Malta AML abbreviations

122 abbreviations and terms from the Maltese AML/CFT framework and the corporate services sector, rated by how well they need to be known. Search anything, or filter.

57 know cold · 47 should know · 18 recognise

What this is

Study notes made while teaching myself Maltese AML/CFT. Not advice, not authoritative, and not a substitute for the primary sources. Verify anything that matters against the FIAU Implementing Procedures, the PMLFTR or the relevant rulebook.

122 of 122 entries are not yet sourced. Those are working notes rather than references — treat them accordingly until a citation appears.

  • Know cold Define it unprompted.
  • Should know Know what it is and why it matters.
  • Recognise Enough context to follow the conversation.

122 of 122 entries shown

Malta - law & regulators

FIAU Know cold Financial Intelligence Analysis Unit

Malta's financial intelligence unit and AML/CFT supervisor. Issues the Implementing Procedures, receives STRs, carries out compliance examinations and imposes administrative penalties. Your reports go here.

MFSA Know cold Malta Financial Services Authority

Malta's financial services regulator. Authorises and supervises Company Service Providers, which must be registered with it.

PMLA Know cold Prevention of Money Laundering Act (Cap. 373)

The primary Maltese AML statute. Creates the money laundering offences and establishes the FIAU. The parent Act above the PMLFTR.

PMLFTR Know cold Prevention of Money Laundering and Funding of Terrorism Regulations (S.L. 373.01)

The subsidiary legislation that sets out what subject persons must actually do: risk assessment, CDD, record keeping, reporting, training. The single most-cited instrument in Maltese AML practice.

IPs / IP Part I Know cold Implementing Procedures, Part I

FIAU guidance interpreting the PMLFTR, applying to all sectors. Legally binding, not optional best practice - breaching them is an enforceable failure. Current version dated July 2026 - make sure you are reading that one and not an older PDF. Note: 'IP' here has nothing to do with intellectual property.

IP Part II Know cold Implementing Procedures, Part II (sectoral)

Sector-specific supplements to Part I. There is a Part II for Company Service Providers - the one that matters to corporate services firms. Others exist for remote gaming, crypto-assets, casinos, and accountants and auditors.

Cap. 529 Know cold Company Service Providers Act

The statute governing CSPs in Malta - who must be authorised, what they may do, and the MFSA's powers over them. Amended in recent years to widen scope and tighten the framework.

Cap. 386 Should know Companies Act

Maltese company law. Formation, share capital, directors, company secretary, registered office, annual returns. You will be reading documents constituted under this Act every day.

Cap. 331 Should know Trusts and Trustees Act

Governs trusts and trustees in Malta. Matters because identifying the UBO of a trust is different from a company: settlor, trustee, protector, beneficiaries and anyone else exercising ultimate control.

Cap. 365 Should know National Interest (Enabling Powers) Act

The legal basis on which UN and EU sanctions are given effect and enforced in Malta. Establishes the Sanctions Monitoring Board.

SMB Know cold Sanctions Monitoring Board

The Maltese body responsible for sanctions implementation, guidance and licensing. Where you go with a sanctions question or a possible true match.

MBR Know cold Malta Business Registry

The registry of Maltese companies and the register of beneficial owners. Your primary source for verifying Maltese corporate documents.

CASPAR Should know FIAU online supervisory platform

The FIAU's web portal through which subject persons submit supervisory returns, most notably the annual Risk Evaluation Questionnaire.

REQ Should know Risk Evaluation Questionnaire

An annual return submitted to the FIAU via CASPAR describing the firm's ML/FT risk exposure and controls. Feeds the FIAU's risk-based supervision and helps determine who gets inspected. A junior compliance role often helps compile it.

goAML Know cold goAML reporting platform

The UNODC-developed system used to file STRs with the FIAU. Named in most Maltese compliance job specs.

CSP Know cold Company Service Provider

A firm that forms companies, acts as or provides directors or company secretaries, or provides a registered office or similar services. CSPs are treated as gatekeepers and are inherently higher-risk.

