List your product on Stack Search

Get in front of thousands of GRC decision-makers

MFSA Enforcement Activity Rose in 2025 as Reporting Failures Dominated

MFSA Enforcement Activity Rose in 2025 as Reporting Failures Dominated

By
Key Takeaways
  • 91 Enforcement Actions: The Malta Financial Services Authority issued 91 enforcement actions and administrative penalties totaling €570,673 in 2025 while handling 943 potential enforcement cases.
  • Reporting Failures Drove Enforcement: Late or missing statutory filings resulted in 63 administrative penalties, accounting for roughly 69% of all enforcement actions during the year.
  • Client Funds Under Scrutiny: Investigations identified shortcomings in the segregation and reconciliation of client funds, as well as weaknesses in governance and internal controls at certain financial institutions.
Deep Dive

The Malta Financial Services Authority worked through 943 potential enforcement cases in 2025. Ninety-one ended in enforcement actions and administrative penalties totaling €570,673, but the clearest pattern in the regulator’s year was not buried in its more complicated investigations. It was there in the calendar.

Sixty-three administrative penalties arose from statutory documents that were filed late or not filed at all. That was roughly 69% of the MFSA’s enforcement actions for the year, with 25 of those cases concluded through settlement.

The concentration is striking partly because there is so little ambiguity about what the authority expects. Regulatory reporting is a core obligation of every license holder, the MFSA said, and the responsibility cannot be delegated away. The regulator does not send reminders when deadlines approach. Extensions are granted only in exceptional circumstances. Even failures considered non-material can result in a penalty, although aggravating and mitigating factors are taken into account.

There is a harder edge to those rules than the subject of regulatory filings might suggest. Supervisors depend on what firms tell them, and on receiving it when they are supposed to. A missed filing may be administrative in form, but repeated failures can say something more consequential about the controls, discipline and governance of the institution behind it.

The authority investigated potential unauthorized business and scams, as well as governance and internal-control deficiencies uncovered through supervision. And in some cases, the weaknesses reached somewhere more sensitive still: the protection of client money.

When the Failure Reaches Client Funds

The MFSA found shortcomings in safeguarding practices at certain financial institutions, including payment and electronic money institutions. Investigations identified inadequate segregation of client funds, insufficient or irregular reconciliations, and weak governance and internal-control frameworks.

These are not interchangeable failures. But they meet at the same uncomfortable place. Safeguarding rules exist to ensure that money belonging to customers remains properly protected rather than becoming entangled with the finances or failures of the institution holding it.

The MFSA treats that responsibility accordingly. Safeguarding is not merely something a firm must demonstrate when seeking authorization. It remains an obligation for as long as the institution operates under its license.

In one case last year, the consequences reached the license itself. The authority canceled the license of a financial institution in part because of breaches of safeguarding requirements. Other investigations in the area remain ongoing.

The distinction matters because the MFSA’s enforcement powers run considerably further than fines. Depending on the breach, the authority can impose administrative penalties and directives, issue public reprimands, suspend a license or cancel it altogether.

Before reaching that point, its Enforcement Function investigates whether a regulatory breach has occurred and whether action is warranted. Where appropriate, recommendations go to the authority’s decision-making body. Firms facing potential enforcement are given an opportunity to make representations during the MFSA’s “Minded Action” stage, while settlements remain available in accordance with its policies. The authority says its measures are intended to be fair and proportionate, but also effective and dissuasive.

That leaves the 2025 enforcement record with two rather different stories inside it. One is about the ordinary discipline of being regulated: submit the documents, submit them accurately and submit them on time. The other begins where those routines cease to be routine, when weak controls and poor governance reach the money firms have been trusted to protect.

The first produced most of Malta’s enforcement actions last year. The second shows why the machinery exists.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong