Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
MGA · Licensing 18 min read Jul 20, 2026

MGA B2C Licence Application: The 22 Documents Examiners Scrutinise Most

MGA examiners reject or delay most first-time B2C applications over the same recurring gaps. This guide maps every document category they scrutinise — and why each one stalls approvals.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Jul 20, 2026 18 min read Filed Licensing Requirements

Most MGA B2C Gaming Service Licence applications that stall or fail do so because of the same recurring document deficiencies, not because the underlying business is unviable. The MGA’s Licensee Relationship Management System (LRMS) accepts submissions online, but the assessment process that follows is substantive: the MGA’s Fit and Proper Committee, established at Board level, decides which entities and individuals are screened, determines when enhanced due diligence is required, and can impose licence conditions or reject applications at its own discretion. Understanding what that committee is looking for across each document category is the most direct route to a first-pass approval.

The following document categories are drawn from the MGA’s primary regulatory instruments: the Gaming Act 2018 (Cap. 583 of the Laws of Malta), the Gaming Authorisations and Compliance Directive (Directive 3 of 2018), the Player Protection Directive (Directive 2 of 2018), the MGA Compliance Audit Manual (MGA/G/001), and the MGA’s Technical Infrastructure guidelines for Remote Gaming. Compliance teams should read these instruments in parallel, not in sequence, because examiners treat them as an integrated framework, not as separate checklists. Operators should consult qualified Maltese legal counsel for jurisdiction-specific application of any requirement.

What Licence Type Are You Actually Applying For?

The Gaming Act 2018 structures B2C authorisations around four gaming service types. Type 1 covers casino-style games of chance played against the house. Type 2 covers fixed-odds betting. Type 3 covers peer-to-peer games including poker and exchange betting. Type 4 covers controlled skill games. Minimum issued and paid-up share capital requirements differ by type: €100,000 for Type 1 and Type 2, and €40,000 for Type 3 and Type 4. Applicants seeking multiple type approvals must meet these requirements cumulatively, up to a maximum cap of €240,000.

Applications that list gaming verticals inconsistent with the requested licence type are rejected at intake. An applicant seeking to offer poker under a Type 1 approval, or slots under a Type 3 approval, will not proceed past the initial review. Examiners also check whether the business plan and financial projections match the requested type, a projection model built for a high-volume casino product submitted alongside a Type 3 peer-to-peer application signals that the applicant has not properly understood what they are applying for.

Key Requirement: Any major change to the application after submission, including changes affecting more than 75% of equity ownership, control, or funding, or changes requiring a new business plan, requires a completely new licence application. Applicants must lock down their corporate structure before submitting.

Category 1: Corporate Structure and Ownership Documentation

The MGA’s Compliance Audit Manual (MGA/G/001) identifies corporate group chart accuracy as a standing verification item in every compliance engagement. At application stage, examiners require a complete and current corporate group chart identifying every entity in the ownership chain, every qualifying ultimate beneficial owner (UBO), and the nature and percentage of control at each level. The MGA requires transparency of ownership structure from the UBO level down to the applying entity without interruption.

Documents that routinely create delay in this category include the Certificate of Incorporation, the Memorandum and Articles of Association (M&A), and proof of company objectives. The M&A must include gaming as an explicit main objective. Examiners cross-reference the M&A against the Malta Financial Services Authority (MFSA) register and flag any discrepancies, applicants whose company objectives have been amended but whose M&A on file predates that amendment will be asked to explain and remediate before the review continues.

Category 2: The Fit and Proper Pack for UBOs and Directors

Every qualifying UBO, director, and individual in a position of control must pass the MGA’s fit and proper assessment before the licence can be issued. The Fit and Proper Committee, established by the MGA’s Board, decides which individuals are subject to enhanced due diligence and retains discretion to recommend enforcement actions where it deems necessary. It can also impose licence conditions unilaterally.

The fit and proper documentation pack for each qualifying individual typically includes a certified copy of a valid government-issued photo ID, a sworn declaration of no criminal convictions for offences involving dishonesty or financial crime, a Curriculum Vitae with at least ten years of verifiable professional history, and a personal declaration of financial standing. Examiners verify declared professional histories independently. Gaps in employment history that are left unexplained, or CVs that list senior gaming industry roles without supporting references, generate formal information requests that pause the timeline.

The MGA’s Guidance Note on Individual Applications, listed on the Authority’s Guidance Notes page, supplements the Directive 3 of 2018 requirements and should be read before preparing these packs. Applicants should note that fit and proper status is assessed on an ongoing basis, not only at the time of application, this means individuals who subsequently acquire criminal records or adverse regulatory findings can trigger a review of an existing licence.

