Banks and finance companies will face a tighter customer due diligence (CDD) framework requiring continuous transaction monitoring and fresh reviews when customer profiles materially change, as the Financial Intelligence Unit (FIU) prepares new rules following the overhaul of the country’s anti-money laundering (AML) regime.
FIU Director General Dr. Subhani Keerthiratne said the new framework would move CDD beyond checks conducted when a customer is first onboarded, requiring financial institutions to monitor transactions throughout the business relationship and respond to material changes in ownership, control, directors, and business activity.
The changes assume added significance amid scrutiny of banking controls following recent alleged frauds involving financial institutions and questions over transactions linked to imports for which goods allegedly did not arrive. Dr. Keerthiratne did not link the new rules to individual cases.
She was speaking at a forum titled ‘The Changes to Sri Lanka’s Anti-Money Laundering Regime,’ organised by Corporate Management Consultants headed by Malik Cader.
Dr. Keerthiratne said institutions would have to identify and verify customers and beneficial owners, understand the purpose of business relationships and accounts, and conduct ongoing due diligence and transaction monitoring.
‘So it is not a one-time exercise at the onboarding, it is a continuous responsibility,’ she said.
The forthcoming rules will introduce what Dr. Keerthiratne described as an ‘event-driven review,’ separate from periodic CDD reviews.
She said a material change in a customer’s profile or relationship, including changes to ownership, control, directors, or business activity, would require the institution to conduct a fresh review.
The regime will apply different levels of scrutiny according to risk. High-risk customers will be subject to enhanced and more frequent due diligence, while simplified CDD and less frequent periodic reviews could apply to lower-risk customers.
Dr. Keerthiratne said a high-risk customer could face an annual CDD update, compared with a review once every three years for a lower-risk customer, although an event-driven review could be triggered between those periods.
The rules will also set out what institutions should do when the required due diligence cannot be completed.
‘If you cannot complete CDD, if it is a new customer, you cannot onboard them. If it is an existing customer, you cannot continue with the transaction and also you cannot continue with the business relationship,’ she said.
Dr. Keerthiratne said institutions terminating or declining a customer relationship should also consider filing a Suspicious Transaction Report (STR).
Where undertaking CDD itself risks alerting a customer after suspicions of money laundering, terrorist financing, or proliferation financing arise, she said the institution should not pursue the CDD process and should instead file an STR with the FIU.
The framework formally introduces a risk-based approach, requiring institutions to assess their exposure to money laundering, terrorist financing, and proliferation financing and direct compliance resources towards areas of higher risk.
Dr. Keerthiratne said institutions would be expected to undertake enterprise-wide risk assessments, establish policies and controls, conduct enhanced due diligence where necessary, monitor transactions, and maintain mechanisms for reporting suspicious transactions without tipping off customers.
The FIU expects to issue the new CDD rules by mid-September. Dr. Keerthiratne said they had been finalised and referred to the Legal Draftsman, pending sector comments.
Existing separate CDD rules for financial institutions and insurers will be combined, with the new framework covering financial institutions, the insurance sector, and virtual asset service providers. A separate CDD rule will apply to designated non-financial businesses and professions.
The tougher framework is backed by a sharp increase in sanctions. Dr. Keerthiratne said the maximum monetary penalty for a single Anti-Money Laundering and Combatting the Financing of Terrorism (AML/CFT) compliance breach had increased from Rs. 1 million to Rs. 100 million, while a second instance could attract a penalty of up to Rs. 200 million.
The amended framework also provides for sanctions including cease-and-desist orders, public statements, and recommendations to sector regulators for administrative action such as suspension or cancellation of a licence.
The changes come ahead of Sri Lanka’s third Mutual Evaluation of its AML/CFT framework. Dr. Keerthiratne said international assessors would arrive on 26 October for a two-week onsite assessment ending on 6 November, which would be the cut-off date for measures to be considered in the current assessment.
Sri Lanka has already submitted its risk and context material, technical compliance report covering the 40 Financial Action Task Force (FATF) recommendations, and its effectiveness report covering 11 immediate outcomes.
Dr. Keerthiratne recalled that Sri Lanka was placed on the FATF grey list in November 2017 following its previous Mutual Evaluation and was subsequently blacklisted by the European Union. She said correspondent banking relationships were affected, while the consequences could extend to sovereign and credit ratings, international borrowing risk premiums, reinsurance costs, and foreign investment.
‘The bottom line is very clear. We cannot go back to the grey list,’ she said.
With the new CDD rules expected by mid-September, institutions would have only four to five weeks to put them into practice before the onsite assessment.
‘However, having the legal framework is not sufficient. We have to implement them,’ she said.