The Financial Intelligence Analysis Unit (“FIAU”) has issued a new Guidance Note for Limited (Registered) Company Service Providers (“CSPs”), providing clarity on how small-scale CSPs should meet their anti-money laundering and countering the financing of terrorism (“AML/CFT”) obligations in Malta. This development follows reforms to the Company Service Providers Act and the Prevention of Money Laundering and Funding of Terrorism Regulations (“PMLFTR”), which created a new category of limited CSPs. These are individuals who typically hold a small number of directorships or company secretary appointments, capped at ten, and therefore operate on a much more restricted scale than fully authorised CSPs.
The FIAU recognises that applying the same regulatory standards to both large-scale corporate service providers and individuals carrying out limited activities would be disproportionate. For this reason, the Guidance Note seeks to strike a balance: easing certain documentation and procedural requirements while retaining the fundamental AML/CFT safeguards that are necessary to protect the integrity of Malta’s financial system. The note makes it clear that the scope of this guidance is confined to registered CSPs. Those who are merely notified, referred to as restricted CSPs, are not considered subject persons under the PMLFTR and are therefore not subject to these obligations. However, if a registered CSP undertakes any additional relevant financial activity, they will be required to comply with the full AML/CFT regime applicable to subject persons.
A key area addressed by the guidance is risk assessment. Under the PMLFTR, subject persons are required to identify and assess the risks of money laundering and terrorist financing to which they are exposed. The FIAU acknowledges that, for limited CSPs, a full documented business risk assessment and a detailed risk methodology for each engagement may be excessive. As such, these providers are not obliged to draft a formal business risk assessment or to record their risk methodology for individual clients. Nevertheless, they are still required to understand the risks that their activities present, to remain familiar with the findings of national and supranational risk assessments, and to keep a basic record of their engagements together with the level of risk they assign to each one.
The guidance also takes a flexible approach to policies, procedures, and controls. While the law generally requires subject persons to adopt documented measures and policies to mitigate risks, the FIAU does not expect limited CSPs to maintain a formalised procedures manual. Instead, these individuals should be able to explain the AML/CFT measures they apply and demonstrate how these measures are proportionate to the nature and scale of their activities. This is particularly important in the context of supervisory examinations or compliance reviews, where the ability to articulate and justify one’s approach is just as valuable as a written manual.
From a reporting and registration perspective, the Guidance Note outlines several simplifications. Limited CSPs do not need to register themselves on CASPAR, the centralised register, since the Malta Financial Services Authority (“MFSA”) will handle the process by transmitting the necessary details to the FIAU. These CSPs are also exempt from submitting the Risk Evaluation Questionnaire unless they are involved in other financial or relevant business. However, they remain obliged to file an annual return with the MFSA, which enables both the Authority and the FIAU to assess the risks connected to their activities. Importantly, they must still register on the FIAU’s goAML platform and submit suspicious transaction reports (“STRs”) whenever necessary, as well as respond to any requests for information.
It is important to underline that this proportionality does not amount to a waiver of the law. All limited CSPs remain subject to the obligations set out in Regulation 7 onwards of the PMLFTR, including the requirement to apply customer due diligence, monitor relationships on an ongoing basis, and retain records in line with Regulation 13. The relaxation mainly concerns the extent of documentation expected, but not the substance of the obligations themselves. Furthermore, if a registered CSP broadens their activities beyond the limited scope permitted under their registration, they will automatically be required to comply with the full AML/CFT framework, unless a specific exemption applies.
In conclusion, the FIAU’s Guidance Note introduces a more proportionate compliance regime for limited CSPs. It acknowledges their smaller scale and limited exposure while ensuring that they remain integrated within Malta’s AML/CFT system. By easing unnecessary administrative burdens but maintaining the core duties of vigilance, reporting, and record-keeping, the guidance ensures that Malta upholds high standards of financial integrity without over-regulating those who operate in a limited and low-risk capacity.
This Guidance Note is a welcome example of regulatory calibration: it recognises that not all CSPs are large firms with resources, and it adjusts expectations accordingly. But it also maintains the integrity of Malta’s AML/CFT regime ensuring small operators remain transparent, accountable, and integrated into the oversight system.
