Fourteen years inside the FSC, as Head of Global Business and Head of Surveillance, taught Sarika Subdhan how a regulator thinks. Today, the Founder of CompFidus Group sits on the other side of the table, and she no longer needs foreign scandals to train Mauritian compliance officers: the local enforcement landscape supplies all her case studies. In this interview, she explains why compliance has become an algorithm battle, why a green dashboard should worry a board more than reassure it, and what she would tell every CEO on the island before the end of the year.
The financial sector is absorbing a massive double-shock: the entry into force of the AML/CFT Act 2026, the FSC’s strict revised Enforcement Manual and increased licensing fees. Are we genuinely building a world-class culture of compliance, or are firms just panicking to tick new boxes?
It is a defining moment for our International Financial Centre, and we are seeing a healthy blend of both adjustment and transformation. Naturally, there is widespread operational anxiety. When you combine the entry into force of the AML/CFT Act 2026 and a data-driven FSC Enforcement Manual with immediate, increased licensing fees, the structural and financial pressure on licensees scales instantly.
Frankly, things could have been handled differently. A phased implementation, like deferring the increased fees to 1 July 2027, would have given licensees proper breathing room to budget. La manière de faire est tout aussi importante que le résultat escompté: the manner of execution matters just as much as the regulatory outcome. When changes are rushed or punitive, it directly damages our competitiveness on the global stage. International investors view these last-minute fee increases, coupled with short deadlines on the eve of settlement dates, as a lack of long-term planning. Ultimately, this unpredictability risks eroding the very trust we need to sustain our status as a premier international financial centre.
However, looking past this immediate friction, our long-term goal must remain the cultivation of a world-class culture of compliance. Passive, back-office box-ticking is completely dead in Mauritius; with the MRA, ROC and FSC moving toward automated enforcement, administrative gaps are simply too costly to ignore. At CompFidus, we guide boards to look past the immediate cost shocks and treat these frameworks as a corporate shield.
With your 14 years of experience inside the FSC, is the 2026 Enforcement Manual’s shift from a consultative approach to strict sanctions and negotiated settlements the natural maturation you anticipated, or has the severity of this reform surprised you?
This shift does not surprise me; rather, it represents the natural maturation of a jurisdiction striving to anchor itself among the world’s elite financial centres. Having spent some 14 years as Head of Global Business and Head of Surveillance within the FSC, I view this transition from a consultative stance to a structured Settlement Process as an inevitable evolutionary step.
Look at international benchmarks like the UK’s FCA or Singapore’s MAS: negotiated settlements and public sanctions are standard tools used to enforce discipline without crippling the legal system with endless litigation. A mature regulator must have teeth, and it must act with certainty.
Where international best practice diverges from our current local reality is the pace of transition. In mature markets, enforcement manuals are backed by extensive, transparent industry guidance notes and transitional ‘grandfathering’ periods. The goal of a settlement process should be to rectify systemic gaps swiftly, not to act as an aggressive revenue mechanism, and the FSC must ensure that ‘negotiated settlements’ do not become one-sided ultimatums. For Mauritius to truly mature, enforcement must be balanced with clear, proactive compliance education. The framework is correct, but its application must remain fair, predictable and aligned with commercial realities.
In your day-to-day work with Global Business Licence (GBL) holders and management companies, what is the most dangerous misconception about what “being compliant” means under the AML/CFT Act 2026 and the new FSC Guidelines on CDD frequency?
The absolute most dangerous misconception dominating the Global Business sector today is treating compliance as a static, checklist-driven mathematical equation rather than a live, event-driven operational pulse. Firms are currently tripping over six critical blind spots where theory, operational practice and software systems are crashing into each other.
“Administrative fines are now prorated directly against your gross turnover, not your net profits. For a high-volume operator, a percentage-based fine on top-line revenue can be absolutely catastrophic.”
— Sarika Subdhan, Founder of CompFidus Group
1. The “Cap Table Trap” in UBO definitions
Firms are wrongly treating Ultimate Beneficial Ownership (UBO) verification as a basic shareholding calculation. Under the AML/CFT Act 2026, the exclusive link between percentage equity and ownership is officially broken. While the statutory threshold has been maintained at the strict 20% voting power or profit distribution, that is only layer one. You must now map out qualitative control in its entirety back to a natural person, including effective control through voting rights, management authority, veto powers and contractual side-letters. If you only look at share percentages on a structure chart, your compliance framework is built on a dangerous blind spot.
2. The illusion of the Board / Senior Management shortcut
Many compliance teams treat the Board or Senior Management fallback as an easy operational escape route. For example, when faced with a highly fractionalized structure where no individual crosses the strict 20% equity mark, or when encountering complex compliance technicalities that the compliance function struggles to resolve, teams simply default to entering the name of the CEO or Director to clear the regulatory registry’s digital portal checklist.
Let me be absolutely clear: the FSC views the Board or Senior Management designation as a last-resort failure mechanism, not a convenience path—even though they hold ultimate governance accountability for the entity’s AML/CFT framework. Naming the Board / Senior Management is Tier 3 of a strict, sequential cascade review. If you resort to a Board or Senior Management fallback without documented, exhaustive proof that you tried and failed to isolate a hidden qualitative controller under Tiers 1 and 2, your file is completely non-compliant. The regulator treats an unproven the Board / Senior Management listing as an omission of the compliance function to fulfil its obligations.
3. The asynchronous data contradiction (CRA vs CDD frequency)
The new FSC CDD Frequency Guidelines establish minimum periodic floors for CDD document collection: three years for medium-risk and four years for low-risk clients, while the frequency for high-risk clients remains unchanged at one year. Many firms look at these timelines and think they can relax, but they are walking into an operational trap by decoupling CDD collection from their Customer Risk Assessment (CRA) and screening frequency.
Under Chapter 4 of the core FSC AML/CFT Handbook, CRAs must be reviewed at least every two years for medium-risk and three years for low-risk clients. The board-approved policies CompFidus formulates for its clients, strictly grounded in these Handbook provisions and successfully tested during live FSC on-site inspections, therefore keep CRAs, screening and CDD collection on one synchronised, continuous lifecycle: client file reviews at three years for low-risk and two years for medium-risk profiles, the strictest common denominator.
If you separate these calendars, running a CRA at Year 3 but waiting until Year 4 to collect the physical CDD, the system breaks completely: the moment that new CDD arrives, you are legally mandated to re-assess the entire file anyway, and you end up trapped in an inefficient loop of double work. Unless I have completely misread the architecture of the new Guidelines, there is a fundamental inconsistency between the periodic collection floors and the core expectations of a true risk-based approach. This creates a clear non-alignment issue, and it is precisely the kind of case where operational clarification from the regulator would be useful to bridge the gap.
4. The “remediation window” illusion
The regulations mandate a one-year window to remediate legacy customer files, and the dangerous myth in the industry is treating this as a structural grace period. From a strict regulatory standpoint, that extension only applies to dormant, stable legacy files. If an FSC inspector conducts an on-site review today and finds a legacy file with an unaddressed historical trigger-event, such as an unflagged shift in management authority or a change in beneficial ownership from two years ago, that file is not waiting for remediation. It is an immediate, actionable breach under the new FSC Enforcement Manual.
5. Misunderstanding the legal weight of “guidance”
There is a persistent legal misunderstanding that because the FSC Handbook and Guidelines are framed as advisory instruments rather than primary parliamentary statutes, they are not strictly enforceable. This is a severe misinterpretation of Mauritian administrative law. Under the Financial Services Act, the FSC holds absolute statutory power to determine whether a licensee and its officers remain ‘fit and proper’, measured directly against the exact criteria detailed in the Handbook and Guidelines. With the MRA, Registrar of Companies and FSC moving toward an integrated, automated enforcement loop, administrative penalties are now triggered instantly by system scripts when electronic filing deadlines are missed. Compliance has shifted from a legal debate with a human supervisor to an algorithm battle. In Mauritius today, ‘guidance’ from the regulator carries the functional weight of a command.
6. The new bank signatory mandate
We are seeing a severe operational clash regarding the New Authorised Bank Signatory Regime (effective 19 June 2026), introduced via the newly amended Paragraph 9.2 of the Guidelines for Management Companies: every bank account operated by a GBC must include at least one FSC-approved officer of the Management Company as an authorised bank signatory. Many of my institutional Global Business Companies (GBCs) clients, who employ highly specialised, dedicated non-MC internal staff, feel deeply offended. They view this mandate as highly intrusive, arguing that providing the MC with full view-access or read-only bank privileges is already completely sufficient for robust transaction monitoring. On the operational front, MCs are often structurally unequipped to handle the high velocity demands of GBCs, particularly large holding structures, subsidiaries or sister companies of multinational corporations executing over 500 transactions daily.
While the FSC undoubtedly has its own regulatory justifications for imposing this regime —such as enforcing strict local substance and ensuring direct compliance touchpoints over fund flows— the fundamental issue here is the total absence of industry consultation. During my tenure as Head of Global Business at the FSC, I served as the Secretary of a GB industry committee chaired at that time by Couldip Basant Lala. We used to host monthly early-morning breakfast meetings, bringing together some twenty top representatives from across the sector; regulators and operators sat at the same table to collaboratively debate, refine and prepare upcoming policies and new product developments before they were finalised and approved at the FSC Board level. True regulatory maturation requires a return to that level of institutional synchronisation, an alignment of the steps of decision-makers and operators sending timely, predictable signals to the market, rather than blindsiding the very entities driving the economy.
Look at the headlines: the Financial Crimes Commission (FCC) is accelerating asset seizures and forensic investigations. What is the single systemic gap in how Mauritian institutions approach beneficial ownership transparency and transaction monitoring right now?
The single greatest systemic gap is the reliance on historical, static data to monitor live, fast-evolving transactional risks. Too many institutions are treating transaction monitoring as a delayed retrospective accounting review rather than a predictive forensic discipline.
There is an ironic silver lining to this structural gap in my role as an AML/CFT educator and mentor. Every case study I present to boards and compliance officers during my training courses stems from direct, first-hand experience or active matters. For years, when designing advanced compliance case studies, I had to look internationally, relying on classic regulatory failures from the UK FCA or US FinCEN to teach complex ownership shielding or asset diversion. Today, I no longer need to look abroad. The enforcement landscape has changed so drastically that I source all my material for my AML/CFT masterclass case studies locally, from recent, real-world Mauritian enforcement outcomes. The recent high-profile investigations and immediate asset seizures executed under the FCC framework provide incredibly rich, real-world lessons. There is nothing to be proud of, but that is the evolution.
What these local cases consistently expose is a severe disconnect between structural charts and live execution. The FCC is accelerating seizures because they are tracing the money in real time. On the other hand, firms are excellent at documenting a corporate structure during onboarding, but they fail to monitor the operational velocity that happens after. They miss the subtle shift when a client’s transaction pattern deviates entirely from their declared source of wealth, or when contractual authority quietly migrates to an unvetted third party. Mauritian institutions will continue to find themselves featured in my local case studies until they bridge this gap – moving away from annual, retroactive lookbacks and adopting live, trigger-based transactional intelligence.
What are the silent warning signs that tell you an institution’s governance framework is about to crack under an unexpected FSC inspection, even when its compliance software shows all green?
The most dangerous illusion in modern compliance is the “green dashboard”. Software is a vital tool, but it only measures data input, not operational comprehension. When I step into an institution for a governance audit or mentoring session, I look entirely past the screens. In my day-to-day work, I see firms consistently blindsided by six structural flaws.
1. The “low BRA score” delusion
There is a pervasive, flawed belief that maintaining a Low score on the Business Risk Assessment (BRA) is inherently a positive regulatory sign. A low-risk score is only valid if it accurately mirrors a highly conservative, simplified business model. If an institution is operating complex, cross-border Global Business structures, a Low BRA score is not a good sign; it is a glaring red flag. It tells me, and will certainly tell an FSC inspector, that the firm’s risk identification methodology is completely disconnected from its actual operational profile.
2. The independent audit scope limitation
Alarmingly, some potential clients ask to strictly restrain our Independent Audit scope exclusively to AML/CFT, explicitly demanding that we ignore broader governance pillars. Let me be completely explicit: attempting to cap the scope of an independent regulatory audit is an immediate red flag. It tells me that a board either fails to realise that the FSC evaluates their institution as a single integrated ecosystem, or is actively trying to conceal deeper systemic fractures. If your corporate governance framework is broken, your AML/CFT controls are guaranteed to fail.
3. The independent audit as a passive shield
Many boards mistakenly assume that a boilerplate clean bill of health from an independent auditor guarantees a seamless FSC inspection. An independent audit is a point-in-time, sample-based review of your framework’s design and operating effectiveness; it is not an ongoing immunity shield. If your day-to-day transaction monitoring has lapsed, or a material trigger-event occurred the week after the audit was signed off, a past clean report will not protect you from immediate administrative sanctions.
4. The “not my job” compliance silo
A major indicator of impending failure is the existence of corporate silos, where frontline staff blindly feed data into a compliance system without understanding the underlying risk metrics. If a relationship manager treats a transaction anomaly or an updated UBO declaration merely as an administrative hassle to be pushed over the wall, the regulatory breach will occur before the compliance software even registers a flag.
5. Explanations absent from the file (the missing “why”)
Compliance systems are excellent at tracking what was done, but they rarely capture why. When I review client files, a significant red flag is seeing a Customer Risk Assessment score manually overridden without an exhaustive, contemporaneous written rationale substantiated in a board or committee minute. If it is not clearly documented in writing, from a regulatory standpoint, it simply did not happen.
6. The “silent” board and passive governance
The software might show that a BRA or a policy manual was uploaded on time, but if you interview the directors, they struggle to explain the actual risks specific to their licensee type. An FSC inspection team will bypass the software and question senior management directly. If the board speaks only in generic compliance phrases and fails to demonstrate active oversight, the institution’s governance framework will fracture within the first hour of an audit.
“To the Board and Senior Management: the regulator is no longer evaluating your compliance department; they are auditing your executive leadership. If you treat regulatory frameworks as a back-office technicality rather than the steering wheel of your business strategy, you are exposing your entire licence to an immediate enforcement trap.”
— Sarika Subdhan, Founder of CompFidus Group
If you could send one urgent message to every compliance officer and CEO on the island before the end of 2026, what would it be?
My message is simple: stop treating compliance as a shield to hide behind, and start building it as the steering wheel of your business. The era of passive box-ticking is dead, and the regulatory landscape of 2026 will not tolerate coasting. I have two distinct directives for the leadership on this island.
To the CEOs
Stop treating your compliance function as an administrative cost centre or a back-office firewall. Under the new FSC Enforcement Manual and the FCC framework, you cannot delegate your legal liability. If the ship goes down, the captain goes down with it. You must also face the harsh mathematical reality of the updated penalty structures: administrative fines are now prorated directly against your gross turnover, not your net profits. For a high-volume Global Business operator or Management Company, a percentage-based fine on top-line revenue can be absolutely catastrophic, easily triggering immediate cash-flow paralysis.
Invest heavily in your compliance architecture and governance today. Or prepare to face business-ending liabilities tomorrow. It is that simple.
To the Compliance Officers
Step out of the operational silo and engage directly with the boardroom. Your mandate has evolved far beyond gathering documents and filing registry updates; you are a risk strategist and a frontline protector of the institution’s licence. Confidently demand the resources, automated monitoring systems and executive-level access required to execute your statutory duties in real time. Be fully prepared to challenge management decisions whenever necessary, ensuring your positions are always strictly anchored in verifiable facts, regulatory text and operational substance. If the Board ultimately chooses to disregard the material risks you explicitly flag, ensure that your dissent and your formal advisories are meticulously documented in writing, to protect both the entity and your personal professional standing.
The bottom line for 2026
National compliance effectiveness is not a government marketing slogan; it is the sum total of our individual institutional discipline. The ESAAMLG countdown is running. If your governance framework is still built on calendar check-boxes instead of dynamic trigger-events, your clock has already run out.
If you want to fix the foundations before the storm hits, feel free to contact me at ssubdhan@compfidus.com. You can also contact CompFidus Ltd to schedule a comprehensive Strategic Governance Review.
About Sarika Subdhan • Sarika Subdhan is the Founder of CompFidus Group, an independent regulatory and compliance consultancy based in Mauritius. She spent 14 years within the Financial Services Commission, serving as Head of Global Business and Head of Surveillance, and now advises boards, conducts independent regulatory audits and trains the next generation of compliance professionals through CompFidus Mentoring.