Implementing Article 32 – Sanctions Compliance Requirements

Stephanie Mangani

9/2/20265 min read

white concrete building
white concrete building

Introduction

On 20 August 2026, Malta’s Sanctions Monitoring Board (SMB) issued its guidance “Implementing Article 32 – Sanctions Compliance Requirements” under the National Interest (Enabling Powers) Act, Chapter 653. The guidance is intended to explain how organisations within the scope of Article 32 should establish, implement and maintain effective sanctions-compliance arrangements. The SMB’s central message is that sanctions compliance is not simply a matter of having policies or screening software: operators must be able to demonstrate that they understand their sanctions exposure and have effective, proportionate controls for identifying, managing and mitigating that risk.

The guidance is applicable to “Operators” listed in Schedule I of the Act, a category that largely mirrors the subject persons already falling within Malta’s AML/CFT framework. This includes financial institutions as well as a broad range of regulated businesses and professions. Consequently, the guidance is relevant not only to banks and payment institutions but also to other natural or legal person considered as a subject person under the PMLFTR.

A key principle is that the sanctions framework must be risk-based and proportionate. The SMB expressly recognises that there is no single compliance model suitable for every organisation. Controls should reflect an operator’s nature, size, complexity, activities and sanctions exposure, while being reviewed as sanctions regimes and business risks evolve. The guidance consequently expects operators to treat sanctions compliance as an ongoing management process rather than a static exercise.

Sanctions Risk Assessment

A fundamental element of the sanctions compliance framework is the Sanctions Risk Assessment (SRA). Operators should use this assessment to obtain a comprehensive understanding of the sanctions risks to which their business may be exposed. This requires consideration of the various characteristics and activities of the organisation, including its customer base, products and services, geographical footprint, distribution and delivery channels, transaction patterns, and relationships with relevant counterparties. The assessment should be conducted on an organisation-wide basis and supported by appropriate records, enabling the Operator to demonstrate the methodology applied, the factors considered, and the rationale underlying its conclusions.

The Sanctions Risk Assessment should be regarded as an ongoing process rather than a static or one-time exercise. Operators should establish a suitable mechanism for periodically reviewing the assessment and should undertake a further evaluation whenever significant changes may affect their sanctions exposure. Such circumstances may include expansion into new jurisdictions, the introduction or modification of products and services, changes to the organisation’s business model, or developments in applicable sanctions regimes. The findings of the SRA should also be incorporated into the organisation’s sanctions compliance framework and used to determine the nature and extent of the controls required to address the risks identified.

Customer due diligence, ownership and screening

An effective sanctions compliance framework requires Operators to establish a clear understanding of the parties and structures connected with a business relationship or transaction. Screening should not be confined to the customer with whom the Operator has a direct relationship. Appropriate due diligence should extend, where relevant, to beneficial owners, persons exercising control and other parties connected to the transaction, including counterparties. Operators should also examine the underlying ownership and control arrangements of relevant legal entities to identify potential sanctions exposure that may not be apparent from the identity of the immediate customer.

This is particularly important where ownership is layered or opaque. The guidance expects operators to look through corporate structures and consider whether designated persons may exercise ownership or control indirectly. It also addresses circumstances where a designated person holds less than 50% and requires appropriate investigation of the wider ownership structure where necessary.

Screening should cover relevant persons and entities against applicable sanctions lists, with procedures for identifying, investigating and resolving potential matches. Screening is not limited to onboarding: ongoing monitoring and re-screening are expected so that changes in sanctions designations or customer circumstances can be detected promptly. Enhanced due diligence should be applied where sanctions risk warrants additional scrutiny.

Freezing, escalation and reporting

The sanctions compliance framework should provide a clear process for responding to potential and confirmed sanctions matches. Where screening or subsequent investigation establishes that a person or entity is subject to applicable sanctions, the Operator must implement the measures required by the relevant legal framework without delay. Depending on the nature of the applicable restrictions, this may include restricting access to or dealings with relevant funds or economic resources and ensuring that such assets or resources are not made available, directly or indirectly, to the designated party. Appropriate escalation and documentation procedures should support these actions and ensure that decisions taken in response to sanctions alerts can be properly evidenced.

