Regulatory expectations across Malta and the EU are entering a new phase. As we move through 2026 and beyond, supervisors are placing increasing emphasis on how governance, risk, and control frameworks operate in practice, not just how they are designed or documented.
This three-part series brings together key regulatory insights across governance, financial crime, digital resilience, payments, digital assets, and fund structures. Each piece groups related developments into a clear theme, providing a practical view of where supervisory focus is heading and how firms can stay aligned, responsive, and prepared for ongoing change.
This series is intended for general informational purposes only. It does not constitute legal, regulatory, tax or other professional advice, and should not be relied upon as a substitute for reviewing the relevant legislation, regulatory publications or seeking advice from appropriately qualified advisers.
In part 1, we covered governance, assurance, and supervisory expectations and in part 3, we examine sector-specific regulatory change across payments, digital assets and funds.
Financial Crime, Tax Transparency and Digital Resilience
Across financial crime, tax transparency and digital resilience, regulators are placing greater emphasis on consistency, defensibility and the ability to evidence how controls operate in practice. This second piece considers areas where firms may wish to assess whether implementation, oversight and documentation are sufficiently robust to show that risk management processes are not only designed appropriately, but embedded and inspection-ready.
Building on the governance and assurance themes covered in Part 1, this piece looks at how those expectations translate into more specific control areas. The focus shifts to the practical evidence firms may be expected to maintain around ICT resilience, outsourcing oversight, AML and financial crime controls, and FATCA and CRS governance.
What do firms need to know about DORA and digital resilience?
DORA in practice: from compliance to operational resilience
The Digital Operational Resilience Act (DORA) introduces a comprehensive framework for ICT risk management across regulated entities. A central requirement is the Register of Information (RoI), which must capture all ICT third-party arrangements.
However, regulatory expectations go beyond maintaining a register. In-scope firms are expected to demonstrate that it is actively used to manage risk, with clear governance, monitoring, and accountability. The RoI should be considered alongside outsourcing oversight, incident management, and broader risk frameworks.
The challenge is not in compiling the data, but in proving that systems and processes operate effectively in practice and remain inspection-ready at all times.
MFSA expectations on ICT governance and outsourcing
MFSA guidance reinforces the importance of robust ICT governance, particularly in the context of third-party dependencies. Firms are expected to maintain accurate records, apply consistent oversight, and ensure that governance frameworks support operational resilience.
Regulators are increasingly focused on how firms manage outsourcing and technology risks in practice, requiring clear documentation, ongoing monitoring, and effective control frameworks.
This reflects a broader trend towards integrated risk management, where ICT, compliance, and internal audit functions operate cohesively.
How are AML and financial crime expectations evolving?
REQ submissions: consistency and defensibility
As firms approach regulatory submission deadlines such as the FIAU Risk Evaluation Questionnaire (REQ), common issues often emerge. These include misalignment between risk assessments and submitted responses, insufficient supporting evidence, and inconsistencies across reporting functions.
At this stage, firms may wish to focus on ensuring that submissions present a coherent and defensible picture of how AML controls operate in practice. Regulators are increasingly concerned with consistency and credibility rather than volume of documentation.
A well-prepared REQ demonstrates clear linkage between risk, controls, and governance.
Financial crime: evolving expectations and risk differentiation
Recent thematic reviews highlight a shift in regulatory expectations around financial crime risk management. Rather than treating risks such as terrorist financing, proliferation financing, and sanctions evasion as subsets of AML frameworks, firms are now expected to identify and manage these areas more granularly.
Supervisors are also placing greater emphasis on governance, training, and the use of technology, with firms expected to understand and evidence how their controls operate. As financial crime risks evolve, particularly with digitalisation and complex cross-border activity, firms may need to adopt a more adaptive and forward-looking approach.
The emphasis is now on ensuring that controls are risk-driven, calibrated, and consistently applied.
What should firms be focusing on for FATCA and CRS compliance?
FATCA & CRS: from compliance to embedded control
The introduction of the annual Self-Compliance Questionnaire (SCQ) has increased focus on FATCA and CRS obligations in Malta. While awareness of requirements is generally well established, supervisory feedback indicates that the maturity of governance and control frameworks varies significantly.
Common challenges include insufficient integration of controls into day-to-day operations, reliance on third-party providers without clear oversight, and gaps in documentation and review cycles.
Regulators are reinforcing that accountability remains with the institution. Firms are expected to demonstrate that controls are embedded, consistently applied, and aligned with broader compliance frameworks.
The common thread across these areas is the need for firms to connect regulatory obligations with practical control activity. Whether dealing with AML submissions, financial crime risk, FATCA and CRS governance or ICT resilience, supervisors are looking for clear ownership, consistent evidence and frameworks that are capable of withstanding scrutiny in day-to-day operations as well as during review or inspection.
In the final part of the series, we turn to sector-specific developments affecting payment institutions and electronic money institutions, crypto-asset service providers, and fund or family office structures. These areas show how broader expectations around governance, resilience and control effectiveness are being applied to particular business models and regulatory frameworks.
The last part will examine sector-specific regulatory change across payments, digital assets and funds.
Further reading
MFSA Circular – DORA Register of Information Reporting Timelines for the Year 2026 and Onwards
MFSA User Guide for Submitting the Register of Information
MFSA Dear CEO Letter / Thematic Review – Terrorist Financing, Proliferation Financing and Targeted Financial Sanctions Evasion Risks
FIAU Risk Evaluation Questionnaire
MTCA Circular on the Findings and Supervisory Expectations Following the 2026 CRS/FATCA Self-Compliance Questionnaire Exercise