The Malta Financial Services Authority has published a methodology for setting administrative penalties for regulatory breaches by supervised credit institutions and, where relevant, legal persons conducting unauthorized banking activities. Penalties will reflect the breach’s severity, the institution’s size and financial strength, and any aggravating or mitigating circumstances, while remaining subject to statutory limits and a cap of 10% of annual net turnover. Breaches are classified from Minor to Extremely Severe based on their impact and the degree of misconduct. For Minor to Very Severe breaches, starting amounts are calibrated using five asset clusters ranging from EUR 2 billion or less to more than EUR 15 billion, with further size-sensitive adjustments. Reliably quantified profits gained or losses avoided may instead determine the base amount, while Extremely Severe breaches are assessed as a percentage of annual turnover. Adjustments may reflect disclosure, cooperation, remediation, financial condition and multiple breaches arising from the same facts. The methodology does not cover regulatory reporting breaches, unauthorized banking by natural persons or prudential breaches by significant institutions under direct European Central Bank supervision. It applies, however, to conduct-related breaches by significant institutions where these remain within the authority’s remit. The framework is guidance rather than an automatic calculation mechanism, and the authority retains discretion based on each case’s circumstances and representations from the institution.