FSC Fintech Series Guidance Notes 4, responsible use of artificial intelligence in financial services
Financial Services Commission (Mauritius), Fintech Series Guidance Notes No. 4, September 2025
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.fscmauritius.org/media/206401/guidelines-on-responsible-use-of-ai.pdfGuidance, not a law: the Financial Services Commission of Mauritius's reading of Data Protection Act 2017, automated individual decision making. It binds nobody by itself; the law it reads does.
Guidance on an AI sector rules rule, addressed to private bodies.
- Enforcement body
- Financial Services Commission of Mauritius
- Instrument type
- guidance published by a regulator
- Obligation class
- Governance, Disclosure, DPIA
- Audit expectation
- continuous
- Who audits it
- Self
As of .
What the regulator expects
- It reaches you if you are licensed by the Financial Services Commission of Mauritius as an insurer, a wealth manager or another non-bank financial institution (NBFI): the Commission says that, in accordance with section 38 of the Data Protection Act 2017, you are required to ensure that data subjects are informed that automated decision-making processes exist, that meaningful information is provided on their logic, criteria and significance, and that individuals can obtain human intervention, express their views and contest the outcome.
- The Commission says that, in line with section 34 of the Data Protection Act 2017, you must conduct a Data Protection Impact Assessment before implementing any AI system likely to present a high risk to the rights and freedoms of data subjects.
- The Commission advises you to include human oversight in critical decision-making processes and to define clearly who is responsible for an AI system across its entire life cycle, without changing the supervisory expectations that already apply to your governance.
- The Commission advises you to identify and mitigate biases in AI algorithms and datasets, and to perform regular audits to assess and address biases in AI models.
- The Commission advises you to give customers clear and understandable information on how algorithms are used for decision-making, a clear channel to seek information and raise concerns, and an effective grievance redress mechanism for complaints about AI-driven decisions.
- The Commission advises you to establish procedures for monitoring AI systems and clear accountability for AI-related errors or malfunctions, and to run ongoing monitoring and evaluation of the ethical and societal impact of your AI systems.
- The Commission says that if you use third-party AI systems you should secure sufficient documentation and assurances on model behavior and compliance, and where appropriate consider system redundancy, mechanical monitoring of AI inputs and outputs, and kill switches that can deactivate the AI system under predefined conditions.
- The Commission says robustness testing should be treated as a continuous process, so that you adapt your testing strategies as AI technologies evolve.
What this law does
The note is titled Fintech Series Guidance Notes 4 and is dated September 2025. The Commission says the note explores key considerations on the use of artificial intelligence in insurance, wealth management and non-bank financial institutions, with an emphasis on both consumer protection and best practices. The note says its objective is to assist insurance, wealth management and non-bank financial institutions by outlining sound practices.
The note says it is not intended to serve as a prescriptive or exhaustive checklist. The note sets out nine key and non-binding principles for the responsible and ethical use of AI technologies by licensees. The note says it neither derogates nor restricts the powers vested upon the Commission by statute and should be read together with the relevant Acts and the Data Protection Act 2017.
The note says that, in accordance with section 38 of the Data Protection Act 2017, licensees are required to ensure that data subjects are informed of automated decision-making processes, that meaningful information is provided on their logic, criteria and significance, and that mechanisms let individuals obtain human intervention, express their views and contest the outcome.
The note says that, in line with section 34 of the Data Protection Act 2017, licensees must conduct a Data Protection Impact Assessment before implementing any AI system likely to present a high risk to the rights and freedoms of data subjects. The note describes the nine principles as high-level principles that licensees and their associated stakeholders are advised to consider when developing, deploying and using AI technologies.
The note says the principles are expected to contribute progressively and in a non-binding way to a culture of ethical conduct and compliance amongst licensees. The note says that the development, implementation and oversight of AI systems across their life cycle should not change existing supervisory expectations. The note says licensees should establish accountability throughout the AI system lifecycle by clearly defining responsibility for the AI system across its entire life cycle.
Its seventh principle, human-centricity, calls for the inclusion of human oversight in critical decision-making processes. Its first principle, fairness and bias mitigation, calls for identifying and mitigating biases in AI algorithms and datasets and for regular audits to assess and address biases in AI models.
Its second principle, transparency, calls for clear and understandable information on how algorithms are used for decision-making, a clear channel for customers to seek information and raise concerns, and an effective grievance redress mechanism for complaints about AI-driven decisions. Its third principle, accountability, calls for procedures for monitoring AI systems and clear accountability in the event of AI-related errors or malfunctions.
Its eighth principle calls for ongoing monitoring and evaluation processes to assess the ethical and societal impact of AI systems over time. The note says firms using third-party AI systems should secure sufficient documentation and assurances regarding model behavior and compliance.
For AI systems sourced from third parties, the note says insurers should where appropriate consider system redundancy, monitoring of AI inputs and outputs through mechanical controls, and kill switches that can deactivate the AI system under predefined conditions. The note says robustness testing should be treated as a continuous process, allowing insurers to adapt their testing strategies as AI technologies evolve.