Financial crime compliance – Q3 bulletin

An insight into the key Q3 developments in Financial Crime Compliance

AML image
  • 5 minute read
  • August 24, 2026

Confronting change – developments reshaping AML/CFT compliance (AML package and EuReCA) 

A key development is the introduction of the EU AML Package, which aims to create a more harmonised AML/CFT framework across Member States through a single rulebook. Key changes include enhanced customer due diligence requirements, a stronger focus on ongoing monitoring throughout the customer lifecycle, more prescriptive beneficial ownership requirements, and greater emphasis on enterprise-wide risk assessments, governance, and internal controls. Together, these reforms aim to improve consistency, strengthen AML/CFT frameworks, and reduce regulatory fragmentation across the EU. 

Recent findings from the European Reporting System for Material CFT/AML Weaknesses (EuReCA) reinforce why these areas remain a supervisory priority. Recurring weaknesses reported across the EU include shortcomings in customer due diligence and ongoing monitoring, challenges in identifying and verifying beneficial ownership, ineffective screening controls, weaknesses in transaction monitoring frameworks, and inadequate mitigation of risks associated with high-risk products, services and jurisdictions. 


Supervisors are seeing more activity, more risk, and more reporting (annual report) 

The FIAU's 2025 Annual Report highlights an increasingly active AML/CFT environment. Suspicious Transaction Reports (STRs) reached a record high of 10,712 submissions, while supervisory interventions, enforcement measures, warning letters, and international intelligence sharing remained significant. 

Beyond the statistics themselves, the report highlights key trends in both reporting and supervision. CASPs became the largest reporting sector for the first time, overtaking remote gaming, while fraud remained the most commonly identified predicate offence. The main drivers for STR submissions were concerns relating to source of wealth and source of funds, uncooperative customers, and adverse media findings. The report also reflects continued supervisory focus on core AML/CFT controls, with the FIAU carrying out 150 supervisory interventions and identifying recurring deficiencies in customer due diligence, enhanced due diligence, transaction monitoring, and customer understanding. 

The report also highlights the increasingly international nature of financial crime. Growing levels of cross-border intelligence sharing demonstrate the importance of maintaining effective controls capable of identifying and escalating suspicious activity across multiple jurisdictions. 

employers meeting

Virtual assets are becoming a central AML/CFT priority (CASPs) 

One of the most notable trends from the FIAU Annual Report is the emergence of Crypto-Asset Service Providers as the largest contributors to Suspicious Transaction Reports. 

As virtual assets become more widely adopted, firms are increasingly exposed to fast-moving, cross-border, and often pseudonymous transactions. At the same time, both the FIAU Annual Report and Europol's threat assessment highlight growing risks associated with the dark web, decentralised finance (DeFi), privacy-enhancing technologies, mixers, tumblers, and cross-chain services. These technologies can reduce transparency and make it more difficult to trace transactions, identify beneficial ownership, and detect illicit financial flows, increasing both money laundering and terrorist financing risks. 

Information request

Enforcement is moving beyond penalties, towards remediation (AMLD6 Enforcement) 

Alongside changing risk landscapes, the EU AML package is introducing a more harmonised and enforcement-focused supervisory framework. 

AMLD6 places greater emphasis on accountability and demonstrable remediation. This is reflected in the enhanced supervisory tools available to regulators. Administrative measures remain central to the supervisory toolkit, while new periodic penalty payment mechanisms are intended to encourage firms to address weaknesses within prescribed deadlines. Unlike one-off sanctions, these payments can be imposed on an ongoing basis until compliance is achieved and may reach up to 3% of average daily turnover for legal persons. The mechanism was introduced to ensure enforcement measures are effective, proportionate and dissuasive, while promoting greater consistency across Member States. 

The practical implication for firms is clear: regulators are increasingly focused on how quickly deficiencies are escalated, remediated, documented, and closed. Governance structures, management oversight, remediation tracking processes, and accountability frameworks are therefore becoming increasingly important components of effective AML/CFT compliance. 

virtual meeting

Data quality and regulatory reporting are becoming strategic priorities

Another significant local development is the introduction of the Harmonised Regulatory Reporting Framework (HRRF) by the MFSA and FIAU. 

The HRRF aims to modernise domestic regulatory reporting through a standardised framework that reduces duplication, improves consistency, and enhances data quality. By introducing common reporting definitions, formats, and data standards across regulators, the framework seeks to reduce multiple reporting requests for the same information while improving the accuracy, comparability, and usability of regulatory data. The framework will also incorporate updated AML/CFT reporting requirements aligned with forthcoming AMLD6 standards.

For many firms, the impact extends beyond a simple reporting exercise. Effective regulatory reporting increasingly depends on strong data governance, reliable information management processes, and the ability to produce accurate information consistently and efficiently. While the phased implementation approach provides firms with time to prepare, organisations should already be assessing whether existing reporting processes and technical capabilities are sufficient for the new requirements. 


What this means for firms 

Viewed together, these developments reveal a common theme: regulators are placing greater emphasis on risk identification, reporting quality and remediation effectiveness. 

Whether through increased focus on crypto-related risks, record reporting volumes, enhanced enforcement powers, or harmonised reporting standards, the message remains clear: AML/CFT compliance is becoming more data-driven, accountable, and closely scrutinised. 

Organisations that proactively strengthen governance, enhance customer due diligence and monitoring, improve remediation processes, and prepare for upcoming reporting changes will be better positioned to meet regulatory expectations and navigate an increasingly complex financial crime landscape. 


How can we help?

We support organisations in assessing the impact of evolving AML/CFT requirements on their governance, compliance, and control frameworks. This includes AMLA and AMLD6 readiness, remediation governance, crypto and virtual asset risk management, STR quality reviews, transaction monitoring enhancements, and regulatory reporting preparedness. 

We also help organisations prepare for the HRRF, review AML/CFT reporting and data governance frameworks, and assess whether existing controls remain effective considering emerging risks, increasing supervisory expectations, and ongoing regulatory change.

This article was drafted with the support of Zoe Mallia, an intern within the Financial Crime Compliance team.

Stay up to date with our latest

thought leadership

Contact us

Chris Mifsud Bonnici

Chris Mifsud Bonnici

Partner, PwC Malta

Tel: +356 79757005

Kurt Pace

Kurt Pace

Manager, Tax, PwC Malta

Follow us