Back to Bizweek
SEARCH AND PRESS ENTER
Latest News

Mauritius is not a place where you can hide illicit funds

Shawn Robert Duthie, Director at Control Risks - South Africa

Financial crime does not disappear under stronger regulation – it evolves. For Shawn Robert Duthie, Director at Control Risks in South Africa, financial crime is a moving target and the real test for Mauritius is whether criminals believe they can still exploit its financial system without consequences. Having emerged from the FATF grey list, Mauritius has strengthened its AML/CFT framework, but the next challenge is effectiveness, according to Shawn Duthie. From illicit cross-border flows and prediction markets to AI-driven crime and opaque ownership structures, Shawn Duthie warns that “staying ahead requires constant adaptation, intelligence and enforcement.”

You argued that stronger regulation does not automatically reduce financial crime risk, but often changes how it manifests. How should financial institutions adapt when criminals continually shift towards the path of least resistance? 

I think financial institutions have to do the same thing, that is, to adapt as well.

Like I said, there is never a point where you can say, “we have our controls in place, we’re done and we can move on to something else.” Compliance departments have to constantly adapt and be prepared for what comes next.

If your compliance department is not on top of developments in AI, finance, crypto, blockchain and everything else that is emerging — and is not trying to stay two years ahead — that is where the stumbling block lies.

Criminals and people involved in illicit activities are ahead of the game. Financial institutions therefore have to do the same.

FATF assessments are increasingly focused on effectiveness rather than formal compliance. So what concrete outcomes should Mauritius demonstrate to prove that its AML/CFT framework is delivering results? 

I think Mauritius is actually in a better position than South Africa, for example, and even Namibia, because it really took the grey-listing experience to heart and made a lot of changes.

Mauritius was, I believe, one of the fastest jurisdictions to come off the grey list — in about a year and a half. South Africa was on it for around three years. So, obviously, the controls are in place and things are working.

What they will want to see is whether behaviour has changed. They want to see that people no longer look at Mauritius and think, “We could go there and perhaps do something.”

Instead, they need to know: “Mauritius is not a place where we can do this because, if you do, you will be caught, charged and punished.”

As long as Mauritius continues on the same path, I think that, even with the peer review in early 2027, it will probably be fine.

You warned that Mauritius’ role as a financial bridge between Africa and Asia is both an advantage and a vulnerability. Which cross-border financial crime risk should the country be watching more closely? 

I mean, it is obviously hard to kind of pinpoint just one. I think where the issue is going to be is the wider aspect of financial crime. So there are obviously, I think, probably quite a few transactions between Dubai and Mauritius, for example, and probably the vast majority of these are completely legal.

But what you want to then look at is what is the wider story behind those transactions. I mean, I use the example of Zimbabwean gold smuggling, but I’m sure if you looked at diamond smuggling or copper smuggling or cobalt smuggling from Congo or Zambia, through Rwanda into Dubai, back to Mauritius and then back into the continent, I mean, there are all these tiny areas that compliance officials are going to have to look into. 

It is not just going to be what we have to monitor Dubai, they monitor us, that’s it. You have to look at the wider scheme of what’s happening in the broader ecosystem of the financial transaction.

Banks have traditionally been at the centre of financial crime controls, but attention is shifting towards lawyers, accountants, real estate professionals, corporate service providers, and virtual asset businesses. Where do you currently see the most significant regulatory gaps? 

I think the biggest regulatory gaps are going to be in those areas. 

People do not always recognise that lawyers and attorneys can be important cogs in financial crime. They can obviously become involved in these activities.

Real estate has also long been recognised as an easy way to hide and layer funds, although that is becoming more difficult.

I think the bigger issue now is new technology — digital money transfers, cryptocurrency, online gambling and prediction markets such as Polymarket.

Some prediction markets argue that they are not really betting and therefore should not be regulated in the same way. But the mechanism is similar: you can put money in, including crypto, win, and then take money out.

That creates another avenue for people to layer or use illicit funds and hide them from regulators and banks.

And, as I said, this is never going to end. Criminals are always going to find a different way to do this. At the moment, these are the areas that need greater regulatory attention.

You identified unregulated prediction platforms as a potential means of layering and concealing illicit funds. How serious is this emerging risk? Should such platforms be regulated in the same way as gambling or virtual asset services?

I think so, yes. I mean, I think at the moment it might be that it is not as big a platform as online gambling, for example. I mean, particularly on the continent. 

At the moment, prediction markets may not be as significant as online gambling, particularly in Africa. They are still relatively limited here. In the United States, they are very big, and they are also significant in Latin America. In Europe, they are growing.

But people will realise the amount of money that can be made from them and the different ways in which they can be used. It is only a matter of time before that becomes more significant.

Yes, absolutely, they should be treated in the same way we look at online gambling or crypto.

That does not mean we have to stop these activities. We simply have to regulate them.

Beneficial ownership registers have improved transparency, yet criminals can still conceal who actually controls a company. What investigative techniques are most effective in uncovering the individuals operating behind nominees and complex corporate structures? 

It is difficult, because unless someone is sloppy, if they do not put their name down, there may not be a paper trail.

If you have a politically exposed person or someone involved in crime, they are not going to say, “I need that legal shareholder to show that I am the owner.” It is simply not going to happen.

So, when you are looking at a company, you ultimately have to ask: who is really in control? That is something that is never necessarily done on paper. This is where a network of human sources can be extremely important. You can reach out widely, speak to people discreetly and find out what the allegations are.

It is rare that someone will simply say, “It is this person, and here is all the evidence.” Instead, you get little allegations and small nuggets of information. You may get only a first name or a last name.

Those individual data points can then widen the investigation, leading to more data points and further investigation.

At the end of the process, it is rare to have a smoking gun where you can say, “Here is the absolute evidence that this person owns that mine.” Often, it is based on probability.

If four or five independent sources are all saying the same thing, the probability of it being true becomes much higher. That is then what we would advise the client.

At Control Risks, we combine open-source intelligence with human intelligence when investigating suspicious individuals and entities.

At what point should an institution move beyond routine database screening and commission enhanced due diligence? 

For banks and corporate secretaries, there has to be a risk-based approach. You do not want to spend a huge amount of money conducting extensive due diligence on every single client. But if an issue is identified during onboarding, there has to be a decision: either say no to the client or go deeper into the relationship.

There should also be a link between the level of due diligence performed and any subsequent suspicious activity report or suspicious transaction report.

If you only conducted a basic World-Check screening when onboarding a client and subsequently identify suspicious transactions, you should go back and ask why.

There should be guidelines and controls in place so that when you onboard someone, you have sufficient confidence that they are legitimate.

And if an SAR subsequently emerges, you should reassess the relationship and determine whether further due diligence is required and whether you should continue with that client.

You say that AI has democratised digital crime by giving people with limited technical expertise the ability to create malicious programmes. How should financial institutions rethink their cybersecurity and financial crime controls in response?

As I said before, they have to stay ahead of the game.

One way of doing this is through penetration testing, or what we call a red team — having someone continually try to break into your systems. When they find a way in, you identify the vulnerability and fix it.

Obviously, this is becoming more difficult with AI. We now have systems such as Claude that can be used to break into things very quickly, potentially much faster than a human could.

Ultimately, I think that in the future a human may not be enough to stop it. It could be another AI, specifically programmed and trained to defend against sabotage attacks. That is probably the future we are looking at.

Things are going to move so quickly that you will need something else moving just as quickly to defend against them. The challenge is always going to be: how do you stay ahead of the game?

You concluded that the most serious risks increasingly sit within apparently legitimate activities. So, what warning signs can help businesses distinguish an ordinary commercial transaction from one that forms part of a wider financial crime network?

There are obviously red flags that appear throughout the process. If you  are conducting due diligence or a suspicious transaction report emerges, that tells you that something may need to change.

It could be a link to a PEP, a high-risk jurisdiction, or transactions that repeatedly sit just below a reporting threshold. But there is also an element of gut feeling.

If you do this for long enough, you see something come across your desk and think, “Something is not right here.” We have encountered this during investigations. We have looked at something and said, “We need to go deeper. Something just doesn’t add up.”

That is where I see the advantage of having skilled and experienced investigators, rather than relying solely on AI or people who have only been doing this for a year or two.

There are warning signs you are trained to identify, but ultimately there is also a gut feeling that tells you: we need to go deeper. There is something here that requires further investigation.

Skip to content