Malta’s Sanctions Monitoring Board (SMB) has published its first detailed guidance on how organisations are expected to comply with Article 32 of the National Interest (Enabling Powers) Act (NIA), setting out requirements covering sanctions risk assessments, screening, governance and reporting.
The guidance is intended to provide Operators with a practical reference point for assessing whether their existing controls can effectively identify, manage and mitigate sanctions risks.
Article 32 requires certain organisations operating in or from Malta to identify and assess their exposure to sanctions and restrictive measures and put appropriate controls in place.
The obligations apply to Operators listed under Schedule I of the NIA, which currently largely reflects the categories of subject persons already subject to Malta’s anti-money laundering and counter-financing of terrorism framework.
This means that many financial institutions, regulated entities, company service providers, crypto-asset service providers and other businesses already subject to AML/CFT requirements also fall within the scope of Article 32.
However, the SMB makes clear that sanctions compliance is a distinct obligation and cannot simply be treated as an extension of an organisation’s existing AML/CFT controls.
A separate sanctions risk assessment
A central element of the guidance is the requirement for Operators to carry out a Sanctions Risk Assessment (SRA).
This involves identifying and documenting how sanctions risks could arise from an organisation’s clients, counterparties, products and services, geographic exposure, transactions and delivery channels.
The assessment should be proportionate to the size, nature, complexity and risk profile of the organisation. It should also include a sanctions risk appetite statement and be reviewed regularly.
While there may be overlap with the information used in an organisation’s existing business risk assessment for money laundering and terrorism financing, the SMB expects sanctions risks to be explicitly considered in their own right.
The guidance also addresses Operators which form part of international groups. Where an Operator has branches or majority-owned subsidiaries in third countries, sanctions controls are expected to be extended to those entities to the extent permitted under local law. Any gaps should be documented and appropriately mitigated.
Screening must go beyond the immediate client
Another major area addressed by the SMB is sanctions screening and customer due diligence.
The guidance stresses that checking whether the immediate client appears on a sanctions list may not be enough. Operators are expected to identify other relevant parties connected to a business relationship or transaction, including beneficial owners, controllers and counterparties.
This is intended to address situations where a designated person may exercise ownership or control through layered corporate structures, intermediaries or other arrangements without appearing as the immediate customer.
An extensive annex to the guidance provides worked examples covering different ownership and control structures, including private equity arrangements and foundations where beneficiaries may not be immediately identifiable.
Once the relevant parties have been identified, Operators are expected to screen them against applicable sanctions lists, investigate potential matches and carry out ongoing screening and transaction monitoring where appropriate.
Freezing, reporting and tipping-off
The guidance also sets out expectations when an Operator identifies a confirmed sanctions match or other potential breach.
Where required, funds or economic resources must be frozen, while confirmed matches, frozen assets and suspected sanctions breaches must be reported to the SMB without delay.
Operators are also expected to have controls to prevent "tipping off", including restricting access to sensitive information and preventing clients or third parties from being informed in advance that freezing measures are being applied.
Beyond these operational controls, the framework covers internal policies and procedures, record-keeping, outsourcing and third-party reliance, staff training and the systems used for sanctions screening and monitoring.
The SMB expects systems to be appropriately calibrated and their operation to be explainable, while senior management is expected to exercise effective oversight of sanctions compliance. The guidance also addresses the appointment and responsibilities of a Sanctions Compliance Officer.
Failure to comply can carry criminal consequences
Breaches of sanctions obligations under the NIA can constitute criminal offences and may result in fines and imprisonment, in addition to regulatory and reputational consequences.
Importantly, while the document is guidance, the SMB states that a decision by an Operator not to follow it may be considered an aggravating factor in enforcement proceedings.
A failure to put appropriate sanctions controls in place may also be used as evidence in criminal proceedings. The document includes a dedicated annex setting out the administrative penalties and criminal offences associated with different breaches.
The SMB said sanctions compliance should go beyond having policies and procedures on paper, with organisations expected to understand the risks they face and ensure their controls remain effective.
Following the publication of the guidance, organisations falling within the scope of Article 32 will need to assess their existing sanctions arrangements against the SMB’s expectations, particularly in relation to their sanctions risk assessment, the identification of parties beyond the immediate client, and internal governance and reporting arrangements.
The scheme will be extended to non-first-time buyers, but whose second residence will become their primary and only residence
The latest sponsorship means Malta’s national tourism brand will feature on the club’s shirts
Gamescom is one of the world’s biggest video game trade fairs and conventions