Asset Management Policy Template (Malta)

Updated on 13 August 2026

Asset Management Policy Template (Malta) is a Malta-specific fillable document template built around local terminology, filings, evidence and checks that a director, shareholder, creditor, buyer, cultural organiser, artist, accountant or data owner may later need to prove.

It is not a generic US form with Malta written into the heading. A Malta asset management policy should connect purchasing, asset register, VAT retention, data protection, access controls and disposal approvals. The guide therefore focuses on Maltese registry filings, Companies Act mechanics, tax records, employment-transfer rules, copyright and neighbouring rights, IDPC breach assessment and clean evidence trails.

0 of 7 blanks filled

Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark

Asset Management Policy

Entity:
Date:
Owner:

1. Scope

2. Approvals and register

3. Security, data and access

4. Retention and disposal

Director

Date:

Asset owner

Date:

Maltese equivalent and when to use it

The local equivalent is an internal asset management policy: scope, roles, approval thresholds, register fields, acquisition evidence, custody, security, data-bearing assets, movement, review, disposal, VAT records and incident response.

For Malta, the useful question is not just what the document is called, but whether it lines up with the Malta Business Registry, the Companies Act, the tax and VAT record trail, employment-transfer rules, copyright permissions and any online filing or authority notification that sits outside the private document.

Use this template to prepare a working draft in the browser, then download a DOCX for editing and a PDF for signature or circulation. Where an MBR form, BAROS filing, court process, tax registration, IDPC notification, Jobsplus or Identita submission, or Arts Council Malta application is required, the template remains a supporting document and the official step must be completed separately.

Legal and practical basis in Malta

MTCA VAT Records guidance requires transaction records, documents and accounts to be retained for at least six years in most cases, with special timing for capital goods and certain electronic records.

The guidance also addresses electronic storage of invoices and authenticity/integrity data, which matters when purchase invoices, software licences and asset records are stored digitally.

The IDPC breach page requires controllers to assess whether a security incident risks data subjects and, where required, notify within 72 hours. The policy should make asset loss, unauthorised access and device disposal reportable internally.

Decisions before filling

Define covered assets: fixed assets, capital goods, laptops, phones, servers, software, keys, cards, customer databases, archive drives, art, equipment and assets held by employees.

Assign responsibility for purchase approval, register maintenance, physical checks, IT access, insurance, breach assessment and disposal.

Tie the policy to onboarding, offboarding, procurement, grant-funded projects, finance close, VAT evidence and data breach procedures.

Attachments and proof trail

Attach the evidence that makes the document checkable: asset register, purchase approval matrix, VAT record checklist, IT access procedure, device handover form, breach log, disposal approval form and periodic review schedule. The attachment name, date and version should match the signed document, email thread, filing receipt and archive folder.

If an attachment changes after signature, do not silently replace the old file. Record who approved the change, whether a new signature, MBR filing, debtor notice, employee transfer declaration, copyright permission or IDPC assessment is needed, and where the previous version remains stored.

Most disputes are evidence disputes. The missing item is often a resolution, proof of bank deposit, MBR form, fiscal record, assignment notice, asset list, employee schedule, photo credit, recording licence, breach log or acknowledgement of receipt. This template makes those items visible instead of leaving them in informal messages.

Records, tax and data protection

Many of these documents contain personal data: names, addresses, signatures, shareholder or director details, artist photos, employee lists, debtor files, customer databases, access credentials and device identifiers. Share only what is necessary for the transaction or filing.

The Malta Tax and Customs Administration states that VAT records, information, documents and accounts must generally be retained for at least six years, with longer electronic retention for certain intra-community distance sales and special timing for capital goods. If the document affects invoices, assets, consideration, business transfer or liquidation, record retention must be planned with the contract.

The IDPC states that a controller must notify a personal data breach within 72 hours of becoming aware of it unless the breach is unlikely to result in a risk to data subjects. Asset, data, press and employee-transfer documents should therefore identify data-bearing assets, access handover and incident responsibility before something goes wrong.

How to fill it

Start with the document function: define asset scope, responsible owner and approval thresholds. Then enter parties exactly as they appear in the MBR, contract, grant application, invoice, employment record or press file.

