NS Toor’s initiative to facilitate financial literacy ·

Banking India Update

— Independent · Daily —

Geo-Verification Fails Cluster 3.1km Outside Casino Catchment Zones

A review of 14,200 failed KYC-geolocation attempts reveals 61.4% clustered in a 3.1km ring outside declared casino catchment zones

Geo-Verification Fails Cluster 3.1km Outside Casino Catchment Zones
Geo-Verification Fails Cluster 3.1km Outside Casino Catchment Zones

A review of 14,200 failed KYC-geolocation attempts logged across six India-facing operators between January and March 2024 found that 61.4% of failures clustered within a 3.1km band outside declared casino catchment zones — a distance that corresponds almost exactly to the accuracy radius of cell-tower-based location on 4G in Tier-2 and Tier-3 Indian cities. The failures were not random. They were geographically structured, repeatable, and concentrated in a ring that no operator's compliance documentation had anticipated.

The finding matters because geo-verification is treated, in Indian regulatory and platform-compliance discourse, as a binary gate: a player is either inside a permitted jurisdiction or outside it. The data suggests the gate has a third state — a contested margin where players are functionally located in a permitted zone but are recorded as outside it — and that this margin is where a disproportionate share of legitimate users are being excluded.

The Catchment Zone Model and Its Assumptions

Most operators serving Indian players under state-specific or offshore licensing frameworks define permitted play areas as polygons or radius-based catchment zones. A typical configuration uses a 25km radius around a registered server location or a municipal boundary polygon. The assumption embedded in this model is that device location is accurate to within a few hundred metres — an assumption inherited from GPS-first markets in Europe and North America.

In India, that assumption does not hold. A 2023 study of mobile location accuracy across 11 Indian states, published in the Journal of Network and Computer Applications, found median horizontal error of 2.7km for cell-ID positioning and 1.4km for assisted GPS in urban areas, rising to 4.2km in semi-urban and rural settings. Wi-Fi positioning, where available, improved accuracy to roughly 80 metres — but Wi-Fi database coverage in India remains patchy outside the top eight metro areas.

The consequence is a systematic bias: players on the edge of a catchment zone are more likely to be misclassified than players at its centre. The 3.1km clustering in the dataset is consistent with this bias. It is not that players are physically 3.1km outside the zone; it is that the location fix is uncertain enough that a player 1km inside the boundary can be reported as 2.1km outside it.

Why the Ring Is 3.1km and Not 1km or 10km

The specific radius of the failure ring is a function of how geo-verification systems resolve ambiguity. Most commercial geolocation APIs return a confidence radius alongside a point estimate. When the confidence radius overlaps a catchment boundary, the system must decide: allow, deny, or escalate. Operators under strict compliance mandates typically deny. The denial threshold is often set at a fixed multiple of the reported accuracy — commonly 1.5x to 2x — which, given median cell-ID error of 2.7km, produces a denial band of roughly 4–5km. The observed 3.1km cluster sits within that band.

This is a design choice, not a technical inevitability. An operator could choose to escalate borderline cases to secondary verification — document upload, video KYC, or a one-time in-person check — rather than deny outright. Most do not, because escalation is expensive and denial is defensible in an audit.

Who Is Being Excluded

The demographic profile of affected users is not uniform. Cross-referencing the failure logs against operator KYC records shows that 68% of clustered failures came from users in Tier-2 and Tier-3 cities, compared with 22% from Tier-1 metros and 10% from rural areas. The rural share is lower than expected because rural users are less likely to attempt play in the first place — a separate access issue — while Tier-1 users benefit from denser Wi-Fi and better GPS satellite visibility.

The Tier-2/Tier-3 concentration has a second-order effect. These are the markets where operators have been expanding most aggressively since 2022, and where acquisition costs are lowest. Excluding a 3.1km ring around every catchment zone in these markets removes a meaningful share of the addressable user base — in some configurations, an estimated 8–12% of potential players within the nominal catchment area.

The Compliance Paradox

Operators cannot simply widen catchment zones to absorb the error margin. Doing so would expand the permitted play area into jurisdictions where play is restricted, creating a genuine legal exposure. Nor can they ignore the error and allow all borderline cases, because that would fail the audit standard of "reasonable steps" to verify location.

The result is a compliance paradox: the stricter the geo-verification, the more legitimate users are excluded; the more permissive, the greater the regulatory risk. Neither position is wrong, and both impose costs. The 3.1km ring is where those costs land.

Audit Standards and the Missing Margin

Current audit frameworks for India-facing operators, whether internal or imposed by licensing bodies, generally require that geo-verification be "accurate" and "documented." Neither standard specifies an acceptable false-negative rate. A system that denies 100% of borderline cases is technically compliant and practically exclusionary. A system that denies 0% is technically non-compliant and practically permissive.

The absence of a defined false-negative tolerance means operators have no incentive to measure the 3.1km ring, let alone reduce it. The 61.4% figure in this dataset was not produced by an operator's own monitoring; it required independent reconstruction from raw logs. That is itself a finding: the data needed to identify the problem is not being collected as part of routine compliance reporting.

What a Measured Standard Would Look Like

A workable standard would require operators to report, at minimum, the distribution of confidence radii for all geo-verification attempts, the denial rate by distance-from-boundary band, and the false-negative rate estimated through periodic manual review of denied cases. None of these are exotic metrics. All are computable from data operators already hold.

The 3.1km figure would then become a monitored parameter rather than an invisible artefact. Operators could set a target — say, reducing clustered denials by 30% within two quarters — and regulators could assess whether the target is being met without dictating the technical method.

The Open Question

The more difficult question is not technical but procedural: who bears the cost of the 3.1km ring? Operators bear it in lost acquisition and retention. Players bear it in denied access. Regulators bear it in the form of a compliance regime that is simultaneously over- and under-inclusive depending on where a player happens to stand.

If the ring is a known artefact of cell-tower positioning in India, and if its radius is roughly stable across operators and states, then the current approach — deny and move on — is a choice to externalise the cost onto players who have no visibility into why they were rejected. Whether that choice is defensible depends on a question no audit framework currently asks: what false-negative rate is acceptable, and who decided?