Category

New

Should the Commercial Agent Exclusion be treated as a Free Pass?

The exclusion for commercial agents has historically held an ambiguous position within EU payments regulation. Originally intended as a limited exception for legitimate sales intermediaries, it has increasingly been used in arrangements that regulators perceive as a means of avoiding licensing requirements. This regulatory tension is not new, but it is now being directly addressed through the forthcoming Payment Services Regulation (PSR), following the broader reforms introduced under PSD3.

Read article
Financial Institutions Circulars

Together, they point to a regulator that is sharpening prudential expectations while also reducing unnecessary reporting friction. For firms, the message is simple: safeguarding arrangements must be well-justified, well-documented and continuously monitored, and reporting systems must start preparing now for a more structured, JSON-based future.

Read article
Supervisory ICT Risk and Cybersecurity Circulars

Among the main pressure points, the MFSA highlighted weaknesses in business continuity, incident handling, patch and vulnerability management, and contractual controls for ICT outsourcing arrangements. It also noted that overreliance on unverified generative AI in submissions can create generic or inaccurate materials that slow down authorisation processes.

Read article
PLS Getting MiCAR

The implications of a MiCAR licence are multiple, but two of the largest hurdles are cost and compliance. The price fluctuates based on the class of licence required which in turn fluctuates based on the service being provided by the PI. Furthermore, the cost of obtaining and 1 maintaining a MiCAR licence is rarely limited to the application fee alone.

Read article
Tokenisation of Financial Instruments and Real-World Assets in Malta

The European Union's payments landscape is about to undergo its most significant transformation since PSD2. The forthcoming PSD3 Directive and Payment Services Regulation (PSR) package expected to enter into force in mid-2026 will reshape the licensing, conduct, and operational requirements for every payment institution, electronic money institution, and crypto-asset service provider operating in the EU. This is not a distant regulatory event. The transitional clock starts on publication, and firms that delay preparation risk losing their authorisation. Here is what you need to know!

Read article
PSD3 and PSR: What Every Payment Institution and EMI Needs to Know Now!

The European Union's payments landscape is about to undergo its most significant transformation since PSD2. The forthcoming PSD3 Directive and Payment Services Regulation (PSR) package expected to enter into force in mid-2026 will reshape the licensing, conduct, and operational requirements for every payment institution, electronic money institution, and crypto-asset service provider operating in the EU. This is not a distant regulatory event. The transitional clock starts on publication, and firms that delay preparation risk losing their authorisation. Here is what you need to know!

Read article
Is the Travel Rule Being Weaponised? What Recent Arbiter Decisions Reveal About CASP’s Duty of Care

Recent rulings by Malta’s Arbiter for Financial Services signal a significant shift in how Crypto-Asset Service Providers (CASPs) must approach Travel Rule compliance. While historically viewed as a technical anti-money laundering (AML) requirement, the Travel Rule (Regulation (EU) 2023/1113) is increasingly being repurposed by the Arbiter as a core benchmark for a CASPs duty of care and fiduciary obligations toward retail consumers.

Read article
Crypto Tax Reporting: Does DAC8 have a Wider Reach Than MiCA?

DAC8 marks a significant development in the EU’s treatment of crypto-assets because it moves the sector firmly into the tax transparency framework already familiar in traditional f inance. While the regime is closely linked to MiCA in structure and terminology, it serves a different regulatory purpose: tax reporting and cross-border information exchange rather than market access, licensing, conduct supervision, or prudential regulation.

Read article
Financial Institutions and Supervisory ICT Risk and Cybersecurity Circulars Q1 2026

Chapter 2 and Chapter 3 of the Financial Institutions Rulebook (‘FIR/02’ and ‘FIR/03’), set out the obligation that an Annual Compliance Report (‘ACR’) is to be drawn up by its Compliance Officer. The Compliance Officer is expected to list regulatory breaches identified and their respective status and to come up with an Annual Compliance Monitoring Plan which is approved by the Board of Directors and must detail the outcome of such plan.

Read article