Malta licensee compliance guide

Malta Gaming Authority compliance monitoring: build the licensee operating record.

MGA compliance is not one annual audit or one portal calendar. It is the recurring operating record that connects the authorised activity, approved people, reports, notifications, controls, evidence and every material change.

The short answer

Monitor the complete licensee record—not a generic checklist.

A useful MGA compliance platform supports—not replaces—the licensee monitoring programme. It identifies what applies to the licensed entity and activity, connects each requirement to an accountable owner and control, preserves the evidence, and re-tests the position whenever the business, technical set-up or rulebook changes.

01

Role-specific

B2C operators, B2B critical gaming suppliers and other authorised persons do not share one identical obligation set.

02

Source-bound

The Gaming Act, regulations, directives, licence conditions, Authority notices and current portal routes must be read together.

03

Event-driven

Some work is periodic. Other work is triggered by a technical, corporate, supplier, people, product or incident event.

04

Evidence-led

The durable output is the decision, control, submission, receipt, exception and remediation history—not a green dashboard alone.

Monitoring perimeter

Six workstreams belong in one reviewable model.

The exact duties vary by authorisation, but the operating structure is stable: establish scope, keep approved accountability current, run recurring obligations, classify change, route regulatory events and retain assurance-ready evidence.

Authorisation and activity scope

Keep the licensed entity, B2C or B2B role, approved game types, services, domains, markets and material suppliers connected to the obligations they activate.

Key functions and competence

Record approved role holders, conflicts, involvement changes, renewal evidence and continuing-professional-development requirements without treating a job title as approval.

Recurring reporting and dues

Build a verified calendar for applicable monthly, half-yearly, annual, financial, audit, player-funds, gaming-revenue, fee and tax obligations.

Operational and corporate change

Classify changes before implementation: technical set-up, ownership, financing, policies, terms, payment methods, suppliers, key persons and other material events can follow different routes.

Incidents and regulatory events

Route information-security incidents, suspicious betting, complaints, investigations and other reportable events to the correct owner and timetable with the source decision attached.

Controls, evidence and assurance

Connect each requirement to the operating control, evidence, exception, remediation and review, then package the record for supervision, audit or an Authority request.

Operating cycle

Turn MGA obligations into owned, evidenced work.

A calendar catches dates. A compliance operating model also preserves applicability, event triggers, dependencies, evidence and the reason a requirement was closed.

  1. 01

    Scope

    Confirm the entity, licence, activity, role, game type, system and supplier perimeter.

  2. 02

    Map

    Bind current MGA sources and licence-specific conditions to requirements and owners.

  3. 03

    Operate

    Run controls, reporting, notifications, payments and approved-person workflows.

  4. 04

    Evidence

    Retain decisions, submissions, receipts, testing, exceptions and remediation.

  5. 05

    Re-test

    Review the record after regulatory, product, corporate, technical or supplier change.

Timing architecture

Separate recurring dates from event-triggered deadlines.

These are examples from current MGA material, not a universal calendar. Confirm applicability, the current instrument, the portal route and the calculation point for the specific licensee before relying on any date.

Monthly when applicable

B2B compliance reports

The MGA says B2B licensees submit monthly reports identifying the B2B and B2C client companies receiving licensable services and the relationship type.

Monthly when applicable

Compliance contribution

The MGA fee-and-tax guidance states that applicable B2C compliance contributions are calculated monthly and paid by the twentieth day of the following month.

Within 6 months

Audited financial statements

The reporting page states that audited financial statements are submitted within six months after the end of the financial year.

Within 9 months

Auditor declarations and letter

Applicable player-funds and gaming-revenue declarations, and the auditor’s management letter, are listed with a nine-month year-end deadline.

Within 30 days

Specified change notifications

The MGA publishes a defined 30-day route for specified technical-set-up, corporate, policy, terms-and-conditions and payment-method changes.

