TRW KNOWLEDGE · LEGAL INFORMATION

Understanding Bangladesh Banking Sector Regulations: Bangladesh Legal Guide (2026)

The banking sector is central to Bangladesh’s economy and is governed by a layered regulatory framework designed to protect depositors, promote financial stability and support fair competition. This guide summarizes key legal structures, supervisory approaches, licensing steps and practical compliance measures for banks and financial institutions.
Originally published 25 May 2026

Introduction

The banking system in Bangladesh performs a wide range of economic and financial functions: mobilising savings, providing credit, facilitating payments and supporting trade. Regulation of banking activity aims to preserve systemic stability, protect consumer interests, reduce the risk of financial crime and align domestic practice with international supervisory expectations. This article explains the principal regulatory themes affecting banks and non-bank financial institutions, outlines a step-by-step approach to licensing and ongoing compliance, and summarises practical measures organisations commonly use to manage regulatory risk.

How to use this guide

This document provides legal information intended to help managers, compliance officers, in-house counsel and external advisers understand the main regulatory considerations in the Bangladesh banking sector. It is not legal advice. Readers should consult their own legal advisers about specific transactions and regulatory questions, and may wish to engage specialist teams within TRW Law Firm. For practice-area information, see our /our-practices/ pages and the firm overview at /our-firm/.

Legal and institutional framework

Regulation and supervision in Bangladesh are exercised through a combination of statutes, central bank rules, regulatory circulars and prudential guidelines. The central bank plays a primary supervisory role, issuing standards and monitoring compliance. Key components of the framework include licensing and entry rules, capital and liquidity requirements, governance and reporting obligations, consumer protection measures, and specific regimes addressing financial crime risk and digital operations. Entities operating in cross-border contexts should coordinate bank regulatory considerations with foreign direct investment and tax planning teams; see /foreign-direct-investment-lawyers/ and /tax-lawyers/ for related topics.

Core regulatory pillars

Regulatory regimes for banks typically rest on a set of core pillars. Each pillar is intended to reduce a category of operational or systemic risk and to promote market confidence.
  • Prudential safety and soundness: capital adequacy, leverage limits and liquidity requirements ensure institutions can withstand shocks and meet short-term obligations.
  • Corporate governance and risk management: board responsibilities, internal controls, audit and risk oversight promote accountable management and prudent decision-making.
  • Conduct, consumer protection and disclosure: rules on fair treatment of customers, transparency of terms and handling of complaints protect end-users and support trust in the financial system.
  • Anti-money laundering / countering the financing of terrorism (AML/CFT): due diligence, suspicious transaction reporting and transaction monitoring reduce abuse of the banking system.
  • Technology and operational resilience: governance for digital channels, information security and continuity planning mitigate technological and cyber risks.

Licensing and authorisation: step-by-step

Entities seeking to operate as deposit-taking institutions or to perform regulated banking activities generally follow a multi-stage authorisation route. While procedural detail varies with type of entity, the following steps describe the usual sequence. Applicants should consult the central bank’s published requirements and may wish to engage specialist counsel to prepare robust submissions.
  1. Pre-application planning: prepare a feasibility assessment covering market need, business model, governance structure and projected financials.
  2. Capital and sponsor assessment: ensure the proposed capital base and ownership structure meet minimum regulatory thresholds and that sponsors demonstrate fitness and propriety.
  3. Formal application: submit required documents, including business plan, governance and compliance frameworks, and key-person resumes.
  4. Regulatory review: the authority evaluates capital adequacy, risk frameworks, AML/CFT arrangements, information technology readiness and compliance capacity.
  5. Pre-operational checks: undertaking inspections and verification of premises, systems, and personnel clearances.
  6. Licence issuance and conditions: a licence may be granted subject to conditions, including phased capital or documentation deliverables.
  7. Ongoing supervision: once licensed, institutions submit regular prudential returns, cooperate with inspections and comply with directives.

Capital, liquidity and related prudential requirements

Maintaining adequate capital and liquidity is central to prudential supervision. Regulatory frameworks set minimum capital ratios, require quality of capital, and set limits on large exposures and related-party lending. Liquidity standards typically require banks to hold an appropriate buffer of highly liquid assets and to maintain contingency funding plans. Compliance requires accurate measurement of on- and off-balance-sheet exposures, robust internal models where permitted, and board-level oversight of capital planning.

Corporate governance and fit-and-proper assessments

Governance expectations typically extend to board composition, independence, competency and active oversight of senior management. Regulators expect boards to approve risk appetite statements, remuneration policies that avoid excessive risk-taking, and to ensure internal audit and compliance functions have sufficient authority and resources. Fit-and-proper assessments of directors and senior managers evaluate integrity, competence and time commitment. Firms that anticipate disputes or governance escalation often coordinate with litigation and arbitration specialists; see /leading-arbitration-lawyer/ for matters that may benefit from early dispute-resolution planning.

Consumer protection and conduct obligations

Consumer protection standards require clear disclosure of contractual terms, transparent pricing, procedures for handling complaints and mechanisms for remediation where conduct shortfalls occur. Banks that design or distribute consumer credit, deposit accounts or electronic payment services should align product governance with supervisory guidance and maintain accessible complaint and redress channels. Where employment practices intersect with customer-facing responsibilities, coordination with employment and labour counsel can be useful; see /employment-and-labor-lawyers/ for related considerations.

Anti-money laundering and counter-terrorist financing (AML/CFT)

Effective AML/CFT frameworks combine customer due diligence, transaction-monitoring systems, recordkeeping and reporting of suspicious activity. Compliance programmes should be proportionate to an institution’s size and risk profile, include ongoing staff training, and assign a senior compliance officer with direct access to the board. Institutions with significant cross-border business must align local AML/CFT controls with correspondent banking expectations and international standards.

Digital banking, fintech and operational resilience

Digital channels introduce benefits and new risks: cyber threats, third-party dependency, data protection concerns and operational interruptions. Supervisory attention on digital banking includes requirements for information-security governance, incident reporting, customer authentication standards and vendor oversight. Firms pursuing digital innovation often partner with fintech entities or cloud-service providers; such arrangements require robust contractual protections and contingency planning aligned with regulatory expectations.

Supervision, enforcement and remedies

Regulatory authorities use a range of supervisory tools: periodic reporting, on-site examinations, off-site surveillance, and thematic reviews. Where deficiencies are found, regulators may issue directives, require capital actions, impose fines or, in serious cases, initiate licence suspension or revocation. Effective engagement with supervisors often involves timely remediation plans, transparent reporting of corrective measures and, where appropriate, structured dialogues to agree on milestones for compliance.

Practical compliance checklist

AreaCheckpointsResponsible function
LicensingBusiness plan, capital proof, governing documentsCorporate/Legal
Capital & LiquidityRegulatory ratios, contingency funding plan, stress testingFinance/Risk
GovernanceBoard charters, fit-and-proper records, escalation protocolsGovernance/Compliance
AML/CFTCustomer due diligence, monitoring rules, SAR proceduresCompliance/Operations
TechnologyCyber policy, vendor SLAs, resilience testingIT/Operations

Common compliance pitfalls and mitigation strategies

Common errors include underestimating capital needs, weak board oversight, inadequate AML/CFT controls, incomplete reporting and insufficient attention to third-party risk. Mitigations include early and integrated compliance planning, independent validation of models and systems, investment in staff training, and establishing clear lines of accountability. Companies expanding operations or entering new product lines should engage multidisciplinary teams early, including regulatory, tax and foreign investment counsel, to align licences, corporate structuring and tax considerations. Relevant internal resources include /financial-services-regulatory-lawyers/ and the teams focused on cross-border investment at /foreign-direct-investment-lawyers/.

Practical governance measures for boards and senior management

Boards should approve a written risk appetite, review regular risk and compliance reporting, ensure succession planning for key control roles and confirm that remuneration policies are not creating incentives for imprudent risk-taking. Senior management should maintain a live register of regulatory obligations, test operational continuity plans periodically and ensure regular scenario-based testing of capital and liquidity stress plans.

Recent supervisory developments (2024–2025): themes and implications

Recent supervisory emphasis has tended to concentrate on three interrelated themes: the expansion of digital financial services and associated operational risk; higher expectations for AML/CFT effectiveness and transparency; and a growing regulatory interest in environmental, social and governance factors, including sustainable finance. These themes influence supervisory priorities and the content of examinations. Institutions should review their product governance, AML controls and disclosure practices in light of these supervisory priorities and consider updating policies and staff training accordingly.

Practical examples of internal controls and monitoring

Effective internal controls typically include automated monitoring of transactions against risk indicators, periodic independent reviews of AML systems, documented procedures for escalation of regulatory issues, and a central repository of regulatory communications and returns. Financial institutions often adopt a three-lines-of-defence model that defines operational ownership of risk, independent oversight by compliance and risk functions, and external or internal audit assurance.

When to involve external counsel or specialised advisers

Engage external counsel and specialists when applying for licences, responding to regulatory inspections, designing complex products or cross-border arrangements, defending regulatory enforcement actions, or structuring responses to significant operational incidents. Early involvement helps to manage regulatory expectations, structure remediation plans and reduce the risk of downstream disputes. TRW Law Firm maintains teams with experience across regulatory, dispute resolution and transactional areas; see our /services/ overview for how legal support can be organised and contact information at /contact/ for firm queries.

Brief legal-information disclaimer

The information in this article is provided for general informational purposes only and does not constitute legal advice. Readers should obtain professional legal advice before acting on any matters discussed. TRW Law Firm does not accept responsibility for actions taken on the basis of this information.For broader context on TRW’s work across banking, financial-regulatory, immigration, employment-mobility and commercial matters, readers can explore TRW Law Firm, its practice areas, the firm’s legal services, and the appropriate route to contact the team. These resources provide general information and do not replace advice on a particular record, transaction, regulatory question or current legal position.

FAQ

Q: What are the primary objectives of banking regulation in Bangladesh?

A: The principal objectives are to maintain financial system stability, protect depositors and consumers, promote fair and transparent market conduct, and to reduce abuse of the financial system for illicit purposes. These objectives are pursued through prudential standards, governance requirements, consumer-protection measures and AML/CFT controls. The balance between promoting innovation and preserving stability is a recurrent theme in supervisory practice.

Q: How does the central bank typically enforce compliance?

A: Enforcement tools include off-site monitoring, on-site examinations, remedial directions, administrative sanctions and, in serious cases, restrictions on operations or licence removal. Supervisors tend to use graduated measures, beginning with remediation requirements and escalating where firms fail to implement agreed actions. Transparency and constructive engagement with supervisors can materially affect the supervisory outcome.

Q: What constitutes a fit-and-proper assessment for directors and senior managers?

A: Fit-and-proper assessments evaluate professional competence, experience, integrity and absence of conflicts or regulatory disqualifications. Documentation typically includes CVs, certificates of character, declarations of other directorships and evidence of relevant qualifications. Regulators expect applicants to demonstrate that proposed board members and senior managers will provide effective oversight and have the time available to perform their duties.

Q: How should banks approach digital-banking risk management?

A: Banks should adopt a risk-based approach that covers information security, incident response, third-party vendor oversight, customer authentication and data-protection safeguards. The governance framework should include senior accountability for technology risk, periodic testing of systems, robust contractual protections with vendors, and clear policies for customer communication in the event of incidents.

Q: What are reasonable steps to ensure AML/CFT compliance?

A: Reasonable steps include conducting customer due diligence proportionate to risk, maintaining transaction-monitoring systems tuned to the institution’s risk profile, establishing clear procedures for suspicious-activity reporting, retaining adequate records and conducting regular staff training. Periodic independent reviews of AML controls help to identify gaps and prioritise remediation.

Q: How can financial institutions anticipate and prepare for supervisory reviews?

A: Institutions can prepare by maintaining up-to-date documentation of policies and procedures, ensuring timely submission of regulatory returns, conducting internal mock inspections, documenting remediation of prior findings and keeping senior management and the board informed of supervisory interactions. Proactive disclosure and remediation planning often improve dialogue with supervisors.

Q: When should a bank consider restructuring governance or capital plans?

A: Consider restructuring when stress testing reveals persistent capital shortfalls, when business expansion materially changes risk-weighted exposures, or when supervisory feedback identifies governance weaknesses. Any restructuring should be supported by a clear plan, board approval, and, where necessary, prior engagement with regulators to align on milestones and reporting expectations.

Additional resources and related practice areas

Regulatory compliance is closely connected to other legal disciplines. For cross-border investment matters consult /foreign-direct-investment-lawyers/; for regulatory disputes and arbitration see /leading-arbitration-lawyer/; for tax implications of banking activities consult /tax-lawyers/. Practitioners and market participants can also consult publicly issued regulatory circulars and supervisory guidance for technical detail when designing compliance arrangements. For administrative information and procedural queries, the /supreme-court-bangladesh-cause-list/ resource may be relevant where litigation is contemplated.

Concluding remarks

Effective compliance with banking regulation requires a combination of sound governance, prudent capital and liquidity management, effective AML/CFT controls, and careful attention to operational and technology risks. Institutions that plan early, document decisions, and engage with regulators and specialist advisers are better placed to manage supervisory scrutiny and to adapt to evolving regulatory priorities. Where organisations require targeted legal assistance, multidisciplinary teams can help bridge regulatory, transactional and dispute-resolution needs while respecting the particularities of each business model.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org
WhatsApp