How to Build a Casino Platform for a UAE iGaming License (GCGRA 2026 Guide) | Capermint
UAE iGaming · GCGRA Compliance · 2026 Edition
How to Build a Casino Platform That Complies With a UAE iGaming License
The UAE is now a fully regulated commercial gaming jurisdiction. Federal Decree-Law No. 25
of 2025 took effect on 1 June 2026, the GCGRA has issued its first internet gaming and sports wagering
licences, and Wynn Al Marjan opens in 2027. This is the complete technical and regulatory blueprint for the
platform you need to build — license categories, GLI standards, AML architecture, geolocation, taxation,
permitted games and real build costs.
Updated: August 2026Read time: 26 minBy: Capermint Technologies
$3–5B
Projected UAE gaming TAM
5
GCGRA license categories
9% + 5%
Corporate tax + VAT
21+
Minimum player age, UAE-located
CT
Capermint Technologies | iGaming Platform Development Company · Ahmedabad,
India
Founded 2014 · 500+ games and real-money platforms delivered · 40+ countries
served including UAE · Custom, turnkey, white-label and crypto iGaming platforms · 100% source
code ownership transferred to clients
Published August 2026 · Primary sources: GCGRA official portal (gcgra.gov.ae),
Federal Decree-Law No. 25 of 2025, GCGRA Technical Standards (GLI series), GCGRA Advertising
Standards, GCGRA Licensee Register, Khaleej Times, iGaming Business, Vixio, Alvarez & Marsal,
Wynn Resorts investor disclosures
For the first time in its history, the United Arab Emirates has a working federal framework for
commercial gaming — and the technology requirements attached to it are among the most demanding in any
new jurisdiction. The General Commercial Gaming Regulatory Authority (GCGRA),
established by federal decree in September 2023 and headquartered in Abu Dhabi, holds exclusive
jurisdiction over lottery, internet gaming, sports wagering and land-based gaming facilities across all
seven emirates. There is no emirate-level alternative and no free-zone workaround. Every route into this
market runs through the GCGRA.
The commercial prize is substantial. Wynn Resorts projects a total addressable UAE gaming market of
$3 billion to $5 billion; CBRE has cited projections as high as $8.5 billion in annual
gross gaming revenue if three to four integrated resorts are built. Bloomberg Intelligence has modelled
$6.6 billion. Play971, operated by Coin Technology Projects LLC, went fully live in December 2025 as the
country's first authorised real-money online sportsbook and iGaming platform. The window for second and
third movers is open right now.
But the barrier is deliberately high, and it is largely a technology barrier. The GCGRA has
adopted the full Gaming Laboratories International standard series as its technical framework. It
expects a demonstrably robust AML and KYC framework to exist before a licence is granted, not
after. It requires emirate-level geolocation enforcement, immutable audit trails, certified RNG and a
responsible gaming control stack. This guide walks through every one of those requirements and what each
means for the platform you actually have to build.
Quick Answer
How do you build a casino platform that complies with a UAE iGaming license?
To comply with a UAE GCGRA iGaming license, your casino platform must be architected to the
GLI-19 (Interactive Gaming Systems) and GLI-33 (Event Wagering
Systems) standards, with a compliance core built before any player-facing feature. That
core comprises: a certified RNG, a player account management (PAM) system with segregated player
funds, KYC orchestration with document and liveness verification enforcing a 21+ minimum age, AML
transaction monitoring with sanctions and PEP screening, continuous emirate-level geolocation
enforcement, a responsible gaming control set including self-exclusion, and an immutable audit log
that can produce regulator-ready reports on demand. Content must come only from GCGRA-licensed
suppliers. Payments must be fiat AED — crypto sits outside the current GCGRA perimeter.
RegulatorGCGRA, Abu Dhabi — exclusive federal jurisdiction, all 7 emirates
Governing lawFederal Decree-Law No. 25 of 2025, in force 1 June 2026
Technical standardsGLI-19 + GLI-33 (plus GLI-11/13/16/17/18/21/24/25/28 by scope)
Minimum age21 years, physically located in the UAE
Taxation9% corporate tax (15% top-up for large groups) + 5% VAT
Platform build cost$40K white-label to $700K+ custom compliance-first
Short answer: Online gaming is legal in the UAE only under a valid
GCGRA licence. Federal Decree-Law No. 25 of 2025, effective 1 June 2026, removed
Articles 1012 to 1019 (the gambling and betting chapter) from the UAE Civil Transactions Law, making
licensed gaming contracts legally enforceable for the first time. Unlicensed operation remains a
criminal offence under the Penal Code, and the GCGRA has stated that facilitators
of unlicensed activity are exposed alongside operators.
Understanding the legal architecture matters because it determines your risk posture as a technology
provider as well as an operator. Four developments sit on the timeline:
Date
Development
What it changed
September 2023
GCGRA established by Federal Law by Decree
Created the UAE's first federal gaming regulator with exclusive jurisdiction over commercial
gaming across all seven emirates. Headquartered in Abu Dhabi.
2024
First lottery licence issued to The Game LLC
Proved the licensing machinery worked. Mahzooz and Emirates Draw lost their bids in the same
round, establishing that the process is genuinely competitive and exclusionary.
Late 2024
Wynn Al Marjan receives first land-based licence
Island 3 AMI FZ-LLC licensed for the UAE's first integrated resort casino in Ras Al Khaimah.
$5.1 billion project, 225,000 sq ft gaming floor, opening 2027.
28 Nov 2025
First internet gaming and sports wagering licence
Coin Technology Projects LLC licensed as the 19th GCGRA licensee. Play971 soft-launched
within a week and went fully operational on 15 December 2025.
1 June 2026
Federal Decree-Law No. 25 of 2025 in force
Removed the civil-code gambling prohibition chapter, eliminating the legal tension where
licensed operators held valid authorisation under a civil code that declared gaming
contracts void.
The civil code change did not legalise unregulated gambling — and this
distinction is commercially critical. Removing Articles 1012 to 1019 created the legal
architecture for GCGRA-licensed gaming to function as enforceable commercial activity. It did
nothing for anyone operating outside the licence perimeter. UAE Penal Code provisions remain fully
in force, operating any commercial gaming without a valid GCGRA licence is still a criminal offence,
and the GCGRA has issued Consumer Advisory Notices warning residents about unlicensed operators. If
you are building a platform intended to serve UAE players, the licence is not optional
infrastructure — it is the precondition for the business existing at all.
Market Size and the Commercial Opportunity
$3–5B
UAE total addressable gaming market
Wynn Resorts investor projection
$8.5B
Upper-bound annual GGR estimate with 3–4 integrated resorts
CBRE Capital Advisors, G2E
$1.33B
Wynn Al Marjan base-case steady-state GGR projection
Range: $1.0B to $1.66B
1
Licensed internet gaming operators as of the current register
Coin Technology Projects LLC (Play971)
UAE Gaming Market Projections and Licensee Growth (Indicative)
Sources: Wynn Resorts investor presentation; CBRE Capital Advisors (G2E);
Bloomberg Intelligence; GCGRA public licensee register; JP Morgan Securities commentary on UAE TAM
assumptions
The structural case for the UAE is not just market size — it is market quality. JP Morgan noted
that the project's core target markets represent roughly 25 percent of the world's population, 20
percent of global GDP and nearly 20 percent of global high-net-worth wealth. The UAE has 99 percent
internet penetration, top-five global smartphone penetration, no personal income tax on player winnings,
and a resident and tourist population with among the highest disposable incomes in the region.
