A reading of what the MFSA’s outsourcing requirements actually demand of a Malta-licensed technology function — and why concentration risk isn’t a hypothetical for firms operating in a jurisdiction with a genuinely small vendor pool.
Chapter 3 of the Financial Institutions Rulebook (FIR/03) sets out outsourcing requirements for MFSA-licensed financial institutions, running alongside the Authority’s broader Guidance on Technology Arrangements, ICT and Security Risk Management and Outsourcing Arrangements. For firms in scope of DORA, that guidance document steps back and DORA governs instead — but a large share of Malta-licensed entities, particularly smaller financial institutions and payment firms, still sit under FIR/03 directly. This is what it requires, and where Malta’s specific market structure makes the requirements harder to satisfy than the text alone suggests.
What FIR/03 actually asks for
The rulebook requires licence holders to correctly classify every arrangement — distinguishing outsourcing from non-outsourcing service relationships — and to identify which outsourced functions are critical or important. That classification decision is the foundation: get it wrong, and every downstream governance step inherits the error. The MFSA’s thematic review of outsourcing and third-party arrangements found this was precisely where institutions most often failed, with critical functions like compliance, risk, and internal audit repeatedly misclassified as non-critical.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
Beyond classification, the requirements cover pre-outsourcing due diligence, written contracts with minimum prescribed clauses, ongoing monitoring, audit and access rights for both the institution and the MFSA, and — for banks under Banking Rule BR/14/2020 — written notice to the Authority at least 60 days before any material outsourcing arrangement takes effect.
Who this is for
- The compliance officer at a Malta-licensed financial institution who has to differentiate genuine outsourcing from ordinary supplier relationships, and prove it to the MFSA’s satisfaction.
- The CTO evaluating a new vendor and trying to work out whether it triggers the 60-day notice period, the register entry, or both.
- The board member reading the MFSA’s thematic review findings and wondering how many of the observed failures apply to their own institution.
The register is a dependency map, not a vendor list
The MFSA’s expectations for the outsourcing register go well beyond a list of suppliers. Firms are expected to record sub-outsourcing chains — which entities are involved, where they’re registered, where data is processed and stored — along with substitutability (how easily the service could be replaced), time-criticality, and whether a written, referenced exit strategy exists. Treated as an administrative log, the register misses the point. The MFSA treats it as a map of operational dependency, and reads it that way during supervisory engagement.
Why concentration risk isn’t hypothetical here
Malta’s regulated-services market is small, and the pool of local compliance, audit, and technology providers serving it is smaller still. The MFSA’s thematic review found a concerning pattern: several institutions relying on the same limited pool of outsourced compliance and audit professionals, often for only a few hours of engagement per week, with real doubt about whether that level of commitment could satisfy the underlying regulatory obligation being outsourced.
This isn’t a failure of any one firm’s due diligence — it’s a structural feature of operating in a small jurisdiction. The same specialist providers serve much of the sector, which means concentration risk exists at the systemic level even where each individual firm’s outsourcing arrangement looks reasonable in isolation. The Authority is explicit that firms carry some responsibility for being aware of this, even though individual firms have limited visibility into who else uses the same provider.
The intra-group blind spot
A second recurring finding: institutions treating intra-group outsourcing — arrangements with a parent company or affiliate — as exempt from the same scrutiny applied to third-party arrangements. It isn’t. Intra-group arrangements are required to meet the equivalent standard: risk assessment, contractual terms, and ongoing oversight, regardless of the corporate relationship. The MFSA has flagged heavy reliance on intra-group outsourcing conducted without sufficient risk evaluation as a specific area of concern.
Sub-outsourcing: the risk you didn’t contract for
The outsourcing agreement should state explicitly whether sub-outsourcing is permitted, and if it is, the MFSA expects prior authorisation mechanics, notification periods that give the firm a genuine chance to object, and equivalent controls for any sub-outsourcing of data specifically. Without these, a firm can end up in a position where its contracted vendor is effectively a broker, and the actual data handling and processing sits with entities the firm never assessed and doesn’t know exist.
What actually holds up under review
- A documented classification methodology that correctly identifies critical and important functions — tested against the MFSA’s own thematic review findings, not just the firm’s internal assumptions.
- An outsourcing register that captures sub-outsourcing chains, substitutability, and exit strategy — not just vendor names and contract dates.
- Evidence that intra-group arrangements went through the same due diligence as third-party ones.
- A concentration risk assessment that acknowledges the realistic size of Malta’s specialist vendor pool, rather than assuming each contract is independently low-risk.
- Sub-outsourcing controls in every material contract — authorisation, notification, and objection rights — not just a silent assumption that the primary vendor handles everything itself.
Knowing which framework actually applies to you
A firm-level scoping question worth settling before anything else: the MFSA’s separate Guidance on Technology Arrangements, ICT and Security Risk Management and Outsourcing Arrangements explicitly does not apply to entities in scope of DORA — those firms are governed by DORA’s own requirements instead. FIR/03’s outsourcing chapter continues to apply regardless, but a firm that has assumed DORA fully supersedes its Chapter 3 obligations, or conversely has assumed FIR/03 alone is sufficient without checking DORA applicability, is working from the wrong rulebook. This determination should sit in writing, reviewed whenever the firm’s licensing category or DORA in-scope status changes.
A related finding from the same thematic review worth flagging to any board: institutions relying on a single safeguarding channel for client funds, without diversification, heighten their exposure in the event of institutional failure. It’s not a technology-outsourcing point directly, but it’s the same underlying governance failure — over-concentration accepted without a documented risk assessment — showing up in a different part of the same review. Annual audits of safeguarding arrangements are a standing obligation (R3-2.9.25), and material changes to safeguarding methods must be notified to the MFSA (R3-2.9.12); a firm’s outsourcing governance and its safeguarding governance are worth reviewing together rather than as separate compliance streams.
How we engage with this
We read outsourcing arrangements against what FIR/03 and the MFSA’s guidance actually require, as a Supplier and Dependency Review — including an honest assessment of concentration exposure given the realistic size of the Malta vendor market a firm draws from. The output is a written assessment the board can act on, not a compliance checklist.
We don’t broker vendor relationships. We don’t sell outsourcing register software. We don’t represent firms to the MFSA. We read what’s there, identify what’s missing, and write it down for the people who have to decide what to do about it.
Pricing is published at /pricing/. If your outsourcing register hasn’t been reviewed against the MFSA’s actual thematic review findings, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming