MFSA Thematic Review – Essential Insights on the Risk Management Function of CSPs

On the 25th November 2025, the Malta Financial Services Authority (“MFSA”) issued a Dear CEO Letter summarising the findings of their Thematic Review on the effectiveness and resilience of the Risk Management Function within Company Service Providers (“CSPs”). The review forms part of the MFSA’s 2025 Supervisory Priorities, which place strong emphasis on governance, risk culture, and outcomes-based supervision.

The Thematic Review involved a risk-based approach by selecting ten out of sixty-one Class C CSPs (16.4% of the total) that have an independent risk management function. Of these, nine were corporate CSPs and one was a natural person.

The MFSA assessed the practical implementation of risk frameworks, including Money Laundering (“ML”)/Financing of Terrorism (“FT”) and non-ML/FT risks. While the MFSA acknowledged the progress achieved since the introduction of the CSP Rulebook, it also identified recurring weaknesses across the sector.

Key Findings

The MFSA highlighted several areas requiring urgent attention:

1. Insufficient Identification of Non-ML/FT Risks – CSPs often failed to properly identify or assess risks such as reputational risk (especially from clients with whom they had lost contact), outsourcing risk, and cybersecurity risk.

2. Weaknesses in Risk Controls and Documentation – Controls were frequently generic or inadequately matched to the specific risk. In addition, testing of controls was often carried out but not formally documented, limiting the Board of Directors’ ability to assess their effectiveness.

3. Deficiencies in Risk Registers – Although all CSPs maintained a risk register, many did not meet Rulebook requirements, particularly in identifying risks inherent to each client’s business model and linking them to client risk ratings.

4. Cybersecurity Gaps – Many CSPs rely heavily on outsourced IT providers yet struggled to articulate their own cybersecurity risk frameworks or testing procedures. Concerningly, some did not have formally documented escalation procedures for cyber incidents.

5. Inconsistent Board Reporting – While most Risk Officers reported to the Board of Directors, risk reports often lacked detail, particularly on control testing, emerging risks, and actionable recommendations.

MFSA Expectations and Next Steps

The MFSA has urged all CSPs (not only those reviewed in the Thematic Review) to conduct and document a comprehensive gap analysis of their Risk Management Function against the findings of the review. This should include:

  • Enhancing non-ML/FT risk identification and assessment;
  • Strengthening and documenting risk control testing;
  • Aligning risk registers with CSP Rulebook requirements;
  • Improving cybersecurity governance and internal escalation processes; and
  • Ensuring regular, structured and well-documented risk reporting to the Board of Directors.

The Authority expects CSPs to apply a proportionate approach based on the size, nature and complexity of their operations while reinforcing the Three Lines Model (a widely used risk-management and governance framework) and overall risk culture.

This Thematic Review signals a clear supervisory direction: risk management within CSPs is no longer a purely formal obligation but a core governance function subject to intensified scrutiny. CSPs should act proactively to address gaps, strengthen controls, and demonstrate effective Board of Directors oversight of risk.

Please feel free to contact our Corporate Services team to learn more about strengthening and effectively managing the risk management function of CSPs.

The full MFSA Dear CEO Letter can be accessed here.