Affordability by API
- Kevin Jones

- 21 hours ago
- 11 min read
Stage one of financial risk assessments obliges Great Britain's largest operators to buy, build and integrate a data supply chain that did not exist as a regulated category before this July. The winners will be decided by match rates, per-query pricing and integration quality that nobody has published. This is the anatomy of that supply chain, and of the two numbers the debate is missing: what the machinery costs, and whether it is right.

On 7 July 2026 the Gambling Commission confirmed that financial risk assessments will arrive in stages, starting with the largest remote operators and the highest-spending accounts, and in doing so turned a policy argument into a procurement event. The announcement settled the principle. It settled nothing about the system: a regulation can require that a customer account be connected to an external financial record, interpreted and acted on, but someone still has to build that pipeline, procure the data feeding it and stand behind its decisions. Every consequence that matters commercially now hangs on how well that is done.
Three instruments are routinely conflated, and this analysis depends on separating them. The light-touch vulnerability checks in force since 2024 are public-record lookups at £150 net deposits in a rolling month, scanning bankruptcies, debt relief orders and county court judgments. The stage-one assessment is a different instrument: a credit reference agency lookup triggered at £5,000 net deposits in a rolling 24 hours for customers 25 and over, £2,500 under 25, a pattern the Commission says fewer than 0.5 per cent of customers reach, returning an overall rating and four data points, defaults, multiple arrears, significant arrears and any debt management plan. Open banking is a third thing: a fallback for the residual the credit file cannot place. The Commission's pilot found 97 per cent of accounts above the thresholds could be assessed frictionlessly, against the 80 per cent the 2023 White Paper assumed, leaving fewer than one in 1,000 accounts needing identity verification and an alternative route. Lower triggers, £1,000 in a rolling day or £3,000 over 90 days, are expected once fully implemented, though the Commission has left later stages contingent on stage one.
Whether the design succeeds turns on six questions the regulation does not answer. How accurately can a customer be matched to the right financial record? What happens when that record is incomplete? How quickly does the check complete, and does the customer notice? Who reviews a result the system is not confident about? How does a customer challenge a decision they believe is wrong? What evidence must the operator retain, and for how long? None is a policy question. Each is an engineering, product or governance question with a right and a wrong answer, and the rest of this piece traces where the answers will come from.
The check already has a supply chain
Operators are not building from nothing. Rank Interactive announced in early 2024 that it had integrated Department of Trust's DoTrust Complete, described by its provider as bundling financial risk, affordability and anti-money-laundering checks into a single call, with access to a central Vulnerability Registration Service that returns risk flags without exposing customer identity. Rank buying rather than building is the signal: an operator that already screened every customer at registration still judged the integration work worth outsourcing. FDJ United is rolling out Crucial Compliance for transaction monitoring and real-time risk scoring across its British and Dutch books, and Kindred, before its acquisition by FDJ United, had built an affordability framework around credit reference data ahead of any mandate.
The operators that built instead tell a story about scale. Entain's ARC programme, Rank's Central Engagement Platform, Evoke's Observer and its Multi-Dimensional Risk Model, Flutter's GamProtect register queried daily against shared self-exclusion data: each is a proprietary compliance asset only a large balance sheet can fund. "Conduct a financial risk assessment" resolves, in practice, into a procurement decision, an integration project and a set of data-sharing arrangements, and the capacity to make those decisions well is unevenly distributed. Stage one applies to the largest operators first. The firms with the deepest engineering budgets will bed in the machinery, shape the guidance through the implementation groups forming this summer, and amortise the cost before smaller rivals face the same rule. The staging is protective in intent. In effect, it is a head start.
One check, three strategies
One layer upstream sit the three large credit reference agencies, running three different strategies against the same mandate. TransUnion has the deepest dedicated gaming vertical, built on its 2018 purchase of the British bureau Callcredit: a gaming affordability suite claiming nearly two decades of operator experience, a gaming-specific open banking product whose engine sorts transactions into more than 330 gambling categories, and, since May 2026, a standalone US gaming subsidiary exporting the model. Experian has bought its way in, adding the RegTech firm KYC360 in late 2025 and the income-and-employment verifier Konfir in 2026 to a broader identity and fraud platform. Equifax runs a lighter offer through RiskScan, blending its Risk Navigator score with public data to flag financially vulnerable gambling customers from within its horizontal credit-risk portfolio.
The disagreement is commercial. If the mandated four-flag lookup becomes a commodity, competition moves to everything around it: identity proofing, the fallback route, dispute handling, audit trails. TransUnion is betting the assessment becomes the front door to a full gaming-compliance stack, Experian that the capability sells better inside a financial-crime suite, Equifax that a scoring product suffices. An operator choosing among them is choosing an architecture, not a data feed.
