Casino surveillance can be measured, but the easiest numbers are often the least useful. Counting how many incidents an operator “catches” rewards luck, assignment mix, and aggressive reporting more than judgment. Counting reports encourages unnecessary reports. Measuring only response time can produce fast but incomplete reviews.
A sound metric system asks a different question: Can surveillance reliably observe required activity, retrieve evidence, identify material risk, communicate accurate findings, and support the casino without losing independence?
No single score can answer that. Managers need a balanced set of system, workload, quality, timeliness, and outcome measures.
Begin with the department’s actual obligations
Before choosing metrics, define what surveillance is required to do under local law, the property’s surveillance plan, internal controls, and approved procedures. Depending on the jurisdiction and property, responsibilities may include:
- continuous or event-based coverage of specified gaming and cash areas;
- recording and retention;
- live observation;
- incident and dispute review;
- support for table games, slots, cage, count, security, and compliance;
- detection and escalation of suspicious or prohibited conduct;
- preservation and controlled release of video evidence;
- camera and system fault reporting;
- regulator and law-enforcement support;
- confidential report writing and case management.
A metric is valid only if it reflects an assigned responsibility. Surveillance should not be judged for activities the department is prohibited from performing or for business outcomes it does not control.
For the department structure, read surveillance department overview and surveillance manager role.
The balanced metric model
A practical surveillance scorecard can be divided into six families.
| Metric family | What it tests | Examples |
|---|---|---|
| Coverage and system health | Whether required observation and recording are available | Camera availability, recording failures, clock synchronization, retention compliance |
| Workload and capacity | Whether demand is visible and manageable | Review requests, live-monitoring hours, backlog, workload by priority |
| Timeliness | Whether urgent and routine work is completed within appropriate targets | Acknowledgement time, review turnaround, evidence export time |
| Quality and completeness | Whether conclusions and evidence are reliable | Report rework, missing attachments, incorrect timestamps, quality-review findings |
| Escalation usefulness | Whether material findings reach the right owner | Confirmed escalations, overdue notifications, unresolved high-risk findings |
| Improvement and resilience | Whether recurring weaknesses are being reduced | Repeat camera faults, repeated procedural findings, corrective-action closure, training completion |
The scorecard should not collapse all six into one “operator productivity” number. A department can be fast but inaccurate, technically healthy but overloaded, or productive on routine reviews while missing urgent risks.
Coverage availability is the first control
Surveillance cannot perform well when required cameras, recording, storage, or video-management functions are unavailable.
A useful measure is required-coverage availability:
[ \text{Required-coverage availability} = \frac{\text{Usable required camera-hours}}{\text{Required camera-hours}} \times 100% ]
Suppose 120 required cameras should record for 24 hours, producing 2,880 required camera-hours. Faults make 18 camera-hours unusable.
[ \frac{2{,}880 - 18}{2{,}880} \times 100% = 99.375% ]
The percentage is useful, but it must be paired with criticality. Losing one hour of a dedicated count-room camera may matter more than several hours from a low-risk overview camera. Reports should classify outages by area, duration, cause, and whether a compensating control existed.
Nevada’s current surveillance standards illustrate the range of regulated coverage areas, records, recording systems, and surveillance-system requirements. Other jurisdictions use different categories and retention periods.
System-health metrics may include:
- required cameras unavailable;
- recording gaps;
- storage or retention exceptions;
- video-management-system alarms;
- failed evidence exports;
- time synchronization errors;
- repeated faults by camera, encoder, switch, or recorder;
- mean time to acknowledge and repair critical faults.
A high availability percentage should never hide a recurring failure in the same high-risk area.
Workload must be normalized by type and difficulty
Ten five-minute lookups are not equal to ten complex table-game investigations. Workload reporting should separate at least:
- urgent live support;
- patron disputes;
- gaming-procedure reviews;
- cash and count reviews;
- security incidents;
- employee investigations;
- regulator or law-enforcement requests;
- proactive observation;
- quality assurance;
- evidence export and retention work.
The manager can then see whether backlog comes from volume, complexity, staffing, system limitations, or poor request quality.
Raw case counts should be normalized by operating exposure where useful. Examples include reviews per 1,000 gaming hours, incidents per 10,000 transactions, or report hours per open table hour. The denominator should fit the activity; one denominator for the whole department creates false comparisons.
Use median turnaround, not only average turnaround
A few very long investigations can distort the average. The median shows the middle completion time and is often a better description of routine service.
