Mauritius: 39 AML breaches, three penalty bands, Rs 5,000 to Rs 250,000

Section 19H(1)(d) of the Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA) gives a regulatory body a set of administrative sanctions it can apply to a member under its purview: a private warning, a public censure, a ban of up to 5 years where…

Illustration for “Mauritius: 39 AML breaches, three penalty bands, Rs 5,000 to Rs 250,000”

Section 19H(1)(d) of the Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA) gives a regulatory body a set of administrative sanctions it can apply to a member under its purview: a private warning, a public censure, a ban of up to 5 years where it licensed or authorised the member, the revocation of a licence, approval or authorisation — and, at paragraph (iii), “such administrative penalty as may be prescribed”.

The Financial Intelligence and Anti-Money Laundering (Administrative Penalties) Regulations 2025, Government Notice No. 112 of 2025, do the prescribing. The Minister made them on 18 November 2025 under sections 19H(1)(d)(iii) and 35 of FIAMLA, and they came into operation the same day. They appear in the Legal Supplement to the Government Gazette of Mauritius No. 92 of 22 November 2025.

The Regulations are short. Six regulations, then two schedules. The First Schedule lists 39 breaches and gives each one a gravity. The Second Schedule puts a price range on each gravity. Together they are a published grid, and it is worth knowing where your firm’s weak spots sit on it.

Who the grid applies to

Regulation 3 lets a regulatory body impose an administrative penalty on any member of a relevant profession or occupation falling under its purview who commits a breach listed in the First Schedule. FIAMLA’s section 19F(1) makes the same limit for the whole of Part IVB: the regulatory body’s functions and powers apply only to members of a relevant profession or occupation under its purview.

Part I of FIAMLA’s First Schedule pairs each member with its regulatory body:

Member of a relevant profession or occupationRegulatory body
Professional accountants and public accountants under the Financial Reporting Act (sole practitioners, partners or employed professionals within member firms), and member firmsMauritius Institute of Professional Accountants
Law firms, foreign law firms, joint law ventures and foreign lawyers under the Law Practitioners Act; attorneys; barristers; notariesFIU
Persons licensed to operate a casino and a gaming house A under the Gambling Regulatory Authority ActGambling Regulatory Authority
Dealers in jewellery, precious stones or precious metalsFIU
Real estate agents, including land promoters and property developers, and certain persons under the Real Estate Authority Act 2020 who carry out a real estate transactionFIU
Company service providersRegistrar of Companies

Banks and Financial Services Commission licensees are not in that table. This grid is written for the professions and occupations.

One carve-out for lawyers. Where a barrister, an attorney or a notary has failed to comply with FIAMLA or the United Nations (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act 2019, section 19H(2)(b) lets the FIU, in lieu of applying an administrative sanction, lodge a written complaint with the Complaints Commission under the Law Practitioners (Disciplinary Proceedings) Act 2025.

The three bands

The Second Schedule sets the ranges:

Gravity of breachRange of penalties (Rs)
Low5,000 – 25,000
Moderate25,001 – 100,000
High100,001 – 250,000

The First Schedule does not use the bands evenly. Of the 39 breaches, 19 are graded High and 18 Moderate to High. One is graded Moderate on its own, and only one — providing information and records within the time and at the place a regulatory body sets — is graded Low to Moderate. Read together, the two schedules put a High breach at Rs 100,001 to Rs 250,000 and a Moderate to High breach anywhere from Rs 25,001 to Rs 250,000.

What sits in the High band

The 19 High-graded breaches cluster in five places.

  • The reporting officers and the programme. Failing to appoint a Money Laundering Reporting Officer and a Deputy MLRO (regulations 26(1), (2) or (4) of the FIAML Regulations 2018); failing to establish, maintain and operate reporting and disclosure procedures (regulation 26(3)); failing to designate a compliance officer at senior management level (regulation 22(1)(a)); failing to implement an independent audit function (regulation 22(1)(d)); and failing to implement a group-wide programme (regulation 23).
  • Customer due diligence and records. Failing to undertake CDD (sections 17C and 17E of FIAMLA and regulations 3, 4, 5, 8 and 10); failing to conduct enhanced due diligence (sections 17C(3) and (4), regulations 12 and 24(3)); failing to maintain books and records (section 17F); failing to conduct ongoing monitoring (regulations 3(1)(e) and 15(1)(d)); keeping an anonymous account or an account in a fictitious name (section 17B); and dealing with a shell bank (regulation 17).
  • Suspicion and disclosure. Failing to make a suspicious transaction report in accordance with regulation 8(5); failing to comply with regulations 28 and 29 in relation to a suspicious activity, an unusual activity or an internal disclosure; failing to maintain registers of internal and external disclosure (regulation 30); and disclosing that an STR is being or has been filed, contrary to section 16 of FIAMLA.
  • Registration. Failing to register with the FIU under section 14C of FIAMLA and the Registration by Reporting Person Regulations 2019.
  • Targeted financial sanctions. Dealing with the funds or other assets of a designated or listed party (section 23 of the United Nations Sanctions Act), making funds or other assets available to one (section 24), and failing to comply with the reporting obligations under section 25.

