EST · MMXXVI
Home/Jurisdictions/Mauritius/AML/cft policy drafting in Mauritius: Legal Requirements for Businesses
Compliance, AML & Travel Rule

AML/cft policy drafting in Mauritius: Legal Requirements for Businesses

Aml/cft policy drafting in Mauritius. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a virtual asset business in Mauritius without a documented, regulator-ready AML/CFT policy (anti-money laundering and countering the financing of terrorism program) is one of the fastest routes to a suspended licence, frozen banking rails, and correspondent-bank exits. The Financial Intelligence and Anti-Money Laundering Act and the VAITOS Act 2021 together impose specific written-program obligations on every VASP (virtual asset service provider) licensed or operating in the jurisdiction. Getting those documents right – and keeping them current as the Financial Services Commission (FSC) tightens its supervisory posture – is the baseline requirement for any business serious about the Mauritius market.

This page sets out the legal basis for AML/CFT program requirements in Mauritius, the practical steps to draft a compliant policy, the cross-border pressures that shape what the documents must cover, and the decision point at which external counsel adds most value. One anonymized matter illustrates how the process plays out in practice.

The Regulatory Basis for AML/CFT in Mauritius

Mauritius imposes AML/CFT obligations on VASPs through a layered regime. At the statutory level, the Financial Intelligence and Anti-Money Laundering Act establishes the core obligations – customer due diligence, record-keeping, suspicious-transaction reporting, and internal-controls requirements – that apply across financial services. The VAITOS Act 2021 brings virtual asset activities squarely within that regime and adds sector-specific conditions. The Financial Intelligence Unit (FIU) receives suspicious-transaction reports and coordinates with law enforcement. The FSC supervises licensed VASPs and has authority to inspect, require remediation, and revoke.

For an inbound business, the starting question is not whether AML/CFT applies – it does, from the date of licensing – but whether the written program already in place for another jurisdiction satisfies the FSC's local expectations. In our cross-border practice, the answer is rarely straightforward: the Mauritius regime follows FATF Recommendation 15 on virtual assets, but the FSC's supervisory guidance layers local specifics on top of the FATF baseline. A policy drafted for an EU CASP (crypto-asset service provider) authorisation under MiCA, or for a Singapore Payment Services Act licence, will typically need material amendments before it meets the FSC's expectations.

What a Compliant AML/CFT Policy Must Contain

A compliant policy for a Mauritius-licensed VASP is not a single document but a set of interrelated policies, procedures, and controls that together demonstrate to the FSC that the business understands its risk exposure and has operational measures to manage it.

The core written program must address: a documented business-risk assessment covering the products offered, the customer base, the geographies served, and the delivery channels used; a KYC framework (know-your-customer framework) governing customer identification, verification, and ongoing monitoring at the individual and corporate-account level; enhanced due diligence triggers for higher-risk categories; transaction monitoring rules and escalation procedures; suspicious-transaction reporting protocols to the FIU; record-retention schedules aligned to the statutory minimums; training obligations for staff with customer-facing or compliance roles; and a governance map identifying the MLRO (money laundering reporting officer) and the compliance function's reporting line to the board.

Operators we advise routinely underestimate two elements. First, the risk assessment must be product-specific, not generic: a business offering custody and exchange services faces a materially different risk profile than one offering only advisory services, and the FSC expects that distinction to be visible in the document. Second, the policy must address the Travel Rule – the obligation, derived from FATF and incorporated into Mauritius VASP supervision, to pass originator and beneficiary data with transfers above the applicable threshold. Where the business uses a technology solution to comply with the Travel Rule, the policy must name the solution and its data-handling logic, and it must address what happens when a counterparty VASP does not respond or is unverified.

How Does the FATF Travel Rule Apply to a Mauritius VASP?

The Travel Rule requires a VASP to collect, verify, and transmit specified originator and beneficiary information alongside every qualifying virtual-asset transfer. In Mauritius, the FSC expects licensed VASPs to operationalize the Travel Rule as part of their AML/CFT program, consistent with FATF Recommendation 16 as it applies to virtual assets.

In practice, compliance requires three layers. First, the written policy must define the scope – which transfers fall within the rule, what data must be collected from the originator and verified before transmission, and how the business handles inbound transfers where the originator data is incomplete. Second, the technology layer must actually capture and transmit the data: this typically means integration with a VASP-to-VASP Travel Rule messaging protocol, and the FSC will ask about it during onboarding and supervision. Third, the risk-based procedure for "unhosted wallets" – transfers to or from private, self-custodied addresses – must be documented, because the FSC, following the FATF model, expects enhanced scrutiny of those flows.

The cross-border dimension matters here. A Mauritius VASP sending transfers to counterparties in Singapore (supervised by MAS), in the EU (where ESMA and national competent authorities enforce the MiCA Travel Rule standard), or in the UAE (where VARA applies its own rulebook) will face different data expectations at each end of the wire. The Mauritius policy must be drafted with that multi-jurisdiction reality in mind – a policy built only to the local standard may cause the business to fail a receiving regulator's compliance check.

For a scoped review of your Travel Rule program and cross-border data obligations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your specific product mix, user geography, and banking stack will change the analysis.

Who Must Serve as MLRO, and What Does That Role Require?

Under the Mauritius VASP regime, every licensed entity must designate a nominated officer – effectively an MLRO – who holds personal responsibility for the AML/CFT function, for suspicious-transaction reporting to the FIU, and for the program's ongoing adequacy. The FSC will assess the MLRO's suitability as part of the licensing process and may revisit that assessment at supervision.

In our practice, the MLRO question is often the most operationally difficult for smaller VASPs and for foreign businesses establishing a Mauritius presence. The regulator expects the MLRO to be reachable, sufficiently senior, and genuinely empowered to escalate concerns to the board. A nominal appointment – a name on a form, with the actual compliance work happening offshore – is unlikely to satisfy the FSC, and it exposes the named individual to personal regulatory risk.

For businesses that do not yet have a suitable local officer, the options are: hire for the role before licensing; appoint a suitably qualified service provider on an interim basis while the permanent hire is identified; or, in certain circumstances, seek FSC agreement to a modified arrangement. Each path has different timeline and cost implications. The important point is that the MLRO structure must be determined before the application is filed, because it forms part of the governance documentation the FSC reviews.

The Drafting Process: Step by Step

A well-structured AML/CFT policy drafting engagement for a Mauritius VASP typically moves through five stages, each of which produces a document or decision that feeds the next.

The first stage is the business and risk scoping call: counsel and the client map the products, customer segments, geographies, and distribution channels. This is not a legal nicety – the FSC expects the risk assessment to reflect the actual business, and a mismatch between the policy and the operating model is a common finding in supervisory reviews. The second stage is the risk assessment itself: a written document classifying the business's inherent risk across money-laundering and terrorism-financing vectors, identifying the controls already in place, and concluding on residual risk. The FSC and the FIU may both request this document.

The third stage drafts the core policy suite – customer due diligence procedures, the transaction monitoring framework, the suspicious-transaction reporting protocol, the Travel Rule procedure, the record-retention schedule, and the training matrix. The fourth stage addresses governance: the MLRO mandate, the board-reporting template, and the internal-audit or compliance-review schedule. The fifth stage is a table-top review of the draft against the FSC's current supervisory expectations, incorporating any specific conditions attached to the licence or raised during the application process. We have seen conditions attached at licensing that require bespoke procedural additions not captured in a standard template – catching those early saves remediation cost later.

Why AML Policy Quality Affects Banking Access

Banking access for Mauritius VASPs is tightly correlated with the quality of the AML/CFT program – and this is where the cross-border reality bites hardest. A domestic bank in Mauritius, and any correspondent bank in a major financial centre, will conduct its own due-diligence review of a VASP customer before opening or maintaining an account. That review typically includes a request for the written AML/CFT policy, the latest risk assessment, and evidence of regulatory standing with the FSC.

A policy that is thin, generic, or out of date signals to the bank's compliance team that the business has not internalized the regulatory expectations. In our cross-border practice, we regularly advise businesses that lost a banking relationship not because of an FSC enforcement action, but because the bank's correspondent in New York, London, or Frankfurt applied its own AML standards and found the Mauritius VASP's documentation inadequate. The loss of a correspondent banking relationship is a material business risk – in some cases an existential one – and the AML/CFT policy is the document most likely to be reviewed at that decision point.

This is also where the VAITOS Act 2021 framework interacts with the broader international AML architecture. Mauritius is on the FATF monitoring list from time to time; the status of the jurisdiction at any given moment is relevant to the risk-appetite decisions of correspondent banks and to the enhanced-due-diligence obligations that MiCA-regulated, FCA-registered, or MAS-licensed counterparties may apply when transacting with a Mauritius-domiciled entity.

If a prior banking application stalled or an account was closed, a structural review of the AML documentation can often surface the gap. Write to info@oboluslaw.com to discuss your situation.

Common Mistakes in Mauritius AML/CFT Policy Drafting

A common assumption among inbound operators is that a well-drafted policy from another FATF-member jurisdiction transfers directly to Mauritius with minimal editing. It does not. The FSC applies local guidance that goes beyond the FATF baseline, and a policy that has passed muster in, say, a BVI FSC registration or a Cayman CIMA review will typically need substantive reworking to meet FSC expectations.

Beyond the portability error, the most frequent drafting mistakes we encounter are: using generic risk-appetite language that does not reflect the specific products offered; omitting a defined escalation path from transaction-monitoring alerts to the MLRO and from the MLRO to the board; failing to address how the business handles politically exposed persons (PEPs) in a crypto context, where the standard bank-relationship model does not map cleanly; treating the Travel Rule as a technology question rather than a written-procedure requirement; and producing a policy that was accurate at the time of licensing but has not been updated to reflect new products, new geographies, or changes in the FSC's supervisory guidance.

The FSC is increasingly conducting thematic reviews and on-site inspections of licensed VASPs. A policy that is not demonstrably current – dated, not reviewed, not signed off by the board in the last twelve months – is a supervisory red flag, even if the substantive content was once adequate.

In Practice: Policy Remediation Before a Supervisory Review

In a recent engagement, an exchange licensed in Mauritius received advance notice of an FSC thematic review covering transaction monitoring and Travel Rule compliance. The business had an existing AML/CFT policy inherited from its prior registration in another jurisdiction. On review, the policy lacked a documented Travel Rule procedure, the risk assessment did not address DeFi-adjacent product flows the business had added since original licensing, and the MLRO governance section referenced a role that had been vacant for several months. We undertook a gap analysis against the FSC's current supervisory expectations, drafted a revised policy suite including a stand-alone Travel Rule procedure and an updated risk assessment, and supported the client through the board sign-off process. The thematic review proceeded without a remediation notice.

Decision Matrix: Which Operator Needs What Level of Program?

Not every Mauritius VASP requires the same depth of AML/CFT documentation. The appropriate program varies by activity type, customer base, and cross-border exposure.

A custody-only operator with a limited, institutional customer base and no direct retail-facing flows typically needs a strong customer due-diligence and onboarding procedure, a clear record-retention framework, and an MLRO structure – but its transaction-monitoring requirements are narrower than those of a full exchange. Its key risk area is usually the quality of its institutional client onboarding and its exposure to concentrated counterparty risk.

A retail exchange with cross-border users in multiple jurisdictions faces the broadest documentation requirement: a full KYC framework covering tiered verification, a transaction-monitoring rulebook that addresses both on-chain and off-ramp flows, a Travel Rule procedure that covers multiple counterparty jurisdiction standards, enhanced-due-diligence protocols for high-risk geographies, and an MLRO function with real operational authority. The timeline for drafting and FSC acceptance of this level of program is materially longer than for a narrower business.

A token issuer conducting a regulated offering from Mauritius occupies a middle position: the AML/CFT policy must address the distribution mechanics, the investor-verification process, and any secondary-market flows the issuer facilitates, but it is less concerned with ongoing transaction monitoring at the account level than an exchange is.

In each case, the trigger for upgrading the program is typically either a supervisory event – an inspection notice, a thematic review, a condition attached at licence renewal – or a banking event – a correspondent's due-diligence request, an account-opening requirement, or a payment-rails review. We map the policy requirements to the specific business profile before drafting begins, so the resulting document is calibrated rather than generic.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16 as applied to virtual assets, requires a VASP to collect specified originator and beneficiary information before or at the point of a qualifying transfer, to verify that data, and to transmit it to the receiving VASP. The information must travel with the transaction. In Mauritius, the FSC expects this obligation to be documented in the written AML/CFT policy and operationalized through a technical solution capable of VASP-to-VASP data exchange. Transfers to unhosted wallets require a risk-based documented procedure. Applicable thresholds vary and should be confirmed against current FSC guidance.

Who must act as MLRO for a crypto firm?

A Mauritius-licensed VASP must designate a money laundering reporting officer who holds personal responsibility for the AML/CFT function, for suspicious-transaction reporting to the Financial Intelligence Unit, and for the program's ongoing adequacy. The FSC assesses the MLRO's suitability during licensing and at supervision. The officer must be sufficiently senior, genuinely empowered, and reachable. A nominal appointment where the compliance function operates entirely offshore is unlikely to satisfy the regulator and exposes the named individual to personal risk. The MLRO structure should be confirmed before the licence application is filed.

How do regulators audit crypto AML programs?

The FSC conducts AML/CFT supervision of licensed VASPs through a combination of document reviews at licensing, thematic reviews targeting specific risk areas (such as Travel Rule compliance or transaction monitoring), and on-site or desk-based inspections. Supervisors typically request the written policy, the current risk assessment, evidence of MLRO appointment, transaction-monitoring records, and staff-training logs. A policy that is undated, not board-approved, or inconsistent with the business's actual operations is a common adverse finding. Annual review and board sign-off are baseline expectations across the leading FATF-member supervisors.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we have advised crypto businesses across more than seventy licensing jurisdictions on the AML and compliance programs that underpin their regulatory standing and banking access. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in AML/CFT program design, VASP licensing requirements, and cross-border compliance obligations for digital-asset businesses operating in Mauritius and across the major licensing hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours