Malta's financial intelligence unit and AML/CFT supervisor. Issues the Implementing Procedures, receives STRs, carries out compliance examinations and imposes administrative penalties. Your reports go here.
Malta - law & regulators
Malta's financial services regulator. Authorises and supervises Company Service Providers, which must be registered with it.
The primary Maltese AML statute. Creates the money laundering offences and establishes the FIAU. The parent Act above the PMLFTR.
The subsidiary legislation that sets out what subject persons must actually do: risk assessment, CDD, record keeping, reporting, training. The single most-cited instrument in Maltese AML practice.
FIAU guidance interpreting the PMLFTR, applying to all sectors. Legally binding, not optional best practice - breaching them is an enforceable failure. Current version dated July 2026 - make sure you are reading that one and not an older PDF. Note: 'IP' here has nothing to do with intellectual property.
Sector-specific supplements to Part I. There is a Part II for Company Service Providers - the one that matters to corporate services firms. Others exist for remote gaming, crypto-assets, casinos, and accountants and auditors.
The statute governing CSPs in Malta - who must be authorised, what they may do, and the MFSA's powers over them. Amended in recent years to widen scope and tighten the framework.
Maltese company law. Formation, share capital, directors, company secretary, registered office, annual returns. You will be reading documents constituted under this Act every day.
Governs trusts and trustees in Malta. Matters because identifying the UBO of a trust is different from a company: settlor, trustee, protector, beneficiaries and anyone else exercising ultimate control.
The legal basis on which UN and EU sanctions are given effect and enforced in Malta. Establishes the Sanctions Monitoring Board.
The Maltese body responsible for sanctions implementation, guidance and licensing. Where you go with a sanctions question or a possible true match.
The registry of Maltese companies and the register of beneficial owners. Your primary source for verifying Maltese corporate documents.
The FIAU's web portal through which subject persons submit supervisory returns, most notably the annual Risk Evaluation Questionnaire.
An annual return submitted to the FIAU via CASPAR describing the firm's ML/FT risk exposure and controls. Feeds the FIAU's risk-based supervision and helps determine who gets inspected. A junior compliance role often helps compile it.
The UNODC-developed system used to file STRs with the FIAU. Named in most Maltese compliance job specs.
A firm that forms companies, acts as or provides directors or company secretaries, or provides a registered office or similar services. CSPs are treated as gatekeepers and are inherently higher-risk.
Classes under the CSP Rulebook, broadly: Class A for company formation services, Class B for providing directors or company secretaries, Class C for both. Minimum own funds run EUR 10,000 (A), EUR 15,000 (B) and EUR 25,000 (C); B and C also require professional indemnity insurance, and C requires a risk management and compliance function.
Separate to the A/B/C split, the MFSA operates tiers with their own rulebooks: Standard CSPs (full authorisation), Limited CSPs (reduced scope, own rulebook revised May 2025) and Restricted CSPs (a notification process rather than full authorisation, mainly for individuals holding few directorships). Worth confirming the current definitions in the Rulebook - this area has moved recently.
The independent compliance function a Class C CSP must maintain.
The MFSA's yearly return from authorised CSPs, separate from the FIAU's REQ. Two regulators, two returns - a distinction worth being able to draw.
Malta's country-level assessment of its own ML/FT risks. Firms are expected to reflect its findings in their own business risk assessment.
The officer who receives internal reports, decides whether suspicion exists and files STRs with the FIAU. A statutory role carrying personal responsibility. Staff escalate to the MLRO; they do not report to the FIAU themselves.
Stands in for the MLRO. The function must be covered at all times, so larger firms appoint a deputy.
A PMLFTR role: a person at management level made responsible for the firm's AML/CFT compliance. Distinct from the MLRO, though the same person sometimes holds both.
The Maltese statutory term for a business caught by the PMLFTR - the entity carrying out relevant financial business or relevant activity. A CSP, a bank, a lawyer or an accountant is a subject person. Maltese material uses this phrase rather than 'regulated firm'.
EU framework
The series of EU directives that shaped national AML law. 4AMLD (2015) introduced the risk-based approach and UBO registers; 5AMLD (2018) extended scope to crypto and tightened UBO access; 6AMLD (2018) harmonised criminal offences. Directives must be transposed into national law - which is why Malta has its own PMLFTR.
