Financial Integrity Monitor

Sri Lanka LK

Domains (D1–D6)
5
Sources
12
Role actions
8
Horizon <90d
3
Jurisdiction profile
CleanTier BRisk: StableMixed

Sri Lanka operates AML/CFT under the Prevention of Money Laundering Act, Financial Transactions Reporting Act and Convention on Suppression of Terrorist Financing Act, supervised by the CBSL-housed Financial Intelligence Unit (Egmont member).

MoreRemoved from the FATF grey list in 2019 and remains in APG enhanced follow-up. No dedicated virtual-asset/VASP regulatory regime exists, and beneficial-ownership transparency for trusts/legal persons remains weak, exploited by offshore professional facilitators.

Key deficiencies
  • No centralized, publicly accessible beneficial-ownership register for legal persons and trusts
  • Historic FATF-flagged gaps in timely access to beneficial-ownership information and Trust Ordinance modernisation
  • Absence of a dedicated virtual-asset/VASP licensing and AML framework
  • Weak transaction-verification controls in sovereign payment/treasury systems (BEC fraud exposure)
  • Stalled elite-corruption prosecutions despite CIABOC's nominal mandate
Recent developments (18m)
  • UK Global Human Rights sanctions regime designation of 4 individuals for civil-war era abuses (24 March 2025)
  • Central Bank/Finance Ministry $2.5m business-email-compromise fund diversion revealed (April 2026), investigation ongoing
  • UNODC-supported development of a national strategy to counter organized crime (2025-2026)
  • UNODC-Sri Lanka/Maldives joint project tracing drug-related illicit financial flows to terrorism financing (December 2025)
  • FATF/APG follow-up report technical-compliance update (latest update December 2025); Sri Lanka remains in enhanced follow-up
  • OHCHR report (February 2026) documenting Sri Lankan nationals trafficked into Southeast Asian scam-centre forced criminality
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

This cycle establishes the first FIM interpretation baseline for Sri Lanka, setting a jurisdictional risk posture assessed as mixed between enforcement and enablement, and mixed between structural and episodic drivers. Sri Lanka is not currently listed on the FATF grey or black list, having been removed from grey-list monitoring in October 2019, though it remains under Asia/Pacific Group enhanced follow-up pending a full Mutual Evaluation expected around mid-2027. Against this comparatively clean formal standing, the baseline surfaces a durable elite-protection pattern in the corporate-transparency space: politically exposed Sri Lankan officials and associates used offshore trusts and shell companies administered by corporate service providers in Singapore and the United Arab Emirates to acquire luxury real estate, artwork and cash, obscuring beneficial ownership from Sri Lankan courts and the financial intelligence unit, as exposed by the 2021 Pandora Papers leak. No confirmed material prosecutorial outcome on the resulting referral to the Commission to Investigate Allegations of Bribery or Corruption, concerning Rajapaksa-family offshore trusts, has been identified within an eighteen-month baseline window, and no centralized, publicly accessible beneficial-ownership register for legal persons or trusts exists to close the underlying structural gap.

The baseline also establishes two further architecture-level signals of comparable weight. First, a business-email-compromise scheme diverted approximately 2.5 million US dollars from five loan-repayment instalments intended for Australian export-finance counterparties between December 2025 and March 2026, exploiting weak email-authentication and payment-verification controls within sovereign Treasury payment infrastructure; the destination and further laundering path of the diverted funds remains unestablished. Second, Sri Lanka is confirmed, per a February 2026 OHCHR report, as a source-of-labour jurisdiction for the regional Southeast Asian scam-crypto laundering ecosystem, with jobseekers recruited via fraudulent job advertisements trafficked into guarded compounds in Myanmar, Cambodia and Laos and forced to run online romance and crypto scams. Sri Lanka has no dedicated virtual-asset service provider licensing or crypto-specific AML framework, a structural gap that intersects directly with this confirmed exposure.

Other Developments

Sanctions-regime divergence on human-rights grounds sharpened this cycle. OFSI and the Foreign, Commonwealth and Development Office designated four individuals under the UK Global Human Rights sanctions regime on 24 March 2025, including former senior Sri Lankan military commanders and ex-LTTE/Karuna Group leader Vinayagamoorthy Muralitharan, for extrajudicial killings, torture and sexual violence during the civil war. No parallel US Treasury OFAC or EU asset-freeze designation of the same four individuals has been identified as of the baseline date, a divergence assessed as sharper than that typically observed on Russia-related designations, where the three blocs tend to act in closer parallel.

FATF and APG technical-compliance monitoring continues on a steady track. The latest technical-compliance follow-up update for Sri Lanka, dated December 2025, confirms continued enhanced follow-up status pending the next full Mutual Evaluation, estimated for mid-2027, which will be the first assessment to apply current FATF effectiveness-testing methodology since 2015.

Trade conditionality outside the AML supervisory perimeter offers a parallel governance lever. A new EU GSP Regulation, signed in June 2026 and applying from 1 January 2027 for a further ten years, continues twenty-seven-to-thirty-two-convention conditionality underpinning the status of Sri Lanka as the third-largest GSP+ beneficiary, a non-financial-sanctions mechanism sustaining reform pressure independent of the EU AML Package, from which Sri Lanka as a non-EEA state is structurally excluded.

A narcotics-transit terrorism-finance nexus was traced by UNODC through parcel-mail and air-cargo channels in Sri Lanka, with proceeds from synthetic drugs, hashish and cocaine trafficking assessed as divertible into terrorism financing. Sri Lanka Customs interdicted 4.2 kilograms of synthetic drugs at the Colombo Central Postal Mail Exchange and 17.5 kilograms of hashish and cocaine at Bandaranaike International Airport, including the first slab-form cocaine interdiction for the jurisdiction, demonstrating capacity gains following UNODC training support.

A national organized-crime strategy built around four pillars, prevention, pursuit of groups and proceeds, protection, and partnership, is moving toward defined implementing activities during 2026, following 2025 UNODC-supported workshops; sustained follow-through would strengthen inter-agency AML and organized-crime enforcement architecture.

Formal high-risk listing status remains unchanged. Sri Lanka is not listed on the current EU high-risk third country delegated regulation nor the UK Money Laundering Regulations high-risk third country advisory notice as of the baseline date, though the two lists move independently and are re-verified each cycle rather than assumed stable.

Cross-Monitor Connections

The confirmed trafficking of Sri Lankan nationals into forced criminality within the Southeast Asian scam-crypto ecosystem, with proceeds laundered on-chain and through informal remittance channels, has been flagged to SCEM given relevance to organized-crime and conflict-adjacent financial-flow monitoring. The same OHCHR-documented forced-criminality ecosystem, spanning cross-border victim and proceeds flows, has also been flagged toward AIM given the bearing of that ecosystem on anti-human-trafficking monitoring architecture. Read together with the narcotics-transit terrorism-finance nexus traced through parcel-mail and air-cargo channels in Sri Lanka, the baseline positions Sri Lanka less as a hosting or enforcement jurisdiction and more as a source-country node feeding regional illicit-finance infrastructure that properly requires monitoring across financial-integrity, conflict-finance and human-trafficking lenses simultaneously.

Outlook

The forward horizon for Sri Lanka is dominated by non-AML-specific levers rather than binding EU AML Package instruments, from which the jurisdiction remains structurally excluded as a non-EEA state. The nearest term structural test is the next full FATF Mutual Evaluation for Sri Lanka, expected around mid-2027, which will apply the current effectiveness-testing methodology, including virtual-asset effectiveness testing, for the first time since 2015, and is generally expected to surface effectiveness gaps not visible through technical-compliance follow-up alone, particularly around beneficial ownership and virtual-asset supervision. The renewed EU GSP+ conditionality, applying from 1 January 2027, will continue to function as a governance-leverage mechanism adjacent to, but distinct from, AML supervisory frameworks. Whether the four-pillar national organized-crime strategy converts 2026 implementation activity into a durable strengthening of inter-agency AML architecture, and whether the stalled Pandora Papers-linked CIABOC referral produces a material prosecutorial outcome, will be the clearest tests of whether the mixed enforcement-versus-enablement posture of Sri Lanka shifts toward enforcement or continues to reflect elite-protection dynamics consistent with partial capture of the accountability pipeline. Confidence in that read remains assessed rather than high pending further-cycle evidence.

weekly_brief_draft · JID LK
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The baseline position of Sri Lanka on the international sanctions-architecture ledger is, on its face, unremarkable. The jurisdiction is not on the FATF grey or black list, having been removed from grey-list monitoring in October 2019, and it remains under Asia/Pacific Group enhanced follow-up, with the latest technical-compliance follow-up update dated December 2025, ahead of a full Mutual Evaluation expected around mid-2027. Sri Lanka is also absent from both the current EU high-risk third country delegated regulation and the UK Money Laundering Regulations high-risk third country advisory notice as of this baseline. These two lists move independently of one another rather than in lockstep, and the baseline treats each as requiring re-verification at every cycle rather than an assumption of continuity between them.

Set against that comparatively clean formal standing, the most architecturally significant development this cycle is the exercise by the UK of an entirely separate sanctions instrument, one that operates outside the FATF/APG technical-compliance track altogether. On 24 March 2025, OFSI, acting alongside the Foreign, Commonwealth and Development Office, designated four individuals under the UK Global Human Rights sanctions regime. The designees include former senior Sri Lankan military commanders and ex-LTTE/Karuna Group leader Vinayagamoorthy Muralitharan, sanctioned for extrajudicial killings, torture and sexual violence committed during the civil-war era. As of the baseline, no parallel US Treasury OFAC or EU asset-freeze designation of the same four individuals has been identified.

This absence is assessed, not merely observed. The available evidence does not point to an evidentiary or capacity gap in Washington or Brussels; rather, it is read as a genuine divergence in cross-bloc human-rights-sanctions policy, and one assessed as sharper than the divergence typically observed on Russia-related designations, where the UK, US and EU tend to act in closer parallel through coordinated designation cycles. The architectural reading that follows is that unilateral, single-bloc human-rights sanctions regimes now function as an independent enforcement channel, operating without the coordination reflexes that have come to characterise the Russia sanctions ecosystem specifically. That is a structural feature of the current sanctions landscape with implications extending well beyond Sri Lanka: wherever a single jurisdiction human-rights sanctions authority moves unilaterally, the resulting designation gap becomes a standing feature of the compliance environment rather than a transitional anomaly awaiting harmonisation.

For obliged entities operating across the UK, US and EU nexus, the practical consequence of this divergence is a fragmented designation landscape in which screening against any single sanctions list is insufficient to capture the full universe of human-rights-driven exposure. A customer or counterparty cleared against the OFAC Specially Designated Nationals list or an EU asset-freeze annex may nonetheless carry UK Global Human Rights sanctions exposure that a US-only or EU-only screening architecture would miss entirely, and the inverse holds equally should Washington or Brussels act unilaterally in a future cycle. This is properly read as a structural screening-architecture question rather than an isolated compliance failure attributable to any single institution control environment; it is the sanctions-architecture equivalent of a coverage gap built into the multilateral system by design rather than by oversight.

The FATF/APG technical-compliance track, meanwhile, continues on a steady and largely uneventful trajectory. The December 2025 follow-up update confirms continued enhanced-follow-up status for Sri Lanka without escalation toward re-listing, and without the kind of adverse finding that would itself constitute a sanctions-architecture signal. The two tracks, FATF technical compliance and unilateral human-rights sanctions authority, are, on this baseline, moving on entirely independent timelines, evidencing that the formal AML/CFT standing of Sri Lanka and its human-rights-accountability exposure are assessed and acted upon through wholly separate institutional channels internationally.

Outlook

The clearest forward test for the sanctions-architecture posture of Sri Lanka is the next full FATF Mutual Evaluation, expected around mid-2027, which will apply the 2025-revised FATF methodology, including current-effectiveness and virtual-asset-effectiveness testing, for the first time since 2015. General industry expectation is that this current-methodology assessment will surface effectiveness gaps not visible through technical-compliance follow-up alone, a materially more searching exercise than the December 2025 update, which simply confirmed continued enhanced-follow-up status without probing underlying implementation effectiveness.

Independent of that FATF trajectory, whether the divergence between UK unilateral human-rights sanctions action and the continued absence of matching OFAC or EU designations narrows or persists is itself worth tracking at each future cycle. No public statement from OFAC or EU authorities has been identified explaining that absence, leaving open whether it reflects a considered political choice or an undisclosed capacity constraint, a distinction with material consequences for how obliged entities should weight the durability of the current designation gap. The continued absence of Sri Lanka from both the EU and UK high-risk third country lists should also be re-verified rather than assumed stable, given that the two lists have moved independently of each other in the past and could diverge again with limited warning.

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

This is the inaugural cycle of FIM coverage for Sri Lanka, so the cumulative sanctions-architecture picture rests on this single baseline; future cycles will build on, rather than restate, the foundation established here. The starting position is a jurisdiction with a comparatively clean formal sanctions-list standing set against a live, unresolved cross-bloc divergence in human-rights-driven sanctions enforcement.

The baseline position of Sri Lanka on the international sanctions-architecture ledger is, on its face, unremarkable. The jurisdiction is not on the FATF grey or black list, having been removed from grey-list monitoring in October 2019, and it remains under Asia/Pacific Group enhanced follow-up, with the latest technical-compliance follow-up update dated December 2025, ahead of a full Mutual Evaluation expected around mid-2027. Sri Lanka is also absent from both the current EU high-risk third country delegated regulation and the UK Money Laundering Regulations high-risk third country advisory notice as of this baseline. These two lists move independently of one another rather than in lockstep, and this cumulative assessment will treat each as requiring re-verification at every future cycle rather than an assumption of continuity between them.

Set against that comparatively clean formal standing, the most architecturally significant development anchoring this cumulative baseline is the exercise by the UK of an entirely separate sanctions instrument, one that operates outside the FATF/APG technical-compliance track altogether. On 24 March 2025, OFSI, acting alongside the Foreign, Commonwealth and Development Office, designated four individuals under the UK Global Human Rights sanctions regime. The designees include former senior Sri Lankan military commanders and ex-LTTE/Karuna Group leader Vinayagamoorthy Muralitharan, sanctioned for extrajudicial killings, torture and sexual violence committed during the civil-war era. Through this baseline, no parallel US Treasury OFAC or EU asset-freeze designation of the same four individuals has been identified.

This absence is assessed, not merely observed, and forms the core interpretive judgment carried forward from this baseline. The available evidence does not point to an evidentiary or capacity gap in Washington or Brussels; rather, it is read as a genuine divergence in cross-bloc human-rights-sanctions policy, and one assessed as sharper than the divergence typically observed on Russia-related designations, where the UK, US and EU tend to act in closer parallel through coordinated designation cycles. The architectural reading carried forward is that unilateral, single-bloc human-rights sanctions regimes now function as an independent enforcement channel, operating without the coordination reflexes that have come to characterise the Russia sanctions ecosystem specifically, and that this fragmentation constitutes a durable screening-architecture gap rather than a transitional anomaly.

For obliged entities operating across the UK, US and EU nexus, this baseline establishes that screening against any single sanctions list is insufficient to capture the full universe of human-rights-driven exposure connected to Sri Lanka. A customer or counterparty cleared against the OFAC Specially Designated Nationals list or an EU asset-freeze annex may nonetheless carry UK Global Human Rights sanctions exposure that a US-only or EU-only screening architecture would miss entirely, and the inverse holds equally should Washington or Brussels act unilaterally in a future cycle. This is properly read as a structural screening-architecture question rather than an isolated compliance failure attributable to any single institution control environment.

The FATF/APG technical-compliance track, meanwhile, has moved throughout this baseline period on a steady and largely uneventful trajectory, distinct from the human-rights-sanctions track described above. The December 2025 follow-up update confirms continued enhanced-follow-up status for Sri Lanka without escalation toward re-listing. The cumulative picture established at this first cycle is therefore of two institutional tracks moving independently, with the human-rights-sanctions divergence currently carrying the greater analytical weight for this domain.

Outlook

Going forward, this domain will be tracked along two axes established at this baseline: first, whether the FATF Mutual Evaluation expected around mid-2027, applying the 2025-revised methodology including virtual-asset effectiveness testing for the first time since 2015, surfaces effectiveness gaps beyond what the technical-compliance follow-up track has shown to date; and second, whether the divergence between UK unilateral human-rights sanctions action and the continued absence of matching OFAC or EU designations narrows, persists, or is joined by comparable unilateral action from a third bloc. No public statement from OFAC or EU authorities has been identified explaining the current absence of matching designations, leaving the capacity-versus-choice question open for resolution in future cycles. Continued absence of Sri Lanka from both the EU and UK high-risk third country lists should also be re-verified at each cycle rather than assumed stable, since the two lists have moved independently of one another before and could diverge again with limited warning. Absent movement on either axis, this baseline stands as the governing architecture for Sri Lanka sanctions-related coverage going forward.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

Sri Lanka sits outside the evolving beneficial-ownership and anti-money-laundering supervisory architecture of the European Union entirely: as a non-EU, non-EEA third country, it falls outside the directly-applicable scope of the AML Regulation, outside the Sixth AML Directive Member State transposition requirement, and outside the direct and indirect supervisory perimeter of the Anti-Money Laundering Authority. No 6AMLD transposition question therefore applies to Sri Lanka, and the principal EU-linked exposure for the jurisdiction runs instead through two adjacent, non-AML-specific levers: the EU high-risk third country delegated regulation, on which Sri Lanka is not currently listed, and GSP+ trade conditionality, addressed further below. The directly relevant beneficial-ownership developments for Sri Lanka this cycle are domestic rather than EU-derived, and it is to those that the assessment turns first.

Sri Lanka has no centralized, publicly accessible beneficial-ownership register for legal persons or trusts. This structural absence is the backdrop against which a durable elite-protection pattern has played out: politically exposed Sri Lankan officials and associates used offshore trusts and shell companies administered by corporate service providers based in Singapore and the United Arab Emirates, the 2021 Pandora Papers leak specifically identified Singapore-based Asiaciti Trust in this role, to acquire luxury real estate, artwork and cash across low-tax jurisdictions, obscuring beneficial ownership from Sri Lankan courts and the domestic financial intelligence unit. The resulting referral to the Commission to Investigate Allegations of Bribery or Corruption, concerning Rajapaksa-family offshore trusts, shows no confirmed material prosecutorial outcome within an eighteen-month baseline window.

Read together, the absence of a centralized BO register and the stalled CIABOC referral are assessed, at Assessed confidence, as indicating elite-protection dynamics consistent with partial state capture of the enforcement pipeline, rather than a pure capacity deficit. That distinction matters analytically: a capacity deficit implies the gap narrows with technical assistance and time; a state-capture dynamic implies the gap persists until the underlying political-economy incentives shift, regardless of technical-assistance investment in registry infrastructure. Historic FATF ICRG findings have separately flagged gaps in timely competent-authority access to beneficial-ownership information and called for modernisation of the Trust Ordinance, though current evidence does not establish whether that modernisation, or registry development more broadly, has advanced beyond those historic findings. The obligation gap is documented under FATF Recommendations 24 and 25, covering customer due diligence and governance and transparency obligations respectively, with the control-gap signal assessed as partial rather than absent, obliged entities operating in or with exposure to Sri Lanka retain functioning CDD frameworks but lack the registry infrastructure that would allow verification of ultimate beneficial ownership independent of customer self-disclosure.

Standing beneath any single jurisdiction beneficial-ownership posture is the structural fact of the AML Package of the European Union, which continues to reshape the baseline against which beneficial-ownership regimes worldwide are increasingly measured, even where, as with Sri Lanka, a jurisdiction sits outside its direct perimeter. The EU AML Package comprises three distinct instruments: the AML Regulation, or AMLR, Regulation (EU) 2024/1624, which is directly applicable across EU Member States without national transposition; the Sixth AML Directive, or 6AMLD, which each Member State transposes into domestic law; and the AMLA Regulation, Regulation (EU) 2024/1620, which establishes the Anti-Money Laundering Authority and its direct and indirect supervisory perimeter over designated obliged entities. Together these instruments shift EU supervision from a purely national-authority model toward a hybrid EU-level regime, with AMLA assuming direct supervisory responsibility for a defined set of higher-risk cross-border obliged entities while indirect supervision and 6AMLD transposition remain distributed across national supervisors. This architecture is a durable structural backdrop against which the beneficial-ownership signal for Sri Lanka this cycle should be read: it illustrates the direction of travel toward centralised, harmonised BO transparency regimes internationally, even as it confirms, by contrast, that the registry gap in Sri Lanka sits wholly outside that harmonising pressure and must instead be closed through domestic reform or FATF Mutual Evaluation leverage.

Outlook

The nearest forward-looking test of the beneficial-ownership posture of Sri Lanka will arrive via the FATF Mutual Evaluation expected around mid-2027, which will apply current-effectiveness testing to beneficial-ownership access and use for the first time since 2015 and is likely to test directly whether the registry gap and the stalled CIABOC referral have been addressed in the interim. Absent a confirmed prosecutorial outcome or registry development before that assessment, the current baseline, no centralized BO register, an unresolved elite-asset-flight referral, and a jurisdiction structurally outside the harmonising perimeter of the EU AML Package, should be treated as the durable status quo rather than a transitional state. Any future cycle showing either a confirmed CIABOC outcome or concrete registry-development legislation would represent a genuine structural shift warranting a reassessment of the current partial-capture judgment; absent such movement, this pattern is expected to persist unchanged.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

This is the first cycle of FIM coverage for Sri Lanka, so the cumulative beneficial-ownership picture rests on this single baseline and will be built upon, rather than restated, in subsequent cycles.

Sri Lanka sits outside the evolving beneficial-ownership and anti-money-laundering supervisory architecture of the European Union entirely: as a non-EU, non-EEA third country, it falls outside the directly-applicable scope of the AML Regulation, outside the Sixth AML Directive Member State transposition requirement, and outside the direct and indirect supervisory perimeter of the Anti-Money Laundering Authority. No 6AMLD transposition question therefore applies to Sri Lanka, and the principal EU-linked exposure for the jurisdiction runs instead through two adjacent, non-AML-specific levers established at this baseline: the EU high-risk third country delegated regulation, on which Sri Lanka is not currently listed, and GSP+ trade conditionality. The directly relevant beneficial-ownership developments for Sri Lanka are domestic rather than EU-derived, and this cumulative assessment turns to those first, as the standing analytical anchor for the domain.

Sri Lanka has no centralized, publicly accessible beneficial-ownership register for legal persons or trusts. This structural absence is the backdrop against which a durable elite-protection pattern has been documented at this baseline: politically exposed Sri Lankan officials and associates used offshore trusts and shell companies administered by corporate service providers based in Singapore and the United Arab Emirates, the 2021 Pandora Papers leak specifically identified Singapore-based Asiaciti Trust in this role, to acquire luxury real estate, artwork and cash across low-tax jurisdictions, obscuring beneficial ownership from Sri Lankan courts and the domestic financial intelligence unit. The resulting referral to the Commission to Investigate Allegations of Bribery or Corruption, concerning Rajapaksa-family offshore trusts, shows no confirmed material prosecutorial outcome within an eighteen-month window captured in this baseline.

Read together, and carried forward as the standing interpretive judgment for this domain, the absence of a centralized BO register and the stalled CIABOC referral are assessed, at Assessed confidence, as indicating elite-protection dynamics consistent with partial state capture of the enforcement pipeline, rather than a pure capacity deficit. A capacity deficit implies the gap narrows with technical assistance and time; a state-capture dynamic implies the gap persists until the underlying political-economy incentives shift, regardless of technical-assistance investment in registry infrastructure. Historic FATF ICRG findings have separately flagged gaps in timely competent-authority access to beneficial-ownership information and called for modernisation of the Trust Ordinance, though current evidence does not establish whether that modernisation, or registry development more broadly, has advanced beyond those historic findings. The obligation gap is documented under FATF Recommendations 24 and 25, covering customer due diligence and governance and transparency obligations respectively, with the control-gap signal assessed as partial rather than absent.

Standing beneath this baseline, and carried forward as durable structural context for every future cycle of this domain, is the three-instrument architecture of the AML Package of the European Union. The EU AML Package comprises the AML Regulation, or AMLR, Regulation (EU) 2024/1624, directly applicable across EU Member States without national transposition; the Sixth AML Directive, or 6AMLD, transposed by each Member State into domestic law; and the AMLA Regulation, Regulation (EU) 2024/1620, establishing the Anti-Money Laundering Authority and its direct and indirect supervisory perimeter over designated obliged entities. Together these instruments shift EU supervision from a purely national-authority model toward a hybrid EU-level regime. This architecture is the durable backdrop against which the beneficial-ownership signal for Sri Lanka is read at every cycle: it illustrates the direction of travel toward centralised, harmonised BO transparency regimes internationally, even as it confirms, by contrast, that the registry gap in Sri Lanka sits wholly outside that harmonising pressure.

Outlook

The nearest forward-looking test of the beneficial-ownership posture of Sri Lanka, and the marker against which this cumulative baseline will next be updated, is the FATF Mutual Evaluation expected around mid-2027, which will apply current-effectiveness testing to beneficial-ownership access and use for the first time since 2015 and is likely to test directly whether the registry gap and the stalled CIABOC referral have been addressed in the interim. Absent a confirmed prosecutorial outcome or registry development before that assessment, this baseline, no centralized BO register, an unresolved elite-asset-flight referral, and a jurisdiction structurally outside the harmonising perimeter of the EU AML Package, stands as the durable status quo rather than a transitional state. Any future cycle showing either a confirmed CIABOC outcome or concrete registry-development legislation would represent a genuine structural shift warranting reassessment of the partial-capture judgment recorded here; absent such movement, this baseline is expected to persist unchanged into subsequent cycles.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The baseline enabler-jurisdiction exposure of Sri Lanka runs in two directions simultaneously: outward, through the professional-facilitator infrastructure that receives Sri Lankan elite capital flight, and inward, through the transnational trafficking networks that exploit the maritime and logistics position of Sri Lanka. Both patterns were established this cycle and are assessed as durable rather than episodic.

On the outward axis, politically exposed Sri Lankan officials and associates used offshore trusts and shell companies administered by corporate service providers based in Singapore and the United Arab Emirates, the 2021 Pandora Papers leak specifically identified Singapore-based Asiaciti Trust in this role, to acquire luxury real estate, artwork and cash across low-tax jurisdictions, obscuring beneficial ownership from Sri Lankan courts and creditors. This is the textbook enabler-jurisdiction pattern: the professional-facilitator infrastructure sits entirely outside the domestic regulatory perimeter of Sri Lanka, in jurisdictions with well-developed corporate-services sectors and comparatively permissive beneficial-ownership disclosure requirements for foreign-administered trust structures, meaning that closing the domestic beneficial-ownership register gap in Sri Lanka would only partially address the exposure, the facilitator infrastructure itself sits in Singapore and the UAE, beyond the regulatory reach of Colombo. The absence of a confirmed material prosecutorial outcome on the resulting CIABOC referral compounds this: even where the underlying assets and structures are documented via investigative journalism, the accountability pipeline from documentation to enforcement has not converted into an outcome within an eighteen-month baseline window.

On the inward axis, the position of Sri Lanka on Indian Ocean shipping lanes and growing parcel-mail and air-cargo volumes are exploited by transnational networks moving synthetic drugs, hashish and cocaine, with the UN Office on Drugs and Crime explicitly framing the resulting illicit financial flows as divertible into terrorism financing, drug trafficking generating vast illicit profits that fuel organized crime and can be diverted to finance violent extremism. This is a three-level architecture in the classic sense: the scheme is narcotics movement through postal and air-cargo channels; the architecture is the informal and digital transfer infrastructure that launders the resulting proceeds; and the strategic consequence is the potential diversion of those proceeds into terrorism financing, a CTF-pillar finding that would otherwise be structurally under-weighted relative to the AML-pillar findings that dominate enforcement-volume reporting. Sri Lanka Customs interdicted 4.2 kilograms of synthetic drugs at the Colombo Central Postal Mail Exchange and 17.5 kilograms of hashish and cocaine at Bandaranaike International Airport, including the first slab-form cocaine interdiction for the jurisdiction, evidencing genuine capacity gains following UNODC Programme against Corruption and Crime training, a rare instance in this baseline where the enforcement axis, rather than the enablement axis, shows forward motion.

Two further developments bear on the enabler-jurisdiction assessment without fitting neatly into either the outward or inward axis. The renewed Generalised Scheme of Preferences Regulation of the European Union, signed in June 2026 and applying from 1 January 2027 for a further ten years, continues twenty-seven-to-thirty-two-convention conditionality underpinning the status of Sri Lanka as the third-largest GSP+ beneficiary, a governance-leverage mechanism operating adjacent to, but structurally distinct from, the AML supervisory perimeter from which Sri Lanka is otherwise excluded as a non-EEA state. Separately, a four-pillar national strategy against organized crime in Sri Lanka, spanning prevention, pursuit of groups and proceeds, protection, and partnership, is expected to move toward defined implementing activities during 2026, following 2025 UNODC-supported workshops; sustained implementation could meaningfully strengthen the inter-agency architecture needed to address both the outward elite-capital-flight pattern and the inward trafficking-finance nexus described above.

Outlook

The enabler-jurisdiction picture for Sri Lanka is best read as asymmetric: genuine capacity-building progress on the inward, narcotics-interdiction axis, set against a largely unaddressed outward axis where the professional-facilitator infrastructure enabling elite asset flight sits beyond the jurisdiction of Colombo entirely and where the domestic accountability pipeline, the CIABOC referral, remains stalled. Whether the move to implementation during 2026 by the four-pillar national organized-crime strategy extends capacity gains beyond narcotics interdiction into the beneficial-ownership and asset-recovery space is the clearest near-term signal to track. The GSP+ conditionality of the EU, renewed for a further ten years from 2027, will continue to apply external governance pressure independent of that domestic track, but as a trade-conditionality lever rather than an AML-supervisory one, its capacity to compel closure of the professional-facilitator gap specifically is limited by design.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

This is the first cycle of FIM coverage for Sri Lanka, so the cumulative enabler-jurisdiction picture rests on this single baseline, to be built upon in subsequent cycles rather than restated.

The baseline enabler-jurisdiction exposure of Sri Lanka runs in two directions simultaneously: outward, through the professional-facilitator infrastructure that receives Sri Lankan elite capital flight, and inward, through the transnational trafficking networks that exploit the maritime and logistics position of Sri Lanka. Both patterns, established at this baseline, are assessed as durable rather than episodic and will anchor this domain going forward.

On the outward axis, politically exposed Sri Lankan officials and associates used offshore trusts and shell companies administered by corporate service providers based in Singapore and the United Arab Emirates, the 2021 Pandora Papers leak specifically identified Singapore-based Asiaciti Trust in this role, to acquire luxury real estate, artwork and cash across low-tax jurisdictions, obscuring beneficial ownership from Sri Lankan courts and creditors. This is the textbook enabler-jurisdiction pattern: the professional-facilitator infrastructure sits entirely outside the domestic regulatory perimeter of Sri Lanka, in jurisdictions with well-developed corporate-services sectors and comparatively permissive beneficial-ownership disclosure requirements for foreign-administered trust structures. Closing the domestic beneficial-ownership register gap in Sri Lanka would therefore only partially address this exposure, since the facilitator infrastructure itself sits in Singapore and the UAE, beyond the regulatory reach of Colombo. The absence of a confirmed material prosecutorial outcome on the resulting CIABOC referral compounds this, and is carried forward as a standing gap: even where underlying assets and structures are documented via investigative journalism, the accountability pipeline from documentation to enforcement has not converted into an outcome within an eighteen-month window.

On the inward axis, the position of Sri Lanka on Indian Ocean shipping lanes and growing parcel-mail and air-cargo volumes are exploited by transnational networks moving synthetic drugs, hashish and cocaine, with the UN Office on Drugs and Crime explicitly framing the resulting illicit financial flows as divertible into terrorism financing. This baseline establishes a three-level architecture that will structure future-cycle tracking of this pattern: the scheme is narcotics movement through postal and air-cargo channels; the architecture is the informal and digital transfer infrastructure that launders the resulting proceeds; and the strategic consequence is the potential diversion of those proceeds into terrorism financing, a CTF-pillar finding that would otherwise be structurally under-weighted relative to AML-pillar findings. Sri Lanka Customs interdicted 4.2 kilograms of synthetic drugs at the Colombo Central Postal Mail Exchange and 17.5 kilograms of hashish and cocaine at Bandaranaike International Airport, including the first slab-form cocaine interdiction for the jurisdiction, evidencing genuine capacity gains following UNODC training, a rare instance in this baseline where the enforcement axis, rather than the enablement axis, shows forward motion.

Two further developments, carried forward as standing context, bear on the enabler-jurisdiction assessment without fitting neatly into either axis. The renewed Generalised Scheme of Preferences Regulation of the European Union, signed in June 2026 and applying from 1 January 2027 for a further ten years, continues twenty-seven-to-thirty-two-convention conditionality underpinning the status of Sri Lanka as the third-largest GSP+ beneficiary, a governance-leverage mechanism structurally distinct from the AML supervisory perimeter from which Sri Lanka is otherwise excluded. Separately, a four-pillar national strategy against organized crime in Sri Lanka is expected to move toward defined implementing activities during 2026, following 2025 UNODC-supported workshops.

Outlook

The enabler-jurisdiction picture for Sri Lanka, as established at this baseline and carried forward, is best read as asymmetric: genuine capacity-building progress on the inward, narcotics-interdiction axis, set against a largely unaddressed outward axis where the professional-facilitator infrastructure enabling elite asset flight sits beyond the jurisdiction of Colombo entirely and where the domestic accountability pipeline remains stalled. Whether the move to implementation during 2026 by the four-pillar national organized-crime strategy extends capacity gains beyond narcotics interdiction into the beneficial-ownership and asset-recovery space is the clearest near-term signal for future cycles to track. The GSP+ conditionality of the EU, renewed for a further ten years from 2027, will continue to apply external governance pressure independent of that domestic track, but its capacity to compel closure of the professional-facilitator gap specifically remains limited by design, and this baseline judgment should be revisited only upon confirmed evidence of movement on either axis.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The own digital-asset regulatory perimeter of Sri Lanka is, at baseline, undeveloped: no dedicated virtual-asset service provider licensing regime or crypto-specific anti-money-laundering framework has been identified for the jurisdiction, in contrast to regional peers that have advanced crypto-specific oversight during 2025 and 2026. This is the directly relevant starting point for assessing the digital-asset exposure of Sri Lanka, not the Markets in Crypto-Assets framework of the EU or the global virtual-asset standards of FATF, which function as contextual backdrop rather than the primary determinant of the regulatory posture of the jurisdiction itself.

That domestic regulatory vacuum sits alongside a confirmed and troubling exposure pattern. Per a February 2026 OHCHR report, Sri Lankan nationals are confirmed as trafficking victims within a regional scam-crypto laundering ecosystem estimated at tens of billions of dollars annually. Jobseekers recruited via fraudulent job advertisements are trafficked into guarded compounds in Myanmar, Cambodia and Laos and forced to run online romance and crypto scams; one survivor recounted being subjected to hours of water-prison style punishment after missing monthly scam targets. Scam proceeds are laundered on-chain and through informal remittance channels within this regional ecosystem. The role of Sri Lanka in this pattern is functionally distinct from that of the hosting jurisdictions where the scam compounds physically operate, or the jurisdictions building enforcement capacity against the resulting laundering infrastructure: Sri Lanka functions primarily as a source-of-labour exposure point, supplying trafficked personnel into a criminal enterprise whose financial architecture sits substantially outside Sri Lankan territory or regulatory reach.

The combination of these two findings, a confirmed source-country trafficking exposure into a crypto-enabled laundering ecosystem, and the complete absence of any domestic VASP licensing or crypto-AML framework, is assessed, at Possible confidence, as constituting an emerging structural gap rather than an episodic incident. The Possible-tier confidence reflects that the causal link between the regulatory vacuum specifically and the trafficking exposure specifically has not been established with the same evidentiary weight as either finding independently; what is established is that both conditions exist simultaneously and are, on their face, mutually reinforcing. A jurisdiction lacking any crypto-specific licensing or AML oversight has correspondingly limited domestic tooling to trace, freeze or investigate on-chain proceeds connected to its own trafficked nationals, even where the underlying labour-sourcing pattern is documented by international bodies. The firm types most directly exposed to this pattern are crypto-asset operators and payment companies handling retail and VASP-counterparty relationships linked to the affected corridor, reflecting both the payment-remittance leg used to move scam proceeds and the on-chain leg through which laundering ultimately occurs.

Set against this domestic picture, the global regulatory direction of travel, the virtual-asset standards of FATF, the MiCA framework of the EU, and the 2025-revised FATF Mutual Evaluation methodology incorporation of virtual-asset effectiveness testing, represents a structural backdrop against which the own regulatory vacuum of Sri Lanka will eventually be measured, most concretely at the next full Mutual Evaluation expected around mid-2027, the first assessment of Sri Lanka to apply virtual-asset effectiveness criteria. Until that assessment, the digital-asset framework of Sri Lanka remains, on current evidence, unbuilt rather than merely under-enforced.

Outlook

The clearest forward marker for the digital-asset posture of Sri Lanka is the mid-2027 FATF Mutual Evaluation, which will test virtual-asset effectiveness for the first time and is likely to surface the absence of any VASP licensing or crypto-AML regime as a material finding rather than a footnote. Absent a legislative proposal specific to virtual-asset regulation before that assessment, and none has been identified in the current research cycle, the worsening trajectory assigned to this domain, driven by the combination of a widening regional scam-crypto ecosystem and an unchanging domestic regulatory vacuum, is expected to persist. Any future cycle in which Sri Lanka introduces VASP-specific licensing, or in which the destination and laundering path of Sri Lankan-linked scam proceeds becomes traceable through domestic tooling, would represent the first concrete structural improvement against this baseline.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

This is the first cycle of FIM coverage for Sri Lanka, so the cumulative digital-asset picture rests on this single baseline, to be built upon rather than restated in subsequent cycles.

The own digital-asset regulatory perimeter of Sri Lanka is, at this baseline, undeveloped: no dedicated virtual-asset service provider licensing regime or crypto-specific anti-money-laundering framework has been identified for the jurisdiction, in contrast to regional peers that have advanced crypto-specific oversight during 2025 and 2026. This is the directly relevant starting point for the cumulative assessment of the digital-asset exposure of Sri Lanka, not the Markets in Crypto-Assets framework of the EU or the global virtual-asset standards of FATF, which function as contextual backdrop rather than the primary determinant of the regulatory posture of the jurisdiction itself. This vacuum also means that any future licensing or registration regime introduced for virtual-asset service providers in Sri Lanka would mark a first-order structural shift for this domain, given that no such regime has existed at any point captured by this baseline.

That domestic regulatory vacuum sits alongside a confirmed and troubling exposure pattern established at this baseline. Per a February 2026 OHCHR report, Sri Lankan nationals are confirmed as trafficking victims within a regional scam-crypto laundering ecosystem estimated at tens of billions of dollars annually. Jobseekers recruited via fraudulent job advertisements are trafficked into guarded compounds in Myanmar, Cambodia and Laos and forced to run online romance and crypto scams; one survivor recounted being subjected to hours of water-prison style punishment after missing monthly scam targets. Scam proceeds are laundered on-chain and through informal remittance channels within this regional ecosystem. The role of Sri Lanka in this pattern, carried forward as a standing characterisation, is functionally distinct from that of the hosting jurisdictions where scam compounds physically operate, or the jurisdictions building enforcement capacity against the resulting laundering infrastructure: Sri Lanka functions primarily as a source-of-labour exposure point, supplying trafficked personnel into a criminal enterprise whose financial architecture sits substantially outside Sri Lankan territory or regulatory reach.

The combination of these two findings, a confirmed source-country trafficking exposure into a crypto-enabled laundering ecosystem, and the complete absence of any domestic VASP licensing or crypto-AML framework, is assessed, at Possible confidence, as constituting an emerging structural gap rather than an episodic incident, and this judgment anchors the domain going forward. The Possible-tier confidence reflects that the causal link between the regulatory vacuum specifically and the trafficking exposure specifically has not been established with the same evidentiary weight as either finding independently; what is established is that both conditions exist simultaneously and are, on their face, mutually reinforcing. A jurisdiction lacking any crypto-specific licensing or AML oversight has correspondingly limited domestic tooling to trace, freeze or investigate on-chain proceeds connected to its own trafficked nationals. The firm types most directly exposed to this pattern are crypto-asset operators and payment companies handling retail and VASP-counterparty relationships linked to the affected corridor.

Set against this domestic picture, the global regulatory direction of travel, the virtual-asset standards of FATF, the MiCA framework of the EU, and the 2025-revised FATF Mutual Evaluation methodology incorporation of virtual-asset effectiveness testing, represents a structural backdrop, carried forward as standing context, against which the own regulatory vacuum of Sri Lanka will eventually be measured, most concretely at the next full Mutual Evaluation expected around mid-2027.

Outlook

The clearest forward marker for the digital-asset posture of Sri Lanka, and the trigger for the next material update to this cumulative assessment, is the mid-2027 FATF Mutual Evaluation, which will test virtual-asset effectiveness for the first time and is likely to surface the absence of any VASP licensing or crypto-AML regime as a material finding. Absent a legislative proposal specific to virtual-asset regulation before that assessment, the worsening trajectory assigned to this domain at this baseline, driven by the combination of a widening regional scam-crypto ecosystem and an unchanging domestic regulatory vacuum, is expected to persist into subsequent cycles. Any future cycle in which Sri Lanka introduces VASP-specific licensing, or in which the destination and laundering path of Sri Lankan-linked scam proceeds becomes traceable through domestic tooling, would represent the first concrete structural improvement against this baseline and would warrant revision of the worsening-trajectory judgment recorded here.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The clearest compliance-technology finding in this baseline is a business-email-compromise scheme that diverted approximately 2.5 million US dollars from sovereign Treasury payment channels. Between December 2025 and March 2026, criminals intercepted email communications between the Sri Lankan Treasury and Australian export-finance counterparties, enabling the redirection of five successive loan-repayment instalments into criminal-controlled accounts. The scheme exploited weak email-authentication and payment-verification controls within sovereign financial infrastructure, the kind of control gap that, at institutional scale, active-defence tooling such as payment-verification callback protocols, domain-authentication standards, and anomaly-detection on payment-instruction changes is specifically designed to close. That the exploited counterparty was a Central Bank and Treasury payment channel, rather than a commercial banking relationship, raises the stakes: sovereign payment infrastructure sits at the top of the trust hierarchy that correspondent banking and export-finance arrangements depend upon, and a successful business-email-compromise intrusion at that level signals a control gap with potential systemic reach across every counterparty relying on the authenticity of that same payment channel.

The destination and further laundering path of the diverted funds has not been established by investigators as of this baseline, which limits the ability of the assessment to trace whether the proceeds moved through the same enabler-jurisdiction or crypto-laundering infrastructure documented elsewhere in this baseline, or through an entirely separate channel. This is a material evidentiary gap rather than a closed investigation, and the current absence of a confirmed destination should not be read as an indication that tracing efforts have concluded.

The compliance-technology reading of this incident is twofold. First, it reflects a technology gap: the payment-verification controls that would ordinarily flag a change in payment instructions between long-standing counterparties evidently did not trigger, or were not in place, across the five successive fraudulent instalments, a repeated-exploitation pattern rather than a single lapse, suggesting the underlying control gap persisted across multiple payment cycles without detection or correction. Second, it reflects a governance and disclosure gap: the public visibility of the incident rests on investigative reporting rather than a proactive supervisory disclosure, raising a broader question about whether sovereign payment-infrastructure incidents of this kind are subject to the same disclosure expectations increasingly applied to regulated financial institutions. Both gaps are assessed as compounding rather than isolated failures, a technology control gap and a governance and transparency gap operating in the same incident, each reinforcing the conditions that allowed the other to persist undetected for months.

The customer-typology profile of this scheme, corporate and correspondent-banking relationships rather than retail, situates it squarely within the trade-finance and correspondent-banking control environment that active-defence programmes at commercial banks have increasingly prioritised since 2020, yet its occurrence within sovereign Treasury infrastructure suggests that hardening at the level of individual correspondent banks does not automatically extend to state payment channels, which may sit outside the direct supervisory reach of banking-sector cyber-fraud controls entirely.

For active-defence purposes, this incident functions as an architecture-level case study rather than an isolated fraud loss: it demonstrates concretely how sovereign-level payment infrastructure, often assumed to carry higher assurance than commercial banking rails, can in practice lack the basic payment-instruction verification controls that regulated commercial institutions are increasingly expected to deploy as standard active-defence measures against business-email-compromise typologies.

Outlook

Whether the Treasury and Central Bank of Sri Lanka strengthen payment-verification and email-authentication controls in response to this incident, and whether the destination and laundering path of the diverted 2.5 million US dollars is eventually established, are the two clearest forward markers for this domain. A future cycle establishing the laundering destination would allow this incident to be integrated with other financial-crime findings for the jurisdiction, particularly the enabler-jurisdiction and crypto-laundering patterns documented elsewhere in this baseline, rather than being assessed in isolation as it currently must be. Absent confirmed remediation, the underlying control gap should be assumed to persist, and the incident should be read as a standing illustration of active-defence control gaps in sovereign payment infrastructure more broadly, not merely a closed historical event. Whether any post-incident supervisory review of Treasury payment controls has since been initiated is not established in current evidence and constitutes a standing gap for future-cycle tracking. This incident sits within a domain that captures compliance technology and active defence broadly, and the trajectory assessed as worsening for Sri Lanka on this axis reflects that the exploited control gap is both recent and unremediated as of this baseline, distinguishing it from the comparatively stable trajectories assessed for the D1 sanctions-architecture and D3 enabler-jurisdiction postures of Sri Lanka this cycle.

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

This is the first cycle of FIM coverage for Sri Lanka, so the cumulative compliance-technology picture rests on this single baseline, to be built upon in subsequent cycles rather than restated.

