Column 03

My nine-step review protocol from account creation to cashout

A clean review is not a screenshot audit. It is nine specific steps, done in the same order every time, with receipts. Here is exactly how I run one, without shortcuts.

Column 03Review method9 min read
editorial workspace with a stopwatch, a small notebook, and a laptop showing a bank statement on a sage-green desk

Why I test before I write about any site

There is a lot of casino review content in circulation that never went through the sign-up form. I do not write that way. Every operator I comment on has taken my own real name, my own real card, and paid a real withdrawal into my real bank account, or failed to. That is the standard I hold myself to, and it is the standard I would want a reviewer I read to hold themselves to.

What a static audit misses

A screenshot audit can tell you that a licence footer exists, that the RG tools link is present, and that the terms and conditions page loads. It cannot tell you whether the operator will actually pay out on the third Tuesday of the month at three in the afternoon after you have opted into their reload bonus. That kind of information only comes from doing the sign-up. So a review that has not done the sign-up is telling you about the marketing page, not about the operator.

What a paid review misses

Paid reviews (where the operator has funded the reviewer) tend to soften on the same handful of items: withdrawal times, KYC friction at cashout, and the bonus max-cashout clause. Those are, not by coincidence, the three items a real customer is most likely to hit. I do not accept operator payment for reviews, which is a smaller business than the alternative but produces reviews I can defend.

Why receipts matter

I keep every email, every chat transcript, every screenshot, and every bank statement from every review, timestamped and locked. If the operator changes its terms three months later I can show what a reader saw when they followed my recommendation. That folder is the single most valuable asset in this operation, and it is the reason I take the tests seriously.

Reading the licence, and reading between the lines

The first step in any test is a proper licence read. Not a glance at the footer, a proper read: issuer, licence number, entity name, registered address, and a cross-check against the regulator's public register. I do this before I have entered any personal detail on the site, because if something does not line up I want to know before I have handed over an email address.

hand holding a magnifying glass over a printed footer with regulatory information
The licence footer is the first thing I read on any operator homepage.

What I check on the licence page

I want the issuer named clearly, a licence number I can search, and an entity name I can verify against the licencing regulator's register. If the operator page links directly through to the regulator's register entry, that is a small green flag on its own. If the link is broken or points to the wrong entity, I stop the review. That has happened to me twice in the past year, on both occasions with newer Anjouan-licenced brands.

How I trace sister brands

Once I have the incorporated entity name, I search the same regulator's register for other brands operating under the same directors. Groups almost always run multiple brands under one legal entity, which is not a problem in itself, but it does mean the reputation and enforcement history of the sister brands is directly relevant to the brand I am about to test. A messy closure eighteen months ago at a sister brand is information I want in the review.

The things that end the review before I sign up

Three things end the review at the licence stage. A licence that cannot be verified against the regulator's register. An entity name that appears to have been substituted after complaints against the previous entity. A jurisdiction with no gambling licencing regime at all (Costa Rica commercial incorporation being the classic). None of those get further than the first read, because there is nothing recoverable in the rest of the site if the foundation does not stand.

Signup, and what I do not put in the form

The sign-up form is the operator's first look at you, and the volume of information they ask for at this stage tells you something about their compliance posture. I sign up with my real name, my real date of birth, and a working email address, but there are two or three items I withhold at this stage and add later, deliberately.

What I always provide upfront

Real name, real date of birth, real address, a working email address I check daily, and a phone number I own. This is not a place to game the system. If the operator flags an inconsistency at KYC later, the whole review is compromised, and in any case falsifying account details is a rule breach at every operator I have ever seen. I want the operator to see a clean, real customer they cannot fault on identity.

What I hold back on the first pass

I do not attach a payment method on the sign-up page even where the option is offered. I want to see whether the site allows me into the account without one, which speaks to how aggressive the operator is on conversion. I also do not opt into any newsletter or SMS marketing at this stage. Both of those preferences I set explicitly in the account preferences page after I have logged in, so I can screenshot the toggle state and check it against what actually turns up in my inbox.

