Sanctions risk assessment for CSPs in Malta
Sanctions risk assessment for CSPs in Malta is now an important compliance priority for company service providers that fall within the Article 32 subject person framework.
For many CSPs, the issue is not that no screening takes place. The issue is that the file does not always show how sanctions risk was considered.
A client may pass a name check and still raise questions. Who owns the company? Who controls it? Where did the instruction come from? Has the ownership changed since onboarding? Are there foreign shareholders, advisers or connected parties that need closer review? What are the hidden connections with other parties or jurisdictions?
A2CO supports CSPs with compliance support, governance support and documentation review. We help firms understand what is already in place, where the gaps are and how to build a sanctions risk assessment that can be used in practice.
Why sanctions compliance for CSPs in Malta matters
Article 32 applies to persons, entities and bodies listed in Schedule I of the National Interest framework. A CSP will always fall within scope as the work it carries out is relevant activity as a subject person.
In CSP work, sanctions risk often sits inside ordinary client files. A Maltese company may be owned by another company overseas. A shareholder exercising control may sit behind a trust or holding structure. A registered office client may later change directors. An introducer may be the person giving instructions. A third-party company within the client’s group may utilise the deliverables of the subject person indirectly.
None of this is unusual. However, Sanctions Risk goes beyond screening. It takes into consideration various complex possibilities, including that of circumvention of sanctions and proliferation finance. A sanctions risk assessment helps with identifying weaknesses in the CSP’s processes and Sanctions procedures. It takes into consideration the clients of the CSP, extract from it various possible scenarios and combinations, builds an impact calculation and through the same statistical data, it examines the likelihood of a scenario taking place in practice. The combination between likelihood and impact would identify the Sanctions inherent risk that scenario brings to the business. The same would apply when it comes to circumvention of sanctions risk and proliferation finance risks.
Mitigation tests are then applied to establish the mitigation levels in the context of sanctions risk, circumvention of sanctions risk and proliferation finance risks. The inherent risk less the mitigation levels established would provide us with an indication of the residual sanctions risk of the particular scenario.
For wider context, see our article on Article 32 sanctions risk assessment in Malta.
What should a CSP review?
The review should start with the services the CSP provides.
Company formation may involve new shareholders, beneficial owners, instructions from overseas advisers and the need for sanctions screening to be conducted on the client, beneficial owners and other persons exercising control. Registered office work may look administrative, but the CSP is still connected to the client relationship. Directorship and company secretary services may place the CSP closer to decisions being taken for the company.
The file should answer basic questions clearly. Who is the client? Who owns it? Who controls it? Who gave the instructions? Which countries are involved? What service is being provided? Can services be pushed up towards a sanctioned entity? Can services be re-sold by the client to a sanctioned entity?
Where the CSP provides company formation and corporate support, this review should be linked to the client file, not left in a generic policy.

Sanction screening is only part of the process
Sanctions screening should usually happen before the CSP accepts the client. It also needs to be repeated when ownership, control, activity or connected parties change.
The file should show who was screened, when the check was done, what result came back and what decision was taken. If a possible match was cleared, the reason should be recorded. It should also show any mitigation or actions taken by the CSP to clarify any potential red flags or address any sanctions-related risks.
A2CO can assist with client onboarding and KYC support where CSPs want to make this part of their process easier to evidence.

Sanctions assessment and AML business risk assessment
A sanctions assessment is not simply an ML/FT business risk assessment (BRA) with a different title.
The ML/FT assessment usually looks exclusively at money laundering and funding of terrorism risk. The sanctions risk assessment (SRA) looks at exposure to restrictive measures, possible proliferation financing concerns, sanctioned ownership or control, indirect links and possible circumvention.
There may be useful overlap. The same client, country, structure or service may be relevant to both. But the CSP should still be able to show how sanctions risk was considered in its own right.
Thus, while regulation does not specifically obliges the CSPs to have a separate Sanctions Risk Assessment, this is highly recommended given that the exposures being analysed are different and therefore, the targeted results are also different from those of the Business Risk Assessment.
How A2CO supports CSPs
A2CO provides compliance support, governance support and regulatory support. This article is for general information only and does not constitute legal advice.
Our Sanctions specialist can help you identify your Sanctions GAPs, risks, vulnerabilities and assist you with desired action to rectify any shortcomings and start building a sanctions framework for the benefit and protection of your firm.
Need help reviewing your CSP’s sanctions risk assessment?
A2CO supports company service providers in Malta with compliance and governance support under Article 32 of the National Interest (Enabling Powers) Act