The scarcity is the other half of the thesis. The number of licences is deliberately limited and the
suitability bar is deliberately high. A licensed platform in this market is not competing against a
hundred grey-market operators — it is competing in a closed, supervised environment where regulatory
standing is itself the moat.
The Five GCGRA License Categories
Short answer: The GCGRA grants five licence categories — three for entities and two
for individuals. Most platform and software companies enter through the Gaming-Related
Vendor category. Player-facing operators need a Gaming Operator
licence. Your directors and controllers separately need Key Person licences. Many
businesses require multiple licences simultaneously.
Entity Licenses
Entity License 01
Gaming Operators
Entities operating internet gaming platforms, sports wagering, land-based gaming
facilities, and the lottery and lottery retailers. This is the player-facing licence — the one
that permits you to accept real-money wagers from UAE-located players.
Who needs itOnline casino operators, sportsbook operators, integrated
resort casino operators, lottery operators and retailers.
Entity License 02
Gaming-Related Vendors
Suppliers of gaming equipment or related goods and services. This is the
category into which platform providers, game studios, aggregators, RNG suppliers, geolocation
providers and payment technology vendors fall. It is the most accessible entry point for
technology companies because it does not require player-facing operations.
Who needs itPlatform and PAM providers, game content studios,
aggregators, geolocation and KYC vendors, payment technology suppliers, sports data providers.
Entity License 03
Key Persons — Corporates
Entities holding decision-making roles within the ownership structure of
applicants or licensees, including but not limited to controllers, affiliates and management
service providers. This catches holding companies and parent entities that sit above the
licensed operating company.
Who needs itHolding companies, controlling shareholders that are
corporate entities, affiliates, management service providers.
Individual Licenses
Individual License 01
Key Persons — Individuals
Individuals holding executive decision-making roles within applicant or licensed
entities, including but not limited to directors, executive officers and controllers. These
individuals undergo personal suitability investigation covering integrity, financial standing
and source of wealth.
Who needs itDirectors, C-suite executives, individual controlling
shareholders, compliance officers with decision authority.
Individual License 02
Gaming Employees
Individuals working for, or otherwise connected with, applicants or licensees.
The breadth of this category is deliberate — it extends the regulatory perimeter down to
operational staff who touch gaming systems or player funds.
Who needs itOperational staff, dealers, platform administrators,
customer support handling player accounts, payments staff.
The vendor licence is the strategic entry point most technology businesses
miss. If you are building an iGaming platform, a game studio, an aggregator or a
compliance service, you do not need to become a player-facing operator to enter the UAE market. The
Gaming-Related Vendor category exists precisely for you, it carries no player-facing operational
burden, and the existing vendor register — Aristocrat, Novomatic, IGT, Konami, Playtech, Endorphina,
Games Global, Sportradar, GeoComply and others — shows exactly which suppliers have already taken
that route. For a B2B technology company, vendor licensure plus supply agreements with licensed
operators is a materially faster and cheaper path to UAE revenue than pursuing an operator licence.
The GCGRA Licensing Process, Step by Step
Short answer: The GCGRA process runs in five published stages: (1)
Intake Form and preliminary screening, (2) portal access and full application
submission, (3) suitability investigation, (4) compliance and
ongoing monitoring, (5) renewals and amendments. The GCGRA engages with applicants
directly only — it does not entertain impromptu meetings and all meetings are by
appointment via email request.
GCGRA Licensing Process · Official Five-Stage Pathway
STAGE 01
Intake Form
Notify intention to apply. Name the licence type(s). Basic entity data
for initial screening.
STAGE 02
Portal Submission
If screened eligible, gain portal access. Submit full application,
business plan and compliance strategy.
STAGE 03
Suitability Investigation
Rigorous assessment of eligibility, integrity and operational capability
against GCGRA standards.
STAGE 04
Compliance & Monitoring
Periodic regulatory reporting and ongoing supervision of approved
licensees.
STAGE 05
Renewal & Amendment
Ongoing licence maintenance, scope amendments and periodic renewal.
Platform planning note: Stage 03 is where technology
readiness is assessed. The GCGRA expects a demonstrably robust AML and KYC framework to exist
before a licence is granted, not as a post-approval commitment. This means your platform
build and your licence application must run in parallel. Applicants who submit an
application intending to build the compliance stack afterwards are the ones who stall at Stage 03.
What the Suitability Investigation Examines
Corporate structure and beneficial ownership: a UAE-registered legal entity or a
credible plan to establish one, with a fully traced ownership chain to ultimate beneficial owners.
Opaque structures are the fastest route to rejection.
Integrity and probity of key persons: criminal record checks, regulatory history in
other jurisdictions, litigation history, and personal financial standing for every director,
executive officer and controller.
Source of funds and source of wealth: documented provenance of the capital funding
the venture. This is bank-grade scrutiny, not a formality.
Financial capacity: audited financials, capital adequacy to cover player
liabilities and operating runway, and evidence that player funds can be segregated and protected.
Business plan: product scope, target market, revenue model, marketing plan and
growth projections, all of which must be internally consistent with the technology you propose to
deploy.
Compliance framework: written AML/CFT policy, KYC procedures, responsible gaming
policy, complaints handling, data protection and incident response — each supported by the systems
that actually enforce them.
Technology and operational capability: platform architecture, certification status,
security posture, hosting arrangements, disaster recovery and the reporting capability the regulator
will rely on for supervision.
Building the platform your GCGRA application will be judged on?
Capermint architects iGaming platforms to GLI-19 and GLI-33 from the first sprint, with the AML,
KYC, geolocation and reporting evidence pack the suitability investigation asks for. NDA first,
itemised scope within 48 hours.
Who Is Already Licensed — The Current GCGRA Register
The public licensee register is the single most useful strategic document in this market. It tells you
exactly which categories are being granted, which suppliers have already cleared suitability, and where
the gaps are. Here is the register as published by the GCGRA:
Category
Licensees
What it signals
Lottery
The Game LLC (operator of the UAE Lottery)
First licence category activated. Mahzooz and Emirates Draw lost their bids in the same
round.
Land-Based Gaming Facilities
Island 3 AMI FZ-LLC (DBA Wynn Al Marjan)
Single land-based licensee to date. $5.1B project in Ras Al Khaimah, 225,000 sq ft
gaming floor, opening 2027.
Internet Gaming
Coin Technology Projects LLC
The only internet gaming licensee. Operates Play971 from Twofour54 Yas Creative Hub, Abu
Dhabi. Fully live 15 December 2025.
Sports Wagering
Coin Technology Projects LLC
Same entity holds both online licences — a dual-licence structure worth noting for
anyone modelling a combined casino and sportsbook product.
