CC··
IP
TZ
Four-stage AML/CFT pipeline — risk assessment, customer due diligence, monitoring, STR — and the Mauritius governance ecosystem
Updated 12 June 2026Reading time 17 minRegion Mauritius

Primary statute

FIAMLA

Financial Intelligence & Anti-Money Laundering Act

Regulations

FIAMLR 2018

plus FSC & BoM AML/CFT handbooks

International

FATF · 40 Recs

mutual-evaluation framework

STR deadline

Promptly

no tipping-off · FIU Mauritius

01Why AML/CFT matters in Mauritius

Mauritius operates a substantial international financial sector — global business companies, fintechs, management companies, and licensed financial institutions. That activity sits under continuous international scrutiny. The 2018–2021 FATF grey-list experience tightened expectations across the entire financial-services chain. The regulatory bar is now permanently higher.

For Mauritian regulated entities — and for any organisation processing financial flows — AML/CFT compliance is now both a legal obligation and a continuous reputational requirement.

02The Mauritius AML/CFT framework

Key statutes and regulators:

  • FIAMLA — Financial Intelligence and Anti-Money Laundering Act 2002, the foundational statute.
  • FIAMLR 2018 — the implementing regulations, the operational rulebook.
  • POCA — Prevention of Corruption Act.
  • POTA — Prevention of Terrorism Act.
  • UN Sanctions Act — implements UN Security Council financial sanctions in Mauritius.
  • FIU — Financial Intelligence Unit, the national STR/SAR receiver and analysis body.
  • FSC — Financial Services Commission, primary AML/CFT supervisor for non-bank financial entities.
  • Bank of Mauritius — primary AML/CFT supervisor for banks and deposit-taking institutions.

03Enterprise-wide risk assessment

Every reporting person must conduct and document an enterprise-wide risk assessment. It looks at:

  • Customers — type, jurisdiction, profile.
  • Products and services — risk of misuse.
  • Geographies — exposure to high-risk jurisdictions.
  • Delivery channels — face-to-face vs remote onboarding.

The assessment is the foundation of your risk-based approach. The CDD, monitoring and training programmes must be calibrated to its findings. It is reviewed annually or on material change.

04Customer Due Diligence (CDD)

Three tiers, calibrated by risk:

  • Simplified CDD — for demonstrably low-risk customers and products. Documented justification required.
  • Standard CDD — identification, verification, beneficial ownership, purpose and intended nature of the relationship.
  • Enhanced CDD — for higher-risk customers, PEPs, high-risk jurisdictions, complex structures. Senior management approval and ongoing scrutiny.

Beneficial ownership identification — going beyond legal ownership to identify the natural persons who ultimately own or control the customer — is non-negotiable. Trust and corporate structures cannot be used to obscure ultimate ownership.

05PEP and sanctions screening

Politically Exposed Persons (PEPs), their family members and close associates require enhanced due diligence. Sanctions screening against UN, EU and other applicable lists must be conducted at onboarding and continuously thereafter. False positives need a documented adjudication process. The screening lists, the matching engine and the audit trail are all part of what supervisors will examine.

06Transaction monitoring, STR and SAR reporting

Transaction monitoring identifies unusual patterns relative to the customer's profile. The monitoring rules must be documented, tuned and reviewed. False-positive rate matters, but failing to detect a true positive matters more.

When suspicion arises, a Suspicious Transaction Report (STR) is filed with the FIU. The tipping-off prohibition is absolute — the customer must not be told. STR records must be retained, the decision rationale documented, and the case follow-up tracked.

07Governance and training

  • Compliance officer — appointed in writing, with independence and resources.
  • MLRO — Money Laundering Reporting Officer, the single point of accountability for STRs and FIU liaison.
  • Board oversight — minuted, with periodic management information.
  • Training — induction for new staff and annual refresh for everyone. Role-based for high-exposure functions.
  • Independent audit — periodic AML/CFT audit by internal audit or external assurance.
resources.consultation --book
Want a concrete plan for your context? Book a working session with our Mauritius consultants.