As the Central Bank of Sri Lanka (CBSL) rolls out a series of new governance and compliance directives, the regulatory landscape for financial institutions is undergoing a transformative shift. These updates are not just routine amendments, they signal a broader movement toward stronger oversight, greater accountability, and higher ethical standards. For organizations operating in Sri Lanka’s financial and professional services sectors, the message is clear: the time to act is now.
Understanding the Regulatory Shift
CBSL has introduced significant regulatory changes in 2024 and 2025, aimed at enhancing financial stability, corporate governance, and institutional resilience. Chief among these is Banking Act Direction No. 05 of 2024, which comes into effect on January 1, 2025.
Key Highlights:
Stronger Board Governance
By 2027, at least 50% of directors on a bank’s board must be independent. Gender representation is also being addressed, with at least one female director required by the end of 2025.
Mandatory Board Committees
All regulated entities must form specialized board committees for audit, risk, nominations, remuneration, and related party transactions.
Separation of Powers
The Chairperson of a financial institution must be independent and cannot serve as the CEO, ensuring clear separation between strategic oversight and day-to-day management.
Robust Internal Oversight
Internal audit, risk management, and compliance roles must now operate with greater independence, providing direct reports to the board or relevant subcommittees.
Stricter AML/CFT Controls
With a mutual evaluation by the Asia Pacific Group scheduled for 2025, Sri Lanka is under increased pressure to tighten its Anti-Money Laundering and Countering the Financing of Terrorism frameworks.
Enhanced Cybersecurity & Tech Risk Regulations
Institutions must now report cyber incidents and comply with CBSL’s updated Technology Risk Management Framework, raising the bar for data protection and IT governance.
Why Acting Now Is Crucial
These reforms will soon become mandatory, and ignoring them could lead to serious consequences. Waiting until the last minute can result in rushed setups, weak systems, and extra attention from regulators.
Taking action early helps any organizations to:
- Reduce the risk of breaking regulations
- Strengthen internal systems and board responsibilities
- Boost your organization’s performance and reputation
- Show that you’re serious about good governance and ethics
Where NorthLark Makes a Difference
Adapting effectively to CBSL’s sweeping changes demands strategic execution, expert insight, and tools that support ongoing compliance. NorthLark, as an all in one entity management system, delivers precisely that capability.
NorthLark’s Entity Management System enables businesses to centralize and streamline compliance documentation, governance records, and entity structures, all within a single digital platform.
With its emphasis on identity verification, transaction monitoring, and reporting automation, NorthLark ensures organizations remain oversight-ready and aligned with regulatory expectations.