Skip to content

Sanctions Risk Assessment: Malta CSPs

John Caruana
July 9, 2026
5 min read
Contributions
2 articles published
Compliance
July 9, 2026
5 min read
Share on social:

Sanctions risk assessment for CSPs in Malta 

Sanctions risk assessment for CSPs in Malta is now an important compliance priority for company service providers that fall within the Article 32 subject person framework. 

For many CSPs, the issue is not that no screening takes place. The issue is that the file does not always show how sanctions risk was considered. 

A client may pass a name check and still raise questions. Who owns the company? Who controls it? Where did the instruction come from? Has the ownership changed since onboarding? Are there foreign shareholders, advisers or connected parties that need closer review? What are the hidden connections with other parties or jurisdictions? 

A2CO supports CSPs with compliance support, governance support and documentation review. We help firms understand what is already in place, where the gaps are and how to build a sanctions risk assessment that can be used in practice. 

Article 32 applies to persons, entities and bodies listed in Schedule I of the National Interest framework. A CSP will always fall within scope as the work it carries out is relevant activity as a subject person.  

In CSP work, sanctions risk often sits inside ordinary client files. A Maltese company may be owned by another company overseas. A shareholder exercising control may sit behind a trust or holding structure. A registered office client may later change directors. An introducer may be the person giving instructions. A third-party company within the client’s group may utilise the deliverables of the subject person indirectly. 

None of this is unusual. However, Sanctions Risk goes beyond screening. It takes into consideration various complex possibilities, including that of circumvention of sanctions and proliferation finance. A sanctions risk assessment helps with identifying weaknesses in the CSP’s processes and Sanctions procedures. It takes into consideration the clients of the CSP, extract from it various possible scenarios and combinations, builds an impact calculation and through the same statistical data, it examines the likelihood of a scenario taking place in practice. The combination between likelihood and impact would identify the Sanctions inherent risk that scenario brings to the business. The same would apply when it comes to circumvention of sanctions risk and proliferation finance risks.  

Mitigation tests are then applied to establish the mitigation levels in the context of sanctions risk, circumvention of sanctions risk and proliferation finance risks. The inherent risk less the mitigation levels established would provide us with an indication of the residual sanctions risk of the particular scenario.  

For wider context, see our article on Article 32 sanctions risk assessment in Malta

The review should start with the services the CSP provides. 

Company formation may involve new shareholders, beneficial owners, instructions from overseas advisers and the need for sanctions screening to be conducted on the client, beneficial owners and other persons exercising control. Registered office work may look administrative, but the CSP is still connected to the client relationship. Directorship and company secretary services may place the CSP closer to decisions being taken for the company. 

The file should answer basic questions clearly. Who is the client? Who owns it? Who controls it? Who gave the instructions? Which countries are involved? What service is being provided? Can services be pushed up towards a sanctioned entity? Can services be re-sold by the client to a sanctioned entity? 

Where the CSP provides company formation and corporate support, this review should be linked to the client file, not left in a generic policy.  

Sanctions risk assessment for CSPs Malta infographic showing common sanctions risk triggers, including complex ownership structures, high risk jurisdictions, intermediaries, relationship changes, service type and foreign bank accounts.

Sanctions screening should usually happen before the CSP accepts the client. It also needs to be repeated when ownership, control, activity or connected parties change. 

The file should show who was screened, when the check was done, what result came back and what decision was taken. If a possible match was cleared, the reason should be recorded. It should also show any mitigation or actions taken by the CSP to clarify any potential red flags or address any sanctions-related risks.  

A2CO can assist with client onboarding and KYC support where CSPs want to make this part of their process easier to evidence. 

Sanctions risk assessment for company service providers in Malta infographic showing common CSP risk triggers, including complex ownership structures, high risk jurisdictions, intermediaries, relationship changes, services provided and foreign bank accounts.

A sanctions assessment is not simply an ML/FT business risk assessment (BRA) with a different title. 

The ML/FT assessment usually looks exclusively at money laundering and funding of terrorism risk. The sanctions risk assessment (SRA) looks at exposure to restrictive measures, possible proliferation financing concerns, sanctioned ownership or control, indirect links and possible circumvention. 

There may be useful overlap. The same client, country, structure or service may be relevant to both. But the CSP should still be able to show how sanctions risk was considered in its own right. 

Thus, while regulation does not specifically obliges the CSPs to have a separate Sanctions Risk Assessment, this is highly recommended given that the exposures being analysed are different and therefore, the targeted results are also different from those of the Business Risk Assessment.  

A2CO provides compliance support, governance support and regulatory support. This article is for general information only and does not constitute legal advice. 

Our Sanctions specialist can help you identify your Sanctions GAPs, risks, vulnerabilities and assist you with desired action to rectify any shortcomings and start building a sanctions framework for the benefit and protection of your firm. 

A2CO supports company service providers in Malta with compliance and governance support under Article 32 of the National Interest (Enabling Powers) Act 

FAQs

Frequently Asked Questions: Sanction Risk Assessment for CSPs in Malta

A CSP will always need one given that CSP services is a regulated activity which is considered as a ‘relevant activity’ under AML regulations and hence, a CSP would be considered as a subject person.

Yes. A2CO can help CSPs review existing documentation, identify gaps and build a practical sanctions risk assessment process. We can also draft an initial Sanction Risk Assessment when this has not yet been drafted.

No. Screening is an important control, but it does not replace a written assessment.

Couldn't find your answer?
LET’S REVIEW YOUR SANCTIONS RISK

Need support with a sanctions risk assessment for CSPs?

A2CO supports company service providers in Malta with practical compliance and governance support under Article 32, including risk assessment structure, documentation review and gap analysis.
John Caruana
John Caruana

Compliance Director

Anton Dalli
Anton Dalli

Partner

We're on Socials:

"*" indicates required fields

This field is for validation purposes and should be left unchanged.