The tells I watch for during signup

Watch what fields are marked optional and what fields are marked mandatory. Any operator that requires marketing consent as a condition of account creation is starting on the wrong foot. Any operator that asks for source-of-funds information before you have deposited is asking a compliance question in the wrong sequence. Small things individually, but they tell you the shape of the operation, and I note them in the review even if they are technically legal in the licencing jurisdiction.

First deposit, deliberately small

My first deposit at any operator is between twenty and fifty pounds, and it is placed on a rail I can revoke without difficulty if I need to. That means a UK debit card with a clear chargeback path, or in some cases a stablecoin transfer I am willing to write off if it does not arrive. Never an e-wallet on the first deposit, because e-wallets weaken the chargeback route.

Why the amount is small

Small deposits limit downside if the operator turns out to be worse than the licence suggests, and they also mean the first withdrawal is a modest amount that is unlikely to trigger any high-value review process at the operator's payments team. I want the withdrawal to travel the same route a real first-time depositor's would. If the operator holds up a fifty-pound withdrawal for two weeks, that tells me exactly what will happen to a five-hundred-pound one.

Why the rail matters

A UK debit-card deposit gives me a chargeback path if the operator fails to settle. Under UK card scheme rules I have 120 days to file a chargeback for non-delivery. An e-wallet deposit weakens that leverage significantly; a crypto deposit essentially eliminates it. So the first-deposit rail choice is not about convenience, it is about preserving optionality if the review goes badly. I put that choice back into every subsequent test, regardless of whichever operator is being tested.

What I record from the deposit itself

Deposit timestamp, method, amount, and the on-site balance immediately after posting. Then a screenshot of the bank statement showing the debit, once it clears. If there is a mismatch between the amount displayed on-site and the amount debited (which is unusual but does happen with dynamic currency conversion), that goes in the review as a distinct concern. Everything after this point is measured against the deposit timestamp.

Playing through, and keeping the log

The playthrough phase serves two purposes. It gives the operator time to see me as a real active player rather than a bonus-hunter, and it lets me sense-check the game catalogue against advertised RTPs. I keep a simple written log of every session, and I do not deviate from it even when the temptation to test unusual game types is strong.

Note. I never chase losses during a review playthrough. Everything on this page has to be reproducible for a reader, which means I stay inside the playbook. That is the professional version of the same discipline every player benefits from.

The single game I default to

I test slots on Book of Dead by Play'n GO. It is the most-integrated title in the sector, it has a well-documented 94.25 percent RTP, and the volatility profile is predictable enough that a fifty-spin session lets me sense-check whether the site's return matches the stated number to within a reasonable margin. I bet at 40 pence per spin, which puts fifty spins at a twenty-pound turnover, and I run it two or three times over the deposit's lifetime.

What I record on each session

Session start balance, bet size, spin count, session end balance, and any bonus feature triggers. If the site offers a session summary in the player account (a genuinely useful RG feature), I screenshot it. This log is the raw material for the 'game catalogue and provider integration' section of the eventual review, and it is also my early-warning system if a site's actual RTP is drifting from the sticker.

The behaviour I watch for during play

Unexpected disconnects during a bonus round, session timeouts that void spins, autoplay controls that behave strangely, and any prompt to accept a mid-session bonus offer are all things I note. None of them are automatically red flags, but any one of them is worth mentioning in the eventual review. Good operators are boring in this phase; bad operators do something novel and unhelpful every fifty spins.

The proactive KYC step

One of the most useful review steps, and one of the ones I add against the common industry practice, is submitting KYC documents proactively before I request a withdrawal. It is the single most reliable way to expose late-stage friction that would otherwise sit hidden until the cashout stage.

What I submit and how

Passport (photo page), a utility bill or bank statement dated within the last three months for proof of address, and (increasingly) a selfie holding the passport for biometric verification. I submit all three through the operator's own KYC portal rather than by email attachment, so the audit trail sits with them and not with me. I log the timestamp of submission and every subsequent email or notification.

