Who needs AML/CFT training

Select a role to see why the training duty reaches it, and what that role’s training has to cover.

Choose a role

§7.2(a)

Directors and partners

Who this is
The board of a Maltese CSP — executive and non-executive directors, and partners in a partnership. In a smaller firm these are usually the same people who run client work, and are in scope twice over.
Why the duty reaches them
Named first in §7.2’s own list. The chapter also records that individual members of staff, and in particular directors or similar officers responsible for management, may face administrative sanctions for contraventions committed by the firm, and criminal penalties for involvement in ML/FT or for breaching non-disclosure obligations.
What their training has to cover
The outcomes of the firm’s own business risk assessment, the customer acceptance policy they approve, and the effect of a breach on the firm, on its customers and on them personally.
§7.2(b)

Senior management

Who this is
Managing directors, heads of department and practice leads — anyone directing how client work is done without necessarily sitting on the board.
Why the duty reaches them
Named second in §7.2. Senior management is separately expected to provide the MLRO and the monitoring function with sufficient resources, including appropriate staff and technological means, which is not a judgement anyone can make without understanding what those functions do.
What their training has to cover
The firm’s risk management measures — customer acceptance policies, the customer risk assessment procedure, internal controls, compliance management and communications.
§7.2(c)

The MLRO and designated employee(s)

Who this is
The MLRO, any deputy, and the designated employee(s). Where the firm has appointed an officer at management level to monitor day-to-day implementation, that role expressly includes seeing to periodic internal AML/CFT training for all relevant staff.
Why the duty reaches them
Named third in §7.2. Some of the monitoring duties may be delegated to other employees, but the officer entrusted with the function retains responsibility for implementing and assessing how the firm’s measures actually operate.
What their training has to cover
The framework end to end. The distinct obligation attaching to this group is visibility: every employee is required to know who the MLRO and the designated employee are, so the role has to be identifiable and not merely filled.
§7.2(d)

Compliance staff

Who this is
Compliance officers, compliance executives and analysts supporting the monitoring function, short of holding the MLRO role itself.
Why the duty reaches them
Named fourth in §7.2, as a group distinct from the MLRO. Being the people who administer the framework is not treated as a substitute for being trained on it.
What their training has to cover
CDD measures, record-keeping procedures, internal reporting procedures, and the MLRO’s role in filing STRs with the FIAU — the framework as a system rather than one file at a time.
§7.2(e)

Client relationship and portfolio managers

Who this is
Senior client-facing staff who own a portfolio and take the client’s instructions — the person a client asks for by name.
Why the duty reaches them
Within §7.2(e): all members of staff involved in activities falling within ‘relevant financial business’ and ‘relevant activity’. The monitoring chapter is more specific still — employees dealing with customers directly are described as best positioned to recognise and detect suspicious or unusual actions and to flag them for assessment before execution.
What their training has to cover
The steps to follow when onboarding customers, the handling of high-risk customers, and the behaviour to adopt when faced with transactions that appear to be suspicious.
§7.2(e)

Corporate services executives and company administrators

Who this is
The core of a CSP’s first line: administrators running incorporations, maintaining client files, collecting and checking CDD, and handling day-to-day client contact.
Why the duty reaches them
Within §7.2(e). Training has to be relevant to the employees’ specific responsibilities and functions, and §7.2 expects front-office employees to be trained differently from back-office ones — so this group cannot be served by whatever the firm gives everybody.
What their training has to cover
How the firm’s own products and services may be misused for ML/FT, and the typologies, red flags and risk indicators applicable to the services this seat actually delivers.
§7.2(e)

Company secretarial officers

Who this is
Staff maintaining statutory registers, filing returns, and processing changes of officer, shareholder and registered office.
Why the duty reaches them
Within §7.2(e). The work is administrative in form but sits inside relevant activity, and the records it produces are the ones the framework later relies on.
What their training has to cover
Record-keeping procedures and CDD measures as they bear on the records this seat maintains, and the internal reporting route out of it.
§7.2(e)

Accounts and bookkeeping staff

Who this is
Bookkeepers and accounts staff processing client transactions and preparing management accounts. Back-office in §7.2’s sense — which is a statement about what their training should contain, not about whether they need any.
Why the duty reaches them
Within §7.2(e), and the front-office / back-office distinction is drawn in §7.2 itself.
What their training has to cover
Being trained to identify unusual or suspicious transactions and activities that may be related to ML/FT, and the red flags associated with the particular customer, service or product in front of them.
§7.2(e)

Junior administrators and trainees

Who this is
Junior staff and trainees carrying out parts of relevant activity under supervision.
Why the duty reaches them
§7.2 applies irrespective of level of seniority. Being supervised does not move the duty up to the supervisor.
What their training has to cover
Whatever the function requires — plus the escalation route. Reporting lines are to be kept as short as possible, ideally allowing an employee to report directly to the MLRO, which matters most for the people sitting furthest from the MLRO on the organigram.
§7.2 & §5.4

Temporary, contract and outsourced staff

Who this is
Agency staff, contractors, secondees, and outsourced third parties engaged to carry out aspects of the business.
Why the duty reaches them
§7.2 says the term ‘employees’ is not to be read restrictively: it covers individuals engaged to carry out aspects of the business involving relevant activity, such as temporary or contract staff. The internal reporting chapter says the same thing independently — those requirements apply to individuals with no employment relationship, including contracted or outsourced third parties.
What their training has to cover
Whatever the covered function requires, plus the part most easily left out of an engagement: who the MLRO is and what procedure to follow.
§7.2

Employees located outside Malta

Who this is
Staff in branches, subsidiaries or service centres outside Malta doing work for the Maltese subject person.
Why the duty reaches them
Where relevant activity is carried out by staff outside Malta, those employees must be made aware of and trained to follow the Maltese requirements.
What their training has to cover
The Maltese framework specifically — the PMLA, the PMLFTR, the Criminal Code provisions on the funding of terrorism and these Implementing Procedures — and not only the local equivalent where they sit.

Source: FIAU Implementing Procedures, Part I (§7.2, pp. 267–269, last amended 27 April 2026) · individual exposure at §7.1, p. 267, last amended 27 April 2026 · the resourcing and monitoring duties at §5.3–5.4, pp. 232–233, last amended 27 April 2026

Why case studies

Being able to say where the duty lands is not the same as recognising the file it lands on.

Section 7.1 does not ask for awareness alone. It asks for training in the recognition and handling of operations and transactions that may be related to ML/FT — and the monitoring chapter puts that recognition on the people holding the file rather than on the ones who wrote the policy. Recognition is a judgement made on incomplete facts, in someone else’s client file, usually while the work is waiting. Reading a list of roles does not rehearse it.

That is what the case studies are for. Each of the 18 cases hands you a file and makes you take it to a decision — the risk factors, the screening result, whether enhanced measures are triggered, whether it goes to the MLRO, and what you may say to the client. Every answer is marked and explained, and a wrong flag costs a mark: over-flagging is the beginner’s failure mode and scores as badly as missing the thing entirely.

The abbreviations are a different problem — volume rather than judgement — so the 122 of them are drilled by spaced repetition instead, weighted by how likely you are to need them.

Source: FIAU Implementing Procedures, Part I (§7.1, pp. 266–267, last amended 27 April 2026) · recognition by front-line staff at ongoing monitoring, p. 159, last amended 27 April 2026

The same for every role

How the list is drawn

Section 7.2 lists (a) directors, (b) senior management, (c) the MLRO and designated employee(s), (d) compliance staff, and (e) all members of staff involved in activities falling within relevant financial business or relevant activity — and says the duty applies irrespective of level of seniority. Category (e) is where most of a corporate services provider’s people sit, so it is broken out into job families above.

Source: FIAU Implementing Procedures, Part I (§7.2, pp. 267–269, last amended 27 April 2026)

What every role’s training must contain

Section 7.3 sets out what relevant employees are to be knowledgeable of, whichever role they hold. It divides into the firm’s own arrangements and the law behind them.

  • The firm’s CDD measures, record-keeping procedures and internal reporting procedures.
  • The role of the MLRO in filing STRs with the FIAU.
  • Its risk management measures — customer acceptance policies, the customer risk assessment procedure, internal controls, compliance management, communications and employee screening.
  • The ML/FT risks posed by the firm’s own business, meaning the outcomes of its business risk assessment.
  • The PMLA, the PMLFTR, the Criminal Code provisions on the funding of terrorism, relevant data protection law, and the FIAU Implementing Procedures and guidance.
  • The applicable offences and penalties, and the potential effect of a breach on the firm, on employees personally and on customers.

Separately, all employees are to know who their MLRO, any designated employee(s) and the officer carrying out the monitoring function are, together with what those people are responsible for.

