This is same process as you computing SHA1 of a file you downloaded and comparing it with the SHA1 provided on the website, if you could also provide a 128 bit number as seed of the SAH1 to the website.
And yes, they look for hardware backdoors: (The chairman may require transportation of not more than two working models of a new gaming device to the new game lab of the board ... The lab may dismantle the models and may destroy electronic components in order to fully evaluate the device.)[3]
The second phase is the field check. In the days of standalone slot machines, the field check involved an Gaming Commission inspector plugging the machine's pluggable EPROM into a reader and computing its hash. Now it's tougher, but if the program is on some removable medium, it can be checked independently. Downloading updates is prohibited.
The third phase is logging. The logging requirements require logging all gambling and maintenance activity on logging media that survive maintenance. Every time a machine is opened, that's logged, too. In multi-machine systems, logs are kept both locally and centrally, and the central logging machine has to be physically inaccessible to the people maintaining the machines. If something funny is going on, there should be enough info in the logs to find out what, and who.
There are lots of specific requirements, from two-factor authentication to random number generator design and testing. There are many statements made under penalty of perjury. They even prohibit pop-up ads on slot machines, although advertising when the machine is idle and has no credit on it is allowed.
Just about everything they check for has been tried at some point by someone trying to cheat. They're up against organized crime. This isn't airtight, but it's far better than what we have now for embedded consumer software.
[1] http://gaming.nv.gov/modules/showdocument.aspx?documentid=27... [2] http://gaming.nv.gov/index.aspx?page=102 [3] http://gaming.nv.gov/modules/showdocument.aspx?documentid=29...