What operators do well at this stage

Good operators verify in under 24 hours, send an email confirmation, and mark the account as verified in the customer's own account dashboard. Very good operators offer a live verification service (an actual staffer looking at the documents while you are online), which cuts the process to minutes. Both patterns are more common on Malta-licenced and older Curacao-licenced operators than on newer Anjouan brands, but the pattern is not deterministic.

What operators do badly at this stage, and what it predicts

The behaviour I watch for is a KYC portal that quietly does not process the submission until a withdrawal is requested, followed by a demand for the same documents to be re-uploaded at that later stage. That pattern is a classic 'friction farm', and it strongly predicts a slow first payout. If I catch it during proactive KYC, the review will say so explicitly, because the reader deserves to know that the operator is banking on customers giving up mid-verification.

Requesting withdrawal and timing the wait

The withdrawal request is the review's key moment. Everything up to this point has been observation. This is the operator making a promise with real money in front of a real customer, and the way they perform in this window shapes the whole verdict.

close-up of a small stopwatch resting on a printed bank statement
The stopwatch is theatre, of course, but the point of it is real. I record every hour.

The full-balance withdrawal, not a partial

I always withdraw the whole balance. Partial withdrawals often route through a different flow than full ones, sometimes with different processing priorities, so a partial-only test misses information a real customer will experience. Full withdrawal, same bank card that the deposit came from, no bonus balance attached (I clear or forfeit any active bonus before the request), simple and clean.

What I record during the wait

Timestamp of request, any 'pending' state changes I can see in the account dashboard, every email received from the operator, and the exact time funds arrive in my bank. I convert everything to hours-from-request in the eventual review, and I compare it against the SLA the operator's terms and conditions state. A published 24-hour SLA that resolves in 22 hours is normal. A published 24-hour SLA that resolves in 60 hours is a review-level finding.

The second withdrawal, and what it tells me

After the first withdrawal completes I redeposit and cash out again a week later. The second withdrawal usually runs faster because the customer's payment route is now cached in the operator's payments system. If it runs slower, that is unusual and worth investigating, because it typically means the operator has tightened its payments risk stance in the intervening week (which is itself an operational signal worth reporting).

Frequently asked questions

Common questions about non gamstop casinos in the UK, answered plainly.

How long does the full review process take?

About three weeks end to end. One week to sign up, deposit, play, submit KYC, and request the first withdrawal. Then a week's wait to redeposit and cash out again. Then a week to write the review and cross-check every claim against the folder of receipts I have kept.

Do you accept payment from the operators you review?

No. If a review is paid, it is disclosed at the top of the page or it does not go up. My income comes from readers who back the column and from occasional consultancy for legal or compliance clients. Not from operator commissions.

Why do you use your real name and details?

Because falsified sign-up details invalidate the whole test at the KYC stage, and because I want to see the same experience a real customer would see. Fake accounts often get treated differently by risk systems, so a fake-account review is measuring the wrong thing.

Do you always take the welcome bonus?

No. I test both paths on most operators, because some readers want the bonus and some do not. If I only ran the bonus path, the review would over-represent bonus-related friction. If I only ran the no-bonus path, it would under-represent it.

What if the first withdrawal fails entirely?

Then the review says so, with the exact wording of the rejection and my correspondence with support. In practice this has happened three times in the last two years, and in every case the operator's licence footer had already given me pause. Complete non-payment is rare on properly licenced operators; slow payment is common.

Do you retest operators after publication?

Yes, roughly every eighteen months on a rolling schedule. Operators change quietly, and a review two years old is not necessarily still accurate. I mark the retest date at the top of every operator write-up so readers can see when they are looking at fresh information.

How much do the tests cost you personally?

Between fifty and two hundred pounds per operator, depending on whether I use a bonus path. I lose money on the tests in aggregate, which is fine, because the reviews are the product, not the play sessions. If I ever start winning on the tests overall, I would be suspicious of my own methodology.