Class A / B / C Should know CSP authorisation classes

Classes under the CSP Rulebook, broadly: Class A for company formation services, Class B for providing directors or company secretaries, Class C for both. Minimum own funds run EUR 10,000 (A), EUR 15,000 (B) and EUR 25,000 (C); B and C also require professional indemnity insurance, and C requires a risk management and compliance function.

Standard / Limited / Restricted CSP Should know CSP authorisation tiers

Separate to the A/B/C split, the MFSA operates tiers with their own rulebooks: Standard CSPs (full authorisation), Limited CSPs (reduced scope, own rulebook revised May 2025) and Restricted CSPs (a notification process rather than full authorisation, mainly for individuals holding few directorships). Worth confirming the current definitions in the Rulebook - this area has moved recently.

RMCF Should know Risk Management and Compliance Function

The independent compliance function a Class C CSP must maintain.

ACR Recognise Annual Compliance Return

The MFSA's yearly return from authorised CSPs, separate from the FIAU's REQ. Two regulators, two returns - a distinction worth being able to draw.

NRA Should know National Risk Assessment

Malta's country-level assessment of its own ML/FT risks. Firms are expected to reflect its findings in their own business risk assessment.

MLRO Know cold Money Laundering Reporting Officer

The officer who receives internal reports, decides whether suspicion exists and files STRs with the FIAU. A statutory role carrying personal responsibility. Staff escalate to the MLRO; they do not report to the FIAU themselves.

DMLRO Recognise Deputy MLRO

Stands in for the MLRO. The function must be covered at all times, so larger firms appoint a deputy.

Designated Employee Should know Designated Employee

A PMLFTR role: a person at management level made responsible for the firm's AML/CFT compliance. Distinct from the MLRO, though the same person sometimes holds both.

SP Know cold Subject Person

The Maltese statutory term for a business caught by the PMLFTR - the entity carrying out relevant financial business or relevant activity. A CSP, a bank, a lawyer or an accountant is a subject person. Maltese material uses this phrase rather than 'regulated firm'.

EU framework

AMLD Know cold Anti-Money Laundering Directive

The series of EU directives that shaped national AML law. 4AMLD (2015) introduced the risk-based approach and UBO registers; 5AMLD (2018) extended scope to crypto and tightened UBO access; 6AMLD (2018) harmonised criminal offences. Directives must be transposed into national law - which is why Malta has its own PMLFTR.

AMLR Know cold Anti-Money Laundering Regulation (EU) 2024/1624

The centrepiece of the new EU AML package: a directly applicable single rulebook that will largely replace national divergence on CDD, UBO and beneficial ownership rules. Applies from 10 July 2027.

AMLD6 (new) Know cold Directive (EU) 2024/1640

The directive limb of the 2024 package, covering supervision, FIUs, registers and national arrangements. Confusingly, an earlier 2018 directive was also called 6AMLD - if you use the term, say which one you mean.

AMLA Know cold Anti-Money Laundering Authority

The new EU-level AML authority, seated in Frankfurt. Will directly supervise a set of high-risk cross-border obliged entities and coordinate national supervisors. The biggest structural change to EU AML supervision in a generation.

HRTC list Know cold EU list of high-risk third countries

Jurisdictions with strategic AML/CFT deficiencies. A client connected to one triggers mandatory EDD. Distinct from, though overlapping with, the FATF lists - check both.

SNRA Recognise Supranational Risk Assessment

The European Commission's EU-wide equivalent of a national risk assessment.

EBA Recognise European Banking Authority

Held the EU-level AML/CFT mandate and issued risk factor guidelines before AMLA took over. Its guidelines remain useful reference material.

GDPR Should know General Data Protection Regulation

You will hold large volumes of sensitive personal data. There is a real tension between AML record-keeping duties and data minimisation and erasure rights - AML obligations generally provide the lawful basis, but the tension is a good thing to show awareness of.

WM & Sovim Should know CJEU judgment, November 2022

Not an abbreviation but essential context: the Court of Justice struck down general public access to beneficial ownership registers as a disproportionate interference with privacy. Access is now narrower, which makes UBO verification harder in practice. Knowing this shows you follow the field.

MiCA Recognise Markets in Crypto-Assets Regulation

The EU crypto regulatory framework. Peripheral to a CSP role but worth recognising.

CASP Recognise Crypto-Asset Service Provider

Note the near-collision with CSP - different thing entirely. A source of genuine confusion in written work.

TFR Recognise Transfer of Funds Regulation

Requires originator and beneficiary information to travel with transfers, including crypto transfers - the EU's version of the FATF 'travel rule'.

DAC6 Recognise EU mandatory disclosure rules for cross-border arrangements

Tax rather than AML, but corporate services firms deal with it and it sits alongside compliance work.

ATAD Recognise Anti-Tax Avoidance Directive

Again tax rather than AML, but part of the substance and structuring backdrop to a CSP's client base.

International standards

FATF Know cold Financial Action Task Force

The global AML/CFT standard-setter. Its 40 Recommendations sit behind essentially every national regime including Malta's. Not a law-maker, but everything flows from it.

Moneyval Know cold Committee of Experts on the Evaluation of Anti-Money Laundering Measures

The Council of Europe body that evaluates Malta against the FATF standards. Malta's Moneyval assessment is what triggered the 2021 greylisting - the single most important piece of context for why Maltese compliance is as heavy as it is.

MER Should know Mutual Evaluation Report

The published assessment of a country's AML/CFT regime, scoring both technical compliance and effectiveness. Malta's MER is the document behind most of the last five years of regulatory tightening.

Greylist Know cold FATF list of jurisdictions under increased monitoring

Malta was greylisted in June 2021 and removed in June 2022 - the first EU member state ever greylisted. Those dates explain a great deal about the intensity of the Maltese compliance culture that followed.

Blacklist Know cold FATF list of high-risk jurisdictions subject to a call for action

The severe tier. Countermeasures apply, and business with these jurisdictions is heavily restricted.

ICRG Recognise International Co-operation Review Group

The FATF body that runs the listing process and decides who goes on the greylist.

UNSCR Should know United Nations Security Council Resolution

The source of UN sanctions regimes, given effect in the EU and then in Malta. Binding on all members.

Egmont Group Recognise Egmont Group of Financial Intelligence Units

The international network through which FIUs, including the FIAU, exchange intelligence.

CPI Should know Corruption Perceptions Index

Transparency International's annual corruption ranking. A standard, defensible input into country risk scoring - useful because you can cite a source rather than an impression.

Basel AML Index Recognise Basel Institute on Governance AML Index

Another country risk ranking commonly used in risk methodologies.

Wolfsberg / CBDDQ Recognise Wolfsberg Group Correspondent Banking Due Diligence Questionnaire

An industry-standard due diligence questionnaire. More a banking than a CSP tool, but you may see it.

Core AML/CFT concepts

AML Know cold Anti-Money Laundering

The body of law, regulation and practice aimed at preventing the laundering of criminal proceeds.

CFT / CTF Know cold Combating (or Countering) the Financing of Terrorism

Both forms are used interchangeably. Note that terrorist financing can involve small sums of clean money going to a criminal purpose - the mirror image of laundering, which is dirty money going to a clean purpose.

ML Know cold Money Laundering

Converting or concealing the proceeds of crime so they appear legitimate.

FT / TF Know cold Funding (or Financing) of Terrorism

Maltese legislation uses 'funding of terrorism' - the F in PMLFTR. International material tends to say 'terrorist financing'. Same thing.

PF Should know Proliferation Financing

Financing the spread of weapons of mass destruction. Increasingly required as a distinct strand in risk assessments alongside ML and FT.

Placement / Layering / Integration Know cold The three stages of money laundering

Placement puts criminal cash into the system; layering moves it through transactions and structures to break the audit trail; integration returns it looking legitimate. A CSP mostly sees layering - which is exactly what a nominee-heavy multi-jurisdiction structure is for.

RBA Know cold Risk-Based Approach

The organising principle of modern AML: assess risk, then apply resources and scrutiny in proportion to it. The opposite of a tick-box approach. If you learn one concept properly, make it this one.

BRA Know cold Business Risk Assessment

The firm-level assessment of the ML/FT risks the business as a whole is exposed to, given its clients, services, geographies and delivery channels. Required by the PMLFTR and it drives the firm's policies and risk appetite.

CRA Know cold Customer Risk Assessment

The client-level assessment producing an individual risk rating, which in turn sets the depth of CDD and the frequency of review. Do not confuse with the BRA - the BRA shapes the framework, the CRA applies it to one client.

Predicate offence Should know Predicate offence

The underlying crime that generates the proceeds - fraud, corruption, drug trafficking, tax evasion. Malta operates an all-crimes approach.

TBML Should know Trade-Based Money Laundering

Moving value by mis-invoicing trade: over- and under-invoicing, phantom shipments, and - directly relevant to a CSP - service invoices such as 'consultancy' with no verifiable deliverable.

DNFBP Should know Designated Non-Financial Business or Profession

The FATF category covering lawyers, accountants, notaries, estate agents, casinos and TCSPs - non-banks that are nonetheless AML-obliged. CSPs fall in here.

TCSP Know cold Trust or Company Service Provider

The FATF's term for what Malta calls a CSP. Search FATF material under TCSP, not CSP, when you want the international perspective on the sector's risks.

Gatekeeper Should know Gatekeeper

The idea that professionals who create structures and open doors into the financial system carry heightened responsibility. It is the whole rationale for regulating CSPs.

Due diligence & screening

CDD Know cold Customer Due Diligence

The core obligation. Four limbs: identify the customer; verify identity from reliable independent sources; understand the purpose and intended nature of the relationship; and conduct ongoing monitoring. Worth being able to list all four unprompted.

KYC Know cold Know Your Customer

The everyday industry term, used loosely as a synonym for CDD. Regulators prefer CDD because it is the statutory concept.

KYB Recognise Know Your Business

CDD applied to corporate customers rather than individuals. A vendor term more than a regulatory one.

SDD Know cold Simplified Due Diligence

Reduced measures where risk is demonstrably low. Important: SDD is a reduction in extent and timing, never an exemption. You still identify the customer and you still monitor.

EDD Know cold Enhanced Due Diligence

Additional measures where risk is high - deeper source of wealth and funds evidence, more verification, senior management approval, closer monitoring. Know the mandatory triggers: high-risk third countries, PEPs, complex or unusually large transactions, non-face-to-face onboarding, and anything your own assessment rates high.

UBO / BO Know cold Ultimate Beneficial Owner

The natural person who ultimately owns or controls the customer. The EU threshold is 25% plus one share, or 25% of voting rights - but control can exist without shareholding, and that is the harder and more interesting case.

SMO Should know Senior Managing Official

The fallback where, after exhausting all means, no beneficial owner can be identified: you record the senior managing official instead, and record the fact that you had to. It is a last resort, not a shortcut, and using it should itself raise the risk rating.

SoW Know cold Source of Wealth

How the customer's overall fortune was accumulated - career, business sale, inheritance, investment. Must be evidenced, not merely stated.

SoF Know cold Source of Funds

Where the specific money in this relationship or transaction has come from. The difference between SoW and SoF is constantly conflated. Worth being able to state it in one line.

PEP Know cold Politically Exposed Person

Someone entrusted with a prominent public function - domestic, foreign, or in an international organisation. Triggers senior management approval, source of wealth enquiry and enhanced monitoring. Being a PEP is not an accusation; it is a risk category.

RCA Know cold Relatives and Close Associates

Family members and known close associates of a PEP, who attract the same treatment. Screening only the named individual and not their circle is one of the most common failures found on inspection.

Adverse media Know cold Adverse media / negative news screening

Open-source searching for allegations, investigations and reputational red flags. Do it in the relevant local languages - English-only screening on a non-English-speaking client is close to worthless.

Ongoing monitoring Know cold Ongoing monitoring

The fourth CDD limb and the bulk of the day job: keeping documents current, re-screening, checking that activity still matches the stated profile, and reviewing at a frequency set by risk rating.

Trigger event Should know Trigger event

A change - new UBO, new activity, adverse media hit, sanctions development - that prompts review outside the scheduled cycle.

Nominee Know cold Nominee shareholder or director

Someone holding shares or a directorship on behalf of another. Legal, but it means the public register does not show who is really in control - so you must establish control by other means. A well-recognised red flag in the CSP sector.

Declaration of trust Should know Declaration of trust / nominee agreement

The document disclosing that a nominee holds for a named beneficial owner. What you ask for when you find a nominee arrangement.

Reliance Should know Third-party reliance

Relying on CDD carried out by another regulated party, such as an introducing firm. Permitted in defined circumstances, but responsibility never transfers - the liability stays with you.

NFTF Should know Non-face-to-face

Onboarding without meeting the client in person. A recognised risk factor, though electronic identification has softened it.

Structure chart Know cold Ownership and control structure chart

The diagram tracing ownership from the customer up to natural persons. If it cannot be drawn, the client is not understood - and there is no way to evidence that it is.

Certified true copy Should know Certified true copy

A document copy certified by an approved person as a true likeness of the original. Know who may certify and how recent the certification must be.

Apostille Should know Apostille (Hague Convention)

International authentication of a public document for use in another country. Common on foreign corporate documents crossing your desk.

FP Should know False Positive

A screening alert that on review is not a genuine match. Handling these is much of the daily work - and the discipline is that discounting an alert must be documented and reasoned, not just closed.

True match Know cold True match / true hit

A confirmed match against a sanctions, PEP or adverse media list. A sanctions true match is not a risk rating question - it triggers freezing and reporting obligations immediately.

Sanctions

TFS Should know Targeted Financial Sanctions

Asset freezes and prohibitions aimed at named individuals and entities, as distinct from broad sectoral or country measures.

EU Consolidated List Know cold EU consolidated list of persons and entities subject to financial sanctions

The list binding in Malta as an EU member state. Your primary screening list.

OFAC Know cold Office of Foreign Assets Control (US Treasury)

The US sanctions authority. Not directly binding in Malta, but its reach through USD clearing and secondary sanctions means most firms screen against it anyway.

SDN Should know Specially Designated Nationals and Blocked Persons List

OFAC's main designations list.

OFSI Should know Office of Financial Sanctions Implementation (UK)

The UK sanctions authority, within HM Treasury. Relevant where there is UK exposure.

50% rule Know cold Ownership and control test

An entity owned 50% or more, or otherwise controlled, by a designated person is generally treated as designated itself even though it is not named on any list. This is the trap in sanctions screening: name screening alone will not catch it, so you have to look through the structure.

Asset freeze Know cold Asset freeze

Funds and economic resources must be immobilised and not made available, directly or indirectly, to the designated person. Distinguish from a prohibition, which bars a type of activity rather than freezing a person's assets.

Circumvention Know cold Sanctions circumvention

Structuring around sanctions - proxies, front companies, re-export routes, layered ownership. Prohibited in its own right, and a live concern for any CSP whose clients touch Russia or Belarus, because the corporate structures you help create are exactly the tool.

Designation Should know Designation / listing

The formal act of placing a person or entity on a sanctions list.

Licence Recognise General and specific licences

Authorisations permitting otherwise prohibited activity. In Malta these come from the Sanctions Monitoring Board.

Reporting & suspicion

STR Know cold Suspicious Transaction Report

The report filed by the MLRO with the FIAU via goAML. The Maltese term - use it in preference to SAR.

SAR Should know Suspicious Activity Report

The UK and US term. Broader in principle, since activity need not involve a transaction. Know both terms and know which one Malta uses.

Internal report Know cold Internal report to the MLRO

What you file when you form a suspicion. It goes to the MLRO, not to the FIAU. The MLRO then decides whether it becomes an STR. Getting this chain right is basic, and it is still commonly got wrong.

Knowledge / suspicion / reasonable grounds Know cold The reporting thresholds

You report suspicion, not proof, and the test includes reasonable grounds to suspect - an objective standard, so 'I did not personally suspect' is no defence if you should have. This is the point most often missed by people new to the field.

Tipping off Know cold Tipping off

A criminal offence: disclosing to the client or a third party that a report has been made or an investigation is underway. It is why a declined client cannot be told the real reason.

Attempted transaction Should know Attempted transaction reporting

The obligation extends to transactions and relationships that never completed. Walking away from a client does not discharge the duty to report - an easily overlooked point.

Corporate services & company law

M&A Know cold Memorandum and Articles of Association

In corporate services 'M&A' means the constitutional documents of a company, not mergers and acquisitions. A genuine source of confusion for people arriving from a commercial background.

AR Should know Annual Return

The yearly filing to the MBR confirming a company's officers, shareholders and registered office. Overdue returns are a housekeeping red flag.

RO Should know Registered Office

The company's official address. Providing it is a core CSP service - and a substance question, because a registered office is not the same as a real presence.

Holdco / Opco / SPV Should know Holding company / operating company / special purpose vehicle

Standard structuring building blocks. Legitimate and everywhere - but each additional layer is more distance between the money and the person, which is why structure charts matter.

Redomiciliation Should know Redomiciliation / continuation

Moving a company's registration from one jurisdiction to another without dissolving it. Ask why - the reason is usually mundane, occasionally not.

Bearer shares Should know Bearer shares

Shares owned by whoever physically holds the certificate, making ownership untraceable. Heavily restricted or abolished across the EU. If you encounter them, treat it as serious.

Shelf company Should know Shelf company

A pre-formed dormant company sold off the shelf for immediate use. Legal, but the ready-made history can be used to imply longevity that is not real.

Trust roles Should know Settlor, trustee, protector, beneficiary

Not abbreviations, but you must know them: the settlor puts assets in, the trustee holds and administers them, the protector may hold veto or appointment powers, the beneficiaries benefit. For CDD purposes all of them can be relevant beneficial owners.

Foundation Should know Foundation

A Maltese legal structure with no shareholders, used for private wealth and philanthropy. Beneficial ownership analysis works differently again - founder, administrators, beneficiaries.

LEI Recognise Legal Entity Identifier

A global 20-character code identifying legal entities in financial transactions.

Tax, substance & exchange of information

CRS Should know Common Reporting Standard

The OECD framework for automatic exchange of financial account information between tax authorities. Corporate services clients are classified and reported under it, so the compliance team is usually involved.

FATCA Should know Foreign Account Tax Compliance Act

The US regime requiring reporting on US persons' accounts. Sits alongside CRS in most firms' onboarding forms.

TIN Recognise Tax Identification Number

Collected as part of CRS and FATCA classification.

6/7ths refund Should know Malta's shareholder tax refund

The mechanism reducing the effective tax rate on distributed profits, and a large part of why international clients incorporate in Malta. A compliance officer does not need to advise on it, but does need to know it exists: 'why Malta?' is a question asked of clients constantly, and a legitimate answer should be recognisable.

Participation exemption Recognise Participation exemption

Relief on qualifying holdings, another driver of holding company structures in Malta.

Substance Know cold Economic substance / mind and management

Whether a company genuinely operates where it is registered - real decision-making, real people, real premises. A structure with no substance is both a tax risk and an AML risk, and 'where is mind and management?' is one of the most useful questions you can learn to ask.

Qualifications & training

ICA Know cold International Compliance Association

The professional body whose AML certificates and diplomas are the standard entry route in Malta. The Certificate in AML is the usual introductory qualification; in Malta it is delivered through the Institute of Financial Services.

ACAMS / CAMS Should know Association of Certified Anti-Money Laundering Specialists / Certified Anti-Money Laundering Specialist

The main international alternative to ICA. Worth comparing the two before choosing a route.

CPD Should know Continuing Professional Development

Ongoing training hours. AML training is a regulatory requirement for staff, and delivering it is often part of a compliance role.