
MGA governance review flags lack of challenge and audit trail gaps
2026-07-30
Source: Global Gaming Insider
An MGA thematic review of governance among licensed operators found decision-making concentrated among a few executives, insufficient challenge of strategic proposals, and weak audit trails, prompting the regulator to urge stronger accountability structures as part of its risk-based 2025 supervisory priorities.
The Malta Gaming Authority (MGA) has concluded a thematic review of governance practices among its licensed B2C and B2B entities, uncovering several recurring deficiencies in how decisions are made, documented and contested. The exercise looked at the real-world functioning of CEO, compliance, internal audit and anti-money laundering/counter-financing of terrorism (AML/CFT) roles, drawing evidence from direct supervisory examinations and meetings with a sample of authorised persons.
While the regulator acknowledged that many licensees had built governance structures with strong senior management backing and increasingly risk-based compliance and assurance processes, it noted a pattern of decision-making being overly concentrated within a small circle of senior executives. Other common problems included little evidence that strategic proposals received meaningful challenge before approval, a limited assessment of the regulatory implications of major business moves, and weak audit trails that made it difficult to trace how conclusions were reached.
These shortcomings, the MGA warned, could undermine the ability of compliance, internal audit and AML/CFT staff to demonstrate effective oversight—especially when operators enter new jurisdictions, launch new products or undergo significant corporate restructuring. The authority stressed that stronger governance frameworks give key function holders sufficient authority and independence to escalate concerns, and that effective setups typically include governance committees, structured escalation routes, risk-based monitoring and cooperation among separate assurance functions.
Governance assurance ranks among the MGA’s supervisory priorities for 2025, sitting alongside reviews of operational resilience, self-exclusion systems and player protection controls. This programme forms part of a broader shift toward supervision that is calibrated to the specific risks posed by individual licensees, rather than relying predominantly on standard compliance checks. AML/CFT controls remain a significant component of that framework; Malta’s Financial Intelligence Analysis Unit treats remote gaming operators as subject persons and applies sector-specific guidance, risk assessments and supervisory examinations.
The MGA intends to use the review’s findings to help authorised persons evaluate whether their governance arrangements deliver effective accountability and whether key function holders can truly influence business decisions—rather than simply serving in procedural or reporting roles. The findings come on the heels of the MGA’s 2025 Annual Report, which recorded 109 completed thematic reviews, 19 licences issued and 30 administrative penalties totalling €162,520 ($185,743).