TRW KNOWLEDGE · LEGAL INFORMATION

Banking Compliance Requirements in Bangladesh: A Practical Guide (2026)

This guide explains the principal banking compliance requirements in Bangladesh, outlines practical steps institutions commonly adopt, and highlights governance and reporting practices. It is designed to help compliance officers, in-house counsel and senior managers understand the regulatory environment and prepare for changing supervision and technological developments.
Originally published 25 May 2026

Introduction

Banking compliance in Bangladesh operates within a layered regulatory environment that combines statute, central-bank direction and supervisory guidance. Financial institutions need to interpret statutory duties alongside routine supervisory expectations in order to manage legal and operational risk. This guide summarises the typical compliance topics that recur in regulatory reviews and offers practical considerations for compliance governance, reporting and control design.

How to Read This Guide

The material that follows is structured to be practice-oriented rather than exhaustive. It highlights common compliance areas, describes governance arrangements that are widely used by banks and non-bank financial institutions, and sets out steps that organisations frequently take when they update policies or respond to supervisory changes. The guide also refers to related practice areas and resources on the firm’s site, including pages for our firm, our practices and specific advisory teams such as financial-services-regulatory-lawyers and tax-lawyers where coordinated advice is often required.

Broad Legal Framework and Supervisory Context

In Bangladesh, banks and similar financial institutions operate under a combination of primary legislation and subordinate measures. Primary laws set the statutory foundation for licensing, capital and prudential policy; central-bank orders and circulars routinely provide the supervisory detail that determines day-to-day compliance obligations. Because many regulatory directions are issued as circulars or guidance notes, compliance teams should maintain a documented process to track, interpret and implement supervisory communications.

Key Compliance Areas (at a glance)

The table below summarises recurring compliance areas, the practical focus of supervisory reviews, and typical sources of supervisory expectation. Use it as a checklist when assessing whether policies and controls exist for each area.
Compliance AreaPractical FocusTypical Regulatory Source
Customer Identity and OnboardingCustomer due diligence, record retention, enhanced checks for higher-risk clientsCentral bank circulars; AML guidance
Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF)Transaction monitoring, suspicious activity reporting, employee trainingAML law and implementing rules; supervisory instructions
Prudential RequirementsCapital adequacy, asset classification, provisioning and liquidity metricsBanking statute and prudential circulars
Operational ResilienceBusiness continuity planning, cyber risk controls and incident responseSupervisory guidance and technology risk circulars
Reporting and DisclosureTimely statutory returns, regulatory reporting and transparency obligationsReporting schedules and circulars

Designing a Practical Compliance Programme

An effective compliance programme typically combines clear governance, documented policies, proactive monitoring and continuous staff engagement. Governance begins with a board-approved compliance policy that explains roles and responsibilities and sets thresholds for escalation. The policy should be accompanied by operational procedures that are accessible to front-line staff and risk teams. Because supervisory expectations change, the programme should include a routine review cycle, a mechanism for logging regulator communications, and a documented approach to implementing updates.

Governance and Senior Management Responsibilities

Senior management and the board play distinct but complementary roles. The board is typically expected to approve the compliance strategy and to review major compliance risks regularly. Senior management is expected to implement board policies, allocate resources and ensure that the compliance function has sufficient independence and capability to carry out monitoring and reporting tasks. Many institutions establish a compliance committee that meets periodically to review incidents, supervisory developments and remediation plans.

Operational Controls and Technology

Operational control design must align with the risk profile of the institution. Common elements include customer acceptance policies, transaction monitoring systems, sanctions screening and secure channels for reporting suspicious activity. Digital banking and payments platforms require specific controls for authentication, access management and vendor oversight. Where third-party providers are used, institutions typically document vendor due diligence, contractual risk allocation and ongoing performance monitoring.

Risk Assessment and Prioritisation

Compliance risk assessments help institutions prioritise investment and attention. A practical assessment maps activities against potential harm (financial loss, regulatory sanction, reputational damage) and assigns risk ratings. High-risk areas—such as cross-border correspondent relationships or new product launches—are often subject to heightened controls and periodic testing. The outputs of the assessment feed into internal audit scope and compliance monitoring workplans.

Internal Audit, Monitoring and Testing

Internal audit and compliance monitoring provide independent assurance that policies are effective. Typical monitoring approaches include transaction sampling, review of exception reports, and testing of automated controls. Findings should be tracked in a remediation log with clear owners and deadlines. Regular reporting to senior management and the board helps maintain visibility of unresolved issues and mitigations.

Record-Keeping and Reporting Practices

Regulatory reporting is both a compliance and a governance activity. Institutions should keep a register of statutory returns and reporting timelines and validate data extraction processes to reduce the risk of errors. Records that support customer due diligence, transaction monitoring and internal investigations should be retained in accordance with legal and supervisory retention requirements and be retrievable for audits and regulatory requests.

Digital Banking, Innovation and Emerging Risks

New digital channels and services expand access but also introduce new compliance considerations. Where banks or financial services providers introduce digital products, they generally assess legal and regulatory implications before launch, implement proportionate controls for user authentication and transaction monitoring, and ensure customer-facing terms clearly describe rights and obligations. Supervisory guidance frequently emphasises resilience and consumer protection in digital contexts.

International Standards and Cross-Border Considerations

Bangladeshi institutions that engage in cross-border activity should consider international supervisory expectations and correspondent bank requirements. Many institutions align certain practices with internationally recognised standards to facilitate correspondent relationships and to reduce friction when operating across jurisdictions. Cross-border transactions may also require additional due diligence where differing legal frameworks apply.

Common Pitfalls and Practical Mitigations

Typical issues encountered in supervisory reviews include gaps in documentation, insufficient staff training, weak systems for escalation and slow implementation of regulator circulars. Practical mitigations include maintaining an issues register, documenting the rationale for compliance decisions, mandating regular training and creating a standing process to triage and implement new directives. Where multiple departments are involved, drafting clear process maps minimises ambiguity about handoffs.

Recent Supervisory Trends Impacting Compliance Practice

Regulators increasingly focus on areas such as technology risk, the integrity of KYC on digital platforms and the adequacy of transaction-monitoring programmes. Supervisory teams are also paying attention to governance practices around outsourced services and the sufficiency of contingency planning. Institutions updating their compliance programmes commonly document how they will address these supervisory priorities, often as part of annual compliance plans.

Coordination with Other Advisory Teams

Compliance work often requires multidisciplinary advice. For example, product design or tax treatment of transactions may require coordination with teams that specialise in tax, foreign investment or employment matters. Where disputes, regulatory enforcement or cross-border legal issues arise, collaboration with litigators or arbitration counsel may be necessary. Relevant practice pages include foreign-direct-investment-lawyers, tax-lawyers, and other specialist pages under services.

Practical Steps for Implementing or Updating a Compliance Programme

When an institution implements a new compliance programme or updates an existing one, the following steps are commonly taken: obtain board-level approval for the compliance strategy; map current controls to supervisory expectations; prioritise remediation tasks based on risk; update policies and procedures; roll out targeted staff training; perform focused testing of high-risk processes; and report results up the governance chain. Transparent documentation of decisions and timelines supports supervisory engagement and demonstrates an organised approach to compliance.

How the Firm’s Advisory Teams Typically Assist Clients

Legal teams working with financial institutions commonly assist with interpretation of regulatory communications, drafting and review of compliance policies, design of monitoring frameworks, and coordination of remediation programmes following supervisory reviews. Where regulatory engagement is required, legal advisers may help prepare submissions, coordinate responses and participate in structured dialogue with supervisors. Further information about our approach to client work can be found on our practices and the firm overview on our firm.

Brief Legal-Information Disclaimer

The material in this article is provided for general informational purposes only and does not constitute legal advice. Readers should obtain tailored legal advice before taking action because the facts and applicable law can change. This content does not create a lawyer-client relationship.A practical preparation step is to create a concise chronology and document index. The chronology can identify relevant communications, notices, applications, filings, contracts, approvals, payments, deadlines and decisions. The index can identify the current version of each record, its source, the responsible party and any matter that still requires confirmation. This helps distinguish established facts from assumptions and focuses attention on the decision that needs to be made.It can also be useful to identify the immediate practical question, the person or authority able to confirm an uncertain point, and the date by which a response may be needed. Maintaining a clear record of these points can reduce avoidable delay and support more focused communication with relevant stakeholders. General legal information cannot determine the appropriate next step for a particular matter; the current facts and legal position should be considered together before action is taken.Compliance programmes are more reliable when responsibilities, escalation paths and evidence retention are considered alongside the applicable current requirements.Periodic review should account for changes to products, counterparties, delivery channels and internal systems. Clear records of decisions, controls, monitoring and remedial action can assist organisations in understanding what was done and why.

Frequently Asked Questions

Q1: What should a basic compliance programme include?

A basic compliance programme typically includes board-approved policies, a designated compliance function with clear reporting lines, documented customer due diligence procedures, transaction monitoring and suspicious-activity reporting processes, routine staff training, internal audit arrangements and a mechanism to log and implement regulatory communications. The programme should be proportionate to the size and risk profile of the institution.

Q2: How often should compliance policies be reviewed?

Compliance policies are commonly reviewed at least annually and whenever there is a material change in products, services, ownership, or supervisory requirements. Institutions often maintain a version history and a change-log to show when and why policies were updated, and to demonstrate responsiveness to supervisory developments.

Q3: What are practical indicators of an effective transaction-monitoring system?

Practical indicators include clearly documented monitoring rules, routine tuning of thresholds and scenarios, an efficient process for triaging alerts, sufficient staffing to investigate escalations, and a feedback loop that uses investigation outcomes to refine monitoring parameters. Documentation of investigations and outcomes is important for supervisory reviews.

Q4: How should institutions manage third-party risk related to compliance?

Third-party risk is typically managed through obligating contracts, pre-engagement due diligence, ongoing performance monitoring and documented contingency plans. Contracts usually allocate responsibilities for compliance-related tasks and require the right to audit or obtain assurance from the vendor. Institutions frequently require vendors to meet defined minimum controls and to report incidents promptly.

Q5: When is it appropriate to seek external legal advice on compliance matters?

External legal advice is often appropriate when supervisory communications are complex or novel, when new products raise unclear regulatory questions, when remediation programs require legal assessment, or when a regulator begins an inquiry. External counsel can also assist in preparing responses to supervisory requests and in coordinating cross-functional remediation that has legal implications.

Q6: How can institutions demonstrate remediation progress to a supervisor?

Institutions commonly use a remediation plan that lists issues, root causes, remediation actions, owners, and completion dates. Progress reports that show milestones reached, evidence of implemented controls, and updated risk assessments help supervisors assess whether actions are effective. Independent testing or attestation can strengthen the evidence of remediation.

Q7: What role does staff training play in sustaining compliance?

Staff training is a foundational control that supports policy implementation and helps staff recognise and escalate compliance risks. Training programmes are most effective when tailored to employee roles, include assessments or practical scenarios, are documented for attendance and completion, and are refreshed periodically or when processes change.

Conclusion

Maintaining a robust compliance programme in the banking sector requires attention to governance, operations, systems and people. Institutions that document decision-making, prioritise risks, and maintain clear channels for implementing supervisory updates are better positioned to manage compliance demand. For institutions that require coordinated advice across regulatory, tax or transactional disciplines, working with experienced advisers can help align compliance design with commercial objectives while responding to supervisory priorities. For contact and practice information, see /contact/ and our services pages under /services.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org
WhatsApp