A useful report might show:
| Priority | Target | Median | 90th percentile | Oldest open item |
|---|---|---|---|---|
| Immediate live risk | 5 minutes to acknowledgement | 2 minutes | 4 minutes | Not applicable |
| High-priority incident review | 2 hours | 48 minutes | 1 hour 35 minutes | 2 hours 10 minutes |
| Routine video request | 24 hours | 6 hours | 18 hours | 31 hours |
| Historical research | 3 business days | 1.6 days | 2.8 days | 4.2 days |
These are illustrative targets, not industry standards. Each property must set targets based on law, risk, operating hours, staffing, and service commitments.
Turnaround should be measured from a defined start point. If the clock starts before the request contains a valid time, location, and incident description, the metric measures request quality as much as surveillance performance.
Backlog aging reveals risk better than total backlog
A department with 40 new routine requests may be healthy. A department with five high-risk reviews open beyond their required notification window may not be.
Group open work by priority and age:
- not yet due;
- due within the current shift;
- overdue by less than one day;
- overdue by one to three days;
- overdue more than three days;
- held for an identified external dependency.
The manager should review the oldest and highest-risk items individually. A backlog chart is not a substitute for case ownership.
Report quality can be measured without rewarding silence
Quality review should examine whether a report is accurate, supported, and usable. Possible criteria include:
- correct date, time, location, game, terminal, and people identifiers;
- clear distinction between observation and inference;
- complete event sequence;
- relevant camera references;
- preserved evidence identifiers;
- correct amounts and calculations;
- neutral language;
- correct escalation and distribution;
- no unsupported accusation;
- compliance with confidentiality and retention rules.
One measure is the material rework rate:
[ \text{Material rework rate} = \frac{\text{Reports returned for material correction}}{\text{Reports quality-reviewed}} \times 100% ]
If 80 reports are sampled and six require correction because the amount, event sequence, or conclusion is materially wrong:
[ \frac{6}{80} \times 100% = 7.5% ]
Minor formatting edits should not be counted as material rework. The manager should classify the error so training addresses the real weakness.
For report standards, read surveillance report writing.
Evidence retrieval is a separate capability
A well-written report is not enough if the supporting video cannot be found, exported, verified, or played.
Evidence metrics can include:
- successful retrieval on first attempt;
- export completion within target;
- checksum or integrity-verification success where used;
- correct labeling and case association;
- release authorization completed;
- chain-of-custody documentation complete;
- failed playback or incompatible format incidents;
- evidence requests rejected because of missing authority.
The current federal minimum internal-control framework for some tribal gaming operations includes surveillance controls and record requirements in the eCFR Part 543 standards. Properties should follow the rules that apply to their own jurisdiction and gaming class.
Escalation metrics require careful interpretation
An escalation is useful when surveillance identifies a material issue, sends it to the correct owner, and provides enough evidence for action. Counting escalations alone encourages over-reporting. A very low count can also indicate under-reporting.
A cautious metric is confirmed escalation yield:
[ \text{Confirmed escalation yield} = \frac{\text{Escalations confirmed as actionable}}{\text{Escalations reviewed}} \times 100% ]
Suppose 50 escalations are reviewed and 38 lead to a verified operational, security, compliance, or investigative action.
[ \frac{38}{50} \times 100% = 76% ]
The remaining 24% are not automatically mistakes. Some good-faith alerts will be resolved as normal activity. The measure should be reviewed by category, severity, and information available at the time.
Do not use this number to punish operators for escalating uncertain high-risk situations. The cost of missing a serious event may justify a lower yield in selected categories.
Missed-event review is more informative than blame
When another department discovers an event that surveillance did not identify, management should ask:
- Was surveillance expected to observe it live?
- Was the area covered and the image usable?
- Was the operator assigned to conflicting priorities?
- Did an alert or request fail to reach the room?
- Was the conduct visually detectable?
- Did the procedure define an escalation threshold?
- Was the event found later through routine review?
Classify the cause: coverage, technology, staffing, workload, training, procedure, communication, or reasonable non-detection. This creates improvement data without pretending that every visible event can be caught live.
Individual operator rankings are risky
Ranking operators by catches, reports, or reviewed hours can damage the department.
Assignments are not equal. An operator covering high-limit baccarat has different exposure from an operator reviewing a quiet corridor. Some excellent work prevents loss quietly through accurate verification; other work produces a dramatic case. Operators may avoid helping colleagues if assistance reduces their personal numbers.
Individual performance review should combine:
- competency checks;
- report quality;
- correct escalation;
- evidence handling;
- policy compliance;
- communication;
- training and calibration results;
- observed decision-making;
- reliability and confidentiality.
