2026 Guide Operator playbook · 6 steps

How to start an online casino in 2026.

The step-by-step playbook for founders and operators — from choosing a platform model to your first regulated deposit. Written by the team behind a Player Account Management platform that has run real money since 2013 — 3B+ transactions and €10B+ processed.

New Brand · Launch Checklist
IN PROGRESS
1 · Brand & skin configured✓ Done
2 · Jurisdiction rules — 🇸🇪 SE✓ Done
3 · Game providers enabled✓ 25+
4 · Payments — PaymentIQ✓ Live
5 · KYC + Spelpaus checksTesting
6 · Welcome bonus + CRMQueued
New code required
0 lines
Shared deployment
Isolated
Platform
PAM BeAware CMS .NET 10 SignalR
10+
Years in production — running real money since 2013
5
Regulated markets live — UK, Sweden, Spain, Denmark, Malta. Finland next.
3B+
Transactions processed through the PAM wallet
€10B+
Total value processed across operators and brands

The questions every launch has to answer.

Most casino launches don't fail on game selection. They fail on the platform underneath — a wallet that deadlocks under promotion traffic, a jurisdiction rule hardcoded in the wrong place, a self-excluded player who slips through a login path. This guide covers what we've learned keeping that layer running.

01

Build, white-label or run on a PAM?

Which launch model fits your capital, timeline and regulatory ambitions — and what you give up with each.

02

Which jurisdiction first?

How KYC timelines, source-of-wealth thresholds and exclusion registries differ between markets — and why that matters on day one.

03

What content do you actually need?

Casino, live casino, sportsbook — how to pick a vertical mix without locking yourself into one aggregator.

04

How should money move?

Payment providers, review queues, multi-currency wallets — and the concurrency problems nobody warns you about.

05

What does compliance really require?

KYC, AML, SOW, deposit limits, GAMSTOP and Spelpaus — as infrastructure, not a checkbox before the audit.

06

How do you grow after launch?

Bonuses, cashback, segmentation, CRM and your second brand — without a second deployment.

Two kinds of founders. One platform question.

First-time operators

Launching your first brand

You have capital, a market in mind and maybe an audience — but not ten years of learning what breaks in a live wallet. You need a platform that gets compliance right from the start, not a codebase to maintain.

  • ✓Entering a regulated market for the first time
  • ✓Affiliates, streamers and media owners monetising an audience
  • ✓White-label or B2B launches on a shared deployment
Established operators

Adding brands, markets or migrating

You already run a brand and have outgrown your platform — every new market is a project, every provider change a risk. You need multi-brand, multi-jurisdiction operations from one back-office.

  • ✓Launching a second or third brand
  • ✓Expanding into Sweden, Finland, Malta or the UK
  • ✓Migrating off a legacy PAM without disrupting live play

Six steps from idea to live brand.

Each step covers the decision you have to make, what typically goes wrong, and how it's handled in PAM.

01

Choose your platform model

The platform is the one decision that's expensive to reverse. Everything else — providers, markets, bonuses — sits on top of it.

There are three realistic ways to launch in 2026. Building your own PAM gives full control but means re-learning a decade of production lessons. A generic white-label is fast but limits your brand, your markets and your data. Running on a proven PAM gives you the operational core as a platform — with your own brand, providers and compliance configuration on top.

Build in-house Generic white-label Brand on PAM
Time to launchLongestFast1–2 weeks per brand — configuration, not a rebuild
Own brand & skinFullLimitedPer-brand skins, currencies, languages
Choice of providersFull — you build each oneVendor's list50+ integrated, new ones as isolated modules
Multi-jurisdictionCode per marketVendor-dependentDeclarative config per jurisdiction
Back-office & auditYou build itShared, often shallowFull operator portal, audited writes
Second brandOften a forkA new contractSame deployment, isolated data
How PAM handles it

Two ways in: turnkey / white-label services where WebPrefer operates the platform for your brand, or a full PAM licence for operators who need their own — both regulated-market ready.

PAM is multi-tenant by design. One deployment understands the full hierarchy — platform, operator, brand, jurisdiction — with data isolation enforced at every layer: player data, configuration, content, integrations, reports and back-office access. A new brand shares infrastructure with existing operations without sharing anything it shouldn't. One deployment, many operators →

02

Pick your jurisdictions and licence

Regulated markets are not interchangeable. What's acceptable in Curacao is not acceptable in Sweden — and Ontario differs again.

Your licence decides which players you can accept, which payment methods you can offer, and what your platform must enforce: KYC timelines, source-of-wealth thresholds, deposit limit rules, self-exclusion propagation and national exclusion registries. Pick your first market with your second one in mind — the platform should make market two a configuration change, not a project.

🇸🇪 Sweden
Spelinspektionen licence. Spelpaus checks at registration, login and in daily batch. Strict deposit-limit enforcement.
🇩🇰 Denmark · 🇪🇸 Spain
Live markets with their own KYC, limit and reporting rules — each a configuration block, not a code branch.
🇲🇹 Malta
MGA licence as a European base. Common hub for multi-market operators.
🇬🇧 United Kingdom
UKGC licence. Every player checked against GAMSTOP before they register or log in.
🇫🇮 Finland
New market
The Veikkaus monopoly opens to licensed competition on 1 July 2027 — licence applications have been accepted by the National Police Board since March 2026, with Lupa- ja valvontavirasto taking over supervision from July 2027. Five-year online casino and betting licences. Strong identification of every player, a centralised self-exclusion register across all operators, and a ban on affiliate and influencer marketing.
How PAM handles it

Compliance in PAM is declarative. Each jurisdiction has its own configuration block — KYC requirements, SOW thresholds, self-exclusion rules, deposit limit behaviour — separate from application code. When a regulator changes a number, it's a configuration update, not a deployment, and it doesn't touch other markets. Adding a market is not a release. The same model covers Ontario and Curacao — and Finland becomes one more configuration block. Making compliance declarative →

03

Build your content and vertical mix

Players come for the games. Your platform decides how many providers you can add — and how safely.

Start with the verticals your market and audience actually want — slots and live casino for most casino brands, sportsbook for cross-sell. Then make sure every provider you add stays isolated: a provider's API change should touch exactly one module, never your bonus engine or your wallet.

Casino / live
NetEnt · Pragmatic · Evolution · NoLimitCity · Yggdrasil · QuickSpin · PushGaming · Relax · RedTiger · ISoftBet · Endorphina · AuthenticGaming · 100HPGaming · …
Sportsbook
SportTech · BetConstruct · Betby · First
How PAM handles it

Every provider integration is a self-contained module behind typed interfaces. The PAM core only knows contracts — not which providers exist. Bring your own provider and it's built as an isolated module that doesn't affect anything else. Game menus, lobbies and promotions are first-class types in the WebPrefer CMS, with brand × skin × jurisdiction built into the data model — promotion pages link to real PAM bonus IDs, and game data (RTP, volatility, provider) comes live from the integration layer. 50+ providers, zero coupling →

04

Set up payments and the wallet

The wallet is where your platform earns trust — or loses it. Balances must be right, instantly, under peak load.

Choose payment providers that fit your market and the methods your players use, then plan for the hard parts: deposits that need human review before funds are credited, withdrawals that need approval, callbacks that must be idempotent, and multiple currencies per brand with rates that stay consistent from bet to payout.

  • ✓Payment providers — PaymentIQ, Hexopay, SafeCharge, PayAdmit, WorldLine
  • ✓Real-time wallet — optimistic concurrency on every operation, SignalR balance push, no stale balances
  • ✓Review workflows — flagged deposits held, not credited, with full player context in the compliance queue
  • ✓Multi-currency — exchange rates, display precision and wallet denomination handled in the money layer; rates locked per game session
How PAM handles it

Deadlocks in high-concurrency wallet operations were solved with an optimistic transaction pattern and automatic retry — tested under real promotion traffic. Duplicate wallet creation is prevented at the database layer. Payment review is a first-class state machine: approve, reject or escalate, every action timestamped and logged with operator identity. The wallet problem → · Payment approval workflows →

05

Make KYC, AML and responsible gaming infrastructure

In a regulated market, compliance failures are licence-threatening events. Treat them as architecture, not features.

Identity verification, source-of-wealth checks, deposit and loss limits, reality checks, self-exclusion and national exclusion registries must work on every code path — registration, login, deposit, game launch and marketing. A player who self-excludes at 2pm must not be playing at 2:01pm, and must never receive a marketing email inviting them back.

Identity & AML
TransUnion, Experian, Acuris. Source-of-wealth triggers per jurisdiction.
Limits & interventions
Deposit limits at wallet level. Loss limits, session limits, reality checks, cool-off.
Exclusion registries
GAMSTOP and Spelpaus at registration, login and in daily batch. Cross-brand self-exclusion.
How PAM handles it

Every responsible gaming intervention runs on the same behavior engine as bonuses and payments — BeAware. Same event stream, same reliability guarantees. Deposit limits are enforced where money moves, self-exclusion propagates across brands per jurisdiction rules, and compliance teams change thresholds without a deployment. The platform is run under ISO 27001 procedures, with automated tests aligned to regulatory requirements and multiple completed software audits, including for Bethard Group. Built in, not bolted on → · Exclusion lists in real time →

06

Launch, retain and scale

A PAM alone doesn't retain players. Plan the first 90 days of player lifecycle before you open the doors.

Launch day is when the real work starts. You need welcome offers with wagering rules that hold up, cashback that's calculated correctly per product, segments your CRM can act on, and a back-office your support team can work in from day one. Then you need to do it again for brand number two.

Bonus & cashback engine
Welcome, deposit-match, free spins, cashback, tournament prize pools. Wagering, expiry and rollover tracked.
Segmentation & CRM
Segments by deposit history, activity, KYC status, jurisdiction and bonus tier. FastTrack, Optimove, Affise.
Back-office + AI
80+ controllers, RBAC down to the action. AI assistant with permission-scoped player context.
Re-streaming
One RTMP source to Twitch, YouTube, Facebook and your site. Host-triggered Slot, Wheel and Double-or-Nothing games credit the PAM wallet.
How PAM handles it

PAM is the core of a five-product suite: PAM, BeAware, CMS, Streaming and WePredict. Deposit thresholds can drive bonus tiers, SOW flags and CRM updates in real time — configured, not coded. Your next brand runs on the same deployment, with its own skin, providers and compliance config. Cashback without the headaches →

Speed to market

Platform to a live site in 1–2 weeks.

Every site shares the same core — so launching a new brand is configuration, not a rebuild.

Already built · shared
0 days
  • PAM core — wallet, KYC, bonuses, audit
  • BeAware compliance & responsible gaming rules
  • Game-provider integrations
  • Re-Streaming & retention games
  • CMS engine & component library
Configured per brand
1–2 weeks
  • Skin, theme, domain & branding
  • Game menus & lobby layout
  • Promotions & editorial content
  • Jurisdiction & payment rails
  • Launch QA & go-live
  1. Day 0
    Kickoff
  2. Day 1–3
    Brand & skin
  3. Day 3–7
    Content & menus
  4. Day 7–10
    Compliance & payments
  5. Day 10–14
    Go live

Timeline for a new brand on the shared platform. Obtaining your own gambling licence is a separate process that depends on the regulator.

Launch mistakes we've seen in production.

None of this was designed on a whiteboard. Each is a failure we watched happen — and made sure couldn't happen the same way again.

Hardcoding the first market

If market one is if (jurisdiction == "SE"), market two is a three-month project with regression risk across everything else.

Coupling providers to business logic

A renamed field in a payment callback once meant deposits completed but bonuses never fired. Silent, and hours to trace.

Load-testing only in theory

Wallet deadlocks show up during your first big promotion, not in a synthetic test. Concurrency needs to be solved before launch.