None of the three has published the number that matters: how reliably it can tie a real gambling customer to the right credit file. The metrics they do publish invite misreading. Experian's 82 per cent coverage figure measures its income-verification service's view of the payrolled workforce, a different product from the credit-file lookup. TransUnion's 330 categories describe its open banking product, not the primary check. And there is regulatory evidence the underlying files diverge: the Financial Conduct Authority's credit information market study found significant material differences in data coverage between the three large agencies, such that lenders can receive different perceptions of the same individual's credit risk depending on which agency they use, and the Commission's own pilot analysis reported learnings on data differences between agencies. Which agency an operator contracts with may, at the margin, change which customers get flagged. That is a procurement variable no tender yet prices.
The fallback that wants to be the default
The confirmed design gives open banking one job: when the credit file cannot match a customer, the operator verifies identity and may fall back to open banking or documents. The vendors are marketing well beyond it. TrueLayer argues a monthly credit-bureau snapshot is a dated way to judge affordability where bank-verified transaction data sees spend in real time; Trustly and Yaspa make adjacent cases for checks living inside the payment flow; GBG, FullCircl and Experian crowd in from the compliance side. The published vendor numbers are payments conversion figures, not assessment accuracy, and should be read as such.
Two external facts complicate the pitch. First, adoption: industry research puts active use of open banking at around one British adult in five, and separate polling has found a similar share saying they consider it secure. A fallback that depends on in-the-moment consent will lose some of the very hard-to-match, thin-file customers it exists to catch. Second, an inversion of the player-protection claim: banking oversight material from 2023 documented vulnerable consumers using account-to-account payments to route around card-based gambling blocks they had set themselves, because such payments can bypass merchant category code controls. Whether banks have since closed that gap is an open question, and a fair one for any operator's procurement team to put to a vendor selling open banking as native protection.
The deeper issue is targeting. The one independent test in view, a retrospective analysis of 243,478 gamblers' open banking data published in the journal Public Health in late 2025, found a £150 net-deposit trigger would flag nearly a quarter of the gamblers in its sample, roughly half of whom clustered as diversified spenders whose gambling appeared proportionate to income. The sample skews toward credit-seeking, digitally banked customers, a limitation the authors state plainly, but the direction of the finding is the point. Stage one sits far above that threshold, but the finding travels: a check can fire exactly as designed and still land on people who were never at risk. Ninety-seven per cent frictionless measures completion. Nothing yet published measures correctness.
The number nobody prints
The listed operators are exact about what regulation costs at the top line and silent about what compliance machinery costs to run. Entain has put percentage-point figures on lost growth, Rank prices the slot limits and statutory levy to the nearest million, Flutter has guided a £25 million to £50 million EBITDA impact for the whole White Paper suite, reaffirmed unprompted by its chief financial officer on the third-quarter 2024 call, and every group has modelled the 2026 duty rise. None breaks out the build: the engineering cost of a proprietary risk platform, per-query fees paid to agencies or integrators, the payroll of protection teams. Flutter's statement that it has seen no materially increased compliance cost from the vulnerability checks illustrates the point rather than settling it. Costs absorbed into operating expenditure are invisible, not absent.
The reticence is rational; a check engine is a competitive asset and query pricing is sensitive. But the consequence is that a regulator has just created a recurring, compulsory revenue line for the credit reference agencies, every threshold-crossing account generating query volume indefinitely by mandate, and nobody outside the contracting parties can size that market. The operators' silence on cost and the agencies' silence on price are two halves of the same gap. When the largest operators wire up at scale, that cost stops being an internal line item and starts shaping who can afford to compete.
The precedent is in the accounts
Audited financial statements already show what badly coordinated affordability enforcement does. Between 2021 and 2023, when operators imposed checks unilaterally at thresholds of their own choosing, Entain told investors the measures had removed roughly ten percentage points from its British online revenue growth rate, six points in 2023 alone, with spend per head falling every quarter from early 2021 to late 2024 as higher-value customers hit friction or migrated to looser competitors. The reversal came not from lighter regulation but from the voluntary industry code that standardised checks: spend per head grew in the fourth quarter of 2024 for the first time since early 2021, a turn Entain's chief financial officer attributed primarily to the code and the removal of friction from its own customer journeys.
The light-touch checks that followed were largely absorbed, and where they were not, the difference was mix. Rank's chief executive described them as having no effect or a slightly positive one, since they replaced blanket manual verification with a targeted trigger. Playtech reported a 16 per cent revenue decline in its Sun Bingo consumer segment, which the company attributed to financial vulnerability and affordability checks alongside tighter marketing restrictions. Same instrument, opposite outcomes, decided by implementation.
