Insights

The FSC guidance on responsible AI: an implementation checklist for licensees

In September 2025 the Financial Services Commission of Mauritius published Fintech Series Guidance Notes No. 4, “Principles for the Responsible Use of Artificial Intelligence in Financial Services”. Much of it is descriptive: what AI is, how the sector uses it, what other regulators are doing. Its operative content is a set of nine principles in an appendix, a section on governance, and a restatement of two obligations under the Data Protection Act 2017.

This article turns that content into an implementation checklist for the managing director, compliance officer or board member of a licensee that wants to show the regulator a considered response rather than an improvised one. Throughout, we separate what the guidance says (guidance), what the law requires (legal requirement), and what we think a sensible licensee should do (Consultaix recommendation).

This article is general information, not legal advice. Licensees should take their own legal advice on how the Data Protection Act 2017, the Financial Services Act and any sector-specific rules apply to them.

Who is in scope

The guidance note states that it explores key considerations surrounding the use of AI in the insurance, wealth management and non-banking financial institutions (NBFI) sectors, with an emphasis on consumer protection and best practice. The appendix is titled “Principles for the responsible use of artificial intelligence in the non-banking financial services sector of Mauritius”, and the principles are ones that licensees and their associated stakeholders “are advised to consider” when developing, deploying and using AI.

Three points about status follow from the text.

Guidance. The document describes its nine principles as “key and non-binding”. It states that it is not intended as a prescriptive or exhaustive checklist and should not be construed as legal advice. The Way Forward section repeats that the principles are expected to contribute in a non-binding way to a culture of ethical conduct and compliance.

Guidance. The note does not propose new standards. It records the International Association of Insurance Supervisors’ view that existing Insurance Core Principles remain appropriate for AI risk, and aims for AI to support fair customer outcomes within existing governance, risk management and internal control frameworks.

Legal requirement. The note is to be read with the relevant Acts, the Data Protection Act 2017, and the Commission’s Principles and Circulars, and it neither derogates from nor restricts the Commission’s statutory powers. Non-binding guidance sits on top of binding law and licence conditions, not in place of them.

Banks are supervised by the Bank of Mauritius and are outside this guidance. Firms offering automated investment advice are also subject to separate FSC rules, discussed at the end.

The governance expectations behind the principles

Before the nine principles, the note sets out a section on governance through human oversight and assigned management accountability. Its starting point is that AI does not change existing supervisory expectations: boards should continue to ensure a clearly defined and documented governance framework with an effective separation between oversight and management.

It then identifies four areas needing particular attention. Accountability should be established across the whole AI lifecycle, from design through procurement, deployment, monitoring and decommissioning, possibly using a responsibility matrix and a structured handover, because responsibility drifts from the technical team to business units over time. Board members and senior management should have enough baseline expertise to assess AI outputs critically where AI is used in critical decisions. Human oversight should be effective, with board-level expertise where AI significantly influences consumer outcomes. And the limits of oversight over third-party systems should be addressed through due diligence, system redundancy, mechanical monitoring of inputs and outputs, and kill switches. Almost every principle below relies on one of these expectations.

The nine principles and how to implement them

For each principle we give a summary in our own words, then implementation actions and the evidence a licensee could hold. Actions and evidence are Consultaix recommendations unless labelled otherwise.

1. Fairness and bias mitigation

The principle asks licensees to identify and mitigate bias in algorithms and datasets so that outcomes are not unfair or discriminatory, and to audit models regularly. The body of the note describes a “fairness by design” approach in which fairness is built into governance and risk management rather than checked afterwards, and warns against AI that exploits consumers’ behavioural tendencies, such as reluctance to compare options at renewal.

Actions: - For each AI use, document which customer groups could be disadvantaged by a skewed output and what protected characteristics or proxies exist in the data. - Test outputs across those groups before go-live and at a defined interval afterwards. - Prohibit in policy any use of AI designed to exploit consumer behaviour.

Evidence: a bias assessment per AI use; dated test results; a policy clause on prohibited uses; minutes showing review.

2. Transparency

The principle asks for clear, understandable information on how algorithms are used in decisions, a channel for customers to raise concerns about AI-based services, and an effective grievance mechanism for AI-driven decisions. The note links this to the existing duty to act with due skill, care and diligence, accepts that disclosure may be limited in areas such as fraud detection, and says firms using third-party AI should secure documentation and assurances about model behaviour.

Actions: - Publish a plain-language explanation of where AI is used in customer-facing decisions. - Flag AI-related complaints within the existing complaints procedure so they can be counted and reviewed. - Obtain and file the vendor’s model documentation, including known limitations.

Evidence: customer-facing disclosure text; complaints log with an AI category; vendor documentation pack.

3. Accountability

The principle asks for procedures to monitor AI systems and mechanisms for clear accountability when errors or malfunctions occur. Read with the governance section, this means a named person must own each system at every stage, including after the original project team has moved on.

Actions: - Maintain an AI register listing every system, its purpose, executive owner, vendor and go-live date. - Adopt a responsibility matrix covering the lifecycle from design to decommissioning. - Define an incident procedure for AI errors, including who decides to suspend the system.

Evidence: the register; the matrix; the incident procedure; a record of incidents and their handling.

4. Privacy

This is the longest principle and the one most directly anchored in law. It asks licensees to comply with data protection law, use privacy-preserving techniques, inform data subjects of automated decision-making, provide meaningful information on its logic, criteria and significance, give individuals a route to human intervention and contestation, and implement a data protection impact assessment.

Legal requirement. The note’s section 12.4 restates obligations that exist under the Data Protection Act 2017 independently of the guidance. Section 38 gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects them, subject to exceptions for contract necessity, legal authorisation with safeguards, and explicit consent, and prohibits automated evaluation of personal aspects based on special categories of data. Section 34 requires a DPIA before processing likely to result in a high risk to data subjects, expressly including systematic and extensive evaluation based on automated processing on which significant decisions are based. Section 22 makes a DPIA a duty of every controller.

Actions: - Classify each AI use by whether it makes or materially shapes decisions about individuals, and whether any such decision is solely automated. - Where a DPIA is required, complete it before go-live and submit it through the Data Protection Office’s eDPO system; where it is not, record the reasoning. - Update privacy notices to disclose automated decision-making and build a documented route for human review.

Evidence: classification record; DPIAs or documented exemption reasoning; updated privacy notice; a human review log.

5. Security

The principle asks for robust cybersecurity measures to protect AI systems, regularly reassessed as threats evolve. The note’s security section adds that systems which learn and change after deployment need enhanced safeguards around model validation and data governance, that robustness testing should be continuous with automated monitoring for shifts in data distribution, and that material findings should be shared with third-party providers.

Actions: - Bring every AI system, including cloud-hosted vendor tools, inside the existing information security policy and access control regime. - Define expected outcomes for each system in advance and monitor for drift. - Share material robustness findings with the vendor and record the response.

Evidence: security policy scope naming AI systems; monitoring reports; vendor correspondence.

Legal requirement. Section 31 of the Data Protection Act 2017 separately requires appropriate security and organisational measures against unauthorised access, alteration, disclosure, loss and destruction of personal data.

6. Environmental sustainability

The principle asks licensees to explore AI that aligns with environmental sustainability goals and to consider the environmental impact of AI systems and infrastructure, including energy and resource use. This is a lighter expectation for most Mauritian licensees, who consume cloud services rather than run their own compute.

Actions: - Ask vendors for their environmental disclosures and file them. - Include an environmental note in the AI register where the licensee already reports on sustainability.

Evidence: vendor disclosures on file; a line in the sustainability section of the annual report if one exists.

7. Human-centricity

The principle asks licensees to prioritise AI that enhances human capability and decision-making rather than replacing it, and to ensure human oversight in critical decisions. It implies that “a human signs off” must be real.

Actions: - For each critical decision process, specify what the human reviewer sees, what they check, and what authority they have to override. - Sample reviewer decisions periodically to confirm that overrides actually occur.

Evidence: reviewer procedure; sampling results showing the override rate.

8. Continuous monitoring and evaluation

The principle asks for ongoing training of staff involved in AI, ongoing monitoring of the ethical and societal impact of AI systems, and regular review of systems to safeguard data integrity, accuracy, relevance and transparency. Elsewhere the note adds that boards and senior management should understand AI well enough to oversee it and challenge its outputs, with training regularly reviewed.

Actions: - Schedule a periodic review of each AI system covering performance, incidents, complaints and changes in use. - Maintain a training record for staff who operate, oversee or approve AI, and for the board. - Report to the board or a committee on AI at a fixed interval.

Evidence: completed reviews; training records; board or committee papers.

9. Compliance and ethics

The principle asks licensees to comply with laws and regulations governing technology and AI in financial services, to manage regulatory change, fraud prevention and AML/CFT requirements, and to align AI-based decisions with the licensee’s ethical standards and code of conduct.

Actions: - Add AI to the compliance monitoring plan and regulatory horizon-scanning. - Extend the code of conduct so that AI-assisted decisions are held to the same standard as human ones. - Where AI supports AML/CFT screening or fraud detection, document how false positives and negatives are handled.

Evidence: compliance plan entry; code of conduct amendment; AML/CFT AI procedure.

Mapping the principles to ISO/IEC 42001 and the Data Protection Act

Best practice. ISO/IEC 42001:2023 is a voluntary international standard for an AI management system, following the common management system structure (context, leadership, planning, support, operation, performance evaluation, improvement) with controls covering AI policy, roles, impact assessment, lifecycle management, data quality, third parties and transparency. No FSC guidance requires certification; a licensee can use the standard as a structure without certifying. The mapping below is Consultaix’s general reading, not endorsed by the FSC or ISO.

FSC principle ISO/IEC 42001 emphasis Data Protection Act 2017
1 Fairness and bias Impact assessment; data quality and provenance s.38(3) no evaluation on special categories; s.34 DPIA
2 Transparency Communication to interested parties; documentation s.23 information to data subjects; s.38(4) disclosure
3 Accountability Leadership; roles; lifecycle management s.22 duties of controller
4 Privacy Impact assessment; data management s.34 DPIA; s.38 automated decisions
5 Security Operational controls; supplier management s.31 security of processing
6 Environmental sustainability Societal and environmental impacts in impact assessment Not addressed
7 Human-centricity Human oversight controls; responsible AI objectives s.38 right not to be subject to solely automated decisions
8 Continuous monitoring Performance evaluation; internal audit; improvement s.22(3) verification of effectiveness of measures
9 Compliance and ethics Legal and regulatory requirements; AI policy Whole Act

A licensee that builds even a light management system around ISO/IEC 42001 will generate most of the evidence the FSC principles call for as a by-product, and will have a defensible answer to the Act at the same time.

A first-90-days sequence

Consultaix recommendation. For a licensee starting from little or nothing, this order works because each step feeds the next.

Days 1 to 30: know what you have. Build the AI register, including generative AI tools staff use informally. Name an executive owner for each entry. Classify each by whether it touches personal data and whether it shapes decisions about individuals. Brief the board on the guidance note and on sections 34 and 38 of the Act.

Days 31 to 60: close the legal gaps. For every entry that could involve high-risk processing or solely automated decisions, complete a DPIA or record why one is not required. Update privacy notices. Confirm that each vendor contract addresses data location, use of data for model training, security and audit rights. Bring AI systems into the information security policy.

Days 61 to 90: build the operating rhythm. Adopt a short AI policy referencing the nine principles and the code of conduct. Set up the responsibility matrix, incident procedure and review schedule. Run the first bias and drift check on the highest-risk system. Train operators and the board. Table the first AI report to the board or relevant committee. By day 90 the licensee can show a register, DPIAs, a policy, named owners, a review cycle and board engagement: a considered response.

A note on the Robotic and AI-Enabled Advisory Services Rules

Firms providing automated investment advice fall under a separate regime that is binding, not guidance.

Legal requirement. The Financial Services (Robotic and Artificial Intelligence Enabled Advisory Services) Rules, made by the FSC under section 14 of the Financial Services Act, require any person providing digital and personalised advisory services through a computer program or AI-enabled algorithms with limited human intervention to hold a specific licence. The rules impose obligations including internal controls and risk management, business continuity, board composition requirements, minimum capital and professional indemnity cover, and client suitability assessment. The specific thresholds should be taken from the current text of the 2021 Rules as published by the FSC. The board is ultimately responsible for policies and controls ensuring algorithms continue to perform as intended, a framework for their design, monitoring and testing, and competent officers to review them even where outsourced. Licensees may not outsource the key processes and management of client-facing tools, must provide prescribed disclosures and a service-level agreement, must keep records including details of all algorithms and software, and must submit independent evaluation reports on systems and controls at least every two years and after material changes.

A firm in this category should treat the nine principles as the floor and the rules as the binding layer above it.

Where Consultaix fits

Consultaix’s AI Governance Advisory service helps licensees build the register, policy, responsibility matrix and review cycle described here, structured on ISO/IEC 42001 and aligned to the Data Protection Act 2017, so that the response to the FSC guidance is evidence rather than assertion. Where the organisation has not yet mapped its AI use at all, the AI Readiness Assessment provides the starting inventory.

Sources