The Malta Financial Services Authority (MFSA) has announced a significant increase in potential administrative fines for banks and credit institutions.

Through an update in its guidance notes, the MFSA is raising the administrative fine ceiling for credit institutions from a maximum of €150,000 to a maximum of €12.5 million.

The MFSA used to calculate administrative penalties by tabulating the impact and seriousness of a breach with the average revenue generated by the entity in the preceding three financial years. 

Fines therefore ranged from a minimum of €5,000 for very low risk breaches committed by institutions with an average revenue of €50,000 or under to a maximum of €150,000 for very high risk breaches committed by institutions with an average revenue of over €3 million. 

The former system used to calculate fines

In certain cases, the MFSA was also empowered to increase the final amount through the application of a daily, weekly or monthly penalty. 

Through a new framework published in July, the MFSA has revamped the methodology it uses to calculate fines. 

The regulator will now first assess the severity of a breach by tabulating the degree of misconduct with its level of impact. 

Impact is calculated based on factors such as the duration of the breach, profits gained or losses avoided as a result, the extent of damage to third parties, and the impact of the brach on the reputation in the banking sector. 

Misconduct evaluation assesses whether the breach was intentional or the result of negligence.

The new fining system - Part 1

A final severity score, ranging from 'minor' to 'extremely severe', is then assigned, after which a new penalty grid is used to determine the fine based on both the score and the institution's total assets.

Base fines now range from €6,250 for minor breaches committed by institutions with €2 billion or under in assets to €12.5 million for very severe breaches committed by banks with assets of over €15 billion. 

If the profits gained or losses avoided through the breach can be quantified, then the base amount of the fine is calculated by applying a percentage to this amount according to the severity of the breach. In this case, the base amount can never be less than the total profits gained or losses avoided. 

The new fining system - Part 2

And in breaches classified as ‘extremely severe’, the MFSA can increase the maximum base fine by adding a percentage of the institution’s annual turnover depending on the scale, duration and impact of the breach.  

Once a base fine has been set, the MFSA can then adjust it to reflect any mitigating or aggravating circumstances, such as whether the institution voluntarily disclosed the breach prior to investigative actions, its degree of proactive cooperation with investigators, and remedial actions taken to address the breach and prevent recurrence.

So as to ensure the fine doesn’t risk jeopardising the institution’s financial viability, the final fine will be subject to an absolute capping limit of 10 per cent of its total annual net turnover. 

Related

‘Not the image Malta should portray’: MHRA President objects to soldiers patrolling Swieqi

August 12, 2026
by Nicole Zammit

'It is not their job and I wonder what powers they have in cases where a contravention is taking place'

Former San Luċjan oil depot earmarked for transformation into innovation hub

August 12, 2026
by Nicole Zammit

The framework seeks to safeguard surrounding agricultural land as well as nearby ecologically and historically sensitive protected areas

MFSA sounds alarm over rise in financial scams, flags unauthorised entities operating in Malta

August 12, 2026
by Nicole Zammit

Scammers and entities are keeping busy with a series of fraudulent campaigns and companies