Metrics can support coaching, but they should not replace supervisory judgment.
Quality calibration keeps reviewers consistent
Managers and quality reviewers should periodically examine the same sample cases and compare decisions. Calibration asks whether reviewers agree on:
- incident classification;
- severity;
- required escalation;
- report sufficiency;
- evidence retention;
- closure status.
Large differences may mean the policy is unclear rather than that one person is wrong. Record the agreed interpretation and update examples used in training.
Build a metric dictionary before building a dashboard
Many surveillance reports fail because two people calculate the same label differently. A metric dictionary should define:
- the exact numerator and denominator;
- the systems or logs used as sources;
- the time zone and business-day cutoff;
- which cases are included or excluded;
- the owner responsible for data quality;
- the reporting frequency;
- the target or warning threshold;
- the action required when the threshold is crossed.
For example, “review turnaround” might begin when a complete request reaches the surveillance queue and end when the approved report is released. If one shift starts the clock at the incident time and another starts at assignment time, the monthly comparison is not valid.
Version the definition when the process changes. A new case-management system, a different priority model, or a longer retention rule can alter the metric even when performance is unchanged.
Alert tuning should be measured as controlled change
Surveillance may receive alerts from access control, slot systems, table systems, exception reports, analytics, or security devices. An alert that fires constantly without useful differentiation creates alarm fatigue.
For each automated alert, track:
- alert volume;
- duplicate or repeated alerts;
- acknowledged alerts;
- alerts requiring investigation;
- confirmed actionable findings;
- false or non-actionable causes;
- time spent per alert;
- rule or threshold changes;
- performance after tuning.
A rule should not be changed merely to make the dashboard look better. The change should be approved, tested, documented, and reviewed for missed risk. Read exception reporting systems for the difference between a control trigger and proof of wrongdoing.
Separate departmental health from case outcomes
Some outcomes depend on other departments or outside authorities. Surveillance may complete an accurate review, preserve evidence, and escalate correctly, yet management may decide that no discipline, reimbursement, exclusion, or police referral is appropriate.
The department should therefore be measured on the quality and timeliness of its work, not on whether another decision-maker produces a dramatic result. Useful closure categories include:
- evidence confirmed and action taken;
- evidence confirmed, informational only;
- allegation not supported by available evidence;
- insufficient evidence;
- referred to another department or authority;
- duplicate or invalid request;
- open pending an identified dependency.
This classification makes outcomes visible without pressuring surveillance to overstate findings.
Review metrics after major incidents
A serious incident is a test of the measurement system. Afterward, ask whether the existing scorecard would have shown the underlying weakness before the event.
If a critical camera failed repeatedly but monthly availability remained green, the metric may be too aggregated. If a report was technically on time but omitted the decisive sequence, the quality review may be too superficial. If an operator faced five simultaneous urgent requests, workload reporting may not capture concurrency.
Metrics should evolve when they fail to describe the real operational risk. The dashboard is a control tool, not a permanent set of decorative numbers.
A monthly management scorecard
A concise monthly view might contain:
- System readiness: required coverage availability, critical outages, retention exceptions.
- Demand: cases received by category and priority, live-support requests, proactive reviews.
- Timeliness: median and 90th-percentile turnaround, overdue high-priority work.
- Quality: material rework, evidence retrieval failures, calibration findings.
- Risk: major escalations, missed events, repeat control findings.
- People: staffing coverage, overtime, training completion, vacancies.
- Improvement: overdue corrective actions, repeated technology faults, policy changes.
The narrative should explain the movement. “Turnaround worsened from six to eleven hours because two investigators were reassigned to a major case; no high-priority item exceeded target” is more useful than a red indicator alone.
Metrics that should trigger caution
Be skeptical of these measures when they are presented without context:
- total incidents caught;
- total reports written;
- total hours watched;
- percentage of operators with no errors;
- average review time across all case types;
- loss prevented estimates with no documented method;
- surveillance contribution to casino win;
- arrests or terminations attributed to the department;
- a single composite productivity score.
They may describe activity, but they do not reliably measure quality or integrity.
The purpose is operational confidence
Surveillance metrics should help management answer practical questions:
- Is required coverage working?
- Can the department meet urgent demand?
- Are reports and evidence dependable?
- Are high-risk findings reaching decision-makers?
- Are backlogs and repeated faults visible?
- Is staffing appropriate to the property’s risk and operating volume?
- Are procedures improving after incidents?
The best scorecard does not make surveillance look busy. It makes the department’s reliability, limitations, and unresolved risks visible.