TRW KNOWLEDGE · LEGAL INFORMATION
Understanding Financial Crime Laws in Bangladesh
Financial crime laws in Bangladesh cover money laundering, fraud, corruption and other misconduct that affect trust in the financial system. This article outlines the principal legal framework, core compliance obligations, practical risk-management steps, and common pitfalls for businesses and individuals operating in or with Bangladesh.
Introduction
Financial crime laws in Bangladesh are designed to protect the integrity of the financial system and to reduce the harms that arise from illicit flows of funds, deceptive practices and abuse of position. For businesses, financial institutions and individuals who engage with the Bangladesh market, a practical understanding of the statutory framework and common compliance expectations supports risk management and helps to limit legal and reputational exposure. This article explains the principal statutes and regulators, sets out core compliance measures and provides an actionable compliance pathway. It is written as general legal information and does not substitute for tailored legal advice.Legal framework: the principal statutes and regulators
The statutory architecture relevant to financial crime in Bangladesh combines anti‑money‑laundering provisions, anti‑corruption rules, sectoral financial regulation and instruments addressing cyber‑enabled wrongdoing. Multiple agencies share responsibilities for investigation, supervision and enforcement. The table below summarises the primary laws commonly cited in discussions of financial crime governance.| Law | Year Enacted | Key focus |
|---|---|---|
| Money Laundering Prevention Act | 2002 | Identification of suspicious transactions and prevention of the integration of illicit funds |
| Prevention of Corruption Act | 2004 | Prohibitions and penalties related to corrupt conduct in public and private sectors |
| Financial Institutions Act | 1993 | Prudential regulation and supervision of banking and other authorised financial institutions |
| Cyber Security Act | 2021 | Offences and protections related to computer systems and cyber‑enabled fraud |
Core obligations and common legal concepts
The statutory regime typically imposes a set of recurring obligations on entities that interact with the financial system. While precise duties vary by statute and regulator, the common elements include customer due diligence, suspicious transaction reporting, recordkeeping, and cooperation with authorised inquiries. Understanding these concepts helps institutions design practical controls that align with legal expectations.Customer due diligence (CDD)
CDD procedures require firms to identify and verify the identity of customers, understand the nature of a business relationship and assess risk indicators. Enhanced due diligence is expected for higher‑risk clients or transactions. A documented risk‑based approach that allocates greater resources to higher risk scenarios is a widely accepted compliance principle.Suspicious transaction reporting
Where transactions raise reasonable suspicion of illegal activity, reporting to a financial intelligence unit or another designated authority is typically required. Timely, accurate and confidential reporting strengthens the ability of authorities to disrupt illicit flows and supports cooperative investigations.Recordkeeping and retention
Maintaining clear, contemporaneous records of CDD, transaction monitoring results and internal decision‑making is essential. Records that demonstrate why a transaction was treated as routine or suspicious can be decisive if questions later arise about compliance.Designing a compliance programme: practical elements
A compliance programme that seeks to meet statutory expectations generally includes governance, risk assessment, policies and procedures, technology, training, monitoring and an escalation framework. The following sections describe each element and suggest practical measures.Governance and oversight
Assign clear roles and responsibilities for compliance oversight at board and senior management levels. An accountable senior officer with dedicated resources supports consistency and timeliness in decision‑making. Governance arrangements should align with the organisation’s size, complexity and risk profile.Risk assessment
Regular, documented risk assessments help identify where the organisation faces the greatest exposure to financial crime risks — for example, cross‑border payment corridors, politically exposed persons, cash‑intensive business lines, or new products and channels. Risk assessments should inform the allocation of controls and the frequency of monitoring.Policies and procedures
Written policies should cover CDD, transaction monitoring, sanctions screening, recordkeeping and reporting obligations. Procedures must translate policy into concrete steps for frontline staff, compliance officers and senior reviewers, and should be updated when laws or business models change.Technology and transaction monitoring
Appropriate technology supports the detection of anomalous flows and unusual patterns. Automated monitoring tools, when calibrated to the institution’s risk profile, can increase detection efficiency and reduce false positives. Technology should complement, not replace, documented human review and decision‑making.Training and culture
Training programmes tailored to role and seniority provide staff with the knowledge to recognise and respond to red flags. A culture that emphasises compliance, ethical conduct and timely reporting reduces the likelihood that suspicious activity will go unreported.Step‑by‑step operational guide
- Map products, services and geographies to identify inherent financial crime risks.
