- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Egypt
- Estonia
- Eswatini
- Ethiopia
- Finland
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Lithuania
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Mongolia
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Poland
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- USA
- Vietnam
MALTA KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Malta
Verify Maltese customers and businesses through the notified Maltese eID scheme, NFC chip reading, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the PMLFTR today and AMLR from 10 July 2027.
Operational Performance for Malta KYC
Our Numbers Speak Volumes
96.79%
First-pass
verification rate
< 10 sec
Median
verification time
5+
Maltese ID methods
supported
Malta IDV/KYC Challenges
The eID Reaches the Card, Not the Phone
Malta's notified eID sits on the identity card at assurance level high, but everyday use needs a card reader and a PIN. No national eID app exists, so remote onboarding leans on chip reading.
Maltese Diacritics Vanish in the Machine-Readable Zone
Maltese names carry Ċ, Ġ, Ħ and Ż, but ICAO Doc 9303 bars diacritics in the machine-readable zone. ŻAMMIT and ZAMMIT then reach sanctions screening as two people.
Ownership Data Is No Longer Open to Look Up
Since 10 July 2026 the Malta Business Registry register runs three-tier access, no public tier. Obliged entities pay a fee for CDD access. Simplified-regime companies file no BO record; others file Form BO4 by 10 January 2027.
Two Supervisors, One Binding Rulebook
The FIAU supervises AML in Malta, and the MFSA and MGA examine as its agents. One licensed firm can face review from two directions against the same binding Implementing Procedures.
Regulatory Update
What AMLR Changes for Identity Verification in Malta
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Malta from 10 July 2027, with no transposition period. It sets the due diligence rules the PMLFTR and FIAU Implementing Procedures will operate under, with AMLA supervising from Frankfurt.
Timeline
- End of 2026 Member State EUDI Wallet issuance target
- September 2026 Bids close 24 September on Malta's EU Digital Identity Wallet tender (CT2274/2026), run for the MDIA
- 10 July 2027 AMLR applies, no transposition
- December 2027 Private relying parties using strong user authentication, micro and small firms excluded, must accept EUDI Wallets on user request. eIDAS 2.0 Art 5f(2)
- 2028 AMLA direct supervision begins
eIDAS Becomes an Explicit Route
Article 22(6) gives obliged entities two equal means: an identity document or passport with reliable independent sources, or eIDAS electronic identification at substantial or high with relevant qualified trust services. Malta notified at level high in 2021, so that route is open today.
The Ownership Test Tightens
AMLR harmonises the beneficial-ownership test at 25% or more and requires control to be assessed in parallel, so KYB checks cover holdings and control.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 18 keeps customer due diligence accountable with the obliged entity even when verification is outsourced, and Chapter 6 of the FIAU Implementing Procedures Part I already sets the conditions for outsourcing today.
FOR MFSA-SUPERVISED BUSINESSES
Streamline MFSA-Supervised Onboarding in Malta
Connect identity verification, QES and compliance evidence in one configurable workflow, with Penny Drop where risk calls for it, for firms within the MFSA's remit. Reduce customer drop-off and manual handovers while giving compliance teams a review-ready record of every decision.
1. Verify the Customer
Verify identity using the configured route, such as the notified Maltese eID, NFC chip reading or document and biometric checks.
2. Complete Qualified Signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together.
3. Confirm the Payment Account
Where the risk assessment calls for it, Penny Drop Verification confirms that the payment account belongs to the customer.
Shufti's IDV/KYC Solutions for Malta
KYC Solutions
Clear onboarding for Maltese customers under the PMLFTR, with age and address checked in the same flow as identity, each check completing in seconds.
Explore MoreIdentity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.Face Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation with document verification where higher assurance is required. For MGA licensees it supports the registration and minor-protection checks in MGA Directives 3 and 2 of 2018.
.Address Verification
Shufti verifies Maltese address-bearing documents, including the combined electricity and water utility bill, internet bills and bank statements from major Maltese issuers.
.Document Verification
Verification of the Maltese identity card, the Maltese passport, the eResidence document and the Maltese driving licence, including NFC chip reading on the identity card and the biometric passport.
.Bank Account Verification
Confirms a Maltese bank account (MT IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.
