Skip to content

Platform

Regulatory capability, delivered as infrastructure.

Our cloud-native regulatory infrastructure enables governments to launch fully operational regulatory authorities in months rather than years: designed for rapid deployment across multiple jurisdictions while maintaining the highest standards of security, compliance and operational efficiency.

Building a regulator from scratch is conventionally a multi-year capital programme. A jurisdiction has to draft legislation, procure and integrate systems, recruit supervisors who do not yet exist in the domestic labour market, and then discover through experience which parts of the design do not survive contact with real applicants. Regulation as a Service compresses that by supplying the operating capability as a configured service, leaving the government to do the part only a government can do: set policy and exercise sovereign authority.

TGMRC supplies and operates regulatory infrastructure. The sovereign authority remains the regulator.

What a regulator actually does

Licensing is the project. Supervision is the job.

A licensing round has an end date. Everything below runs every working day afterwards, for the life of the regime. Regimes fail far more often on this recurring load than on the quality of their founding legislation.

  • Assess applications against fit-and-proper, financial capacity and source-of-funds tests
  • Ingest and validate periodic returns from every licensed entity
  • Score and rank entities by risk, then allocate supervisory attention accordingly
  • Run examinations and investigations, and carry them through to enforcement
  • Maintain a public register that third parties can rely on
  • Handle consumer complaints and route them into supervision
  • Operate self-exclusion and player protection registers where the sector requires them
  • File and receive financial intelligence, domestically and across borders
  • Evidence all of the above to international assessors on request

Platform modules

Six systems that carry that load.

  1. LIC

    Licensing Administration

    Application intake, fit-and-proper, due diligence, issuance and renewals, with configurable regimes per sector.

    Licence types, conditions and fee schedules are configured per sector rather than hard-coded, so a jurisdiction can run remote gaming, virtual asset and payment regimes side by side without a separate system for each. The renewal cycle is treated as a first-class workflow, including surrender and revocation, because a regime that has no tested process for ending a licence discovers the gap at the worst possible moment.

  2. SUP

    Supervision & Case Management

    Risk-based supervision, examinations, investigations and enforcement workflows across regulated entities.

    Entities are scored against a configurable risk model that draws on reporting history, complaint volume, breach record and sector risk, so supervisory attention follows exposure rather than the alphabet. Examinations, investigations and enforcement run as linked cases with evidence, correspondence and decisions retained against the entity for the life of the licence.

  3. RPT

    Regulatory Reporting

    Structured returns, XBRL/JSON ingestion, validation and analytics for prudential and conduct data.

    Returns are validated on submission rather than on review, which is the difference between a regulator that finds a problem in days and one that finds it at the next annual assessment. Rejected submissions carry specific error locations so operators can correct and resubmit without a supervisory conversation.

  4. AML

    AML & Financial Integrity

    Sanctions screening, STR/SAR pipelines, travel-rule support and cross-border information sharing.

    Suspicious transaction and activity reporting runs on structured templates that map to FATF recommendations, so the evidence a mutual evaluation asks for exists as a by-product of normal operation rather than as a retrofit. Travel-rule message handling and counterparty checks are supported for jurisdictions supervising virtual asset service providers.

  5. PUB

    Public Register & Portal

    Bilingual public registers, consumer complaint channels and transparency dashboards.

    A working public register is the single clearest signal of a functioning regulator, and it is the first thing payment partners and international assessors check. Registers publish licence status, conditions and enforcement history, with consumer complaint intake routed straight into supervisory case management.

  6. OPS

    Managed Operations

    Trained supervisors, contact centres and 24/7 operational support running alongside the technology.

    Software does not supervise anyone. Managed operations put trained personnel behind the platform for jurisdictions building capability from a low base, with a defined transfer path as national staff are recruited and trained.

Deployment

From memorandum to live regulator: in months.

The sequence matters as much as the content. Applications should open early enough that a viable licensed market exists before unlicensed operation becomes an offence, or day one of the regime is also day one of an enforcement backlog.

  1. Phase 01Diagnostic & design

    Legislative gap analysis, sector scoping and regulatory architecture. This phase decides the perimeter: which activities require a licence, which are exempt, and where the boundary sits against neighbouring regimes. Getting the perimeter wrong is the most expensive error available, because every later decision inherits it.

  2. Phase 02Statutory drafting

    Primary and secondary legislation, licensing regimes and international benchmarking. Drafting is benchmarked against comparable jurisdictions so the resulting regime is recognisable to the banks, payment providers and international assessors who will judge it, rather than novel for its own sake.

  3. Phase 03Platform provisioning

    Tenant deployment, taxonomy configuration and integrations with government systems. Licence types, reporting schemas, risk models and fee schedules are configured to the drafted legislation, and connected to company registries, identity systems and payment infrastructure where those exist.

  4. Phase 04Operations go-live

    Personnel training, public register launch and first licensing rounds under supervision. The first cohort of applications is processed alongside trained supervisors so that the authority builds an operating record before it is left to run alone.

Architecture

Multi-jurisdiction by design, sovereign by default.

Each authority runs as its own tenant with its own data, its own configuration and its own users. Nothing is shared between jurisdictions except the underlying codebase, which is what allows a regime to be provisioned in weeks rather than procured over years. Supervisory data belongs to the authority that generates it.

Configuration rather than customisation is the operating principle. Licence types, conditions, reporting schemas, risk models, fee schedules and workflow states are all configured against the jurisdiction's own legislation. That keeps every tenant on the same maintained platform, so a security patch or a regulatory feature reaches every authority at once instead of forking into as many versions as there are clients.

Because the same infrastructure supports several regulated sectors, a jurisdiction can extend from one regime to the next without a second procurement. A gaming regulator that later takes on virtual asset supervision adds a configured licence type, not a new system.

Frequently asked

What governments ask before commissioning.

Want to see the model running? The Guinea-Bissau framework

How long does it take to launch a regulatory authority?

Months rather than years. The platform is deployed as a configured tenant rather than a bespoke build, so the critical path runs through legislation, institutional design and recruitment instead of software development. A typical programme moves through diagnostic and design, statutory drafting, platform provisioning and operations go-live, with the first licensing round conducted under supervision before the authority operates independently.

What is a Regulation-as-a-Service platform?

It is regulatory infrastructure delivered as an operating service rather than a capital project. A government gets the licensing, supervision, reporting, AML and public register systems a regulator needs, together with the trained personnel to run them, without procuring and integrating those systems itself. The jurisdiction retains sovereign authority over policy, rules and licensing decisions. TGMRC provides the capability those decisions are executed through.

Can one platform supervise several sectors at once?

Yes. Licence types, conditions, reporting schemas, risk models and fee schedules are configured per sector, so a single authority can supervise remote gaming, virtual asset service providers, payment institutions and prediction markets from one system. That matters most for smaller jurisdictions, where running a separate authority and separate technology stack for each sector is not affordable.

How does the platform support international assessment?

Mutual evaluations and international assessments increasingly grade effectiveness rather than the statute book, which means a regulator has to evidence that its rules changed behaviour. Reporting, case management and enforcement records are structured against the methodologies assessors apply, so evidence of supervisory activity accumulates continuously instead of being assembled after an assessment is scheduled.

Who owns the data and the regulatory decisions?

The jurisdiction. The authority holds its own supervisory data and makes its own licensing and enforcement decisions. TGMRC provides the technology, the operating capability and, where requested, trained personnel. The model is designed so that capability transfers to national staff over the life of the concession rather than creating permanent dependency.