- Adopt a written risk‑based AML/anti‑corruption policy endorsed by senior management.
- Implement CDD and screening controls at onboarding and during the customer lifecycle.
- Deploy monitoring to detect unusual behaviours and investigate alerts promptly.
- Report suspicious matters to the appropriate authority in accordance with law.
- Retain comprehensive records and prepare for regulatory or investigative requests.
- Review and test controls periodically and after major business or legal changes.
Investigations and cooperation with authorities
When authorities initiate enquiries or investigations, cooperation can reduce friction and help establish facts. Firms commonly appoint legal counsel to manage the response, coordinate document production and preserve privileged material where applicable. Cooperation should be structured, lawful and recorded, with attention to confidentiality rules and procedural safeguards.Cross‑border considerations
Cross‑border transactions raise issues of multiple legal regimes, correspondent banking relationships and differing standards of information sharing. Entities operating internationally should consider how local rules interact with other jurisdictions’ obligations and the organisation’s own global policies. Where appropriate, seek specialist advice from lawyers experienced in international compliance, such as teams focused on financial services regulation or foreign investment matters; see /financial-services-regulatory-lawyers/ and /foreign-direct-investment-lawyers/ for related practice areas.Technology, data protection and cyber risks
Digital channels increase both convenience and exposure to cyber‑enabled fraud. Controls should include secure authentication, transaction‑level anomaly detection and incident response plans that coordinate legal, technical and communications functions. Data protection obligations must be balanced with reporting duties; organisations should consult relevant legal and privacy specialists when designing data flows and retention schedules, including counsel in related areas such as /tax-lawyers/ when tax reporting intersects with AML obligations.Corporate governance, internal investigations and remediation
When a suspected internal or third‑party misconduct arises, an internal investigation should be proportionate, documented and, where appropriate, supported by independent experts. Findings should lead to remedial actions such as policy updates, personnel measures or enhanced controls. Transparent governance and prompt corrective steps reduce the likelihood of recurrence and help demonstrate a commitment to compliance.Common mistakes and how to avoid them
Certain recurring errors increase legal and operational risk. Common missteps include relying on outdated risk assessments, failing to adapt to new delivery channels, weak recordkeeping and inadequate escalation when red flags appear. Practical mitigations include scheduled reviews, scenario testing, role‑based training and management sign‑off on critical compliance decisions.Recent trends and evolving priorities (contextual note)
The compliance environment evolves as regulators and legislatures respond to emerging threats. Recent policy work in many jurisdictions emphasises stronger penalties, enhanced information exchange and closer oversight of non‑bank financial actors. Organisations should adopt a posture of anticipatory compliance: monitoring legal developments, reassessing risks promptly and adjusting controls to address new modalities of abuse. Where legislative or regulatory proposals are under discussion, entities should consult counsel before implementing material operational changes.When to seek specialist legal assistance
Early engagement with experienced legal advisers can reduce risk and clarify obligations. Consider prompt advice when a suspicious activity report may be required, when an authority begins enquiries, or when a major product or market expansion raises novel compliance questions. Legal teams that combine regulatory, transactional and dispute experience are helpful — for example, practitioners who advise on financial services regulation, employment matters or disputes can assist across the lifecycle of a compliance matter; see /our-practices/, /our-firm/ and /services/ for broader context on multidisciplinary support.Brief legal‑information disclaimer
This article provides general information about financial crime laws and compliance considerations in Bangladesh. It is not legal advice and does not create a lawyer‑client relationship. For advice tailored to specific facts, consult qualified legal counsel. For enquiries about professional services, please use the organisation’s published contact route at /contact/.For broader context on TRW’s work across criminal, banking, financial-regulatory and dispute matters, readers can explore TRW Law Firm, its practice areas, the firm’s legal services, and the appropriate route to contact the team. These resources provide general information and do not replace advice on a particular record, transaction, regulatory question or current legal position.FAQ
Q: What behaviour commonly triggers suspicion in transaction monitoring?
