The Malta Financial Services Authority (“MFSA”) recently issued guidance on how financial entities should report their Register of Information (“RoI”) under the Digital Operational Resilience Act (“DORA”). This Circular affects banks, investment firms, fund managers, payment institutions, and any other financial entity that falls within the scope of DORA. While the rules are detailed, getting ahead of them now can save time and ensure a smooth reporting process when the first official submissions begin in 2026.
So, what exactly is the Register of Information? Simply put, it’s a comprehensive record of a firm’s relationships with all ICT Third-Party Service Providers (“ICT TPPs”). This register allows regulators, including the European Supervisory Authorities (“ESAs”), to identify which providers are critical and may require additional oversight. Think of it as a way for your firm to show regulators that you have a clear understanding of your operational landscape and are proactively managing your digital risks.
Starting in 2026, all authorised financial entities in Malta must submit their full RoI annually to the MFSA. Submissions should be made between 1 January and 21 March of each year, using 31 December of the previous year as the reference date. For example, the 2026 submission will reflect information as of 31 December 2025. For credit institutions directly supervised by the European Central Bank (“ECB”), guidance from the ECB will take precedence.
The MFSA has made it clear that RoI submissions must be done through their LH Portal. Access to the RoI project page is required, and if it’s not visible, your team can request access by emailing [email protected] with the relevant details. A submission is only considered compliant once it’s marked as “Accepted” on the LH Portal. If it’s “Rejected,” the issues identified must be addressed, and the RoI resubmitted. The MFSA is not a technical support provider, so preparing the RoI correctly and in the right format (plain CSV) is the responsibility of each entity.
It’s important to note that these deadlines are regulatory obligations. Missing the submission window or failing to provide a fully validated RoI could result in enforcement action under L.N. 166 of 2024 and the MFSA Act.
For firms looking for guidance, there are several resources available. The MFSA’s ICT Third-Party Risk section, the EBA DORA webpage, and the DORA Level 1 and Level 2 texts all provide instructions, templates, and technical guidance. Keeping your RoI aligned with the latest Reporting Technical Package is essential, as updates from the ESAs may occur periodically.
At Zerafa Advocates, we help financial entities make sense of these requirements and take the stress out of compliance. We work with clients to map ICT outsourcing arrangements, structure their RoI correctly, and implement reporting workflows that ensure submissions are timely and fully compliant. Preparing your RoI in advance not only keeps you in line with the MFSA but also strengthens your firm’s overall operational resilience and oversight of critical ICT relationships.
Being proactive is key. With the first full RoI submissions only a few months away, now is the perfect time to review your ICT third-party arrangements and make sure your reporting is ready. Our team of regulatory experts is here to guide you every step of the way, from preparing your RoI to implementing internal processes that make future reporting easier.
Reach out to us today to ensure your firm is fully prepared for DORA compliance and can approach 2026 with confidence.