.KYB Solutions
Shufti checks businesses as deeply as the people behind them, supporting your risk-based approach under the PMLFTR. Registry records, beneficial ownership and VAT details are checked in real time, and UBOs screened against 4,000+ watchlists for sanctions and adverse media.
Explore MoreBusiness Verification
Automated validation of Malta Business Registry data, the registration number, the MT-prefixed VAT number and the directors entitled to bind the entity.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities and higher-risk sectors, with PEP screening of directors and beneficial owners and source-of-wealth checks, supporting the risk-based obligations in the PMLFTR and the FIAU Implementing Procedures.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP, and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing monitoring calibrated to Maltese financial flows flags anomalies, supporting the controls the FIAU expects, with reports prepared for filing through goAML under Regulation 15 PMLFTR.
.Supported Verification Methods for Malta
Every Verification Route Malta Uses, in One Platform
Shufti supports the full range of remote verification routes used in Malta, from the EU Digital Identity Wallet to the notified Maltese eID scheme, NFC chip reading and attended video identification. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6) points to electronic identification means at the eIDAS substantial or high levels. Malta is procuring its EU Digital Identity Wallet through the Malta Digital Innovation Authority, and Shufti is built to accept wallet-based verification as it goes live.
Notified eID
LiveeIDAS HighThe Maltese eID scheme covers the identity card and the residence document, notified at assurance level high on 10 December 2021. Citizens use it through the eID account at eid.gov.mt with a card reader. Malta has no bank eID scheme.
Docless Database eIDV
LiveDatabase-driven verification confirms identity in seconds for low-risk onboarding, with no document upload. Shufti confirms which sources are available for Malta at scoping and escalates as risk rises.
NFC Chip Verification
LiveShufti reads the contactless chip in the Maltese identity card, the eResidence document and the Maltese biometric passport. Chip reading gives the strongest document-based assurance where an eID session is not available.
Document and Face Biometric
LiveExpressly permitted under AMLR Art 22(6)(a). Authentication of the identity card, passport, eResidence document and driving licence, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness confirming a real, present person.
Video Identification
LiveSection 4.3.1.2 of the FIAU Implementing Procedures Part I permits attended video identification, binding on subject persons under Regulation 17 of the PMLFTR. The call must give simultaneous visual and verbal contact, the customer is asked to tilt the document so security features are visible, and the session is retained with timestamped screenshots.
Qualified Electronic Signature
LiveRegulation 7(1)(a) of the PMLFTR accepts relevant trust services under Regulation (EU) No 910/2014 as a source for verifying identity. Shufti runs eIDAS-qualified signing powered by Evrotrust, an EU qualified trust service provider, producing PAdES-LTV signatures. For Malta the signing identity check runs through NFC and face biometrics.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Top Vendor for Product Execution in the Liminal Index for KYC 2026
View Report
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader in G2 Fall 2026 reports
Read MoreVerifications with robust evidentiary support
Evidence-Ready Checks Across People & Businesses
Individual Documents We Verify
Shufti verifies 11+ Maltese document types.
View All Supported DocumentsKarta tal-Identità (Maltese Identity Card)
Mandatory from age 14 under the Identity Card and other Identity Documents Act. Contactless chip with authentication and qualified signature certificates, and the notified eID at level high.
Passaport Malti (Maltese Passport)
Biometric passport issued by the Passport Office of Identità, valid for ten years. It captures the facial image, fingerprints and signature, and Shufti reads its chip.
eResidence Document
Issued to EU and EEA nationals registering residence beyond three months, and covered alongside the identity card in Malta's eIDAS notification.
Driving Licence
EU-format photocard licence issued by Transport Malta. The FIAU Implementing Procedures accept it as photographic identity evidence and, where the address is printed, as address evidence.
Entity Identity
Malta Business Registry (MBR) Registration Certificate
Malta Business Registry record proving legal existence. It evidences company identity, registration number, registered office and appointed officers in the KYB file.
Certificate of Incorporation
Issued on formation under the Companies Act. It confirms legal existence and the registration number later KYB refreshes are matched against.
Tax Identity
VAT Registration Number
Maltese VAT identification carries the MT prefix ahead of eight digits, issued by the Malta Tax and Customs Administration. Article 11 small enterprise numbers lack the prefix and fail VIES.