Gaming-Related Vendors
Aristocrat Technologies Europe, Novomatic AG, Scientific Games International,
International Game Technology (IGT), Konami Gaming, LNW Gaming, Endorphina, GG UAE
Limited (Games Global), VSTechnology (Playtech), Hub 88 Holdings, Live Online Gaming
Services (Live88), Sportradar AG, GeoComply Solutions, Xpoint Technology FZ LLC,
Smartplay International, EQL Games, Brightstar Lottery Cyprus, Random State AB, Fennica
Gaming, TCS John Huxley Singapore, Pollard Banknote, Arena Leisure, Cammegh Limited
The deepest category by count. Content studios, aggregators, geolocation providers,
sports data and land-based equipment suppliers have all cleared suitability. This is the
practical entry route for B2B technology companies.
Read the vendor register as a gap analysis. Two geolocation providers
(GeoComply, Xpoint) are licensed — which tells you geolocation is a hard requirement, not a
nice-to-have. Sportradar is licensed — sports data integrity is expected. Multiple content studios
and aggregators are licensed — the content supply chain is forming. What is comparatively thin is
the platform and PAM layer, and operators seeking an alternative to the incumbent platform
provider have limited licensed options. For any operator planning a second or third UAE brand, that
gap is the reason building or commissioning your own compliant platform is a stronger strategic
position than waiting for a white-label slot to open.
GLI Technical Standards: The Actual Engineering Specification
Short answer: The GCGRA has adopted the Gaming Laboratories International
(GLI) standard series, produced by GLI in collaboration with legal experts, as its
technical framework for testing and certifying gaming technology. For an online casino and
sportsbook the two governing documents are GLI-19 (Standards for Interactive Gaming
Systems) and GLI-33 (Standards for Event Wagering Systems). The GCGRA
states plainly that operators are responsible for being aware of and complying with these standards.
This is the section most operators underestimate. A GLI standard is not a policy document — it is a
detailed engineering specification covering RNG behaviour, game fairness, account management,
transaction integrity, reporting, security and recovery. Building to it after the fact means rewriting
the core. Here is the full set the GCGRA publishes, mapped to what each governs:
Standard
Governs
Applies to your build if…
GLI-19
Standards for Interactive Gaming Systems
Always, for online casino. The core specification for your platform:
RNG, game integrity, player account management, session handling, transaction logging,
reporting and recovery.
GLI-33
Standards for Event Wagering Systems
Always, for sportsbook. Bet placement, odds handling, settlement, void
and cancellation logic, in-play wagering integrity and event data sourcing.
GLI-11
Standards for Gaming Devices
You supply or operate physical gaming devices or slot machines.
GLI-12
Progressive Gaming Devices in Gaming Facilities
Your product includes progressive jackpots in a land-based facility.
GLI-13
On-Line Monitoring and Control Systems (MCS) and Validation Systems
You operate a monitoring or validation system in a gaming facility.
GLI-14
Finite Scratch Ticket and Pull-Tab Systems
Your product includes instant-win or scratch mechanics.
GLI-15
Electronic Bingo and Keno Systems
You offer bingo or keno verticals.
GLI-16
Cashless Systems in Gaming Facilities
You implement cashless wallet functionality in a facility.
GLI-17
Bonusing Systems in Gaming Facilities
You run bonus, comp or loyalty award systems.
GLI-18
Promotional Systems in Gaming Facilities
You run promotional campaigns, free bets or prize draws.
GLI-20
Standards for Kiosks
You deploy self-service kiosks or retail terminals.
GLI-21
Client-Server Systems
Your architecture uses a thin-client model with server-side game logic.
GLI-24
Electronic Table Game Systems
You offer electronic roulette, blackjack or baccarat tables.
GLI-25
Dealer Controlled Electronic Table Games
You operate hybrid dealer-controlled electronic tables.
GLI-26
Wireless Systems Standard
Your deployment includes wireless gaming systems.
GLI-28
Player User Interface Systems
You build a distinct player-facing interface layer — which most modern platforms do.
GLI-29
Card Shufflers and Dealer Shoes
You supply physical shuffling equipment.
What GLI-19 Actually Requires From Your Platform
Certified RNG with demonstrable statistical integrity: the random number generator
must be independently tested and certified. Seeding must be cryptographically sound, the period must
be sufficient, and the output must pass statistical randomness testing. Client-side RNG is not
acceptable — game outcomes must be determined server-side.
Server-authoritative game logic: the client is a rendering layer only. Every
outcome, balance change and state transition is determined and recorded on the server. Any
architecture where the client can influence outcomes fails immediately.
Complete and immutable transaction logging: every wager, win, deposit, withdrawal,
bonus award, adjustment and session event must be logged with sufficient detail to reconstruct any
player's full history. Logs must be tamper-evident.
Player account management integrity: account creation, verification status, balance
handling, limits and self-exclusion states must be enforced consistently across every entry point —
web, mobile web, native app and any API.
Game recovery and interrupted-session handling: if a session drops mid-game, the
platform must be able to restore or correctly settle the game state. This is a common certification
failure point in platforms not built for regulated markets.
Published and enforced RTP: return-to-player values must be certified, accurate and
not silently variable. Any RTP configuration capability must be controlled, logged and within
certified bounds.
Reporting capability: the platform must be able to generate the operational,
financial and regulatory reports the authority requires, on demand and for arbitrary historical
periods.
The Compliance-First Platform Architecture
Short answer: A GCGRA-ready platform is built in five layers, and
the order of construction matters. The compliance core (PAM, wallet, AML/KYC, geolocation,
responsible gaming, audit log) is built first. The game and content layer, the
payment layer and the player-facing front end are built on top of it. Platforms built the other way
around — front end first, compliance retrofitted — are the ones that fail certification and stall at
the suitability investigation.
Player Account Management (PAM), segregated player wallet and ledger, KYC
orchestration, AML transaction monitoring, geolocation enforcement service, responsible gaming
control set, immutable audit log. Everything else depends on this layer being correct.
Layer 2 — Game Engine & Content
GLI-19 GOVERNED
Certified server-side RNG, game session manager, bet and settlement engine,
RTP configuration control, aggregator integration layer connecting only to GCGRA-licensed
content suppliers, jackpot and bonus engines.
Layer 3 — Sportsbook Engine
GLI-33 GOVERNED
Odds ingestion from licensed data providers, market and event management,
bet placement and acceptance rules, in-play handling, risk and liability management, settlement,
void and cancellation logic, cash-out engine.
Layer 4 — Payments & Financial
PCI DSS + AML
AED-first payment orchestration, local UAE rails, PCI DSS compliant card
handling, deposit and withdrawal workflow with source-of-funds capture, payout approval queue,
reconciliation and financial reporting.
Layer 5 — Player Experience
GLI-28 GOVERNED
Responsive web and native mobile clients, onboarding and verification
journey, lobby and game discovery, account and limits management, bilingual English and Arabic
interface with full RTL support, CRM and engagement.
The PAM and Wallet Layer
The Player Account Management system is the regulatory heart of the platform. It is what the regulator
supervises, what the auditor examines and what determines whether you can evidence compliance. It must
handle:
Single player identity across all products: one verified identity, one wallet, one
set of limits and one self-exclusion state spanning casino, live casino and sportsbook. Separate
silos per vertical are a compliance failure — a self-excluded player must be excluded everywhere,
instantly.
Segregated player funds with a double-entry ledger: player balances must be
accounted separately from operating funds, with every movement recorded as a balanced double-entry
transaction. This is what makes financial reporting and player-liability reporting possible.
