TRW KNOWLEDGE · LEGAL INFORMATION

Understanding Bangladesh Banking Compliance Regulations: Bangladesh Legal Guide (2026)

This guide explains the principal elements of banking compliance in Bangladesh: the regulatory framework, core compliance areas such as capital adequacy and anti‑money laundering, practical steps for building an effective compliance programme, recent developments, and common implementation challenges for banks and financial services providers.
Originally published 14 June 2026

Introduction

Banking compliance in Bangladesh has grown in importance as the financial sector has expanded and diversified. This article presents legal information about the structure of banking regulation, the obligations that commonly apply to banks and similar financial institutions, and practical considerations when moving from policy to implementation. The content focuses on themes that recur in supervision and industry guidance: governance, risk management, customer due diligence, reporting, and technology-enabled controls. It is intended to support in‑house compliance teams, risk officers, board members, and external advisers seeking a structured overview rather than to provide legal advice.

Regulatory architecture and principal statutes

The banking sector in Bangladesh is overseen by a set of laws, regulations and supervisory instruments. The central supervisory authority issues circulars and guidelines that interpret statutory duties and set supervisory expectations. A number of enacted statutes provide the primary legal framework for banking operations, licensing and prudential standards; these statutes are implemented and supplemented by regulatory rules and supervisory guidance.Regulatory oversight typically covers capital and liquidity requirements, permissible activities, reporting and disclosure, consumer protection, anti‑money laundering obligations, foreign exchange controls and the conduct of digital services. Because supervisory practice evolves, institutions maintain systems for monitoring circulars and other guidance from the central authority as a routine part of compliance monitoring.

Key prudential and conduct areas

While the precise regulatory texts and numerical thresholds are matters for the statutes and the central bank's official instruments, several compliance areas recur in supervisory assessments. Organising compliance activity around these areas helps institutions ensure coverage of commonly assessed risks.

Capital and solvency-related measures

Prudential supervision focuses on capital adequacy and the ability of a bank to absorb losses. Capital frameworks allocate different risk weights to asset classes and set minimum capital ratios intended to protect depositors and maintain financial stability. Compliance teams track regulatory capital composition, adequacy ratios and any supervisory expectations about internal capital assessment processes.

Anti‑money laundering and countering the financing of terrorism (AML/CFT)

AML/CFT obligations require institutions to implement customer due diligence (CDD), ongoing monitoring, transaction screening and reporting of suspicious transactions to the designated authority. Effective AML/CFT programmes combine policies, transaction monitoring systems, staff training and escalation procedures for reporting. Compliance functions also test CDD and monitoring systems to identify gaps and false positives that impede investigations.

Corporate governance and internal controls

Boards and senior management have supervisory and policy responsibilities that translate into written governance frameworks. Responsibilities typically include setting risk appetite, approving compliance programmes, ensuring adequate resourcing of control functions and overseeing audit and compliance reporting lines. Internal controls should be proportionate to the institution's size and complexity and must cover both operational and compliance risks.

Consumer protection and conduct

Consumer protection obligations relate to transparent disclosure, fair treatment, grievance handling and dispute resolution. Compliance programmes include product governance controls, pricing transparency checks and procedures for handling complaints. Supervisors often review sample contracts, marketing materials and complaint logs to assess whether customers are treated fairly.

Foreign exchange and cross-border transactions

Cross-border payments and foreign exchange activities are governed by exchange control requirements and licensing conditions. Institutions engaged in foreign currency operations maintain controls to ensure compliance with remittance limits, reporting obligations and documentation requirements for outward and inward transfers.

Digital banking, cybersecurity and data governance

Digital channels increase operational efficiency but also widen the risk surface. Regulatory attention has shifted toward cybersecurity standards, resilience testing, and data protection controls, including customer authentication, incident response and secure development lifecycles. Institutions should integrate technology risk into enterprise risk management, with measurable controls and testing regimes.

Practical compliance programme: design and maintenance

Effective compliance depends on a structured programme that translates obligations into policies, procedures, controls and monitoring activities. The section below outlines a stepwise approach that institutions frequently adopt when introducing or maturing compliance frameworks.

1. Regulatory inventory and impact mapping

Start by maintaining an up‑to‑date inventory of applicable statutes, regulations and supervisory circulars. Each regulatory item should be mapped to operational processes and ownership assigned to business units and control functions. This mapping creates the baseline for compliance monitoring and regulatory change management.

2. Policy framework and procedures

Policies articulate commitments and responsibilities at a high level; procedures provide step‑by‑step instructions for execution. Policies should be approved by the board or a delegated committee and communicated across the institution. Procedures are living documents reviewed on a periodic schedule and updated when regulatory requirements change.

3. Risk‑based controls and monitoring

Adopt risk‑based controls proportionate to the institution’s risk profile. Transaction monitoring systems, limits, exception reporting and periodic reconciliations are typical control elements. Monitoring includes key risk indicators and regular management reporting that feed into board oversight.

4. Training and culture

Training programmes tailored to roles and functions are central to embedding compliance in daily operations. Training should cover regulatory basics, the institution’s procedures and escalation pathways for suspected breaches. Cultural reinforcement from senior management helps translate training into behavioural change.

5. Testing, assurance and remediation

Independent testing by internal audit or an external reviewer verifies the design and effectiveness of controls. Findings must be tracked to closure with clear remediation plans and deadlines. Periodic testing cycles and targeted reviews after material incidents preserve control integrity over time.

One-page compliance checklist

Compliance AreaCore ObligationSuggested Next Step
Capital & PrudentialMaintain regulatory capital ratios and submission of prudential returnsVerify capital calculations and reconciliations; run stress scenarios
AML/CFTCustomer due diligence and suspicious transaction reportingReview CDD files; tune transaction monitoring to reduce false positives
Corporate GovernanceBoard oversight, policies and clear reporting linesUpdate committee charters; schedule quarterly compliance reporting
Digital OperationsCybersecurity, incident response and data protectionRun tabletop incident exercises; verify encryption and access logs
Customer ConductTransparent disclosure, fair treatment and complaint handlingAudit sample contracts and complaint resolution times

Reporting, audits and regulatory engagement

Regulatory engagement is often an ongoing dialogue between supervisors and supervised entities. Routine regulatory reporting and ad hoc requests require reliable data flows and documented validation processes. Internal audit provides independent assurance over compliance and operational controls, while external auditors may assess statutory accounts and regulatory filings. When supervisors request information, providing timely, accurate responses and a clear remediation timeline for identified issues supports constructive supervisory relationships.

Technology, data and innovation considerations

Technology choices influence compliance effectiveness. Well‑designed systems reduce manual intervention, improve monitoring and generate audit trails. Data governance ensures that records needed for reporting and investigations are available, consistent and retained according to regulatory retention policies. For institutions pursuing innovation—such as digital onboarding or new payment rails—pilots should include compliance checkpoints and phased rollouts to manage operational and conduct risks.

Common implementation challenges and how institutions address them

Several recurring challenges emerge during compliance implementation. These include fragmented data across legacy systems, insufficient resourcing for control functions, and the tension between business growth objectives and conservative risk controls. Institutions address these issues by investing in data consolidation projects, aligning performance objectives to compliance outcomes, and outsourcing specialised functions such as transaction monitoring where it is more efficient and allows access to vendor expertise.

Recent developments (2024–2025) and supervisory focus areas

Supervisory focus in recent years has gravitated toward strengthening AML/CFT frameworks, adapting frameworks to digital banking models, and enhancing cyber resilience. Supervisors have also signalled continued attention to governance arrangements and the need for proportionate risk management for non‑bank financial services. Institutions that can demonstrate robust programme governance, documented controls and evidence of testing are generally better positioned during supervisory reviews.

Interacting with other legal practice areas

Banking compliance often overlaps with other areas of law. For work involving cross‑border transactions, coordination with advisers experienced in foreign investment matters supports compliance with inbound or outbound investment rules; see /foreign-direct-investment-lawyers/ for a venue of specialist support. Tax issues arise in structuring transactions and operational arrangements; referral to /tax-lawyers/ helps align tax planning with regulatory constraints. Where regulatory disputes or administrative reviews arise, teams with experience in financial services regulation are relevant—consider /financial-services-regulatory-lawyers/ for specialist regulatory litigation or representation.

Practical examples of compliance implementation

Below are illustrative, anonymised scenarios that show how an institution might approach common compliance tasks. These are examples of approaches rather than prescriptions:

Example: strengthening customer due diligence

A mid‑sized bank upgraded its CDD procedures to include enhanced verification for higher‑risk customers. The bank mapped its client segments to risk tiers, integrated data from reliable third‑party identity sources, and implemented periodic CDD refresh triggers. Compliance testing focused on the accuracy of risk categorisation and whether monitoring alerts produced actionable reviews.

Example: integrating cyber resilience into enterprise risk management

An institution conducting significant digital transactions established a cross‑functional cyber steering committee. The committee defined critical systems, agreed recovery time objectives, mandated penetration testing schedules and coordinated incident response plans with legal, operations and communications personnel. Testing exercises informed prioritisation of remediation work.

