent audit function, and ongoing training. The technology controls that support these requirements, transaction monitoring systems, patron identity verification, and audit trail management, are cybersecurity controls as much as compliance controls. FinCEN enforcement actions against casinos have cited failures in AML technology integrity alongside failures in the compliance programme itself.

For operators in cross-border markets, particularly those serving Canadian patrons at US properties or vice versa, both FINTRAC and FinCEN obligations may apply to aspects of the same operation. Legal and compliance guidance specific to cross-border gaming operations is essential, with cybersecurity controls built to support both reporting regimes.

Where the Frameworks Converge: Common Cybersecurity Requirements

Despite different regulatory structures, US and Canadian gaming cybersecurity frameworks share a common set of expectations. Gaming system integrity controls, including access management on slot floor and table game systems, change control procedures, and audit logging, are expected in both jurisdictions. Patron data protection through encryption, access controls, and data retention limitations is required by privacy laws in both countries and by gaming authority standards. AML technology integrity, covering access controls, audit logging, and system integrity monitoring for transaction monitoring platforms, is expected by both FINTRAC and FinCEN.

PCI DSS applies to all gaming operators processing cardholder data, regardless of jurisdiction. The penetration testing, vulnerability scanning, and network segmentation requirements of PCI DSS overlap significantly with what gaming regulators expect for payment infrastructure security. Building these controls once, and mapping them to each applicable framework, avoids the duplication of effort that separate compliance tracks require.

How Armour Cybersecurity Supports Gaming Operator Compliance

Armour Cybersecurity delivers gaming cybersecurity services to operators holding licences in Canadian and US jurisdictions, with compliance programmes that address the regulatory environment across both countries. The starting point is a regulatory mapping exercise that identifies all applicable authorities, their specific technical and security requirements, and the current state of the operator’s programme against each.

The compliance audit service produces documented controls and evidence packages built from a common control baseline aligned to gaming authority standards, PCI DSS requirements, and AML technology control expectations. The vCISO service provides the governance leadership that regulators expect: a designated senior cybersecurity professional who can brief regulators, prepare board reporting, and manage the ongoing compliance programme. Penetration testing covers the gaming systems, payment infrastructure, and platform integrations that gaming authorities assess.

Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the gaming operators that handle a multi-regulator environment without a dedicated compliance army are the ones who stopped treating AGCO, FINTRAC, a state board, and FinCEN as four separate projects. They built one control set for gaming integrity, patron data, payments, and AML technology, then mapped that single set to each regulator, so a new state licence or a tightened notification rule is a mapping update rather than a new programme.

Frequently Asked Questions

What triggers a cybersecurity incident notification to a gaming regulator?

The threshold varies by jurisdiction. Most gaming authorities require notification of incidents that affect gaming system integrity, patron data, or the ability to meet AML reporting obligations. Timelines are tightening: Nevada, for example, amended Regulation 5.260 in 2026 to require notification within 24 hours of becoming aware of a cybersecurity incident, down from 72 hours, while other jurisdictions require prompt notification without a fixed deadline. Operators should have their notification obligations by jurisdiction documented in their incident response plan so that notification decisions can be made quickly when an incident occurs, rather than being researched under pressure.

How does AGCO assess cybersecurity for iGaming operators?

AGCO’s technical standards for registered iGaming operators in Ontario address platform security, patron authentication, data protection, game fairness, and responsible gambling controls. AGCO-registered operators undergo initial technical review and ongoing audit. Cybersecurity controls are assessed both at initial registration and through ongoing compliance reviews. Armour’s compliance audit service maps AGCO technical standards to a documented control set and produces the evidence that audit reviews require.

Do tribal gaming operations in the US have the same regulatory requirements?

Tribal gaming operations are regulated under the Indian Gaming Regulatory Act and overseen by the National Indian Gaming Commission, in addition to tribal gaming commissions and compacts with state governments. The specific cybersecurity and AML requirements vary by compact and tribal gaming ordinance. NIGC has published minimum internal control standards that include technology and cybersecurity provisions. Tribal operators with Class III gaming compacts also typically comply with state technical standards as a compact condition.

Can a single cybersecurity programme satisfy both US and Canadian gaming regulator requirements?

Yes, with jurisdiction-specific additions layered on a common control baseline. The core requirements around gaming system integrity, patron data protection, payment security, and AML technology controls are consistent across jurisdictions. A programme built around PCI DSS, SOC 2, and gaming authority technical standards covers the shared ground, with specific additions for FINTRAC or FinCEN reporting system controls, AGCO technical standards, or state-specific requirements as applicable. Armour’s approach starts with the common core and adds jurisdiction-specific layers based on each operator’s licence portfolio.

The Bottom Line

A gaming operator does not get to pick one regulator. A casino with an iGaming arm and cross-border patrons answers to a provincial authority like AGCO, to FINTRAC, to a state gaming board, and to FinCEN, plus PCI DSS wherever it takes a card. Running a separate compliance track for each is how teams drown. These regimes converge on the same core: gaming system integrity, patron data protection, payment security, and AML technology controls that are access-managed, logged, and monitored. Build that core once, map it to each authority, and a tightened rule like Nevada’s move to 24-hour notification becomes a small update rather than a scramble. Armour Cybersecurity helps casino and gaming operators build gaming cybersecurity services that meet cybersecurity and AML technology control requirements across Canadian and US jurisdictions, so a growing licence portfolio strengthens the operator rather than multiplying its compliance burden.

Leave the first comment