In August 2026, Malta’s Sanctions Monitoring Board (“SMB”) issued its first Guidance Note on Article 32 of the National Interest (Enabling Powers) Act, Chapter 653 of the Laws of Malta (“NIA”). The 180-page document sets out, for the first time in this level of detail, how the SMB expects entities within scope (“Operators”) to build and run a sanctions compliance framework.
Who is affected?
Article 32 obligations apply to all Operators listed under Schedule I of the NIA. At present, Schedule I largely mirrors the categories of “subject persons” already caught by the Prevention of Money Laundering and Funding of Terrorism Regulations, meaning most entities with existing AML/CFT obligations are automatically in scope for Article 32 as well.
Where an Operator has branches or majority-owned subsidiaries in third countries, it is expected to extend its sanctions controls to those entities to the extent local law allows, and to document and mitigate any gaps where it does not.
The core building blocks of a Sanctions Framework
The Guidance Note frames Article 32 compliance as a single, integrated “Sanctions Framework” made up of the following components, each addressed in its own chapter:
- Sanctions Risk Assessment (SRA) – identifying and documenting the Operator’s exposure to sanctions risk, including a risk appetite statement, and reviewing it regularly.
- Customer Due Diligence – identifying the client and other parties connected to a relationship or transaction (beneficial owners, controllers, counterparties), and determining who needs to be screened.
- Screening and ongoing monitoring – screening relevant parties against applicable sanctions lists, reviewing potential matches, and repeating screening and transaction monitoring on an ongoing basis.
- Freezing and reporting controls – freezing funds or economic resources where required, and reporting confirmed matches, frozen assets and suspected breaches to the SMB without delay.
- Tipping-off controls – restricting access to sensitive sanctions information and preventing advance disclosure to clients or third parties that a freezing order is being applied.
- Policies, procedures and record-keeping – maintaining documented internal controls and adequate records demonstrating compliance.
- Third-party reliance and outsourcing – ensuring any reliance or outsourcing arrangement does not impair the Operator’s ability to meet its NIA obligations.
- Training, systems and governance – ensuring staff are adequately trained, screening/monitoring systems are properly calibrated and explainable, and senior management provides effective oversight, including appointment of a Sanctions Compliance Officer.
A key theme: looking beyond the immediate client
A recurring message throughout the Guidance Note is that sanctions risk cannot be assessed by reference to the immediate client alone. Designated persons may conceal their involvement through layered ownership structures, intermediaries, or informal control arrangements. Operators are therefore expected to look through the client to beneficial owners, controllers, and other connected parties, and the Guidance Note devotes an extensive annex to worked examples, from private equity funds with layered ownership to foundations without identifiable beneficiaries.
Consequences of getting it wrong
A breach of sanctions is a criminal offence under the NIA and may result in fines and/or imprisonment, alongside regulatory and reputational consequences. The Guidance Note is explicit that where an Operator chooses not to follow it, this may be treated as an aggravating factor in any enforcement action, and that failure to implement appropriate controls may itself be used as evidence in criminal proceedings. A dedicated annex sets out the administrative penalties and criminal offences attaching to specific breaches.
The way forward
At this stage, Operators should review the Guidance Note in detail against their existing AML/CFT and sanctions controls to confirm alignment with the SMB’s expectations, particularly on the Sanctions Risk Assessment, the identification of parties beyond the immediate client, and governance and reporting lines.