Jurisdiction · Republic of Mauritius

The Bank of Mauritius does not ask
you to assert compliance. It asks
when you last proved it.

Read the guidelines closely and one shape recurs. Almost every obligation is a clock, a coverage window, an independence requirement, or a record that must survive seven years and an examiner. That is an unusual regime — and it is the shape this system was built for.

§ 01

What the guideline asks. What has to exist to answer it.

Five obligations, and the record each one implies. Every citation is to published Bank of Mauritius text; sources are at the foot of the page.

48-month coverage
Every applicable law, regulation and guideline tested within a three-year cycle — and in no case beyond forty-eight months. A coverage record per obligation — date of last test, who performed it, and the evidence the conclusion rested on. Not a tracker someone maintains, but a record an examiner can reconstruct without you in the room. Compliance Risk Management § 2.14.
The one-year clock
Any new or amended law tested within one year of its effective date. Detection of the change, the obligations it creates or alters, and a clock that starts on the effective date rather than the day someone noticed. § 2.17.
Quarterly board report
Breaches, deficiencies, corrective measures and remediation progress, at least quarterly. A remediation record in which closed means closed against verified evidence — and a closure that lacks it is reported as claimed rather than complete. The distinction is the whole value of the report. § 2.18.
Independence
Compliance sits in the second line, independent of business lines, and is itself independently reviewed by internal audit. Separation enforced by the system that records the work, not asserted by the org chart. The person who remediates cannot be the person who closes. § 2.1(b), § 3.1–3.3.
Seven-year retention
Critical logs and digital evidence retained a minimum of seven years, with forensic-readiness procedures. Evidence that is still verifiable in year seven, after the staff, the tooling and the vendor have all changed. Cyber and Technology Risk ¶ 58; framework audit every two years for D-SIBs and three otherwise, filed within ninety days — ¶ 65, ¶ 67, ¶ 95.
EACH MARK IS ONE OBLIGATION — MONTHS SINCE IT WAS LAST TESTED A NEW OR AMENDED GUIDELINE MUST BE TESTED WITHIN 12 MONTHS OF ITS EFFECTIVE DATE · § 2.17 48-MONTH LIMIT § 2.14 OUT OF WINDOW 0 12 24 36 48 60 FIG. — THE OBLIGATION NOBODY IS LOOKING AT IS THE ONE CLOSEST TO THE WALL. SCHEMATIC — NO DATA. SHAPE ONLY.

Every one is the same request in different words: show the work, not the conclusion. A platform that produces a green dashboard answers none of them. A system that records what was examined, when, by whom, against which evidence — and refuses to record a conclusion it cannot support — answers all of them by construction.

§ 02

The obligations do not shrink with the balance sheet.

The guidelines apply proportionately — commensurate with the size, nature and complexity of the institution. What proportionality adjusts is the scale of the framework. What it does not adjust is the requirement to evidence it.

— D-SIB

The coordination problem

Two-year audit cycle

Two cyber-experienced independent directors, a distinct cyber risk sub-committee, mandatory red-team testing, and a two-year full external audit cycle rather than three. Group subsidiaries abroad report into the group Head of Compliance in Mauritius.

Cyber ¶ 3¶ 6¶ 67Compliance § 4.3
— Mid-tier

The clock problem

Forty-eight-month window

The same coverage obligation and the same one-year testing clock on every new guideline, with a compliance function of a dozen people. The failure mode is the quarter where three guidelines land at once and an older window quietly expires.

§ 2.14§ 2.17§ 2.15–2.16
— Small & branch

The floor problem

Proportionality has a floor

A smaller framework is permitted. A smaller record is not. Four people still evidence a three-year cycle, quarterly board reporting and seven-year retention. A branch may adopt its parent's framework — provided it can be evidenced locally.

Cyber ¶ 17Compliance § 4.1–4.3
§ 03

Five people. One record. Four of them required to be independent of each other.

That independence is not a preference — it is written into the guidelines. A record that cannot demonstrate it is not evidence of compliance; it is evidence of a control weakness.

Head of Compliance
Accountable for the quarterly board report and the coverage window on every obligation; may hold no conflicting role, and sits on committees in an advisory capacity without a vote. Needs to see what is out of window before the board does — and to hand over a pack whose every line traces to an examination that actually happened. § 2.2(e), § 2.3–2.4, § 2.18.
Chief Risk Officer
Receives compliance testing results for enterprise-wide assessment and owns the indicators by which compliance risk is measured. Needs tested and passed, tested and failed, and not yet examined kept distinct rather than averaged into a score. § 2.10(e), § 2.16.
CISO
Second line, independent of IT operations, reporting quarterly to the board on testing results; seven-year evidence retention, and audit findings filed with the Bank within ninety days. Needs testing evidence that is still verifiable long after the tool that produced it was replaced. Cyber ¶ 9–11, ¶ 58, ¶ 95.
Internal Audit
Required to independently review the compliance function, and to remain separate from it. Needs to verify the record without relying on the assurances of the function being audited — independence that depends on trusting the audited party is not independence. § 3.1–3.3.
Auditor · examiner
Conducts the two- or three-yearly framework audit, must be functionally independent, and may not assess the same provider more than three consecutive years without a two-year cooling-off. Needs to reconstruct a point in time and check the evidence without access to your systems and without taking your word for it. Cyber ¶ 41–42, ¶ 67–72.
Evidence that verifies
independently of the party
presenting it. Not "trust
the platform." Not "trust
the bank." A record whose
integrity an examiner checks
on their own machine.

This is the property that serves all five, and it is the reason the architecture looks the way it does. Every other commitment in this system follows from a single refusal: not to be the trusted party.

An examiner who must trust the vendor to believe the evidence has not received evidence. They have received an assurance, from an interested party, about a system they cannot inspect.

§ 04

Here, sovereignty is not a preference. It is a due-diligence file.

Default: self-hosted,
inside the institution.
Evidence never leaves
the bank's own estate.

Managed regional cloud
remains available —
as an election, not
as the architecture.

Where data is hosted outside Mauritius, the guideline requires due diligence on the host country, an assessment of foreign-authority access risk, pre-agreed processing locations, and notification to the Bank of any disclosure made to a foreign authority under court or regulatory order. Cyber and Technology Risk ¶ 43–46; Guideline on Use of Cloud Services, September 2022; Guidelines on Outsourcing by Financial Institutions, January 2026.

Contracts must carry audit rights — on-site or remote — for the institution, its external auditor, the Bank, and third parties the Bank appoints. Exit must be evidenced, including independent assurance that data is permanently irrecoverable and inaccessible. And the compliance function itself may not be outsourced at all, save intra-group, case by case, with the Bank's prior authorisation. Cyber ¶ 38(v); Compliance § 5.1.

Deployed inside the institution, most of that file is not argued. It does not arise. For a bank weighing a foreign-authority access assessment, the difference is the length of the submission.

§ 05

Where these claims stop.

The general boundaries on the main page apply here without amendment. Four more are specific to this jurisdiction.

Mapping is not approval
Obligations from published Bank of Mauritius guidelines are represented as controls. Nothing here is endorsed, reviewed or approved by the Bank of Mauritius, and no representation is made that it has been.
Evidence is not compliance
This system produces records of what was examined and what was found. Whether an institution meets its obligations is a supervisory judgement, made by people, on the whole of its conduct.
What coverage means
It does not mean every control is automated. Some obligations are governance acts performed by named officers — a board approval, a semi-annual meeting, a notification. The system records them. It does not perform them.
Not advice
Nothing here substitutes for the institution's own reading of the guidelines it is bound by. Clause references are to the text as published at the date below; where our reading and yours differ, yours governs.

SOURCES — ALL PUBLISHED BY THE BANK OF MAURITIUS:
Guideline on Compliance Risk Management and Governance Framework, 13 November 2024
Guideline on Cyber and Technology Risk Management, 29 May 2023
Guideline on Use of Cloud Services, 7 September 2022
Guidelines on Outsourcing by Financial Institutions, 6 January 2026

§ 06 · Begin

Bring the guideline you are worried about.

A diligence call covers the mapping to the specific guidelines that bind you, deployment inside your perimeter, what the evidence does and does not establish, and pilot scope. Thirty minutes. With the founder.