HomeAdvisoryAML/CFT Audit

Independent AML/CFT audit for Mauritius regulated entities

FIAMLA, the FSC Code on the Prevention of Money Laundering and Terrorist Financing, the Bank of Mauritius AML/CFT Guideline and FIU sector-specific guidance all require independent testing of your AML/CFT framework. We deliver that audit — from scoping through to a board-ready findings report and a practical remediation plan.

Yudish Lutchmenarraidoo, the founding partner of Audacia and a Barrister-at-Law, has personally led 60+ independent AML/CFT audits across FSC licensees, management companies, banks and DNFBPs.

What the audit covers

  • Governance & senior management oversight — board reporting, MLRO independence, escalation paths.
  • AML/CFT risk assessment — methodology, customer/product/geography/channel coverage, refresh cadence.
  • Customer Due Diligence — standard, simplified and Enhanced Due Diligence procedures, with sample file testing.
  • Sanctions screening — UN, EU, OFAC list coverage, screening at onboarding and ongoing.
  • Transaction monitoring — rules, thresholds, alert investigation, false positive rate.
  • Suspicious transaction reporting — internal escalation, FIU filing process, record retention.
  • Record keeping — CDD documentation, transaction history, retention periods.
  • Staff training — coverage, refresher cadence, evidence of completion.
  • MLRO function — resources, independence, reporting lines.

How we work

1

Scoping (1 week)

We agree the scope, identify your regulator(s), build the audit plan and request the document set.

2

Document review (1–2 weeks)

Policies, procedures, the AML/CFT manual, board minutes, training records.

3

Sample testing (1–2 weeks)

Customer files, EDD cases, STRs, sanctions hits, training completion.

4

MLRO & senior management interviews

Where the design meets the practice.

5

Findings report

Board-ready, with a prioritised remediation plan and timelines.

6

Follow-up support

Optional — we can support remediation and re-test after closure.

Frequently asked questions

Why do I need an independent AML/CFT audit?
FIAMLA, the FSC Code and the Bank of Mauritius AML/CFT Guideline require regulated entities to periodically test the effectiveness of their AML/CFT framework through independent review. The audit provides assurance to the board, evidence to regulators on inspection, and a structured improvement plan.
How often should we audit?
Most FSC licensees and Bank of Mauritius-supervised institutions audit annually. Lower-risk DNFBPs may audit biennially. Frequency should be proportionate to your risk profile — higher-risk firms with large transaction volumes, PEP exposure or high-risk geographies need more frequent reviews.
What does the audit cover?
Governance and senior management oversight; risk assessment methodology; CDD/EDD procedures and sample testing; sanctions screening; transaction monitoring; STR filing process; record-keeping; staff training; and the MLRO function. We test the framework as designed and as actually applied.
Who carries out the audit?
Yudish Lutchmenarraidoo, the founding partner, leads every audit. He has personally completed 60+ independent AML/CFT audits across FSC licensees, banks and DNFBPs in Mauritius and is a Barrister-at-Law.

Related

Ready to scope your audit?

A 30-minute call to understand your business, your regulator and your timing.