Read the last five FIU enforcement actions. Then read the last five FSC sanctions. Count how many cite "inadequate staff training" or "inability to produce training records" among the root causes. The answer is: almost all of them.
Training gaps are the single most common AML/CFT audit finding in Mauritius — because training is still perceived as low-risk, low-priority, and low-status. It is none of those things. A poorly-trained front-line employee can, in a single unchecked transaction, create more regulatory exposure than a month of governance work can undo.
Why training fails, culturally
In most firms, training is treated as a compliance task, not a compliance control. The symptoms are familiar:
- An annual in-person session that runs out of the MLRO’s calendar, not the business’s risk profile.
- The same slide deck recycled year after year, with no reference to the FCC Act 2023 or the FCC Guidelines on Legal Persons.
- An attendance sheet photographed on a phone and emailed to the compliance mailbox.
- No differentiation between roles: the HR officer sits through the same module as the relationship manager handling PEP portfolios.
- No assessment — so no evidence that anyone absorbed anything.
Every one of these is a finding waiting to be written in the next audit report.
Why training fails, legally
The legal bar is specific, and it is narrower than most policies assume. Regulation 22(1)(c) of the FIAML Regulations 2018 requires an ongoing training programme for a reporting person’s directors, officers and employees — to maintain awareness of the laws and regulations relating to money laundering and terrorism financing, to help them recognise transactions that may be linked to it, and to instruct them in the procedure to follow. That is the statutory floor, and it is one word: ongoing.
The duties to write things down sit elsewhere in the same framework. FIAMLA s.17A(1)(c) requires a record in writing of your AML/CFT policies, controls and procedures, of any changes made to them on review, and of the steps taken to communicate them internally. Regulation 27 requires internal reporting procedures to be established, documented, maintained and operated. FIAMLA s.17(4) requires the risk assessments to be documented, kept up to date and produced to a competent authority on request. The FSC Code and the BoM AML/CFT Guideline both anchor training as a specific, testable control. The FCC Guidelines on Legal Persons (2023) make it a component of the "adequate procedures" defence — meaning a legal person accused of a qualifying offence cannot rely on the defence unless it can demonstrate documented, proportionate training.
So the two failures are not the same kind of failure. Training that has not been refreshed misses the statutory requirement itself: regulation 22(1)(c) says ongoing. Training that is undocumented, or identical for every role, is not described in those words in regulation 22 — it is an inability to demonstrate a control you may well be operating, measured against a framework that requires records elsewhere and inspectors who ask for them. In practice it is the second that gets written up, because it is the one you cannot argue your way out of in the room.
The closed-loop model
Modern regulatory expectations are not a series of disconnected controls. They are a closed loop:
Audit → Train → Evidence → Re-audit
- Audit surfaces the gap — honestly, specifically, with a named finding and a target remediation date.
- Training closes the gap — role-appropriate, current, and completed by the relevant staff.
- Software documents the proof — timestamps, certificates, assessment scores, exportable register.
- The next audit verifies closure — before the regulator arrives to do it for you.
This is what "mature" compliance looks like in 2026. The controls are not separate. They are instrumented, linked, and self-evidencing.
How Audacia delivers the closed loop
Audacia was structured to deliver this model in one firm, without handoffs:
- AML/CFT audit and advisory led by Barrister-at-Law Yudish Lutchmenarraidoo, with 60+ independent AML/CFT audits across FSC licensees, banks and DNFBPs — surfacing the gaps a self-assessment would miss.
- Audacia Training, our AI-supported training platform — producing the evidence trail that closes those gaps before the regulator finds them.
- Sherlock Onboarding and Sherlock Transactions — capturing the daily evidence of compliance in the way the FIU and FSC expect to see it.
Advisory plus software, in one firm, wired into a closed loop. The audit does not just produce a report — it produces a remediation plan your training platform can execute on, and your software can evidence.
The cheapest control, the biggest exposure
Training is, dollar-for-dollar, the cheapest AML/CFT control you can deploy. A learning management system with role-specific modules costs a fraction of a single enforcement action. Yet it is the control most firms under-invest in — and the one that most reliably appears in enforcement reports.
If your audit history has highlighted training gaps, or if you simply suspect your evidence trail would not survive scrutiny, the fix is tractable. It starts with a scoping call.
Talk to us about closing the loop
A 30-minute conversation — no sales pitch — on where your training evidence sits today and what it would take to make it audit-ready.
Related
AML/CFT · Training
Building an audit-ready AML/CFT training programme
The four properties of a training programme that survives FSC and FIU inspection — scalable, role-specific, auditable and current.
Read article →AML/CFT · Audit
Is your AML/CFT framework ready for an independent audit?
What regulators actually expect from an independent AML/CFT audit, how to scope it, and the common gaps we see across Mauritius licensees.
Read article →AML/CFT · Governance
MLRO, DMLRO and Compliance Officer: roles, responsibilities and independence
The three compliance roles distinguished, the independence test regulators apply, and the board reporting standard they expect.
Read article →