Curaçao tightens rules on B2C operations manuals

The Curaçao Gaming Authority details what B2C operators must include in their mandatory operations manual under the LOK.
Share on
Welcome to Curacao sign
  • The Curaçao Gaming Authority has published new Operations Manual Guidelines for B2C licensees under Article 5.9 of the LOK
  • Licensees must upload a compliant manual to the CGA portal by the end of October 2026 and review it at least annually
  • The guidance sets out a proportionality principle, letting operators reference underlying policies rather than reproduce them in full

The Curaçao Gaming Authority (CGA) has published detailed guidance on the operations manual every holder of a B2C online gaming licence must keep under Article 5.9 of the National Ordinance on Games of Chance (LOK), setting an end-of-October 2026 deadline for licensees to upload a compliant version to its portal.

What the CGA expects inside the manual itself

The Operations Manual Guidelines, dated September 2026, describe the manual as a management summary, not a place to dump every underlying document. That distinction is the first thing operators should check against their own draft: a manual padded out with full contracts, certificates and system logs is doing the wrong job.

The CGA does not expect licensees to reproduce material that already exists elsewhere in the organisation in controlled form. Instead, each section should describe the area briefly, point to the relevant policy, register or agreement, and confirm exactly where it is kept and by whom. Operators still working from a single sprawling document should treat this as a cue to split it: a short summary in the manual, full records held separately and ready to produce.

That readiness is not optional. The CGA can request the underlying documents at any point, and licensees have five working days to hand them over, unless a shorter window applies under the LOK or a specific licence condition. Anyone who cannot locate a current supplier contract or test report within that window has a gap worth closing now, not in October.

Annual reviews and version control now mandatory

Three principles sit behind the approach: proportionality, accuracy over volume, and evidence produced on request rather than filed in the manual itself. The CGA argues that bet limits and payout parameters shift too often in a live operation for a static document to stay accurate, and that a short, correct manual serves supervision better than a long one that goes stale within weeks.

Version control is a simple but easy step to miss. Each edition needs a version number, an issue date, and the name and role of whoever maintains it. Licensees should build an annual review into their compliance calendar now, since the manual must also be updated after any material change, even though the CGA has yet to define exactly what that means.

What your supplier and payment registers need

Article 5.9 sets out ten areas the manual has to address: games, payments, bet limits and payouts; quality testing; player data storage; how required information is displayed on-site; blocking banned players; technical infrastructure and continuity; responsible gambling; terms and conditions; dispute handling; and the location of critical player records, alongside a reference to staff training. Operators without a manual yet should use this list as the build order, not ten separate projects.

The most concrete task is the paperwork. Licensees need a Game Supplier Register and a Payment Provider Register, each listing the supplier, whether they are contracted directly or through an aggregator, the product type, and the date the agreement was signed.

Every third-party content provider has to be checked against the CGA’s own supplier list, so this is a good moment to reconcile that list against live integrations rather than assume it is current. Bet limits work differently: instead of a static schedule, the manual has to explain how minimum and maximum amounts are set, approved and changed, and who signs off on them.

Making sure your systems match your paperwork

Quality testing and player data get a lighter touch on paper but still need real substance behind them. The manual only has to note the test methods, how often they run and how results are recorded, with reports kept on file for inspection.

Player data follows the same shape: a summary of security measures, storage location, retention periods and deletion process, backed by the full data protection policy held separately. Operators should confirm both summaries actually match what their systems do today, not what a policy document said a year ago.

On the customer-facing side, the guidance covers how a site displays its terms, responsible gambling tools, AML and KYC information, and the CGA seal alongside the operator’s registered details. It sits close to a related update from earlier this year, when the regulator introduced stricter identity checks for players onboarded remotely, giving operators until May 2027 to adjust their systems, so teams working on that project can fold this documentation into the same review.

Two further items are easy to overlook. Licensees must show a current infrastructure diagram and a continuity summary, with the full disaster recovery plan produced only if asked, and they must confirm that critical player and transaction data sits in a Tier-IV certified data centre registered in Curaçao. That last requirement still depends on a ministerial decree on local server reporting standards that has not yet taken effect, so operators should note it as pending rather than treat it as settled.

The October deadline sits among several others

The upload deadline itself is not new. Compliance advisory EM Group reported in July that the CGA had already pushed back an earlier target for having a manual in place to 31 August 2026. What changes now is specificity: operators have a working definition of what belongs inside the manual and what can stay outside it, across all ten elements, which means there is no excuse left for guessing at scope before the October deadline.

The timing also matters because it is not the only date on the calendar. B2C licensees face a separate 8 October deadline to rewrite their terms and conditions under a CGA policy published in April, and a crypto guideline issued in June set its own three-month window for uploading a compliant policy.

Supplier registration under the LOK’s transitional rules is due to open before a 24 December cut-off. Compliance teams juggling all four should treat the operations manual as the anchor document, since it references the others directly.

The practical next step is a gap analysis, not a rewrite from scratch: take the ten elements, check what documentation already exists for each, and note where a register, a policy reference or a version history is missing.

The LOK only replaced Curaçao’s old master licence and sub-licence system in December 2024, and the CGA has spent the months since filling in this kind of operational detail.


Submit story

Do you have a story worth sharing?
Send it over to our editors!

Send story
Advertise with us