iGaming compliance: scaling from 9 to 900
I joined Kaizen Gaming when it was nine people. I left with a roughly 900-person operation behind me and three departments I had built from scratch. This is what broke at each stage.
New to the topic?What is regulatory compliance?The plain-English foundation: what compliance is, what the function does day to day, and how it works across multiple licences.Scaling stories are usually told as a smooth curve. They are not smooth. Growth arrives in steps, and at each step something that worked perfectly the week before stops working entirely. Below is the honest version of scaling risk and compliance inside an iGaming operator that went from a room of nine people to a business of around nine hundred, powering Stoiximan and Betano's international expansion.
9 to 30 — everything is one person and that is fine
At this size compliance is a person, not a function. Everyone knows every customer issue. Decisions are made by walking across the room. The only real job is to write things down: which permissions the company holds, what it promised the regulator, and what it actually does. The team that skips this stage pays for it three years later when someone asks for evidence from a period nobody documented.
30 to 100 — the first break: informal escalation
Walking across the room stops scaling first. Cases start getting decided differently depending on who picks them up. This is where the first department has to exist: defined case types, defined thresholds, defined escalation. Not sophisticated — just written and consistent. Consistency is the entire product of a compliance function, and this is the stage where you either establish it or spend years retrofitting it.
- Named case types with owners and SLAs.
- A written escalation matrix, one page.
- First reporting pack: volumes, ageing, decisions.
100 to 300 — the second break: multiple markets at once
New markets arrive faster than the operating model adapts. The temptation is to let each market team solve its own compliance problem, because it is faster this quarter. It is the most expensive shortcut available. This is the point at which I built the group standard plus local annex model: one control set, one risk scoring model, thin per-market deltas. It slowed down the third market launch and made every launch after it dramatically faster.
Scaling compliance is not about doing more of the same work. It is about deciding, early, what will never be allowed to differ between markets.
300 to 600 — the third break: data
Around this size, the constraint stops being people and becomes information. Analysts spend more time gathering context than deciding. The fix is structural: one customer record, one case system, evidence written at the moment the control runs rather than reconstructed at audit time. Every hour of gathering you remove is an hour of judgement you get back, and judgement is the only thing you actually pay a compliance analyst for.
600 to 900 — the fourth break: management depth
At this scale the head of function cannot see the work any more. You need team leads who own quality, a QA loop independent of the people doing the work, and a training path that turns a new hire into a productive analyst on a predictable timeline. Three departments built from scratch is really three answers to this problem: separating financial crime, regulatory operations and customer-facing risk so each has its own leadership, metrics and career path.
What I would do differently
- 1.Write the group standard at 50 people, not at 200.
- 2.Instrument the function with metrics from day one — retro-fitting measurement is painful.
- 3.Invest in the single customer record a full year earlier than felt justified.
- 4.Build the QA loop before it is obviously needed, because by then it is already late.
- 5.Hire throughput before seniority, and internal trainers before external consultants.
Why this transfers beyond iGaming
iGaming is a useful teacher because it combines high transaction volume, real-time decisions, strict licence conditions and multiple regulators with different opinions. Any sector with those four properties — payments, crypto, lending, marketplaces — hits the same breaks in the same order. The specifics of the regulation change. The sequence of what breaks does not.
Frequently asked
How does a compliance team scale from a startup to hundreds of people?
In steps, not smoothly. Informal escalation breaks first, then per-market fragmentation, then data quality, then management depth. Each break needs a structural fix rather than more headcount.
What does building a compliance department from scratch involve?
Defined case types and escalation, a group-level control set with local annexes, measurement from day one, a single customer and case record, and an independent quality-assurance loop before it feels necessary.
Do iGaming compliance lessons apply to other industries?
Yes. Any sector with high transaction volume, real-time decisions, strict licence conditions and multiple regulators — payments, crypto, lending, marketplaces — hits the same constraints in the same order.
Building or scaling a compliance function?
I have done this from zero three times, across multiple licences and a NYSE-listed parent. Happy to compare notes.
Keep reading
A plain-English definition of regulatory compliance, what a compliance function actually does day to day, and how it works across multiple licences and jurisdictions.
A practical playbook for building a compliance function from one person to a real department: first 90 days, hiring order, frameworks, and multi-jurisdiction ops.
An operator's view of compliance automation: which processes genuinely automate, which ones should not, how to sequence tooling, and how to avoid buying a platform you cannot feed.
How to redesign a compliance operations division across multiple licences without stopping the business — sequencing, evidence, and running the programme on public-market timelines.