by David Vialpando
The Indian Gaming Regulatory Act (IGRA) designates tribes as the primary regulator of casino gaming on tribal lands. Tribal Gaming Regulatory Agencies (TGRAs) or gaming commissions are the independent tribal government units empowered to regulate tribal casinos. Most TGRAs perform this task admirably and consistently set industry standards for effective gaming regulation. Over the past three decades, tribes have developed sophisticated regulatory agencies staffed by experienced professionals and supported by comprehensive regulations, internal controls, surveillance systems and licensing programs.
Despite the proven success of tribal gaming regulation, a TGRA may find itself slipping into complacency and performing short of optimal levels. An underperforming TGRA may have a full staff, conduct inspections, issue licenses, review surveillance reports and attend industry meetings. On paper, the regulatory program may appear fully functional. Yet, effective regulation is measured not simply by the amount of regulatory activity; it is measured by whether the agency identifies and controls the risks that could threaten the integrity of gaming.
In most cases, TGRA underperformance can be traced to deficiencies in the following five areas:
• Regulating personalities instead of risk.
• Failing to maintain independence from casino operations.
• Allowing TGRA regulations to become outdated.
• Underinvesting in training.
• Reacting to problems instead of proactively identifying risks.
These deficiencies are not limited to small or inexperienced TGRAs. Unchecked, these dynamics can affect relatively large and experienced TGRAs. What’s important is whether the agency recognizes the problem and has the leadership discipline to correct it. What follows is a review of the most frequent areas of TGRA underperformance.
Regulating Personalities Instead of Risk
Among the most obvious signs of dysfunction within a TGRA occurs when regulatory decisions become influenced by personalities rather than objective risk analysis. TGRA regulators interact constantly with casino management, employees, vendors, patrons and casino visitors. Relationships naturally develop and professional relationships can enhance TGRA effectiveness. While not inherently problematic, dysfunction begins when relationships influence regulatory judgment.
A TGRA regulator may exercise more aggressive enforcement with casino employees who are difficult or confrontational while giving greater latitude to highly respected and amenable executives. Another regulator may become reluctant to challenge a casino department because its leadership has historically been cooperative. The TGRA may devote substantial attention to a controversial individual while overlooking a systemic weakness that presents a far greater threat to gaming integrity.
This dysfunction is referred to as personality-driven regulation. Effective regulation should instead be risk-driven. Risk, not the influence of relationships, should determine regulatory emphasis. To avoid personality-driven regulation, a TGRA should emphasize the following:
• What could compromise the integrity of gaming?
• What could result in financial loss?
• What could create regulatory or legal exposure?
• What could facilitate fraud or criminal activity?
• What could undermine public confidence?
• What weaknesses could allow an otherwise compliant employee to commit misconduct?
• Which casino areas and systems are most vulnerable?
• Which areas have experienced repeated findings?
• Which vendors or technologies create new risks?
What we’re proposing here is a formal TGRA risk assessment process. A minor procedural deficiency may have little effect on gaming integrity. A seemingly small weakness in access controls, surveillance oversight, cage accountability, key control, IT protection, player account management or anti-money laundering (AML) procedures could have substantially greater consequences. The goal of regulation is not simply to find regulatory violations, but to understand the significance of violations and mitigate risk.
TGRAs may consider devising a risk matrix that assigns a numerical priority to various casino processes based on the likelihood of risk behavior occurring and the potential impact should the adverse behavior materialize. Based on this risk matrix, high risk areas would receive greater regulatory inspection frequency, in-depth process testing, enhanced management attention, and thorough documentation. When regulatory decisions are based on documented risk criteria rather than personalities, relationships or individual preferences, the TGRA becomes more consistent and its actions more defensible.
Failing to Maintain Independence from Casino Operations
On occasion, the lines of demarcation distinguishing the TGRA from casino management may become murky. A TGRA losses effectiveness when its personnel begin thinking like casino management. It is important for regulators to keep in mind that the casino’s goals are to operate efficiently, increase revenue, introduce new technology, improve the customer experience and control costs. The responsibility of the TGRA is to protect the integrity of gaming and protect tribal assets through independent regulation.
One of the most important distinctions in tribal gaming regulation is the difference between casino management’s responsibility for compliance and the TGRA’s responsibility for regulatory oversight. Casino management should establish operational controls, train employees, monitor performance and correct deficiencies. The TGRA should independently determine whether those controls are adequate and whether the operation is complying with applicable requirements. If the TGRA begins solving operational problems for management, generating operational procedures for the casino, directing employees or becoming involved in day-to-day business decisions, regulatory independence can quickly erode.
For most TGRAs, gaming regulations guide the development of internal controls designed by the casino operator and approved by the TGRA. Casino procedures are then generated based on the requirements of the TGRA-approved internal controls, and again, submitted to the TGRA for approval. Nothing precludes the TGRA from offering suggested edits to the internal controls or casino policies, but the TGRA should not be the entity drafting either of these documents.
To assess the TGRA’s independence from the casino operator, an important question to ask is, “Could the TGRA make a certain regulatory decision if the casino’s senior management strongly disagreed with it?” If the answer is no, the TGRA may have an independence problem.
Allowing TGRA Regulations to Become Outdated
Gaming technology, business practices, financial systems, cybersecurity threats and regulatory expectations are continually evolving. TGRA regulations that were appropriate five years ago may be inadequate today.
Amendments to TGRA gaming regulations may require not only legal review, but also tribal government review and approval, typically the elected tribal council. This may be one reason why regulations are infrequently updated, but consistent changes in the casino gaming landscape require regulations that stay abreast of the evolving and emerging risks that accompany operational changes.
Consider the following current industry trends and ask yourself if the regulations last updated a few years ago effectively address the potential risks accompanying these changes:
• Mobile applications
• Cloud computing
• Artificial intelligence
• Facial recognition
• Radio Frequency Identification or RFID
• Advanced player tracking and analytics
• Sports wagering
• Third-party technology providers
• BSA/AML reporting changes
One alternative TGRAs might consider in lieu of frequent amendments to regulations is the development of internal controls to address the risks and outline TGRA requirements for proposed technological integration. TGRAs should establish a formal regulatory review cycle to ensure that the regulations are sufficient to address the casino’s current state. The goal should be to close the gap between what the casino does and what the TGRA regulates.
The TGRA should review regulations after significant events. A serious incident, regulatory finding, technological change or enforcement case should prompt the following question: Does this event reveal a weakness in our regulatory framework? If the answer is yes, the regulation should be updated.
Underinvesting in Training
A TGRA with updated regulations and detailed policies can still fail if the TGRA’s regulators do not understand how to apply them. A poorly trained inspector can miss a significant violation. A poorly trained licensing investigator can overlook critical suitability information. A poorly trained auditor can fail to identify a control deficiency. A poorly trained manager can mishandle an investigation or make an inconsistent or inappropriate enforcement decision.
TGRA Management Should Not View Experience as a Substitute for Professional Skills Training
One of the most dangerous assumptions in regulatory organizations is: “We’ve been doing this for years, so we know what we’re doing.” The constantly evolving nature of the casino gaming industry and consistent updating of regulatory best practices demands a commitment to continual training for TGRA personnel. The National Indian Gaming Commission (NIGC) recognizes this need and provides free state-of-the-art training to tribal regulators through their national workshops and virtual national training topics of the month. Industry organizations and vendors, including the Indian Gaming Association (IGA), National Tribal Gaming Commissioners and Regulators (NTGCR) Association, GLI University, BMM’s RG24/7, Tribal Gaming Protection Network (TGPN), and many others strive to provide training and shared experience forums for regulators and casino operators.
A strong TGRA maintains competency standards for each position within the agency/commission and encourages staff to remain proficient in required skills by supporting attendance at training forums and industry conferences. Mere attendance at training forums is not sufficient. TGRA management should require staff to demonstrate newly acquired and updated skills and share acquired knowledge with others in the TGRA. The objective is to produce competent and proficient regulators.
Reacting to Problems Instead of Proactively Identifying Risks
What distinguishes a peak performance TGRA from an underperforming TGRA more than anything else is whether the agency is primarily reactive or proactive. A reactive TGRA waits for something to happen that requires regulatory action and a proactive TGRA asks what could happen and looks for warning signs before it does.
A reactive TGRA spends more of the agency’s resources addressing the following: complaints, incidents, employee misconduct, failed audits, patron disputes, system failures, regulatory violations, casino management requests and enforcement matters. While these issues are important, the dysfunction happens when reactive tasks consume the TGRA’s entire capacity.
A proactive TGRA works to identify risks before an incident occurs. This is accomplished by the following: analyzing recurring violations, inspection findings,; audit results,surveillance incidents, employee turnover, unusual financial activity, patron complaints, system and process changes, cybersecurity events, vendor performance, licensing trends,
disciplinary patterns, and emerging technologies.
Designing and implementing a regulatory dashboard that tracks the following will identify patterns leading to control system failures and transitioning the TGRA from incident management to risk management:
• Repeat findings
• Overdue corrective actions
• Unresolved audit issues
• Licensing deficiencies
• Employee disciplinary trends
• Surveillance exceptions
• System outages
• AML alerts
• Cybersecurity incidents
• Vendor deficiencies
• Complaints
• Enforcement cases
The most effective TGRAs will increasingly function as strategic regulatory organizations rather than traditional compliance offices. They will accomplish this by committing to better regulatory intelligence, stronger agency independence, continuous professional development and a risk-based approach to regulatory oversight. This is the difference between a TGRA that merely exists and a TGRA that effectively protects the integrity of tribal gaming.
David Vialpando, MBA is Executive Director of the Pala Gaming Commission, Vice-Chairman of the Tribal Gaming Protection Network and author of the book, Fundamentals of Tribal Casino Gaming Regulation – A Primer for Regulators. He can be reached by calling (760) 201-7088 or email [email protected].













































