Malta licensee compliance guide
Malta Gaming Authority compliance monitoring: build the licensee operating record.
MGA compliance is not one annual audit or one portal calendar. It is the recurring operating record that connects the authorised activity, approved people, reports, notifications, controls, evidence and every material change.
The short answer
Monitor the complete licensee record—not a generic checklist.
A useful MGA compliance platform supports—not replaces—the licensee monitoring programme. It identifies what applies to the licensed entity and activity, connects each requirement to an accountable owner and control, preserves the evidence, and re-tests the position whenever the business, technical set-up or rulebook changes.
Role-specific
B2C operators, B2B critical gaming suppliers and other authorised persons do not share one identical obligation set.
Source-bound
The Gaming Act, regulations, directives, licence conditions, Authority notices and current portal routes must be read together.
Event-driven
Some work is periodic. Other work is triggered by a technical, corporate, supplier, people, product or incident event.
Evidence-led
The durable output is the decision, control, submission, receipt, exception and remediation history—not a green dashboard alone.
Monitoring perimeter
Six workstreams belong in one reviewable model.
The exact duties vary by authorisation, but the operating structure is stable: establish scope, keep approved accountability current, run recurring obligations, classify change, route regulatory events and retain assurance-ready evidence.
Authorisation and activity scope
Keep the licensed entity, B2C or B2B role, approved game types, services, domains, markets and material suppliers connected to the obligations they activate.
Key functions and competence
Record approved role holders, conflicts, involvement changes, renewal evidence and continuing-professional-development requirements without treating a job title as approval.
Recurring reporting and dues
Build a verified calendar for applicable monthly, half-yearly, annual, financial, audit, player-funds, gaming-revenue, fee and tax obligations.
Operational and corporate change
Classify changes before implementation: technical set-up, ownership, financing, policies, terms, payment methods, suppliers, key persons and other material events can follow different routes.
Incidents and regulatory events
Route information-security incidents, suspicious betting, complaints, investigations and other reportable events to the correct owner and timetable with the source decision attached.
Controls, evidence and assurance
Connect each requirement to the operating control, evidence, exception, remediation and review, then package the record for supervision, audit or an Authority request.
Operating cycle
Turn MGA obligations into owned, evidenced work.
A calendar catches dates. A compliance operating model also preserves applicability, event triggers, dependencies, evidence and the reason a requirement was closed.
- 01
Scope
Confirm the entity, licence, activity, role, game type, system and supplier perimeter.
- 02
Map
Bind current MGA sources and licence-specific conditions to requirements and owners.
- 03
Operate
Run controls, reporting, notifications, payments and approved-person workflows.
- 04
Evidence
Retain decisions, submissions, receipts, testing, exceptions and remediation.
- 05
Re-test
Review the record after regulatory, product, corporate, technical or supplier change.
Timing architecture
Separate recurring dates from event-triggered deadlines.
These are examples from current MGA material, not a universal calendar. Confirm applicability, the current instrument, the portal route and the calculation point for the specific licensee before relying on any date.
Monthly when applicable
B2B compliance reports
The MGA says B2B licensees submit monthly reports identifying the B2B and B2C client companies receiving licensable services and the relationship type.
Monthly when applicable
Compliance contribution
The MGA fee-and-tax guidance states that applicable B2C compliance contributions are calculated monthly and paid by the twentieth day of the following month.
Within 6 months
Audited financial statements
The reporting page states that audited financial statements are submitted within six months after the end of the financial year.
Within 9 months
Auditor declarations and letter
Applicable player-funds and gaming-revenue declarations, and the auditor’s management letter, are listed with a nine-month year-end deadline.
Within 30 days
Specified change notifications
The MGA publishes a defined 30-day route for specified technical-set-up, corporate, policy, terms-and-conditions and payment-method changes.
72 hours or immediate
Specified regulatory events
The reporting page gives a 72-hour route for defined information-security incidents and says suspicious betting is reported immediately.
Change classification
Do not turn the 30-day list into a universal rule.
The MGA’s published 30-day page is one route, not the whole change-control model. A change can instead need prior approval, another notification period, immediate reporting, supporting testing or no submission. Classify first and retain the decision with the official source used.
- 01
Describe the event
Record the legal entity, licence, activity, system, supplier, person, policy or financial fact that is changing.
- 02
Compare the approved baseline
Identify what differs from the material already submitted, approved or used to support the current authorisation.
- 03
Find the current route
Check binding instruments, licence conditions, current MGA guidance and the precise Licensee Portal application.
- 04
Resolve timing and dependencies
Determine whether approval, notification, audit, testing, documents, fees or named sign-off must precede the change.
- 05
Retain the completed record
Keep the decision, reviewers, submitted package, receipt, effective date, production proof and any follow-up together.
Official material
Build from the current MGA source, then preserve the version used.
The public pages below are the starting points checked for this guide. They do not replace licence-specific conditions, direct Authority correspondence, updated portal instructions or specialist advice on an unresolved obligation.
MGA — Key Functions
Current application, eligibility, conflict, renewal and continuing-professional-development requirements for approved key functions.
MGA — Reporting Requirements
Current reporting and notification routes, including B2B reports, financial submissions, go-live, outsourcing, specified security incidents and suspicious betting.
MGA — 30-Day Notification Requirements
The published 30-day route for specified technical, corporate, policy, terms-and-conditions and payment-method changes.
MGA — Gaming Authorisations and Compliance Directive
Binding instrument covering authorisations and compliance requirements, including role-specific key functions and reporting obligations.
MGA — Audit Service Provider Approvals
The Authority’s current route for approved providers of systems audits, compliance audits, statutory audits and agreed-upon-procedures reports.
MGA — Licence Fees and Taxation Guidance
Official guidance on licence fees, gaming tax and the timing and calculation framework for applicable compliance contributions.
Platform boundary
Use software to organise the record—not to impersonate the accountable function.
Atlas can connect the MGA source, requirement, owner, control, date, evidence, submission receipt and monitored change. It cannot obtain an approval, hold a key-function certificate, submit legal advice, conduct an independent audit or operate player-level controls.
- Approved key-function judgement and regulatory accountability
- Legal interpretation of an unresolved or licence-specific question
- Licensee Portal authority, submission approval and formal regulator correspondence
- Independent systems, compliance, statutory or agreed-upon-procedures audit work
- AML transaction monitoring, identity verification and suspicious-activity investigation
- Player-risk detection, intervention and suspicious-betting surveillance
Questions
MGA compliance monitoring FAQ
Short answers to the questions teams should settle before relying on a cross-market operating model.
What is MGA compliance monitoring?
MGA compliance monitoring is the recurring work used by a Malta Gaming Authority licensee to identify the obligations that apply to its authorised activities, assign accountable owners, track reports and notifications, preserve control evidence, assess operational change and respond to supervisory or audit activity. The exact record depends on the licence, role, game types, delivery model and current binding instruments.
What should an MGA compliance calendar track?
It should track only duties that have been verified for the licensee. Depending on scope, that can include B2B monthly compliance reports, licence and compliance dues, audited financial statements, auditor declarations and management letters, industry performance returns, key-function renewals, portal notifications, incident reporting and remediation commitments.
Does an MGA compliance platform replace the compliance key function?
No. The MGA requires approval for key functions and publishes eligibility and continuing-professional-development requirements. Software can organise sources, requirements, owners, dates, decisions and evidence, but it cannot hold the certificate, exercise the approved person’s judgement or make a regulatory submission on that person’s behalf without an authorised process.
Which MGA changes require notification?
The notification route and timing depend on the change. The MGA publishes a specific 30-day list covering matters such as non-essential changes to the key technical set-up, entity events, updated policies and procedures, material terms-and-conditions changes and payment-method changes. Other changes may require prior approval, immediate reporting or a different portal application, so teams should classify each change against the current official route before implementation.
What evidence should an MGA licensee retain?
A practical record includes the governing source and version, applicability decision, licence and activity scope, owner, due date, control, operating evidence, submission or notification receipt, approvals, exceptions, remediation and review history. Technical changes should also retain the approved baseline, updated diagrams, risk assessment, testing and release decision.
Is an MGA compliance audit the same as ongoing monitoring?
No. Ongoing monitoring is the licensee’s recurring operating discipline. A compliance or systems audit is a defined assurance engagement that may be required by the Authority or a binding instrument. The MGA states that operators may engage an approved audit service provider when such an audit or report is required. A platform may organise the audit trail, but it does not replace the approved auditor.
Atlas
Put the market context next to the compliance work.
See how Atlas connects requirements, systems, owners, evidence and monitored change across your priority markets.