Chips & Truths No spin. Just the math.
Home/Back of House/Casino Operations & Management/BOH 113: Exception Reporting

BOH 113: Exception Reporting

Exception reporting is the management process for turning deviations and unusual activity into owned, evidence-based review, corrective action, and verified closure.

A casino exception report says that an event, record, sequence, or pattern fell outside an approved expectation. It does not say that fraud, cheating, or misconduct occurred. Its purpose is to create a controlled review before the deviation disappears into daily volume.

That distinction protects both the casino and its staff. If every alert becomes an accusation, employees hide errors and managers drown in conflict. If deviations are ignored because the shift eventually balanced, repeated control failures remain invisible.

This page explains the management process: classification, ownership, investigation, escalation, correction, and closure. Exception Reporting Systems covers the technology that generates and routes many of those alerts.

Begin with the expected control

An exception only has meaning in relation to an expectation. The report should identify the rule, limit, sequence, or baseline that was not met.

Examples include:

  • a cage transaction missing required approval;
  • a table fill or credit recorded in the wrong sequence;
  • a jackpot record that does not match machine or cage data;
  • a manual comp above the employee’s authority;
  • repeated player-rating changes after a shift closes;
  • access to a restricted system outside an assigned role;
  • a count variance outside the property’s review threshold;
  • a required document or identification step not completed;
  • several individually small events forming an unusual pattern.

“Unusual” is not enough. A useful exception states what was expected, what was observed, when it happened, how the report knows, and which department owns the first review.

Different exceptions require different treatment

ClassTypical exampleFirst ownerMain objective
DocumentationMissing signature or reason codeOperating supervisorComplete and verify the record
ReconciliationCash, chip, ticket, meter, or inventory mismatchCage, accounting, count, or slotsLocate the source and correct accountability
AuthorityComp, adjustment, void, or access outside limitDepartment managerConfirm approval and prevent unauthorized action
SequenceRequired step happened late or out of orderProcess ownerDetermine whether the control still operated
PatternRepeated small events or concentrated activityAudit, compliance, surveillance, or managementTest whether events are related
RegulatoryTrigger affecting reporting, identification, exclusion, or recordsComplianceFollow jurisdiction-specific obligations
Safety or conductEvent requiring immediate physical responseSecurity or shift managementStabilize first; document separately
Data qualityDuplicate, delayed, missing, or mismatched system recordsSystem owner and business ownerRestore reliable information

A report may move between classes as facts develop. A missing approval can be a harmless clerical failure, a training problem, or part of unauthorized activity. The reviewer should not decide which one before examining evidence.

The operational lifecycle

1. Detect and preserve

The exception may come from a system rule, reconciliation, audit sample, supervisor observation, surveillance review, complaint, or employee report. Preserve the source record before it can be overwritten or corrected without trace.

The initial record should include:

  • unique exception number;
  • date and synchronized time;
  • property, department, area, table, machine, window, or system;
  • transaction or event identifiers;
  • rule or threshold that generated the item;
  • amount or exposure where relevant;
  • people and accounts involved;
  • source records or footage references;
  • immediate action already taken.

2. Triage by risk and urgency

Priority should consider more than dollar amount. A small event may require rapid escalation if it affects regulatory reporting, exclusion, personal safety, data integrity, or a control that remains open. A large variance may be lower risk after records show a timing difference already contained.

A practical triage asks:

  1. Is money, game integrity, safety, or regulated information still exposed?
  2. Can the activity continue or repeat before review?
  3. Is evidence at risk of being lost?
  4. Does policy require immediate notification?
  5. Could the issue affect more than one transaction, employee, player, or system?

3. Assign one accountable owner

Several departments may assist, but one role must own the next action. “Sent to management” is not ownership. The exception should show who is responsible, the due time, and the escalation path if the deadline is missed.

The first owner is not necessarily the final investigator. A slot supervisor may verify a machine event before accounting reconciles payment records. Compliance may restrict access to a sensitive review while requesting facts from cage, surveillance, or player development.

4. Reconstruct the event

The reviewer should build a timeline from independent records where possible. Depending on the case, that may include:

  • transaction logs and audit trails;
  • table or machine records;
  • cage and count documentation;
  • player ratings and account history;
  • access-control records;
  • approvals and authority limits;
  • staff statements;
  • surveillance references;
  • system-health and interface logs;
  • related exceptions from earlier shifts.

Corrections should not destroy the original state. The operation needs to know both what happened and how it was repaired.

5. Decide the disposition

A controlled set of closure codes makes trend analysis possible. Examples include:

  • valid activity, sufficiently explained;
  • clerical error corrected;
  • training or procedure issue;
  • system or interface defect;
  • policy exception properly approved;
  • duplicate or false alert;
  • control breach requiring corrective action;
  • referred to compliance, surveillance, HR, legal, regulator, or law enforcement;
  • open pending external information.

“Reviewed” is not a disposition. It describes an activity, not an outcome.

6. Verify corrective action

A manager may assign retraining, configuration change, procedure revision, access removal, reconciliation, or follow-up audit. Closure should require evidence that the action occurred and worked. Otherwise the exception was administratively closed while the cause remained.