Use consistent vocabulary across the whole packet. If the parties use both a Maltese statutory term and a commercial English label, choose one main label and define the other. Dates, amounts, annexes, rights, filings and notices must match the resolutions, accounts, tax records, contracts and authority submissions.

Before sending, produce a PDF for signature or controlled circulation and keep a DOCX working copy. Store the signed copy, filing receipt, notice evidence, email acknowledgement, invoice, payment proof, consent, licence or reference number together with the final document.

Quality check

Read the document as if you were the recipient. Can you tell who is deciding, selling, assigning, paying, transferring, publishing, storing or notifying without a phone call? If not, add a definition, schedule or next-step clause.

Check for contradictions between the document and the rest of the file: company name, registration number, registered office, share capital, authorised signatory, price, assets included, employees transferred, data files, copyright permissions, filing deadlines, tax records and attachments.

If the matter involves high value, regulated activity, company filings, minority shareholders, employees, foreign parties, security interests, insolvency risk, copyright exploitation, personal data or official grant money, get professional review before signing.

Limits

This template does not replace the Malta Business Registry portal, a Companies Act filing, BAROS submission, court process, statutory form, tax or VAT registration, Jobsplus/Identita process, IDPC breach notification, copyright licence or professional advice.

It also does not guarantee that a grant will be awarded, a debtor will pay, a creditor will release an existing debtor, a buyer will avoid employee-transfer consequences, an asset list will exclude hidden liabilities, or press material may be used in every channel. Those outcomes depend on facts, contracts, statutory filings and consents.

Clause-by-clause guide

Scope
Defines which assets and records fall under the policy.
Roles
Assigns finance, operations, IT, manager and user responsibilities.
Register
Requires minimum fields and periodic review.
Records
Links purchase, VAT, capital goods and invoice retention.
Security
Controls devices, credentials, access, backups and breach reporting.
Disposal
Requires approval, data wipe, accounting update and evidence.

Malta checklist

Before signing, filing or storing the document, check these Malta-specific points and sources.

  • Set VAT record retention

    VAT records are generally retained for at least six years.

    MTCA VAT records
  • Address capital goods

    For capital goods, retention timing runs from the end of the adjustment period.

    MTCA VAT records
  • Create incident route

    IDPC expects risk assessment and notification where required within 72 hours.

    IDPC - notify a breach
  • Document electronic invoices

    Electronic invoice storage must preserve authenticity and integrity where required.

    MTCA VAT records

How to use this template

  1. Choose the legal function. Name the assets covered and the internal owner of the policy.
  2. Collect schedules. Prepare asset register, purchase approval matrix, VAT record checklist, IT access procedure, device handover form, breach log, disposal approval form and periodic review schedule, plus the responsible contacts and archive location.
  3. Fill the document. Enter parties, dates, amounts, rights, filings, notices, attachments, approvals and evidence owners.
  4. Run the Malta checks. Compare the draft with the MBR, tax, VAT, employment, copyright and IDPC checklist before signing.
  5. Download and store. Download DOCX for edits and PDF for signature; store receipts, notices, licences, filings, payments and signed versions.

Frequently asked questions

Does a small Malta company need this?

If it holds devices, records, licences, valuable equipment or VAT evidence, a short policy is useful.

Is the policy the same as the register?

No. The policy sets rules; the register lists assets and evidence.

Should employee devices be included?

Yes, especially where devices contain work data, customer data, credentials or grant-funded assets.

How should lost equipment be handled?

Require immediate internal reporting, access revocation, data-risk assessment and IDPC notification where needed.

What is the VAT retention rule?

MTCA says VAT records are generally kept for at least six years, subject to special rules.

Who approves disposal?

The policy should name an approver and require finance and IT checks where relevant.

Can assets be stored digitally only?

Electronic storage may be acceptable, but invoice authenticity, integrity and accessibility should be preserved.

When should the policy be reviewed?

After major purchases, incidents, audits, employee exits, office moves, system migrations and at a regular interval.

Related templates

Disclaimer

This Malta template and guide are for general information only. They are not legal, tax, accounting, employment, financial or data-protection advice, and they do not claim approval by the Malta Business Registry, Commissioner for Tax and Customs, DIER, Jobsplus, Identita, IDPC, Arts Council Malta, a lawyer, auditor, notary or any other Maltese authority.