Outcomes Based Supervision Credit Institutions, Insurance Undertakings & Investment Firms – Complaints Handling
The MFSA conducted a cross-sector review of complaints handling frameworks across credit institutions, insurance undertakings and investment firms, assessing governance, complaints management processes, root cause analysis, consumer communications and compliance with conduct requirements.
Key Findings: The review identified weaknesses in complaints policies, registers, governance oversight and root cause analysis. Firms also demonstrated inconsistencies in complaint handling timelines, transparency of procedures, communication of escalation rights, and monitoring of complaints trends.
Supervisory Expectations:
- Governance and Oversight: Complaints handling frameworks should be effectively governed, regularly reviewed and integrated within conduct risk management.
- Complaints Management: Firms should maintain comprehensive policies and accurate complaints registers.
- Root Cause Analysis: Complaints data should be used to identify systemic issues and support remediation.
- Consumer Communication: Complaints procedures should be transparent and supported by timely communication, including information on escalation rights.
Thematic Review of Pillar 3 Disclosures – Supervisory Findings and Expectations
The MFSA assessed the quality and consistency of Pillar 3 disclosures published by credit institutions, focusing on compliance with CRR disclosure requirements, governance arrangements, and the effectiveness of controls supporting regulatory disclosures.
Key Findings: While institutions generally complied with Pillar 3 requirements, the review identified areas for improvement relating to the completeness and consistency of disclosures, governance oversight, documentation of disclosure decisions, and the alignment between Pillar 3 disclosures and regulatory reporting.
Supervisory Expectations:
- Governance and Oversight: Clear accountability and effective oversight should be established for the preparation and approval of Pillar 3 disclosures.
- Disclosure Controls: Institutions should strengthen review, validation and reconciliation processes to ensure accurate and consistent disclosures.
- Transparency: Qualitative disclosures should provide clear and meaningful information on the institution's risk profile and risk management practices.
- Documentation: Adequate records should be maintained to support disclosure decisions and internal review processes.
Artificial Intelligence (AI) – Governance, Risk and Prudential Expectations
The MFSA outlined supervisory expectations for the use of AI within the financial services sector, emphasising governance, risk management, operational resilience and prudential considerations in line with emerging regulatory developments.
Key Findings: While AI adoption remains at an early stage, institutions are increasingly deploying AI solutions across business and control functions. The review highlighted the need for stronger governance, clearer accountability, enhanced third-party oversight and more comprehensive risk assessments.
Supervisory Expectations:
- Governance and Accountability: Boards and senior management should retain responsibility for AI systems and their oversight.
- Risk Management: AI-related risks should be incorporated into existing risk and control frameworks.
- Third-Party Risk: Firms should assess and manage risks arising from external AI providers.
- Self-Assessment: Institutions should identify governance and control gaps through regular AI risk assessments.
Insurance Entities: Outcomes Based Supervision 2025 & Investment Firms: Outcomes Based Supervision 2025
The Malta Financial Services Authority (“MFSA”) has issued a Dear CEO Letter outlining the findings of the Outcomes Based supervision thematic review on marketing practices adopted by Investment firms and Insurance entities. The reviews form part of the Authority’s high-level supervisory priorities for 2025, primarily aiming to ensure that advertisements relating to financial products and services are fair, clear and not misleading, and that clients are not enticed to purchase products that do not align with their needs, objectives and risk profile.
The MFSA has assessed a number of authorised insurance entities and investment firms based on the volume of marketing materials distributed during 2024. Key findings from the MFSA’s review were:
1. Granularity of Policies and Procedures
It was observed that in certain instances, the marketing policies and procedures submitted for the scope of this exercise, did not reflect the processes applied in practice.
2. Review of Policies and Procedures
It was observed that the marketing policies and procedures referred to above, were reviewed on an ad hoc basis rather than at pre determined, regular intervals. Furthermore, it was noted that certain investment firms did not include such reviews into the Compliance Monitoring Programme.
3. Updating of Marketing Material relating to specific products
While in practice monitoring might be conducted to ensure that marketing material is up to date, it was noted that certain i entities had no formal monitoring procedures in place. Other entities, included such reviews within their compliance monitoring plans, however they were not formally documented within their policy framework whereas in other instances policies reflected such monitoring, however, were not evidenced in the compliance monitoring plan.
4. Marketing Reviews as part of the Compliance Monitoring Programme
The review found that certain investment firms lacked a structured approach to post-publication monitoring of marketing materials. In some cases, no post-publication checks were performed, while in others such checks were conducted infrequently or only after considerable delays.
5. Recording of Marketing Material
In terms of record keeping practices of marketing material, it was noted that marketing logs were not always kept in line with the requirements set out in the Conduct of Business Rulebook (“COBR”).
