A certificate on the wall is not the end of the obligation. Most standards that govern iGaming require the people inside an organisation to be trained — and re-trained, on a schedule. This is the map: which certification or regime creates a training duty, who it falls on, how often, and what it must cover — each linked to the lesson that teaches it.
Certification vs staff training
Two different things get confused. Certification is granted to a system or an organisation — an RNG passes GLI-19; a company’s information-security management is certified to ISO/IEC 27001. Training is an obligation on people: the standard or law requires that staff understand the risks and rules and can prove it. Becoming certified typically commits an organisation to an ongoing training programme — the certificate is a snapshot; the training is the upkeep.
Why it recurs
Training duties are rarely one-off. They attach to joining (induction), to a fixed cadence (commonly annual), and to material change — a new law, a new system, a new role. Regulators and auditors look for records: who was trained, on what, and when. A programme that lapses is an audit finding waiting to happen — which is why these obligations are a standing line in every compliant operator’s calendar.
The obligations · verified 2026-08-05
🔐
Information security
ISO/IEC 27001:2022
Who must trainAll personnel (employees and relevant contractors) working under the organisation's information security management system
How oftenOn joining, then at regular intervals (commonly at least annually)
Training must coverAwareness of the information security policy, each person's security responsibilities, and how to recognise and report information security events.
ISO/IEC 27001:2022 Annex A 6.3 (Information security awareness, education and training); reinforced by main Clause 7.3 (Awareness)Standardiso.org
🕵️
Anti-money laundering
UK Money Laundering Regulations 2017
Who must trainAll relevant employees whose work is relevant to AML/CTF compliance (and relevant agents)
How oftenRegularly (typically at least annually), plus at induction
Training must coverAwareness of the law on money laundering and terrorist financing and how to recognise and deal with suspicious transactions and activity.
Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, Regulation 24 (Training)Learn it →legislation.gov.uk
🛟
Safer gambling
UK Gambling Commission LCCP
indicative
Who must trainStaff involved in customer interaction at GB-licensed remote (online) operators
How oftenAt induction, then ongoing refresher training
Training must coverHow to identify indicators of gambling harm and interact with affected customers, including staff roles, techniques and acting promptly on alerts.
LCCP Social Responsibility Code Provision 3.4.3 (Remote customer interaction), via its binding formal 'Customer interaction guidance for remote gambling licensees' (in effect 31 Oct 2023) which 3.4.3 requires operators to take into accountLearn it →gamblingcommission.gov.uk
🎲
Game & RNG certification
GLI-19 Interactive Gaming Systems v3.0
Who must trainNot staff training: operators and game/system suppliers must submit their interactive gaming system, games and RNG for independent laboratory certification
How oftenBefore deployment, and again on each material change or new game release (re-submission of modified components)
Training must coverIndependent evaluation that the RNG, game outcome determination, RTP and system controls conform to the standard before go-live and after material changes.
GLI-19 Interactive Gaming Systems v3.0 — system/game certification and re-submission of modified components (a certification cadence, not a staff-training obligation)Learn it →Standardgaminglabs.com
💳
Payments security
PCI DSS v4.0.1
Who must trainAll personnel in, or with access to, the cardholder data environment (CDE)
How oftenUpon hire, then at least once every 12 months
Training must coverSecurity awareness including relevant threats such as phishing and social engineering, and acceptable use of end-user technologies.
How oftenRegular and ongoing; ICO/EDPB recommend at least an annual refresher (no fixed statutory interval)
Training must coverThe data protection principles, staff obligations when handling personal data, and how to recognise and report a personal data breach.
UK GDPR Article 5(2) (accountability), supported by Article 39 (DPO awareness-raising and training of staff) and Article 32 (security measures); ICO Accountability Framework — Training and awarenessico.org.uk
Educational, not accredited. iGamer teaches this material — every duty above links to the lesson that covers it — but we are an independent educational portal, not an accredited certification body. Our lessons support your training; they do not replace an employer’s formal, accredited obligations. Guided courses with a completion record are on the roadmap.