Measures that keep the process honest

The goal is not to drive the number of exceptions to zero. Zero may mean perfect control, but it can also mean weak detection or staff reluctance to report.

Exception rate

[ \text{Exception Rate} = \frac{X}{V} \times 1{,}000 ]

where (X) is the number of exceptions and (V) is a relevant volume such as transactions, jackpots, ratings, or operating hours. Multiplying by 1,000 creates a comparable rate.

If a cage records 18 exceptions across 12,000 reviewed transactions:

[ \frac{18}{12{,}000} \times 1{,}000 = 1.5 ]

The result is 1.5 exceptions per 1,000 transactions. It does not show severity or cause; the categories still matter.

Actionable yield

[ \text{Actionable Yield} = \frac{A}{R} \times 100% ]

where (A) is reviewed exceptions requiring correction, escalation, or control action and (R) is all exceptions reviewed.

If 24 of 160 alerts require action, the yield is 15%. A very low yield may indicate noisy thresholds. A very high yield may mean the rules are too narrow and missing early warnings.

Aging and closure

Median age is often more useful than average age because a few very old cases can distort the average. Management should also track the oldest open item by risk class, not just overall closure percentage.

A department that closes easy documentation items while leaving one serious access-control issue open should not appear healthy because its closure rate is high.

Example: repeated manual rating adjustments

A weekly report shows that one pit has more post-shift rating changes than comparable areas.

The wrong response is to assume the supervisor is inflating player value. The first review asks:

  • Were ratings delayed because the pit was unusually busy?
  • Did the player-tracking system have an outage?
  • Are edits concentrated around one game, shift, or employee?
  • Do table activity and surveillance records support the adjustments?
  • Were reason codes and approvals complete?
  • Did the changes affect comps or offers already issued?

The outcome might be a system problem, a staffing issue, poor training, legitimate correction, or deliberate manipulation. The exception process is valuable because it preserves those possibilities until evidence narrows them.

Regulatory and AML exceptions need restricted handling

Some casino exceptions relate to financial-crime monitoring, customer identification, recordkeeping, or suspicious activity. These are not ordinary operational reports. Access, wording, retention, and disclosure may be restricted by law and policy.

FinCEN states that casinos must use procedures reasonably designed to detect and properly report suspicious transactions, and its casino recordkeeping and reporting FAQ specifically discusses the use of automated systems to aid BSA compliance. That U.S. guidance is jurisdiction-specific, but the operational lesson is broader: automated alerts require trained review, supporting documentation, and controlled escalation.

Internal-control requirements also vary. Nevada’s Minimum Internal Control Standards are one example of a formal control framework covering gaming processes and documentation. A property must apply the requirements of its own regulator and approved internal controls rather than copy another jurisdiction’s thresholds.

Staff should never place restricted case details in a general shift chat or broad distribution list. The operating department may receive a request for facts without being told whether a suspicious-activity filing is being considered or made.

How exception reporting becomes harmful

A badly managed process creates several predictable failures.

Alert fatigue

Thresholds generate so many low-value items that reviewers close them mechanically. Real risk hides in the queue.

Blame culture

Employees believe every self-reported mistake will be punished. They delay or disguise corrections, which makes the evidence worse.

Dollar-only prioritization

Large amounts receive attention while repeated small control failures are ignored.

Unexplained overrides

Managers suppress alerts to keep reports clean. The system records fewer exceptions but the operation becomes less transparent.

Closure without learning

The individual item is fixed, yet no one asks whether the procedure, staffing, interface, or authority design caused it.

Combining incompatible data

Events from different time zones, business dates, player identities, or machine identifiers are compared as though they align. The report looks precise but is false.

The manager’s review rhythm

Daily review should focus on urgent open exposure, overdue high-risk items, failed handoffs, and exceptions requiring action before the next shift.

Weekly review should examine patterns:

  • repeated exception types;
  • concentration by area, shift, system, or process;
  • false-alert sources;
  • unresolved root causes;
  • recurring manual overrides;
  • actions assigned but not verified;
  • changes after a threshold or software update.

Monthly or quarterly governance should decide whether rules, authority limits, staffing, training, or system interfaces need change. It should also sample closed items to confirm that the recorded disposition matches the evidence.

What a good exception report allows someone to do

A manager who did not work the original shift should be able to answer:

  • What expectation failed?
  • What exactly happened?
  • Which records support that statement?
  • What remains uncertain?
  • Who owns the next step?
  • Was any exposure contained?
  • What decision was made?
  • What corrective action occurred?
  • Who verified closure?
  • Does this connect to earlier items?

If the report cannot support those questions, it is probably a notification, not a completed control record.

Exception reporting works when it turns abnormal activity into fair, proportionate, evidence-based management. It fails when alerts are treated as guilt, reports are produced without owners, or closure becomes a box-ticking exercise.

Continue with Internal Audits in Casinos, Incident Reporting, Data Quality in Casinos, and Casino Control Room Logic.

Play smart. Gambling involves real financial risk. If the game stops being entertainment, it's time to stop playing.