Due diligence · 22 September 2026 · 9 min read
What we look for in an iGaming technology due diligence
Eight areas decide whether a platform is worth what the seller is asking. Six of them are invisible in a data room, and the first one is always the ledger.
Technology diligence on an iGaming target is not a code review with a gambling flavour. The things that move the valuation are specific to this industry, and most of them cannot be assessed from documentation the seller prepared. What follows is the order we work in, and why that order is deliberate.
1. The ledger, before anything else
Every other finding is negotiable. This one is not. We want to know whether a player balance can be derived from an append-only record of events, or whether it is a number in a column that various parts of the system update directly. The second pattern is common, and it means no one can reconstruct why a player has the balance they have.
From there we look for idempotency on every write path that moves money. Providers resend callbacks, players double-tap, networks fail mid-payment. The correct behaviour on the second identical request is the single most important property of a gaming platform, and the most frequently missing.
Red flag
A wallet client that generates its own idempotency key when the caller does not supply one. It looks defensive and it silently defeats the entire mechanism, because every retry produces a new key and applies the operation again.
2. Whether the architecture can carry the plan
The commercial model usually assumes a second brand, a second jurisdiction or a second product. We test whether the platform can do that without a fork. Tenancy that was never designed gets simulated with environment variables and copied databases, and every launch then costs what the first one cost. That is a rebuild hiding inside a roadmap, and it belongs in the model.
3. Compliance enforced in software, not in process
We check where geographic restriction is actually applied. If a blocked jurisdiction is filtered in the front end, the request has already been accepted by the platform. We check whether self-exclusion is enforced at every entry point or only at login, whether an audit trail can be reconstructed for a specific player on a specific date, and whether the reporting a licence requires is captured at all.
This matters commercially because it is the category of finding that converts into a licence problem on your first day of ownership, rather than a backlog item you can schedule.
4. Supplier dependency and the real cost of switching
Game aggregation, payments and identity verification are all places where a contract can outlive a relationship. We map exclusivity, minimum revenue commitments, notice periods and the technical cost of moving. A platform with one payment route and no abstraction layer is carrying a commercial risk that does not appear anywhere in the code.
5. What the infrastructure actually costs to run
We pull the bill and compare it to real traffic. Over-provisioned clusters, non-production running around the clock, orphaned storage and cross-zone transfer typically account for twenty to forty percent of spend, and that is recoverable without touching availability. We also check whether production can be changed outside a reviewed pipeline, because that is a control finding as much as an engineering one.
6. Where the knowledge lives
We interview engineering leadership, the people who carry the pager, product and whoever owns compliance. The gaps between those four accounts are usually where the risk sits. Key person concentration is the finding that most often changes deal structure, because it converts into retention terms rather than a price adjustment.
7 and 8. Testing, and the honesty of the roadmap
Coverage numbers tell us little. What tells us a great deal is whether there is a single test that provokes a duplicate provider callback and asserts the ledger outcome. Then we compare the last four quarters of delivery against what was planned, which is the cheapest available predictor of what the next four will look like.
What the report has to do
A finding without an effort estimate is an opinion. Every item we raise carries a severity, an effort in engineering weeks and a position in a sequence, so the number can move into the model and the remediation plan can become a backlog on the day you complete. If we find something we consider a deal breaker, you hear it by phone on the day we find it, not in a document three weeks later.
Related service
Technology Due Diligence
Know exactly what you are buying, funding or inheriting before you sign.
Read the service pageMore insights
- The idempotency contract for wallet writes
Most stranded balances trace back to five decisions. Here is the contract we implement, including the one clause that teams consistently get backwards.
- Multi-brand without a fork: what tenancy actually costs
Launching a second brand is where platform decisions made two years earlier present their bill. The decisions that matter are smaller and earlier than most teams expect.