TRW KNOWLEDGE · LEGAL INFORMATION

Legal Framework for Banking in Bangladesh: Step-by-Step Legal Process (2026)

The legal framework for banking in Bangladesh comprises central banking rules, licensing standards, prudential norms and sectoral policies designed to promote stability and consumer protection. This article sets out a structured, practical overview of the regulatory landscape, common compliance priorities and steps institutions typically follow when establishing and operating in the sector.
Originally published 25 May 2026

Introduction

The banking sector in Bangladesh operates within a layered regulatory environment intended to balance financial stability, market development and consumer protection. Over time regulators and policymakers have introduced rules addressing licensing, capital adequacy, governance, anti-money laundering, digital services and sectoral policy goals such as financial inclusion and sustainability. This article provides a step-by-step legal-information overview of the key elements that typically shape banking operations in Bangladesh, emphasising practical compliance considerations for new entrants and established institutions alike.

Scope and purpose of this guide

This guide explains the structure of regulation, typical statutory themes and the kinds of processes banks and financial institutions commonly follow to meet regulatory expectations. It is intended as legal information: it summarises recurring regulatory subjects and practical compliance steps rather than offering case-specific legal advice. For targeted issues, institutions normally consult qualified counsel or dedicated regulatory advisers.

Regulatory architecture: who oversees the sector

At the centre of banking oversight are the national authorities and sectoral supervisory bodies that set prudential standards, issue licences and monitor ongoing compliance. The central bank plays a primary role in monetary policy and banking supervision, while other statutory regimes address non-bank financial institutions, anti-money laundering, and customer protection. Administrative guidance and circulars supplement primary legislation and are frequently used by regulators to implement policy objectives in operational detail.

Core statutory themes

Across the sector, several recurring statutory themes shape conduct and operations. These include licensing and minimum capital requirements, governance and fit-and-proper standards for directors and senior officers, prudential rules such as capital adequacy and loan provisioning, reporting and audit obligations, anti-money laundering and counter-financing-of-terrorism (AML/CFT) duties, and customer protection measures covering transparency and dispute resolution.

Primary steps to establish banking operations: a practical sequence

Entities preparing to enter the banking market or to expand services typically follow a sequence of internal and external steps. The order and emphasis depend on the business model, whether the applicant is a new local bank, a branch of a foreign bank, or a non-bank financial institution. Typical steps include corporate structuring and documentation, meeting minimum capital and shareholder suitability requirements, completing regulatory applications, establishing governance and internal control frameworks, and preparing for on-site inspections and approvals.

1. Business model and corporate design

Begin with a clear statement of the proposed business model: retail banking, corporate banking, specialized finance, digital-only services or a mixed model. The model determines capital needs, permissible activities, reporting lines and required licences. Corporatisation choices — whether through a locally incorporated company or a foreign branch — influence the regulatory pathway and the range of local compliance obligations, including taxation and statutory filings.

2. Licensing and regulatory engagement

Applicants prepare and submit licence applications to the primary regulator. Applications typically require business plans, financial projections, governance arrangements, information on beneficial owners and senior executives, proof of capital, and policies for risk management and compliance. Expect substantive regulatory engagement: regulators may request clarifications, supplementary documentation and interviews with senior management as part of the assessment process.

3. Governance and internal controls

Regulators emphasise board composition, separation of duties, internal audit functions, compliance units and risk committees. Fit-and-proper assessments for directors and senior officers are common; independent non-executive directors and clearly defined escalation and reporting lines strengthen regulatory comfort. Policies should be documented and tested, including those for credit, market and operational risk.

4. Capital, liquidity and prudential planning

Meeting minimum capital and liquidity requirements is an early operational priority. Institutions should prepare capital-adequacy projections, liquidity contingency funding plans and stress-test results. Prudential norms are implemented by regulation and supervisory guidance; institutions that maintain robust buffers and clear contingency plans are better positioned for regulatory review.

5. Compliance programmes: AML/CFT and sanctions

Robust customer due diligence, transaction monitoring, suspicious-activity reporting and record-keeping policies are central compliance elements. Institutions must also stay alert to sanctions-related obligations and to local regulations that require designated reporting of suspicious transactions. Compliance programmes should be risk-based, resourced with trained personnel, and subject to regular independent review.

6. Technology, cybersecurity and digital service delivery

Digital channels raise discrete regulatory expectations around data protection, cybersecurity, operational resilience and customer authentication. Institutions offering online or mobile banking typically implement layered security controls, incident response plans and vendor oversight mechanisms to manage third-party risks associated with fintech partnerships and outsourced services.

Supervisory reporting, inspections and ongoing obligations

After licensing, supervised entities are required to submit periodic financial returns, prudential reports, audit opinions and compliance certificates. Supervisors may perform off-site surveillance as well as on-site inspections focused on governance, credit underwriting, liquidity, AML/CFT controls and IT resilience. Regular regulatory communications commonly include circulars to clarify supervisory expectations; maintaining responsive reporting systems and an internal regulatory liaison function reduces the risk of non-compliance.

Consumer protection, transparency and dispute resolution

Consumer-facing rules address information disclosure, fair treatment, complaint handling and dispute settlement. Banks are expected to publish clear terms for deposit and lending products, disclose fees and charges, and maintain accessible complaints channels. Effective documentation and staff training on consumer-facing requirements reduce reputational and legal risk. Where disputes arise, options often include internal escalation, regulator-facilitated mediation and court-based remedies.

Risk management: practical considerations

An effective risk management framework identifies, measures and mitigates material risks across credit, market, liquidity, operational and compliance categories. Key practices include lending policies with delegated authorities, concentration limits, collateral management, portfolio monitoring, scenario analysis and independent risk reporting. Operational risk policies should address process controls, business continuity and vendor management. Regular independent testing of models and limits supports credibility with supervisors.

Anti-money laundering and counter-financing of terrorism (AML/CFT)

AML/CFT programmes are typically risk-based and include customer risk-rating, enhanced due diligence for high-risk customers, transaction monitoring and suspicious-activity reporting. Record retention requirements and staff training are standard elements. Financial institutions must also align internal policies with applicable statutory obligations and guidance from the supervisory authority to manage regulatory and reputational exposure.

Digital banking and cybersecurity

As digital services expand, regulators have increased focus on minimum cybersecurity measures, data protection practices and incident notification obligations. Institutions should maintain clear policies on encryption, access controls, secure development and patch management, incident response and post-incident communication. Third-party arrangements, including cloud services and payment processors, require contractual protections and continual oversight.

Green banking, financial inclusion and policy priorities

Recent policy themes include measures that encourage sustainable finance, green lending programmes and efforts to extend financial services to underbanked communities. These policy priorities can translate into supervisory guidance, incentive schemes or disclosure expectations. Institutions aligning product innovation with policy priorities often document their approach through environmental and social risk policies.

Common compliance pitfalls and practical controls

Common pitfalls include weak or undocumented governance, insufficient AML controls, delayed regulatory reporting, under-resourced compliance teams and inadequate staff training. Practical controls to reduce these risks include a documented regulatory-change management process, regular internal audits, continuous professional development for front-line staff, and periodic third-party reviews of key control systems.

Operational checklist (table)

AreaKey actionsTypical timing
Licence applicationPrepare business plan, capital proof, governance documents, beneficial ownership disclosuresPre-application to submission
GovernanceAppoint board, adopt policies, establish audit and risk committeesBefore operations commence
Capital & liquiditySubmit projections, build buffers, implement liquidity planPre- and post-licence
Compliance & AMLAdopt KYC/CDD procedures, transaction monitoring, staff trainingOngoing
TechnologyComplete security assessments, vendor contracts, incident response planBefore and during launch

How TRW Law Firm can assist

Legal advisers typically support licensing submissions, regulatory engagement, governance design and regulatory-risk assessments. Our team can help institutions interpret supervisory guidance, prepare documentation for licensing and prepare compliance frameworks that reflect the institution’s chosen business model. For matters involving cross-border investment, we coordinate with advisers specialising in related areas such as foreign direct investment, taxation considerations with tax advisers, and sector-specific regulatory counsel such as financial services regulatory lawyers. Summary information about our firm is available via /our-firm/, our practice areas are described at /our-practices/, and our engagement options are summarised under /services/. If you need to arrange further discussions, our contact page is /contact/.

Practical tips for in-house teams

In-house counsel and compliance officers frequently adopt a regulatory-change log, map internal processes to regulatory obligations, prioritise hiring or training in AML and IT security, and arrange periodic external compliance reviews. Close coordination between business units, internal audit and senior management reduces the risk of gaps when the supervisor conducts on-site reviews. Where disputes with customers or other parties arise, specialist capability in dispute resolution and enforcement proceedings — including access to counsel experienced with arbitration or court practice — can be critical; relevant practices often intersect with employment, tax and commercial counsel.

Brief legal-information disclaimer

This publication provides general legal information compiled for practical orientation and does not constitute legal advice. It summarises common regulatory themes and typical processes; institutions should seek tailored legal and regulatory advice before acting on issues that affect their specific circumstances.A practical preparation step is to create a concise chronology and document index. The chronology can identify relevant communications, notices, applications, filings, contracts, approvals, payments, deadlines and decisions. The index can identify the current version of each record, its source, the responsible party and any matter that still requires confirmation. This helps distinguish established facts from assumptions and focuses attention on the decision that needs to be made.It can also be useful to identify the immediate practical question, the person or authority able to confirm an uncertain point, and the date by which a response may be needed. Maintaining a clear record of these points can reduce avoidable delay and support more focused communication with relevant stakeholders. General legal information cannot determine the appropriate next step for a particular matter; the current facts and legal position should be considered together before action is taken.

Frequently Asked Questions

Q: Which authority has primary oversight over banks and deposit-taking institutions?

A: The central banking authority is the principal supervisor for banks and oversees monetary policy, licensing and prudential supervision. Other statutory regimes and administrative instruments complement central bank supervision to address matters such as non-bank financial institutions, AML/CFT obligations and consumer protections.

Q: What are the core elements that a regulator examines in a licence application?

A: Regulators commonly assess the applicant’s business plan and financial projections, proof of minimum capital, governance arrangements, the fitness and propriety of directors and senior officers, risk-management policies, AML/CFT controls and operational readiness including IT and cybersecurity measures. Applicants should present coherent documentation and clear implementation timelines.

Q: How should an institution prepare for supervisory inspections?

A: Preparation typically involves maintaining up-to-date regulatory returns, ensuring policies and procedures are documented and implemented, conducting internal audits of key control areas, and compiling clear evidence of compliance for on-site reviewers. Designating a regulatory liaison and preparing a structured response plan for queries can speed resolution of inspectorate questions.

Q: What practical steps reduce AML/CFT compliance risk?

A: Implementing a risk-based customer due-diligence regime, effective transaction-monitoring tools, timely suspicious-activity reporting, staff training and independent audits of AML controls are key steps. Firms should ensure record-keeping systems retain the documentation required by applicable statutes and supervisory guidance.

Q: What are typical shortcomings that attract supervisory attention?

A: Common shortcomings include weak governance and internal oversight, inadequate documentation of risk policies, delayed or inaccurate reporting to supervisors, insufficient AML controls, and lack of tested business continuity plans. Addressing these areas proactively reduces the likelihood of enforcement action or supervisory restrictions.

Q: How do digital banking services change regulatory priorities?

A: Digital services shift attention toward cybersecurity, data protection, incident response, vendor management and customer authentication. Regulators often expect institutions to demonstrate secure architectures, tested resilience measures and robust oversight of third-party service providers that support digital channels.

Additional resources and practice intersections

Regulatory questions often intersect with related practice areas. For example, cross-border transactions and investments may involve advisers in foreign direct investment law, taxation specialists listed under /tax-lawyers/, and dispute resolution counsel where enforcement or arbitration is a possibility. Where specialised regulatory strategy is required, firms that combine sectoral regulatory expertise with transactional experience can coordinate multi-disciplinary advice.

Conclusion

Operating in the banking sector requires attention to a broad set of legal and regulatory themes: licensing, governance, prudential requirements, AML/CFT, consumer protection and technology resilience. Institutions that adopt structured project plans for licensing and compliance, maintain clear governance and engage proactively with regulators are better placed to manage regulatory expectations. For complex or novel issues, institutions commonly retain external counsel with regulatory and sectoral experience to support submissions, compliance programme design and regulatory engagement.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org
WhatsApp