HomeAdvisory

Our services

Advisory in AML/CFT, Intellectual Property and Data Protection — backed by software when the work is repeatable, and by a Barrister-at-Law when it isn't.

AML/CFT

End-to-end AML/CFT compliance support — from policies and procedures to independent audit and ongoing staff training.

  • Drafting of AML/CFT policies and procedures manual
  • Customer Risk Assessment
  • Advice on Enhanced Due Diligence measures
  • Independent Audit of AML/CFT Framework
  • AML/CFT Training

Intellectual Property

Full-spectrum IP advisory — from registration and protection to enforcement and dispute resolution.

  • Combating of piracy and counterfeiting
  • Copyright
  • Protection of intellectual property rights
  • Registration of industrial designs, patents and trademarks
  • Resolution of intellectual property disputes

Data Protection

Practical Data Protection support aligned with Mauritius' Data Protection Act 2017 and international best practice.

  • Drafting of Data Protection policies and procedures
  • Audit of Data Protection framework
  • Advice on data subject rights and breach response
  • Data Protection training for staff and officers

Our digital solutions

Purpose-built software to help regulated businesses meet their AML/CFT, data-protection and estate-management obligations with confidence.

Sherlock

Sanctions, PEP and adverse-media screening with a customer risk assessment engine — built for regulated entities and DNFBPs in Mauritius.

Sherlock Transactions

Real-time, AI-assisted transaction screening — particularly suited to real estate and notaries, with a full MLRO-reviewed audit trail.

Sherlock Compliance

The full MLRO workbench — onboarding, screening, monitoring, STR workflow and regulator packs, all in one platform.

Sherlock Privacy

A living Data Protection Act 2017 processing register — free 30-day trial, no card required.

Syndic

Estate and copropriété management, built on the Code Civil Mauricien's statutory obligation register.

Audacia Training

Interactive AML/CFT and Data Protection training — structured courses, quizzes and certificates of completion.

Frequently asked questions

Common questions on AML/CFT, Data Protection and compliance obligations in Mauritius.

What is AML/CFT compliance in Mauritius?
AML/CFT (Anti-Money Laundering / Counter-Terrorism Financing) compliance in Mauritius is governed primarily by the Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA) and the FIAML Regulations 2018. Regulated entities — banks, FSC licensees, and designated non-financial businesses and professions (DNFBPs) — must identify customers, assess their risk, monitor transactions, report suspicious activity, and keep records. Supervision is shared between the Bank of Mauritius, the Financial Services Commission (FSC) and the Financial Intelligence Unit (FIU) depending on sector.
Who needs an AML/CFT audit in Mauritius?
Every regulated reporting person must periodically review the effectiveness of their AML/CFT framework. Most FSC licensees and Bank of Mauritius-supervised institutions require an independent audit at defined intervals, usually annually or biennially depending on risk profile. DNFBPs — including real estate agents, jewellers, accountants, tax advisors and law practitioners — are also expected to have their framework independently reviewed, proportionate to their size and risk.
What does a Money Laundering Reporting Officer (MLRO) do?
The MLRO is the central AML/CFT contact in a reporting entity: receiving internal suspicious transaction reports, analysing them, filing Suspicious Transaction Reports (STRs) with the FIU, maintaining the AML/CFT programme, providing staff training, and acting as the primary liaison with regulators. The MLRO must be independent, suitably qualified, and have direct access to senior management and the board.
What is the Financial Crimes Commission Act 2023?
The Financial Crimes Commission Act 2023 (effective 29 March 2024) established a single agency, the FCC, consolidating functions previously split between ICAC, the Asset Recovery Investigation Division and other bodies. It repealed the Prevention of Corruption Act 2002 and the Asset Recovery Act 2011, and section 52 requires every legal person to have "adequate procedures" to prevent financial crime on its behalf, as set out in the FCC Guidelines on Legal Persons.
Do I need a Data Protection Officer in Mauritius?
Under the Data Protection Act 2017, every controller and processor established in Mauritius must register with the Data Protection Office and identify a person responsible for compliance with the Act. Organisations carrying out regular and systematic monitoring of data subjects at scale, or processing sensitive data at scale, are strongly advised to appoint a dedicated Data Protection Officer.
What services are FSC-regulated?
The Financial Services Commission (FSC) is the integrated regulator for non-banking financial services in Mauritius, covering management companies, investment advisers, investment dealers, CIS and CIS managers, insurance, pensions, capital markets intermediaries, credit finance, fintech and virtual asset service providers under the VAITOS Act 2021. All FSC licensees are subject to FIAMLA, the FIAML Regulations 2018 and the FSC Code on the Prevention of Money Laundering and Terrorist Financing.
What is Enhanced Due Diligence (EDD) and when does it apply?
EDD is a heightened level of customer due diligence required when the money laundering or terrorism financing risk is higher than standard — triggered by Politically Exposed Persons, customers from high-risk third countries, complex or unusually large transactions, relationships with no apparent economic purpose, and certain higher-risk sectors. It typically involves senior management approval, additional source-of-funds and source-of-wealth information, and more frequent ongoing monitoring.
How can compliance software help my business?
Software like our Sherlock products automates the parts of compliance that are high-volume, rule-based and error-prone: sanctions screening, transaction monitoring, KYC onboarding, risk scoring and ongoing due diligence. It reduces manual review workload, improves consistency, shortens onboarding times, and produces the structured audit trail a regulator expects. Human judgement stays essential for final decisions — the software handles the heavy lifting so your team can focus on the edge cases.

Not sure where to start?

Tell us your sector and your regulator, and we'll tell you where the risk actually is.