72 hours or immediate

Specified regulatory events

The reporting page gives a 72-hour route for defined information-security incidents and says suspicious betting is reported immediately.

Change classification

Do not turn the 30-day list into a universal rule.

The MGA’s published 30-day page is one route, not the whole change-control model. A change can instead need prior approval, another notification period, immediate reporting, supporting testing or no submission. Classify first and retain the decision with the official source used.

  1. 01

    Describe the event

    Record the legal entity, licence, activity, system, supplier, person, policy or financial fact that is changing.

  2. 02

    Compare the approved baseline

    Identify what differs from the material already submitted, approved or used to support the current authorisation.

  3. 03

    Find the current route

    Check binding instruments, licence conditions, current MGA guidance and the precise Licensee Portal application.

  4. 04

    Resolve timing and dependencies

    Determine whether approval, notification, audit, testing, documents, fees or named sign-off must precede the change.

  5. 05

    Retain the completed record

    Keep the decision, reviewers, submitted package, receipt, effective date, production proof and any follow-up together.

Platform boundary

Use software to organise the record—not to impersonate the accountable function.

Atlas can connect the MGA source, requirement, owner, control, date, evidence, submission receipt and monitored change. It cannot obtain an approval, hold a key-function certificate, submit legal advice, conduct an independent audit or operate player-level controls.

  • Approved key-function judgement and regulatory accountability
  • Legal interpretation of an unresolved or licence-specific question
  • Licensee Portal authority, submission approval and formal regulator correspondence
  • Independent systems, compliance, statutory or agreed-upon-procedures audit work
  • AML transaction monitoring, identity verification and suspicious-activity investigation
  • Player-risk detection, intervention and suspicious-betting surveillance

Questions

MGA compliance monitoring FAQ

Short answers to the questions teams should settle before relying on a cross-market operating model.

What is MGA compliance monitoring?

MGA compliance monitoring is the recurring work used by a Malta Gaming Authority licensee to identify the obligations that apply to its authorised activities, assign accountable owners, track reports and notifications, preserve control evidence, assess operational change and respond to supervisory or audit activity. The exact record depends on the licence, role, game types, delivery model and current binding instruments.

What should an MGA compliance calendar track?

It should track only duties that have been verified for the licensee. Depending on scope, that can include B2B monthly compliance reports, licence and compliance dues, audited financial statements, auditor declarations and management letters, industry performance returns, key-function renewals, portal notifications, incident reporting and remediation commitments.

Does an MGA compliance platform replace the compliance key function?

No. The MGA requires approval for key functions and publishes eligibility and continuing-professional-development requirements. Software can organise sources, requirements, owners, dates, decisions and evidence, but it cannot hold the certificate, exercise the approved person’s judgement or make a regulatory submission on that person’s behalf without an authorised process.

Which MGA changes require notification?

The notification route and timing depend on the change. The MGA publishes a specific 30-day list covering matters such as non-essential changes to the key technical set-up, entity events, updated policies and procedures, material terms-and-conditions changes and payment-method changes. Other changes may require prior approval, immediate reporting or a different portal application, so teams should classify each change against the current official route before implementation.

What evidence should an MGA licensee retain?

A practical record includes the governing source and version, applicability decision, licence and activity scope, owner, due date, control, operating evidence, submission or notification receipt, approvals, exceptions, remediation and review history. Technical changes should also retain the approved baseline, updated diagrams, risk assessment, testing and release decision.

Is an MGA compliance audit the same as ongoing monitoring?

No. Ongoing monitoring is the licensee’s recurring operating discipline. A compliance or systems audit is a defined assurance engagement that may be required by the Authority or a binding instrument. The MGA states that operators may engage an approved audit service provider when such an audit or report is required. A platform may organise the audit trail, but it does not replace the approved auditor.

Atlas

Put the market context next to the compliance work.

See how Atlas connects requirements, systems, owners, evidence and monitored change across your priority markets.

Book an Atlas demo