Skip to main content
All Watch files
ConfirmedCourts & governance·Watch Explained·Malta·B2B and B2C governance assurance

Malta's gaming review found too much decision-making concentrated in too few hands

The MGA found mature governance in many businesses but also over-reliance on a small number of leaders, weak challenge records and thin audit trails.

Published 26 August 2026 · Updated 26 August 20267 minute read
By iGaming Atlas Editorial Team1 primary sourcesNext review 9 September 2026
Jump to a section

Evidence behind the story

What we checked

Primary documents

1 checked

Response record

Response included

Last source check

26 August 2026

Next scheduled review

9 September 2026

Why this matters

Gaming groups often concentrate technical knowledge, regulatory relationships and approval power in a few people. The review shows why governance quality is measured by challenge, succession and evidence, not by the number of policies on a shared drive.

Procedural status

Thematic findings published

The MGA has issued sector-wide supervisory findings and examples of stronger practice. The announcement does not identify a named enforcement action or monetary penalty.

The current picture

  • The MGA reviewed CEO, compliance, internal audit and AML/CFT functions across a sample of B2B and B2C authorised persons.
  • Common weaknesses included dependence on a few senior decision-makers, limited evidence of challenge and weak audit trails.
  • The publication is sector guidance and does not announce that every sampled licensee breached a rule.

Confirmed by the record

  • The review was a 2025 supervisory priority and used supervisory reviews and meetings.
  • The MGA also found many mature frameworks with active leadership and increasingly risk-based oversight.
  • Good practice included structured escalation, independent assurance, governance committees and risk-based monitoring.
  • The public announcement does not name the sample or quantify how many businesses showed each weakness.

Not established

  • The thematic findings are not a public sanction against all Malta licensees.
  • Over-reliance on a small leadership group does not prove fraud or deliberate concealment.
  • The summary does not establish that a specific licence decision or customer harm resulted from the weaknesses.
  • Atlas has not converted examples of good practice into mandatory legal rules absent a cited instrument.

Sources for each key claim

Evidence map

Each core claim is paired with the document used to substantiate it. Open the record and check our reading.

1

The review examined CEO, compliance, internal-audit and AML/CFT functions across B2B and B2C authorised persons.

2

Common themes included concentration of decision-making, insufficient evidence of challenge and weak audit trails.

3

The authority also recorded mature frameworks and good practice such as committees, escalation and independent assurance.

What changed, and when

  1. 1 January 2025

    Governance selected as priority

    The authority identifies the review as a 2025 supervisory priority; no exact start date is published.

  2. 29 July 2026

    Findings released

    The MGA publishes strengths, common weaknesses and examples of good practice.

  3. 24 August 2026

    Status classified

    Atlas records the publication as thematic guidance rather than a named sanction.

The warning is about dependency, not headcount

Malta's latest governance review does not say a gaming company becomes unsafe when a small executive team makes decisions. It says over-reliance on a limited number of senior people can weaken challenge, continuity and evidence. The risk appears when knowledge and authority have no credible substitute.

The MGA examined how chief executives, compliance, internal audit and AML/CFT functions worked in practice across a sample of B2B and B2C authorised persons. That cross-section matters because supplier and consumer-facing businesses distribute risk differently.

What the review found

The authority reports mature frameworks at many businesses, supported by active leadership and engaged key-function holders. It also identifies three recurring concerns: decisions concentrated in too few hands, insufficient records showing challenge and impact assessment, and weak audit trails.

Those weaknesses can coexist with polished governance documents. A board pack may list a decision without recording who questioned it, what regulatory consequence was considered or why an alternative was rejected.

Challenge needs evidence

A compliance officer disagreeing in a meeting is useful only if the concern reaches the decision, is evaluated and can later be reconstructed. The MGA's emphasis on challenge and impact assessment turns governance from attendance into an observable process.

This does not mean every disagreement requires a long transcript. It means material decisions need enough record to show the information considered, the objections raised and the owner of follow-up actions.

Audit trails protect the business too

A thin record makes supervision harder, but it also leaves a licensee unable to explain a reasonable decision after staff change or a market event. Strong trails preserve context, evidence and approvals without depending on one executive's memory.

The same applies to AML/CFT oversight. A risk-based decision may be defensible even when an outcome later looks bad, but only if the original risk, information and control response were documented.

Records also expose repeated exceptions. One urgent approval outside normal governance may be reasonable. Ten similar exceptions can show that the stated process is not the real process. Without dates, owners and reasons, internal audit cannot distinguish an unusual decision from a control that has quietly stopped operating.

What stronger practice looked like

The MGA points to structured escalation, risk-based monitoring, independent assurance functions, governance committees and early consideration of regulatory effects when entering markets or making significant changes. These are examples, not automatically a universal checklist.

Their common feature is distribution. Information moves to the right level, challenge can come from outside the decision owner and assurance is not performed solely by the team being reviewed.

That design also creates resilience. A deputy can find the record, a committee can revisit the reasoning and an independent reviewer can test whether the promised control actually operated. The system does not collapse when one senior person leaves or becomes unavailable.

What the publication does not establish

The announcement does not name sampled companies, count the businesses showing each weakness or impose a fine. It cannot support a headline claiming Malta found widespread governance breaches. It supports a narrower sector-level finding about patterns and stronger practice.

Nor does concentration prove misconduct. It describes fragility: what happens when a key person is absent, conflicted, wrong or unwilling to be challenged.

The next test is supervisory consequence

A follow-up review could show whether businesses changed committee structure, delegation and decision records. A named decision could show which themes the MGA treats as a breach rather than an improvement opportunity.

Until then, the useful lesson is practical. Governance is not strong because senior people are experienced. It is strong when the business can question, replace and audit their decisions.

Response record

The story includes the MGA's positive findings and avoids attributing thematic weaknesses to unnamed individual licensees.

Status: included

Sources checked