Verification state machine: accounts move through explicit states (registered,
pending verification, verified, restricted, suspended, self-excluded, closed) with strictly defined
permitted actions in each state. Un-verified accounts must be prevented from withdrawing.
Full limit framework: deposit limits (daily, weekly, monthly), loss limits, wager
limits, session time limits and reality-check intervals — each player-settable, with decreases
taking effect immediately and increases subject to a cooling-off period.
Complete activity history: every player must be able to retrieve their own
transaction and gameplay history, and the operator must be able to produce it for the regulator for
any period.
Bonus and promotion ledger: bonus funds tracked separately from cash, with wagering
requirement progress, expiry and conversion fully auditable. Bonus abuse detection sits here.
AML and KYC Engineering
Short answer: The GCGRA expects a bank-grade AML and KYC framework
demonstrably in place before a licence is granted. That means automated document
authentication, biometric liveness detection, sanctions and PEP screening, ongoing transaction
monitoring with behavioural risk scoring, source-of-funds escalation, and suspicious activity
reporting workflows — all producing an audit trail the regulator can inspect.
The KYC Orchestration Layer
Document authentication: automated verification of government-issued identity
documents including Emirates ID and passports, with tampering detection, MRZ and chip reading where
available rather than OCR alone. OCR-only pipelines produce the false-accept rates that fail audit.
Biometric liveness detection: selfie capture matched against the document photo
with active or passive liveness checks to defeat presentation attacks. This is now standard
expectation in any serious regulated market.
Age verification enforcing 21+: the minimum age for gaming in the UAE is 21. Date
of birth must be read from the document rather than self-declared, and the enforcement must be
evidenced in logs. Underage access is the single fastest route to licence loss in any jurisdiction.
Address and residency verification: proof-of-address handling with document
validity rules and expiry management.
Sanctions, PEP and adverse media screening: screening at onboarding and on an
ongoing basis against updated lists, with match resolution workflow, false-positive handling and
full decision audit.
Risk-based tiering: not every player needs the same depth of verification. Build
tiered thresholds where enhanced due diligence triggers on deposit volume, withdrawal patterns,
jurisdiction risk or behavioural flags.
Re-verification triggers: document expiry, material change of circumstances,
dormancy reactivation and threshold breaches must all trigger re-verification automatically.
The AML Transaction Monitoring Engine
Rules-based detection: configurable thresholds for deposit velocity,
deposit-to-wager ratio (a classic laundering signature), rapid deposit-withdraw cycling with minimal
play, structuring below thresholds, and unusual payment method patterns.
Behavioural risk scoring: a running risk score per player combining transaction
patterns, KYC risk tier, geographic signals and gameplay behaviour, with automatic escalation when
the score crosses thresholds.
Source of funds and source of wealth escalation: automated requests for documentary
evidence when cumulative deposits cross defined thresholds, with account restriction until
satisfied.
Case management workflow: alerts route to a compliance queue with investigation
notes, evidence attachment, decision recording and four-eyes approval on material outcomes. Every
decision, including decisions not to escalate, must be recorded with rationale.
Suspicious activity reporting: structured workflow for preparing and filing reports
to the relevant UAE authority, with the underlying evidence preserved immutably.
Immutable audit trail: tamper-evident logging of every AML decision, alert,
override and escalation. If a regulator asks why a specific account was not escalated in March, you
must be able to answer with evidence.
AML architecture is where most platform vendors quietly fall short — and where
the operator carries the liability. Many white-label and off-the-shelf platforms treat
AML as a dashboard bolted onto the payment module: threshold alerts, a list view, a manual review
screen. That is sufficient for a light-touch jurisdiction. It is not sufficient where the regulator
expects to see a designed control framework with behavioural scoring, documented escalation logic,
four-eyes approval and immutable decision audit. When you licence a platform, you inherit its
compliance architecture — but the licence, and the enforcement exposure, sits with you. This is the
single strongest technical argument for owning your platform in the UAE rather than renting one.
Geolocation and Geofencing
Short answer: Players must be physically located in the UAE, and licensed rollouts
have been restricted to specific emirates — so your platform needs emirate-level
geofencing, not just country-level. Two geolocation specialists (GeoComply and Xpoint
Technology) appear on the GCGRA vendor register, which tells you how seriously the regulator treats
this control.
Continuous verification, not login-only: location must be re-verified periodically
during a session and re-checked before any wager or withdrawal. A player who crosses a border
mid-session must be blocked mid-session.
Multi-signal triangulation: GPS, IP geolocation, WiFi access point mapping, mobile
network data and device signals combined into a confidence score, rather than reliance on any single
signal.
VPN, proxy and spoofing detection: detection of commercial VPNs, proxies, Tor, DNS
manipulation, GPS spoofing applications and emulators. This is an arms race and it is why operators
use specialist providers rather than building it in-house.
Emirate-level granularity: Play971's rollout was reported as accessible in Abu
Dhabi and Ras Al Khaimah before wider availability. Your geofencing engine must support per-emirate
rules that can be reconfigured without a code deployment.
Fail-closed behaviour: if location cannot be established with sufficient
confidence, the correct behaviour is to block play — not to allow it and log a warning.
Full decision audit: every location check, its inputs, its confidence score and its
outcome must be logged for regulator inspection.
Responsible Gaming Controls
The GCGRA describes responsible gaming as pivotal to its mandate, with a mission centred on player safety
and socially responsible gaming practices. These are not optional features to be added in a later
release — they are licence conditions.
Self-exclusion: immediate, irreversible-for-the-chosen-period exclusion applying
across every product and every access channel. Must survive account closure and re-registration
attempts, which means exclusion is keyed to verified identity, not to the account record.
Time-outs and cooling-off: shorter voluntary breaks (24 hours, 7 days, 30 days) as
a lighter-touch step before full self-exclusion.
Player-set limits: deposit, loss, wager and session-duration limits. Decreases
apply immediately; increases require a cooling-off delay and explicit reconfirmation.
Reality checks: periodic in-session notifications showing elapsed time and net
position, with the option to end the session.
Behavioural risk detection: automated identification of markers of harm —
escalating deposits, loss-chasing patterns, extended session lengths, play at unusual hours,
cancelled withdrawals followed by immediate play — with defined intervention workflows.
Prominent help resources: accessible information on problem gaming and support
pathways, in both English and Arabic.
Advertising and bonus restrictions for at-risk players: players displaying harm
markers, on a time-out or self-excluded must be suppressed from all marketing and promotional
communication automatically. CRM suppression must be wired to the responsible gaming state, not
managed manually.
Permitted Games and Content Supply
Short answer: The GCGRA regulates four commercial gaming activities:
lottery, internet gaming, sports wagering and land-based gaming facilities. For an
online platform this means casino-style games (slots, live casino, table games), sports and event
wagering, and lottery products. Content must be sourced from GCGRA-licensed suppliers, and every
game requires valid RNG and RTP certification from a recognised testing laboratory.
Vertical
Product scope
Governing standard
Platform implications
Online slots
Video slots, classic slots, progressive jackpot slots, crash and turbo formats
GLI-19 (+ GLI-12 for progressives)
Aggregator integration, certified RNG per title, RTP certification, jackpot contribution
and payout ledger.
