The Financial Intelligence Analysis Unit (FIAU) has released its AML/CFT Supervisory Plan for the 2026/2027 annual cycle, setting out the third year of its five-year risk-based compliance monitoring programme, which runs from July 2024 to June 2029. The plan gives subject persons across Malta’s regulated sectors a clear signal of where supervisory attention will fall over the coming year.
A Risk-Based Approach
The FIAU continues to calibrate its supervisory interventions, ranging from AML/CFT returns and policies and procedures reviews to full-scope and thematic on-site inspections, according to three factors:
- the ML/TF risk exposure of the relevant sector;
- the individual risk profile of the subject person; and
- emerging typologies and priorities identified at national and European level.
Every subject person may generally expect at least one supervisory intervention over the course of the five-year compliance monitoring plan, though the actual frequency remains risk-sensitive and firms with a higher risk profile may be selected for further interventions at any time.
Sector-Specific Priorities
Each sector faces a distinct thematic focus for 2026/2027. Credit and financial institutions will be assessed on STR/SAR reporting and the application of the risk-based approach, while financial institutions offering virtual IBAN services face scrutiny of related controls. CASPs will be examined on STR/SAR compliance and, notably, the effective implementation of the Travel Rule and wallet-related verifications. CSPs can expect focus on transaction monitoring tied to directorship services, while notaries and real estate agents face targeted reviews of real estate financing sources and CDD on high-value lettings respectively. Trustees and fiduciaries, auditors, accountants and investment services providers round out the sector list, with targeted focus on STR/SAR reporting and ongoing monitoring obligations.
Two Constants: TF and the Travel Rule
Regardless of scope, every intervention will assess how subject persons identify and mitigate terrorist financing risk within their control frameworks. Travel Rule compliance also receives standing attention across sectors subject to that requirement, not just CASPs.
What This Means for Subject Persons
Subject persons, should be aware of their sector’s flagged topic and get ahead of it. For example, CSPs should review how directorship-related transaction monitoring is documented, while CASPs should stress-test Travel Rule workflows and wallet verification processes now, before an intervention is scheduled. Firms across all sectors would also do well to revisit their STR/SAR reporting lines, given its recurrence as a cross-sectoral priority. Lastly, the FIAU has made clear that turnover in the MLRO or compliance liaison role is not, on its own, grounds to defer a scheduled review, so succession and handover planning for that function deserves attention alongside the technical preparation.
The FIAU’s supervisory plan may be accessed below:
https://fiaumalta.org/app/uploads/2026/08/The-AMLCFT-Supervisory-Plan-2026-–-2027.pdf