CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MFSA Releases HRRF Draft Technical Docs for FIs and CASPs

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING MFSA Releases HRRF Draft Technical Docsfor FIs and CASPs

Malta's financial services regulator, the Malta Financial Services Authority (MFSA), published draft technical documentation on 25 August 2026 under its Heightened Risk Reporting Framework (HRRF), covering both traditional financial institutions (FIs) and crypto asset service providers (CASPs). The release opens a formal consultation period and gives regulated entities their first detailed look at the data, procedural, and systems requirements the Authority expects them to meet. For accounting teams, auditors, and CFOs relying on crypto accounting software to manage their reporting obligations, the timing matters: understanding the draft now means firms can begin gap assessments before the rules become final.

MFSA Releases HRRF Draft Technical Docs for FIs and CASPs

What Is the HRRF and Why Does It Matter for CASPs?

The HRRF is the MFSA's dedicated mechanism for gathering enhanced risk data from entities it considers to carry elevated financial crime or prudential risk profiles. Unlike routine supervisory reporting, which tends to be periodic and standardised across all firms, the HRRF allows the MFSA to request granular, targeted information from specific categories of licensee on a more dynamic basis.

CASPs have sat squarely in the high-risk category since Malta transposed the original EU AML directives and later built its VFA (Virtual Financial Assets) regulatory architecture. The arrival of MiCA across the EU has added another layer: CASPs operating under MiCA authorisation are now subject to both the harmonised EU rulebook and any supplementary national requirements the MFSA chooses to impose within its permitted discretion. The HRRF sits in that supplementary space, which is why the draft documentation is significant even for firms whose primary licence is in another EU member state but who passport services into Malta.

Scope: Who Sits Inside the Draft Framework?

The MFSA's draft covers two distinct categories. First, traditional financial institutions, meaning banks, payment service providers, e-money institutions, and investment firms subject to MFSA oversight. Second, CASPs authorised under either the legacy Maltese VFA Act or the newer MiCA regime. The inclusion of both categories in a single technical documentation release is deliberate: the Authority appears to be aligning the data collection architecture across the two populations so that risk data can be compared and aggregated at the supervisory level.

Firms passporting into Malta under freedom-of-services rules should check with their legal advisers whether the HRRF obligations attach to the home-state licence or whether the MFSA can require reporting directly from the passport branch. That question is not fully resolved in the draft as published, and it is one of the most practically important points for compliance officers to raise during the consultation.

What the Draft Technical Documentation Sets Out

Because the MFSA has released draft documentation rather than a final rulebook, the specific data fields, submission formats, and frequencies disclosed in the draft are subject to change following consultation. That said, the direction of travel is clear enough to act on.

Data and Reporting Architecture

The draft signals that the MFSA wants structured, machine-readable submissions rather than narrative reports. This is consistent with the direction regulators across the EU have taken since ESMA and the EBA began pushing for standardised reporting taxonomies under MiCA. For CASPs, that means the technical infrastructure underpinning their digital asset accounting software and compliance systems needs to be capable of exporting structured data in formats the regulator can ingest directly, not just generating PDF summaries for human review.

Firms that currently manage their crypto books through manual spreadsheet processes will face the sharpest adjustment. The draft's emphasis on structured data is an implicit signal that those approaches are unlikely to satisfy the HRRF's requirements at scale.

Procedural and Governance Requirements

Beyond raw data, the draft addresses governance: it expects firms to have clearly documented procedures for identifying when an HRRF trigger has been met and for escalating the reporting obligation internally before submission. This is important for audit trail purposes. Regulators increasingly expect that the decision to file, or not to file, a heightened risk report is documented with a clear rationale, reviewable during a supervisory inspection.

For accounting and compliance teams, this translates to a need for written policies that sit alongside whatever crypto bookkeeping software they use. The software can generate the data; the governance policy has to explain who approved the submission and on what basis.

Accounting and Audit Implications

The HRRF draft carries several implications for financial reporting and audit that go beyond pure regulatory compliance.

Impact on the Audit Cycle

External auditors reviewing a CASP's financial statements will now need to consider whether the firm has correctly identified its HRRF obligations and whether any enhanced risk reports filed during the year have affected the firm's risk disclosures or its going-concern assessment. If a firm has been designated as a heightened risk entity by the MFSA, that designation is a reportable fact that auditors are expected to probe.

Audit firms without deep familiarity with the MFSA's supervisory framework may struggle to assess this correctly. The draft documentation, once finalised, will become a key reference point for audit planning in the Malta-licensed CASP space.

Financial Statement Disclosures

IAS 1 and IFRS 7 both require entities to disclose material risks and the controls in place to manage them. A firm operating under an active HRRF designation faces a strong argument that this constitutes a material regulatory risk requiring disclosure, particularly if non-compliance could result in licence suspension or financial penalties. CFOs should discuss with their auditors now whether existing disclosure language adequately covers the HRRF, rather than waiting for year-end.

For Maltese CASPs reporting under local GAAP or IFRS as adopted by the EU, the principle is the same: if a regulatory framework creates a contingent liability or a going-concern risk, it needs to be visible in the notes.

