Regulatory Updates
Probability-Based Items

[In-Depth Analysis] How GRAC Investigates Suspected False Probability Disclosures

TheGameAgent Team
July 13, 2026
5 min read

The Game Rating and Administration Committee (GRAC) has strengthened its ability to investigate reports that disclosed probability information may not match the probabilities actually applied within a game.

Many developers assume that their probability settings are accurate because the values were verified before launch. However, a compliance review may examine not only the configured probability, but also the disclosed tables, server logs, change history, and actual transaction data.

The five-stage framework below summarizes the investigation process publicly described by Korean authorities. The exact procedure may vary depending on the evidence, technical complexity, and nature of the suspected violation.

How GRAC Reviews Suspected False Probability Disclosures

Stage 1: Report Reception and Preliminary Screening

A case may begin through a user report, regulatory monitoring, or another source indicating that the disclosed probability may be inaccurate.

GRAC initially examines whether the report contains a sufficiently objective basis for further review.

Relevant information may include:

  • The name of the game and probability-based product
  • The applicable event or purchase period
  • The number of attempts made by the user
  • The rewards actually obtained
  • Screenshots of the disclosed probability
  • Purchase records or other supporting evidence

A low acquisition rate by itself does not automatically establish that a probability is false. GRAC first considers whether the available information provides a reasonable basis for additional verification.

Stage 2: Decision on Whether to Proceed with an Investigation

After the preliminary review, GRAC determines whether further investigation is necessary.

If there is no objective basis for suspicion, the case may be closed or the complainant may be asked to provide additional information.

If further verification is warranted, GRAC may request relevant materials from the game developer. Depending on the case, these materials may include:

  • Probability configuration data
  • Server or transaction logs
  • User-specific draw records
  • Probability change history
  • Internal probability tables
  • Update and deployment records
  • Public disclosure pages and notices

The scope of the request will depend on the suspected discrepancy and the structure of the probability system.

Stage 3: Technical Verification and Expert Analysis

Where technical verification is required, GRAC may analyze the submitted data and obtain assistance from an external statistical or technical analysis institution.

The analysis may compare:

  • The probability publicly disclosed to users
  • The probability configured in the game system
  • The probability reflected in transaction or draw logs
  • The probability applicable under user-specific conditions
  • Changes made during events, updates, or maintenance periods

This process is particularly important for systems involving pity mechanics, dynamic weighting, multi-stage rewards, limited pools, or probability changes based on previous outcomes.

An external analysis does not rely solely on the developer’s explanation. The relevant data may be statistically reviewed to determine whether the actual results and system configuration are consistent with the disclosed probability.

Stage 4: Assessment of a Possible Probability Discrepancy

After reviewing the available evidence and technical analysis, the authorities assess whether a disclosure violation may have occurred.

The findings may involve different types of issues, including:

  • Required probability information was not disclosed.
  • Individual item probabilities were omitted.
  • The disclosed probability did not match the system configuration.
  • The probability applied during a specific period differed from the published information.
  • Changes to the probability were not properly communicated.
  • User-specific or dynamic probability conditions were omitted.

Where a violation of Korea’s probability disclosure requirements is identified, corrective procedures under the Game Industry Promotion Act may follow. These can include a corrective request, corrective recommendation, or corrective order, depending on the circumstances and whether the developer implements the required changes.

If there are indications that consumers were misled by false or deceptive probability information, the matter may also be reviewed for referral to the Korea Fair Trade Commission (KFTC).

Stage 5: Regulatory Coordination and User Damage Relief

Referral to the KFTC and user damage-relief proceedings are not automatic in every case.

Depending on the nature and seriousness of the suspected conduct, the Ministry of Culture, Sports and Tourism or GRAC may coordinate with the KFTC or another competent authority.

The KFTC may independently assess whether the conduct violates the Act on the Consumer Protection in Electronic Commerce or other applicable consumer-protection laws. GRAC’s technical findings can provide relevant information, but the KFTC makes its own decision regarding investigation and enforcement.

When a user has suffered financial damage from a missing or false probability disclosure, GRAC’s Probability-Based Item Damage Relief Center may also review the claim.

Depending on the case, the user may receive:

  • Guidance concerning the available relief procedure
  • A factual investigation of the reported damage
  • A proposed relief or settlement process
  • Referral to the Content Dispute Resolution Committee
  • Information regarding available civil remedies

The regulatory investigation and user-relief process may be connected, but they remain legally distinct procedures.

Why Expert Analysis Matters

The most significant part of the investigation process is the ability to compare multiple sources of technical data.

A probability shown correctly on a website does not establish compliance if a different value was applied by the server. Likewise, a correctly configured server value may not prevent a violation if the value displayed to users was missing, outdated, or incorrectly calculated.

