ATLAS
← Back to News and Insights

MFSA enforcement record exposes reporting and safeguarding failures

4 min

The report puts Licence Holders on notice: late filings can attract penalties without reminders, while safeguarding remains an ongoing obligation requiring evidence of segregation, reconciliations and escalation.

LinkedIn Post
MFSA enforcement record exposes reporting and safeguarding failures
Malta · Photo: Michail Tsapas / Unsplash

The Malta Financial Services Authority (MFSA) recorded 91 enforcement actions and administrative penalties totalling €570,673 in its 2025 enforcement report. Reporting failures accounted for most completed actions, while safeguarding breaches contributed to a licence cancellation and further investigations remain ongoing.

The MFSA also handled 943 potential enforcement cases arising from supervisory work and other sources. The figures describe different stages: 91 completed actions and a wider pool of matters considered for possible enforcement.

The totals do not show that every potential case became a sanction. The MFSA says safeguarding investigations remain ongoing.

Reporting deadlines drove most completed actions

The clearest completed-action pattern concerns regulatory reporting. The MFSA says 63 administrative penalties involved the late or non-submission of statutory documentation, representing approximately 69% of all enforcement actions. Of those cases, 25 concluded through settlement.

The Authority said "timely and accurate regulatory reporting is a core obligation" that cannot be delegated. It also said it does not issue reminders for deadlines and grants extensions only in exceptional circumstances.

The report does not create a new reporting rule. It shows how existing submission duties produced most of the enforcement actions recorded for 2025.

The non-delegation statement applies to the licence holder. As an operational read-across, rather than an additional MFSA requirement, a firm using a third-party preparer or another group function should retain accountable ownership of the submission. The absence of an MFSA reminder does not change the deadline position stated by the Authority.

The same distinction applies to control design. The report supports testing whether each statutory submission has an accountable owner, a known deadline and a process capable of delivering complete and accurate information on time. The MFSA report does not prescribe that testing method.

The enforcement activity was not limited to reporting. The MFSA said its Enforcement Function investigated potential unauthorised business, scams, and governance and internal-control deficiencies identified through supervisory work. These are areas of investigation, not proof that each potential case resulted in a finding or penalty.

Safeguarding failures reached licensing consequences

The second material theme concerns the protection of client funds. The MFSA identified shortcomings among certain financial institutions, including payment institutions and electronic money institutions. The findings included inadequate segregation of client funds, insufficient or irregular reconciliations, and weak governance and internal-control frameworks.

The Authority said safeguarding obligations constitute both an authorisation requirement and an ongoing obligation. This links the conditions for obtaining permission to operate with the controls that must continue after authorisation. Segregation, reconciliation, governance and internal control are therefore continuing obligations, not one-off application matters.

The enforcement consequence can include licence cancellation. The MFSA said it cancelled the licence of a financial institution in 2025, in part because of safeguarding breaches. The report does not identify the institution in the supplied material, quantify affected client funds or set out the full legal basis and procedural posture of the decision. It does, however, establish a connection between safeguarding failures and a licensing outcome.

Further safeguarding investigations remain ongoing. The reported cancellation is a completed action, while the other investigations are unresolved matters rather than future sanctions.

The report does not announce a new safeguarding rule or filing calendar. Its value lies in showing how the MFSA used existing obligations in practice during 2025.

For reporting teams, the enforcement record puts emphasis on timeliness, accuracy and retained responsibility. The high share of actions linked to late or missing statutory documents makes submission discipline a measurable enforcement exposure. Reviews should start with the obligations and deadlines already applying to the licence holder, rather than assumptions about new requirements.

For payment and electronic money institutions, the safeguarding findings identify the controls named by the Authority: segregation of client funds, regular reconciliations, governance and internal-control frameworks. As an operational read-across, a firm can use those findings to test whether its controls operate consistently and whether weaknesses are identified and escalated. That is analysis, not a finding that every firm in those sectors is deficient.

The next supervisory test is whether the ongoing safeguarding investigations produce published enforcement decisions or further licensing action.

Official source: Malta Financial Services Authority (MFSA)
Financial ServicesEnforcement ActionsLicence ChangesEnforcement Sanctions

Permanent link to this Atlas analysis

Continue with coverage connected by market, topic and operating context.

Continue with Atlas

Move from this development into the relevant research, comparison and workflow.