PE Number (Employer Registration Number)
Permission to Employ number from the Malta Tax and Customs Administration, held by any entity employing people in Malta and identifying it inside the Final Settlement System.
Ownership & Control (UBO)
Beneficial Ownership Register Extract
Held by the Malta Business Registry, on three-tier access since 10 July 2026. Simplified-regime companies file none: their register of members is deemed to be the BO register.
Memoranda and Articles of Association
Constitutional documents defining shareholding, voting rights and who can bind the entity. Shufti reconciles them against the register so the control chain stays documented and reviewable.
Languages We Cover
Maltese and English Document Handling
Malta has two official languages, Maltese and English, and customer records reach onboarding in both. Shufti processes both and preserves the Maltese characters in the audit record.
Maltese Name Matching Controls
Maltese uses ċ, ġ, ħ and ż with the għ digraph, and the machine-readable zone drops them. Diacritic-tolerant matching resolves ŻAMMIT and ZAMMIT to one person.
Evidence Consistency Across Verification Steps
Document, face and screening outputs sit in one case record, so an FIAU or MFSA review is answered from one file.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer Avoidable Re-submissions
Capture tuned to the Maltese identity card, passport and eResidence designs, plus NFC chip reading, cuts avoidable re-uploads.
Cleaner Audit Trails
Structured logs aligned to the Regulation 13 retention rule and goAML reporting keep every decision ready for inspection.
Better Name Matching Outcomes
Matching handles the Maltese diacritics and the għ digraph alongside the accent-free machine-readable zone, cutting false positives and manual review.
One Workflow, One Back Office
KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.
National ID-First Flow Design
Flows lead with the Maltese identity card and fall back to passports and eResidence documents for everyone else.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to the record-keeping standard in Regulation 13 of the PMLFTR, so the file is retrievable for supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors Malta Business Registry filings for shareholding and control changes. Where the register of members is deemed the BO register, control comes from constitutional documents.
Built To Fit Malta's Compliance Landscape
Malta Financial Services Authority (MFSA)
Supervises banking, insurance, investment services and crypto-asset service providers, and runs AML examinations as an agent of the FIAU. Shufti aligns identity evidence, risk classification logs and ongoing monitoring to its requirements.
Financial Intelligence Analysis Unit (FIAU)
Receives suspicious transaction and activity reports through goAML and issues the binding Implementing Procedures. Audit trails and escalation logs support reporting.
Malta Gaming Authority (MGA)
Regulates land-based and remote gaming under the Gaming Act, examining as an agent of the FIAU. Shufti supports age verification and reviewable player onboarding evidence.
Information and Data Protection Commissioner (IDPC)
Malta's supervisory authority for the GDPR and the Data Protection Act. Data minimisation, lawful-basis processing and EU-region hosting keep Maltese personal data handling defensible. The PMLFTR separately restricts a customer's right of access where the tipping-off rule applies, so onboarding records are held with that carve-out in mind.
Malta Digital Innovation Authority (MDIA)
Malta's digital innovation regulator and the body procuring its EU Digital Identity Wallet. Shufti supports reviewable identity workflows for the firms it supervises.
Malta Business Registry (MBR)
Registers Maltese companies under the Companies Act and maintains the register of beneficial owners. KYB workflows verify status, officers and filings, and flag discrepancies.
Malta Tax and Customs Administration (MTCA)
Malta's tax and customs authority, formerly the Office of the Commissioner for Revenue, issuing VAT and PE numbers under the Commissioner for Tax and Customs. Shufti attaches VAT and employer registration evidence to company files and retains a decision history.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. It begins direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Option
Cloud in EU regions or on-premise hosts Maltese customer data in-region and supports GDPR accountability. No hyperscaler runs a Malta-specific region.
Regulatory Alignment
Aligned with PMLFTR due diligence, ownership and record-keeping duties and the binding FIAU Implementing Procedures, with GDPR, the Data Protection Act and AMLR from 10 July 2027.
Retention Controls
Regulation 13(2) of the PMLFTR sets a five-year retention period, running from the end of the business relationship or the occasional transaction. The FIAU, a supervisory authority or law enforcement may extend it, to a maximum of ten years.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logging, supports Article 32 GDPR obligations, under our ISO 27001 and SOC 2 Type II certifications.
