HomeInsightsAudit-ready training programme

AML/CFT · Training

Building an audit-ready AML/CFT training programme

The four properties of a training programme that survives FSC and FIU inspection — scalable, role-specific, auditable and current.

Published 22 April 2026 · 8 min read

Staff training is the cheapest AML/CFT control you will ever deploy — and the most often neglected. When the FIU or FSC arrives on inspection, one of the first documents they request is your training register. Not the policy. Not the risk assessment. The register — because it is the fastest way to tell whether compliance is lived, or performative.

This article sets out what the law actually requires, what inspectors look for, and how to design a training programme that survives scrutiny — not just on paper, but in the detail.

What the law requires

Three instruments set the floor for AML/CFT staff training in Mauritius:

  • FIAMLA — the parent Act, under which the Regulations below are made. It requires each reporting person to establish, review and keep a record in writing of its AML/CFT policies, controls and procedures, including the steps taken to communicate them internally (s.17A(1)(c)), and to document its risk assessments and keep them up to date (s.17(4)).
  • Regulation 22(1)(c) of the FIAML Regulations 2018 — the explicit training obligation: an ongoing training programme for directors, officers and employees, to maintain awareness of the AML/CFT laws, to help them recognise transactions that may be linked to money laundering or terrorism financing, and to instruct them in the procedure to follow. Note what it does not say. "Role-appropriate" and "documented" are not words in regulation 22 — they are supervisory expectations, and the practical means of proving a control, which is why the rest of this article treats them as design requirements rather than as quotations from the Regulations.
  • FSC Code on the Prevention of Money Laundering and the BoM AML/CFT Guideline — each require ongoing, evidence-based training proportionate to the risks faced by the institution.

The FCC Guidelines on Legal Persons (2023) reinforce this with the "adequate procedures" standard: if an employee commits a qualifying offence on behalf of the legal person, the organisation can only defend itself if it can show — among other things — that relevant staff were trained, in a way that was proportionate to the risk, recent, and documented.

The four properties of a defensible training programme

1. Scalable

Whether you have 20 staff, 200 or 2,000, the training programme cannot depend on the MLRO's personal calendar. In-person sessions have their place — typically for senior management, high-risk roles, and for deep-dive scenarios — but the bulk of delivery should be through a platform that can enrol, track and certify at scale without creating a bottleneck.

2. Role-specific

A relationship manager, a notary’s clerk, an onboarding agent at a fintech, and a back-office accountant do not face the same risks and do not need the same modules. A generic "AML 101" assigned identically to everyone is not "role-appropriate" — it is a paper exercise. Inspectors will ask: "Show me a tailored module for your high-risk roles." If you cannot, you have a finding.

3. Auditable

Every completion must be timestamped. Every assessment score must be retained. Every certificate must be retrievable on demand. This is not a nice-to-have: when the inspector asks for evidence that Ms X, who approved a borderline transaction on 14 March, had completed refresher training, you must be able to produce it in minutes, not days.

4. Current

Training content must reflect current law. The FCC Act 2023 repealed POCA 2002 and the Asset Recovery Act 2011. The FCC Guidelines on Legal Persons (2023) introduced the adequate-procedures standard. Typology guidance has shifted to reflect virtual assets, crypto-to-fiat rails, and jurisdictional risk changes. Training written in 2021 is, in material respects, wrong.

The minimum module set

A credible AML/CFT curriculum in Mauritius should cover, at minimum:

  • AML/CFT fundamentals — the ML/TF cycle, typologies, risk-based approach.
  • CDD & EDD — triggers, evidence standards, beneficial ownership.
  • Sanctions screening — UN, EU, OFAC, targeted financial sanctions.
  • PEPs, high-risk countries, and the EU third-country list.
  • STR recognition and internal reporting flow.
  • Sector-specific modules (banking, real estate, notaries, accountants, lawyers, VASPs).
  • Data Protection Act 2017 basics for client-data handlers.
  • Role-specific refresher, at least annually.

What inspectors actually test

A training policy is not the same as a training programme. Inspectors routinely test:

  • Completeness: is the register comprehensive, or are there names missing?
  • Recency: when was the last refresher for each staff member?
  • Differentiation: does a high-risk role have a different completion record than a low-risk role?
  • Evidence: can you produce the actual certificate, not just a line in a spreadsheet?
  • Content currency: does the module reference current law, or is it citing repealed statutes?
  • Assessment: is there a quiz or test? What is the pass mark? Are retakes recorded?

Audacia Training: built for Mauritius regulated firms

Audacia Training is our AI-supported training platform designed specifically for the Mauritius regulatory environment. It delivers on all four properties above out of the box:

  • Modules tailored by sector — banking, FSC licensees, real estate, notaries, accountants, lawyers, jewellers, fintechs, VASPs.
  • Each completion generates a downloadable Certificate of Completion.
  • MLRO dashboard with completion rates, overdue-refresher alerts, and exportable training register.
  • Content maintained by our advisory team — updated within weeks of any regulatory change.
  • Role-specific pathways: the relationship manager does not sit through the same content as the HR administrator.

The result is a training programme that produces, by default, exactly the evidence an inspector asks for — with no scrambling, no spreadsheet archaeology, and no last-minute booking of an in-person session.

See Audacia Training in action

Book a 30-minute walkthrough. We’ll show you the MLRO dashboard, the sector modules, and the certificate audit trail.