Sri Lanka Financial Transactions Reporting Bill 2026 Explained

Sri Lanka Financial Transactions Reporting Bill 2026 Explained

 

Regulation Name: Gambling Prevention Act 2026
Date Of Publish: 01 Jul 2026
Region: Bangladesh
Agency: Government of Bangladesh

Sri Lanka’s Financial Transactions Reporting (Amendment) Bill, 2026: Key AML Compliance Changes You Need to Know

The Financial Transactions Reporting (Amendment) Bill, 2026, proposes the most comprehensive overhaul of Sri Lanka’s anti-money laundering (AML) framework since the Financial Transactions Reporting Act, No. 6 of 2006 came into force. Rather than introducing an entirely new law, the Bill modernizes the existing legislation by strengthening customer due diligence, expanding the powers of the Financial Intelligence Unit (FIU), introducing a mandatory risk-based approach, enhancing governance requirements, and aligning Sri Lanka’s AML regime more closely with evolving international standards.

For banks, financial institutions, designated non-financial businesses and professions (DNFBPs), and AML compliance professionals, the amendments signal a shift towards more proactive, intelligence-driven, and risk-based compliance. This article highlights the most significant amendments proposed under the Bill and explains what they mean for compliance teams.


At a Glance: Major AML Changes

AmendmentCompliance Impact
Financing of Proliferation added to the ActAML obligations now extend beyond money laundering and terrorist financing
Mandatory risk-based approachInstitutions must identify, assess and mitigate ML/TF/PF risks
Stronger Customer Due DiligenceEnhanced beneficial ownership verification and customer risk assessments
Anonymous accounts prohibitedStronger customer identification requirements
Enhanced record retentionSix-year retention with improved accessibility requirements
Expanded reporting obligationsClearer requirements for CTRs and STRs
Mandatory Compliance OfficerStronger internal governance
Independent Financial Intelligence UnitGreater supervisory and enforcement powers
National AML Committee establishedCentralized national AML/CFT policy coordination
Higher penalties and enforcementIncreased accountability for institutions and individuals

A Significant Expansion of Sri Lanka’s AML Framework

One of the most notable amendments is the expansion of the Act’s overall scope.

The existing Financial Transactions Reporting Act primarily focuses on combating money laundering and terrorist financing. The Amendment Bill broadens this framework by explicitly including financing of the proliferation of weapons of mass destruction (PF) within the objectives of the legislation. This change is reflected in the amended long title of the Act, which now requires institutions to undertake due diligence measures to combat money laundering, terrorist financing, and proliferation financing.

For compliance professionals, this is more than a wording update. It means institutions must expand their AML programmes to identify and mitigate proliferation financing risks alongside traditional financial crime risks. Customer screening, sanctions compliance, transaction monitoring, and risk assessments will increasingly need to consider proliferation financing indicators.


Mandatory Risk-Based AML Compliance

Perhaps the most operationally significant amendment is the complete replacement of Section 2, introducing a comprehensive risk-based approach for all reporting institutions.

Rather than applying identical controls to every customer, institutions will now be required to identify, assess, understand, and mitigate risks relating to:

  • Money laundering

  • Terrorist financing

  • Financing of proliferation of weapons of mass destruction

Institutions must assess risks associated with:

  • Customers

  • Countries and geographic exposure

  • Products and services

  • Delivery channels

The Bill also requires Boards of Directors or senior management to approve internal AML policies, procedures, and systems designed to manage identified risks. Importantly, these risk assessments cannot remain static—they must be reviewed periodically to ensure they remain current and effective.

This amendment places enterprise-wide AML risk management at the centre of every institution’s compliance programme and brings Sri Lanka’s framework closer to internationally recognised risk-based supervision.


Stronger Customer Due Diligence Requirements

The proposed amendments significantly strengthen customer due diligence (CDD) obligations.

Institutions will be required to perform CDD whenever they:

  • Establish a business relationship;

  • Conduct occasional transactions above prescribed thresholds;

  • Process qualifying wire transfers;

  • Suspect money laundering, terrorist financing, proliferation financing, or other unlawful activities; or

  • Have doubts regarding previously collected customer identification information.

The Bill further strengthens customer identification requirements by requiring institutions to:

  • Verify customer identity using reliable documents or data;

  • Verify individuals acting on behalf of customers;

  • Identify and verify beneficial owners;

  • Understand the purpose and intended nature of business relationships.

Another important change is the explicit prohibition on opening or maintaining anonymous, fictitious, or numbered accounts where the account holder cannot be properly identified.

Collectively, these provisions place greater emphasis on beneficial ownership transparency and customer verification, making it more difficult for criminals to exploit anonymous corporate structures.


Enhanced Due Diligence Based on Risk

The amendments formally distinguish between enhanced and simplified customer due diligence.

Where higher risks are identified, institutions will be required to conduct Enhanced Customer Due Diligence (EDD).

Conversely, simplified due diligence may be applied where money laundering or terrorist financing risks are assessed as low.

For proliferation financing risks, institutions must ensure that mitigation measures remain proportionate to the level of risk identified.

This flexible approach allows institutions to allocate compliance resources more effectively while maintaining stronger controls over high-risk customers and transactions.


Clearer Procedures When Customer Due Diligence Cannot Be Completed

The Amendment Bill also introduces greater clarity regarding situations where institutions cannot complete required due diligence.

If an institution cannot satisfy customer due diligence requirements, it must:

  • Decline to open the account;

  • Refuse to establish the business relationship;

  • Decline to perform the transaction; or

  • Terminate the existing relationship.

The institution must also consider filing a Suspicious Transaction Report (STR). However, where performing CDD could alert the customer and potentially constitute tipping-off, the institution should refrain from conducting CDD and instead immediately report the matter to the Financial Intelligence Unit.

These provisions provide clearer operational guidance for compliance officers managing higher-risk onboarding scenarios.


Stronger Record-Keeping and Ongoing Monitoring

The Bill modernizes record retention requirements by introducing clearer standards regarding the type, duration, and accessibility of records.

Institutions must retain:

  • Domestic and international transaction records;

  • Customer due diligence records;

  • Risk assessments;

  • Customer account files;

  • Business correspondence;

  • Reports submitted to the Financial Intelligence Unit.

Most records must now be retained for six years, although the Head of the Financial Intelligence Unit may direct institutions to retain records for longer periods where necessary.

The amendments also recognise electronic, machine-readable, audio, and video records, provided they can be reproduced when required for investigations or judicial proceedings.

Additionally, institutions must ensure customer information remains accurate and up to date through ongoing due diligence and regular review of existing records.


Expanded Reporting Obligations

Reporting requirements have also been strengthened.

Institutions must report qualifying:

  • Cash transactions; and

  • Electronic fund transfers

that exceed thresholds specified by the Minister. Different reporting thresholds may be prescribed for different categories of institutions.

Suspicious Transaction Reporting has also become more prescriptive.

Institutions must report suspicious or attempted transactions relating to unlawful activity, money laundering, terrorist financing, or proliferation financing as soon as practicable, and no later than two working days after forming the suspicion or receiving relevant information.

The Bill also provides greater flexibility regarding reporting formats, allowing reports through electronic means or other methods specified by the Head of the Financial Intelligence Unit.

Expanded Powers of the Financial Intelligence Unit

One of the most transformative aspects of the Amendment Bill is the strengthening of the Financial Intelligence Unit (FIU). While the FIU has long served as Sri Lanka’s central agency for receiving and analysing financial intelligence, the proposed amendments establish a more robust legal framework that enhances its operational independence, supervisory authority, and enforcement capabilities.

The Bill introduces a dedicated Part establishing the Financial Intelligence Unit under the Financial Transactions Reporting Act and clearly defines the powers, duties, and functions of the Head of the FIU. This provides greater legal certainty around the FIU’s role as Sri Lanka’s national AML/CFT authority and strengthens its position in overseeing compliance across reporting institutions.

The amendments also expand the FIU’s ability to:

  • Receive and analyse financial intelligence;

  • Issue rules, directions, guidelines, and circulars to reporting institutions;

  • Exchange information with foreign FIUs and competent authorities;

  • Cooperate with regulatory and supervisory authorities on a reciprocal basis; and

  • Strengthen domestic and international AML cooperation.

Perhaps more importantly, the Bill significantly enhances the FIU’s supervisory powers. Officers of the FIU are empowered to enter the premises of reporting institutions, inspect records, examine compliance programmes, and verify whether institutions are meeting their obligations under the Act. These inspection powers reinforce the shift from a reactive reporting framework to one based on ongoing regulatory supervision.

Another noteworthy amendment grants the Head of the Financial Intelligence Unit the authority to make rules covering a wide range of compliance requirements. These include customer identification standards, verification procedures, due diligence thresholds, and other operational requirements necessary for implementing the Act. This provides the FIU with greater flexibility to respond to evolving money laundering and terrorist financing risks without requiring frequent legislative amendments.

For AML compliance teams, these changes indicate that regulatory expectations are likely to evolve more rapidly through FIU-issued rules and guidance. Institutions will therefore need mechanisms to monitor new directions and update their internal AML frameworks accordingly.


Mandatory Appointment of Compliance Officers

The Amendment Bill also places greater emphasis on internal AML governance by making the appointment of a Compliance Officer a statutory requirement.

Rather than treating AML compliance as a shared operational responsibility, the proposed amendments require every reporting institution to designate a Compliance Officer responsible for overseeing compliance with the Financial Transactions Reporting Act. The introduction of a dedicated provision reflects the growing expectation that AML compliance should be embedded within an institution’s governance framework rather than managed as an administrative function.

Although the detailed responsibilities of the Compliance Officer will continue to be shaped by rules and directions issued by the Head of the FIU, the overall objective is clear—to ensure there is a designated individual accountable for coordinating AML controls, monitoring regulatory compliance, and acting as the primary liaison with the Financial Intelligence Unit.

In practice, institutions should expect Compliance Officers to play a central role in:

  • Overseeing the implementation of AML and counter-terrorist financing policies;

  • Monitoring customer due diligence and ongoing monitoring processes;

  • Reviewing suspicious transaction reporting procedures;

  • Coordinating regulatory inspections;

  • Supporting employee awareness and AML training programmes; and

  • Reporting compliance issues to senior management and the Board.

For many smaller financial institutions and DNFBPs, this amendment may require strengthening existing compliance structures or appointing dedicated AML personnel where such arrangements do not already exist.


Establishment of a National AML/CFT/PF Committee

Beyond institutional-level compliance, the Amendment Bill introduces an important governance reform at the national level through the establishment of the National Committee on Anti-Money Laundering, Countering the Financing of Terrorism and Financing of Proliferation of Weapons of Mass Destruction.

The Committee is intended to coordinate and oversee Sri Lanka’s national AML/CFT/PF policy and ensure a more unified approach across government agencies, regulators, law enforcement bodies, and financial sector stakeholders.

Its membership reflects a whole-of-government approach, bringing together senior representatives from key institutions including:

  • The Governor of the Central Bank;

  • Secretaries of ministries responsible for finance, foreign affairs, justice, defence, and public security;

  • The Attorney-General;

  • The Inspector-General of Police;

  • The Director General of the Commission to Investigate Allegations of Bribery or Corruption; and

  • The Head of the Financial Intelligence Unit, who serves as Secretary to the Committee.

The Committee is required to meet at least quarterly and is entrusted with several strategic responsibilities, including:

  • Conducting and overseeing national ML/TF/PF risk assessments;

  • Ensuring risk assessment findings are shared with competent authorities and reporting institutions;

  • Advising the Government on national AML/CFT/PF policies;

  • Coordinating implementation across stakeholders;

  • Monitoring progress against national AML strategies; and

  • Developing recommendations aligned with evolving FATF standards and emerging financial crime threats.

A particularly significant feature of the amendments is that the Committee may issue recommendations and directions to regulatory authorities and other stakeholders. Where those directions are not implemented, the matter may be escalated to the Cabinet of Ministers for appropriate action, reinforcing accountability at the national level.

For compliance leaders, this development signals stronger coordination between policymakers, regulators, and supervisory authorities. It also suggests that future AML reforms and supervisory priorities are likely to be guided by a more structured national risk assessment process rather than isolated regulatory initiatives.


Stronger Enforcement and Higher Penalties for Non-Compliance

Beyond strengthening preventive controls, the Financial Transactions Reporting (Amendment) Bill, 2026 significantly reinforces Sri Lanka’s AML enforcement framework. The proposed amendments introduce stricter supervisory oversight, enhanced administrative sanctions, higher monetary penalties, and broader accountability for both institutions and individuals. Collectively, these changes are designed to improve regulatory compliance and create stronger deterrence against financial crime.

Increased Supervisory Oversight

The Bill places greater responsibility on supervisory and regulatory authorities to actively monitor AML compliance rather than relying solely on institutions to self-report.

Regulators will be required to conduct regular risk-based examinations of reporting institutions to verify compliance with the Financial Transactions Reporting Act, as well as any regulations, rules, directions, guidelines, and circulars issued under it. Where non-compliance is identified, supervisory authorities must report these findings to the Financial Intelligence Unit (FIU). In sectors where no dedicated regulator exists, the FIU itself is empowered to conduct these examinations.

This amendment signals a shift toward a more proactive supervisory model, where institutions should expect increased regulatory scrutiny of their AML frameworks, customer due diligence processes, transaction monitoring systems, and governance arrangements.

Administrative Sanctions Become a Key Enforcement Tool

The Amendment Bill also strengthens the FIU’s ability to enforce compliance through administrative sanctions. Rather than relying exclusively on criminal proceedings, the revised framework allows regulatory action to address breaches of AML obligations more efficiently. The Bill specifically replaces the existing provisions relating to administrative sanctions to strengthen enforcement under the Act.

For reporting institutions, this means that deficiencies identified during supervisory examinations could result in regulatory actions even where criminal conduct is not established. As a result, maintaining effective internal controls and demonstrating ongoing compliance will become increasingly important.

Tougher Penalties Across Multiple Offences

The Bill substantially increases penalties for a range of offences under the Financial Transactions Reporting Act.

Several offences that previously attracted significantly lower penalties are now punishable by fines of up to LKR 10 million, imprisonment, or both, depending on the nature of the violation. These enhanced penalties apply to offences involving false information, failure to comply with regulatory requirements, obstruction of investigations, destruction or concealment of evidence, and other serious breaches of the Act.

The increase in penalties reflects Sri Lanka’s intention to strengthen deterrence and align enforcement measures more closely with international AML standards.

Stronger Border Cash Reporting Requirements

The amendments also revise provisions governing the movement of cash and bearer negotiable instruments across Sri Lanka’s borders.

Individuals entering or leaving the country with cash or bearer negotiable instruments exceeding thresholds prescribed under the Foreign Exchange Act must declare those amounts to the relevant authorities. Failure to comply constitutes an offence punishable by a fine of up to three times the value of the undeclared cash or bearer negotiable instruments, imprisonment for up to one year, or both. The undeclared assets may also be forfeited to the State.

These provisions reinforce Sri Lanka’s efforts to combat cross-border money laundering and illicit movement of funds.

Corporate Accountability Extended to Senior Management

Another notable amendment introduces explicit liability for offences committed by corporate entities.

Where an offence under the Act is committed by a company, partnership, or other body of persons, directors, partners, officers, and individuals responsible for the management and control of the entity may also be deemed liable unless they can demonstrate that the offence occurred without their knowledge or that they exercised due diligence to prevent it.

This provision significantly raises the accountability of senior management and reinforces the importance of establishing effective AML governance frameworks. Compliance can no longer be viewed solely as the responsibility of operational teams; Boards and senior executives must also ensure that adequate controls, oversight mechanisms, and compliance programmes are in place.

Expanded Rule-Making Powers for a Dynamic AML Framework

To support the effective implementation of the amended Act, the Bill empowers the Head of the Financial Intelligence Unit to issue detailed rules on a wide range of operational matters, including customer identification requirements, verification procedures, thresholds, and other compliance obligations.

This approach enables the regulatory framework to evolve more quickly in response to emerging money laundering, terrorist financing, and proliferation financing risks without requiring frequent legislative amendments. Institutions should therefore establish processes to monitor and implement new FIU rules and directions as they are issued.


The cumulative effect of these enforcement-related amendments is clear: Sri Lanka is moving toward a more risk-based, supervisory, and accountability-driven AML regime. Institutions that rely on periodic compliance reviews or outdated AML programmes may find it increasingly difficult to meet regulatory expectations. Instead, compliance teams should focus on building resilient governance structures, strengthening internal controls, and ensuring their AML frameworks can adapt to evolving regulatory requirements.

Read about the laws; click here.

Read about the product: Transact Comply

Empower your organization with ZIGRAM’s integrated RegTech solutions – Book a Demo