ʴDzٱ:June 2026
The instructors at the Faculty of Open Learning & Career Development bring a wealth of experience in their fields, and our learners benefit greatly as they work to advance their careers.
“The modern gaming compliance professional is part regulator, part investigator, part risk manager, part educator, and part business advisor.”
How does your experience with the National Crime Agency influence the practical, boots-on-the-ground technique you teach in your courses?
In law enforcement, you are rarely dealing with perfect information. You are working with fragments: transactions, intelligence reports, company records, interviews, and sometimes conflicting explanations. The skill is not simply knowing the legislation or the typologies. The skill is knowing how to turn incomplete information into a clear investigative strategy.
I want learners to understand how financial crime actually presents itself in the real world. It is often messy, ambiguous, and hidden behind normal-looking business activity. Whether we are talking about money laundering, fraud, casino risk or wildlife or fisheries crime, the same basic questions matter: What is the criminal benefit? Who controls it? How is it being moved? What documents support the story? What does not make sense? What evidence would prove or disprove the suspicion?
My NCA background also influences the emphasis I place on “following the money.” In many cases, the person on the front line of the offence is not the person making the most profit. A good investigator or compliance professional looks beyond the visible incident and asks who is organizing, facilitating, financing, and benefiting from the activity. That mindset is central to the way I teach.
At the same time, my corporate compliance experience has helped me translate that investigative mindset into something practical for professionals working outside law enforcement. Compliance teams, AML analysts, auditors, regulators, and investigators may not all have police powers, but they still need to think critically, identify red flags, document decisions, escalate concerns, and understand risk. The courses are designed to bridge those worlds: the discipline and structure of law enforcement, combined with the operational realities of compliance.
The skill is not simply knowing the legislation or the typologies. The skill is knowing how to turn incomplete information into a clear investigative strategy.”
In your view, how has the role of a Gaming and Compliance professional changed over the last 5-10 years?
Today, gaming compliance professionals are expected to understand the full risk environment around the business including; anti-money laundering, sanctions, responsible gaming, player protection, fraud, payments, cybersecurity, data privacy, etc. Compliance is no longer about whether the organization has a program on paper. It is about whether that program is actually influencing decisions, identifying risk, protecting players, and preventing misuse of the platform.
One of the biggest changes has been the move from a rules-based mindset to a risk-based mindset. Regulators now expect operators to understand their specific risks and demonstrate that their controls are effective in practice. That means compliance professionals need to be able to assess risk, challenge business decisions, interpret data, identify patterns, and explain why certain customers, products, transactions, or behaviours may require enhanced attention.
The growth of online gaming and sports betting has changed the role significantly. In a land-based casino, many risks are visible: cash, chips, cage activity, surveillance footage, and face-to-face customer interaction. In the online environment, much of the risk is digital. Compliance teams need to understand onboarding data, payment flows, account behaviour, geolocation, device information, etc. That requires a much more analytical and technology-aware skill set.
The role has also become more integrated with the business. A good compliance professional cannot sit on the sidelines and simply say “yes” or “no” at the end of a process. They need to be involved in product design, customer journey, payment controls, marketing campaigns, vendor management, and operational decision-making. Compliance has become part of how a gaming business is built and managed, not just how it is reviewed after the fact.
In my view, the modern gaming compliance professional is part regulator, part investigator, part risk manager, part educator, and part business advisor. The best people in this field understand the law, but they also understand operations. They know how games work, how players behave, how money moves, how criminals exploit systems, and how controls affect the player experience.
When you were developing the , what was the specific knowledge gap in the industry you were most determined to bridge?
In many organizations, people are promoted because they are strong technical specialists, but they are not always given the leadership tools they need to succeed. They may know the rules, but they may not yet know how to lead people through change, manage conflict, communicate risk to executives, or create alignment between compliance, operations, and commercial priorities. That was the gap I wanted the certificate to address.
The gaming sector also has a very specific leadership challenge. It is highly regulated, fast-moving, customer-facing, technology-driven, and exposed to significant integrity risks. Leaders need to understand not only what the regulations require, but how decisions made in one part of the business affect other areas. A decision about player onboarding, payments, marketing, game design, responsible gaming, or VIP management can have compliance, reputational, financial, and operational consequences.
So the certificate was designed to help professionals think more broadly. It is not just about managing a department. It is about understanding the gaming ecosystem, leading ethically, making better decisions, building accountable teams, and recognizing how compliance and leadership intersect.