Live casino
Live roulette, blackjack, baccarat, game shows with human dealers
GLI-19 (+ GLI-24 / GLI-25 for electronic tables)
Streaming integration, dealer studio connectivity, bet-behind and side-bet handling,
latency management, seat management.
RNG table games
Digital roulette, blackjack, baccarat, poker variants, video poker
GLI-19
Server-authoritative game logic, certified RNG, per-hand audit records.
Sports wagering
Pre-match and in-play betting on football, cricket, tennis, basketball, racing, esports
GLI-33
Licensed odds and data feed (Sportradar is on the vendor register), risk and liability
engine, settlement and void logic, cash-out.
Lottery products
Draw-based games, instant win, scratch formats
GLI-14 for scratch and pull-tab formats
Draw integrity and certification, prize tier management, unclaimed prize handling.
Bingo and keno
Electronic bingo and keno
GLI-15
Room and session management, card sales, pattern validation, prize distribution.
The content supply rule is the one to internalise: your platform may only serve content from
GCGRA-licensed suppliers. The vendor register already includes Endorphina, Games Global,
Playtech (via VSTechnology), Hub 88, Live Online Gaming Services (OneTouch and Live88), Aristocrat,
Novomatic, IGT, Konami, LNW Gaming and Scientific Games. Your aggregator integration layer should
therefore be built with a jurisdictional content gating capability — the ability to enable or
disable individual titles and suppliers per jurisdiction from configuration, without a code release.
Operators running multi-market platforms without this capability end up maintaining separate builds per
market.
Payments and the Crypto Question
Short answer: Build fiat-first in AED with local UAE rails. Crypto
gambling falls outside both VARA (Dubai) and ADGM (Abu Dhabi) authorisations, and the GCGRA internet
gaming licence does not extend to crypto deposits. Architect the payment layer behind an abstraction
so crypto rails can be enabled in jurisdictions where they are permitted, without re-engineering the
UAE deployment.
AED as base currency with correct rounding, display and reconciliation.
Multi-currency support is useful for a multi-market roadmap but the UAE deployment should settle in
AED.
Local payment rails: UAE debit and credit cards, local bank transfer, and licensed
local payment technology providers. PayBy Technology has been reported among approved vendors in the
GCGRA's licensing rounds.
PCI DSS compliant handling: tokenised card storage, no raw PAN in your systems,
scoped cardholder data environment. This is explicitly cited among GCGRA cybersecurity expectations.
Source-of-funds capture at deposit level: payment method provenance recorded and
linked to the AML risk engine, with card-holder-name matching against verified identity.
Withdrawal approval workflow: automated approval within defined risk parameters,
manual review queue above thresholds, mandatory verification completion before first withdrawal, and
closed-loop payout to the original deposit method where possible.
Payment abstraction layer: providers behind a common interface so adding, removing
or swapping a PSP is a configuration change. This is what makes a platform genuinely
multi-jurisdictional.
Regulator Reporting and Supervision
Approved licensees are subject to periodic regulatory reporting and ongoing supervision. In practice this
means your platform must be able to produce, on demand and for arbitrary historical periods:
Financial reporting: gross gaming revenue by vertical and period, player liability
position, deposits, withdrawals, bonus cost, and reconciliation to your accounting system.
Player activity reporting: registrations, verification completion rates, active
players, self-exclusions and time-outs granted, limit changes, and complaint volumes.
AML reporting: alerts raised, cases opened, escalations, suspicious activity
reports filed, and enhanced due diligence outcomes.
Responsible gaming reporting: harm markers detected, interventions made,
self-exclusion register state and marketing suppression compliance.
Technical and incident reporting: uptime, security incidents, game malfunctions,
recovery events and certification status of all deployed components.
Game-level reporting: per-title wagers, wins, actual versus theoretical RTP
variance, and jackpot movements.
Design the reporting layer as a first-class product surface, not an export
button. The difference between a platform that survives supervision comfortably and one
that consumes a full-time compliance analyst is whether reporting was architected in or bolted on.
If your data model captures every event with the right dimensions from day one — player, session,
game, transaction, jurisdiction, device, location decision, verification state — then any report the
regulator asks for is a query. If it was not, every regulatory request becomes an engineering
project. Capermint builds an event-sourced reporting spine into every regulated platform for exactly
this reason.
Security, Certification and Testing
GCGRA cybersecurity expectations for licensed operators cover platform security testing, RNG
certification, player account protection, PCI DSS compliance for payments, AML and KYC system security,
data protection, third-party vendor assessment, incident response capability and responsible gaming
controls — aligned to the GLI-19 and GLI-33 standards.
Requirement
What it involves
Typical effort
RNG certification
Independent testing and certification of the random number generator by a recognised
laboratory such as GLI or BMM Testlabs. Statistical randomness testing, seeding review,
source code review.
4 to 8 weeks
Platform certification (GLI-19)
Full system testing against the interactive gaming systems standard: game integrity,
account management, transaction handling, reporting, recovery.
8 to 16 weeks
Sportsbook certification (GLI-33)
Event wagering system testing: bet handling, settlement, void logic, in-play integrity,
data sourcing.
6 to 12 weeks
Penetration testing
External and authenticated application testing, infrastructure testing, API security
review, remediation and retest.
3 to 6 weeks
PCI DSS
Scoping the cardholder data environment, tokenisation, network segmentation, evidence
collection and assessment.
6 to 12 weeks
Ongoing obligations
Annual security assessments, continuous control monitoring, incident reporting, regular
AML audits, certification renewals.
Continuous
UAE iGaming Taxation Explained
Short answer: The UAE VAT and corporate tax framework was written before
commercial gaming was regulated, so there are currently no gaming-specific tax
provisions. Three layers apply in practice: 9% corporate tax on net
profits (with a potential top-up to 15% for large multinational groups under Pillar
Two), 5% VAT under general rules since gaming has no sector-specific exemption, and
GCGRA licence and regulatory fees. Wynn has separately disclosed a blended gaming tax of 10%
to 12% of GGR for its land-based resort. There is no personal income tax, so player
winnings are not taxed locally.
Tax layer
Rate
Base
Notes for operators
Corporate Tax
9% headline
Net taxable profits above the threshold
Standard UAE corporate tax applies to gaming entities with a UAE establishment. Highly
competitive against European gaming jurisdictions.
Global Minimum Tax (Pillar Two)
Top-up to 15%
Large multinational groups meeting the revenue threshold
Applies to in-scope MNE groups. Must be modelled into operating economics from the
outset for any group above the threshold.
VAT
5% standard
Taxable supplies under general VAT rules
The VAT law predates gaming regulation and contains no sector-specific provision, so
gaming services fall under general rules. Input VAT recovery treatment is the
consequential question for capital-intensive projects.
Gaming tax (land-based, disclosed)
10% to 12% of GGR (blended)
Gross gaming revenue
Wynn's publicly disclosed blended rate for Wynn Al Marjan. Comparable to Singapore's
tiered structure and materially below most European GGR duties.
Lottery revenue tax
Low single-digit % (reported)
Revenue
Reported alongside the standard 9% corporate tax for the lottery licensee.
Player winnings tax
0%
N/A
The UAE has no personal income tax. Player winnings are not taxed locally. Foreign tax
residents remain subject to their home jurisdiction rules.
