Sanctions Screening for Crypto in Malta: Legal Requirements for Businesses
Every crypto business registered in Malta – or passporting into the EU through a Maltese entity – faces a non-negotiable obligation: a functioning sanctions screening program matched to the pace of on-chain activity. Under the Malta Financial Services Authority (MFSA) regime, now transitioning to the MiCA CASP authorisation framework, a virtual asset service provider must screen clients, transactions and counterparties against applicable EU and international sanctions lists in real time. Failing to do so is not a gap that regulators treat as administrative. It is a licensing risk, a correspondent-banking risk and, in serious cases, a criminal exposure. This page maps the legal basis, the operational requirements and the cross-border dimensions that firms with a Maltese footprint must manage.
The Regulated Basis for Sanctions Screening in Malta
Sanctions screening for crypto in Malta flows from three overlapping legal sources: EU autonomous sanctions regulations, the EU's AML/CFT (anti-money laundering and counter-financing of terrorism) directives transposed into Maltese law, and the MFSA's supervisory expectations under the VFA (Virtual Financial Assets) framework – which is being absorbed into the MiCA CASP regime as Malta aligns with EU-wide standards. All three sources apply simultaneously, and operators cannot ring-fence compliance to one layer.
EU sanctions are directly applicable in Malta without domestic transposition. The moment the EU designates an individual, entity or wallet address under a sanctions regulation, that designation binds every Malta-licensed VASP. The MFSA reinforces this through its supervision of VFA service providers and, going forward, through the CASP authorisation obligations under MiCA. ESMA coordinates supervisory convergence across national competent authorities, which means the MFSA's expectations on sanctions controls track the EU-wide standard closely.
Malta also sits within the FATF framework. FATF Recommendation 15 expressly applies its standards to virtual asset service providers, requiring risk-based AML and sanctions controls as a condition of operating in good standing. A Malta VASP that fails to implement adequate screening faces dual exposure: domestic supervisory action from the MFSA and reputational damage in the broader FATF-compliant ecosystem that governs international banking relationships.
What Exactly Must Be Screened – and Against Which Lists?
A Malta-licensed crypto firm must screen at least three categories of subject: its clients and ultimate beneficial owners, the counterparties it interacts with in a transaction, and the wallet addresses involved in each transfer. Each category carries a distinct screening logic and a distinct list of applicable sanctions programs.
Client and UBO screening runs against the EU Consolidated Sanctions List, maintained by the European External Action Service, and against any additional national lists that the MFSA designates. Firms operating for clients who also have US exposure must additionally screen against OFAC's SDN List – the Specially Designated Nationals and Blocked Persons List maintained by the US Department of the Treasury. In our cross-border practice, we regularly advise firms that the OFAC dimension is frequently underweighted by European operators who assume EU-list compliance is sufficient. It is not, if the business touches USD-denominated stablecoins, US-domiciled counterparties or US correspondent rails.
Wallet-level screening adds a dimension that is specific to crypto. On-chain addresses can be linked to sanctioned entities through forensic tracing, even when the direct counterparty appears clean. Blockchain analytics tools – the same category of capability used by enforcement agencies – are the standard means of fulfilling this obligation. Firms that rely on name-screening alone, without address-level analytics, carry a demonstrable gap that the MFSA and a reviewing correspondent bank will identify.
Transaction monitoring, a closely related obligation, feeds into sanctions screening: velocity, size and address-cluster analysis can surface hits that a static list check would miss. The obligation is not to check once at onboarding; it is continuous.
MLRO Governance and Internal Oversight
Sanctions screening does not operate in a vacuum. It is embedded in the firm's broader AML governance structure, which the MFSA requires to be led by a named and approved MLRO (Money Laundering Reporting Officer). The MLRO is personally accountable for the adequacy of the firm's controls, including the sanctions program. Under the Maltese framework, and under the VFA/CASP structure, the MLRO must meet fitness-and-propriety criteria and must be resident or sufficiently accessible to the supervisory authority.
The MLRO's sanctions responsibilities include: approving the firm's sanctions policy, reviewing screening alert escalations, making or directing Suspicious Transaction Reports where a sanctions match or potential match arises, and maintaining a testing and audit cycle that confirms the screening tools are calibrated correctly. A misconfigured fuzzy-match threshold – set too tight – creates false-negative risk. Set too loose, it produces alert fatigue that overwhelms compliance staff and causes genuine hits to be dismissed. We have seen both failure modes in practice.
Governance documentation is not optional. The MFSA, like ESMA and the broader EU supervisory community, expects a written sanctions policy, a risk-based assessment specific to the firm's product and geography, and evidence of periodic testing. During supervisory review, the absence of documented governance is treated as evidence of inadequate controls – regardless of whether a violation actually occurred.
For a scoped assessment of your Malta compliance structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard architecture. Your entity type, client base and product mix change the analysis materially. Map your options.
How the Travel Rule Intersects with Sanctions Screening
The Travel Rule – the obligation to pass originator and beneficiary identifying information alongside a virtual asset transfer – is analytically distinct from sanctions screening but operationally inseparable from it. Under FATF Recommendation 16 and its implementation through EU frameworks, a Malta VASP transferring virtual assets must collect, verify and transmit specified data about the originator and beneficiary. That data is precisely the information needed to run a sanctions check at the point of transfer.
The interaction creates a sequencing obligation. Before releasing a transfer, the sending VASP must have verified the originator, screened both the originator and the beneficiary against applicable sanctions lists, transmitted the required data to the receiving VASP, and – where the receiving VASP is in a Travel Rule-compliant jurisdiction – confirmed receipt. In practice, this means integrating Travel Rule messaging protocols with real-time sanctions screening, so that a positive sanctions hit triggers a hold before the transaction is released rather than after.
Malta's position inside the EU means that the Travel Rule applies on an intra-EU basis under the Transfer of Funds Regulation (TFR), which was extended to crypto-asset transfers under MiCA. For transfers to or from counterparties outside the EU, the Travel Rule applies as a matter of FATF standards and the firm's own risk-based policy. A Malta VASP routing transfers to a Singapore, Hong Kong or Cayman counterparty must assess that counterparty's Travel Rule compliance posture and apply appropriate enhanced diligence where data is unavailable.
Cross-Border Sanctions Risk: Where the Malta Entity Sits vs. Where Business Flows
Licensing in Malta does not contain sanctions risk to Malta. The legal entity may sit in Valletta; the users may be in 40 countries; the banking may be in Lithuania or the Netherlands; the custody may be in Cayman. Every node in that chain introduces its own sanctions exposure, and the aggregate risk profile is the firm's responsibility.
In our practice, the cross-border mismatch that creates the most acute exposure is the gap between where the VASP is licensed and where its users are located. A Malta-licensed firm passporting under MiCA across the EU reaches users in jurisdictions where sanctions programs may overlap with – but not be identical to – the EU consolidated list. French, German and Dutch regulators each maintain supervisory expectations that may exceed the EU baseline in specific sectors or geographies. Operating on an assumption that a single list covers all EU activity is a structuring error.
Banking is equally sensitive. Correspondent banks – particularly those with US parent institutions – apply OFAC screening as a matter of their own compliance obligations. A Malta VASP that has not implemented OFAC screening will find that its banking relationships are subject to de-risking pressure, because the correspondent bank cannot rely on the VASP's program to satisfy its own obligations. We regularly advise firms on aligning their sanctions architecture to the standards that preserve banking access, not merely the minimum required by the MFSA.
If a prior application stalled or a banking relationship was lost, a structural review can surface the cause and the route back. Reach OBOLUS at info@oboluslaw.com or via t.me/oboluslaw. Map your options.
A Matter in Practice: Screening Gap Identified During Correspondent Bank Review
In a recent compliance matter, a Malta-licensed VASP providing exchange and custody services discovered – during a correspondent bank due-diligence review – that its screening tool was configured to check only the EU Consolidated Sanctions List. The tool was not running wallet-level address screening, and OFAC's SDN List was not integrated. The correspondent bank's internal review flagged the gap and issued a notice of potential de-risking. We were engaged to conduct a rapid gap analysis, reconfigure the sanctions policy, implement a dual-list and address-screening workflow, and produce the governance documentation required to satisfy the bank's remediation request. The banking relationship was preserved. The matter resolved within weeks of engagement. The firm subsequently restructured its MLRO reporting line to give the function direct board-level access, which the MFSA had noted as a supervisory expectation.
How the MFSA Audits Crypto AML and Sanctions Programs
MFSA supervisory reviews of Malta-licensed VASPs follow a risk-based approach: higher-risk business profiles attract more frequent and more intensive examination. The review typically covers four areas: the adequacy of the firm's written policies, the configuration and testing of its screening tools, the quality of its alert management and escalation process, and the documented training of relevant staff.
Screening tool configuration is a specific focus. Regulators have developed sufficient technical understanding to assess whether a tool is calibrated appropriately for the firm's product and counterparty mix. A firm that screens only against one list, or that runs screening only at onboarding rather than continuously, will be challenged on both counts. Equally, a firm that runs screening but cannot produce documentation of alert dispositions – showing who reviewed an alert, what investigation was conducted and what conclusion was reached – has a documentation failure that compounds the substantive risk.
Staff training records are reviewed as evidence that the compliance function is operational, not merely documented. The MFSA expects that the MLRO and key compliance personnel can demonstrate knowledge of the obligations specific to virtual assets – not just general AML principles. Under the MiCA CASP framework, these expectations will be articulated at ESMA level, creating a more uniform audit standard across EU jurisdictions. Malta-licensed firms should treat the transition as an opportunity to align their programs to the EU-wide CASP standard rather than to the minimum that satisfied the legacy VFA regime.
Self-Assessment Checklist: Is Your Malta Sanctions Program Adequate?
A Malta crypto firm can apply a practical self-assessment against five markers. First, are all applicable sanctions lists – EU Consolidated, OFAC SDN, and any others relevant to your business's geographic footprint – integrated into your screening tool? Second, does screening run at onboarding and continuously thereafter, including at the point of each transaction? Third, is wallet-level address screening running alongside name screening? Fourth, can you produce a documented alert management log showing disposition of every hit? Fifth, is your MLRO empowered and resourced to pause or block a transaction pending a sanctions determination?
A "no" on any of the first three markers is a material gap. A "no" on the fourth or fifth is a governance failure. In our practice, we find that firms in the growth phase – scaling rapidly after initial licensing – most commonly let the fourth and fifth markers deteriorate. The screening tool runs, but the human governance around it does not keep pace with volume. That disproportion is exactly what an MFSA review or a correspondent bank audit will surface.
The cross-border dimension adds a sixth marker: have you assessed the sanctions exposure of each jurisdiction in which you have users, banking or custody, and documented the assessment? If the answer is no, the firm is operating on an assumption of adequacy rather than evidence of it.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – our full practice coverage of AML, KYC and Travel Rule obligations across jurisdictions.
- MLRO and compliance officer function in Japan under the FSA and JVCEA – the MLRO governance model in a leading Asian crypto regime.
- Crypto regulation and licensing in Singapore – MAS's Payment Services Act framework and what it means for inbound operators.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect and transmit identifying information about the originator and beneficiary of a virtual asset transfer. Under FATF Recommendation 16 and its EU implementation through the Transfer of Funds Regulation extended under MiCA, this data must accompany the transfer. The sending VASP is responsible for collecting and verifying originator information; both parties must screen against applicable sanctions lists before the transaction is released.
Who must act as MLRO for a crypto firm?
The MLRO (Money Laundering Reporting Officer) must be a named individual approved by the relevant regulator – in Malta, the MFSA – and must meet fitness-and-propriety standards. The role carries personal accountability for the adequacy of the firm's AML and sanctions controls. The MLRO must be sufficiently senior and resourced to escalate concerns directly to the board, and must hold demonstrable knowledge of virtual-asset-specific AML obligations, not only general financial-crime principles.
How do regulators audit crypto AML programs?
Regulators apply a risk-based audit approach: higher-risk firms face more intensive scrutiny. Reviews cover the written sanctions and AML policy, the configuration and calibration of screening tools, the quality of alert management records, and staff training documentation. Regulators increasingly assess whether screening is truly continuous and wallet-level, not merely a one-time onboarding check. Under the MiCA CASP framework, ESMA is driving convergence of these audit standards across EU national competent authorities, including the MFSA.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, sanctions screening and Travel Rule compliance that sit around them. Digital assets are the entirety of our practice. We map the licence, compliance and banking stack across operating, custody and payment layers before you commit – because operating without the right controls risks enforcement, frozen banking rails and lost regulatory standing. To discuss your Malta sanctions program or your cross-border compliance structure, contact info@oboluslaw.com. Map your options.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML governance, sanctions screening programs and VASP compliance across EU and international regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.