MAURITIUS FIU Supplementary STR Guidance Note 4.1: What Reporting Persons Need to Change
The Mauritius FIU has issued a Supplementary STR Guidance Note 4.1:
Issued: 19 August 2026, by the Financial Intelligence Unit (FIU), under s.10(2)(c)(i) FIAMLA –
Effect: Supplements — does not replace — STR Guidance Note 4. Creates no new legal obligation; clarifies existing s.14 FIAMLA duties. –
Why it matters: while the underlying law hasn't changed, the Note sets a materially higher documentation and governance bar for evidencing compliance with it.
1. What Has Changed
Guidance Note 4.1 clarifies the operation of the five-working-day suspicious transaction reporting (STR) deadline under Section 14 of FIAMLA. The two central clarifications are:
The five working days begin when the MLRO/DMLRO determines, following a reasonable preliminary assessment, that reasonable grounds for suspicion exist — not on the date an internal STR is received.
This is not an open-ended assessment period.
The preliminary assessment must be completed within a reasonable timeframe and without unnecessary delay; once suspicion is established, filing should be prompt — same day where reasonably practicable — with five working days as the statutory maximum, not the expected timeframe.
The Note also addresses immediate escalation of internal reports, the meaning of “promptly” under s.14(1), documented internal assessment timeframes, risk-based prioritisation, documentation of the MLRO/DMLRO's decision-making, and immediate reporting of suspected terrorist financing (TF) and proliferation financing (PF) matters.
2. Gap Register: Requirements, Likely Gaps and Recommended Actions
Each item below sets out
A substantive requirement in GN4.1,
The gap most firms are likely to have against it, and
The corresponding action to close it.
The following is intended as a working checklist for reviewing existing AML/CFT policies, STR procedures and record-keeping arrangements.
• Ref 1 — Internal STRs must go directly and immediately to the MLRO/DMLRO, with no mandatory hierarchy, supervisory review or management sign-off in between. –
Likely gap: Escalation routes that pass through a line manager or partner before reaching the MLRO. – Recommended action:
Map the current escalation path and remove any mandatory approval gate before MLRO notification.
• Ref 2 — Firms must establish, document and have senior management approve an internal timeframe for the MLRO/DMLRO's preliminary assessment, calibrated to size, complexity, volume and risk, and reviewed periodically. –
Likely gap: Manuals typically reference the 5-day statutory filing deadline but do not separately define or document a target timeframe for the assessment stage itself. –
Recommended action: Draft and obtain senior management/board sign-off on an internal assessment SLA. Add a periodic review cycle to the governance calendar.
• Ref 3 — The preliminary assessment must be completed within a “reasonable timeframe” — GN4.1 sets no fixed numeric cap. –
Likely gap: Without a documented internal timeframe, a firm has no defensible anchor for what “reasonable” means in its own case. –
Recommended action: Treat the Action at Ref 2 as the control that closes this gap — the firm, not the FIU, must define and evidence “reasonable.”
• Ref 4 — The 5-working-day clock starts on the date the MLRO/DMLRO determines reasonable grounds for suspicion exist — not the date the internal STR was received. Both dates must be documented. –
Likely gap: STR logs that capture only the date an internal report was received, with no separate field for the determination date. –
Recommended action: Amend the STR register to capture both dates distinctly: the date the internal STR was received and the date the MLRO/DMLRO determination was reached.
• Ref 5 — Once suspicion is confirmed, filing should be same-day where reasonably practicable. Resourcing shortfalls (human or IT) are expressly not an acceptable reason for delay. –
Likely gap: No tested, unblocked same-day goAML filing workflow for straightforward cases. –
Recommended action: Confirm the MLRO/DMLRO has direct, unblocked goAML access and sign-off authority. Stress-test turnaround time on a straightforward case.
• Ref 6 — Suspected TF or PF must be reported immediately on the grounds being established, not deferred to the 5-day window or delayed to gather non-essential information. “Immediately” is defined by reference to the UN (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act 2019. –
Likely gap: A single undifferentiated 5-day process applied to all STR categories, with no distinct accelerated TF/PF pathway. –
Recommended action: Build a separate, clearly flagged TF/PF fast-track procedure into the policy manual, cross-referencing the UN Sanctions Act 2019 definition of “immediately.”
• Ref 7 — Internal procedures must prioritise higher-risk matters for a shorter assessment timeframe. Lower-risk matters still need to be addressed and not unnecessarily delayed. –
Likely gap: A single assessment SLA applied uniformly regardless of risk. –
Recommended action: Tier the internal assessment SLA by risk category (standard / elevated / TF-PF-immediate) with defined triggers for each tier.
• Ref 8 — Records must capture: date internal STR received; date assessment commenced; information reviewed; additional information obtained; rationale for the decision; date decision reached; date STR filed; details of any escalation applied. –
Likely gap: STR registers that capture filing outcome and date, but not the full decision trail — particularly the rationale for internal STRs that do not proceed to an external filing. –
Recommended action: Rebuild the STR log/register template against this checklist directly.
• Ref 9 — If goAML rejects a submission, the firm must correct and resubmit without delay. The rejection does not reset or extend the statutory 5-day period. –
Likely gap: A firm treating a rejection as restarting the countdown, which could leave it in an undetected breach of the original deadline. –
Recommended action: Add an explicit SOP line: rejection triggers immediate correction, not a new countdown. Track the original determination date through to the final accepted submission.
• Ref 10 — Auditors identifying suspicion during an audit report directly to the FIU and are not required to follow a Reporting Person's internal MLRO escalation process, unless also acting in a capacity where it applies. –
Likely gap: Relevant chiefly to firms with in-house audit functions or audit engagements — risk of the two reporting routes being conflated. –
Recommended action: Where applicable, confirm audit-function reporting lines are documented separately from the standard MLRO escalation chain.
• Ref 11 — The MLRO/DMLRO must have sufficient authority, independence, resources and full access to relevant information, and must be able to decide without undue influence or unnecessary internal approvals. –
Likely gap: Structures where the MLRO role sits under a managing partner who effectively co-signs filing decisions. –
Recommended action: Document the MLRO/DMLRO's unilateral filing authority in governance documents.
• Ref 12 — STRs and supporting documentation must be retained for a minimum of seven years from the date of the report. –
Likely gap: Low risk of divergence, but worth confirming rather than assuming alignment with existing retention schedules. –
Recommended action: Cross-check that the retention schedule states seven years specifically for STR records.
3. The One-Point Worth Flagging Directly
GN4.1 states it “does not create new legal obligations.” That is correct as a matter of law — it is interpretive guidance issued under existing FIU powers.
In practice, however, Ref 2 (a documented MLRO/DMLRO assessment timeframe policy), Ref 4 (dual-date logging) and Ref 8 (the expanded audit trail) amount to new documented-control expectations that most existing manuals will not already meet, even though the underlying statutory obligation is unchanged. Firms should treat this as a materially higher evidentiary bar for demonstrating compliance with an obligation that has always existed, not as a change to the obligation itself.
4. Consequences of Non-Compliance
The Guidance Note restates the applicable penalty framework, cross-referenced against the FIAML (Administrative Penalties) Regulations 2025:
Failure to file a STR within 5 working days – Provision: Section 14(3) FIAMLA – Penalty: Fine up to MUR 1,000,000 and/or imprisonment up to 5 years
Tipping off — disclosing that a STR has been or is being filed – Provision: Section 16(3)(A) FIAMLA – Penalty: Fine up to MUR 5,000,000 and/or imprisonment up to 10 years
Failure to comply with AML/CFT obligations (administrative sanctions) – Provision: Section 19H(1)(d)(iii) FIAMLA; FIAML (Administrative Penalties) Regulations 2025 – Penalty: Administrative penalties from MUR 5,000 up to MUR 250,000 per breach, depending on gravity
5. Recommended Next Steps
Review internal STR escalation procedures against Ref 1 and Ref 11 (direct routing to the MLRO/DMLRO; unilateral filing authority).
Draft and obtain senior management approval for a documented internal assessment timeframe policy (Ref 2).
Update the STR register/log template to capture both the internal-STR-received date and the MLRO/DMLRO determination date, plus the full decision-trail fields at Ref 8.
Build a distinct TF/PF fast-track reporting pathway, separate from the standard process (Ref 6).
Confirm the record-retention schedule reflects the seven-year minimum for STR records (Ref 12).
Where relevant, review audit-function reporting lines separately from MLRO escalation (Ref 10).
6. Sources
• FIU Supplementary STR Guidance Note 4.1 (PDF): https://www.fiumauritius.org/fiu/wp-content/uploads/2026/08/FIU-Supplementary-STR-Guidance-Note-4.1.pdf
• FIU announcement page: https://www.fiumauritius.org/fiu/?p=6110
• FIU Publications – Guidance (listing page): https://www.fiumauritius.org/fiu/?page_id=5412
• STR Guidance Note 4 (Nov 2020, still in force, read together with GN4.1): https://www.fiumauritius.org/fiu/wp-content/uploads/2020/09/Guidance-Note_-no4-published-23Nov2020.pdf
• FIAMLA 2002 (updated 2025, consolidated text): https://www.fiumauritius.org/fiu/wp-content/uploads/2026/04/FIAMLA-2002-updated-2025.pdf
• FIU homepage: https://www.fiumauritius.org/fiu/
This briefing is provided for general information purposes and does not constitute legal advice. Reporting Persons should review the full text of FIU Supplementary STR Guidance Note 4.1 and STR Guidance Note 4, available at www.fiumauritius.org, and seek specific advice on their own arrangements.
Prepared by Comsure Compliance Limited, 1 Bond Street Chambers, St Helier, Jersey.
The Team
Meet the team of industry experts behind Comsure
Find out moreLatest News
Keep up to date with the very latest news from Comsure
Find out moreGallery
View our latest imagery from our news and work
Find out moreNews Disclaimer
As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.
Archived News
To find our older articles, please click here.
View archive