AI & Financial Services

AI Is Here. Is Your Organisation Ready to Govern It?

Reflections on artificial intelligence, responsible adoption, and what financial services professionals need to consider — now.

Nawshad Bhunnoo 8 min read June 2026
AI Governance and Financial Services — building trust, managing risk, driving value

Artificial intelligence is reshaping financial services at a pace that is difficult to overstate. The opportunities are real. So are the responsibilities that come with them — and in Mauritius, the regulator has now made its expectations clear.

Across the sector — from large institutions to boutique management companies — AI tools are being adopted to improve efficiency, reduce manual workloads, and sharpen decision-making. The direction of travel is clear and largely positive. But as adoption accelerates, one question keeps surfacing: are organisations building the governance frameworks to match?

In my view, this is the defining challenge for financial services professionals right now. Not whether to use AI — but how to use it responsibly, accountably, and with the right controls in place.

The Opportunity Is Genuine

For management companies administering trusts, foundations, GBCs, and authorised companies, AI holds real promise. Document processing, compliance monitoring, KYC workflows, client reporting — these are areas where AI can reduce friction, improve consistency, and free up time for higher-value work. Globally, the scale is already striking: HSBC, working with Google Cloud, runs an AI-powered transaction-monitoring system that screens over a billion transactions a month across tens of millions of accounts, detecting more financial crime while reducing false positives (HSBC, 2025; Ideas2IT, 2025). JPMorgan Chase has embedded AI across more than 450 use cases while maintaining formal risk-management practices (Lucidate, 2025).

Used well, AI does not replace professional judgement. It supports it. It allows practitioners to focus on the decisions that truly require human insight — and to serve clients better as a result.

The institutions that will scale AI well are those that govern it from the outset — not as an afterthought, but as a foundation.

The Governance Gap

The challenge is that AI adoption and AI governance are not always moving at the same speed. Tools are being deployed, workflows are being automated, and processes are being supported by AI — often before clear policies exist to define how this should happen, who is responsible, and what safeguards are in place.

This is not unique to any one organisation. It is a broad pattern across the financial services sector, and one that regulators globally are paying increasing attention to. The leading firms have responded by building dedicated governance structures: Microsoft, for instance, operates an Office of Responsible AI and an internal Responsible AI Standard built on six principles — fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability (Microsoft, 2025). HSBC has established an AI Centre of Excellence that unifies its responsible-AI, governance, and risk-management work under a single framework (Klover.ai, 2025). The message from supervisory authorities is consistent: governance must keep pace with adoption.

What This Means in Mauritius

For those of us working in the Mauritius global business sector, this is no longer a theoretical conversation. In September 2025, the Financial Services Commission (FSC) issued Fintech Series Guidance Notes No. 4 on the Responsible Use of AI in Financial Services, applying to insurance, wealth management and non-banking financial institutions, and covering both traditional and generative AI (FSC, 2025; Africa Legal, 2025). It sets out nine principles for the responsible use of AI: fairness and bias mitigation, transparency, accountability, privacy, security, environmental sustainability, human-centricity, continuous monitoring and evaluation, and compliance ethics (FSC, 2025).

An important point of nuance — and one worth getting right. The Guidance Notes are exactly that: guidance. The FSC states that the principles are matters that licensees are "advised to consider," and that the document "is not intended to serve as a prescriptive or exhaustive checklist" (FSC, 2025). In other words, the AI governance principles are encouraged, not imposed as a standalone rule.

But that is not the end of the analysis, and here is where careful reading matters. The Guidance expressly states that it "neither derogates nor restricts the powers vested upon the Commission by statute and should be read together with the relevant Acts and the Data Protection Act 2017" (FSC, 2025). Those underlying obligations are binding. The Data Protection Act 2017 is law — including Section 38, which governs automated decision-making and profiling that produce legal or similarly significant effects. And for firms holding a Robotic and AI-Enabled Advisory Services licence, the Financial Services (Robotic and Artificial Intelligence Enabled Advisory Services) Rules 2021 require licensees to maintain adequate policies, processes and controls, and a robust framework for the design, monitoring and testing of their algorithms (FSC, 2021).

The Distinction That Matters

The FSC's AI governance principles are encouraged. The data-protection and conduct obligations they rest upon are mandatory. A licensee that treats the guidance as optional, while overlooking the binding law beneath it, has misread the position.

