Home/Compliance
Regulatory alignment
Compliance & regulatory readiness
Security controls that exist but cannot be evidenced fail audits just as thoroughly as controls that do not exist. We design the evidence trail into the deployment.
Mauritius
The local obligations
Mauritius
Data Protection Act 2017
Obligations on controllers and processors covering lawful basis, security of processing, breach notification and cross-border transfer.
- Records of processing and lawful basis mapping
- Technical and organisational measures evidenced, not asserted
- 72-hour breach notification workflow with a named owner
- Consent capture stored with text and timestamp
- Processor agreements with your own suppliers
Mauritius
Cybersecurity & Cybercrime Act 2021
Offences, investigatory powers and expectations on organisations to handle incidents and preserve evidence properly.
- Incident handling procedure with defined escalation
- Evidence preservation to an admissible standard
- Log retention sufficient to reconstruct an incident
- Reporting lines agreed before an incident, not during
Regulated financial institutions
Bank of Mauritius guideline on cyber risk
Board-level accountability, risk assessment cadence, third-party risk and tested recovery capability.
- Board-reportable risk register with cyber entries
- Independent assessment on a defined cycle
- Third-party and outsourcing risk assessment
- Tested business continuity and recovery, with results
Global business and financial services licensees
FSC Mauritius expectations
Client data segregation, operational resilience and demonstrable oversight of outsourced technology.
- Per-client data segregation and access control
- Outsourcing oversight with defined KPIs
- Resilience testing evidence
- Retention aligned to licence conditions
International
Frameworks that follow your clients
| Framework | Applies when | What we contribute |
|---|---|---|
| EU GDPR | Where you process EU resident data or serve EU clients | Article 32 security of processing, breach notification, transfer mechanisms |
| PCI DSS | Any cardholder data environment | Segmentation, logging, patching cadence, quarterly scanning |
| HIPAA | Health data, or serving US healthcare counterparties | Administrative, physical and technical safeguards; audit controls |
| ISO/IEC 27001 | Where clients or tenders require a recognised framework | Annex A control mapping; we align, we do not certify |
| NIST CSF | As a common language for board reporting | Identify, Protect, Detect, Respond, Recover scoring |
Our approach
Evidence as a by-product, not a project
Compliance work fails when it is a separate annual exercise run by people who did not build the controls. We generate the artefacts as part of normal operation, so an audit request is a retrieval task rather than a fire drill.
- Control-to-obligation mapping produced during onboarding and maintained after
- Automated patch, backup verification and coverage reports retained on a schedule
- Incident records written to a standard that satisfies both regulator and insurer
- Annual review against changes in local law and guideline
- Support during audits, inspections and client due diligence exercises
A necessary caveat. This page is a general orientation to obligations we commonly encounter, not legal advice. Applicability, thresholds and timelines depend on your specific circumstances, and the law changes. Take advice from a qualified legal practitioner on what applies to you — we work alongside your counsel rather than in place of them.
Where we stop
We are Solutions Specialists and analysts. We implement and evidence technical and organisational controls, and we support you through audits. We do not issue certifications, act as your external auditor, or provide legal opinions on regulatory interpretation.
Get in touch
Have a deadline?
Client mandate, regulator inspection or insurance renewal — tell us the date and we will work back from it.