Category 3: Key Function Certificates

Directive 3 of 2018, at Article 5 and Article 6, defines key functions as important roles carried out in connection with a gaming service as prescribed by the Directive. For B2C licensees, the mandatory key functions include: the chief executive role or equivalent, management of day-to-day gaming operations (covering financial obligations, player payments, risk strategy, and fraud prevention); compliance (responsible gaming, player support, marketing rules, and sports integrity where applicable); legal affairs, data protection, prevention of money laundering and financing of terrorism, technological affairs (back-end system management and information security); and internal audit.

At application stage, the CEO-equivalent and day-to-day gaming operations key functions must be identified and their certificates applied for. The remainder can be notified within six months of licence issuance. This sequencing is mandatory under Directive 3 of 2018, Article 5(a) and 5(b), and is one of the most frequently misunderstood obligations. Applicants who submit an otherwise complete application without the at-application-stage key function nominations will receive a deficiency notice. Where a key function holder resigns post-issuance, the MGA must be notified within three working days of the resignation and within fifteen working days of the replacement appointment.

“Key Persons are required to have full knowledge, understanding and access to the applicant’s or licensee’s operations, as may be necessary for them to carry out their respective Key Function/s.”

Source: Malta Gaming Authority, FAQs, Key Functions section, referencing the Gaming Authorisations and Compliance Directive (Directive 3 of 2018).

Category 4: Business Plan and Financial Projections

The MGA requires a detailed business plan that covers the markets the applicant intends to target, the products it will offer, its player acquisition strategy, its commercial model, and its projected operational timeline. Financial projections must accompany the business plan and must be internally consistent with it. An examiner who finds that the business plan projects primary revenue from a market where the applicant has no marketing infrastructure described in the plan, or financial projections built on player acquisition cost assumptions unconnected to any described strategy, will raise a formal query.

The MGA’s FAQs confirm that a major change in the business plan, such as material changes to products or target markets, constitutes a major change requiring a new application. Applicants should treat the business plan as a binding document rather than a high-level summary: examiners use it as the reference point against which the rest of the application is assessed for coherence.

Financial projections must demonstrate the applicant’s ability to meet share capital requirements and ongoing financial obligations. The MGA’s 2025 Annual Report noted the introduction of a Capital Requirements Policy requiring operators to maintain positive equity positions, reflecting a broader regulatory focus on financial resilience. Projections that show rapid equity depletion in the early operational period, without a credible plan for recapitalisation, are a common source of examiner concerns.

Category 5: AML and KYC Procedures

The MGA’s Compliance Audit Manual is explicit about what AML documentation must contain. Examiners require a written AML Policy and Procedures document, a KYC Procedures document, and a Funds Management Procedure. All three must be current versions, examiners cross-check whether the MGA holds the same version as the applicant. Generic AML frameworks not tailored to the Maltese regulatory context, and specifically not referencing the Financial Intelligence Analysis Unit (FIAU) as the reporting authority, are rejected.

The MLRO (Money Laundering Reporting Officer) must be named in the application, must be registered with the FIAU, and must be demonstrably knowledgeable of the licensee’s specific AML, KYC, and funds management procedures. The MGA’s audit methodology tests this individually, an MLRO who cannot speak to the specifics of the company’s procedures is treated as a compliance failure, not a procedural gap.

The €2,000 deposit monitoring threshold is a specific technical requirement under the MGA’s AML framework: the system must be capable of flagging deposits where the total accumulation equals or exceeds €2,000, calculated either on a daily basis or on a rolling 180-day period. AML procedures that do not address this threshold will be queried. Procedures must also specify controls for politically exposed persons (PEPs), source of wealth and source of funds requests for high-risk profiles, and player collusion monitoring where peer-to-peer activity is possible.

Category 6: Player Protection and Responsible Gaming Policy

Directive 2 of 2018, the Player Protection Directive (currently at Version 3, January 2023), governs the player-facing obligations that the MGA’s examiners will verify are built into the applicant’s operational design. The application must include a responsible gaming policy that addresses deposit limits, self-exclusion mechanisms, player-set wagering limits, reality checks, and access to problem gambling support organisations.

The Directive requires that following player registration and in any case before a player’s first deposit, the licensee provides information about available responsible gaming tools and clearly indicates where those tools are accessible. This must be designed into the platform before go-live approval is sought. Applications that describe responsible gaming measures as post-launch implementation items are treated as incomplete.

