MFSA Calls on Insurers to Enhance Controls Over Regulatory Reporting

MFSA Office photo logo

Data Quality Remains a Supervisory Priority

The Malta Financial Services Authority (MFSA) has urged authorised (re)insurance undertakings to strengthen their controls around Regulatory Financial Returns, following the publication of its Quality of Data in Regulatory Financial Returns Dear CEO Letter on 3 September 2026.

Addressed to chief executive officers, chief financial officers and compliance officers, the letter highlights the Authority’s ongoing focus on data quality, a key supervisory priority during 2025. The MFSA emphasised that accurate, complete and timely regulatory reporting remains essential for effective supervision and is closely aligned with the expectations of the European Insurance and Occupational Pensions Authority (EIOPA).

Reporting Challenges and Control Weaknesses Identified

While the MFSA noted that firms generally submitted their quarterly returns within the required timeframe, several insurers indicated that the five-week submission deadline can be challenging, particularly where resources are limited.

The review also identified areas where controls could be strengthened. The Authority expects firms to improve consistency across regulatory submissions, reduce the number of non-blocking errors in Quantitative Reporting Templates (QRTs), and ensure reporting teams are adequately resourced.

Particular attention was given to the widespread use of spreadsheets in reporting processes. The MFSA warned that excessive reliance on spreadsheets can increase the risk of human error and create business continuity challenges. Where spreadsheets remain necessary, firms are expected to implement robust reconciliation procedures and appropriate safeguards.

In addition, the Authority observed that the four-eye principle was not always applied consistently. Insurers are expected to maintain a clear and documented preparer-reviewer process, providing evidence that regulatory submissions have been independently reviewed before submission.

Greater Focus on Governance and Internal Audit

The inspections were conducted in the context of Chapter 8 of the Insurance Rules on Financial Statements and Supervisory Reporting Requirements issued under the Insurance Business Act.

The MFSA also highlighted the importance of maintaining up-to-date, version-controlled finance procedure manuals and expects future internal audit reviews to cover the preparation, verification and approval of regulatory submissions.

What This Means for Insurers

The Dear CEO Letter provides a clear indication of the MFSA’s expectations regarding data governance and regulatory reporting. Beyond meeting reporting deadlines, insurers are expected to demonstrate strong oversight, effective controls and reliable reporting processes that support the accuracy and integrity of information submitted to the regulator.