Trackers
2026-07-09 00:00 Trackers

AML & KYC in Malta: 2026 Update

AML & KYC in Malta is governed by a layered framework that combines EU directives, domestic legislation, and sector-specific rules enforced by multiple competent authorities. Malta has significantly strengthened its financial crime controls following earlier scrutiny from international bodies, and the current regime imposes detailed obligations on a broad range of subject persons. Businesses operating in Malta - whether in financial services, gaming, real estate, or professional services - must maintain robust customer due diligence programmes, file suspicious transaction reports, and demonstrate ongoing compliance to their supervisors. This guide explains the legal foundations, the authorities involved, the practical obligations for subject persons, the consequences of non-compliance, and the most recent developments shaping the framework.

The legal foundations of AML & KYC in Malta

The primary domestic statute is the Prevention of Money Laundering Act, which has been amended repeatedly to transpose successive EU Anti-Money Laundering Directives into Maltese law. The most recent transposition incorporated the requirements of the Fourth and Fifth AML Directives, expanding the scope of subject persons, tightening beneficial ownership transparency rules, and introducing enhanced due diligence obligations for high-risk third countries.

Alongside the Act, the Prevention of Money Laundering and Funding of Terrorism Regulations provide the operational detail. These Regulations define customer due diligence measures, set out the conditions for simplified and enhanced due diligence, establish record-keeping periods, and specify the content of internal policies and procedures that subject persons must maintain. The Regulations are supplemented by implementing procedures issued by each supervisory authority, which translate the statutory requirements into sector-specific guidance.

Malta';s membership of the Financial Action Task Force (FATF) and the Council of Europe';s MONEYVAL committee means that the domestic framework is periodically assessed against international standards. MONEYVAL';s mutual evaluation reports have historically driven significant legislative and supervisory reform in Malta, and the current framework reflects commitments made in response to earlier evaluation findings. Subject persons should treat MONEYVAL guidance as a practical indicator of where supervisory scrutiny is likely to focus.

The Proceeds of Crime Act complements the AML framework by criminalising money laundering and providing for the confiscation of criminal proceeds. Together, these instruments create a comprehensive legal architecture that aligns Malta with the broader EU approach to financial crime prevention.

Who qualifies as a subject person in Malta

The concept of a "subject person" is central to AML & KYC in Malta. Subject persons are entities and individuals required by law to implement AML and KYC measures. The category is broad and extends well beyond traditional financial institutions.

Subject persons in Malta include:

  • Credit institutions and financial institutions licensed by the Malta Financial Services Authority (MFSA)
  • Investment firms, fund managers, and insurance intermediaries
  • Accountants, auditors, tax advisers, and notaries when carrying out certain transactions
  • Legal professionals handling real estate transactions, company formation, or client funds
  • Real estate agents and developers involved in high-value property transactions
  • Virtual financial asset service providers licensed under the Virtual Financial Assets Act
  • High-value dealers and gaming operators licensed by the Malta Gaming Authority (MGA)

Each category faces obligations calibrated to the risks inherent in its sector. A licensed credit institution faces more prescriptive requirements than a high-value dealer, but both must apply a risk-based approach, conduct customer due diligence, and report suspicious activity. The breadth of the subject person definition means that many businesses operating in Malta that do not consider themselves financial institutions are nonetheless bound by the full AML & KYC regime.

A common mistake among foreign founders establishing operations in Malta is to assume that AML obligations apply only to banks and payment institutions. In practice, a corporate services provider, a crypto asset firm, or a law firm handling client funds is equally subject to the regime and faces the same supervisory scrutiny.

Core KYC and customer due diligence obligations

Customer due diligence (CDD) is the operational heart of AML & KYC in Malta. Subject persons must apply CDD measures when establishing a business relationship, carrying out occasional transactions above prescribed thresholds, or when there is suspicion of money laundering or terrorist financing regardless of any threshold.

Standard CDD requires identifying the customer and verifying that identity using reliable, independent source documents. For legal entities, this extends to identifying and verifying the beneficial owners - those natural persons who ultimately own or control the entity, typically defined as holding more than 25% of the shares or voting rights. Subject persons must also understand the nature and purpose of the business relationship and conduct ongoing monitoring to ensure that transactions are consistent with the subject person';s knowledge of the customer.

Simplified due diligence is available where the risk is demonstrably low - for example, when dealing with other regulated entities in low-risk jurisdictions. Enhanced due diligence (EDD) is mandatory in higher-risk situations, including transactions involving politically exposed persons (PEPs), customers from high-risk third countries identified by the European Commission, and complex or unusually large transactions with no apparent economic purpose. EDD requires obtaining additional information about the customer and the source of funds, applying senior management approval for the relationship, and conducting more frequent ongoing monitoring.

The Maltese framework places particular emphasis on the identification of beneficial ownership. Subject persons must consult the Maltese Beneficial Ownership Register, maintained by the Malta Business Registry, as part of their CDD process. The Register records the beneficial owners of companies and other legal entities incorporated in Malta, and discrepancies between Register data and information obtained directly from the customer must be reported to the competent authority.

In practice, founders should consider the documentation burden carefully before onboarding. Many subject persons in Malta require certified copies of identity documents, source of funds declarations, corporate structure charts, and proof of business activity. Assembling this documentation in advance - particularly for complex group structures - significantly reduces onboarding delays.

The supervisory architecture: who enforces AML & KYC in Malta

AML & KYC in Malta is supervised by several authorities, each responsible for a distinct sector. Understanding which authority supervises a given business is essential for compliance planning.

The MFSA is the primary supervisor for financial services firms, including banks, investment firms, insurance companies, payment institutions, and virtual financial asset service providers. The MFSA issues sector-specific implementing procedures, conducts on-site and off-site inspections, and has the power to impose administrative penalties, suspend licences, and refer cases for criminal prosecution.

The Malta Gaming Authority supervises gaming operators for AML purposes. Given Malta';s position as a major hub for online gaming, the MGA';s AML supervisory function is substantial. The MGA has issued detailed AML/CFT guidelines for gaming operators and has demonstrated a willingness to impose significant penalties for non-compliance.

The Accountancy Board and the Malta Institute of Accountants supervise accountants and auditors. The Chamber of Advocates and the Notarial Council oversee legal professionals. The Commissioner for Revenue has a supervisory role in relation to certain high-value dealers and real estate professionals.

The Financial Intelligence Analysis Unit (FIAU) sits at the centre of Malta';s AML architecture. The FIAU is the national financial intelligence unit responsible for receiving, analysing, and disseminating suspicious transaction reports (STRs). It also issues implementing procedures that apply across all sectors and publishes risk assessments that subject persons must take into account when calibrating their own risk-based approaches. The FIAU has broad investigative powers and works closely with the Malta Police Force and international counterparts through the Egmont Group network.

A non-obvious requirement is that subject persons must not only comply with their sector supervisor';s implementing procedures but must also follow FIAU implementing procedures, which apply horizontally. Where the two sets of procedures overlap, the more stringent requirement generally prevails.

Suspicious transaction reporting and internal controls

The obligation to file suspicious transaction reports is one of the most operationally demanding aspects of AML & KYC in Malta. Subject persons must report to the FIAU whenever they know, suspect, or have reasonable grounds to suspect that a transaction or activity is connected to money laundering or terrorist financing. The obligation applies regardless of whether the transaction is completed or merely attempted.

Reports must be submitted through the FIAU';s goAML system, the platform used by financial intelligence units across the EU. Subject persons must file promptly - in practice, the FIAU expects reports to be submitted as soon as practicable after suspicion arises, and delay can itself constitute a breach. Tipping off the customer that a report has been filed is a criminal offence.

Beyond STR filing, subject persons must maintain comprehensive internal AML programmes. These must include:

  • A written risk assessment covering the subject person';s business, customers, products, and geographic exposure
  • Internal policies and procedures implementing the risk-based approach
  • Appointment of a Money Laundering Reporting Officer (MLRO) with sufficient seniority and resources
  • Regular AML training for all relevant staff
  • An independent audit function to test the effectiveness of the AML programme

The MLRO role is particularly important in Malta. The MLRO is the individual responsible for receiving internal suspicion reports from staff, deciding whether to file an STR with the FIAU, and acting as the primary point of contact with supervisors. Many subject persons appoint an external MLRO where the internal resource is insufficient, which is permissible under Maltese law provided the arrangement is properly documented and the MLRO has genuine access to the business.

Many underestimate the documentation burden associated with ongoing monitoring. Subject persons must keep records of CDD measures, supporting documents, and transaction records for a minimum of five years from the end of the business relationship or the date of the occasional transaction. These records must be retrievable promptly on request from the FIAU or the relevant supervisor.