Technical analysis may identify discrepancies between:

  • Server configuration and public disclosures
  • Korean and global disclosure pages
  • In-game UI and official website tables
  • Pre-update and post-update probabilities
  • Base probabilities and user-specific probabilities
  • Internal spreadsheets and production data

The issue is therefore not limited to whether the probability algorithm was intentionally manipulated. An implementation mistake, delayed webpage update, localization error, or incorrect decimal calculation may also create compliance exposure.

The Legal Significance of a KFTC Referral

A KFTC referral does not mean that a violation has already been finally established. The KFTC conducts its own review under the laws within its jurisdiction.

However, false or misleading probability information may expose a developer to risks beyond GRAC’s corrective procedures.

Depending on the facts, these risks may include:

  • A KFTC investigation
  • Corrective orders
  • Administrative fines or surcharges
  • Consumer refund or compensation claims
  • Civil liability under the Game Industry Promotion Act
  • Reputational and platform-distribution risks

Korean authorities have previously applied the Electronic Commerce Act to cases involving probability information that was falsely disclosed or omitted in a manner that could mislead consumers.

Audit Readiness: What Developers Should Prepare

Developers should be able to demonstrate how each publicly disclosed value was generated and confirm that it matched the probability actually applied during the relevant service period.

1. Establish a Single Source of Truth

Server configuration, in-game UI, official website tables, and regulatory materials should use the same verified probability data.

Avoid manually entering the same values into multiple systems whenever possible.

2. Preserve Version and Change Records

Maintain records showing:

  • When a probability was created or changed
  • The value before and after the change
  • Who approved the change
  • When the change was deployed
  • When the related user notice was published

These records should make it possible to reconstruct the probability applied on a specific date.

3. Retain Sufficient Transaction and Draw Logs

Logs should allow the relevant probability event to be identified and reviewed.

Depending on the system, this may require recording:

  • Product or pool identifiers
  • Transaction timestamps
  • Applicable probability-table versions
  • User-specific state or pity counters
  • Rewards obtained
  • Reset or guarantee conditions

The appropriate retention period and data scope should be reviewed with technical, privacy, and legal teams.

4. Test Conditional Probability Systems

Pity systems, escalating rates, limited pools, and multi-stage reward structures require additional verification.

Testing should confirm that:

  • The disclosed base probability is accurate.
  • Probability changes occur under the disclosed conditions.
  • Guaranteed rewards activate at the correct threshold.
  • Reset conditions operate as described.
  • Every stage and obtainable outcome is properly disclosed.

5. Synchronize Updates Across All Disclosure Channels

A backend change should not become effective before the related probability information is updated through the applicable user-facing channels.

Review the in-game UI, official website, notices, localized pages, and update history as part of a single release checklist.

Expert Insight: Audit Readiness Is the Best Defense

Most probability disclosure violations do not necessarily arise from deliberate manipulation. They may result from fragmented data management, manual calculations, deployment delays, or a lack of ownership between engineering, live operations, localization, and compliance teams.

Once a formal investigation begins, the developer may need to reproduce historical probability settings and explain how those settings were disclosed to users.

The most effective response is therefore to build audit readiness into the probability system before a complaint or regulatory request occurs.

Ask your team:

  • Can we reproduce the exact probability applied on any given date?
  • Do our server data and public disclosure tables match?
  • Can we explain every dynamic or user-specific probability condition?
  • Are probability changes recorded and approved?
  • Can we provide regulator-ready evidence without manually reconstructing it?

TheGameAgent helps overseas developers review probability disclosures, technical evidence, update procedures, and responses to Korean regulatory inquiries.

For additional guidance, read our Korea Probability Disclosure Compliance: 5 Essential Q&As.

Additional Resources

Is your company’s Korean compliance framework ready for the next regulatory request? Contact TheGameAgent for a practical review of your domestic agent structure and probability disclosure process.

This article provides general information and does not constitute legal advice. Regulatory requirements and administrative guidance may change, so developers should confirm the latest rules before launch.

Related Articles

Korea Domestic Agent
Regulatory Updates

How to Get an Adult-Only Game Rated in Korea: A Step-by-Step Guide

A step-by-step guide for global developers preparing a Korean adult-only game rating application, including required materials, review timing, and store integration.

July 6, 2026
5 min read
Read More
Korea Domestic Agent
Regulatory Updates

Korea Game Advertising Compliance: A Practical Guide to GSOK

A practical guide to GSOK’s game-advertising standards, monitoring process, major compliance risks, and pre-launch review checklist.

June 29, 2006
7 min read
Read More
Korea Domestic Agent
Regulatory Updates
Case Studies

Korea Game Advertising Compliance: KFTC Enforcement and GSOK Standards

The Soul Strike case shows how broad “ad-free” claims can create Korean consumer-protection risk. Learn how KFTC enforcement and GSOK self-regulation apply.

May 29, 2006
7 min read
Read More

Are you looking for a Domestic Agent?

Download our company profile to learn more about our services, or book a discovery call with our team.