MFSA Fines Company Service Provider for Late Regulatory Filings
What the MFSA Found
The Authority's investigation centred on two discrete breaches of the CSP Rulebook, both relating to the financial year ending 31 December 2022.
Breach 1: Late Audited Financial Statements
Under Rule R3-13.3 and Annex 1 of the CSP Rulebook, licensed CSPs are required to submit audited financial statements to the MFSA within a prescribed period after the close of the relevant financial year. The firm in question submitted those statements after the regulatory deadline. The MFSA does not publish the exact number of days late in this notice, but the breach was sufficient to trigger a formal investigation.
Breach 2: Late Management Letter
The same rule and annex also require CSPs to provide the management letter produced by their external auditors. This document, which typically accompanies the audited accounts and records any material weaknesses or observations identified during the audit, was also submitted outside the permitted window for the same 2022 year-end period.
Together, the two failures constituted a pattern of late submission rather than an isolated oversight. The MFSA's decision to investigate and then settle, rather than simply close the matter informally, reflects the authority's approach of creating a documented enforcement record even for lower-value penalties.
The Settlement and the Penalty
The MFSA noted that the CSP demonstrated goodwill throughout the process. In Maltese regulatory practice, goodwill can include voluntary disclosure, prompt remediation, and active cooperation with the authority's requests. That cooperation was taken into account, and both sides agreed to resolve all outstanding matters by way of a settlement agreement rather than through contested proceedings.
The Penalty Amount
The agreed administrative penalty is €2,160. By the standards of financial regulation, that sum is modest. Its significance lies not in its size but in the formal record it creates. A settled penalty is a public enforcement outcome, one that appears on the MFSA's website and, depending on future applications or fit-and-proper assessments, may need to be disclosed. For any CSP looking to expand its licence scope, add regulated activities, or pass due diligence for institutional clients, a settled enforcement action is a factor that will be scrutinised.
Why Regulators Settle Rather Than Drop
Settlement procedures serve two purposes from the regulator's perspective. First, they conserve resources: a contested hearing requires significantly more preparation from both sides. Second, they produce a proportionate but documented outcome, preserving deterrence without imposing a penalty that would be disproportionate to the breach. The MFSA's willingness to settle at €2,160 suggests the breaches were treated as administrative rather than substantive failures, but the authority was not prepared to treat them as no breach at all.
The Relevant Rules: CSP Rulebook R3-13.3 and Annex 1
The CSP Rulebook is issued by the MFSA and sets out the ongoing obligations that Company Service Providers must meet to retain their authorisation. Rule R3-13.3, read together with Annex 1, establishes the specific documents that must be submitted to the authority and the timelines within which each must arrive. Audited financial statements and the accompanying management letter are core components of the annual regulatory return cycle.
Why These Documents Matter to the Regulator
The MFSA uses audited financial statements to assess whether a CSP continues to meet its financial resource requirements and remains solvent. The management letter adds a qualitative layer: it tells the regulator whether the auditor identified any internal control weaknesses that might affect the firm's ongoing fitness to provide regulated services. Late submission of either document means the MFSA is operating without complete information about a regulated firm, which is precisely the oversight gap that the rulebook is designed to prevent.
For firms using digital asset accounting software or crypto bookkeeping software to serve Maltese-licensed clients, the lesson is that these tools need to be configured not just for transaction recording and tax output, but also for regulatory deadline tracking. A missed filing that stems from a workflow failure in the back office is treated the same as one caused by any other reason.
Accounting and Compliance Implications for Firms
This case carries practical weight for three groups: accounting firms servicing Maltese CSPs, in-house compliance teams at those CSPs, and CFOs at holding structures that own or operate through a Maltese CSP.
For Accounting Firms and Auditors
Auditors working on CSP engagements should check whether their client engagement letters clearly assign responsibility for submitting the audited financial statements and management letter to the MFSA. In many cases, the audit firm prepares the documents but the client is contractually responsible for submission. If that division of responsibility is not documented, both parties can end up assuming the other has acted. A simple confirmation step, with a documented handover date, eliminates that risk.
Firms using crypto accounting software to manage client data should also verify that regulatory submission calendars are integrated into their workflow systems, not maintained separately on spreadsheets. When a deadline exists in two places and is owned by two teams, it tends to fall between them.
For Compliance Officers and In-House Teams
The CSP that settled in this case almost certainly had the audited accounts prepared on time; the issue was submission, not production. That distinction matters for root-cause analysis. Compliance teams should map the full chain from audit sign-off to MFSA portal submission, identify every manual step in that chain, and assess which steps carry the highest risk of delay. Automated submission reminders, staged internal deadlines set ahead of the regulatory deadline, and a named responsible person for each filing all reduce exposure.
Given the MFSA's stated focus on goodwill as a mitigating factor, any firm that does identify a late submission should notify the authority proactively rather than wait to be contacted. Early disclosure is the most reliable way to replicate the mitigating circumstance that kept this penalty at €2,160 rather than higher.
For CFOs at Holding Structures
If a group holds interests in or through a Maltese CSP, the penalty record now sits on the regulatory file of that entity. Groups conducting internal governance reviews should ensure that the CSP's MFSA compliance record is included in the scope of those reviews, alongside the more commonly checked items such as AML programme status and capital adequacy. A settled penalty is not a disqualifying event, but it needs to be tracked and, where relevant, disclosed in fit-and-proper confirmations to other regulators or institutional counterparties.
For context on how AML enforcement trends are affecting crypto accounting teams across European jurisdictions, see our earlier coverage of AML enforcement trends for crypto accounting teams, and for a broader picture of how regulated firms are responding to tighter AML and licensing standards across Europe
FAQ
What specific rules did the CSP breach?
The firm breached Rule R3-13.3 and Annex 1 of the MFSA's CSP Rulebook on two counts: late submission of audited financial statements and late submission of the management letter, both for the financial year ending 31 December 2022.
How much was the penalty and why was it relatively low?
The MFSA imposed an administrative penalty of €2,160. The amount reflects the regulator's assessment that the breaches were procedural rather than substantive, and that the firm demonstrated goodwill, including cooperation and remediation, throughout the investigation.
Does a settled MFSA penalty need to be disclosed elsewhere?
It depends on the context. Settled enforcement outcomes may need to be disclosed in fit-and-proper assessments for future licence applications, in due diligence questionnaires from institutional clients, or in regulatory filings with other authorities. Firms should take specific legal advice on their disclosure obligations.
What documents are CSPs required to submit under Rule R3-13.3?
Rule R3-13.3 and Annex 1 of the CSP Rulebook require licensed Company Service Providers to submit audited financial statements and the accompanying auditor management letter within defined timeframes after each financial year-end. The MFSA uses these documents to monitor ongoing financial soundness and internal control quality.
How can accounting firms help CSP clients avoid similar penalties?
The most effective steps are: assigning clear, documented responsibility for each regulatory submission, building internal deadlines ahead of the MFSA's deadlines to allow for correction time, using workflow or crypto accounting software that tracks regulatory filing dates alongside transactional data, and confirming with clients in writing once each submission has been made.