6. Recording of breaches relating to Marketing Material
It was observed that certain entities do not maintain records of shortcomings identified following the publication of the marketing material. As a result, structured remedial actions are not implemented, increasing the risk of recurrence.
7. Record-Keeping of advertisements issued by Tied Insurance Intermediaries (“TIIs”)
When it comes to the issue of advertisements by Tied Insurance Intermediaries, it transpired that there certain principals were not maintaining separate records relating to the approval of adverts issued by their TIIs, as outlined in the COBR.
8. Disclosures
The Authority observed, especially in the context of investment firms, that certain marketing materials referred to benefits without providing balanced disclosure of the associated risks. Additional shortcomings included the absence of hyperlinks to external websites, references to the Authority that could be construed as implying approval or endorsement of a service, and incomplete or missing regulatory disclosures.
9. Target Market and Appropriate Distribution Methods
It was observed that, in certain instances, in the case of investment firms, marketing communications were not adequately targeted to the relevant client groups, potentially resulting in information being distributed to recipients outside the intended target market.
10. Training for Third-Party Service Providers
It was observed that certain investment firms did not provide training to third-party service providers involved in the marketing materials process. In such cases, firms either provided feedback to the relevant service providers or did not provide training where the service providers' role was limited to the distribution of marketing materials.
Next Steps
The MFSA expects that licensed entities implement appropriate internal procedures to ensure that marketing material is fair clear and not misleading to its ultimate target audience. The Dear CEO Letter outlines observations to be addressed and expectations for all licensed entities, including licence holders which were not directly assessed in 2025.
The authority will continue engaging with the licensed entities as this three-year supervisory cycle progresses, through a follow-up to determine whether the findings outlined within this letter have been addressed.
The Malta Financial Services Authority’s Minimum Expectations on the Authorised Person’s preparedness for Payment Services Directive 3
In anticipation of the application of the Payment Services Directive 3 (PSD3), the FinTech Supervision function continues to actively engage with stakeholders through a programme of industry events, targeted discussions, and outreach initiatives. These engagements are intended to raise awareness of the forthcoming regulatory changes while encouraging licence holders to adopt a structured and forward-looking approach to their preparations.
A key priority at this stage is the reauthorisation process that existing authorised persons will be required to undergo in order to operate under the PSD3 framework. This process is expected to be comprehensive and will require firms to demonstrate alignment with enhanced requirements across governance, risk management, operational resilience, and prudential standards.
To support firms in navigating this transition, the Authority is in the process of issuing a dedicated “Dear CEO” letter to all relevant licence holders. This communication will set out the key elements of the reauthorisation process, clarify supervisory expectations, and outline the minimum standards that the Authority expects firms to meet as part of their transition planning.
In view of the limited timeframe that is expected to be available once PSD3 becomes applicable, authorised persons are strongly encouraged to initiate preparatory work at an early stage. This should include conducting a gap analysis against the anticipated requirements, identifying key areas requiring enhancement, and allocating sufficient internal resources to support implementation efforts. Early engagement and proactive planning will be important in facilitating a smooth and efficient transition.
The FinTech Supervision function will continue to monitor developments at European level and remains committed to maintaining an open dialogue with stakeholders throughout the preparatory phase.
Redesign of the Authorisation Process
The redesign of the authorisation process is progressing with a strong focus on enhancing operational efficiency throughout the application lifecycle, while ensuring that all necessary regulatory assessments continue to be carried out effectively.
Key improvements are aimed at streamlining procedures by requesting only the information required for assessment and in a format that facilitates efficient processing. The initiative seeks to eliminate unnecessary steps and duplication, while maintaining full regulatory compliance and robust supervisory standards.
Overall, the updated process is intended to deliver a more efficient, effective, and transparent authorisation framework, enhancing both the applicant experience and internal processing capabilities without compromising the quality and integrity of authorisation assessments.
The EU Commission’s Consultation on the Review of Regulation on the Markets in Crypto-Assets (MiCA)
On 20 May 2026, the EU Commission launched a Targeted Consultation on the review of the Markets in Crypto-Assets Regulation (MiCA). The Malta Financial Services Authority (MFSA) has issued a letter to CEOs, industry experts, and representatives of Malta's crypto-assets sector, urging active participation in this consultation. The consultation is accessible via a dedicated link on the Commission's website and comprises both a general public consultation and a more technical/legal targeted consultation aimed at industry stakeholders.
The targeted consultation is structured into four parts. Part 1 addresses Title II of MiCA, covering crypto-assets other than Asset-Referenced Tokens (ARTs) and E-Money Tokens (EMTs), including questions on MiCA's scope, classification of crypto-assets, transparency obligations, and the ex-post supervisory control regime.
Part 2 focuses on Titles III and IV, dealing with ARTs and EMTs respectively. This section covers stablecoins' future regulatory role, prudential frameworks and capital requirements, liquidity and reserve obligations, criteria for designating ARTs/EMTs as "significant," prohibitions on interest payments, redemption rights, stability concerns, global stablecoin arrangements, interaction with broader regulatory frameworks, implications for EU economic security and the international role of the euro, and existing versus potential additional safeguards.
Part 3 examines Title V, concerning authorisation and operating conditions for Crypto-Asset Service Providers (CASPs). It explores crypto-asset services, prudential requirements applicable to CASPs, treatment of multi-function groups, activity reporting obligations, environmental and sustainability disclosure requirements, and other related matters.
Part 4 looks beyond MiCA's current scope, addressing emerging topical issues such as decentralised finance (DeFi), staking, lending and borrowing activities involving crypto-assets, non-fungible tokens (NFTs), prediction markets and perpetual futures, tokenised deposits, the legal classification of tokens, and conflict-of-laws considerations. This section also includes an open-ended question allowing stakeholders to raise any additional relevant issues not otherwise addressed.
The MFSA emphasises the importance of industry feedback given the technical and legal complexity of the questions posed, and strongly encourages eligible entities to submit responses. The deadline for submission of feedback to the EU Commission is 31 August 2026.
Compliance Outcomes-Based Supervision: The Internal Liquidity Adequacy Assessment Process
The review assessed how institutions have translated liquidity and funding regulatory requirements and supervisory expectations into practice. Particular focus was placed upon the adequacy and effectiveness of institutions’ internal controls, risk management frameworks, and the extent of their alignment with applicable regulatory requirements (CRR, BR/05, BR/24, BR/26) and supervisory expectations.
Key Findings: While encouraging progress has been observed, some gaps remain across a number of institutions. Areas for further enhancement include strengthening the completeness and integration of RAFs, expanding internal audit coverage, and making greater use of reverse and alternative stress‑testing scenarios.
Supervisory Expectations:
- Internal Governance and Oversight: Institutions should ensure that the ILAAP frameworks adequately identify and assess material liquidity risks, including clear documentation of underlying assumptions and parameters.
- Risk Appetite Frameworks: Institutions should define institution-specific liquidity risk metrics and limits, beyond regulatory ratios to support effective risk identification and management.
- Stress Testing Framework: Implementation of stress testing scenarios which are sufficiently severe, relevant, and tailored to the institution’s risk profile, including the use of alternative scenarios.
Mitigating Terrorist Financing, Proliferation Financing and Targeted Financial Sanctions Evasion Risks in Credit Institutions
The Financial Crime Compliance Function within the Malta Financial Services Authority has issued a Dear CEO letter outlining the outcomes of its thematic review on terrorist financing, proliferation financing and targeted financial sanctions evasion risks within credit institutions.
Terrorist financing, proliferation financing, and the evasion of targeted financial sanctions remain critical and evolving threats to the integrity of the global financial system. Recent findings by the Financial Action Task Force (FATF) indicate that, although terrorist groups have diversified away from traditional financial services, they continue to exploit these channels to raise, move, and access funds. Increasingly, a convergence is emerging between conventional methods and innovative digital technologies. This fusion has added complexity to financial crime detection and mitigation. At the same time, the FATF highlights the growing sophistication of actors engaged in sanctions evasion and proliferation financing, employing intricate structures to bypass established controls.
Within this context, and in light of Malta’s national risk profile, the importance of strong, adaptive, and forward-looking control frameworks for credit institutions is paramount. Strengthening these frameworks is essential not only for safeguarding Malta’s financial system but also for contributing to global efforts against illicit finance.
This thematic review, informed by Malta’s National Risk Assessment and recent regulatory developments, including the EU Instant Payments Regulation, the EBA Restrictive Measures Guidelines, and FATF publications, covers all MFSA-licensed Credit Institutions. The review was structured across six key areas namely; risk governance, customer identification, transaction monitoring, sanctions screening, artificial intelligence, and training.
The Dear CEO letter notes that while sound practices are already in place, the guidance highlights opportunities for further enhancement to better align with supervisory expectations. The MFSA extends its appreciation to all participating Credit Institutions and reiterates its commitment to supporting the sector through continued guidance aimed at promoting robust governance and compliance standards.
The Ongoing Financial Analysis of (Re)Insurance Undertakings
This Dear CEO Letter outlines the supervisory approach adopted by the MFSA’s Insurance and Pensions Supervision Function (“IPS”) in relation to financial reviews and regulatory reporting for authorised (re)insurance undertakings. The publication provides an overview of the quarterly and annual financial regulatory returns submitted to the Authority, the review processes undertaken by MFSA Financial Analysts, and the Authority’s expectations regarding financial resilience, solvency oversight, governance, and data quality. The letter also reinforces the importance of accurate, consistent, and comprehensive regulatory submissions in supporting effective supervision and maintaining confidence and stability within Malta’s insurance sector.
