10-Component Template for FSC-Licensed Firms
This guide is for compliance officers, MLROs, board members, and management company professionals at FSC-licensed entities in Mauritius, including investment funds, global business companies, securities dealers, and management companies. You will learn what a compliant AML governance framework must contain under FIAMLA and the FSC AML/CFT Handbook, how AMLA 2026 changes the compliance landscape, and how to build a framework that satisfies FSC inspection criteria today.
Introduction
Mauritius has one of the most rapidly evolving AML governance environments in Africa. Since exiting the FATF grey list in 2021, the jurisdiction has enacted or amended AML legislation in almost every successive year. Government Notice No. 112 of 2025 introduced tiered administrative penalties, with fines up to MUR 250,000 for KYC and reporting failures, effective November 2025. Between December 2025 and March 2026, the Financial Crimes Commission (FCC) conducted 70 search operations, made 26 arrests, and restrained assets worth approximately MUR 160 million. The Anti-Money Laundering Act 2026 (AMLA 2026) introduces proliferation financing as a formal compliance pillar and compresses enforcement timelines.
For FSC-licensed firms in Mauritius, this trajectory means one thing: an AML governance framework adequate in 2022 is almost certainly no longer sufficient. Rebuilding that framework around current FSC expectations is not optional.
Regulatory framework for AML governance in Mauritius
FIAMLA 2002 is the foundational statute for AML governance in Mauritius. Section 17 requires a risk-based AML/CFT programme; Section 18 governs STR reporting; and Section 32A establishes criminal liability for breaches.
The FIAML Regulations 2018 require mandatory designation of a compliance officer at the senior management level to maintain day-to-day AML oversight.
The FSC AML/CFT Handbook sets the operational standard for all FSC licensees, covering programme components, CDD documentation standards, and board governance expectations. FSC inspectors must be able to see documented risk appetite and risk assessment rationale.
AMLA 2026 consolidates FIAMLA and introduces CPF (Countering Proliferation Financing) as a mandatory third compliance pillar alongside AML and CFT, requiring a distinct CPF risk assessment and dedicated screening against proliferation-related sanctions lists.
GN 112/2025 (effective November 2025) introduced tiered administrative penalties up to MUR 250,000 for KYC and reporting failures. The FSC (established March 2024) has significantly intensified enforcement, signalling that documentation gaps, not only active violations, attract enforcement attention.
AML governance framework template for Mauritius
| Framework Component | Required Content |
|---|---|
| 1. Board Oversight | Board responsibility for AML/CFT/CPF programme approval; minimum annual board-level AML review; escalation pathway from MLRO to board; board minutes evidencing substantive AML discussion. |
| 2. MLRO Appointment | MLRO designated at senior management level; role description documented; FSC notification on file; deputy MLRO appointed; MLRO has authority to access all client and transaction data. |
| 3. Business Risk Assessment | Documented ML/TF/PF risk assessment covering client types, products, geographic exposure, and delivery channels; risk appetite statement; linkage to Mauritius National Risk Assessment; and annual review cycle. |
| 4. CDD and EDD Procedures | Standard CDD requirements by client type, UBO identification to the natural-person level, PEP screening, EDD triggers and approval requirements, and source of funds/wealth procedures for high-risk clients. |
| 5. Ongoing Monitoring | Transaction monitoring procedures, re-screening frequency by client risk tier, triggers for reassessment, and a record of monitoring activity. |
| 6. STR Filing | Internal suspicious activity reporting procedure; MLRO review and determination process; FIU filing procedure; tipping-off prohibition; record retention. |
| 7. CPF Programme (AMLA 2026) | CPF risk assessment (separate or integrated); proliferation financing typologies; screening against proliferation-related sanctions lists; CPF training for front-line staff. |
| 8. Training | Annual AML/CFT/CPF training for all relevant staff; content updated for AMLA 2026 and FSC guidance; completion records maintained. |
| 9. Independent Audit | Annual AML programme audit by a suitably qualified independent function; audit report to the board; remediation of findings tracked to closure. |
| 10. Record-keeping | All CDD, transaction, and programme records are retained for 7 years from the end of the business relationship under Mauritius law. |
Key Best Practices
âś… Build CPF as a formal pillar now; AMLA 2026 makes proliferation financing a statutory obligation; integrating CPF screening before full enforcement avoids a reactive rebuild under pressure.
âś… Document risk appetite explicitly; the FSC Handbook requires inspectors to see a clear, documented rationale for risk ratings. Generic assessments without supporting rationale are a recurring inspection finding.
âś… Treat FCC enforcement activity as a calibration signal. GN 112/2025’s tiered penalties mean a single documentation gap now carries direct financial consequences.
âś… Ensure the independent audit covers CPF; audit programmes covering AML/CFT but not CPF will have a material gap once AMLA 2026 is fully in force.
Explore Cascade’s Capabilities for Mauritius-Licensed Firms
Cascade’s AML Software (SaaS Platform) can support Mauritius-licensed firms with centralised KYC/CDD, customer risk assessment, name screening, AML workflows, ongoing monitoring and compliance reporting.
Its add-on modules can further support automated treatment of name-screening alerts, digital client onboarding communications, and AML reporting and analytics. These modules require the core AML Software platform.
Explore Cascade’s compliance workflow capabilities →
Disclaimer
This article is for general informational purposes only and reflects publicly available sources at the time of writing, including FIAMLA, the FSC AML/CFT Handbook, Government Notice No. 112 of 2025, and available summaries of AMLA 2026. Mauritius AML regulatory requirements, FSC supervisory expectations, and enforcement priorities change regularly, and AMLA 2026 was still being finalized at the time of writing. The template and framework provided here are illustrative starting points and do not constitute legal or professional advice. FSC-licensed firms should assess their specific circumstances and consult qualified legal and compliance counsel before implementing any AML governance framework. Cascade makes no representation that this content reflects current regulatory requirements or that its use will ensure regulatory compliance.
Frequently asked questions
What is the record retention period for AML records in Mauritius?
Under FIAMLA, all AML records, CDD documentation, transaction records, and STR records must be retained for 7 years from the end of the business relationship or the date of an occasional transaction. This is longer than most EU-equivalent jurisdictions, which typically require 5 years.
What does AMLA 2026 add to the AML governance framework in Mauritius?
AMLA 2026 consolidates FIAMLA into a single instrument and introduces three material changes to the AML governance framework: proliferation financing (CPF) as a mandatory compliance pillar; a faster administrative penalty procedure; and mandatory electronic beneficial ownership reporting. Every FSC licensee must update its AML governance framework to cover CPF.
How often must the business risk assessment be reviewed?
Annually at minimum, and following any material change in client base, products, or geographic exposure; any new FIU or FSC typology publication; or a regulatory change such as AMLA 2026.
How does Cascade support AML governance for Mauritius-licensed firms?
Cascade can support AML governance for Mauritius-licensed firms by centralising KYC/CDD, risk-based client assessment, screening, ongoing monitoring, workflows, and audit trails, helping compliance teams evidence how AML decisions are made.
This is not legal advice. Mauritius-licensed firms should validate their configuration with a qualified local AML professional.
Which screening providers does Cascade integrate with?
Cascade integrates with three leading screening data providers: Acuris Risk Intelligence, LSEG World-Check, formerly Refinitiv World-Check, and Dow Jones. These integrations support screening for sanctions, PEPs, adverse media and other watchlist or regulatory risk data within Cascade’s AML/KYC workflows.
Related Readings:
AML File Checklist for Mauritius Management Companies
Best KYC Providers in Mauritius






