The MGA requires an approved Alternative Dispute Resolution (ADR) entity to be engaged before operations go live. Failure to engage and maintain an ADR entity during operations is an enforcement trigger. The ADR arrangement must be included in the terms and conditions as submitted, which itself must be no more than one click away from the homepage under the Directive’s accessibility requirements.

Category 7: Terms and Conditions

Examiners read the terms and conditions as a regulatory compliance document, not as a commercial agreement. The Player Protection Directive requires that terms are written in plain and intelligible language, are available before registration, are no more than one click from the homepage or the relevant game, and are not unfair in terms of the Consumer Affairs Act. Terms that contain confiscation or penalty provisions not authorised by the Directive are flagged as non-compliant and must be removed before the licence is issued.

Where the applicant intends to offer the gaming service in languages other than English or Maltese, Directive 2 of 2018 requires that all required information be available in those languages as well. Terms and conditions that are provided in English only, for an operator targeting, for example, German or Scandinavian markets, will require remediation before the application progresses.

Category 8: Technical Infrastructure Documentation

The MGA’s Technical Infrastructure guidelines for Remote Gaming (December 2015, v1) remain live and applicable. Applicants must provide a network schematic showing every piece of hardware and every virtual machine, with internal IP addresses and geographic location of hosting. The MGA’s four regulatory principles for technical infrastructure are integrity and security, availability and traceability, privacy and confidentiality, and accountability. The last principle is operationally significant: the MGA places regulatory responsibility for the technical infrastructure on the licensee, regardless of outsourcing arrangements.

Where the applicant is using cloud hosting or a co-location provider, the relationship and the controls over regulatory data must still be described in terms of what the licensee itself controls and can demonstrate to the MGA. Applications that present a supplier’s hosting brochure or SLA as the technical documentation are deficient. For a broader analysis of what the MGA’s system audit framework requires from the technology stack, see our article on MGA system audit requirements.

Category 9: Gaming System Documentation and Game Certification

The Specification of the Gaming System document must be submitted and must reflect the actual system the applicant intends to operate. Examiners test adherence to this document as part of the compliance audit cycle: the MGA/G/001 manual specifically requires auditors to verify that the specification has been implemented in practice. Submitting a specification that describes a more robust system than the one actually deployed is a compliance risk that will surface at the first audit.

Under Directive 3 of 2018, Article 19, any game that uses a random number generator and is based on a game engine not already approved by the Authority requires prior written MGA approval before it can be offered. Game certification from an accredited testing laboratory (accredited within an EU or EEA Member State, or from another jurisdiction approved by the MGA) is a prerequisite for that approval. The application must identify the testing laboratory used and provide the relevant certification. Applicants should note that adding a new gaming vertical after licence issuance also requires prior written approval from the MGA, together with the relevant administrative fee paid in advance.

Category 10: Player Funds Segregation and Financial Institution Details

Player Protection Directive Article 31 requires that player funds be held in a licensed credit, financial, or payment institution. The setup of any such institution must be presented to the MGA and is subject to the MGA’s approval before operations begin. The player funds account must be separate and separately identifiable at all times, and the MGA retains viewing rights over the common account of player funds. Applicants must provide evidence that the chosen institution has been authorised to release information to the MGA upon request.

The compliance audit methodology under MGA/G/001 tests player funds coverage against player liabilities using monthly player funds reports, applicants should therefore design their funds management procedure with this ongoing reporting requirement in mind from day one. Financial safeguards beyond standard segregation, including trusts, bank guarantees, or reserve accounts, may be imposed by the MGA on a risk-based basis. Applications from applicants with limited operating history or thin capitalisation should anticipate this possibility and address it proactively in the application.

Category 11: Website and Marketing Compliance Documentation

Before a website can go live under an MGA licence, it must meet the Directive 2 of 2018 display requirements. The application must describe how the MGA’s dynamic seal will be incorporated on the homepage, how the responsible gaming page will be accessible within one click of any page on the site, and how the company’s name, registered address, contact number, underage gaming prohibition, and responsible gaming message will appear on all pages. Applications that propose to implement these elements post-licence rather than pre-launch create a structural compliance gap.

Where the applicant intends to offer games regulated by the MGA alongside games not so regulated, Directive 2 of 2018 requires a clearly visible notice on the homepage distinguishing the two. This is relevant for white-label operations and for applicants combining an MGA-licensed product with offerings from other jurisdictions. The MGA retains the right to prohibit a B2C licensee from offering gaming activity not licensed by the MGA if that activity is not covered by any recognised licence.

The 22 Documents: A Reference Table

Document Category Specific Item Governing Instrument Common Failure Mode
Corporate Structure Corporate group chart (full ownership chain to UBO) Directive 3 of 2018, MGA/G/001 Incomplete UBO chain, post-submission equity change
Corporate Structure Certificate of Incorporation MGA/G/001 Outdated version, mismatch with MFSA register
Corporate Structure Memorandum and Articles of Association MGA/G/001 Gaming not listed as main objective
Fit and Proper Photo ID and sworn criminal declaration (each UBO/director) Directive 3 of 2018, Fit and Proper Committee Undeclared prior adverse regulatory findings
Fit and Proper Curriculum Vitae with full professional history Directive 3 of 2018, MGA Guidance Note on Individual Applications Unexplained employment gaps, unverifiable senior roles
Fit and Proper Personal declaration of financial standing Directive 3 of 2018 Inconsistency with projected capitalisation
Key Functions CEO-equivalent Key Function Certificate application Directive 3 of 2018, Art. 5(a), 6(1)(a) Not submitted at application stage
Key Functions Day-to-day gaming operations Key Function Certificate application Directive 3 of 2018, Art. 5(a), 6(1)(b) Not submitted at application stage
Business Plan Detailed business plan with target markets and acquisition strategy MGA FAQs, Licence Applications, Directive 3 of 2018 Inconsistency with financial projections or licence type
Business Plan Financial projections (multi-year) demonstrating positive equity MGA Capital Requirements Policy, MGA FAQs Rapid equity depletion without recapitalisation plan
AML/KYC AML Policy and Procedures (current version, FIAU-referenced) MGA/G/001, Prevention of Money Laundering Act (Cap. 273) Generic framework not tailored to Maltese requirements
AML/KYC KYC Procedures (with €2,000 deposit threshold and PEP controls) MGA/G/001 Missing deposit monitoring threshold, no PEP escalation
AML/KYC Funds Management Procedure (current version) MGA/G/001 Version mismatch with MGA records
AML/KYC MLRO nomination and FIAU registration evidence MGA/G/001, FIAU Implementing Procedures MLRO not registered with FIAU at application stage
Player Protection Responsible Gaming Policy (RG tools, limits, self-exclusion) Directive 2 of 2018, Art. 9, Player Protection Directive v3 Jan 2023 Described as post-launch implementation
Player Protection ADR entity engagement confirmation Directive 2 of 2018, MGA FAQs Not in place prior to go-live approval request
Player Protection Terms and Conditions (plain language, no prohibited penalty clauses) Directive 2 of 2018, Art. 6, Consumer Affairs Act Prohibited confiscation clauses, not accessible pre-registration
Technical Network schematic with hardware, VMs, IPs, and hosting geography MGA Technical Infrastructure guidelines (Dec 2015 v1) Supplier SLA submitted instead of licensee-controlled schematic
Technical Specification of the Gaming System document MGA/G/001, s.5.3 Describes aspirational system, not live configuration
Technical Game certification from accredited testing laboratory (RNG approval) Directive 3 of 2018, Art. 19 and 23 Certification not from MGA-recognised laboratory
Player Funds Player funds institution details and MGA viewing-rights authorisation Directive 2 of 2018, Art. 31, 33 Institution not pre-approved, no viewing-rights authorisation
Website/Marketing Website compliance plan (dynamic seal, RG page, display requirements) Directive 2 of 2018, Art. 5 and Part IV Compliance elements listed as post-launch deliverables

How the Examiner Reviews These Documents in Practice

The MGA does not assess documents in isolation. The Compliance Audit Manual structures the review so that corporate structure, key persons, AML procedures, player funds, and technical systems are all cross-referenced against each other. An examiner reviewing the AML procedures will check whether the named MLRO corresponds to a Key Person on the key functions list and whether their role description in the procedures document matches their Key Function Certificate application. An examiner reviewing the business plan will verify that the gaming verticals described match the licence type applied for and that the financial model is consistent with the share capital held.

The MGA’s 2025 Annual Report confirmed that the Authority’s approach has shifted further toward evidence-led regulatory oversight, including enhanced due diligence, strengthened AML and counter-terrorist financing supervision, and improved risk assessments. Applications that provide only the minimum required documentation without substantive supporting evidence are increasingly likely to face formal information requests that extend the timeline significantly.

“The MGA’s Fit and Proper Committee also evaluates and determines any changes in the risk assessment of licensed operators and may impose licence conditions at its own discretion.”

