AML/CFT screening software for Mauritius

SonarPulse is an AML/CFT screening, risk-scoring and monitoring platform for Mauritius reporting persons, hosted inside Mauritius so customer data never leaves the jurisdiction. The digital risk-scoring engine at its core was developed through collaborative engagement with the Financial Services Commission and the Mauritius Research and Innovation Council.

What Mauritius asks of your screening programme

  • Two mandatory sanctions lists. The Bank of Mauritius guidance of August 2026 makes both the UN Security Council Consolidated List and the National Sanctions Secretariat’s List of Designated Parties mandatory. The second is published on the NSS website and is not carried by the international watchlist feeds. Read the briefing.
  • 24 hours, on every change. As amended by Act No. 3 of 2026, the United Nations (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act 2019 applies its duties forthwith and not later than 24 hours after the UN list or the Secretariat’s public notice, and asks for a report whether or not funds are identified. UN sanctions across the six.
  • Suspicious transaction reports. Section 14(1) of FIAMLA requires a report to the FIU promptly but not later than 5 working days after the suspicion arose, filed through goAML. When the STR clock starts.
  • The 2026 reform. Act No. 3 of 2026, in force since 18 April 2026, lets the FIU order a suspicious transaction suspended for up to 72 hours, with information due within 24 hours of a request. What Act No. 3 of 2026 changed.

How SonarPulse covers it

  • Both mandatory lists, including the NSS designated parties with the gazetted aliases and the passport, NID and date-of-birth identifiers the notice carries.
  • Screening on change, not on a schedule. The mandatory lists are polled hourly; a detected change screens your whole book within minutes and timestamps it, so “within 24 hours” is evidenced rather than asserted.
  • Reports started for you. Where a match is found, the section 25(2) return is generated in the Bank’s own template, pre-filled from the screening. STR and SAR drafting sit alongside it, and TMX generates goAML filings under four-eyes control.
  • Wider coverage. OFAC, EU, UK, World Bank, Interpol and 250+ further sanction, PEP and watchlist sources, a localised in-country PEP database at levels 1 to 3, adverse media, and legal and enforcement records including the Supreme Court of Mauritius.
  • Risk scoring you can explain. A per-tenant rules engine with versioning and rollback, and a transparent low, medium or high rating for every customer.
  • An audit trail built for inspection. Every screening, every alert, who reviewed it, what they concluded and why.

Questions Mauritius compliance teams ask

Is screening against a global watchlist provider enough?

Not on its own. The National Sanctions Secretariat’s List of Designated Parties is published as a document on the NSS website and is not carried by the international watchlist feeds, so an institution screening solely against a global provider may not be screening it at all.

How long do we have to file an STR?

FIAMLA section 14(1) says promptly but not later than 5 working days after the suspicion arose. The FIU’s FAQs add that the five days exclude Saturdays, Sundays and public holidays and run from the time the suspicion is formed.

Where is our customer data held?

Inside Mauritius. Screening, scoring, monitoring and reporting run as an in-country cloud service, with a private data centre or on-premises deployment where that is mandated.

Further reading

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu