All entities holding an Eritrea Gaming license must maintain compliance with the applicable operational, technical, financial and conduct standards throughout the license term.
These standards establish the minimum requirements for licensed internet gaming activities. They apply together with Eritrean law, individual license conditions, regulatory directions and any supplementary standards issued by the Authority.
The requirements applicable to a particular license may vary according to whether the license provides B2C gaming services, B2B gaming technology or another approved service.
Licenses must maintain a transparent and effective governance structure appropriate to the nature and scale of their operations.
The governance framework must clearly identify:
The board and senior management remain responsible for regulatory compliance even where functions are delegated or outsourced.
Licenses must maintain risk based AML/CTF systems designed to prevent licensed gaming services from being used for money laundering, terrorist financing, fraud, sanctions evasion or other unlawful purposes.
Required controls may include:
Each license must appoint a suitably qualified person responsible for AML/CTF oversight.
The license must ensure that its systems are appropriate for fiat currency, cryptocurrency and any other approved payment method it supports.
B2C operators must verify customers according to a risk based process and before any threshold or regulatory trigger requiring verification is reached.
Customer due diligence must be capable of confirming:
Operators must prevent duplicate, fraudulent or improperly controlled accounts and must apply additional checks where suspicious activity, high risk behaviour or inconsistent customer information is identified.
Licensed operators must implement measures intended to reduce gambling related harm and support informed player choice.
The responsible gaming framework must include, where applicable:
Responsible gaming tools must be accessible, clearly explained and implemented without unreasonable delay.
An operator must not encourage a player to cancel or weaken a responsible gaming restriction.
Licensed gaming services must not be provided to persons below the legal gaming age applicable to the player.
Operators must maintain effective controls to:
Games and wagering products must operate fairly, consistently and according to their published rules.
Operators and suppliers must ensure that:
The Authority may require testing or certification by an approved independent testing laboratory.
Operators offering sports or esports wagering must maintain controls designed to detect and respond to suspicious betting, manipulation and misuse of inside information.
Controls may include:
Licenses must protect gaming systems, personal information, financial records and regulatory data against unauthorised access, loss, manipulation and disruption.
The security framework should address:
Material cybersecurity incidents must be reported to the Authority within the period prescribed by the applicable license conditions.
B2C operators must maintain arrangements designed to ensure that player balances and withdrawal obligations can be met when due.
Subject to the specific license conditions, the Authority may require:
Player funds must not be represented as being protected beyond the level of protection actually provided.
Operators must process deposits and withdrawals fairly, securely and according to disclosed procedures.
Operators must:
Advertising must be lawful, truthful, socially responsible and capable of substantiation.
Licenses must not:
Operators remain responsible for marketing conducted by their affiliates, agents and contracted promoters.
Licenses must process personal and confidential information lawfully, securely and only for legitimate purposes.
Appropriate policies and controls must cover:
Licenses must maintain complete and accurate records sufficient to demonstrate compliance.
Records may include:
Licenses must submit regulatory reports in the form, frequency and manner prescribed by the Authority.
Reports may cover:
Reports must be complete, accurate and submitted within the required timeframe.
The license is responsible for maintaining compliance with all applicable standards, including activities carried out by contractors, affiliates, platform providers and other outsourced service providers.
A failure by a third party does not remove the license’s regulatory responsibility.