TRW Knowledge / Financial services regulation
Bangladesh Anti‑Money Laundering Framework: Practical Legal Guide (2026)
This guide explains the principal elements of Bangladesh's anti‑money laundering (AML) framework as relevant in 2026, outlines practical compliance measures for businesses and regulated entities, and identifies where to seek authoritative or specialist guidance. It summarises statutory reference points, supervisory roles, typical compliance obligations, common implementation challenges a

2026 reviewThis article retains its original publication date. It has been structurally and substantively refreshed for 2026; readers should verify current rules, court practice and primary materials before acting on a particular matter.
Introduction
This guide explains the principal elements of Bangladesh's anti‑money laundering (AML) framework as relevant in 2026, outlines practical compliance measures for businesses and regulated entities, and identifies where to seek authoritative or specialist guidance. It summarises statutory reference points, supervisory roles, typical compliance obligations, common implementation challenges and practical steps organisations usually consider to manage AML risks. The content is explanatory and not a substitute for bespoke legal advice; organisations should consult the relevant official authorities or a qualified adviser for application to particular facts.Legal and institutional framework
The AML framework in Bangladesh is grounded in national legislation and implementing directions from regulatory authorities. The Money Laundering Prevention Act (MLPA) enacted in 2012 is the central statute commonly referenced in summaries of the law. The statutory framework is supplemented by rules, notifications and supervisory guidance that are periodically issued by the Bangladesh Bank and the Bangladesh Financial Intelligence Unit (BFIU).Bangladesh also participates in regional and international bodies addressing financial crime, which informs ongoing policy and legislative review. In practice, comparisons to international standards (for example, those set out by the Financial Action Task Force (FATF)) and peer reviews by regional groups are frequently cited in policy documents and regulatory communications. Organisations should consult primary sources and current regulatory pronouncements to confirm the latest legal position and implementation timelines.Key institutions
- Bangladesh Bank — the central bank and lead regulator for many financial sector AML obligations, and a source of supervisory guidance (official site: https://www.bb.org.bd/).
- Bangladesh Financial Intelligence Unit (BFIU) — the national unit charged with receiving and analysing suspicious transaction reports and liaising with law enforcement and supervisory authorities.
- Sectoral regulators and licensing authorities — depending on the sector (banks, non‑bank financial institutions, insurance, capital markets, and designated non‑financial businesses and professions), specific supervisory bodies may issue additional rules or instructions.
Core statutory concepts
The following concepts recur across AML statutes and guidance. They are described in general terms; readers should confirm precise statutory definitions and thresholds in the current legislation and relevant rules.Definition of money laundering
Money laundering typically refers to conduct intended to disguise the proceeds or sources of crime or to integrate criminal proceeds into the formal economy. Statutory definitions may include a range of predicate offences and various acts such as placement, layering and integration, or otherwise criminalise knowingly assisting in such processes.Reporting obligations and suspicious transaction reporting
Financial institutions and certain non‑financial businesses and professions are ordinarily required to report suspicious transactions to the BFIU. Reporting obligations usually include timely submission of Suspicious Transaction Reports (STRs) where the reporting entity has knowledge, suspicion or reasonable grounds to suspect money laundering or related activity. The legal standard for what constitutes reasonable grounds, the form and timing of reports, and confidentiality protections are set out in legislation and supervisory guidance.Customer due diligence and KYC
Customer due diligence (CDD) requires entities to verify the identity of customers and, where applicable, beneficial owners; to understand the nature and purpose of business relationships; and to apply enhanced due diligence in higher‑risk situations. CDD is a fundamental component of a risk‑based approach and typically encompasses identity documentation, electronic verification where authorised, and ongoing monitoring of business relationships.Record keeping
Regulations commonly require retention of customer identification materials, transaction records and STRs for a minimum statutory period. The source material referenced a five‑year record‑keeping period; however, entities should confirm current retention periods and any sector‑specific requirements that may be longer or subject to preservation under investigation or litigation holds.Penalties and enforcement
Non‑compliance with AML obligations can lead to supervisory sanctions, administrative fines, criminal prosecution, or other measures such as licence suspension or revocation. Where criminal liability is established, penalties may include imprisonment and fines. The application of penalties depends on statutory provisions, the facts of the case and prosecutorial discretion; readers should not assume a particular outcome without case‑specific analysis.Risk‑based approach: organising compliance effort
Most modern AML regimes, including in Bangladesh, encourage a risk‑based approach (RBA) to allocate resources proportionally to identified risks. Elements of an RBA include risk identification, risk assessment, risk mitigation and governance oversight.Risk identification and assessment
Organisations commonly document how they assess risks across customer types, product and service offerings, delivery channels, geographies and transactions. A documented risk assessment explains how the entity determines customer risk categories and the criteria used to escalate review or require enhanced due diligence.Risk mitigation measures
Typical mitigation measures include transaction monitoring rules, enhanced due diligence for higher‑risk relationships, source of funds/income verification, sanctions screening, limits on certain services, and use of technology to support investigations and reporting. Entities should establish thresholds and triggers for investigations, retention of evidence and internal escalation procedures.Governance and internal controls
Governance arrangements normally assign clear responsibility for AML compliance. Many institutions maintain a designated compliance officer, compliance committee and reporting lines to senior management or the board. Controls include written policies and procedures, periodic independent testing (internal audit or external reviews), record retention and incident response plans.Practical compliance program components
The following components are commonly found in practical compliance programs. They are presented as points for consideration; the specific content and depth of each element should be tailored to the organisation’s size, risk profile and regulatory obligations.1. Written AML policy and procedures
The policy sets out the organisation’s approach, governance structure, and the minimum standards for CDD, monitoring, reporting and record retention. Procedures provide operational detail, including steps for onboarding, verification methods, suspicious activity escalation, and how to conduct enhanced due diligence.2. Customer due diligence and ongoing monitoring
Procedures should specify identification documents, acceptable verification methods, beneficial ownership processes, and ongoing monitoring techniques to detect deviations from expected customer activity. Digital identity verification tools may be used where supported by law and internal risk assessments.3. Transaction monitoring and alert handling
Transaction monitoring frameworks define the scenarios that generate alerts, how alerts are investigated, and timeframes for escalation and reporting. The monitoring system should be calibrated periodically to reduce false positives while ensuring relevant activity is flagged.4. Suspicious transaction reporting
Entities should train staff on recognising indicators of suspicion and the internal reporting chain that leads to submission of STRs to the BFIU. The STR process should preserve confidentiality and protect against tipping‑off where prohibited by law.5. Screening and sanctions compliance
Screening requirements include checks against sanctions lists, politically exposed persons (PEPs) lists and negative media where appropriate. Processes should be documented, and periodic re‑screening must be scheduled consistent with risk levels.6. Training and culture
Training programmes should be tailored by role: frontline staff require practical detection skills, compliance teams need to understand reporting obligations, and senior management needs awareness of governance obligations. Organisations should retain training records and assess training effectiveness over time.7. Independent audit and continuous improvement
Regular independent review (internal audit or third‑party) evaluates program design and operational effectiveness. Deficiencies identified should be tracked with remediation plans and timelines. Regulatory updates and enforcement trends should inform ongoing adjustments to controls and procedures.Designated non‑financial businesses and professions (DNFBPs)
AML obligations in many jurisdictions extend beyond banks to include specific non‑financial sectors (for example, real estate professionals, legal professionals in certain contexts, accountants, trust and company service providers, and dealers in precious metals and stones). Entities that fall within defined categories should determine whether they are subject to the MLPA or related regulations and adopt proportionate controls. Where classification is unclear, seek authoritative guidance from the relevant regulator or legal counsel.Cross‑border considerations and correspondent relationships
Cross‑border transactions and correspondent banking relationships present particular AML challenges. Institutions should maintain policies for onboarding and monitoring correspondent relationships, including information on ownership, risk profile, and the home regulator of the correspondent institution. Enhanced due diligence and periodic review are frequently applied to higher‑risk correspondent banking relationships.Cooperation with law enforcement and asset recovery
Where suspected criminality is identified, regulators may require reporting to the BFIU and law enforcement. Legal frameworks may provide for provisional measures, asset freezing and confiscation in criminal proceedings. Entities should have processes to respond to lawful orders while preserving privacy and legal privilege considerations where applicable.Practical checklist for implementation
Below is a concise checklist organisations commonly use when establishing or reviewing AML programmes. It is illustrative and not exhaustive.- Document an up‑to‑date AML policy and procedures;
- Appoint a designated AML compliance officer with clear reporting lines;
- Conduct a formal risk assessment and document risk ratings for customers, products and geographies;
- Implement CDD and beneficial ownership verification procedures;
- Design and implement transaction monitoring rules and investigate alerts promptly;
- Establish STR procedures and ensure timely submission to the BFIU where required;
- Maintain record‑keeping systems that meet statutory retention requirements and enable timely retrieval for audits or inquiries;
- Provide role‑specific training and maintain attendance and materials records;
- Schedule independent audits and remediate findings with documented action plans;
- Keep a register of relevant laws, regulations and supervisory guidance and review it periodically.
Common implementation pitfalls
Compliance exercises can be undermined by predictable gaps. Organisations often encounter the following issues:- Insufficient or undocumented risk assessments that make it difficult to justify differential treatment of customers;
- Overly generic policies that lack operational detail for staff tasked with execution;
- Poor record management that impedes response to regulatory queries or investigations;
- Failure to adapt systems and controls when business models, product offerings or delivery channels change;
- Inadequate training that leaves front‑line staff uncertain about how to escalate suspicious activity.
2026 update
Regulatory practice and legislative amendment may continue to evolve in 2026. Recent years have seen broad policy attention to strengthening AML regimes, including enhanced supervision, emphasis on sectoral coverage and development of digital reporting channels. Where the legislative record does not specify a date‑bound change, organisations should verify current obligations by consulting primary sources such as the Bangladesh Bank, the BFIU or official gazettes. The Bangladesh Bank's official website is a primary starting point for official guidance: https://www.bb.org.bd/. For matters that turn on specific dates or transitional arrangements, seek a written statement from the relevant authority or qualified legal adviser.Interaction with sanctions regimes and PEPs
Sanctions screening and identification of politically exposed persons (PEPs) are standard components of an AML programme. Sanctions obligations may derive from international or national measures; entities should maintain up‑to‑date screening lists and escalation procedures where hits occur. For PEPs, organisations generally apply enhanced due diligence to understand the source of wealth and the nature of expected transactions, documenting rationale for any business relationship with a PEP.Technology and data considerations
Technology increasingly supports AML operations through automated monitoring, identity verification and data analytics. When deploying technology, organisations should address data protection and privacy laws, the accuracy and provenance of data sources, algorithmic explainability for alert generation, and retention of audit trails for decisions made by automated systems.Engaging third parties and outsourcing
Many institutions rely on third‑party service providers for KYC, screening or monitoring. Outsourcing does not remove the ultimate compliance obligations of the regulated entity. Written agreements should set out service levels, data protection obligations, audit rights and termination rights where the service provider fails to meet applicable standards.Regulatory engagement and supervisory communications
Proactive engagement with supervisors can reduce compliance uncertainty. Typical interactions include licence applications, notifications of material changes to business models, responses to supervisory examinations and voluntary disclosures of compliance breaches. Entities should maintain records of communications with regulators and ensure that submissions are accurate and timely.When to seek legal advice
Organisations should consider seeking independent legal advice in situations including, but not limited to:- Complex cross‑border transactions with unclear AML or sanction implications;
- Receipt of a regulatory notice, investigation demand or freezing order;
- Uncertainty about whether a business activity falls within designated categories under national law;
- Implementing novel technology that raises questions about data protection or automated decision‑making;
- Where significant penalties, criminal exposure or licence implications are possible.
Practical guide: step‑by‑step for businesses
- Map applicable legal obligations: identify which statutes, rules and supervisory circulars apply to your sector.
- Conduct a formal risk assessment and document the results.
- Draft or update written AML policies and procedures that reflect the risk assessment and regulatory expectations.
- Implement CDD and beneficial ownership verification procedures with proportionate documentation requirements.
- Deploy transaction monitoring and screening systems calibrated to risk profiles.
- Set up STR procedures and maintain a confidential reporting channel to the compliance team.
- Deliver role‑specific training and keep attendance and content records.
- Schedule independent testing and update controls based on findings.
- Maintain regulatory watch and update policies promptly in response to new supervisory guidance.
- Document compliance decisions and retain records in accordance with statutory retention periods.
Five practical FAQs
Q: What is money laundering?
A: Money laundering generally refers to converting or moving proceeds of unlawful activity to conceal their origin and integrate them into the legitimate economy; precise statutory definitions are in national law and vary by jurisdiction.Q: What are the penalties for violating Bangladesh's anti‑money laundering laws?
A: Penalties for non‑compliance can include fines, criminal prosecution and administrative actions such as licence suspension; the applicable penalties depend on the statutory provisions and the facts of each case, so obtain case‑specific legal advice.Q: How can businesses ensure compliance with anti‑money laundering laws?
A: Businesses typically ensure compliance by implementing a documented AML programme that includes risk assessment, CDD, monitoring, STR procedures, training and independent testing; the precise measures should be tailored to the entity’s risk profile and legal obligations.Q: What is the role of the Bangladesh Financial Intelligence Unit (BFIU)?
A: The BFIU receives and analyses suspicious transaction reports, exchanges information with law enforcement and supervises reporting mechanisms; organisations should consult BFIU guidance or the Bangladesh Bank for current reporting procedures.Q: Can TRW Law Firm assist with anti‑money laundering compliance?
A: TRW Law Firm can provide legal advice on interpreting AML obligations, designing compliance programmes and responding to regulatory inquiries; for advice tailored to your circumstances, contact an authorised adviser.Further resources and internal contacts
Official information and notifications from the Bangladesh Bank and the BFIU should be consulted for authoritative guidance; the Bangladesh Bank's site is available at https://www.bb.org.bd/. TRW maintains information on services that may be relevant when considering compliance resources: our firm overview at https://trw.org/our-firm/, practice area summaries at https://trw.org/our-practices/, and services at https://trw.org/services/. To discuss a specific matter or request a consultation, use our contact page at https://trw.org/contact/ or the specialist regulatory pages such as https://trw.org/financial-services-regulatory-lawyers/ and https://trw.org/tax-lawyers/.Concluding remarks
Maintaining an effective AML programme in Bangladesh in 2026 requires attention to statutory obligations, supervisory expectations and operational resilience. Organisations should document their risk‑based decisions, maintain clear governance over compliance responsibilities and seek specialist legal advice where factual or legal questions arise. For up‑to‑date regulatory publications, consult the relevant government and supervisory websites and, where appropriate, obtain written guidance from regulators or a qualified adviser.Book consultation or email info@trw.org to discuss how these considerations apply to your business.Bring the facts.
We bring direction.
For a focused discussion about a dispute, regulatory issue or procedural question, speak with TRW Law Firm. General information on this page is not legal advice.