NIGC Helping Identify Causes and Remedies for AUP IT Findings
Written by Tom Cunningham, NIGC Chief Compliance Officer in Agency Updates
Date: 10/06/2026
It’s no secret that the gaming industry is technology-driven. You would be hard-pressed to find a tribal gaming operation today without a server room, interconnected gaming systems, and thousands, if not millions, of electronic transactions and communications. Disruptions or malicious intrusions into these systems can cripple or shut down a gaming operation for hours or even days.
The National Indian Gaming Commission (NIGC) co-regulates with tribes to protect this vital part of the gaming industry by promulgating minimum internal control standards (MICS) for Information Technology (IT) and requiring annual testing of those controls, known as the Agreed Upon Procedures report (AUP). Results are reported to the gaming operation, the Tribal Gaming Regulatory Authority (TGRA), and to NIGC or a state gaming agency when a tribal-state gaming compact has been approved.
The NIGC doesn’t stop there. We also have a dedicated Technical Compliance Regulatory Assessment and Compliance Services (TRACS) team that provides training, assessments, and testing.
To help tribes identify and mitigate IT risks, in 2026 the NIGC Compliance Division will collaborate with TRACS to focus monitoring and testing efforts during our annual site visits. We will identify operations with (1) a high number of IT-related AUP findings, (2) repeat IT findings from prior years, or (3) other known risk indicators. Agency Compliance Officers will then work with the gaming operation, TGRA, and TRACS to determine potential causes and remedies. However, gaming operations or TGRAs can reach out earlier to their assigned NIGC Compliance Officer to get the conversation started. You can find your Compliance Officer’s contact information here: www.nigc.gov/office-of-chief-of-staff/compliance/regional-offices/
Some issues can be remedied quickly through additional training, enhancements to policies and procedures, or more frequent and targeted testing by the gaming operation or TGRA. Other remedies may require further investment, such as additional staff or consultants, improved physical and electronic security measures, monitoring services, backup locations or cloud solutions, new hardware, or broader network improvements.
Currently, IT, Bingo, and Revenue Audit generate the largest number of AUP findings annually. Our primary goal is to reduce known risks to gaming operations and their IT Departments, and over the next three years we aim to lower the total number of IT AUP findings and move them out of the top three. By working collaboratively, we are confident operations can achieve significant improvements.
To learn more about NIGC’s top IT AUP findings, watch our recorded training available in the NIGC video library.