If your business is establishing or reviewing its AML programme in Malta, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Penalties, enforcement trends, and recent developments

The consequences of AML & KYC failures in Malta are significant. Administrative penalties under the Prevention of Money Laundering and Funding of Terrorism Regulations can reach substantial multiples of the benefit derived from the breach, or fixed maximum amounts that increase with the severity of the violation. For credit institutions and financial institutions, the MFSA can impose penalties running into the millions of euros, suspend or revoke licences, and publicly name non-compliant entities. The FIAU has similarly broad sanctioning powers and has used them with increasing frequency in recent supervisory cycles.

Criminal liability under the Proceeds of Crime Act extends to individuals, including directors and MLROs, who knowingly facilitate money laundering or fail to report suspicion. Prosecution is relatively rare but the risk is real, particularly where supervisory investigations reveal systemic failures or deliberate concealment.

Recent enforcement trends in Malta reflect a shift toward thematic reviews and sector-wide assessments rather than purely reactive investigations. The FIAU has published risk assessments covering specific sectors - including gaming, corporate services, and real estate - and has signalled that subject persons in these sectors face heightened scrutiny. Supervisors have also focused on the quality of STRs, penalising both under-reporting and the filing of low-quality, formulaic reports that provide insufficient analytical value.

On the legislative side, the EU';s AML package - comprising a new AML Regulation, a revised AML Directive, and the establishment of the EU Anti-Money Laundering Authority (AMLA) - will have a direct impact on Malta. The AML Regulation will apply directly in Malta without the need for domestic transposition, creating a single rulebook across the EU. AMLA, once operational, will directly supervise certain high-risk obliged entities, including some operating in Malta';s financial services and crypto asset sectors. Subject persons should begin assessing how the AMLA framework will interact with their existing compliance programmes.

A practical scenario illustrates the stakes: a corporate services provider in Malta that onboards a complex offshore structure without conducting adequate beneficial ownership verification, and fails to file an STR when transaction patterns become unusual, faces simultaneous investigations by the FIAU and the MFSA. The resulting penalties, reputational damage, and potential licence suspension can be existential for a small firm. A second scenario involves a gaming operator that applies a one-size-fits-all CDD approach without calibrating it to the risk profile of individual customers. A thematic review by the MGA that identifies this gap can result in a public penalty notice and mandatory remediation programme, both of which carry significant commercial consequences.

Frequently asked questions

What is the biggest practical compliance risk for a new subject person in Malta?

The most common risk is underestimating the scope of the subject person definition and the depth of the obligations it triggers. Many businesses - particularly in professional services, corporate administration, and crypto assets - discover after licensing that their AML programme is materially deficient. The FIAU and sector supervisors conduct onboarding reviews and early inspections, and findings of inadequate CDD procedures, absent risk assessments, or untrained staff can result in remediation orders and penalties within the first year of operation. Investing in a properly designed AML programme before commencing regulated activity is significantly less costly than remediation under supervisory pressure.

How long does it take to build a compliant AML programme, and what does it cost?

The timeline depends heavily on the complexity of the business and the sector. A straightforward professional services firm with a limited customer base can typically implement a compliant programme - including risk assessment, policies, MLRO appointment, and staff training - within six to ten weeks. A licensed financial institution or gaming operator with a large, diverse customer base will require considerably longer and may need specialist external support. Professional fees for programme design and implementation vary widely; costs for smaller subject persons generally start from the low thousands of euros, while complex institutional programmes can run significantly higher. Ongoing compliance costs - MLRO fees, training, audit, and technology - should be budgeted as a recurring operational expense.

Does Malta';s AML framework apply differently to crypto asset businesses?

Yes, in important respects. Virtual financial asset service providers in Malta are licensed under the Virtual Financial Assets Act and supervised by the MFSA for both prudential and AML purposes. The MFSA has issued specific implementing procedures for VFA service providers that reflect the particular risks of crypto asset transactions, including the application of the travel rule - which requires the transfer of originator and beneficiary information alongside virtual asset transfers. Enhanced due diligence requirements apply more broadly in the crypto sector given the elevated risk profile assigned to it by both the FATF and the European Commission. Businesses in this sector should also monitor the implementation of the EU';s Markets in Crypto-Assets Regulation, which interacts with the AML framework in several important respects.

Conclusion

AML & KYC in Malta operates within a mature, EU-aligned framework that is actively enforced by multiple competent authorities. The obligations are broad, the penalties for non-compliance are material, and the supervisory environment continues to intensify. Businesses entering the Maltese market or reviewing their existing compliance posture should treat AML programme design as a foundational operational requirement, not an afterthought.

VLO Law Firms advises international clients on AML & KYC matters in Malta. We can assist with programme design, MLRO support, regulatory submissions, and supervisory engagement. To request a consultation, contact: info@vlolawfirm.com