Continue Reading
Published on 6 August 2026
•
3 min read
Maltese banks and credit institutions could face significantly steeper financial penalties after the Malta Financial Services Authority (MFSA) introduced a new framework that dramatically increases the maximum fines it can impose for regulatory breaches.
The most notable change is the increase in the maximum base fine for the largest banks, which rises from €150,000 to €12.5 million.
The revised system links fines to the seriousness of the beach and the banks’ total assets as reported in their annual financial statements, rather than their average annual turnover.
Under the new methodology, the MFSA first assigns a severity score based on the degree of misconduct and its level of impact.
When assessing this score, the regulator takes into account factors such as the duration of the breach, any profits gained or losses avoided as a result of it, the extent of damage to third parties, and the impact of the brach on the reputation in the banking sector.
Misconduct evaluation assesses whether the breach was intentional or the result of negligence.
That score is then cross-referenced with the bank's total assets using a new penalty grid, ensuring larger institutions face proportionately higher fines.
The regulator has divided banks into five clusters, ranging from institutions with over €15 billion in assets to those with €2 billion or under.
For the most serious breaches, banks with over €15 billion in assets could face the maximum base fine of €12.5 million, while smaller institutions are subject to lower penalties.
The lowest possible fine is €6,250, slightly up from the previous €5,000.
If the profits gained or losses avoided through the breach can be quantified, then the base amount of the fine is calculated by applying a percentage to this amount according to the severity of the breach. In this case, the base amount can never be less than the total profits gained or losses avoided.
In breaches classified as ‘extremely severe’, the MFSA can increase the maximum base fine by adding a percentage of the institution’s annual turnover depending on the scale, duration and impact of the breach.
The framework also introduces greater flexibility, allowing the MFSA to increase or reduce penalties depending on aggravating or mitigating circumstances surrounding each case.
These include factors such as whether the institution voluntarily disclosed the breach prior to investigative actions, its degree of proactive cooperation with investigators, and its remedial actions taken to address the breach and prevent recurrence.
The final fine will always be subject to an absolute capping limit of 10 per cent of its total annual net turnover, to ensure the penalty doesn’t jeopardise the institution’s financial viability.
The MFSA said this new approach is intended to make enforcement more proportionate, consistent, and effective.
Tim is a senior journalist and producer at Content House, driven by a love of good stories, meaningful human connections and an enduring appetite for cheese and chocolate.