Scope of Our Role
Shufti is a data processor supplying verification technology, not legal advice. Responsibility for customer due diligence and the method chosen stays with the obliged entity, documented in its risk assessment (FIAU Implementing Procedures Part I, Ch. 6).
Automated Decisions and Biometric Data
The controller sets the lawful basis. Biometric data used for unique identification engages Article 9 GDPR, and human review is available.
Data and Privacy Controls in Malta
Malta AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Malta and globally. A few of them are:
Financial Intelligence Analysis Unit (FIAU)
Malta Financial Services Authority (MFSA)
Sanctions Monitoring Board (SMB)
Asset Recovery Bureau (ARB)
Malta Business Registry (MBR)
Malta Gaming Authority (MGA)
Malta Tax and Customs Administration (MTCA)
Malta Police Force
Prevention of Money Laundering Act (Cap. 373) and the PMLFTR
FIAU Implementing Procedures
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
Financial Action Task Force (FATF)
MONEYVAL (Council of Europe)
EU Authority for Anti-Money Laundering (AMLA)
SEE SHUFTI IN YOUR MALTA WORKFLOW
Turn Malta Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Which identity documents can be used for KYC in Malta?
Customers can use the Maltese identity card, known as the Karta tal-Identità, along with the Maltese passport, the eResidence document and the Maltese driving licence. Every Maltese national holds an identity card from age 14. Shufti supports document, NFC and biometric verification in one workflow.
How does Shufti support MFSA-supervised businesses in Malta?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. The MFSA supervises Maltese financial services firms and runs AML examinations as an agent of the FIAU, so supervised firms get standardised records and clearer audit evidence.
What documents are required for KYB in Malta?
A Malta Business Registry certificate, the certificate of incorporation, the memoranda and articles of association, an MT-prefixed VAT number and the beneficial ownership extract. Shufti verifies these in real time and screens the UBOs behind them against sanctions and PEP lists.
How are Maltese diacritics and name variants handled in screening?
Maltese uses ċ, ġ, ħ and ż with the għ digraph, and ICAO Doc 9303 does not allow diacritics in the machine-readable zone. Diacritic-tolerant matching resolves ŻAMMIT and ZAMMIT as one person and keeps false positives down.
How long must AML records be retained in Malta?
Five years. Regulation 13 of the PMLFTR requires CDD, transaction and report records to be kept for five years from the end of the business relationship or the occasional transaction. The FIAU, a supervisory authority or law enforcement may extend that, to a maximum of ten years. From 10 July 2027 AMLR Article 77 sets the same five-year baseline.
Is EU-region data hosting available for Maltese customer data?
Yes. Shufti offers EU-based cloud regions, so Maltese customer data is hosted in-region in line with GDPR and the Data Protection Act. On-premise deployment is available where residency rules are stricter.
What changes for Malta under AMLR from July 2027?
AMLR applies directly, so no Maltese transposition law is needed. Article 22(6) points to eIDAS electronic identification means and qualified trust services, document plus biometric checks stay a lawful route, and the beneficial ownership test moves to 25% or more under Article 52(1). AMLR also brings an EU-wide cash limit of 10,000 euro.
Does Malta have an eIDAS-notified eID scheme?
Yes. Malta notified its eID scheme on 10 December 2021 at assurance level high, covering the identity card and the residence document. The everyday route is the eID account at eid.gov.mt, used with the card and a reader.
Is remote video identification allowed in Malta?
Yes. Section 4.3.1.2 of the FIAU Implementing Procedures Part I sets out the conditions for attended video identification, and Regulation 17 of the PMLFTR makes those procedures binding on subject persons. The call must give simultaneous visual and verbal contact, the customer is asked to tilt the document so security features are visible, and the session is retained with timestamped screenshots. AMLR does not remove this route.
When will the EU Digital Identity Wallet be usable for onboarding in Malta?
Under eIDAS 2.0, Member States target wallet issuance from the end of 2026. From December 2027, private relying parties that use strong user authentication, micro and small firms excluded, must accept wallets on a user's request under Article 5f(2). Malta is procuring its wallet through the MDIA, and Shufti accepts wallet verification as it goes live.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





