Short answer
A custom casino platform is a player account system with a ledger at its centre: accounts and KYC, a wallet, a bonus engine, a game-provider integration layer, payments, responsible-gambling controls, a back office and regulatory reporting. Build the ledger and wallet first, connect game content through one integration layer, and design for certification from the start: GLI-19 v3.0 is the Gaming Laboratories International standard for interactive gaming systems. Rent what is not your advantage, such as a game aggregator or KYC, and own what your product differs on, usually bonuses, the wallet and the data.
| Component | What it owns | Usually built or rented |
|---|---|---|
| Player accounts (PAM) and KYC | Registration, identity checks, account status, limits, exclusions | Accounts built; identity verification rented from a KYC provider |
| Wallet and ledger | Every balance movement as an entry; real money, bonus money, pending withdrawals | Built: the rest of the platform depends on it |
| Game integration layer | Launch, sessions, debit, credit and rollback calls from game providers | Built as one internal contract, with content from an aggregator or direct |
| Bonus engine | Offers, wagering progress, free rounds, expiry, bonus-to-cash conversion | Built when promotions are your advantage |
| Payments | Deposits, withdrawals, payment-provider routing, reconciliation | Built as an orchestration layer over rented payment providers |
| Responsible gambling | Deposit, loss and time limits, pauses, self-exclusion, alerts | Built, because rules differ by market |
| Back office and CRM | Player support, manual adjustments with an audit trail, segments | Built or rented, depending on how much the team customises |
| Regulatory reporting | Records and reports in each regulator's format | Built per market |
| Front end and CMS | Lobby, pages, localisation | Built or rented; often the first thing a brand changes |
Three routes exist: rent a whole platform, build your own, or split, renting some layers and owning the rest. Published figures help set the scale.
SOFTSWISS's cost calculator says "it is reasonable to plan for an initial investment starting from EUR 1 million to cover setup and the first year of operations", listing company setup and legal registration, licence acquisition, software purchase or integration, website and front-end development and initial marketing as one-time costs, and licence fees and software maintenance, staff, marketing, payments, bonus payouts, game provider fees, taxes and compliance as recurring ones[2].
A platform agreement filed with the U.S. SEC, between Pragmatic Solutions (IOM) Limited and HR Entertainment Ltd and dated 31 January 2023, sets a EUR 40,000 platform setup fee and a EUR 20,000 migration fee, a EUR 15,000 monthly minimum, royalties of 2.00% of GGR up to EUR 1,000,000 and 1.50% above it, and a 3-year term[4].
The same agreement licenses the platform for use "in object code form only", states that "the Supplier retains all Intellectual Property Rights in and to the Platform and applicable Documentation", and sets termination compensation as the monthly minimum multiplied by the number of months outstanding of the term[4].
These are the terms you replace when you build, and the ones you keep when you split. One such split: an own wallet, bonus engine and back office, with a rented game aggregator and rented KYC. It keeps the data and the product logic yours without rebuilding content integrations from scratch. What the rented platforms publish, vendor by vendor, is on SOFTSWISS alternatives, Pragmatic Solutions PAM alternative and SOFTSWISS vs EveryMatrix.
A ledger, not a balance column. Store every movement as an immutable entry and derive balances from entries. Retries from game providers, payment callbacks and manual adjustments then become lookups and new entries, not overwrites, and a regulator's question about one transaction is answered from records.
Bonus money as its own balance. Keep bonus money, wagering progress and loyalty points apart from withdrawable cash, so a bonus can be granted, wagered, converted or forfeited without touching the cash ledger. The bonus engine also has to encode what a market forbids.
Brazil's regulator states that, to prevent bettor indebtedness, offering credit to bet and sign-up bonuses to attract bettors is forbidden, as is the use of credit cards, with the measures in force from 1 January 2025[5].
Identity and money as a closed loop. Registration owns identity, and the cashier owns which instruments a player may use. Some markets fix both in their rules.
The SPA states that every bettor has to be identified with documents and a "sistema de reconhecimento facial com prova de vida", and has to register a bank or payment account in their own name that is "a origem e o destino de todos os recursos que enviar ou receber da empresa de apostas"; operators are forbidden to accept deposits from any other account, and deposits or prizes in cash or by boleto are prohibited[5].
Records designed for the regulator from the first table. Retention, backup and export rules reach into the data model, so they are decided before it exists.
The SPA states that operators must keep an updated backup, for at least five years, of all data relating to bettors and operations, under Annex I of Ordinance SPA/MF 722/2024; that the data must be updated at least every 24 hours; and that its integrity and correspondence must be tested at least every seven days[5].
Game content is certified, and the catalogue has to know it. Certification is a gate on which games may be offered, per market, so the catalogue carries certification data and the lobby filters on it. The regulator's own wording for Brazil: every online game must be certified, and from 1 January 2025 operators may offer only online games sent via Sigap and certified by the five certifying entities authorised by the SPA[5]. The integration side is on casino game aggregation and integration; the full reading of Brazil's rules is on Brazil sportsbook platform requirements.
Configuration per market and brand. Limits, game availability, bonus rules, tax and reports differ by jurisdiction. Treat them as data with versioned changes, so a market launch is configuration and certification, not a fork of the code.
SOFTSWISS's knowledge base says of the move from a white label to an own platform: "Migration requires new investment, compliance re-certification, and regulatory approval timelines"[3].
The sequence that holds up in practice, with licence and payment accounts moved first, is in moving from a white label to your own platform. If you are on SOFTSWISS specifically, the exit checklist is on the SOFTSWISS alternatives page.
About amBrain
Related on this site: iGaming platform case study.
Player accounts and KYC, a wallet and ledger, a game integration layer, a bonus engine, payments, responsible-gambling controls, a back office and regulatory reporting, plus the front end. Some of these are usually rented, such as identity verification and payment providers.
Build what your product differs on and what holds your data, usually the wallet, bonus engine and back office. Renting a game aggregator and KYC keeps the build smaller.
It depends on the market. GLI-19 v3.0 is the Gaming Laboratories International standard for interactive gaming systems[1], and regulators add their own rules: Brazil's SPA, for example, requires every online game to be certified and, from 1 January 2025, offered only after certification by the entities it has authorised[5].
Few suppliers publish prices. One agreement filed with the U.S. SEC sets a EUR 40,000 setup fee, a EUR 15,000 monthly minimum and royalties of 2.00% and 1.50% of GGR over a 3-year term[4]. Your quote will differ.
Yes, but plan for re-certification and regulatory approval, not only data import[3]. Agree the export format with the current provider before notice, then run both platforms in parallel and cut over by market.
Product and company names are trademarks of their respective owners and are used only to identify their products and published documents. No vendor named here reviewed or endorsed this page. The regulatory passages are an engineering reading of the SPA's own FAQ, read on 2026-09-23, not legal advice, and nothing here says which operators hold authorisations.
Related