Systems & compliance audit in iGaming

Independent MGA audit support for gaming licensees and applicants

Forvis Mazars in Malta supports iGaming operators, B2B suppliers and licence applicants with independent audit and assurance services required under the Malta Gaming Authority framework. Our services cover MGA System Audits, System Reviews and Compliance Audits, as well as related regulatory audit obligations where these are required by the Authority and fall within the approved Audit Service Provider framework.

The MGA’s current approach is not limited to confirming that documentation exists. It focuses on whether the authorised person can demonstrate, with clear evidence, that its governance, systems, controls, policies and reporting processes operate effectively in practice. The MGA’s published materials describe a risk-based, evidence-led and outcomes-focused supervisory model, supported by full-scope Compliance Audits, thematic reviews, supervisory meetings, supervisory reviews and inspections.

Forvis Mazars brings together IT audit, regulatory compliance, financial reporting, AML/CFT, governance and player-protection expertise to help clients prepare for, manage and complete MGA audit and review processes efficiently, with the level of evidence and structure expected by the Authority.

When an MGA audit or review may be required

System Audits

A System Audit is carried out as part of the MGA licence onboarding process or whenever the Authority deems it necessary. The MGA’s Approved Audit Service Provider Policy states that a System Audit is carried out as part of the Authority’s licence onboarding process or when required by the Authority. The MGA’s revised System Audit Checklist applies across different licence types, including B2C, B2C with DLT, B2B and B2B software needs, and came into force for System Audits engaged as of 1 January 2023.

System Reviews

A System Review is a separate live-environment review used after licence issuance to verify that the implemented systems operated by the licensee reflect the information submitted to the Authority and comply with the Gaming Act and relevant subsidiary legislation. The MGA states that System Reviews are generally required one year after the issuance of a new licence, or within a shorter timeframe if a System Audit was not required at licence issuance stage, and may also be required in other instances decided by the Authority.

Compliance Audits

Compliance Audits are performed throughout the licence period when required by the Authority. The MGA’s 2026 supervisory document states that full-scope Compliance Audits conducted by authorised Audit Service Providers remain a pivotal component of the Authority’s oversight framework and involve evaluation of operational and regulatory standards such as financial stability, player protection practices, AML controls and IT systems. The Compliance Audit Manual covers areas including standing information, key persons, financial analysis, IT, gaming operations, B2C checks and B2B checks.

How we work

1. Scoping and readiness assessment

We start by understanding the licence type, the operating model, the approved technical setup, the applicable checklist or manual, and the evidence already available. The MGA’s current process expects audits and reviews to be supported by structured evidence, and the Authority may return or reject reports if the evidence or report quality does not allow it to arrive at a conclusive outcome.

2. Evidence mapping and live-system walkthroughs

We map each applicable requirement to the supporting documents, system demonstrations, screenshots, extracts, logs, policies, procedures, declarations or confirmations required. System Reviews must be carried out on the live environment, with licensee personnel available to demonstrate functionality and provide evidence and information as required by the list of checks.

3. Testing, findings and remediation support

Where issues are identified during the audit period, the MGA’s process allows findings to be recorded transparently, including through “Resolved at Audit Stage” where the issue is remediated and re-audited, or “Partially Compliant” where a detailed rectification plan is required. We help clients understand the evidence needed to support remediation and reduce the risk of unresolved or unsupported findings.

4. Report submission and follow-up

We prepare the audit or review report and supporting evidence in line with the MGA’s published process. The MGA’s 2025 clarification introduced structured SharePoint VDR folders for System Audits, System Reviews and Compliance Audits, and requires evidence to be uploaded into numbered folders reflecting the relevant checklist sections. External auditors are expected to reference supporting document or screenshot file names in the report and explain why the evidence is sufficient and conclusive.

Why work with Forvis Mazars

Forvis Mazars combines regulatory, IT, financial, AML/CFT and governance experience in a single integrated team. We understand that an MGA audit is not only a technical exercise; it is a test of whether the licensee can evidence that its operating model, systems, controls, reporting and governance arrangements remain aligned with its regulatory obligations throughout the licence lifecycle.

Our approach is practical, evidence-led and transparent. We help clients identify gaps early, structure evidence clearly, engage with the MGA process efficiently and address findings in a way that is consistent with the Authority’s published requirements and current supervisory expectations.

Want to know more?