A: Indicators of suspicious activity often include rapid movement of funds through multiple accounts, payments inconsistent with a customer’s stated business, use of shell or nominee entities, frequent large cash deposits and transactions routed through jurisdictions with weak transparency. Unusual patterns should prompt documented inquiries and, where suspicions persist, reporting to the competent authority. The objective is to assess whether activity deviates materially from reasonable commercial explanations.Q: How should a small or medium enterprise approach compliance if it has limited resources?
A: SMEs can adopt a scaled approach that focuses resources on the highest risks. Practical steps include developing a concise risk assessment, creating a simple customer identification process, training staff on red flags, and documenting transactions above defined thresholds. Where internal resources are constrained, consider outsourcing specialised functions or obtaining periodic external reviews. Proportionality and documentation are central: an SME’s programme should be demonstrable and consistently applied.Q: What protections exist for someone who files a suspicious transaction report?
A: Many legal systems provide confidentiality and protections for individuals and entities that file reports in good faith, to encourage reporting without fear of retaliation. Organisations should have internal policies that prohibit adverse action against staff who make compliant disclosures and that preserve the confidentiality of reports in accordance with law. If a reporter faces retaliation or other legal exposure, timely legal advice is important to understand available remedies and protections.Q: How long should records be retained to meet legal expectations?
A: Retention periods vary by statute and regulatory guidance, and may differ for transaction records, customer identification and internal investigation files. A common compliance practice is to retain core transaction and CDD records for a minimum period aligned with regulatory requirements and to extend retention where investigations or litigation are possible. Organisations should align retention policies with legal obligations and privacy constraints, documenting the rationale for retention periods.Q: What steps should an organisation take if it discovers historical compliance gaps?
A: When historical gaps are identified, organisations should assess the scope and materiality, remediate immediate control weaknesses, preserve potentially relevant records and consider disclosure obligations to regulators. Legal counsel can advise on the balance between voluntary disclosure and other response options. Remediation plans should include corrective measures, monitoring for recurrence and training to embed improved practices.Q: Can international cooperation affect an investigation involving Bangladesh?
A: Cross‑border investigations commonly involve cooperation between authorities, mutual legal assistance requests and coordination with foreign counsel. Such cooperation can broaden the scope and speed of evidence gathering but also raises complexities around data sharing, privilege and forum considerations. Organisations should prepare for international engagement by maintaining clear records, understanding which jurisdictions are involved and seeking counsel experienced in cross‑border regulatory matters.Q: How do anti‑corruption rules interact with corporate governance obligations?
A: Anti‑corruption rules often intersect with governance by requiring transparency, internal controls and oversight mechanisms that prevent misuse of authority. Boards and senior management are expected to set a clear tone, implement controls that limit conflicts of interest and ensure appropriate oversight of third parties and facilitators. Firms should integrate anti‑corruption considerations into procurement, sales and partnership processes to reduce exposure.Practical resources and related practice areas
Entities managing financial crime risk may benefit from multi‑disciplinary input. Relevant advisory areas include financial services regulatory compliance, transactional advice for inbound investors and tax considerations that affect structuring and reporting. Specialist practitioners in /financial-services-regulatory-lawyers/, /foreign-direct-investment-lawyers/ and /tax-lawyers/ can provide complementary perspectives. For disputes or arbitration arising from related matters, advice from an experienced /leading-arbitration-lawyer/ may be relevant. For litigation or cause list matters in the national courts, see resources such as /supreme-court-bangladesh-cause-list/ to understand procedural scheduling.Closing observations
Managing financial crime risk demands a disciplined and documented approach that combines proportionate policies, targeted monitoring, clear escalation channels and an ethical culture. Regular review, staff engagement and timely legal input strengthen resilience. Where uncertainty exists about how a legal requirement applies to particular facts or transactions, obtaining tailored legal advice is the prudent course.CONTINUE EXPLORINGConnected
Connected
legal insight.
Let’s discuss
the detail.
For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org