MFSA Recruits New Executive Team as Malta Crypto Oversight Enters Delivery Phase
Malta's financial regulator has moved its internal restructuring from planning into execution, opening recruitment for five Deputy Chief Executive Officer roles that will together lead supervision of crypto-asset businesses, enforcement, financial crime intelligence, policy, and technology. For accounting firms, auditors, and CFOs servicing Malta-licensed entities, this signals a more structured and likely more demanding supervisory environment ahead, one that firms and their clients should begin preparing for now.
What the MFSA Has Actually Announced
On 11 September 2026, the Malta Financial Services Authority published a notice confirming that it had opened a formal recruitment process for five Deputy CEO positions. The move follows Parliamentary approval of Act XV of 2026, which gave the authority the legal basis to restructure its leadership architecture.
The five new Deputy CEO roles
Each Deputy CEO will sit on the MFSA's Executive Leadership Team, reporting directly to the CEO, and will own a distinct slice of the authority's mandate:
- Supervision: day-to-day oversight of banking, insurance, and investment services.
- Enforcement, Resolution and Financial Stability: sanctions, resolution proceedings, and systemic risk.
- Cross-Sectoral Supervision, TCSPs and Intelligence: financial crime compliance and intelligence, covering trust and company service providers alongside broader cross-sectoral work.
- Strategy, Policy and Legal: legislative development, international standards alignment, and legal affairs.
- Digital and Corporate Services: the technology, data, and operational infrastructure underpinning the organisation.
The recruitment process is expected to conclude in Q4 2026, with the incoming team in place during 2027. Candidates will be drawn from both Malta and abroad, with specialist external support assisting the search.
Why This Restructuring Matters for Crypto Businesses
Malta has positioned itself as one of the more active European jurisdictions in crypto-asset supervision. The MFSA CEO Kenneth Farrugia noted directly that the authority has "deepened supervisory expertise, positioning Malta among the more advanced jurisdictions in fintech and crypto-asset supervision." That is not an idle claim: Malta was among the first EU member states to introduce a domestic virtual financial assets framework, and it has been adapting that framework to align with the EU's Markets in Crypto-Assets Regulation (MiCA).
Dedicated executive ownership of crypto compliance
The creation of a dedicated Deputy CEO role for Cross-Sectoral Supervision, TCSPs and Intelligence is the most directly relevant development for crypto firms. Financial crime risk, wallet screening, source-of-funds documentation, and beneficial ownership disclosure sit squarely in that lane. Having a named executive accountable for this function signals that the MFSA intends to treat intelligence-led supervision as a first-class priority rather than an ancillary concern.
Equally, the Digital and Corporate Services role suggests the authority will invest in its own supervisory technology. Regulators that upgrade their data and analytics capabilities tend to raise the bar on what they expect from licence holders in terms of audit trails, transaction monitoring outputs, and regulatory reporting formats. Firms using manual or fragmented record-keeping processes should take note.
Enforcement as a standalone function
Separating enforcement and resolution into its own Deputy CEO portfolio is a structural signal. Where enforcement was previously one of many competing priorities, it now has dedicated leadership. For Malta-licensed VFA agents, issuers, and service providers, this suggests that investigations and sanctions proceedings will be handled with greater speed and consistency than a more diffuse structure would allow.
The Regulatory Context: MiCA and Malta's Position
The MFSA's restructuring is not happening in isolation. MiCA became fully applicable across EU member states in December 2024, and national competent authorities have been under pressure to demonstrate that their supervisory capacity matches the new framework's demands. MiCA introduced harmonised licensing categories for crypto-asset service providers (CASPs), stablecoin issuers, and asset-referenced token issuers, and it assigns national authorities meaningful ongoing supervisory obligations: periodic reviews, capital adequacy checks, governance assessments, and AML oversight working in tandem with the EU's Anti-Money Laundering Authority (AMLA), which will take on direct supervisory responsibility for the highest-risk CASPs from 2027.
The timing of MFSA's leadership overhaul aligns almost precisely with AMLA's ramp-up. A regulator that enters the AMLA era with a fragmented leadership structure would be poorly placed to meet its obligations as a host supervisor. Building a proper executive team before 2027 is therefore a practical necessity, not simply an administrative preference.
Strategy and Policy leadership: international standards alignment
The Strategy, Policy and Legal Deputy CEO role will carry responsibility for keeping Malta's frameworks aligned with evolving international standards. In practice, this means FATF travel rule requirements, the EU's transfer-of-funds regulation as it applies to crypto transfers, and any further amendments to MiCA's delegated acts. For firms that rely on Malta as their EU passporting base, this executive will effectively be the counterpart to their own compliance officers when guidance is being drafted or consultations are open.
Accounting and Reporting Implications
Organisational changes at a regulator flow through into practical obligations for licence holders, and this restructuring carries several worth tracking.
Supervisory reporting quality will face greater scrutiny
A dedicated enforcement leadership and an intelligence-focused Deputy CEO role both point toward closer examination of the data that licence holders submit. Prudential returns, AML suspicious transaction reports, transaction monitoring statistics, and beneficial ownership filings will all be reviewed by teams with clearer mandates and, presumably, better tooling. Firms that have been submitting returns on a tick-box basis rather than investing in genuinely accurate and granular data should use the period before the new team is in place to audit their own outputs.
This is precisely the context in which reliable crypto accounting software becomes a compliance asset rather than a back-office convenience. The MFSA's investment in its Digital and Corporate Services capability implies it will increasingly expect structured, machine-readable data from reporting entities. Firms whose records exist in spreadsheets or disconnected ledgers will find it harder to respond quickly to supervisory requests.
Governance documentation under Supervision and Enforcement
With Supervision and Enforcement now each under dedicated leadership, governance reviews are likely to become more systematic. For CFOs and finance directors at Malta-licensed entities, that means board-approved policies, documented risk appetites, and clear audit trails for key decisions will need to be genuinely up to date, not just filed and forgotten. Annual reviews of AML policies, outsourcing arrangements, and conflicts-of-interest registers become more important when the authority conducting the review has a clear line of accountability for outcomes.
TCSP-specific obligations
Trust and company service providers operating in Malta appear explicitly in the new structure under the Cross-Sectoral Supervision, TCSPs and Intelligence Deputy CEO. TCSPs that also interact with crypto-asset clients, whether by acting as registered agents, providing nominee services, or administering structures that hold digital assets, should expect that their compliance obligations will be viewed through a combined lens: the standard TCSP framework and the specific AML/CTF requirements that apply when the underlying assets are crypto-related. Accounting and audit firms advising TCSPs in Malta should flag this dual exposure to clients now.
What Firms Should Do Before 2027
The new executive team will not be in place until sometime in 2027, but the gap between now and then is not a grace period. It is the window in which firms can get ahead of a more capable supervisory authority rather than scrambling to catch up once it arrives.
Practical steps for accounting firms and CFOs
A structured pre-2027 review should cover at least the following areas:
- Data infrastructure: assess whether transaction records, wallet attribution data, and counterparty documentation are held in formats that can be exported quickly and accurately in response to a supervisory request.
- AML policy refresh: cross-reference existing AML/CFT policies against MiCA's requirements and the FATF travel rule obligations as implemented in Malta, and document any gaps with a remediation timeline.
- Governance audit: confirm that board minutes, risk committee records, and outsourcing registers reflect actual practice and have been reviewed in the last twelve months.
- Regulatory reporting accuracy: run a sample check of recent prudential and AML returns to verify that submitted figures reconcile with underlying accounting records.
- Engagement with consultations: monitor MFSA's website for guidance and consultation papers issued under the new leadership once in place, given that the Strategy, Policy and Legal Deputy CEO role will be active in shaping Malta's implementation of evolving EU standards.
Frequently Asked Questions
What is Act XV of 2026 and why does it matter?
Act XV of 2026 is the Maltese legislation that Parliament approved to give the MFSA the formal authority to restructure its internal organisation. It provides the legal basis for creating the new Deputy CEO layer within the Executive Leadership Team. Without it, the structural changes could not be implemented under the MFSA's governing framework.
When will the new MFSA leadership team be operational?
The MFSA expects the recruitment process to conclude in Q4 2026, with the new executive team in place during 2027. Licence holders should not expect significant supervisory practice changes before then, but should use the intervening period to prepare.
Does this restructuring change the licensing requirements for crypto businesses in Malta?
Not directly. The restructuring is an internal governance change at the MFSA, not a change to the underlying legal framework governing virtual financial assets or MiCA-compliant crypto-asset service providers. However, it is likely to change how supervision is conducted in practice, particularly the depth and consistency of enforcement activity.
How does the MFSA restructuring interact with AMLA?
The EU's Anti-Money Laundering Authority is expected to begin direct supervision of the highest-risk crypto-asset service providers from 2027. The MFSA, as Malta's national competent authority, will need to function as an effective partner to AMLA. Building a dedicated intelligence and enforcement leadership structure before AMLA becomes operational positions the MFSA to meet those obligations rather than scrambling to adapt after the fact.
What should Malta-based crypto firms prioritise in their compliance budgets given this change?
The restructuring points toward three areas of heightened scrutiny: financial crime intelligence and AML reporting quality; enforcement readiness, meaning documented governance and audit trails; and data infrastructure that can support supervisory requests in structured formats. Investment in digital asset accounting software that produces audit-ready, exportable records is likely to pay dividends as supervisory expectations rise.
