The legal base
The framework is the Gaming Act (Cap. 583) and the Gaming Authorisations and Compliance Directive (Directive 3 of 2018). Three of its articles matter for security. Article 16: the licensee documents its key technical setup — hardware, virtual machines, connections, "specifications of firewalls and routers", applications — and "any changes to essential components shall require the prior written approval of the Authority" (urgent changes: notify within 72 hours); audit logs of changes are kept for at least two years. Article 17: hardware may only sit in premises with "a high level of information security" and a live mirror server for essential regulatory data is required. Article 18: a risk assessment on essential components, "continuously updated".
Article 37 adds the incident duty: "any breach of the licensee's information security that adversely affects the confidentiality of information relating to players" — and any breach that locks players out of their accounts for more than twelve hours — must be notified "forthwith, and in any case no later than three (3) working days" (incident reporting update).
Three audits, three moments
| Audit | When | What it checks |
|---|---|---|
| System Audit | Before the licence is issued: after the technical documentation review the applicant has 60 days to stage the system and "may trigger a request for an external System Audit". The policy also allows it "when deemed necessary by the Authority". | The staged environment "against the submitted policies and procedures" — architecture, network schematic and IPs must match what was filed; plus the security items below. |
| System Review | "Generally carried out one year after the licence issuance", or sooner if no System Audit was needed at onboarding. | That the live system still matches the documented setup. |
| Compliance Audit | "Throughout the licence period as required by the Authority" — no fixed cadence is published. | Policies against practice: access control, information security, incident response, change management, and the rest of the compliance manual. |
Sources: Application Process guidance note; System Audit checklist; Approved Audit Service Provider policy. A common misconception is that the System Audit is due "within 90 days of go-live": the System Audit precedes the licence; the 90-day figure that circulates appears to relate to Compliance Audit completion windows, reported by advisory firms rather than in an MGA page we could locate.
Who may audit
Only Approved Audit Service Providers, chosen by the licensee "on free commercial terms" and approved by the MGA for each engagement before it starts. Individual auditors need a warrant under the Accountancy Profession Act and/or an IT or IT-audit certification (the policy cites a BSc in IT, CISA, CISSP-Architecture, CRISC) plus at least three years of IT-audit experience in the last seven, or five in the last ten. Firms need at least two approved auditors and €1,000,000 of professional indemnity cover. Consultancy, application assistance, systems implementation, bookkeeping or internal audit for the licensee in the previous two years is a conflict of interest.
What the audits actually check on security
The System Audit checklist ("System Security" and "Player Account Security") is concrete and mostly about the player-facing platform: back-end auto log-off after at most one hour and player auto log-off after 30 minutes of inactivity; player passwords "stored in one-way cryptographic hash format"; card numbers "stored in encrypted format"; account lock after failed logons; "secure communication protocol" during registration, password change, logon, play, deposits and withdrawals; synchronized server clock; an audit trail for changes to regulatory data. There is no penetration-test or vulnerability-scan item in the checklist.
The Compliance Audit Manual (section 4, Information Technology) goes deeper on governance: a System Access Control Policy (rights per role, remote and third-party access, periodic reviews, audit trails); an Information Security Policy covering data, applications, equipment and networks, "threat of viruses and intrusion", media disposal, secure protocols and secure storage of passwords and payment data; an Incident Response Policy with reporting to the MGA within 72 hours (the Directive's "no later than three working days" is the binding wording); and Change Management (essential components changed without approval? key technical setup changes notified? logs kept two years?). One line is the closest Malta comes to a testing requirement — item 4.2.7: the auditor must "inquire whether the Licensee obtained an independent review of the Licensee's information security and its implementation. Identify the date of this review, the identity of the reviewer and critical findings."
ISO 27001 and PCI DSS
Neither is mandatory for licensees. The MGA's 2015 hosting guideline states that "the information security level the MGA seeks is that of ISO/IEC 27001:2013" for cloud and hosting providers, seeks PCI DSS Level 1 for card data, and wants cloud risk assessments framed by ISO 31000 (technical infrastructure guideline). "Seeks" is the operative word; no instrument requires certification.
What this means in practice
Malta's security requirements are about correspondence — the live system matching the filed documents, the practice matching the policy — and about a handful of concrete platform behaviors. What trips operators up is drift: a firewall specification that changed without a notification, a session timeout that a redeploy reset, a new IP that is not on the network schematic, an "independent review of information security" that nobody can date. Those are not exotic findings; they are the ordinary consequence of a platform that changes every week and an audit that looks once a year.
Frequently asked questions
Does the MGA require penetration testing?
No MGA instrument mandates penetration tests or vulnerability scans. The System Audit checklist has no such item; the Compliance Audit Manual asks whether the licensee obtained an independent review of its information security, with date, reviewer and findings.
Is the System Audit due within 90 days of go-live?
No. The System Audit is triggered before the licence is issued, during the 60-day staging window after the technical documentation review — or, in the words of the MGA policy, when deemed necessary by the Authority.
Do we need ISO 27001 to be licensed in Malta?
No. The MGA's hosting guideline says it 'seeks' the ISO/IEC 27001 level of security from hosting providers, but certification is not a licence requirement.
What is an information security incident we must report?
A breach that adversely affects the confidentiality of player information, or one that prevents players from accessing their accounts for more than twelve hours — to be notified forthwith and no later than three working days, through the Licensee Portal.