Four Pillars of Responsible AI Adoption

  • 1
    Know what you are usingBuild a clear inventory of AI tools in use across your organisation. Understanding your current footprint is the starting point for everything else.
  • 2
    Put a policy in placeA concise, practical AI policy — covering permitted uses, data handling, and approval processes — gives your teams clarity and your organisation protection, and maps naturally onto the FSC's nine principles.
  • 3
    Assign accountability clearlyAI governance requires named owners. Boards and senior management remain responsible for outcomes generated by AI systems — whether built in-house or supplied by a third party. Those questions need answers before deployment, not after.
  • 4
    Keep humans in the loopFor decisions that affect clients, regulatory compliance, or financial outcomes, human oversight is not optional. Professional accountability does not transfer to an automated process.

The Fiduciary Standard Remains Unchanged

For those of us working in trust administration, corporate governance, and client-facing fiduciary roles, this point deserves emphasis. The duty of care owed to clients has not been altered by the emergence of AI. The professional and regulatory obligations that define our work remain exactly where they have always been.

What AI changes is the way some of those obligations are fulfilled — not the standard to which they are held. Governance frameworks, policies, and oversight mechanisms ensure that the two remain aligned.

Approached thoughtfully, AI is a genuine asset for the financial services profession. The goal is to embrace it with the same rigour and care that we apply to every other aspect of our work — and, in Mauritius, to recognise that the regulator has now set out what "responsible" looks like.

References

Africa Legal (2025) Mauritius: harnessing the benefits of AI in financial services while protecting consumers. Available at: https://www.africa-legal.com/opinion/mauritius-harnessing-the-benefits-of-ai-in-financial-services-while-protecting-consumers/123590 (Accessed: 18 June 2026).

Financial Services Commission (2021) Financial Services (Robotic and Artificial Intelligence Enabled Advisory Services) Rules 2021. Port Louis: FSC Mauritius. Available at: https://www.fscmauritius.org/media/101852/annex-1-128_the-financial-services-robotic-and-artificial-intelligence-enabled-advisory-services-rules-2021.pdf (Accessed: 18 June 2026).

Financial Services Commission (2025) Fintech Series Guidance Notes No. 4: Responsible Use of AI in Financial Services. Port Louis: FSC Mauritius. Available at: https://www.fscmauritius.org/media/206401/guidelines-on-responsible-use-of-ai.pdf (Accessed: 18 June 2026).

HSBC (2025) Transforming HSBC with AI. Available at: https://www.hsbc.com/who-we-are/hsbc-and-digital/hsbc-and-ai/transforming-hsbc-with-ai (Accessed: 18 June 2026).

Ideas2IT (2025) AI Governance in Finance: Key Strategies and Challenges. Available at: https://www.ideas2it.com/blogs/ai-governance-in-finance (Accessed: 18 June 2026).

Klover.ai (2025) HSBC's AI Strategy: Analysis of AI Dominance in Financial Services. Available at: https://www.klover.ai/hsbc-ai-strategy-analysis-of-ai-dominance-in-financial-services/ (Accessed: 18 June 2026).

Lucidate (2025) Beyond the Pilot: How JPMorgan, Goldman Sachs, and HSBC Are Scaling AI to Enterprise Production. Available at: https://www.lucidate.co.uk/post/beyond-the-pilot-how-jpmorgan-goldman-sachs-and-hsbc-are-scaling-ai-to-enterprise-production (Accessed: 18 June 2026).

Microsoft (2025) Responsible AI Principles and Approach. Available at: https://www.microsoft.com/en-us/ai/principles-and-approach (Accessed: 18 June 2026).

Republic of Mauritius (2017) Data Protection Act 2017. Port Louis: Government of Mauritius.

The right question to ask today.

Does your organisation have a clear, written policy on how AI tools are used — and by whom? If not, that is where to start.

Get in Touch
AI Governance Management Companies Data Protection Financial Services Mauritius Fiduciary Duty GBC Trust Administration
Nawshad Bhunnoo

Nawshad Bhunnoo

Corporate Services & Private Wealth · Mauritius

A seasoned professional with over 10 years of experience in financial and corporate services, holding an MSc in Finance and Investment. Specialising in Global Business Companies, Trusts, Foundations, and regulatory compliance across jurisdictions.

Connect on LinkedIn →