The Central Bank of Malta has issued 11 supervisory expectations for payment service providers offering instant payments, following the entry into force of the European Union’s Instant Payments Regulation. Providers must strengthen the prevention, detection and management of payment fraud, particularly authorised push payment fraud, impersonation scams and emerging fraud typologies, with controls proportionate to the nature, scale and complexity of their activities. The expectations include continuous real-time pre- and post-transaction monitoring, 24/7 availability and resilience of Verification of Payee, risk-based management of spending-limit changes and new-device registrations, automated warnings and notifications, and controls addressing remote-access and screen-sharing tools. Providers may apply delays of up to six hours to remote spending-limit adjustments or payments following new-device registration, but these safeguards must be risk-based and must not operate as systematic or business-hours restrictions. The framework also covers customer awareness, staff training, fraud information sharing and governance. Effective application of these measures may be considered in liability assessments for customer-authorised fraud, while material control deficiencies may weigh against a provider. Providers must conduct a gap analysis and submit an implementation plan to the Bank within two months of the notice. They must then provide progress updates every two months until full alignment is achieved, no later than July 1, 2027.