Join our Newsletter — 33% off our NHI Course

Personal Functional Licence

A Personal Functional Licence authorises individuals to work in operational gambling roles such as dealers, cashiers, pit bosses, or security surveillance. It is used to control who can perform regulated tasks inside the gambling environment and helps ensure staff are properly screened before handling sensitive duties.

What the licence is for

A Personal Functional Licence is a role-based authorisation for people working in regulated gambling operations. It separates approved operational staff from everyone else and creates a formal gate before someone can perform sensitive duties on the floor or in surveillance.

Its purpose is not just administrative. It is part of the operator’s control environment, helping ensure that the people handling cash, monitoring play, or exercising authority in a gaming venue have been screened, approved, and assigned to a permitted function.

Where it sits in gambling governance

This kind of licence is typically used where the regulator wants a clear link between a person, the job they are allowed to do, and the level of trust required for that role. It helps operators demonstrate that access to regulated functions is not informal, inherited, or left to local discretion.

In practice, it supports accountability. If a person changes duties, moves site, or leaves the role, the licence status becomes part of the decision about whether they can continue working in that operational capacity.

What it controls in daily operations

Personal Functional Licences usually matter most in jobs where discretion, cash handling, customer interaction, or security oversight can materially affect fairness, integrity, and loss prevention. The licence acts as a control on who may carry out those functions, rather than on the machines or systems themselves.

That makes it a governance mechanism as much as an employment one. It helps management assign work only to approved people, and it gives regulators a way to distinguish ordinary staff from those authorised to perform controlled operational tasks.

Why the term matters for practitioners

For operators, the important point is that a Personal Functional Licence is only effective when it is tied to role assignment, supervision, and timely revocation. A licence that exists on paper but is not checked against actual duties creates a gap between regulatory intent and day-to-day practice.

It is also a reminder that regulated access is contextual. The same individual may be suitable for one function and not another, so the licence should be treated as a specific authority to work in defined duties, not as a general endorsement for all casino activity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Controls who is authorised for specific operational roles and duties.
IA-2 — Identification and Authentication (Organizational Users) Requires verified personnel identity before authorising regulated operational tasks.
Recommendation — Link role assignment to approved status and remove access when duties change. Ensure only positively identified staff are approved for regulated duties.
ISO/IEC 27001:2022 A.5.16 — Identity management Supports governance of who is authorised to perform defined roles and responsibilities.
A.5.18 — Access rights Covers granting, reviewing, and revoking access based on role and need.
Recommendation — Maintain an accurate record of who is authorised for each regulated function. Review and revoke role-based authorisation when staff change duties or leave.
CIS Controls v8 CIS-5 — Account Management Addresses tracking authorised users and removing unnecessary access.
Recommendation — Track approved operational roles and promptly remove outdated authorisations.

Practitioner Guidance

Governance implication: Treat the licence as part of workforce access control, not just a compliance record. The relevant question is whether the person is currently approved for the specific function they are performing, in the venue and role they are performing it in.

What to watch for: Pay attention when staff change duties, move between operational areas, or are granted temporary coverage outside their usual function. Those are the moments when licence status, supervision, and authorisation can drift apart.

Practitioner takeaway: The licence only reduces risk when it is actively checked against actual work, with clear ownership for approval, reassignment, and removal from duty.