This interview is part of a series spotlighting AGRC’s global training partners and exploring how they are advancing professional education, thought leadership, and GRC practice in markets around the world.


Could you begin by introducing the Auren Institute and telling us how your experience in compliance training has shaped the organisation’s work in Malta and beyond?

Auren Institute is a compliance training business. We work with employers in Malta and the UK, and the job is easy to describe and hard to do well: take a regulatory obligation and turn it into something a person can actually use at their desk. Our line is ‘Compliance, Done Right’.

I started Auren after years of watching compliance training done badly. I had spent a long time training and consulting for businesses, some of them multinationals, and lecturing in management, and I kept seeing the same two failures. On one side, dense legal content that almost nobody finished. On the other, generic e-learning built to tick a box and change nothing. Both leave an employer exposed, because a certificate in a folder is not the same thing as a team that knows what to do when something goes wrong.

So, we built Auren around one question: would this training survive in the room where the decision actually gets made? In practice that means content written by practitioners, real scenarios instead of abstract principle, and a promise to keep regulated material current, which for us is a thirty-day rule on anything that changes. Malta is where we started and where we know the ground. The thinking travels, and that is why the work now reaches past it.

Malta is a small jurisdiction with a significant concentration of financial services, iGaming and digital-asset businesses. What makes its governance, risk and compliance environment distinctive?

The distinctive thing about Malta is the gap between the size of the country and the size of what it regulates. The domestic workforce is smaller than many single cities, yet it carries financial services, iGaming and digital assets that trade on a fully international scale. The expectations are European and global. The pool of people who meet them is small, and most of them know each other.

That shapes everything. The Malta Financial Services Authority, the Malta Gaming Authority, the Financial Intelligence Analysis Unit and the data protection regulator are all active, and the firms they supervise have clients and counterparties all over the world. Malta also moved early on digital assets, with a virtual financial assets framework in place before much of Europe had acted, and that sector now has to line up with the EU-wide crypto rules.

Then there is the grey listing. Malta went onto the Financial Action Task Force grey list in 2021 and came off it in 2022. It was a hard period, but it sharpened standards and it changed the culture around anti-money laundering in a way that has held. So, the environment is distinctive for a reason that is easy to miss from the outside. This is a small jurisdiction that has had to work to the standards of a much larger one, under real scrutiny, and learn quickly. That produces serious compliance people, and it raises the bar for how you train them.

In many Maltese organisations, responsibility for areas such as AML, risk, data protection and regulatory compliance may fall to a relatively small team. What pressures does this create, and where are the most urgent training needs?

In a lot of Maltese firms it is not a small team, it is one person wearing several hats. The same individual is the money laundering reporting officer, the point of contact for data protection, and the person the board leans on for risk. That creates three problems worth naming plainly.

The first is key-person risk. If it all lives in one head and that person leaves or burns out, the firm’s compliance capability walks out with them. The second is that there is no room to specialise. When you are holding anti-money laundering, data protection and operational risk at once, it is hard to go deep on any of them, and depth is exactly what a regulator wants to see when something is tested. The third is pace. The obligations keep arriving and the team does not grow to match.

The most urgent need is not more awareness. These people are already aware. What they need is practical, role-ready capability across several areas, delivered in a way that spreads knowledge rather than piling it higher on one person. That means training a second and a third colleague to a credible level, not just the obvious lead. It also means recognised, certificated qualifications, because a portable credential helps a small firm attract and keep the compliance talent it cannot afford to lose. Done properly, training here is not a cost line. It is how a stretched team stops being a single point of failure.

With requirements relating to AML, DORA, the EU AI Act and ESG increasingly converging, what does effective GRC training need to deliver beyond basic regulatory awareness?

Awareness is the floor, not the ceiling. Knowing that DORA exists, that the AI Act is phasing in across 2026 and 2027, that ESG reporting is tightening, none of that is the hard part. The hard part is judgement: knowing what to do, in your own organisation, when these obligations land on the same desk at the same time.

Good training has to give people three things on top of awareness. One is application. Not ‘here is what the regulation says’, but ‘here is how you turn it into a control, a policy, and a decision you can defend’. 

The second is the ability to see the connections. Anti-money laundering, operational resilience, AI governance and ESG look like separate regimes, but underneath they run on the same discipline: find the risk, put proportionate controls around it, write down your reasoning, and review it. Someone who gets that pattern adapts to the next regulation far faster than someone who has only memorised the current one. 

The third is currency. Regulation moves, and training that was right last year can quietly go wrong. That is why we hold ourselves to a thirty-day rule on regulated content. If a person is going to carry real responsibility, the material behind them has to be right on the day they use it.

The test of good GRC training is not what someone can recite in an exam. It is what they can do on the Monday morning after.

Why did Auren Institute choose to collaborate with AGRC, and how do AGRC’s internationally recognised qualifications complement the training and expertise you already provide?

We chose AGRC because the two halves fit together cleanly. What Auren does well is make training land: practical, current, built by practitioners, aimed at changing how people actually work. What AGRC adds is the recognised qualification that sits on top of that and makes it count, on a CV, with an employer, and with a regulator.

AGRC is a professional body whose certificates are accredited by the London Institute of Banking and Finance, and its range maps almost exactly onto the pressures we have been talking about. Certificates in compliance, anti-money laundering, know-your-customer and due diligence, risk management, sanctions, corporate governance and ESG, with specialist routes into financial crime in crypto and into AI risk, and diplomas that pull the strands together. For the small, stretched teams I described, that is the cross-area coverage they need, carrying a credential that travels.

The complement is the whole point. A good internal course can change behaviour, but on its own it does not give someone portable professional standing. An accredited certificate gives that standing, but on its own it can sit at a distance from the day job. 

Deliver AGRC qualifications with the Auren approach to how people learn, and a professional gets both: capability they can use on Monday, and recognition that follows them through a career. For an employer, that is training that strengthens the person and the organisation at the same time, which is the reason we do any of this.

What impact do you hope your AGRC partnership will have on GRC professionals and employers in Malta, and what lessons from the Maltese market would you like to share with the wider international community?

For professionals, I want this to raise the floor. I want the people quietly holding compliance together in small and mid-sized firms to have recognised qualifications, real confidence, and a credential that moves with them. Too many capable compliance people are undervalued because their skill has never been formally recognised. Fixing that is good for them and good for the market.

For employers, I want the conversation to move from buying a course to building capability. The goal is not a certificate on file. It is a team that is genuinely harder to catch out, with the knowledge sitting in more than one head. That is the outcome worth paying for.

As for lessons from Malta, two stand out. The first is that a small jurisdiction under real scrutiny learns fast, and there is value in that. The grey-listing years were painful, but they forced a maturity in anti-money laundering and governance that larger markets sometimes reach more slowly. 

The second is proportionality. Small teams here routinely meet international standards without international-sized budgets, by being honest about the risks that actually matter and not drowning in the ones that do not. Doing the serious things seriously, and refusing to treat compliance as paperwork, is something any market can borrow, whatever its size.


Stefan Gauci Scicluna is the Managing Director of Auren Institute, a compliance training business working with employers across Malta and the UK under the line Compliance, Done Right. His background spans compliance and management training, business consulting for multinational clients, and lecturing in management at Maltese higher education institutions. He is completing a Doctor of Business Administration at Signum Magnum College, researching eLearning as organisational practice in Maltese organisations. He holds a B.Com from the University of Malta and an MA from the College of Europe in Bruges, and sits on the Malta Chamber of SMEs Skilling, Up-Skilling and Future of Work Standing Committee.