The Readiness Framework: A Sweepstakes Compliance Standard

Seven sections. What an operator in the sweepstakes market must be able to demonstrate, and how to demonstrate it. Published in full, because a framework kept behind a contact form is a lead magnet, not a standard.

Why publish it

A compliance framework’s value is not in its secrecy. Any competent practitioner could reconstruct these seven sections from the statutes in a fortnight. The value is in the implementation, and the implementation is where operators are failing — not because the requirements are unknown, but because meeting them costs product revenue and nobody has been forced to yet.

Flickloot exists as the proof that a platform can meet all seven and still be worth playing.

Complete

1. State access matrix

A live, statute-linked map of every jurisdiction, distinguishing statutory bans from enforcement states — because an operator tracking bills alone will log West Virginia, Michigan and Minnesota as open markets, and all three are closed. Includes the operative test each statute applies, so that a product change can be assessed against the text rather than against a summary.

See the tracker

Complete

2. AMOE and promotional-rules checklist

Alternative method of entry, official rules, prize registration and bonding thresholds, disclosure placement, and the drafting errors that convert a lawful promotion into an unlawful lottery. Most sweeps operators inherited their AMOE language from a template and have never had it read against the statute of a single state.

In build

3. Redemption KYC and AML

Where identification must occur, what an operator is obliged to hold and for how long, transaction monitoring calibrated to the sweeps model rather than borrowed from a casino, and the suspicious-activity thresholds that apply to a business that insists it is not a gambling business.

In build

4. Responsible gaming against the SPGA code

The industry’s own code of conduct, read as a compliance baseline, with the gaps between what it says and what member sites actually implement. A self-regulatory code an operator fails to meet is a document a plaintiff will introduce as evidence.

In build

5. Processor and ad-platform survival

Payment processing and advertising access are the two chokepoints where the sweeps model dies quietly, and they answer to card-scheme rules and platform policy rather than to state law. New York and California both extended statutory liability to processors and affiliates directly.

In build

6. Security baseline

Access control, credential handling, session management, data-retention discipline. The unglamorous half. It is also the half that produces the breach that ends the company, and it is the audit that gets bought first because it can be scoped in a week.

Complete

7. US model compliance

The three elements — consideration, chance, prize — and where each state’s statute attaches. Includes the design space that survives every ban currently in force, evidenced by the fact that this framework’s author built a working platform inside it and published the source.

See the implementation

How this framework is used

As a scoring instrument. An operator is assessed section by section against public signals first — terms of service, promotional rules, geolocation behaviour, disclosure practice, payment flows — and then, under engagement, against the systems themselves. The output is a gap list with an implementation sequence, not a report.

Advisory work produces a document. Implementation work produces a change to the product. Only one of those survives a regulator’s question.

Last updated: 13 July 2026. Compliance reference, not legal advice.