Financial services · August 2026
AI in Financial Services: What the FSC's Rules Require
Financial services is the one sector in Mauritius where deploying AI is not purely a commercial decision. The Financial Services Commission has set out expectations for the responsible use of AI across the sector, and they sit alongside the national FAIR framework rather than replacing it.
This is a practitioner's read of what those expectations mean operationally. It is general commentary, not regulatory advice, and a licensee should read the current instruments in full.
Human-in-the-loop is the load-bearing requirement
The principle doing the most work is human-in-the-loop: critical financial decision-making requires a point at which a person can intervene. The system may recommend; a human decides.
This is easy to state and easy to implement badly. A checkbox that a reviewer clicks through five hundred times a day is technically a human in the loop and practically an automation with extra steps. If you want the control to hold, three things have to be true:
- The reviewer can see why. An output with no reasoning attached cannot meaningfully be reviewed, only ratified.
- The reviewer has time. If throughput expectations assume the reviewer agrees, the control is decorative.
- Disagreement is recorded. A loop where nobody has ever overridden the system is evidence that the loop is not working, not that the model is perfect.
Model risk and drift
The second theme is model risk management, and specifically the expectation that licensees can detect model drift: the decline in a model's performance as the data and the economic environment move away from what it was built on.
Drift is the failure mode that catches firms out, because nothing breaks. The system keeps returning confident answers; they simply become less right. A firm that validated a model at deployment and never revalidated has no way of knowing where on that curve it currently sits.
Practically this means holding back a test set, re-running it on a schedule, and keeping the results. It is unglamorous and it is the difference between a governed model and a hopeful one.
Robotic and AI Enabled Advisory Services
If your system provides personalised advisory services through algorithms with limited human intervention, you are likely inside the Financial Services (Robotic and Artificial Intelligence Enabled Advisory Services) Rules 2021, which is a licensing question rather than a governance one.
The boundary matters commercially. A tool that helps your advisers prepare is a different regulatory proposition from a tool that advises your clients. Firms sometimes cross that line by accident, usually by adding a client-facing interface to something built as an internal aid.
What we would put in place first
- An inventory. Every model or AI-enabled process in use, what it decides or recommends, and who owns it. Most firms cannot produce this on request, and it is the first thing anyone will ask for.
- A held-back test set. Real cases with known answers, kept out of development, re-run on a schedule. This is your drift detector and your evidence.
- An override log. Where a human disagreed with the system and what happened next. This is the artefact that demonstrates the loop is real.
- A boundary note. A written view on whether each system is internal support or client-facing advice, and why. Write it before someone asks.
For the accounting and reporting side of finance rather than the regulated advisory side, see where the return in finance AI actually comes from, and our finance automation work.
Common questions
Does the FSC require a licence to use AI internally?
Using AI as an internal tool is generally a governance question rather than a licensing one. Licensing becomes relevant where the system provides personalised advisory services to clients through algorithms with limited human intervention, which falls under the Financial Services (Robotic and Artificial Intelligence Enabled Advisory Services) Rules 2021. The boundary is worth documenting before a client-facing interface is added to an internal tool.
What does human-in-the-loop actually require?
That a person can meaningfully intervene in critical decisions. For the control to be real rather than nominal, the reviewer needs the reasoning behind an output, enough time to consider it, and a recorded route to disagree. A review step nobody has ever used to override the system is evidence the loop is not functioning.
What is model drift and how do we detect it?
Drift is the decline in a model's performance as data and conditions move away from what it was built on. Nothing visibly breaks, which is what makes it dangerous. Detection means holding back a test set of real cases with known answers, keeping it out of development, re-running it on a schedule and retaining the results as evidence.
Can we use a general-purpose AI tool for regulated work?
Cautiously and with the same governance you would apply to any model. The specific risks are that general tools give no reproducibility guarantee between versions, may not tell you when the underlying model changes, and typically cannot show the reasoning behind an output. Each of those makes the human-in-the-loop and drift expectations harder to satisfy.
Do these expectations apply to Bank of Mauritius licensees too?
Banking supervision sits with the Bank of Mauritius rather than the FSC, so the applicable instruments differ. The underlying supervisory themes are broadly consistent across both, but a licensee should work from the instruments that apply to its own licence rather than assuming equivalence.
General commentary, not legal, regulatory or financial advice. · All notes