Mauritius
4 regulators · 4 instruments · 6 obligations · 1 upcoming deadline
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | FIU-MU | Financial Intelligence and Anti-Money Laundering Act (FIAMLA) | official | |
The laws in Mauritius are largely based on the Financial Intelligence and Anti-Money Laundering Act (FIAMLA), which requires obliged institutions to adopt a stringent and risk-based approach in detecting and preventing any form of financial crime, money laundering, terrorism financing, and proliferation financing. The obliged organizations are required to put in place internal controls; conduct obligatory customer due diligence and confirm the ultimate beneficial owner (UBO) at 25%; undertake continuous transaction monitoring, and keep compliance records for a minimum period of 7 years. There is a need to have a structure where institutions appoint an officer to act as the Compliance Officer (CO) to handle the daily compliance process, conduct business risk assessments, and arrange independent audits. On the other hand, there is a need for organizations to appoint an MLRO, who acts independently to evaluate the red flags and file suspicious transaction reports (STRs) to the FIU through the goAML system within 5 working days after detection of the anomaly. Failure to adhere to the requirements makes them susceptible to sanctions, which may include administrative sanctions of Rs 250,000 for structure violations, or criminal prosecution with penalties of Rs 10 million. |
|||||
| AML record retention | Retention period 7 years | FIU-MU | Financial Intelligence and Anti-Money Laundering Act (FIAMLA) | official | |
As per Section 17F of the Financial Intelligence and Anti-Money Laundering Act (FIAMLA) of Mauritius, it is mandatory for the reporting institutions to maintain all compliance documents for a minimum duration of 7 years. The maintenance of these documents within the defined time frame makes it necessary that CDD documentation, identification document records, and account records are retained for a minimum of 7 years from the end of the business relationship. Likewise, individual transaction records, account books, and STRs whether internal or external have to be maintained for a minimum of 7 years since the completion of the transactions or reporting of the transactions. The records must be retained in such a manner that transactions can be reconstructed instantly and FIU and supervisory authorities can easily retrieve the historical asset trails. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | FIU-MU | Financial Intelligence and Anti-Money Laundering Act (FIAMLA) | official | |
The requirements on Customer Due Diligence (CDD) and Know Your Customer (KYC) are part of regulatory framework in Mauritius as per Financial Intelligence and Anti-Money Laundering Act (FIAMLA), regulated by Bank of Mauritius (BoM) and Financial Services Commission (FSC). All clients must be identified and verified using the strict threshold of 20% in order to identify the Ultimate Beneficial Owner (UBO) in the corporate structure. The process involves the application of the risk-based approach where Simplified Due Diligence (SDD) is applied to low-risk clients, whereas Enhanced Due Diligence (EDD) is used to high-risk clients or Politically Exposed Person (PEP), including verification of his Source of Wealth and Funds. Moreover, ongoing monitoring and periodic reviews should take place, depending on the risk level, ranging from annually for high-risk clients up to every four years for low-risk clients, and keeping transactions and identification data for 5-7 years. |
|||||
| Suspicious transaction reporting | Deadline Event-based | FIU-MU | Financial Intelligence and Anti-Money Laundering Act (FIAMLA) | official | |
Suspicious Transaction Report (STR) under Mauritian law requires any suspicious activity that may be involved in money laundering, terrorist financing, and proliferation financing to be reported to the FIU using the electronic goAML system. STR is governed by the Financial Intelligence and Anti-Money Laundering Act (FIAMLA), which states that reporting entities should file an STR within a maximum period of 5 working days after determining reasonable grounds for suspicion by the Money Laundering Reporting Officer (MLRO); however, reporting within the day is highly recommended. STR is a very strict process that does not allow “tipping off” or informing the customer about reporting. The FIU can freeze funds for a maximum of 72 hours while doing analysis on transactions. Penalties for failure to report a suspicious transaction include a fine of MUR 1,000,000 and imprisonment for a term of 5 years, and in case of illegal disclosure, a fine of up to MUR 5,000,000 and a term of 10 years' imprisonment. |
|||||
| Telecom & Tech | |||||
| Lawful basis, notice and data subject rights | Ongoing | DPO | Data Protection Act 2017 | official | |
Personal data protection in Mauritius is guided by the provisions of the Data Protection Act 2017 (DPA 2017) and regulated by the Data Protection Office, and the law is consistent with international practices [fscmauritius.org]. Under this legislation, the data controller has an obligation to ensure that there is a sound legal basis for processing the personal data, which can be consent, necessity for performing the contract or legal obligation. There is an obligation to present individuals with a clear Privacy Notice containing details of the reasons for the processing, the period of time for which the data will be retained, and the transfer of the information to other parties. The rights of the individual under DPA 2017 include the right of access, rectification, erasure, objection, and restriction of automated decision making. Failure to comply with these obligations results in criminal penalties of imprisonment and fines. |
|||||
| Personal data breach notification | Deadline Event-based | DPO | Data Protection Act 2017 | official | |
The requirement for breach notification of personal data in Mauritius requires that the data controller notify the DPO of the breach without delay and, if possible, not later than 72 hours from discovering the breach. Under Section 37 of the Data Protection Act 2017, data processors shall notify the breach to their respective controllers immediately, and the controllers should notify the affected person directly if the breach involves a high risk to the rights and freedoms of the individual. The notification of the breach should detail the kind of breach, type of personal data involved, likely consequences, and measures taken to mitigate the breach. Failure to comply with breach notification requirements is considered a criminal offense and punishable by a MUR 200,000 fine and 5 years of imprisonment. |
|||||
| No obligations match these filters. | |||||