What sits lower

The 18 Moderate to High breaches include failing to comply with a direction from the regulatory body; failing to submit a report on corrective measures; failing to provide information the regulatory body requests; failing to keep written policies, controls and procedures (section 17A); failing to identify, assess and understand ML and TF risks (section 17(1)); failing to assess the risks of new products, business practices and technologies (section 17(3) and regulation 19); failing to train directors, officers and employees (regulation 22(1)(c)); failing on beneficial ownership and identity verification (regulations 6, 7 and 9); third-party reliance (regulation 21); high-risk country measures (section 17H and regulation 24); sanctions internal controls under section 41 of the United Nations Sanctions Act; PEP measures (regulation 15); reporting procedures (regulation 27); and failing to give the regulatory body access for an on-site inspection, or full and free access to records during one.

Failing to screen employees when hiring (regulation 22(1)(b)) is the one breach graded Moderate.

Look at items 3 and 4 side by side. Failing to provide information the regulatory body requests is Moderate to High. Failing to provide it within the time and at the place determined is Low to Moderate. The grid distinguishes not answering from answering late.

How the amount is set

Regulation 4 lists the factors the regulatory body shall take into consideration:

  1. the nature, gravity and duration of the breach;
  2. any action the member took on becoming aware of it;
  3. the member’s compliance history and general conduct;
  4. recurrent breach and previous sanctions for the same breach;
  5. any disciplinary action the member took against a person who committed or contributed to the breach;
  6. any prior remedial action the regulatory body required, and the degree of compliance with it;
  7. the economic impact of the penalty on the member; and
  8. any other relevant factor the regulatory body deems appropriate.

Regulation 5 then requires it to impose the appropriate amount in accordance with the Second Schedule.

FIAMLA supplies the procedure. Under section 19N(2), a regulatory body that intends to impose an administrative sanction must first issue a notice stating its intention, the type and terms of the sanction, and the member’s right to make written representations within 21 days. A member aggrieved by the decision may apply to the Review Panel within 21 days (section 19S(1)), and the decision is given effect immediately after 21 days from the date of the decision unless the Review Panel suspends it (section 19S(3) and (4)). A penalty is a debt due to the regulatory body, recoverable as a civil debt, and is credited to the Consolidated Fund (section 19N(5) and (6)). Section 19H(4) lets the regulatory body publish its decision.

The grid is not the only exposure

Some breaches on the grid are also criminal offences in FIAMLA itself. Failing to comply with a direction under section 19H(1)(b) or (c) carries, on conviction, a fine not exceeding one million rupees and imprisonment up to 5 years (section 19H(3)). Section 19J(2) requires a member to comply with a request for information immediately, and section 19J(4) makes failure an offence carrying a fine not exceeding one million rupees and imprisonment up to 2 years. Where a direction sets a compliance period, section 19M(1) makes each day of non-compliance after it a separate offence, with a fine of 5,000 rupees per day.

Three things worth doing

  1. Map your controls to the 39 rows. The First Schedule is effectively a supervisor’s checklist, with the gravity already filled in. Know which of your gaps land on a High row, and fix those first.
  2. Treat a regulator’s information request as a deadline. FIAMLA says “immediately”, and the grid prices a late answer separately from no answer. Log every request, the time and place set, and the date you responded.
  3. Keep the file that regulation 4 will read. Five of the eight factors turn on what you did: your action on becoming aware of the breach, your compliance history, repeat breaches, your internal discipline and your follow-through on remediation. Record them as you go, not after the notice arrives.

SonarPulse in this jurisdiction: AML/CFT screening software for Mauritius


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu