The Malta Gaming Authority (MGA) has identified weaknesses in decision-making, internal challenge and audit documentation following a thematic review of governance arrangements among licensed B2B suppliers and B2C operators.
The review examined how CEO, compliance, internal audit and prevention of money laundering and terrorist financing functions operated in practice. Evidence was gathered through supervisory reviews and meetings with a sample of authorised persons.
The regulator found that many licensees had established governance frameworks supported by senior management involvement and increasingly risk-based compliance and assurance processes.
However, it also found cases where decision-making remained concentrated among a small number of senior executives.
Other recurring issues included insufficient evidence that strategic proposals had been challenged before approval, limited assessment of the regulatory impact of major business decisions and weaknesses in audit trails documenting how conclusions had been reached.
These shortcomings can reduce the ability of compliance, internal audit and AML/CFT personnel to demonstrate effective oversight, particularly when operators enter new jurisdictions, launch products or make significant changes to their corporate structures.
The MGA said stronger governance arrangements gave key function holders sufficient authority and independence to escalate concerns. Effective frameworks also included governance committees, structured escalation processes, risk-based monitoring and cooperation between separate assurance functions.
Governance assurance was one of the supervisory priorities established by the Authority for 2025, alongside reviews covering operational resilience, self-exclusion systems and player protection controls.
The programme forms part of a wider move towards supervision based on the risks posed by individual licensees rather than relying primarily on standard compliance checks.
AML/CFT controls remain a significant part of that framework. Malta’s Financial Intelligence Analysis Unit treats remote gaming operators as subject persons and applies sector-specific guidance, risk assessments and supervisory examinations.
The MGA intends to use the findings to help authorised persons assess whether their governance structures provide effective accountability and whether key function holders can influence business decisions rather than operating as procedural or reporting roles.
The findings follow the MGA’s 2025 Annual Report, which showed that it completed 109 thematic reviews, issued 19 licences and imposed 30 administrative penalties worth €162,520 ($185,743).
MGA licensees must appoint approved individuals to key functions, with responsibilities allocated according to the services provided and the risks arising from their operations