Operators are also subject to reporting requirements in relation to sanctions-related matters. Where a sanctions match is confirmed, assets are subject to freezing, or circumstances give rise to a reportable breach, the matter should be notified to the SMB in accordance with the relevant legal and regulatory requirements. Operators should maintain adequate records throughout the process, including the information considered, the conclusions reached and the measures implemented. Such documentation enables the organisation to demonstrate that potential sanctions concerns were assessed appropriately and that the required action was taken.

The guidance also addresses tipping-off controls, meaning organisations must ensure that information concerning sanctions investigations or freezing measures is appropriately restricted and that clients or third parties are not improperly alerted to sensitive information.

Governance and accountability

Effective sanctions compliance should form an integral part of an Operator’s wider governance and control arrangements. Responsibility for the sanctions framework should be clearly assigned, with senior management maintaining appropriate oversight of its implementation and effectiveness. The organisation should also designate a Sanctions Compliance Officer (or assign equivalent responsibility within the Compliance function) with appropriate expertise to oversee sanctions compliance. This role should have sufficient organisational standing, autonomy and access to the necessary personnel, information and resources to perform its responsibilities effectively.

The sanctions compliance framework should operate across different levels of the organisation, with responsibility for day-to-day controls, compliance oversight and independent review appropriately separated. Governance arrangements should ensure that material sanctions risks are communicated to, and considered by, senior management and, where applicable, the board. This ensures that sanctions compliance forms part of the organisation’s broader risk-management and governance processes rather than being confined to the operational performance of screening activities.

Policies, systems, training and outsourcing

Operators are expected to maintain documented policies and procedures covering risk assessment, due diligence, screening, escalation, freezing, reporting and record keeping. Systems should be appropriately calibrated and capable of supporting effective screening and monitoring.

Training is also an important component: staff involved in relevant activities should understand sanctions risks, escalation requirements and their responsibilities. Where functions are outsourced or reliance is placed on third parties, the operator retains responsibility for compliance and must maintain appropriate oversight and assurance over those arrangements.

The guidance additionally addresses matters such as data protection, record retention and controls surrounding frozen funds. It makes clear that sanctions compliance should be demonstrable in practice rather than existing merely on paper.

Overall significance

Overall, the SMB guidance represents a move toward a structured, integrated sanctions-compliance framework under Article 32. Its principal components are sanctions risk assessment, customer due diligence, ownership and control analysis, screening and ongoing monitoring, freezing and reporting, tipping-off controls, governance, policies and records, training, systems and third-party oversight.

For Operators, the publication of the guidance provides an opportunity to evaluate their existing sanctions arrangements and identify any areas requiring further development. This review should consider whether the organisation has adequately identified its sanctions exposure, whether its due diligence and screening processes capture all relevant parties, and whether mechanisms for escalation and regulatory reporting can respond effectively to potential issues. The review should also examine whether responsibility for sanctions compliance is clearly assigned and whether appropriate oversight is exercised at management level. In this respect, the SMB guidance can be used as a benchmark against which Operators may evaluate the adequacy and effectiveness of their existing sanctions controls.

The guidance is available through the SMB’s official Guidance Notes page.

How we can help

MS Squared Compliance can assist Operators in meeting the requirements under Article 32 by conducting a structured assessment of their existing sanctions compliance framework against applicable regulatory requirements. This may include reviewing governance arrangements, sanctions policies, risk assessments, customer and counterparty screening processes, transaction monitoring, escalation procedures, record-keeping and reporting arrangements. Independent review can identify gaps, recommend proportionate remediation measures and support the implementation of appropriate controls and procedures. We may also assist with staff training, testing and periodic reviews to assess the effectiveness of controls. Such support can help Operators establish a documented, risk-based and appropriately governed sanctions compliance framework.

Email

stephanie.mangani@mssquaredcompliance.com

© 2026 MS Squared Compliance. All rights reserved.