Two mandatory lists: the Bank of Mauritius sanctions guidance, and what it asks of you
The Bank of Mauritius's guidance page Implementation of Targeted Sanctions, dated August 2026, sets out the obligations of financial institutions under the United Nations (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act 2019. It is specific…
The Bank of Mauritius’s guidance page Implementation of Targeted Sanctions, dated August 2026, sets out the obligations of financial institutions under the United Nations (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act 2019. It is specific about how, not just what.
Two lists, from two publishers
The guidance requires financial institutions to consult two lists regularly:
- the United Nations Security Council Consolidated List, taking immediate action on any change to it;
- the National Sanctions Secretariat’s list of designated parties, published on the Secretariat’s own website, together with any notice the Secretariat issues, and to act on them immediately.
The Sanctions Act defines “immediately” as without delay and not later than 24 hours.
The designated-parties list is a document on the NSS website. At the time of writing, the list published there is headed “as at 06 June 2025”. For each party it carries aliases (A.K.A.), date of birth, passport number and NID, as well as name and address.
Because this list comes from the NSS rather than the UN, do not assume it is in your screening data. Ask your provider whether its feed includes the NSS list, and how quickly a change to it reaches you.
When to screen, and against whom
- All clients and transactions. The Bank expects internal controls to include screening all clients and transactions against sanctions lists, with a system suited to the nature, size and risk of the business.
- At onboarding and on triggers. Screening should also take place when a new relationship is established, at regular intervals, or on trigger events such as a change in directors or ownership.
- On every change to either list. Additions, extensions, removals, exemptions and any other amendments all count.
- Within 24 hours. Screening must be done without delay (within 24 hours), so that reporting can be made within 24 hours after the Security Council publishes a list or a change to it, or after the NSS gives public notice of a declaration of a designated party. Use the most up-to-date lists.
Note where the clock starts: at publication by the Security Council, or at the NSS’s public notice.
What to report, and to whom
- Positive match, whether or not funds or other assets are found: report it immediately to both the NSS and the Bank, on the Template for Reporting Positive Name Match under section 25(2) of the Act.
- Negative match: on the Bank’s instruction, report it immediately to the Bank, on the same section 25(2) template. Only positive name matches, including nil returns on positive name matches, go to the NSS.
- Information about a listed or designated party that you know of goes to the FIU immediately, under section 14 of the Financial Intelligence and Anti-Money Laundering Act.
The section 25(2) template was issued by the National Sanctions Secretariat. It can be found on the NSS website and on the Bank’s. The Bank monitors both positive and negative match reporting, to ensure that screening is carried out after changes to the lists are disseminated.
Records you must be able to produce
Screening records and evidence of screening must be properly documented. Keep records of every screening, every report to the NSS and the Bank, and every action taken on the results, and make them available to the Bank on request. You also need clear policies and procedures to investigate and escalate alerts raised by a potential match.
The Bank supervises and enforces its licensees’ compliance under section 40(2) of the Sanctions Act. Failing to comply with the Act, or with the Bank’s guidelines and instructions on it, is an offence and may lead to regulatory sanctions, including monetary penalties.
> A 24-hour obligation is not a reporting deadline you meet at the end. It is a control you have to be > able to show working.
How SonarPulse maps to it
This section describes SonarPulse’s own products.
SonarPulse is a financial-crime compliance platform hosted inside Mauritius, so customer data never leaves the jurisdiction. Against this guidance specifically:
- Both mandatory lists, including the NSS designated parties with the aliases, dates of birth, passport numbers and NIDs the list carries.
- Screening on change, not on a schedule. The mandatory lists are polled hourly; a detected change screens your whole book within minutes and timestamps it, so “within 24 hours” is evidenced rather than asserted.
- Every client by default, with exceptions you set deliberately, and a visible count of anyone outside the net.
- An audit trail built for inspection: every screening, every alert, who reviewed it, what they concluded and why.
- Wider coverage when you need it: OFAC, EU, UK, World Bank and 250+ further sources available on demand. These go beyond the two lists this guidance names.
- Reports started for you. Where a match is found, we generate the section 25(2) return on the NSS template, pre-filled with everything the screening produced, so your MLRO completes it rather than starting from a blank page. Negative returns to the Bank we can complete in full.
Transaction screening, which the guidance also covers, is handled by TMX, our on-premises companion in the payment perimeter. We are happy to scope either or both.
We would suggest a 45-minute session in which we screen a sample of your own customer book against both mandatory lists and show you, name by name, what a 24-hour cycle and its audit trail look like. No obligation, and you keep the output.
Sources
This article draws on the following sources. Follow the links for the original text.