AML Controls and the Accounting Interface

AML reporting and financial accounting are often treated as separate workstreams inside a firm, but the HRRF blurs that boundary. The framework asks for risk data that spans both domains: transactional volumes, counterparty risk profiles, and suspicious activity indicators all feed into the heightened risk picture that the MFSA wants to see. Firms whose AML systems and accounting systems do not talk to each other will find it difficult to produce the kind of integrated submissions the draft appears to contemplate.

This is where robust crypto accounting software with genuine AML data integration becomes operationally relevant, not just as a compliance tool, but as a foundation for the kind of cross-functional reporting the MFSA is moving toward. For context on what best-in-class AML monitoring looks like in practice, see our earlier piece on what continuous AML monitoring means for crypto firms.

Context: Malta in the Broader EU CASP Landscape

Malta was an early mover in crypto regulation through its VFA Act, and that head start gave Maltese-licensed CASPs a degree of regulatory certainty before MiCA arrived. The challenge now is that MiCA has created a single EU market for CASP services, and competition for licences has intensified. As reported in our coverage of how Germany leads the EU CASP register with 79 authorised firms, Germany has moved quickly to position itself as the dominant MiCA jurisdiction by volume.

Malta's response, in part, appears to be raising the quality bar for firms it authorises rather than competing purely on speed or volume. The HRRF framework is consistent with that positioning: it signals that the MFSA intends to run a high-intensity supervisory relationship with the CASPs on its books, which may deter volume applicants but is likely to attract institutional-grade operators who see regulatory rigour as a feature rather than a burden.

For firms choosing between EU jurisdictions for their MiCA licence, this is relevant context. A Malta licence now comes with more intensive reporting obligations than some alternatives, but it also comes with the credibility of a regulator that is demonstrably active in its supervision.

What Firms Should Do Before the Consultation Closes

The MFSA has invited feedback on the draft documentation. Consultation responses are one of the few opportunities firms have to influence the final shape of technical requirements before they become binding, and the window should not be wasted.

Immediate Steps for Compliance and Finance Teams

Start with a gap assessment against the draft as published. Map the data fields the MFSA is requesting against what your current systems actually capture. Where gaps exist, determine whether they can be closed through configuration of existing tools or whether new integrations are required. Document that assessment: it doubles as evidence of good-faith compliance preparation if the MFSA ever asks.

Review your governance policies for HRRF triggers. If you do not have a documented procedure for identifying and escalating a heightened risk reporting obligation, draft one now. The procedure should specify who is responsible, what the escalation path looks like, and how submissions are reviewed before filing.

Engage your external auditors early. Share the draft documentation with your audit team and ask them to assess whether your current financial statement disclosures are adequate given the HRRF's scope. If they are not, plan the remediation for the next reporting period rather than scrambling at year-end.

If you have questions about the technical format of submissions, raise them in your consultation response. The MFSA has flagged that the documentation is in draft precisely because it wants industry input, and technical ambiguities that go unresolved now will cause problems at implementation.

MFSA Releases HRRF Draft Technical Docs for FIs and CASPs

Frequently Asked Questions

What is the MFSA's HRRF?

The Heightened Risk Reporting Framework is an MFSA supervisory tool that enables the Authority to require enhanced, targeted risk data from financial institutions and CASPs it has assessed as carrying elevated risk profiles. It sits alongside, rather than replacing, standard periodic regulatory reporting.

Does the HRRF apply to CASPs licensed in other EU member states that passport into Malta?

The draft documentation does not fully resolve this question. Firms in that position should seek legal advice on whether the MFSA can impose HRRF obligations directly on passport services and, if so, whether any exemptions or modified requirements apply. Raising this point in a consultation response is advisable.

What format does the MFSA expect for HRRF submissions?

The draft signals a preference for structured, machine-readable data rather than narrative reports. Specific formats and taxonomies are subject to change following the consultation, but firms should ensure their reporting systems can export structured data outputs rather than relying solely on PDF or manual submissions.

How does the HRRF affect my firm's financial statement disclosures?

If your firm carries an active HRRF designation or is at material risk of one, that regulatory exposure is likely to require disclosure under IAS 1 and IFRS 7 as a material risk or contingent liability. CFOs and auditors should review current disclosure language now rather than at year-end.

Is the HRRF final, or can firms influence the outcome?

The documentation published on 25 August 2026 is explicitly a draft open for consultation. Firms have a genuine opportunity to shape the final requirements by submitting responses that identify technical ambiguities, disproportionate burdens, or gaps in the draft. The MFSA typically reviews consultation responses before publishing a final version of any technical documentation.

Source: Malta Financial Services Authority (MFSA)

EUGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Ireland's National AML Strategy: What the Crypto Private-Wallet and Gambling Rules Mean for Accounting Firms and CFOs
AML/KYC & Licensing
CZ Backs ASEAN Crypto License Passporting: What Accounting Firms and CFOs Must Track Now
AML/KYC & Licensing
AFM AI Act Implementation Assessment: Gaps Firms Must Address
AML/KYC & Licensing
AI Governance in Compliance: The Accountability and Control Gap Regulators Are Already Watching