Customs duty
Varies
Imported gaming equipment
Relevant for land-based equipment importers rather than pure online operators.
GCGRA fees
Application and annual
Per licence category
Payable at multiple stages of the licensing process. Scale with licence category and
operation size.
The VAT treatment question is the live one, and it has a direct
platform-architecture consequence. Tax specialists have noted that the UAE VAT system
was designed before commercial gaming was formally regulated, so the absence of sector-specific
provisions reflects timing rather than policy intent. The European model pairs VAT exemption with a
separate GGR-based gambling duty; the UAE framework is well placed to adapt that structure, and the
GCGRA offers a natural home for such a levy. What this means for your build: your financial
reporting layer must be able to compute and report on both a transaction-VAT basis and a
GGR basis, with configurable rates, because the fiscal treatment may be clarified during your
platform's operating life. Hard-coding one tax model into your ledger is a costly assumption. This
is not tax advice — engage UAE tax counsel — but it is a design requirement.
Advertising and Marketing Rules
Short answer: The GCGRA publishes Advertising Standards for Commercial
Gaming, amended June 2024, which complement Chapter 17 of the GCGRA Executing
Regulations. Since 18 February 2026, Google Ads permits gambling advertisements
from GCGRA-authorised entities, and Meta operates a similar authorisation requirement. Advertising
is lawful only when tied to authorised commercial gaming conducted by a GCGRA-licensed
operator.
The platform implications of the advertising regime are frequently overlooked at architecture stage, but
they are real engineering requirements:
Geo-targeted campaigns: campaigns must be restricted to the UAE or to the specific
emirates covered by your authorisation. Your attribution and tracking layer must be able to evidence
this.
Age-gated ad delivery: ads must not be served to users below the applicable minimum
age, which requires age signal handling in your marketing stack.
Landing page compliance: destination URLs must display GCGRA licence details,
responsible gaming statements, self-exclusion links and Arabic-language content where required. This
means your CMS and front end must render compliant footers and disclosures on every acquisition
landing page, not just the main site.
Marketing suppression wired to RG state: self-excluded players, players on a
time-out and players flagged with harm markers must be automatically suppressed across every channel
— email, SMS, push, on-site and paid retargeting audiences. This suppression must be an automated
data flow from the responsible gaming service to the CRM and ad platforms, not a manual list export.
Affiliate compliance controls: if you run an affiliate programme, affiliate
creatives and landing pages fall within your compliance perimeter. Your affiliate platform needs
creative approval workflow and compliance monitoring.
Need a platform that satisfies all of this — not just the game lobby?
Compliance core, PAM, AML engine, geolocation, RG controls, regulator reporting, Arabic RTL front
end. Capermint builds the whole stack and transfers 100% of the source code to you.
Short answer: For the UAE specifically, the depth of the GCGRA suitability
investigation favours operators who can demonstrate direct control over their
technology. White-label is fastest but you inherit someone else's compliance
architecture while carrying the enforcement liability yourself. Turnkey gives you ownership of a
proven platform. Custom gives you an architecture designed around GCGRA requirements from the ground
up — the strongest position for a licence application.
Model 01 · White-Label
$40K–$120K
Setup + 15–40% GGR revenue share · 8 to 14 weeks
Branded deployment on an existing platform
Fastest possible route to market
Pre-integrated content and payments
Lowest upfront capital requirement
You do not own the source code
Compliance posture inherited from provider
Revenue share becomes your largest cost at scale
Best forSpeed and market validation
Model 02 · Turnkey (Most Chosen)
$150K–$400K
One-time build, infrastructure-only ongoing · 4 to 8 months
You own the platform outright, source code included
Configured specifically for GCGRA compliance
No ongoing revenue share to a platform vendor
Full control of the compliance evidence pack
Your own PAM, wallet and reporting spine
Aggregator and PSP relationships in your name
Multi-brand capable from one platform
Best forSerious operators, best long-term margin
Model 03 · Custom Compliance-First
$250K–$700K+
Ground-up architecture · 8 to 16 months
Architected around GLI-19 and GLI-33 from sprint one
Proprietary PAM, wallet, AML and reporting engine
Every control designed to be evidenced to the regulator
Bespoke game engine and proprietary content option
Multi-jurisdiction from a single codebase
Full IP ownership — a balance-sheet asset
Strongest position in a suitability investigation
Best forGroups building a durable regulated
business
Run the revenue-share arithmetic before choosing white-label. A
platform generating $300,000 in monthly GGR on a 30 percent revenue share pays $90,000 per month —
$1.08 million per year, indefinitely, with no asset at the end. The same operator could have
commissioned a turnkey platform outright for $150,000 to $400,000 as a one-time cost and owned it.
Industry analysis places the crossover point at roughly $50,000 monthly GGR, beyond which setup-only
economics beat revenue share decisively. In a market with the UAE's projected ARPU, that threshold
arrives fast. The strategic sequence most sophisticated operators run: validate on white-label if
you must, but architect the migration to owned technology into your plan from day one rather than
discovering the cost of it in year three.
Full Platform Cost Breakdown
Below is a component-level breakdown for a turnkey GCGRA-ready casino and sportsbook platform, at
Capermint's India development rates of $20 to $50 per hour. These figures cover platform software and
integration only — they exclude GCGRA licence fees, legal and corporate formation, third-party
certification laboratory fees, staffing and marketing.
Payable at multiple stages. Vendor-category applications have been indicated from around
AED 100,000 in industry guidance; operator categories are materially higher and
scale-dependent.
Budget at parity with or above your build cost for year one. GCGRA-authorised
advertising only.
Realistic Build Timeline
Turnkey GCGRA-Ready Platform · 4 to 8 Month Build (Run in Parallel With
Licensing)
PHASE 01
Compliance Mapping
2-3 weeks
PHASE 02
Compliance Core
6-9 weeks
PHASE 03
Game & Sportsbook
6-10 weeks
PHASE 04
Payments & Back Office
4-6 weeks
PHASE 05
Front End EN/AR
5-7 weeks
PHASE 06
Security & QA
4-6 weeks
PHASE 07
Certification
8-16 weeks
Phases
overlap in practice. The critical dependency is that Phase 02 must complete before your
suitability investigation reaches technology assessment — the regulator expects the AML
and KYC framework to exist, not to be planned. Certification (Phase 07) runs partly in parallel with
late-stage build.
Seven Costly Mistakes Operators Make Entering the UAE
1. Treating compliance as a feature instead of the foundation. Building the lobby
and games first, then bolting on AML and KYC, produces a platform that cannot be certified without
substantial rework. Build the compliance core first, always.
2. Applying for a licence before the technology exists. The GCGRA expects a
demonstrably robust AML and KYC framework before granting a licence. Sequential planning —
licence first, build second — stalls at the suitability investigation. Run them in parallel.
3. Assuming country-level geofencing is sufficient. Licensed rollouts have been
restricted to specific emirates. Build emirate-level geofencing with runtime reconfiguration, or you
will be re-engineering under time pressure.
4. Inheriting an opaque compliance architecture via white-label. The licence and
the enforcement exposure sit with the operator, not the platform vendor. If you cannot inspect and
evidence how your AML engine makes decisions, you cannot defend them to a regulator.
5. Planning for crypto deposits. Crypto sits outside both VARA and ADGM
authorisations and outside the GCGRA internet gaming licence. Architect fiat-first for the UAE; keep
the payment abstraction so crypto can be enabled in permitted jurisdictions.
6. Hard-coding a single tax model. The VAT treatment of gaming supplies is a live
question and a dedicated GGR levy is a realistic future development. Your ledger and reporting must
support both bases with configurable rates.
7. Sourcing content from unlicensed suppliers. Every content supplier serving your
UAE players must appear on the GCGRA vendor register. Build jurisdictional content gating so titles
and suppliers can be enabled or disabled per market from configuration.
Why Capermint for Your UAE iGaming Platform
2014
Founded
500+
Games & RMG Platforms Delivered
40+
Countries Served, Incl. UAE
100%
Source Code Ownership Transferred
Compliance-First Architecture
We build the PAM, wallet, AML engine, KYC orchestration, geolocation service, responsible gaming
controls and immutable audit log before the game lobby. Every control is designed to be
evidenced to a regulator, because that is what a suitability investigation actually examines.
Built to GLI-19 and GLI-33
Server-authoritative game logic, certified RNG integration, complete transaction logging, game
recovery handling and certified RTP control — designed to the standards the GCGRA has formally
adopted, not adapted to them afterwards.
Real-Money Gaming at Volume
500+ games and real-money platforms shipped since 2014 across casino, sportsbook, poker, rummy,
fantasy, lottery and sweepstakes. RMG is not an adjacent capability for us — it is the core of
the practice.
Multi-Jurisdiction From One Codebase
Jurisdictional rule engines, per-market content gating, configurable tax models and
market-specific compliance profiles — so the same platform can serve the UAE, and later Saudi
Arabia, Europe or Latin America, without a separate build per market.
Arabic-First, Not Arabic-Later
Full RTL layout, Arabic typography, culturally appropriate UX and bilingual compliance
disclosures built into the design system from the start — not retrofitted as a translation pass
that breaks every layout.
India Rates, Global Standards
$20 to $50 per hour against $90 to $250 at European and US iGaming vendors — typically 55 to 70
percent lower total build cost for equivalent output. And unlike a white-label deal, there is no
perpetual GGR revenue share.
The ownership question is the one that compounds. On every turnkey and
custom engagement, Capermint transfers 100 percent of the source code and IP to the client at
handover. There is no platform lock-in, no revenue share, no dependency on us to continue operating,
and no scenario where your regulator asks a question about your architecture that you cannot answer
because a vendor will not disclose it. In a jurisdiction where the regulator supervises you
continuously and holds you — not your vendor — accountable, owning your stack is not a preference.
It is a risk control.
Engagement Models
Model 01
Fixed-Price Project
Best for: defined turnkey scope
Full scope locked before development begins
Milestones tied to compliance core, game layer, certification readiness
Capermint absorbs delivery risk
Certification support included in scope
100% IP and source code at handover
30-day post-launch fix window
Best when your licence category and product scope are settled
The General Commercial Gaming Regulatory Authority. Established by Federal Law by Decree in
September 2023 and headquartered in Abu Dhabi, it is the exclusive federal authority regulating,
licensing and supervising all commercial gaming across all seven emirates. There is no alternative
licensing route.
Federal Decree-Law No. 25 of 2025
The legislation, effective 1 June 2026, that removed Articles 1012 to 1019 (the gambling and betting
chapter) from the UAE Civil Transactions Law, creating the legal architecture for enforceable
licensed gaming contracts. It did not legalise unregulated gambling.
GLI-19
Gaming Laboratories International Standards for Interactive Gaming Systems. The core technical
specification for an online gaming platform: RNG, game integrity, player account management,
transaction logging, reporting and recovery. Adopted by the GCGRA.
GLI-33
GLI Standards for Event Wagering Systems. The governing specification for sportsbook operations: bet
placement, odds handling, settlement, void and cancellation logic, and in-play integrity.
PAM (Player Account Management)
The back-office system that manages player identity, verification state, wallet balances, limits,
self-exclusion and activity history. The regulatory heart of an iGaming platform and the primary
object of regulatory supervision.
Suitability investigation
The GCGRA's rigorous assessment of an applicant's eligibility, integrity and operational capability.
Covers corporate structure, beneficial ownership, source of funds, key person probity, financial
capacity, compliance framework and technology readiness.
Gaming-Related Vendor licence
The GCGRA entity licence category for suppliers of gaming equipment or related goods and services.
The entry route for platform providers, game studios, aggregators and compliance technology vendors,
requiring no player-facing operations.
Geofencing
Technical enforcement of the rule that players must be physically located within a permitted area.
In the UAE this must operate at emirate level, using multi-signal triangulation with VPN and
spoofing detection, verified continuously rather than only at login.
Segregated player funds
The requirement that player balances be held and accounted separately from operating funds,
evidenced through a double-entry ledger, so player liability is always demonstrable.
GGR (Gross Gaming Revenue)
Total wagers less winnings paid to players. The standard base for gaming taxation and for platform
revenue-share arrangements. Wynn has disclosed a blended UAE gaming tax of 10 to 12 percent of GGR
for its land-based resort.
RTP (Return to Player)
The certified theoretical percentage of wagers a game returns to players over time. Must be
certified, accurate and not silently variable, with any configuration capability controlled and
logged.
Pillar Two / Global Minimum Tax
The OECD framework under which large multinational enterprise groups face a minimum effective tax
rate of 15 percent, potentially topping up the UAE's 9 percent headline corporate rate for in-scope
groups.
Ready to build? Start with a compliance-mapped scope.
Tell us your licence category, product verticals and target launch. We return an itemised
platform scope, architecture outline and fixed quotation within 48 hours — under NDA, at no
cost.
Yes, but only when conducted by an operator holding a valid GCGRA licence. The
General Commercial Gaming Regulatory Authority, established in September 2023 and headquartered in
Abu Dhabi, holds exclusive federal jurisdiction over all commercial gaming across all seven
emirates. Federal Decree-Law No. 25 of 2025, effective 1 June 2026, removed Articles 1012 to 1019
(the gambling and betting chapter) from the UAE Civil Transactions Law, creating the legal
architecture for enforceable commercial gaming contracts. Unlicensed online gambling remains a
criminal offence under the UAE Penal Code, and the GCGRA has explicitly stated that facilitators of
unlicensed activity, not just operators, are also exposed to enforcement.
What licence categories does the GCGRA issue?
The GCGRA grants five categories. Three are entity licences: Gaming
Operators (internet gaming platforms, sports wagering, land-based facilities, lottery
and lottery retailers), Gaming-Related Vendors (suppliers of gaming equipment or
related goods and services — the category most platform and software providers fall into), and
Key Persons – Corporates (entities holding decision-making roles in the ownership
structure, including controllers, affiliates and management service providers). Two are individual
licences: Key Persons – Individuals (directors, executive officers, controllers)
and Gaming Employees. Many businesses require multiple licences simultaneously.
What technical standards must a UAE iGaming platform meet?
The GCGRA has adopted the Gaming Laboratories International (GLI) standard series as
its technical framework, produced by GLI in collaboration with legal experts. For an online casino
and sportsbook the two governing documents are GLI-19 (Standards for Interactive
Gaming Systems), covering the platform, RNG, player account management, game fairness and reporting,
and GLI-33 (Standards for Event Wagering Systems), covering sportsbook operations.
