iTech Labs and GLI: A Look at Casino Testing Agencies
The industry claims: "Certified by GLI" or "Tested by iTech Labs."
Filed 12 September 2026 · 4 min read

The industry claims: "Certified by GLI" or "Tested by iTech Labs." Players see these logos and assume trustworthiness. This is reasonable. It's also incomplete. Testing agencies exist to validate randomness. They're not financial auditors. They don't verify payouts match marketing. They don't check if the operator has money. They certify one specific property: the RNG works as claimed.
GLI (Gaming Laboratories International) certifies approximately 70% of regulated gaming machines in North America. iTech Labs holds roughly 15% of online betting certifications globally. The remaining 15% splits between Everi, Kambi, and others. These two firms are the de facto gatekeepers. A game cannot launch in most jurisdictions without their approval. That creates a structural advantage. Also a structural risk.
What These Agencies Actually Test
GLI's certification process for a slot machine involves: Installing the machine in a test lab. Running it for 3+ million spins. Measuring the payout frequency. Confirming the RTP (Return to Player) matches claims. For example, a casino claims a game has 94% RTP. GLI runs 3 million spins. If average payout is 93.8-94.2%, it passes. If it's 90%, it fails. The tolerance is typically 0.5 percentage points.
They also test randomness itself. Using statistical analysis (chi-squared tests, entropy measures), they verify the RNG produces sequences that are statistically indistinguishable from true randomness. This is important because an operator could theoretically build an RNG that always hands the house 6% edge (instead of the claimed 5%) by subtly biasing outcomes. Testing detects this.
But here's the limitation: Testing captures the RTP over a sample of 3 million spins. In real casinos, over decades of play, that sample expands to billions of spins. The question: does real-world performance match test-world performance? The answer is yes, most of the time. But sample-size issues can hide bias in test conditions that become visible in deployment.
In 2015, a Las Vegas casino discovered that a certified slot machine (GLI-approved) had a flaw. The RNG was technically random. But the physical machine had a mechanical defect. A certain combination of button presses could bias which reel landed on specific symbols. The game was mathematically sound. The machine was flawed. Testing didn't catch it because GLI only tested software, not hardware integration.
That's the first risk: scope. Testing focuses on the algorithm, not the implementation. The second risk is audit recency. GLI certifies a game. Casinos use it for 5 years. Meanwhile, the operator updates the software. They don't re-test. Why? Re-testing costs $50,000-$100,000. Casinos won't pay unless required. So games run under expired certifications. Regulators in some jurisdictions require annual re-testing. Most don't. Nevada requires re-certification every 7 years, but only if the machine is updated. Updated how? There's ambiguity.
The third risk is manufacturer discretion. Developers submit code to GLI. GLI tests the submitted code. The developer could theoretically change the code post-approval. Modern deployments use cryptographic signatures to prevent this. But in older games, it's possible. A theoretical exploit would be: create two versions of the code. Submit the fair version to GLI. Ship the biased version to casinos. No detection because the code tested and the code deployed are different.
iTech Labs operates similarly. They test online gaming software. They certify poker platforms, sportsbooks, casino games. For poker specifically, they verify that equity calculations are correct. If two players go all-in, the software calculates their winning probability against each remaining deck. iTech verifies that calculation is accurate. They also test for collusion detection. Does the software catch when two accounts are playing together unfairly? The test is binary: yes or no.
Here's the data: The number of gaming certifications issued annually by all agencies combined is roughly 12,000. The number of formal challenges or revocations per year is 4-7 globally. That's 0.03-0.06% failure rate. Sounds impressive. But it reflects the test process. If testing doesn't scrutinize something, operators have latitude. The agencies can only catch what they specifically look for.
There are incentive misalignments. Gaming Laboratories International is a profitable company. DCI, its parent corporation, generated $200 million in revenue last year. They rely on casinos and operators paying for certifications. If GLI became excessively strict, operators would push for competitors. Less business follows. The incentive is not absolute failure (certify dangerous games) but relative leniency (set standards other labs will match).
The reality: Testing agencies certify randomness, not safety or fairness in the broader sense. Their approvals are necessary but insufficient. A GLI-certified game is random and mathematically sound. It could still be designed to disadvantage players through complexity (many obscure bet types, unclear payoff schedules). It could have updated code that wasn't tested. It could have mechanical flaws. The certification means: we tested this specific thing, under these specific conditions, at this specific time. It doesn't mean the game is trustworthy across all dimensions.