Organisational capacity and resourcing

Resourcing choices reflect an institution’s scale, complexity and risk appetite. Core compliance capabilities include policy development, monitoring, reporting, training and escalation processes. Some institutions centralise compliance to achieve consistency, while others use a hybrid model where business lines retain primary compliance responsibility supported by a central compliance oversight function. Outsourcing non‑core tasks to specialised service providers can be a practical way to access technology and expertise, but governance and vendor oversight remain responsibilities of the regulated institution.

How firms and advisers can support institutions

External advisers support compliance programmes in many ways: regulatory change monitoring, drafting policies, performing independent reviews, helping with response to regulatory inquiries and designing tailored training. Firms often work with in‑house teams to strengthen procedures and provide technical assistance in specialised areas such as sanctions screening, fintech integrations, and complex transaction due diligence. For a description of practice areas that commonly assist financial institutions, see /our-practices/ and for firm background see /our-firm/; for details about services, consult /services/.

Legal‑information disclaimer

The content in this article is presented for general informational purposes about regulatory topics affecting banking and financial services in Bangladesh. It does not constitute legal advice, create a lawyer‑client relationship, or provide a substitute for obtaining tailored legal advice about specific facts and circumstances. For assistance with a particular matter, please follow the institutional procedures for engaging external counsel or advisors; information on contacting the firm is available at /contact/.For broader context on TRW’s work across banking, finance, immigration, regulatory and dispute matters, readers can explore TRW Law Firm, its practice areas, the firm’s legal services, and the appropriate route to contact the team. These resources provide general information and do not replace advice on a particular record, transaction, regulatory question or current legal position.

FAQ

What are the primary objectives of banking regulation in Bangladesh?

Banking regulation seeks to preserve financial stability, protect depositors and consumers, reduce systemic risk and promote integrity in financial markets. Regulators balance prudential safeguards with the objective of supporting efficient, inclusive financial intermediation. Institutions are expected to implement policies and controls that reflect these objectives while remaining responsive to supervisory guidance.

How often should a bank review its AML/CFT programme?

Review frequency depends on risk exposure and regulatory expectations. High‑risk programmes typically undergo more frequent reviews, including at least annual independent testing and more frequent targeted assessments after significant business changes or incidents. Regular updates are also necessary when new supervisory guidance or legislative changes affect compliance obligations.

What documentation should a bank maintain to demonstrate regulatory compliance?

Documentation commonly includes written policies and procedures, evidence of board approvals, training records, audit and testing reports, reconciliations and management reports, CDD files, transaction records and incident logs. Retention periods and format requirements may be set by statute or supervisory guidance, and documentation should enable timely responses to supervisory inquiries.

How can smaller banks manage compliance costs while meeting supervisory expectations?

Smaller banks can adopt risk‑based approaches that prioritize higher‑impact controls, use shared services or approved third‑party providers for specialised functions, and invest in scalable technology that automates routine checks. Proportionality in governance and controls—matched to the institution’s size and complexity—helps meet supervisory expectations without imposing unnecessary burdens.

What should institutions consider when adopting new digital banking services?

When launching or scaling digital services, institutions should evaluate legal and regulatory implications, data protection and security measures, customer authentication mechanisms, business continuity arrangements and vendor risks. Pilot phases with defined metrics, layered controls and clear escalation procedures reduce operational surprises and inform safe rollouts.

When is it appropriate to seek external legal or regulatory advice?

External advice is appropriate for complex regulatory interpretations, cross‑border transactions, significant regulatory inquiries, disputes with supervisors or when the institution lacks internal expertise for specialised matters such as tax, foreign investment or regulatory litigation. Using advisers with sector experience supports informed decision‑making and helps manage exposure to regulatory risk.

Further reading and related practice areas

Institutions requiring deeper engagement on specific topics commonly work with specialists across practice areas. Relevant practice areas include financial services regulatory work, tax advice and foreign investment counsel. For practical assistance and further information on related services refer to /financial-services-regulatory-lawyers/, /tax-lawyers/ and /foreign-direct-investment-lawyers/.

Closing observations

Maintaining a credible compliance programme is a continuous endeavour that combines governance, people, processes and technology. Supervisory environments evolve and compliance programmes that incorporate regular monitoring, testing and a culture of accountability are better positioned to respond constructively to regulatory expectations. For institutions seeking structured legal support, material in this article can guide preparatory work ahead of targeted engagement with advisers and regulators.

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org
WhatsApp