The other gap I wanted to bridge was the divide between compliance and business operations. Sometimes compliance is seen as separate from the business, or even as a barrier to business growth. Effective compliance leadership should support sustainable growth by helping the organization understand risk, protect players, satisfy regulators, and maintain trust. Good leaders need to be able to explain that clearly and confidently.
Regulations in the gaming industry are very complex. How does the Certificate in Gaming Leadership help professionals navigate those “grey” areas with confidence?
The Certificate in Gaming Leadership helps professionals navigate those grey areas by giving them a structured way to think about risk, responsibility, and decision-making. It is not designed simply to teach people what the regulations say. It is designed to help them apply those expectations in real business situations, where there may be competing pressures, incomplete information, and no obvious “right” answer. For example, a compliance professional may have to consider whether a player’s behaviour raises responsible gaming concerns. The issue is not just technical compliance. It is judgment, leadership, documentation, communication, and accountability.
The certificate helps professionals build confidence by focusing on how decisions should be made. That includes understanding the intent behind regulation, identifying the risks involved, considering the impact on players and the business, documenting the rationale, and knowing when to escalate. In regulated industries, confidence does not come from always having certainty. It comes from having a defensible process.
With the shift toward digital and iGaming, how has the course evolved to cover both physical and digital threats?
Traditionally, casino security and surveillance were viewed primarily through a physical lens: protecting the property, monitoring the gaming floor, identifying cheating or advantage play, responding to incidents, supporting investigations, and ensuring the safety of guests and staff. Those responsibilities are still central, but they are no longer enough on their own.
With the growth of digital gaming, security and surveillance professionals need to understand how physical and digital risks now overlap. A modern casino or gaming operator is not just a building with tables, slots, cameras, and access points. It is also a technology environment, a payments environment, a data environment, and in many cases, an online customer platform.
The course has therefore evolved to help learners think about security and surveillance as an integrated function. Physical threats still matter: theft, violence, cheating, collusion, internal misconduct, intoxication, etc. But those risks may now connect to digital issues such as account takeover, identity misuse, payment fraud, bonus abuse, cyber-enabled threats, and suspicious online behaviour.
One of the key messages in the course is that the old divide between “security” and “technology” is becoming less useful. For example, a fraudster may begin with a compromised online account, use stolen identity information, move funds through a digital wallet, and then appear at a land-based property to withdraw or convert value. These are not purely physical or purely digital problems; they are converged risks.
The surveillance function has also changed. Historically, surveillance was often associated with camera coverage and observation of activity on the gaming floor. Today, surveillance professionals increasingly need to understand how video evidence, transaction data, player account activity, and digital alerts can be brought together. The ability to connect different sources of information is now just as important as watching what is happening in real time.
The course also places more emphasis on collaboration. Security and surveillance teams cannot work in isolation from compliance, AML, fraud, IT, responsible gaming, payments, legal, and operations. The modern professional needs to know when to escalate, who to involve, and how to document the issue clearly.
When leaders treat compliance as something that happens after the operational decision has already been made, they often miss the opportunity to prevent the issue in the first place.”
In the course, what are the most common operational pitfalls you see leaders make, and how does this training help them avoid those costly mistakes?
One of the most common operational pitfalls I see is treating compliance and investigations as separate from day-to-day operations. In gaming, risk does not sit neatly in one department. It appears in player onboarding, cage activity, payments, surveillance, responsible gaming interactions, and internal controls. When leaders treat compliance as something that happens after the operational decision has already been made, they often miss the opportunity to prevent the issue in the first place.
Another common pitfall is relying too heavily on policies and procedures without asking whether those controls are working in practice. A gaming operator may have a strong AML policy, an incident reporting process, or a responsible gaming framework on paper, but the real question is whether staff understand it, whether supervisors apply it consistently, whether red flags are escalated, and whether the organization can evidence the decisions it makes. Regulators are increasingly focused on effectiveness, not just documentation.
I also see leaders underestimate the importance of good information flow. A surveillance team may see one part of the picture, the cage may see another, compliance may see another, and customer service may hold important behavioural information. Many costly mistakes happen because information exists somewhere in the business, but it is not brought together in time to support a better decision.
Another issue is weak escalation culture. Staff may notice something unusual but feel unsure whether it is important, who to tell, or whether raising a concern will create conflict with the business. In a strong compliance culture, people are encouraged to escalate concerns early, even when the information is incomplete. It is much better to review a concern and decide it is not significant than to miss a serious issue.
The Casino Gaming Compliance and Investigations course helps leaders avoid these mistakes by focusing on practical decision-making. It is not just about knowing the rules. It is about understanding how risk appears in real casino and gaming operations, how investigations should be structured, how evidence should be documented, and how different departments need to work together.
With the rise of AI and automated monitoring, why is the human element—the 'investigator’s intuition' taught in your courses—more valuable now than ever?
I actually think the human element has become more important, not less important. Technology can process huge volumes of information, identify anomalies, prioritize alerts, and detect patterns that would be very difficult for a person to find manually. But AI does not understand context in the same way an experienced investigator does. That is where human judgment becomes essential.
In financial crime investigation, an alert is only the beginning of the process. A system might tell you that something is unusual, but it cannot always tell you whether it is suspicious, explainable, or part of a wider pattern of criminal behaviour. That distinction requires experience, curiosity, and professional judgment.
What I teach in my courses is that “investigator’s intuition” should not mean guesswork. It means informed judgment built from experience, typology knowledge, evidence review, and an ability to recognize when something does not quite make sense. A good investigator notices inconsistencies. They ask why a transaction happened in that way, why a customer’s behaviour changed, why a document does not match the business profile, or why the explanation feels incomplete.
AI is very good at identifying patterns, but financial crime is often hidden in ambiguity. Criminals do not present themselves as criminals. They use legitimate businesses, normal-looking transactions, professional intermediaries, digital platforms, and plausible explanations. The investigator’s role is to interpret the meaning behind the data and decide what should happen next.
This is especially important because automated systems can produce both false positives and false negatives. A system may flag activity that is legitimate, or it may miss activity because the criminal method is new, subtle, or outside the model’s training data. Human review helps test the output.
The human element is also vital for explainability. Regulators and senior leaders do not just want to know that a model produced a result. They want to understand why a decision was made. If an account is exited, a suspicious transaction report is filed, an investigation is escalated, or a customer is treated as higher risk, the organization needs a clear and defensible rationale. That rationale comes from human analysis, not just automated scoring.
What does a 'successful' graduate of these programs look like to you? What kind of impact are they making in their respective organizations six months after finishing your courses?
A successful graduate is not simply someone who has completed the course. A successful graduate is someone who returns to their organization and starts thinking differently, asking better questions, and making more confident, risk-based decisions.
Six months after finishing one of our programs, I would expect that person to be having a practical impact in their role. They may be improving how investigations are scoped, strengthening escalation processes, identifying gaps in controls, improving documentation, or helping colleagues understand why compliance is not just a regulatory requirement but part of good decision-making.
In financial crime and gaming compliance, success is often seen in the quality of judgment. A strong graduate does not just spot a red flag and move on. They understand what the red flag means, what additional information is needed, who should be involved, and how the issue should be documented or escalated. They are more comfortable dealing with ambiguity and more capable of explaining their reasoning to managers, auditors, regulators, or law enforcement partners.
In a gaming environment, that might mean recognizing that a player’s activity is not just unusual but potentially connected to AML, fraud, responsible gaming, or integrity concerns. In a financial crime investigation role, it might mean moving beyond the immediate transaction and asking who benefits, how the funds are moving, what structures are being used, and what evidence is needed to build a defensible case.
Another sign of success is confidence. Many professionals already have experience, but they may not always have a structured framework for applying it. After completing the program, they should feel more confident in their ability to assess risk, interpret evidence, recognize patterns, and communicate findings clearly. That confidence should be practical, not theoretical.
The best outcome is when a graduate helps their organization become more proactive. Instead of waiting for a regulator, auditor, or enforcement agency to identify a problem, they begin identifying issues earlier, strengthening controls, and improving the organization’s ability to prevent harm.
A successful graduate is someone who returns to their organization and starts thinking differently, asking better questions, and making more confident, risk-based decisions.”
The line dividing physical security from digital threat intelligence has permanently dissolved. As Dr. Ian Messenger highlights, today’s compliance landscapes are defined not by neat, rules-based checklists, but by messy, fragmented data streams across onboarding, payments, and player behavior. True operational resilience requires leaders who possess a structured, investigative methodology—professionals capable of stepping out of functional silos to connect the dots behind converged risks. Navigating these grey areas isn't about achieving absolute certainty; it is about establishing a defensible, proactive process that drives sustainable, ethical growth.
Don't wait for a regulatory breach to find the gaps in your operational strategy. Equip your team with the practical, "boots-on-the-ground" frameworks needed to turn ambiguous data into confident business strategies. Explore all our Dr. Messenger's courses .