TITLE: Malta Financial Services Authority Issues Q2 Dear Chief Executive Letters on Supervisory Expectations
BODY:
On July 8, 2026, the Malta Financial Services Authority (MFSA) published a series of Dear Chief Executive Letters outlining supervisory findings and expectations across multiple financial services sectors. The letters address outcomes-based supervision reviews conducted during the second quarter and provide guidance on key regulatory priorities.
The MFSA conducted cross-sector reviews of complaints handling frameworks across credit institutions, insurance undertakings and investment firms, identifying weaknesses in complaints policies, governance oversight and root cause analysis. The Authority expects firms to maintain comprehensive policies and accurate complaints registers, integrate complaints handling within conduct risk management frameworks, and use complaints data to identify systemic issues. A separate review of Pillar 3 disclosures by credit institutions found general compliance with Capital Requirements Regulation (CRR) requirements but identified gaps in completeness, consistency and governance oversight. The MFSA expects institutions to strengthen review and validation processes and maintain adequate documentation supporting disclosure decisions.
The Authority outlined supervisory expectations for artificial intelligence (AI) governance within financial services, emphasising that boards and senior management must retain responsibility for AI systems. Firms should incorporate AI-related risks into existing risk frameworks and assess risks from external AI providers. Marketing practice reviews of investment firms and insurance entities identified deficiencies in policy granularity, post-publication monitoring, record-keeping and risk disclosures. The MFSA expects licensed entities to implement procedures ensuring marketing materials are fair, clear and not misleading. Additional letters addressed internal liquidity adequacy assessment processes, terrorist financing and proliferation financing risks, Payment Services Directive 3 (PSD3) preparation, authorisation process redesign, and financial analysis of (re)insurance undertakings. The MFSA encouraged participation in the EU Commission's targeted consultation on Markets in Crypto-Assets Regulation (MiCA) review, with responses due by August 31, 2026.
Licensed entities should review findings outlined in the letters and implement necessary remedial actions. The MFSA will conduct follow-up assessments throughout its three-year supervisory cycle to verify compliance with outlined expectations. Firms are encouraged to initiate early preparatory work for PSD3 transition requirements.
REFERENCES:
Malta Financial Services Authority. (2026, July 8). Dear CEO Letters – Q2 Round-Up. Retrieved from https://www.mfsa.mt/