Newsfeed
August 21, 2026
On 20th August 2026, the Sanctions Monitoring Board (“SMB”) has published a comprehensive Sanctions Compliance Requirements Guidance Document (the “Guidelines”) to assist persons, entities and bodies better understand and implement internal policies, procedures and controls in terms of Article 32 of the National Interest (Enabling Powers) Act – Chapter 653 of the Laws of Malta (“NIA”). The Guidelines introduce a structured sanctions compliance framework that is legally binding and intended to strengthen Malta’s sanctions implementation regime.
Article 32 of the NIA establishes a number of core obligations intended to ensure that persons, entities and bodies can identify and prevent breaches or circumvention of restrictive measures, inter alia including the identification and verification of customers and beneficial owners, customer and transactions’ screening, reporting of sanctions hits and suspicious activities and record keeping.
These requirements apply to persons, entities and bodies listed under Schedule I of the NIA, i.e., natural or legal person conducting a relevant activity or relevant financial business as defined in accordance with the Prevention of Money Laundering and Funding of Terrorism Regulations (“PMLFTR”) – subject persons. However, the NIA allows for amendments within Schedule I and therefore the requirements included under Article 32 can be further extended to other persons, entities and bodies, herein referred to as “operators”.
At the core of the Guidelines is the requirement to conduct an enterprise-wide Sanctions Risk Assessment (“SRA”). Operators are expected to identify, assess, and mitigate sanctions risks arising from their customers, products, services, jurisdictions, delivery channels, and transactions. The SRA must be proportionate to the nature, size, and complexity of the business and should actively inform the design of sanctions controls. The SMB further expects firms to establish a documented sanctions risk appetite and ensure ongoing review of sanctions risks, particularly following changes in business activities, customer profiles, or sanctions regimes.
A significant portion of the Guidelines focuses on sanctions-specific customer due diligence. Operators are required to look beyond the customer and assess ownership, control, counterparties, intermediaries, and other parties connected to a business relationship or occasional transaction.
The Guidelines highlight important differences between AML/CFT beneficial ownership requirements and sanctions ownership assessments. Sanctions assessments and analysis require consideration of ownership and control structures that may result in designated persons collectively reaching a 50% ownership threshold, or otherwise exercising control over an entity. Operators are therefore expected to assess both ownership and control risks comprehensively, and enhanced due diligence should be applied where sanctions risks are elevated, particularly where complex ownership structures, sanctioned jurisdictions, unusual transaction patterns, or potential sanctions circumvention indicators are identified. The Guidelines also provide detailed practical examples and case studies of how control may manifest itself in practice.
The Guidelines emphasize that sanctions compliance is an ongoing obligation. Operators are expected to screen customers following sanctions list updates, maintain up-to-date customer information, monitor transactions for sanctions red flags, specifically those transactions involving sanctioned or high-risk jurisdictions, complex payment chains, shell entities, unusual routing arrangements, trading in restricted goods, and structures designed to conceal ultimate beneficiaries, and periodically reassess customer risk ratings.
Where a designated person or sanctioned entity is identified, operators must immediately freeze funds and economic resources and refrain from making assets available, directly or indirectly, to sanctioned parties. The Guidelines clarify that freezing obligations extend beyond cash funds and may include securities, crypto-assets, real estate, vessels, intellectual property, and other economic resources. Confirmed sanctions hits, frozen assets, and suspected sanctions breaches or circumvention attempts must be reported promptly to the SMB. Equally important, reporting obligations also apply even where no designated person is identified, but there are reasonable grounds to suspect sanctions evasion or circumvention.
The SMB expects sanctions compliance to be embedded into governance arrangements through clear allocation of responsibilities, senior management oversight, escalation procedures, and the appointment of a Sanctions Compliance Officer or equivalent function. Operators must also maintain documented policies and procedures, implement appropriate sanctions screening and monitoring systems, retain relevant records for at least five years, and provide staff with regular sanctions training tailored to their exposure to sanctions risks.
The Guidelines underscore the serious consequences of sanctions non-compliance. Breaches may result in administrative penalties, criminal liability, substantial fines, imprisonment, regulatory action, and reputational damage. The SMB also stresses that failure to implement adequate sanctions controls may be considered an aggravating factor in enforcement proceedings.
The Guidelines represent a significant development in Malta’s sanctions compliance framework and substantially raise regulatory expectations for operators. Operators should review existing AML/CFT and sanctions programmes, conduct a gap analysis against the new requirements, and ensure that sanctions risk assessments, screening controls, governance arrangements, reporting mechanisms, and training programmes are fully aligned with the SMB’s expectations.
For further information on the SMB’s Guidelines, or assistance in assessing and strengthening the internal sanctions compliance framework, kindly contact Mario Zerafa, Jonathan Camilleri, or Karl Wismayer.