MFSA's New ICT Rules Could Slow Your Authorisation Applications

·
Listen to this article~3 min
MFSA's New ICT Rules Could Slow Your Authorisation Applications

The MFSA's new ICT circulars tighten scrutiny on authorisation applications, TLPT provider standards, and cyber threat awareness. Firms must strengthen DORA compliance documentation or risk delays.

The Malta Financial Services Authority (MFSA) just dropped new ICT risk and cybersecurity circulars, and the message is clear: regulators are tightening the screws on digital operational resilience. If you're submitting an authorisation application or relying on third-party ICT providers, you'll want to pay close attention. The MFSA is no longer accepting vague documentation or cookie-cutter compliance statements. ### What the MFSA Is Really Looking At The circulars zero in on three main areas: authorisation applications, threat-led penetration testing (TLPT) provider standards, and emerging cyber threat awareness. The authority wants firms to show they actually understand DORA requirements, not just check boxes. That means your ICT risk management framework and third-party oversight need to be tailored to your specific operations, not copied from a template. ### The Weak Spots Regulators Are Flagging According to the MFSA, many firms are falling short in several critical areas: - Business continuity planning that doesn't hold up under real stress scenarios - Incident handling procedures that are too slow or poorly documented - Patch and vulnerability management that lacks urgency or prioritization - Contractual controls for ICT outsourcing that leave gaps in accountability These aren't minor oversights. They're the kind of weaknesses that can derail an authorisation application or trigger supervisory action. The MFSA is signaling that it expects firms to have robust, tested processes, not just policies gathering dust on a shelf. ### The Generative AI Trap One interesting note from the circulars: the MFSA called out overreliance on unverified generative AI in submissions. It turns out that using AI to draft compliance documents can produce generic or inaccurate materials that actually slow down the authorisation process. The authority wants human oversight and genuine understanding behind every submission. > "Firms need stronger, more tailored documentation and a better practical grasp of DORA requirements, especially around ICT risk management and third-party oversight." - MFSA Circular Summary ### What This Means for Your Firm If you're in the middle of an authorisation application or planning to update your ICT risk framework, here's what to do: - Review your business continuity plans against real-world disruption scenarios - Test your incident response procedures with tabletop exercises - Audit your patch management cycle to ensure critical vulnerabilities are patched within 48 hours - Renegotiate ICT outsourcing contracts to include clear SLAs and audit rights - Avoid using generative AI for compliance documentation without thorough human review The MFSA is raising the bar, and firms that treat these circulars as a gentle reminder rather than a call to action may find themselves facing delays or additional scrutiny. The cost of compliance is rising, but the cost of non-compliance is much higher. ### The Bottom Line Digital operational resilience isn't a buzzword anymore. It's a regulatory requirement with teeth. The MFSA's latest circulars make it clear that firms need to invest in practical, tested ICT risk management frameworks. Whether you're a fintech startup or an established payment institution, the message is the same: get your documentation right, understand your vulnerabilities, and don't rely on shortcuts. The regulators are watching, and they're not impressed with generic submissions.