ESBK
1) Brief (TL; DR)
ESBK is the federal casino regulator in Switzerland. He issues and renews licenses, recognizes/approves online extensions for land-based casinos, controls the integrity of games, information security and compliance (AML/KYC, Responsible Gaming), applies coercive measures and administers the operators' obligation to report and pay tax on GGR (in favor of AHV and budget). For lotteries and wagers, the cantons answer via Gespa; ESBK oversees casino & online-casino.
2) Mandate and legal framework
Base: Casino Law 1998 (Spielbankengesetz, SBG) and Modern "Money Gaming" Law 2019
ESBK responsibility:- land casinos (A/B), online casinos (only as an extension of land operator licenses), integrity and technical standards control, supervision of AML/KYC and Responsible Gaming, financial control (reporting, GGR → AHV tax).
3) Licensing: A/B types and online extension
Type A: large venues with a full range of games and high limits.
Type B: regional/resort facilities with limited limits/nomenclature.
Online permit: issued only to the operating land casino after tech/compliance assessment (games, providers, hosting, geofiltration, journaling, RG support).
License cycle: application → due diligence of shareholders and management (fit & proper) → assessment of business plan and risks → technical audits → conditional/full permission → periodic supervision and renewal.
4) Responsible Gaming (RG)
Player tools: self-exclusion, deposit/time/loss limits, "cooling."
Operator processes: identification of vulnerable players, documented interventions, staff training, access to assistance.
Online requirements: mandatory verification of age/personality, a single client record, visibility of risks and conditions, transparent bonuses.
5) AML/KYC and financial circuit
KYC before admission to play and payouts; verification of sources of funds according to the risk approach.
Transactional monitoring: anomaly scenarios, reporting thresholds, case-management.
Control of payment providers: contracts, SLA, audit of compliance with procedures.
Reporting and tax: correct accounting of GGR, deductions to AHV; independent reviews.
6) Honesty of games and technical standards
Approval of each game: RNG/slot certification, verification of payment tables, firmware/build versions under control.
Technical infrastructure: segmentation of environments, key management, logs/audit trail, redundancy, response plan (IR).
Cybersecurity: WAF/DDoS, SIEM monitoring, penetration tests, supplier control (including studios and aggregators).
7) Advertising, bonuses and UX communications
Moderation and truthfulness: prohibition of hyper-announcements and hidden conditions.
Protection of vulnerable groups/minors: targeting and creativity under control.
Bonuses: clear rules of the vager, deadlines, exceptions - explicitly before activation.
8) Grey market blocking and coordination
Online casinos: a list of unlicensed sites for blocking in the casino part - with the participation of ESBK.
Lotteries/Betting: Block List and Supervision - Gespa Zone.
Joint actions: information exchange, synchronization of RG/AML approaches, interaction with telecom operators.
9) Supervisory tools and sanctions
Inspections and investigations: scheduled/sudden inspections, requirement of documents and technical data, interviews with responsible persons.
Impact measures: prescriptions, fines, product line restrictions, suspension/revocation of permits.
Publicity measures: Discipline the market and strengthen consumer confidence.
10) Interaction with the ecosystem
Gespa (cantons): coordination on advertising, RG and block lists; delimitation of powers of "casino" vs "lottery/bet."
FINMA/financial sector: exchange of risk signals on payments and providers if financial issues are raised.
International cooperation: dialogue with EU/EEA regulators on anti-fraud and fair play, industry forums.
11) What is important to the operator (practical checklist)
People: fit & proper management, independent compliance officer, trained RG teams.
Processes: updated policies (AML, RG, IS), role-based access, logging, IR plan.
Technologies: certified RNG/games, secure infrastructure, monitoring, redundancy.
Reporting: timely data on GGR/taxes, incident-reports, KPI RG/AML.
Suppliers: due diligence of studios/aggregators/payment partners, those and compliance-SLA.
12) Supervision and Maturity KPI
Compliance: 0 critical violations; period of elimination of non-conformities.
RG: share of players with limits, speed of interventions, return after pauses.
AML: auto-approve KYC share with low false positives, timeliness of STR/reports.
Information security: MTTD/MTTR, critical level vulnerabilities - 0 in prod.
Finance: accuracy of GGR reporting, timely payment of tax in AHV.
13) The bottom line
ESBK provides "Swiss quality" in the casino sector: a strict license, a high standard of player protection, financial transparency and technological discipline. In conjunction with Gespa and the modern law of 2019, the model does not make the market massive, but reliable and culturally inscribed: it wins the confidence of players, the stability of operators and public interest.