Treating responsible gaming as a checkbox

Limits checked in middleware, exclusions that miss a brand, batch checks that run too rarely — each a licence risk.

Crediting first, reviewing later

Once a suspicious deposit is played through, you're clawing back money, cancelling bets and explaining a finding to your regulator.

One instance per brand

Separate deployments work — until you have ten brands needing independent upgrades, patches and monitoring.

Technology you won't need to replace.

Proven, well-supported, with long support windows. PAM runs on familiar, auditable infrastructure for regulated markets — and the event-driven design is cloud-compatible.

  • ✓Player API — REST + real-time push, rate limiting and fraud checks before business logic runs
  • ✓Back-office — role-based access down to the individual action, audit trail on every write
  • ✓Background workers — behavior engine, scheduled jobs such as exclusion batch checks, async event queues
  • ✓Observability — OpenTelemetry distributed tracing across the platform
.NET 10
Runtime
SQL Server
Database + EF Core
Redis
Caching + SignalR backplane
RabbitMQ
Async messaging
SignalR
Real-time balance push
JWT + Cookie
Dual auth strategy
Track record

Not a pitch. A production system with history.

10+
Years in production
3B+
Transactions processed
€10B+
Total value processed
5
Regulated markets live
Customer · live
Trustplay

Trustplay Technology Sweden AB (owned by Tangiamo) — PAM + Re-Streaming live in production.

Press release →
Showcase · live build
Casimio

A complete casino front-end — lobby, hundreds of game tiles, live win feed and a full cashier — assembled from CMS content and PAM data.

Compliance
ISO 27001 procedures

Automated testing aligned with regulatory requirements. Multiple software audits completed for Bethard Group & others.

Markets
UK · SE · ES · DK · MT

Portable compliance — adding a jurisdiction is configuration, not re-engineering. Next: 🇫🇮 Finland, opening July 2027.

Common questions from new operators

How long does onboarding take for a new operator?+

The core platform is already deployed. Onboarding a new operator means configuring their brand, integrating their chosen payment providers and game content, and setting up jurisdiction compliance rules. Most of this is configuration, not development — typically 1–2 weeks from kickoff to a live site.

Do I need my own gambling licence?+

It depends on your launch model. With WebPrefer's turnkey / white-label services you launch your brand on our platform; with a full PAM licence you run your own. White-label and B2B setups let multiple operators run on one deployment, each with its own skin, jurisdiction config and back-office access. Operators entering markets such as Sweden, Finland or Malta typically hold their own licence — and PAM provides the KYC, AML, SOW, self-exclusion and audit capabilities those regulators expect. We'll scope this with you in the first call.

Can we bring our own game providers?+

Yes. The integration layer accepts new providers without touching the core platform. If we don't have a pre-built integration, we build it as an isolated module. It doesn't affect anything else.

How do you handle regulatory requirements that change?+

Compliance configuration is declarative and separate from application code. A new KYC timeline, an updated SOW threshold or a new self-exclusion rule is a configuration update, not a deployment. For structural changes, we've shipped jurisdiction-specific updates without affecting other markets.

Can we run multiple currencies per brand?+

Yes. Currency handling is built into the money layer, not treated as a formatting concern. Exchange rates, display precision, wallet denomination and cross-currency reconciliation are handled at the platform level, so operators can run multiple currencies per brand without custom logic.

Is PAM cloud-native?+

PAM is deployed on IIS and Windows Services today, providing familiar, auditable infrastructure in regulated markets. The event-driven design, Redis caching and RabbitMQ messaging are cloud-compatible, and a migration path exists for operators who require cloud deployment.

Ready to launch your casino on PAM?

We offer scoped demos based on your operation type — a first brand, a new market, a migration from a legacy PAM or a white-label deployment. No generic walkthroughs.

Email
sales@webprefer.com
Address
Wahlbecksgatan 8, 582 13 Linköping, Sweden
CEO & Founder
Mikael Lindberg Castell · mikael@webprefer.com

Talk to the team

Tell us what you're launching and we'll come back with a scoped plan.