The centrepiece of the new EU AML package: a directly applicable single rulebook that will largely replace national divergence on CDD, UBO and beneficial ownership rules. Applies from 10 July 2027.
The directive limb of the 2024 package, covering supervision, FIUs, registers and national arrangements. Confusingly, an earlier 2018 directive was also called 6AMLD - if you use the term, say which one you mean.
The new EU-level AML authority, seated in Frankfurt. Will directly supervise a set of high-risk cross-border obliged entities and coordinate national supervisors. The biggest structural change to EU AML supervision in a generation.
Jurisdictions with strategic AML/CFT deficiencies. A client connected to one triggers mandatory EDD. Distinct from, though overlapping with, the FATF lists - check both.
The European Commission's EU-wide equivalent of a national risk assessment.
Held the EU-level AML/CFT mandate and issued risk factor guidelines before AMLA took over. Its guidelines remain useful reference material.
You will hold large volumes of sensitive personal data. There is a real tension between AML record-keeping duties and data minimisation and erasure rights - AML obligations generally provide the lawful basis, but the tension is a good thing to show awareness of.
Not an abbreviation but essential context: the Court of Justice struck down general public access to beneficial ownership registers as a disproportionate interference with privacy. Access is now narrower, which makes UBO verification harder in practice. Knowing this shows you follow the field.
The EU crypto regulatory framework. Peripheral to a CSP role but worth recognising.
Note the near-collision with CSP - different thing entirely. A source of genuine confusion in written work.
Requires originator and beneficiary information to travel with transfers, including crypto transfers - the EU's version of the FATF 'travel rule'.
Tax rather than AML, but corporate services firms deal with it and it sits alongside compliance work.
Again tax rather than AML, but part of the substance and structuring backdrop to a CSP's client base.
International standards
The global AML/CFT standard-setter. Its 40 Recommendations sit behind essentially every national regime including Malta's. Not a law-maker, but everything flows from it.
The Council of Europe body that evaluates Malta against the FATF standards. Malta's Moneyval assessment is what triggered the 2021 greylisting - the single most important piece of context for why Maltese compliance is as heavy as it is.
The published assessment of a country's AML/CFT regime, scoring both technical compliance and effectiveness. Malta's MER is the document behind most of the last five years of regulatory tightening.
Malta was greylisted in June 2021 and removed in June 2022 - the first EU member state ever greylisted. Those dates explain a great deal about the intensity of the Maltese compliance culture that followed.
The severe tier. Countermeasures apply, and business with these jurisdictions is heavily restricted.
The FATF body that runs the listing process and decides who goes on the greylist.
The source of UN sanctions regimes, given effect in the EU and then in Malta. Binding on all members.
The international network through which FIUs, including the FIAU, exchange intelligence.
Transparency International's annual corruption ranking. A standard, defensible input into country risk scoring - useful because you can cite a source rather than an impression.
Another country risk ranking commonly used in risk methodologies.
An industry-standard due diligence questionnaire. More a banking than a CSP tool, but you may see it.
Core AML/CFT concepts
The body of law, regulation and practice aimed at preventing the laundering of criminal proceeds.
Both forms are used interchangeably. Note that terrorist financing can involve small sums of clean money going to a criminal purpose - the mirror image of laundering, which is dirty money going to a clean purpose.
Converting or concealing the proceeds of crime so they appear legitimate.
Maltese legislation uses 'funding of terrorism' - the F in PMLFTR. International material tends to say 'terrorist financing'. Same thing.
Financing the spread of weapons of mass destruction. Increasingly required as a distinct strand in risk assessments alongside ML and FT.
Placement puts criminal cash into the system; layering moves it through transactions and structures to break the audit trail; integration returns it looking legitimate. A CSP mostly sees layering - which is exactly what a nominee-heavy multi-jurisdiction structure is for.
The organising principle of modern AML: assess risk, then apply resources and scrutiny in proportion to it. The opposite of a tick-box approach. If you learn one concept properly, make it this one.
The firm-level assessment of the ML/FT risks the business as a whole is exposed to, given its clients, services, geographies and delivery channels. Required by the PMLFTR and it drives the firm's policies and risk appetite.
The client-level assessment producing an individual risk rating, which in turn sets the depth of CDD and the frequency of review. Do not confuse with the BRA - the BRA shapes the framework, the CRA applies it to one client.
The underlying crime that generates the proceeds - fraud, corruption, drug trafficking, tax evasion. Malta operates an all-crimes approach.
Moving value by mis-invoicing trade: over- and under-invoicing, phantom shipments, and - directly relevant to a CSP - service invoices such as 'consultancy' with no verifiable deliverable.
The FATF category covering lawyers, accountants, notaries, estate agents, casinos and TCSPs - non-banks that are nonetheless AML-obliged. CSPs fall in here.
The FATF's term for what Malta calls a CSP. Search FATF material under TCSP, not CSP, when you want the international perspective on the sector's risks.
The idea that professionals who create structures and open doors into the financial system carry heightened responsibility. It is the whole rationale for regulating CSPs.
Due diligence & screening
The core obligation. Four limbs: identify the customer; verify identity from reliable independent sources; understand the purpose and intended nature of the relationship; and conduct ongoing monitoring. Worth being able to list all four unprompted.
The everyday industry term, used loosely as a synonym for CDD. Regulators prefer CDD because it is the statutory concept.
CDD applied to corporate customers rather than individuals. A vendor term more than a regulatory one.
Reduced measures where risk is demonstrably low. Important: SDD is a reduction in extent and timing, never an exemption. You still identify the customer and you still monitor.
Additional measures where risk is high - deeper source of wealth and funds evidence, more verification, senior management approval, closer monitoring. Know the mandatory triggers: high-risk third countries, PEPs, complex or unusually large transactions, non-face-to-face onboarding, and anything your own assessment rates high.
The natural person who ultimately owns or controls the customer. The EU threshold is 25% plus one share, or 25% of voting rights - but control can exist without shareholding, and that is the harder and more interesting case.
The fallback where, after exhausting all means, no beneficial owner can be identified: you record the senior managing official instead, and record the fact that you had to. It is a last resort, not a shortcut, and using it should itself raise the risk rating.
How the customer's overall fortune was accumulated - career, business sale, inheritance, investment. Must be evidenced, not merely stated.
Where the specific money in this relationship or transaction has come from. The difference between SoW and SoF is constantly conflated. Worth being able to state it in one line.
Someone entrusted with a prominent public function - domestic, foreign, or in an international organisation. Triggers senior management approval, source of wealth enquiry and enhanced monitoring. Being a PEP is not an accusation; it is a risk category.
Family members and known close associates of a PEP, who attract the same treatment. Screening only the named individual and not their circle is one of the most common failures found on inspection.
Open-source searching for allegations, investigations and reputational red flags. Do it in the relevant local languages - English-only screening on a non-English-speaking client is close to worthless.
The fourth CDD limb and the bulk of the day job: keeping documents current, re-screening, checking that activity still matches the stated profile, and reviewing at a frequency set by risk rating.
A change - new UBO, new activity, adverse media hit, sanctions development - that prompts review outside the scheduled cycle.
Someone holding shares or a directorship on behalf of another. Legal, but it means the public register does not show who is really in control - so you must establish control by other means. A well-recognised red flag in the CSP sector.
The document disclosing that a nominee holds for a named beneficial owner. What you ask for when you find a nominee arrangement.
Relying on CDD carried out by another regulated party, such as an introducing firm. Permitted in defined circumstances, but responsibility never transfers - the liability stays with you.
Onboarding without meeting the client in person. A recognised risk factor, though electronic identification has softened it.
The diagram tracing ownership from the customer up to natural persons. If it cannot be drawn, the client is not understood - and there is no way to evidence that it is.
A document copy certified by an approved person as a true likeness of the original. Know who may certify and how recent the certification must be.
International authentication of a public document for use in another country. Common on foreign corporate documents crossing your desk.
A screening alert that on review is not a genuine match. Handling these is much of the daily work - and the discipline is that discounting an alert must be documented and reasoned, not just closed.
A confirmed match against a sanctions, PEP or adverse media list. A sanctions true match is not a risk rating question - it triggers freezing and reporting obligations immediately.
Sanctions
Asset freezes and prohibitions aimed at named individuals and entities, as distinct from broad sectoral or country measures.
The list binding in Malta as an EU member state. Your primary screening list.
The US sanctions authority. Not directly binding in Malta, but its reach through USD clearing and secondary sanctions means most firms screen against it anyway.
OFAC's main designations list.
The UK sanctions authority, within HM Treasury. Relevant where there is UK exposure.
An entity owned 50% or more, or otherwise controlled, by a designated person is generally treated as designated itself even though it is not named on any list. This is the trap in sanctions screening: name screening alone will not catch it, so you have to look through the structure.
Funds and economic resources must be immobilised and not made available, directly or indirectly, to the designated person. Distinguish from a prohibition, which bars a type of activity rather than freezing a person's assets.
Structuring around sanctions - proxies, front companies, re-export routes, layered ownership. Prohibited in its own right, and a live concern for any CSP whose clients touch Russia or Belarus, because the corporate structures you help create are exactly the tool.
The formal act of placing a person or entity on a sanctions list.
Authorisations permitting otherwise prohibited activity. In Malta these come from the Sanctions Monitoring Board.
Reporting & suspicion
The report filed by the MLRO with the FIAU via goAML. The Maltese term - use it in preference to SAR.
The UK and US term. Broader in principle, since activity need not involve a transaction. Know both terms and know which one Malta uses.
What you file when you form a suspicion. It goes to the MLRO, not to the FIAU. The MLRO then decides whether it becomes an STR. Getting this chain right is basic, and it is still commonly got wrong.
You report suspicion, not proof, and the test includes reasonable grounds to suspect - an objective standard, so 'I did not personally suspect' is no defence if you should have. This is the point most often missed by people new to the field.
A criminal offence: disclosing to the client or a third party that a report has been made or an investigation is underway. It is why a declined client cannot be told the real reason.
The obligation extends to transactions and relationships that never completed. Walking away from a client does not discharge the duty to report - an easily overlooked point.
Corporate services & company law
In corporate services 'M&A' means the constitutional documents of a company, not mergers and acquisitions. A genuine source of confusion for people arriving from a commercial background.
The yearly filing to the MBR confirming a company's officers, shareholders and registered office. Overdue returns are a housekeeping red flag.
The company's official address. Providing it is a core CSP service - and a substance question, because a registered office is not the same as a real presence.
Standard structuring building blocks. Legitimate and everywhere - but each additional layer is more distance between the money and the person, which is why structure charts matter.
Moving a company's registration from one jurisdiction to another without dissolving it. Ask why - the reason is usually mundane, occasionally not.
Shares owned by whoever physically holds the certificate, making ownership untraceable. Heavily restricted or abolished across the EU. If you encounter them, treat it as serious.
A pre-formed dormant company sold off the shelf for immediate use. Legal, but the ready-made history can be used to imply longevity that is not real.
Not abbreviations, but you must know them: the settlor puts assets in, the trustee holds and administers them, the protector may hold veto or appointment powers, the beneficiaries benefit. For CDD purposes all of them can be relevant beneficial owners.
A Maltese legal structure with no shareholders, used for private wealth and philanthropy. Beneficial ownership analysis works differently again - founder, administrators, beneficiaries.
A global 20-character code identifying legal entities in financial transactions.
Tax, substance & exchange of information
The OECD framework for automatic exchange of financial account information between tax authorities. Corporate services clients are classified and reported under it, so the compliance team is usually involved.
The US regime requiring reporting on US persons' accounts. Sits alongside CRS in most firms' onboarding forms.
Collected as part of CRS and FATCA classification.
The mechanism reducing the effective tax rate on distributed profits, and a large part of why international clients incorporate in Malta. A compliance officer does not need to advise on it, but does need to know it exists: 'why Malta?' is a question asked of clients constantly, and a legitimate answer should be recognisable.
Relief on qualifying holdings, another driver of holding company structures in Malta.
Whether a company genuinely operates where it is registered - real decision-making, real people, real premises. A structure with no substance is both a tax risk and an AML risk, and 'where is mind and management?' is one of the most useful questions you can learn to ask.
Qualifications & training
The professional body whose AML certificates and diplomas are the standard entry route in Malta. The Certificate in AML is the usual introductory qualification; in Malta it is delivered through the Institute of Financial Services.
The main international alternative to ICA. Worth comparing the two before choosing a route.
Ongoing training hours. AML training is a regulatory requirement for staff, and delivering it is often part of a compliance role.
Nothing matches that. Try a shorter search.