Acts
Convention on the Suppression of Terrorist Financing Act, No. 25 of 2005
Convention on the Suppression of Terrorist Financing (Amendment) Act, No. 41 of 2011
Convention on the Suppression of Terrorist Financing (Amendment) Act, No. 3 of 2013
Convention on the Suppression of Terrorist Financing (Amendment) Act, No. 18 of 2026
Prevention of Money Laundering Act, No. 5 of 2006
Prevention of Money Laundering (Amendment) Act, No. 40 of 2011
Prevention of Money Laundering (Amendment) Act, No. 16 of 2026
Financial Transactions Reporting Act, No. 6 of 2006
Financial Transactions Reporting (Amendment) Act, No. 17 of 2026
Regulations
Prevention of Terrorism (Proscription of Extremist Organizations) Regulations No. 1 of 2019.
Order under regulation 75(1) of the Emergency (Miscellaneous Provisions and Powers) Regulations No. 1 of 2019
Suspicious Transactions (Format) Regulations of 2017
Financial Transactions Reporting Regulations No. 1 of 2008
Rules
YEAR 2018
- Amendments to the Financial Institutions (Customer Due Diligence) Rules, No. 1 of 2016 – Extraordinary Gazette No 2092/02, October 08 of 2018
YEAR 2016
- Financial Institutions (Customer Due Diligence) Rules, No. 1 of 2016 – Extraordinary Gazette No 1951/13, January 27 of 2016
Directions
Circulars
YEAR 2026
- Circular 03/2026 – Application of Enhanced Due Diligence (EDD) measures and countermeasures in respect of jurisdictions identified by the Financial Action Task Force (FATF) as higher-risk jurisdictions
- Circular 02/2026 – Certification of Database Screening Against Sanctioned Individuals/Entities
- Circular 01/2026 – Review and Update of Institutional Risk Assessments in line with the National Money Laundering, Terrorist Financing and Proliferation Financing Risk Assessment 2024/25
YEAR 2024
YEAR 2022
- Circular 04/2022 – Authenticating customer identification details through the Department of Immigration and Emigration
- Circular 02/2022 – Further information requested on Suspicious Transaction Reports (STRs)
- Circular 01/2022 – Amendment to the Guidelines for Financial Institutions on CCTV Operations for AML/CFT Purposes, No. 2 of 2021
YEAR 2021
- Circular 03/2021 – Additional measures to mitigate the emerging Money Laundering/ Terrorist Financing risks during the third wave of the COVID-19 Pandemic
- Circular 02/2021 – Trends in Foreign Currency Outflows via ATMs: Cash withdrawals in Overseas
- Circular 01/2021 – Implementation of AML/CFT measures on parties involved with online payment platforms
YEAR 2020
- Circular 03/2020 – Financial Institutions are advised to be vigilant to emerging Money Laundering/ Terrorist Financing risks
- Circular 02/2020 – Extraordinary Measures of Extending the Deadline for Submission of Threshold Reports – Second Extension
- Circular 01/2020 – Extraordinary Measures of Extending the Deadline for Submission of Threshold Reports
Guidelines
YEAR 2021
YEAR 2019
YEAR 2018
Financial Institutions & Designated Non-Finance Businesses
- Guidelines on Implementing United Nations (Sanctions in relation to Iran) Regulations No. 1 of 2018, No. 7 of 2018
- Guidelines on Implementing United Nations (Sanctions in relation to Democratic People’s Republic of Korea) Regulations of 2017, No. 5 of 2018
Financial Institutions
Appointing a Compliance Officer
In terms of Section 14 of the FTRA, every FI, must appoint a Compliance Officer at senior management level. The CO is responsible for ensuring compliance with the FTRA and related regulations.
All appointments or changes to the Compliance Officer must be notified to the Director, FIU, by submitting the CO Declaration Form, duly completed.
Submission Address:
Director,
Financial Intelligence Unit,
Central Bank of Sri Lanka, Colombo 01
Email: fiu@cbsl.lk
Conducting Customer Due Diligence
Under Part II of the CDD Rules for Financial Institutions, FIs are required to carry out CDD when:
- entering into business relationships;
- providing money and currency changing business for transactions involving an amount exceeding rupees two hundred thousand or its equivalent in any foreign currency;
- providing wire transfer services as referred to in Rules 68 to 83;
- carrying out occasional transactions involving an amount exceeding rupees two hundred thousand or its equivalent in any foreign currency where the transaction is carried out in a single transaction or in multiple transactions that appear to be linked;
- the Financial Institution has any suspicion that such customer is involved in money laundering or terrorist financing activities, regardless of amount; or
- the Financial Institution has any doubt about the veracity or adequacy of previously obtained information.
In addition to the CDD requirements under Rule 27 following minimum information to be collected includes:
- Source of earning;
- Purpose of the account or transaction;
- expected monthly turnovers;
- expected mode of transactions (ex; cash, cheque, etc.);
- expected type of counterparties (if applicable)
Customer identity must be verified using reliable, independent source documents or information before establishing a business relationship.
Customer Risk Profiling
As per Rule 8 of the CDD Rules for Financial Institutions, FIs must categorize customers based on risk levels. Factors include the customer profile, geography, products and services used, transaction patterns, and delivery channels.
Enhanced Customer Due Diligence (ECDD)
Rule 27(2) of the CDD Rules requires FIs to apply ECDD measures for higher-risk categories, such as Politically Exposed Persons (PEPs), non-face-to-face relationships, or customers assessed as high risk. ECDD includes:
- Obtaining senior management approval;
- Collecting additional information on the customer and business relationship;
- Updating customer information more frequently;
- Monitoring transactions more closely.
Sanctions Screening
As a member of the United Nations, Sri Lanka is obliged to comply with the Resolutions issued by United Nations Security Council (UNSC). As per the United Nations Act No 45 of 1968, the Minister of Foreign Affairs has issued the following Regulations promulgating such resolutions of the UNSC related to Terrorist Financing and Proliferation Financing.
- The United Nations Regulations No. 01 of 2012
- The United Nations Regulations No. 02 of 2012
- United Nations (Sanctions in relation to Democratic People’s Republic of Korea) Regulations of 2017
- United Nations (Sanctions in relation to Iran) Regulations No. 1 of 2018
Accordingly, Financial Institutions have the obligation to screen their customers and implement financial restrictions/ financial sanctions by freezing all funds, financial assets and economic resources owned or controlled directly or indirectly by individuals or entities designated by the UNSC or persons acting on their behalf.
Record Keeping
In accordance with Sections 4 of the FTRA and Part IV of the CDD Rules for Financial Institutions:
- FIs are required to maintain all relevant records, including account files, business correspondence, and documents obtained during the CDD process, such as identification documents and results of analysis undertaken.
- Records must be accurate, complete, and up to date.
- Records must be retained for a minimum of six years from the date of the transaction or the termination of the business relationship.
- Where records are subject to ongoing investigations, litigation, or are required by law enforcement or regulatory authorities, such records must be retained until the institution is formally informed that they are no longer required.
Reporting Suspicious Transactions
A suspicious transaction is a completed or an attempted transaction where there are reasonable grounds to suspect that the transaction is related to a money laundering (ML), terrorist financing (TF) or an unlawful activity.
A Suspicious Transaction Report (STR) is a report submitted to the FIU under the Section 7 of the FTRA by any Institution regarding a suspicious transaction. Institution means, any person or body of persons engaged in or carrying out any finance business or designated non-finance business.
An institution shall submit an STR as soon as practicable, after forming the suspicion or receiving information, but no later than two working days thereafter.
The FIU has provided Money or Value Transfer Service Providers with access to the goAML system for submitting STRs.
Reporting Threshold Transactions
As per Section 6 of the Financial Transactions Reporting Act No. 6 of 20026 (FTRA) and the Financial Transactions Reporting Regulations No. 1 of 2008, Financial Institutions are required to report to the Financial Intelligence Unit (FIU) any transaction in cash or any electronic funds transfer at the request of a customer, where the amount of such transfer exceeds Rupees One Million (Rs. 1,000,000) or its equivalent in any foreign currency
Such threshold transactions are required to be reported to the FIU using the goAML system as per the guidelines and manuals provided.
Providing Information for Information Requests
Under Section 15(1)(b) of the FTRA, the FIU may request information from Financial Institutions and Designated Non-Finance Businesses and Professions (DNFBPs). Such requests support:
- The analysis of STRs, and
- Investigations of ML/TF or other unlawful activities involving any person or entity.
Institutions are legally required to provide the requested information without delay.