Source: FIAU Implementing Procedures, Part I (§7.3, p. 269, last amended 27 April 2026)

Trained to do what

Every role ends in the same place. Recognise, escalate internally to the MLRO, and say nothing to the client. Where the reporting duty sits, what the suspicion threshold is, and what tipping off means are set out in Who must report.

The moments that trigger the question

The duty attaches to the duties a person performs, and the measures are to be taken “from time to time” — meaning on a regular basis rather than once. From an HR point of view that makes the in-scope population a moving target.

  • Someone joins. In all cases, new employees are to be made aware of their responsibilities and those of the firm on being employed or engaged in their relevant position — which covers engagement as well as employment.
  • Someone changes role. Because the programme is set partly on the specific roles of the employees being trained, and because front-office and back-office training are expected to differ, a move between the two raises the question again. Training given for the old function does not answer the new one.
  • The business or the law changes. Legislative changes, new products or services, and new markets are named as inputs to the training programme, alongside the outcomes of the business risk assessment.

Source: FIAU Implementing Procedures, Part I (§7.1, p. 266 and §7.2, p. 268, last amended 27 April 2026)

Method, and the records HR has to keep

No particular method is imposed — online learning, classroom sessions for higher-risk activities, video, external training or procedures manuals are all open, and the firm chooses according to its size and activities. Training should ideally leave employees with material they can refer back to.

The record-keeping is prescriptive, and it is the part that lands on HR. Firms are to maintain records of the training provided, to monitor which employees have received training, how frequently, and of what nature. Training records are to include:

  • the details of the training provider;
  • the date on which training was delivered;
  • the nature of the training;
  • the names of the employees who received training; and
  • where available, a copy of any training materials provided.

Source: FIAU Implementing Procedures, Part I (§7.4, p. 270, last amended 27 April 2026)

Background: the obligation

Every subject person must take appropriate and proportionate measures to ensure employees are aware of the AML/CFT legislation and of the firm’s own measures, policies, controls and procedures, and to provide training in the recognition and handling of operations and transactions that may be related to proceeds of criminal activity, money laundering or the funding of terrorism.

The Implementing Procedures are blunt about what that rules out: there is no place for a ‘one size fits all’ or a haphazard approach to training. The programme is set on the basis of the risks in the firm’s business risk assessment, the specific roles of the employees being trained, and relevant developments such as legislative changes or new products, services and markets.

Source: FIAU Implementing Procedures, Part I (§7.1, pp. 266–267, last amended 27 April 2026) · awareness and training is listed as one of the core AML/CFT obligations at §2.2(d), p. 37, last amended 27 April 2026

Background: why the list runs this far down

Chapter 7 states the duty. The case for taking it past the compliance function is made elsewhere in the document, in two places that are not about training at all.

Ongoing monitoring. The training of employees is described as playing a vital role in the effectiveness of a firm’s ongoing monitoring systems: employees should be properly trained to identify unusual or suspicious transactions and activities, and the red flags associated with the particular customer, service or product. Employees dealing with customers directly are said to be best positioned to recognise and detect suspicious or unusual actions and to flag them before execution. A monitoring system staffed by people who cannot recognise what it is for does not work, however well it is specified.

Internal reporting. The procedure has to set out the steps to follow from the moment an employee becomes aware of information giving rise to knowledge or suspicion. From that moment it is to be treated with the utmost urgency and reported to the MLRO without delay — the FIAU expects the report by no later than the next working day. The clock starts at the employee’s awareness, not when compliance hears about it. An employee who has not been trained to recognise the thing does not start it, and the firm can be late before anyone in compliance knows there was anything to be late about.

Source: FIAU Implementing Procedures, Part I (ongoing monitoring, p. 159, last amended 27 April 2026) · FIAU Implementing Procedures, Part I (§5.4 internal reporting procedures, pp. 232–233, last amended 27 April 2026)

What this is, and what it is not

These are study notes, written while teaching myself Maltese AML/CFT. They are a revision aid and nothing more.

This is not legal or compliance advice, and no accuracy is guaranteed. Nothing here has been reviewed by a qualified practitioner. Reading this page is not training, and it does not discharge any obligation owed by you or by a subject person. The job families under §7.2(e) are this site’s reading of how the category maps onto a corporate services provider; the Implementing Procedures give the category, not the breakdown. The law changes, and pages here may lag behind it.

Where something matters, go to the source: the PMLFTR (S.L. 373.01), the PMLA (Cap. 373), the FIAU Implementing Procedures, or a professional who is paid to be right about it.