One pattern that consistently extends application timelines is the submission of documents prepared for a different jurisdiction and then lightly adapted for Malta. AML procedures built for a UK or Isle of Man framework will reference the wrong reporting authority, apply the wrong monitoring thresholds, and use terminology not aligned with the Prevention of Money Laundering Act (Cap. 273 of the Laws of Malta). Examiners identify this immediately. The cost of preparing Malta-specific documentation from the outset is substantially lower than the cost of two or three rounds of formal information requests and remediation.

Start-Up Applicants: What the MGA’s Start-Up Directive Changes

The MGA operates a dedicated framework for start-up undertakings. Start-ups that qualify under the relevant Directive benefit from a twelve-month moratorium period during which they are exempt from paying compliance contributions. The minimum compliance contribution does not become due until a full licence period has elapsed. This changes the cash-flow model in the early stages but does not alter any of the document requirements above. All twenty-two document categories apply to start-up applicants in the same way they apply to established operators.

Start-up applicants tend to struggle most with the business plan coherence requirement and with the technical documentation. A start-up that has not yet selected its gaming platform provider cannot submit a credible Specification of the Gaming System document. The practical answer is to finalise the platform partnership before submitting the application, even if that means delaying the submission date. An incomplete technical specification at application stage is more costly to fix than the delay caused by waiting for the platform agreement to be executed.

What the Enforcement Register Tells Applicants About Examiner Priorities

The MGA’s Enforcement Register provides a direct signal about which obligations examiners treat as non-negotiable. Knockout Gaming Limited had its licence (MGA/B2C/412/2017) cancelled in September 2020 in part for failing to submit Key Function applications by the stipulated deadline, one of the most operationally straightforward obligations in the framework. This record confirms that the key function timing requirement in Directive 3 of 2018 is enforced, not merely monitored. Multiple other enforcement actions in the register cite failure to remit compliance contributions on time, failure to maintain adequate player funds, and failure to notify the MGA of changes to corporate structure or key persons.

For applicants preparing their submissions, the enforcement register is a diagnostic tool. Every enforcement action represents a category of document or control that the MGA has demonstrated it will act on. The categories that appear most frequently across the register, key function compliance, player funds adequacy, AML reporting, and timely notification of changes, should be treated as the highest-priority items in the application preparation process.

For a broader comparison of the MGA licensing framework against the UK Gambling Commission’s requirements and cost structure, see our analysis of UKGC vs MGA licence costs in 2026. For the full technical stack documentation requirements under the MGA’s audit framework post-issuance, see our guide to MGA system audit requirements.

Key Resources

Malta Gaming Authority, Gaming Act 2018 (Cap. 583 of the Laws of Malta), governing statute for all MGA authorisations, available at mga.org.mt.

Malta Gaming Authority, Gaming Authorisations and Compliance Directive (Directive 3 of 2018), Version 2, October 2021, primary instrument governing key functions, gaming verticals, and application requirements.

Malta Gaming Authority, Player Protection Directive (Directive 2 of 2018), Version 3, January 2023, governing player funds, responsible gaming, terms and conditions, and website display requirements.

Malta Gaming Authority, Compliance Audit Manual (MGA/G/001), August 2018 v1, defines the audit procedures applicable to all B2C licensees across corporate structure, AML, player funds, and technical systems.

Malta Gaming Authority, Technical Infrastructure guidelines for Remote Gaming, December 2015 v1, applicable technical hosting and systems standards for remote gaming applications and licensees.

Malta Gaming Authority, Guidance Note | Application Process, supplementary guidance on the LRMS application workflow, available via mga.org.mt/regulatory-framework/guidance-notes/.

Sources: Malta Gaming Authority, Gaming Authorisations and Compliance Directive (Directive 3 of 2018), V2 October 2021, Player Protection Directive (Directive 2 of 2018), V3 January 2023, Compliance Audit Manual MGA/G/001 August 2018 v1, Gaming Act (Cap. 583); MGA FAQs, Licence Applications, Key Functions, Licence Fees sections, MGA Enforcement Register, MGA 2025 Annual Report, MGA Technical Infrastructure Guidelines for Remote Gaming December 2015 v1.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged Licensing Requirements

Browse all →

Licensing Requirements

OECD Pillar Two and iGaming: How the 15% GloBE Floor Hits MNE Operators in Malta, Curaçao, and Gibraltar

Jul 20 · 16 min read

Licensing Requirements

AGLC B2B Supplier Registration for Alberta iGaming: What Game Studios, Platform Providers, and Service Vendors Must Do

Jul 14 · 16 min read

Licensing Requirements

Fit-and-Proper Assessment for Alberta iGaming: What AGLC Checks on Directors, Officers, and Key Persons

Jul 7 · 16 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.