Internal Audit Function

An independent, outsourced Internal Audit Function for licensed entities in Malta — giving the Board objective assurance over internal controls, risk management, and governance.

  • MFSA & MGA frameworks
  • Risk-based methodology
  • Reports to the Board
  • Fully outsourced or co-sourced

The Internal Audit Function provides independent and objective assurance on the effectiveness of an organisation’s internal controls, risk management framework, and governance processes. It plays a critical role in safeguarding the organisation against financial, regulatory, operational, strategic, cyber, IT, fraud, and anti-money-laundering (AML) risks.

MFSA · MGA
Frameworks under which certain licensed entities must maintain an independent Internal Audit Function
Board
The function reports directly to the Board of Directors, independent of executive management
7
Typical review areas — from governance and AML/CFT to IT, outsourcing, and fraud risk
2
Engagement models — fully outsourced, or co-sourced alongside an in-house team
Assurance

Why the Internal Audit Function Matters

An effective Internal Audit Function is essential to maintaining organisational resilience and regulatory compliance.

Request a Consultation

Regulatory expectations have tightened, more of the business runs on technology, and supervisors ask harder questions about data protection and financial crime than they did five years ago. Against that background, internal audit has moved from good practice to necessity.

Under applicable regulatory frameworks, including those issued by the Malta Financial Services Authority (MFSA) and the Malta Gaming Authority (MGA), certain licensed entities are required to establish an independent Internal Audit Function. This function must operate with sufficient autonomy and report directly to the Board of Directors, while maintaining appropriate engagement with the relevant supervisory authority.

Note

Internal audit is distinct from the statutory (external) audit. The external auditor forms an opinion on the annual financial statements; internal audit looks across the whole control environment — including areas a financial-statement audit never reaches, such as AML/CFT procedures, IT and cyber controls, outsourcing arrangements, and regulatory reporting.

Objectives of the Function

Risk Management

Assess the adequacy and effectiveness of internal control systems and risk management frameworks across the organisation.

Governance & Accountability

Evaluate adherence to internal policies, procedures, and applicable legal and regulatory requirements.

Independent Assurance

Provide objective assurance and advisory services to the Board of Directors, maintaining independence from executive management.

Risk Identification

Identify emerging risks and control gaps proactively, enabling timely mitigation before material issues arise.

Scope

What an Internal Audit Covers

The scope of each engagement is set by a risk assessment rather than a fixed checklist, so that audit effort is directed at the areas where the organisation is most exposed.

Typical review areas include:

  • Governance and organisational structure — Board composition, delegation of authority, committee effectiveness, and management reporting lines
  • Regulatory compliance — adherence to licence conditions, rulebooks, and supervisory expectations, including regulatory reporting accuracy and timeliness
  • AML/CFT controls — business risk assessment, customer due diligence, ongoing monitoring, screening, and suspicious transaction reporting procedures
  • Financial and operational controls — segregation of duties, reconciliations, payment authorisation, and client-asset safeguarding where applicable
  • IT and cyber risk — access management, change control, business continuity, disaster recovery, and data protection
  • Outsourcing and third parties — due diligence, contractual protections, and ongoing oversight of material service providers
  • Fraud risk — the design and operation of preventative and detective anti-fraud controls

Why Outsource the Internal Audit Function

Independence & Objectivity

External providers enhance independence by eliminating potential conflicts of interest inherent in internal reporting structures.

Specialised Experts

Access to experienced professionals with in-depth knowledge of Maltese and EU regulatory frameworks, including AML/CFT obligations and sector-specific requirements.

Cost Efficiency

Avoid the fixed costs and operational complexities associated with building and maintaining an in-house internal audit team.

Scalable Capacity

Scale the depth of review up or down as the business grows, enters new markets, or comes under closer supervisory attention — without permanent headcount.

Approach

How We Work

We can act as your fully outsourced Internal Audit Function, or work alongside an existing in-house team on a co-sourced basis where specialist coverage is needed for a particular area.

  1. Risk Assessment & Audit Planning

    We map the organisation’s risk profile and agree a risk-based annual audit plan with the Board or Audit Committee.

  2. Fieldwork & Testing

    Walkthroughs, control testing, and sample-based substantive procedures against the agreed scope.

  3. Reporting

    Findings are rated by severity and set out with practical, actionable recommendations and agreed management responses.

  4. Board Presentation

    Results are reported directly to the Board of Directors or Audit Committee, preserving independence from executive management.

  5. Follow-Up

    We track remediation of previously raised findings so that issues are closed rather than carried forward.

Clients

Who This Is For

Licensed and obliged entities that need independent assurance in Malta.

  • MFSA-licensed financial services firms, including investment services providers, EMIs, PSPs, and fund managers
  • MGA-licensed gaming operators and suppliers
  • Insurance and reinsurance undertakings, captives, and insurance managers
  • Corporate service providers, trustees, and other subject persons with AML/CFT obligations
  • International groups that need a Malta-based internal audit capability for a local licensed entity
Why zeta.

An Assurance Partner, Not Just an Auditor

Independence, quality, and recommendations you can actually act on.

  • Deep expertise in Malta’s regulatory environment, including the MFSA and MGA frameworks.
  • Tailored, risk-based audit methodologies aligned with regulatory expectations and industry best practices.
  • Commitment to independence, quality, and practical, actionable recommendations.
  • Connected to the wider zeta. platform — compliance, AML and MLRO support, and regulatory advisory sit under one roof, so findings can be remediated as well as identified.
See our compliance, AML & MLRO support

Discuss your internal audit needs with our team

Tell us about your licence category and current arrangements — we'll set out the right scope, cadence, and engagement model.

Frequently Asked Questions

It depends on the entity. Under applicable MFSA and MGA frameworks, certain categories of licence holder are required to establish an independent Internal Audit Function, while for others it is expected as a matter of good governance and proportionality. Whether the requirement applies to your entity depends on its licence category, size, and risk profile — zeta. can review your obligations and advise.
Yes. Outsourcing the Internal Audit Function to an external provider is well established and, in many cases, strengthens independence by removing the conflicts of interest that can arise when the function reports through executive management. The Board retains ultimate responsibility for the function, and the arrangement must meet applicable regulatory outsourcing requirements.
The statutory (external) audit is a legal requirement that results in an opinion on the annual financial statements. Internal audit is a governance function that provides the Board with ongoing assurance across the whole control environment — including regulatory compliance, AML/CFT, IT and cyber, outsourcing, and fraud risk. The two are complementary; one does not replace the other.
The function reports directly to the Board of Directors, or to an Audit Committee where one exists, rather than to executive management. This reporting line is what preserves its independence. Appropriate engagement with the relevant supervisory authority is also maintained where required.
Internal audit operates to a risk-based annual plan agreed with the Board. Higher-risk areas — typically AML/CFT, regulatory reporting, and client assets — are reviewed more frequently than lower-risk operational areas, with the full control environment covered across a defined cycle.
Remediation support is available through zeta.’s separate compliance and advisory teams. Where we act as your Internal Audit Function, we manage the engagement so that independence is preserved and the audit and remediation roles remain appropriately separated.

Related Insights

View all insights

Strengthen Your Assurance Framework

Speak to our team about establishing or outsourcing your Internal Audit Function — and we’ll advise on the right scope and cadence for your licence category and risk profile.