A Personal Management Licence is a licence for senior individuals who manage gambling business functions such as marketing, planning, IT, or compliance. It creates personal accountability for leadership roles that influence regulatory risk. The licence is separate from operating permission and usually requires renewal after five years.
What the licence represents in gambling governance
A Personal Management Licence is a personal accountability control, not a business operating permit. It sits with senior individuals whose decisions shape regulated gambling activity, especially where leadership authority can affect compliance posture, oversight quality, and the organisation’s willingness to meet regulatory obligations.
Because the licence attaches to the individual, it helps regulators distinguish between entity-level permission and the fitness of the people directing the business. That distinction matters in sectors where governance failures often start with weak leadership, unclear ownership, or poor challenge from senior management.
Who needs a Personal Management Licence
The licence is aimed at people in senior management functions that materially influence how the gambling business is run. Typical roles include leadership over marketing, planning, IT, compliance, or other functions that can affect how regulatory requirements are implemented and monitored.
This makes the licence broader than a narrow compliance badge. It is meant for roles with real decision power, where the person can shape risk decisions, internal controls, and the operating culture that surrounds them.
How the licence differs from operating permission
A common mistake is to treat personal licensing as if it were the same thing as approval for the business itself. The two are separate. The operator may be authorised to trade, while the individual licence assesses whether a senior person is suitable to hold a management position inside that business.
That separation allows regulators to intervene at both levels. A firm can remain licensed while an individual is found unsuitable, and a person can be expected to renew or maintain their licence even when their role changes, because the obligation follows the leadership function rather than the company brand.
Renewal, ongoing fitness, and accountability
Personal Management Licences are usually renewed on a five-year cycle, which makes ongoing fitness part of the model rather than a one-time check. The practical effect is that accountability is not assumed to remain static, especially when the underlying business, role scope, or governance expectations evolve over time.
The licence therefore operates as a recurring assurance mechanism. It reinforces the idea that senior management in gambling is expected to remain fit, competent, and accountable for the duration of the authority granted, not merely at the point of appointment.
Risk and Threat Considerations
Where senior individuals hold a Personal Management Licence, the main risk is not technical compromise but governance failure, weak oversight, and poor decision-making at leadership level. If the wrong person controls key functions, regulatory breaches can emerge through tolerated exceptions, weak challenge, or unmanaged conflicts of interest.
Failure mechanism: Accountability breaks down when senior responsibility is unclear, when licence holders fail to exercise effective control over regulated functions, or when the business treats personal approval as a formality rather than an active governance requirement.
Impact: The result can be regulatory intervention, reputational damage, and increased scrutiny of both the individual and the operator, especially where leadership decisions affect compliance, integrity, or the organisation’s control environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Personal licences sit within regulated organisational context and leadership accountability. |
| GV.RM-01 — Risk Management Strategy | The licence addresses senior role risk and ongoing fitness over time. | |
| Recommendation — Document management accountability for regulated gambling roles and keep leadership responsibilities current. Align senior-person licensing with your risk strategy and review it as roles and controls change. | ||
| ISO/IEC 27001:2022 | A.5.2 — Information security roles and responsibilities | The term centers on accountable senior roles with defined responsibilities. |
| A.5.31 — Legal, statutory, regulatory and contractual requirements | The licence is a regulatory requirement tied to lawful operation in gambling. | |
| A.5.35 — Independent review of information security | Senior accountability benefits from periodic independent scrutiny of control effectiveness. | |
| Recommendation — Assign and evidence clear responsibilities for regulated leadership functions. Track licensing obligations as part of your statutory and regulatory compliance register. Review whether leadership controls and oversight remain effective across the licence period. | ||
| NIS2 | Article 20 — Management body responsibility | NIS2 expresses senior management responsibility for governance and compliance oversight. |
| Recommendation — Make senior leaders visibly accountable for regulated security and compliance outcomes. | ||
| NIST SP 800-53 Rev 5 | PM-1 — Information Security Program Plan | Program-level accountability and governance mirror the licence's leadership focus. |
| Recommendation — Maintain governance documentation that clearly assigns decision ownership and oversight. | ||
Practitioner Guidance
Governance implication: Treat the licence as a leadership assurance mechanism, not an HR credential. The senior person should have a clearly defined scope of responsibility, with evidence that their role matches the regulated function they oversee.
What to watch for: Role drift, informal delegation, or blurred ownership can make a licensed individual accountable for outcomes they no longer fully control. That is often where renewal, suitability, and governance evidence become most important.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org