Depending on product scope, GLI-11, GLI-13, GLI-16, GLI-17, GLI-18, GLI-21, GLI-24, GLI-25 and
GLI-28 may also apply. The GCGRA states that operators are responsible for being aware of and
complying with these standards.
How are iGaming operators taxed in the UAE?
The UAE tax framework was written before commercial gaming was regulated, so there
are currently no gaming-specific tax provisions. Three layers apply in practice: Corporate
Tax at 9 percent on net profits above the threshold, with a potential top-up to
15 percent for large multinational groups under Global Minimum Tax rules;
VAT at 5 percent, since gaming supplies fall under general VAT rules with no
sector-specific exemption; and GCGRA licence and regulatory fees. Separately, Wynn Resorts has
publicly disclosed a blended gaming tax of 10 to 12 percent of gross gaming revenue
for its Ras Al Khaimah resort. There is no personal income tax in the UAE, so player winnings are
not taxed locally. This is general information, not tax advice — engage UAE tax counsel for your
structure.
How much does it cost to build a GCGRA-compliant casino platform?
Cost depends on delivery model. White-label typically runs $40,000
to $120,000 setup plus 15 to 40 percent of GGR in ongoing revenue share. Turnkey
(you own the platform outright) typically runs $150,000 to $400,000 one-time with
infrastructure-only ongoing costs. Custom compliance-first with proprietary PAM,
wallet, AML engine and reporting typically runs $250,000 to $700,000+ over 8 to 16 months. These
cover platform software only — they exclude GCGRA licence fees, legal formation, GLI certification
testing, staffing and marketing. Capermint builds all three models at India rates, typically 55 to
70 percent below equivalent European or US iGaming vendors. Request an itemised
quote.
Who is currently licensed by the GCGRA?
The lottery licensee is The Game LLC (UAE Lottery). The land-based
licensee is Island 3 AMI FZ-LLC, trading as Wynn Al Marjan. Coin Technology
Projects LLC holds both the internet gaming and sports wagering licences and operates
Play971, live since December 2025 as the UAE's first authorised real-money online sportsbook and
iGaming platform. The gaming-related vendor register includes Aristocrat, Novomatic, Scientific
Games, IGT, Konami, LNW Gaming, Endorphina, Games Global, Playtech (VSTechnology), Hub 88, Live
Online Gaming Services, Sportradar, GeoComply, Xpoint Technology, Smartplay, EQL Games, Brightstar
Lottery, Random State, Fennica Gaming, TCS John Huxley, Pollard Banknote, Arena Leisure and Cammegh.
The vendor register is where most platform and content suppliers enter the market.
What is the minimum player age for gaming in the UAE?
21 years. Play971 requires users to be at least 21 and physically
located within the UAE to register, deposit funds or play. The same minimum age of 21 applies to
entry to licensed land-based gaming floors, with valid government-issued photo ID required. Your
platform must enforce this at registration through document verification reading date of birth from
the document rather than self-declaration, and must be able to demonstrate that enforcement to the
regulator through auditable logs. Underage access is the fastest route to licence loss in any
regulated jurisdiction.
Does a UAE iGaming platform need geolocation technology?
Yes, and at emirate level rather than country level. Players must be physically
located within the UAE, and licensed operators have run phased rollouts restricted to specific
emirates. Two geolocation specialists — GeoComply and Xpoint Technology — appear on the GCGRA vendor
licensee register, which indicates how seriously the regulator treats this control. Your
architecture needs continuous location verification rather than a login-only check, VPN and proxy
and GPS-spoofing detection, multi-signal triangulation combining GPS, IP, WiFi and network data,
fail-closed behaviour when confidence is insufficient, and a full audit trail of every location
decision.
Can a UAE iGaming platform accept cryptocurrency?
Not under the current GCGRA framework. Crypto gambling falls outside both VARA
(Dubai's Virtual Assets Regulatory Authority) and ADGM (Abu Dhabi Global Market) authorisations, and
the GCGRA internet gaming licence does not extend to crypto deposits. Operators building for the UAE
should architect a fiat-first AED payment stack with local rails. That said, a well-architected
platform separates the payment layer behind an abstraction so crypto rails can be enabled in other
jurisdictions from the same codebase without re-engineering the core. Capermint builds
crypto-capable platforms for markets where it is permitted while keeping the UAE deployment
fiat-only and compliant.
How long does the GCGRA licensing process take?
The GCGRA does not publish a fixed statutory timeline. The published process runs in
five stages: preliminary screening via the Intake Form, preparation and submission through the
licensing portal, a rigorous suitability investigation, compliance and monitoring after approval,
and renewals or amendments. Industry guidance for vendor-category applications suggests roughly 4 to
6 months from intake to decision, with operator categories taking longer given the depth of the
suitability investigation. The practical planning implication is important: your technology build
and licence application should run in parallel, because the regulator expects a
demonstrably compliant AML and KYC framework to be in place before granting a licence, not after.
What is the difference between white-label, turnkey and custom for the UAE
market?
White-label is fastest and cheapest to launch but you do not own the
stack, you pay ongoing revenue share, and your compliance posture depends on your provider's
architecture — a significant risk when the regulator holds you accountable.
Turnkey means you own a proven platform outright with your own configuration and
branding, giving full control of compliance evidence and no revenue share. Custom
means the platform is architected from the ground up around GCGRA requirements, the strongest
position for a licence application because every control can be evidenced and every reporting
requirement mapped. The UAE's deep suitability investigation favours operators who can demonstrate
direct control over their technology. Capermint delivers all three with 100 percent source code
ownership transferred on turnkey and custom engagements.
Which company should build my UAE iGaming platform?
Look for four things: demonstrable experience building to GLI-19 and GLI-33 rather
than generic casino software; an AML, KYC and reporting architecture designed for regulator audit
rather than bolted on; real-money gaming delivery history at volume; and a commercial model that
transfers source code ownership to you. Capermint Technologies, founded in 2014 in
Ahmedabad India, has delivered 500+ games and real-money gaming platforms across 40+ countries
including the UAE, works at $20 to $50 per hour (typically 55 to 70 percent below European iGaming
vendors), and transfers full IP and source code on every turnkey and custom engagement. Every
enquiry begins with a signed NDA and returns an itemised scope within 48 hours. Start the
conversation.
Disclaimer. This article is a technology and platform-architecture guide produced by
Capermint Technologies for informational purposes. It is not legal, regulatory, tax or investment
advice. Regulatory requirements in the UAE are evolving and licence conditions are determined by the
GCGRA on a case-by-case basis. Always verify current requirements directly with the GCGRA official portal and engage
qualified UAE legal and tax counsel before making commercial decisions. Operating commercial gaming in
the UAE without a valid GCGRA licence is a criminal offence.
Build the Platform Your UAE License Depends On
The GCGRA expects your compliance framework to exist before it grants a licence. Capermint builds the
PAM, wallet, AML engine, KYC orchestration, geolocation service, responsible gaming controls,
regulator reporting and Arabic-first player experience — to GLI-19 and GLI-33, with 100% source code
ownership transferred to you. From $40,000 white-label to full custom.