Key Takeaways
- Foreign-owned companies in Mauritius and their service providers can fall within scope as reporting persons subject to AML and KYC obligations.
- Customer due diligence, ongoing monitoring, and record-keeping form the core duties, with enhanced or simplified measures applied on a risk basis.
- Suspicious transaction reporting runs through a designated MLRO, while supervision is shared across the FIU, FSC, and Bank of Mauritius.
- Non-compliance carries penalties, making the registered agent's role central to keeping a Mauritius company aligned with its AML duties.
AML and KYC Obligations in Mauritius: An Overview
Anti-money laundering and know-your-customer rules in Mauritius set out how a regulated business must verify who its customers are, assess the risk they carry, monitor their activity, and report anything suspicious to the authorities. These obligations apply across the financial sector and to a defined group of non-financial businesses, anchored by the Financial Intelligence and Anti-Money Laundering Act 2002 and the regulations made under it. The framework is supervised by several bodies, and its consolidated text is published by the FIU Mauritius.
For a foreign owner of a Mauritius entity, the AML/KYC regime rarely operates through you directly. It operates through the licensed management company or registered agent that administers your structure, and your job is to feed that agent accurate, current information. This article explains the law, the supervisors, the customer due diligence and reporting duties, record-keeping, and the penalties for getting it wrong. It is most relevant to non-resident holders of Global Business Licence companies, fund structures, and special purpose vehicles administered from the island.
The Legal Framework: FIAMLA, the FIAML Regulations, and AMLA 2026
The Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA) is the foundation. It created an independent Financial Intelligence Unit, imposed customer due diligence duties, and built the suspicious transaction reporting system that the rest of the regime relies on.
Detail sits in the Financial Intelligence and Anti-Money Laundering Regulations 2018, published as Government Notice No. 108 of 2018. These set out, in concrete terms, the measures a reporting person must put in place, and they replaced the earlier 2003 regulations.
Two further statutes round out the core: the Asset Recovery Act 2011 and the United Nations (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act 2019, which governs sanctions screening and asset freezing. Together with amendments to the proceeds-of-crime and terrorism statutes, this body of law was built to meet Financial Action Task Force standards.
The reform cycle has not stopped. The most significant change since FIAMLA itself is AMLA 2026, the Anti-Money Laundering, Combatting the Financing of Terrorism and Countering Proliferation Financing legislation, which restructures the framework, adds proliferation financing as a formal compliance pillar, and strengthens enforcement. FIAMLA was most recently amended by section 10 of Act 3 of 2026, effective 18 April 2026.
Enforcement teeth came earlier. The Financial Crimes Commission Act 2023 created the Financial Crimes Commission as the apex enforcement body, replacing the former Independent Commission Against Corruption.
Mauritius left the FATF grey list in October 2021 and is rated compliant or largely compliant with 39 of 40 FATF Recommendations. The next regional mutual evaluation is scheduled for 2027, and recent reforms are partly preparation for it.
Company Incorporation in Mauritius
Set up your company in Mauritius with Expanship handling registration end to end.
Who Supervises AML and KYC: The FIU, FSC, and Bank of Mauritius
Four bodies divide the work. The Financial Intelligence Unit, established under section 9 of FIAMLA in August 2002, receives, analyses, and disseminates intelligence on suspected proceeds of crime, money laundering, and terrorism financing. Under AMLA 2026 its remit extends to proliferation financing intelligence and gains broader data-sharing powers with foreign counterparts.
The Financial Services Commission is the supervisor most foreign owners will deal with. It oversees the non-bank financial sector, including investment funds, Global Business Licence holders, securities dealers, insurers, and fintech platforms, and it issues binding AML guidance for its licensees, set out on the FSC AML/CFT page.
The FSC issued its Code on the Prevention of Money Laundering and Terrorist Financing in March 2012, a single document covering all licensees, and it has signed a memorandum of understanding with the FIU on cooperation.
The Bank of Mauritius supervises banks, payment service providers, and money changers, issuing AML guidelines on transaction monitoring and reporting specific to those entities. The Financial Crimes Commission, operational from 29 March 2024, investigates and prosecutes financial crime, with conviction penalties reaching MUR 20 million.
Regionally, the jurisdiction is an active member of the Eastern and Southern Africa Anti-Money Laundering Group and an associate member of FATF.
Who Counts as a Reporting Person: Companies and Their Service Providers
The law applies to "reporting persons": banks, financial institutions, cash dealers, and members of defined professions and occupations. In practice this covers all financial institutions and the category known as Designated Non-Financial Businesses and Professions.
Obliged entities include banks, fintechs, investment funds, corporate service providers, and lawyers offering financial or advisory services. For a foreign-owned structure, the most important obliged party is usually the management company administering it.
Management companies running GBL structures sit squarely inside the supervision perimeter, and their failures become the failures of the entities they administer. Under AMLA 2026, a fund's management company and administrator are standalone reporting persons, each required to conduct and document its own due diligence on investors rather than relying on the general partner.
The same principle reaches special purpose vehicles. Trustees and management companies administering SPVs hold independent reporting obligations and can no longer lean entirely on the SPV's registered agent.
The FIU has flagged real estate, especially high-value property purchases by foreign buyers, as a priority money laundering risk sector.
One narrow carve-out matters: legal professionals are not subject to AML obligations when ascertaining a client's legal position or defending or representing that client in judicial, administrative, arbitration, or mediation proceedings.
Ongoing Compliance in Mauritius
Keep your Mauritius entity compliant with filings, returns, and statutory obligations.
The Risk-Based Approach and Business Risk Assessment
Everything starts with risk. Section 17 of FIAMLA obliges every reporting person to identify, assess, and understand the money laundering and terrorism financing risk it faces, and to document that assessment against its own business model, client base, and geographic exposure.
The assessment is not a one-time exercise. Regulation 31 of the 2018 Regulations requires risk assessment systems to be reviewed regularly, with deficiencies remedied quickly; most firms review annually, though circumstances may justify a different cadence.
Responsibility sits at the top. The board must own the business risk assessment, keep it current, and on the strength of it set a formal strategy to counter money laundering and terrorism financing.
The risk-based approach does not lower the floor. Where higher-risk factors appear, enhanced measures must follow regardless of the general posture, and under AMLA 2026 reporting persons must also maintain proliferation-financing risk assessments and screen for targeted financial sanctions on that ground. National context informs all of this: the first National Risk Assessment, completed in August 2019, mapped the principal threats and vulnerabilities across sectors.
Customer Due Diligence and KYC Requirements
Customer due diligence is the operational heart of the regime. In line with section 17C of FIAMLA, a reporting person must identify and verify the true identity of each customer using independent source documents, data, or information.
Identity does not stop at the account holder. Regulation 6 of the 2018 Regulations requires identification of the beneficial owner, defined as the natural person who ultimately holds a controlling ownership interest in the legal person. The Act does not fix a precise percentage for "controlling ownership interest," a gap noted publicly during the legislative process.
For corporate clients, the ultimate beneficial owner must be established from reliable, independent sources and the information verified. Under AMLA 2026, verification standards expand and beneficial owners must be reported to an electronic registry within prescribed timelines.
KYC in Mauritius therefore runs across a defined set of steps:
- Verify the identity of the client.
- Identify and verify the ultimate beneficial owners.
- Apply due diligence proportionate to assessed risk, classifying each client as low, standard, or high risk.
- Monitor transactions through the life of the relationship.
- Report suspicious activity to the FIU.
There is also a hard limit on cash. Section 5 of FIAMLA restricts cash transactions above MUR 500,000, subject to limited exemptions, and a payment at or over that level can itself prompt a suspicious transaction report.
Mauritius Incorporation Pricing
See transparent pricing to incorporate and maintain a company in Mauritius.
Enhanced and Simplified Due Diligence
Risk dictates intensity. Where higher money laundering or terrorism financing risk is present, enhanced due diligence is mandatory, and if a reporting person cannot complete the required enhanced checks it must end the relationship and file a suspicious transaction report under section 14 of FIAMLA.
Politically exposed persons drive much of this. Foreign PEPs always trigger full enhanced due diligence: senior management approval, source of wealth and source of funds verification, and heightened ongoing monitoring. Domestic and international-organisation PEPs trigger enhanced measures only in higher-risk relationships, and the duties extend to family members and close associates in each case.
Regulation 12 sets out the PEP measures, which require firms to determine PEP status of customers and beneficial owners, obtain senior approval before opening or continuing the relationship, and establish source of wealth and funds. The framework deliberately avoids a blanket "all PEPs are high risk" rule, favouring identification plus proportionate controls.
Lower risk allows lighter checks. Simplified due diligence may be applied where lower risk is genuinely identified, provided the measures match the risk and follow any supervisory guidance, but it can never apply where money laundering or terrorism financing is suspected.
Ongoing Monitoring of Business Relationships
Due diligence does not end at onboarding. The risk-based approach requires continuing monitoring of transactions throughout a business relationship, calibrated to the risk each customer presents, and reporting persons must keep collected information current.
PEP relationships demand more: enhanced ongoing monitoring, higher-frequency reviews, and dynamic risk-rating updates as circumstances shift.
Sanctions screening is a separate, continuous duty. The UN Sanctions Act 2019 requires reporting entities to screen against the UN consolidated lists, freeze assets, and report immediately on a match. In practice this means screening at onboarding against UN, OFAC, EU, and relevant regional lists, then re-screening as those lists change rather than once only.
AMLA 2026 raises the operational bar. The move to electronic reporting and a centralised beneficial-ownership registry, combined with tightened filing deadlines, means compliance teams must be properly resourced and authorised to act quickly.
AML Record-Keeping Obligations
Records prove that the system works. Under section 17(b) of FIAMLA, reporting persons must keep records in an accessible and retrievable form, and the FIU treats failures here as serious, exposing firms to regulatory and criminal sanction.
| Record type | Minimum retention |
|---|---|
| CDD and transaction records (FSC-licensed practice) | 7 years from the relevant event or end of relationship |
| Statutory baseline under FIAMLA s. 17(b) | At least 5 years after the relationship ends |
| Internal/external reports and Suspicious Activity Reports | 7 years after the report was made |
The seven-year figure appears in FSC-licensed entity practice manuals; the statutory minimum should be confirmed against the consolidated Act in force following AMLA 2026.
The purpose is simple. A regulated entity must be able to produce customer and transaction information on request by the FSC, FIU, law enforcement, courts, auditors, or other competent authorities.
Tampering carries heavy consequences. Concealing, falsifying, or destroying a document known to be relevant to an inspection or investigation is an offence punishable by a fine up to MUR 5 million and imprisonment up to 10 years. Where the FIU requests information, it must be supplied within 15 working days, a fixed deadline that replaced the older "as soon as practicable" standard.
Suspicious Transaction Reporting and the Role of the MLRO
Reporting is time-critical. The Money Laundering Reporting Officer must lodge a validated suspicious transaction report with the FIU within 5 working days of the suspicion arising, down from the previous 15. Every such report is made under section 14 of FIAMLA and filed through the FIU, which operates the GoAML reporting system.
Two named officers anchor the internal system. Depending on size and nature, a reporting person must appoint both a Compliance Officer and a Money Laundering Reporting Officer; these roles cannot be outsourced and must be held by employees of the entity. The MLRO and any deputy must be appointed, notified to the FIU, and registered on its systems.
The MLRO holds real authority. This officer receives internal reports of unusual activity, decides how to treat them, and may intervene in any transaction or course of conduct where a breach is feared.
Smaller firms have a fallback. Where size or nature makes appointing an MLRO impractical, the entity must still maintain documented policies and procedures and file suspicious transaction reports directly with the FIU.
| Failure | Penalty |
|---|---|
| Late STR (after 5 working days) | Fine up to MUR 1 million; imprisonment up to 5 years |
| No effective risk assessment to detect ML/TF | Fine up to MUR 10 million; imprisonment |
| Tipping off the subject of a report | Imprisonment up to 10 years |
Cash above the MUR 500,000 ceiling, whether single or aggregated, is prohibited and must be reported as suspicious if it occurs.
The Role of the Registered Agent in AML Compliance
This is where the regime meets the non-resident owner most directly. A foreign owner of a GBL company cannot discharge AML duties personally from abroad; the Mauritius-licensed management company that acts as registered agent is the reporting person that holds the KYC file, performs due diligence, and files reports.
That agent depends on you. It acts on the information the beneficial owner supplies, so the file is only as accurate as the data you provide and keep current.
The agent's exposure is also the company's exposure. Because a management company's compliance failings are treated as those of the entities it administers, gaps in your information translate directly into regulatory risk for the structure.
Under AMLA 2026, the chain of responsibility lengthens. Funds' management companies and administrators are standalone reporting persons conducting their own investor due diligence, and lenders providing subscription lines must satisfy themselves that the limited partner base has been screened to enhanced and proliferation-financing standards before committing a facility. Within each entity, the Compliance Officer must sit in senior management and report directly to the board on FIAMLA obligations.
Penalties for AML and KYC Non-Compliance
The sanction toolkit runs from administrative fines to imprisonment. The FIAML (Administrative Penalties) Regulations 2025, made under sections 19H(1)(d)(iii) and 35 of FIAMLA, took effect on 18 November 2025 and let supervisors impose fines from MUR 5,000 to MUR 250,000 according to the gravity of the breach.
The administrative regime is structured, not arbitrary. It categorises 39 breaches as Low, Moderate, Moderate-to-High, or High, weighing the nature, duration, compliance history, and economic impact of each. AMLA 2026 extends this graduated approach, letting the Bank of Mauritius and the FSC fine without waiting for criminal proceedings.
Criminal exposure remains real. Conviction for financial crime under the Financial Crimes Commission Act can reach MUR 20 million, and the record shows the authorities will act.
- A casino operator was fined MUR 500,000 in 2021 for CDD failures.
- A banker was convicted in 2023 and sentenced to 10 years for laundering drug proceeds.
- The FSC revoked the licences of two money changers for AML breaches in 2024.
Enforcement intensity is not incidental. The FSC's escalation, the FCC's expanding activity, and AMLA 2026 together reflect a pre-evaluation posture ahead of the 2027 regional mutual evaluation, so documentation gaps are unlikely to be treated leniently.
Conclusion
For a non-resident owner, AML/KYC compliance in Mauritius is delegated in practice but never transferred in law: your licensed management company carries the reporting duties, yet your structure bears the consequences if the underlying information is wrong, stale, or incomplete. The single most useful thing you can do is treat your beneficial-ownership and source-of-funds disclosures as a continuing obligation, refreshing them whenever your circumstances change.
With penalties now graduated, deadlines shortened, and a mutual evaluation approaching in 2027, the cost of a sloppy file has risen. Confirm that your registered agent has a current, complete KYC record on you and every beneficial owner before the next review cycle, not after a request lands.
How Expanship Can Help Your Business in Mauritius
Expanship supports foreign owners by working directly with your Mauritius-licensed management company to keep customer due diligence files, beneficial-ownership data, and source-of-funds documentation complete and current, so AML/KYC reviews pass without friction. Beyond that, we manage the wider compliance load that comes with owning a regulated entity from abroad.
- Company formation and Global Business Licence structuring
- Registered agent and registered office services
- Ongoing compliance monitoring and statutory filing management
- Accounting and bookkeeping support
- Economic-substance and beneficial-ownership reporting assistance
- Banking introductions for your entity
To discuss your structure's AML obligations and wider compliance needs, contact Expanship Mauritius.
Frequently Asked Questions
Usually not. Your Mauritius-licensed management company is the reporting person and files suspicious transaction reports and KYC information; your role is to supply accurate identity, beneficial-ownership, and source-of-funds details and keep them current.
The Money Laundering Reporting Officer must lodge a validated suspicious transaction report with the FIU within 5 working days of the suspicion arising, a deadline reduced from the earlier 15-day standard. A late report carries a fine up to MUR 1 million and imprisonment up to 5 years.
FSC-licensed entity practice applies a seven-year retention period for due diligence, transaction, and reporting records, while the statutory baseline under section 17(b) of FIAMLA is expressed as at least five years after the relationship ends. The exact figure in force after AMLA 2026 should be verified against the consolidated Act.
Administrative fines under the 2025 regulations run from MUR 5,000 to MUR 250,000 by gravity, while criminal exposure is far higher: up to MUR 10 million and imprisonment for failing to apply an effective risk assessment, and up to MUR 20 million on conviction for financial crime under the Financial Crimes Commission Act.
No. Foreign PEPs always require full enhanced due diligence, but domestic and international-organisation PEPs trigger enhanced measures only in higher-risk relationships, so the framework relies on identification and proportionate controls rather than a blanket rule.
Yes. Section 5 of FIAMLA restricts cash transactions above MUR 500,000, whether a single payment or aggregated amounts, subject to limited exemptions, and such transactions must be reported as suspicious where they occur.
Legal Disclaimer
The information provided in this article is for general informational purposes only and does not constitute legal, tax, or professional advice. While we strive to ensure the accuracy and timeliness of the content, laws and regulations are subject to change, and the application of laws can vary widely based on specific facts and circumstances.
Readers should not act upon this information without seeking professional counsel tailored to their individual situation. Expanship and its authors disclaim any liability for actions taken or not taken based on the content of this article.
For specific advice regarding your business setup, compliance requirements, or any legal matters, please consult with qualified legal and tax professionals in the relevant jurisdiction.