The pattern across both episodes is that measurable damage tracks friction and inconsistency, not the existence of a check. A credit-file lookup returning identical data points to every operator is, in principle, the cure. But consistent data does not force consistent decisions, and the disclosures show how much bespoke interpretation already sits on top: Rank screens every new digital depositor against an external credit profile and models affordability from postcode-level income data banded by age, Evoke built its own multi-dimensional harm model, Entain runs ARC. Three operators, three proprietary readings of financial risk. Stage one standardises the input. The guidance on how operators should respond, still to be developed with the industry during implementation, is where the fight over consistency moves next.
What the flag triggers
The public argument, frictionless versus intrusive, misses where friction lives. The Betting and Gaming Council contested the Commission's central figure in a letter to the regulator's interim chair dated 21 April 2026, first reported by The Sunday Times, arguing the 3 per cent headline holds only because the base includes casual players, and that excluding anyone spending under £200 a year puts the share of regular customers caught by a trigger closer to 20 per cent. The same reporting said the letter cited pilot data in which, for some categories of case, a risk flag was raised by only one of the three credit reference agencies in more than half of instances, the trade body's evidence that the system cannot yet reliably distinguish a vulnerable customer from an unlucky match. Its chief executive, Grainne Hurst, has located the problem more precisely than the trade body's headline numbers suggest, writing in a bylined article in May that "the biggest issue is what happens after a customer is flagged", and stating in the BGC's response to the July confirmation that the Commission has not demonstrated the underlying data is "accurate, reliable or consistent enough" to support regulatory decisions affecting customers. On that second point the trade body and the FCA's market study are, unusually, in agreement. Whichever participation figure is right, the lookup is rarely the friction. Friction lives downstream, in the questions, evidence requests and restrictions that follow a flag, and in the review workload behind them: Betsson's compliance teams manually reviewed more than 22,000 flagged customers in a single quarter, and Entain runs 460 dedicated customer-protection specialists executing over 12,000 safer-gambling interactions a week. A frictionless data call does not remove that work; a system that flags more customers feeds it. Payments has run this experiment before: under Strong Customer Authentication, firms that treated compliance as a bolt-on step lost customers at the checkout, while those that designed it into the flow barely noticed.
There is also a governance layer the debate barely touches. The assessment moves sensitive financial and gambling data between agencies, integrators and operators, engaging UK data protection law. The Information Commissioner's Office set out its position in 2023: data protection law does not prevent the checks, provided they are conducted transparently and proportionately. That settles the legality. It leaves undefined the harder operational questions: retention periods, the audit trail an assessment decision must leave and, above all, liability when a wrong decision harms a customer, whether the operator or the agency answers for a bad match. For compliance teams that undefined space is risk. For suppliers who can productise explainability and dispute handling, it is an opening.
Neither side can prove it
The industry's counterweight is the black market, and operators make the argument in their own accounts: Evoke warning of revenue decline partly through black-market leakage after the 2026 duty rise, Flutter cautioning the tax will push some customers toward unregulated operators, Entain citing France, where it puts the illegal share as high as 60 per cent. These disclosures are real, qualitative, and about tax rather than the assessment.
The quantified version rests on a narrow base. The headline figures, billions staked offshore, a nine-figure tax gap, a market forecast to double by 2028, trace to research commissioned by the BGC itself, principally from Frontier Economics and H2 Gambling Capital, then recycled across operator submissions, letters to sports bodies and press releases. H2 Gambling Capital was acquired in 2026 by the parent of EGR, a commercial publisher serving the same industry, a relationship readers should weigh themselves. Recycling is not corroboration; one commissioned study repeated ten times is still one study. A counter-reading exists: the Campaign for Fairer Gambling argued in a US Senate submission that most British-facing illegal gambling targets under-18s and the self-excluded, people outside the regulated market by definition, a characterisation the industry would dispute. Neither side has published the granular data on who actually leaves and why.
The regulator has been clear that no consumer had action taken against them during the pilot, which was not live. That is a defence against the migration claim, and an admission that the frictionless model's effect on real customer outcomes is untested. Both sides are arguing ahead of the evidence.
The next twelve months decide it
Three dated milestones convert this from argument to record. The implementation groups forming over the summer of 2026 are where response guidance, data standards and, in practice, supplier access will be shaped; who is in the room matters. The stage-one start date, to be published in the Commission's consultation response after that engagement, opens a compulsory buying window for every large operator not yet wired to an agency. The progress report due in December 2026 is the first public checkpoint on whether the machinery performs, the moment match rates, review volumes and disputes could first surface as evidence.
The executive takeaway is this. Financial risk assessment has stopped being a regulatory position to hold and become an operational capability to acquire, and the market for that capability, agencies, integrators, fallback rails and the guidance still unwritten, is forming now, largely out of public view. Operators should be pricing the machinery, not the policy. Suppliers should note that match accuracy, explainability and dispute handling are about to become the qualities customers are forced to buy. And everyone should hold both camps to the same standard the regulation now sets for customers: not whether the check completes, but whether it is right.



