HomeInsightsAML/CFT audit readiness

AML/CFT · Audit

Is your AML/CFT framework ready for an independent audit?

What regulators actually expect from an independent AML/CFT audit, how to scope it, and the common gaps we see across Mauritius licensees.

Published 22 April 2026 · 7 min read

Independent testing of your AML/CFT framework is no longer a "nice-to-have". Under FIAMLA, the FSC Code on the Prevention of Money Laundering, and the Bank of Mauritius AML/CFT Guideline, it is a direct regulatory expectation. Yet many Mauritius firms still treat the audit as a paperwork exercise — and discover, mid-inspection, that compliant on paper is not the same as effective in practice.

This article sets out what a credible AML/CFT audit looks like in 2026, the findings we see most often across Mauritius regulated entities, and how to turn the audit from a box-ticking cost into a genuine piece of compliance infrastructure.

Why the audit matters more than ever

Three trends have raised the stakes since the 2018 ESAAMLG mutual evaluation:

  • Enforcement is visible. The FIU and FSC now publish sanctions, fines and licence conditions with increasing frequency. The deterrent effect is no longer hypothetical.
  • The FCC Act 2023 raised the floor. The Financial Crimes Commission's Guidelines on Legal Persons set an explicit "adequate procedures" standard that every legal person must meet — and that standard is now cited in audit findings.
  • The regulator’s lens is operational. Inspectors no longer accept a well-drafted policy as evidence of compliance. They test whether the framework is actually applied to real client files, real transactions, real STRs.

An independent AML/CFT audit — done properly — is the single fastest way to see your framework through the regulator’s lens before the regulator arrives.

What a credible audit actually covers

A real AML/CFT audit goes far beyond ticking policies off a checklist. At minimum, it should systematically assess:

1. Governance and MLRO oversight

Is the MLRO functionally independent? Does the MLRO have direct reporting access to the board? Is the board actually receiving meaningful compliance reporting — with metrics, trends and unresolved issues — or is it a one-page summary nobody reads? We routinely see MLRO roles that exist on paper but are combined with operational functions in a way that fatally compromises independence.

2. Risk assessment methodology

Does the Business-Wide Risk Assessment (BWRA) reflect your actual client base, products and geographies? Or is it a template borrowed from 2019 that has never been refreshed? A credible BWRA is datable: it cites the date of the latest client book review, the last geographical risk update, and the last product risk scoring. If any of those is older than 12 months, you have an audit finding waiting to happen.

3. CDD, EDD and sanctions screening

We test real client files, not summaries. Gaps in beneficial ownership evidence and missed EDD triggers are the single most common audit finding we report in 2025 — typically in the management-company, real-estate and corporate-services segments. Sanctions screening must be evidenced per client and per transaction, not just "done at onboarding".

4. Transaction monitoring and STR process

Are alerts documented, escalated, and closed with reasoning that would survive FIU scrutiny? Is the decision not to file an STR as well-documented as the decision to file one? A clean STR register is not necessarily a good sign — it may mean alerts are being dismissed without analysis.

5. Training and records

Can you produce, on demand, proof that every relevant staff member completed training in the last 12 months? Can you show role-appropriate differentiation between, say, a relationship manager and a back-office administrator? If the answer is "let me dig through emails", the training control has failed.

The five findings we see most often

  1. BWRA older than 18 months and not reflecting current client book.
  2. Beneficial ownership evidenced only by declaration, without corroboration.
  3. EDD applied selectively, without a clear rules-based trigger.
  4. Transaction monitoring alerts closed without documented rationale.
  5. Training register incomplete or untracked for operational staff.

How often should you audit?

Most FSC licensees and BoM-supervised institutions should audit annually. Lower-risk DNFBPs may audit biennially, but only if the risk profile genuinely supports it — and that judgement itself should be documented. Higher-risk firms (large transaction volumes, significant PEP exposure, high-risk geographies, complex ownership structures) should consider a thematic mid-cycle review in addition to the annual audit.

Frequency is not just a matter of ticking the box. A framework tested once a year, then left untouched, drifts. Clients change. Regulations change. Staff turn over. An audit 14 months ago is already out of date in several dimensions.

Turning the audit into a defensible record

The audit output is not just a report — it is a roadmap your board, your regulator and your MLRO can actually use. A well-structured AML/CFT audit should leave you with:

  • A clear findings register with ratings, root causes and target remediation dates.
  • An evidence pack that maps each tested control to the underlying regulation (FIAMLA section, FSC Code paragraph, BoM Guideline reference).
  • A management response signed by the MLRO and the board, with accountable owners for each action.
  • A follow-up plan that converts findings into closed-loop remediation — not a PDF that sits in a drawer.

Done this way, the audit becomes the spine of your compliance file. When the FSC or FIU arrives on inspection, you do not hand them a policy. You hand them the audit, the remediation register, and the evidence of closure. That is what "defensible" looks like.

Why Audacia

Audacia’s AML/CFT audits are led by Barrister-at-Law Yudish Lutchmenarraidoo, with 60+ independent AML/CFT audits delivered in Mauritius across FSC licensees, banks and DNFBPs. Our approach combines legal depth — reading the regulations as they are actually enforced — with the operational pragmatism to write findings a business can act on.

Ready to scope your next AML/CFT audit?

Book a 30-minute scoping call. No sales pitch — we’ll assess your risk profile, the regulatory perimeter that applies, and the realistic audit scope for your firm.