• Part 1: Regulatory Insights in Malta and the Broader EU in 2026 & Beyond - Governance, Assurance and Supervisory Expectations

Part 1: Regulatory Insights in Malta and the Broader EU in 2026 & Beyond - Governance, Assurance and Supervisory Expectations

Regulatory expectations across Malta and the EU are entering a new phase. As we move through 2026 and beyond, supervisors are placing increasing emphasis on how governance, risk, and control frameworks operate in practice, not just how they are designed or documented.

This three-part series brings together key regulatory insights across governance, financial crime, digital resilience, payments, digital assets, and fund structures. Each piece groups related developments into a clear theme, providing a practical view of where supervisory focus is heading and how firms can stay aligned, responsive, and prepared for ongoing change.

This series is intended for general informational purposes only. It does not constitute legal, regulatory, tax or other professional advice, and should not be relied upon as a substitute for reviewing the relevant legislation, regulatory publications or seeking advice from appropriately qualified advisers.

The following parts examine financial crime, tax transparency and digital resilience, before turning to sector-specific regulatory change across payments, digital assets and funds.

Part 1: Governance, Assurance and Supervisory Expectations

Regulators are increasingly focused on whether governance, risk and control frameworks are genuinely embedded in day-to-day operations. This first piece looks at how supervisory expectations are shifting from documented compliance towards demonstrable effectiveness, with particular emphasis on board accountability, control-function quality and independent assurance.

What are regulators expecting from governance frameworks today?

Governance in practice: from frameworks to effectiveness

Regulatory expectations in Malta are increasingly focused on how governance frameworks operate in practice rather than how they are documented. Supervisors are placing greater emphasis on board accountability, organisational culture, and the effectiveness of control functions.

Firms are expected to demonstrate that governance, risk and compliance functions work as an integrated system, with clear roles, meaningful challenge, and evidence of follow-through. In an outcomes-based environment, the gap between documented frameworks and real-world application is becoming a key area of supervisory focus.

This shift signals a move away from form towards substance, where governance structures must be demonstrably embedded, actively monitored, and capable of supporting sound decision-making.

What are the MFSA’s current supervisory priorities?

MFSA Supervisory Priorities 2026

The MFSA’s Supervisory Priorities for 2026 highlight key focus areas including governance, financial crime, digital finance, and consumer protection. The Authority is reinforcing an outcomes-based supervisory approach, requiring firms to assess how these priorities impact their control frameworks and governance structures.

Emerging areas such as AI, MiCA readiness, ICT risk, and DORA implementation are expected to receive increased scrutiny. Firms are also expected to strengthen governance and enhance compliance capabilities in line with evolving regulatory standards.

For many firms, translating these priorities into practical actions may support ongoing regulatory alignment, depending on their activities, risk profile and applicable obligations.

Compliance and internal audit under scrutiny

Recent MFSA communications, including Dear CEO letters and technical insights, highlight recurring weaknesses in compliance and internal audit functions across regulated entities.

Common issues include risk plans that are not aligned to business realities, findings that are not tracked to closure, and audit frameworks that exist on paper but lack practical application.

The overarching message is clear: regulators want to rely on these control functions, but only where their quality and effectiveness can be demonstrated. Firms are expected to show that compliance and internal audit are risk-driven, actively embedded, and continuously improving.

This represents both a challenge and an opportunity for organisations to strengthen governance frameworks and enhance supervisory confidence.

How is internal audit evolving under current regulatory expectations?

QAIP and the maturity of internal audit functions

Under the new IIA Global Internal Audit Standards, internal audit functions are expected to implement a Quality Assurance and Improvement Programme (QAIP) covering all aspects of internal audit activity.

A robust QAIP provides boards with tangible evidence that internal audit functions are independent, effective, and capable of supporting governance and risk oversight. In Malta, where the profession is still developing, there is a clear opportunity for firms to get ahead by demonstrating alignment with these standards.

In an environment of increasing supervisory scrutiny, QAIP is becoming a key indicator of whether regulators can place reliance on internal audit.

Independent assurance as a governance tool

Boards and audit committees are under growing pressure to demonstrate that governance, risk management and internal controls are not only designed appropriately, but are functioning effectively in practice.

Internal audit is evolving from a retrospective review function into a forward-looking assurance tool, providing insight into emerging risks and supporting decision-making. Areas of focus now include governance effectiveness, financial crime controls, outsourcing, ICT risk, and sustainable remediation of findings.

The value of internal audit lies in its ability to provide independent, evidence-based assurance that control frameworks are operating as intended.

Taken together, these developments point to a more demanding supervisory environment in which governance frameworks must be active, evidence-based and capable of supporting effective challenge. For firms, the priority is not simply to maintain policies and reporting lines, but to demonstrate that assurance functions are sufficiently mature, independent and connected to the risks facing the business.

In the next part of this series, we move from governance and assurance to the operational areas where those frameworks are increasingly being tested: financial crime, tax transparency and digital resilience. This includes DORA implementation, AML risk assessment and reporting, FATCA and CRS controls, and the evidence firms may need to maintain around how these processes operate in practice.

Further reading

  • MFSA Supervisory Priorities 2026

  • MFSA Dear CEO Letter – Thematic Review on Compliance and Internal Audit Functions of Management Companies of AIFs and UCITS Funds

  • MFSA Technical Insight: Recent Supervisory Findings & Expectations

  • IIA Global Internal Audit Standards