The clearest compliance-technology finding at this baseline is a business-email-compromise scheme that diverted approximately 2.5 million US dollars from sovereign Treasury payment channels. Between December 2025 and March 2026, criminals intercepted email communications between the Sri Lankan Treasury and Australian export-finance counterparties, enabling the redirection of five successive loan-repayment instalments into criminal-controlled accounts. The scheme exploited weak email-authentication and payment-verification controls within sovereign financial infrastructure, the kind of control gap that active-defence tooling such as payment-verification callback protocols, domain-authentication standards, and anomaly-detection on payment-instruction changes is specifically designed to close. That the exploited counterparty was a Central Bank and Treasury payment channel, rather than a commercial banking relationship, raises the stakes for this baseline assessment: sovereign payment infrastructure sits at the top of the trust hierarchy that correspondent banking and export-finance arrangements depend upon, and a successful business-email-compromise intrusion at that level signals a control gap with potential systemic reach across every counterparty relying on the authenticity of that same payment channel.

The destination and further laundering path of the diverted funds has not been established by investigators as of this baseline, a material evidentiary gap carried forward as a standing item for future-cycle tracking rather than a closed investigation. Establishing that destination in a future cycle would allow this incident to be integrated with the enabler-jurisdiction and crypto-laundering patterns documented elsewhere in this baseline, rather than being assessed in isolation as it currently must be.

The compliance-technology reading anchored at this baseline is twofold. First, it reflects a technology gap: the payment-verification controls that would ordinarily flag a change in payment instructions between long-standing counterparties evidently did not trigger, or were not in place, across the five successive fraudulent instalments, a repeated-exploitation pattern rather than a single lapse. Second, it reflects a governance and disclosure gap: the public visibility of the incident rests on investigative reporting rather than a proactive supervisory disclosure. Both gaps are assessed as compounding rather than isolated failures, and this compounding judgment is carried forward as the standing interpretive frame for this domain.

The customer-typology profile of this scheme, corporate and correspondent-banking relationships rather than retail, situates it within the trade-finance and correspondent-banking control environment that active-defence programmes at commercial banks have increasingly prioritised since 2020, yet its occurrence within sovereign Treasury infrastructure, established at this baseline, suggests that hardening at the level of individual correspondent banks does not automatically extend to state payment channels, which may sit outside the direct supervisory reach of banking-sector cyber-fraud controls entirely. This incident functions, at this baseline, as an architecture-level case study rather than an isolated fraud loss, illustrating how sovereign-level payment infrastructure, often assumed to carry higher assurance than commercial banking rails, can in practice lack basic payment-instruction verification controls.

Outlook

Whether the Treasury and Central Bank of Sri Lanka strengthen payment-verification and email-authentication controls in response to this incident, and whether the destination and laundering path of the diverted 2.5 million US dollars is eventually established, are the two clearest forward markers for this domain and the triggers for the next material update to this cumulative assessment. Absent confirmed remediation, the underlying control gap recorded at this baseline should be assumed to persist, and the incident should be read as a standing illustration of active-defence control gaps in sovereign payment infrastructure more broadly. The trajectory assessed as worsening for Sri Lanka on this axis at this baseline reflects that the exploited control gap is both recent and unremediated, distinguishing it from the comparatively stable trajectories assessed for the D1 sanctions-architecture and D3 enabler-jurisdiction postures of Sri Lanka recorded in the same cycle.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
In Force Pending2026 · ±year

National strategy to counter organized crime moves to implementation phase

Sri Lanka is expected to define specific implementing activities during 2026 under the four-pillar national strategy established via 2025 UNODC-supported workshops.
In Force Pending1 Jan 2027 · ±quarter

New EU GSP Regulation applies, continuing Sri Lanka GSP+ conditionality

The renewed EU GSP Regulation, signed June 2026, applies from 1 January 2027 for a further ten years, continuing zero-tariff access conditional on implementing 27-32 international conventions covering governance and human rights.
Proposed2027-07 · ±year

FATF/APG next Mutual Evaluation onsite and plenary discussion for Sri Lanka

Sri Lanka undergoes its first current-effectiveness FATF assessment since 2015, potentially revealing material gaps in beneficial ownership, virtual assets and CPF implementation.
3 dated · 3 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROAssessed

Sri Lanka baseline establishes a stalled elite-corruption referral and a sovereign Treasury BEC fraud alongside a durable beneficial-ownership register gap.

The absence of a centralized beneficial-ownership register in Sri Lanka, combined with the stalled Pandora Papers-linked CIABOC referral into Rajapaksa-family offshore trusts, sustains a durable PEP asset-flight typology relevant to enhanced due diligence and SAR-trigger review for any customer or counterparty with Sri Lanka nexus. The sovereign Treasury business-email-compromise fraud, diverting approximately 2.5 million US dollars, further illustrates payment-verification control gaps relevant to correspondent and export-finance exposure.

4 evidence refs
ComplianceHigh

Sri Lanka sits outside the EU AML Package perimeter and outside current EU or UK high-risk third country lists, while lacking any dedicated virtual-asset regulatory framework.

Obliged entities with Sri Lanka exposure should note the jurisdiction remains outside binding EU AML Package instruments and outside both the EU and UK high-risk third country lists as of this baseline, a status that requires re-verification each cycle given the two lists move independently. The absence of any VASP licensing or crypto-AML regime in Sri Lanka represents a policy gap of direct relevance to onboarding and ongoing due diligence controls for crypto-exposed customer relationships.

4 evidence refs
LegalHigh

UK unilateral human-rights sanctions against four Sri Lanka civil-war era figures carry no matching OFAC or EU designation, creating a fragmented liability landscape.

Legal exposure connected to Sri Lanka civil-war accountability figures differs materially depending on which sanctions regime a counterparty or client relationship is screened against, since the UK Global Human Rights designation of four individuals in March 2025 has no confirmed parallel under OFAC or EU asset-freeze authority. This divergence, together with the continued absence of Sri Lanka from EU and UK high-risk third country lists, should inform jurisdiction-specific client-instruction risk assessments.

3 evidence refs
BoardHigh

Sri Lanka baseline surfaces elite-protection dynamics, sanctions divergence, and a sovereign cyber-fraud incident with reputational and governance-oversight relevance.

The stalled prosecutorial outcome on the Pandora Papers-linked offshore trust referral, set against confirmed PEP use of offshore corporate service providers, is assessed as indicating partial capture of the domestic accountability pipeline rather than a pure capacity gap, a material governance signal for institutions with Sri Lanka exposure. The sovereign Treasury business-email-compromise fraud additionally illustrates reputational and control risk extending to state-level payment infrastructure.

3 evidence refs
CTOHigh

Sri Lanka has no dedicated virtual-asset regulatory framework, alongside confirmed national exposure to a regional scam-crypto laundering ecosystem.

The absence of any VASP licensing or crypto-specific AML framework in Sri Lanka, combined with confirmed trafficking of Sri Lankan nationals into forced criminality supporting on-chain scam-proceeds laundering, is relevant to platform-level transaction-monitoring architecture and counterparty-risk scoring for crypto-asset operators handling VASP-counterparty exposure connected to this corridor.

2 evidence refs
RiskHigh

Sri Lanka baseline identifies a worsening crypto-trafficking exposure and an active narcotics-transit terrorism-finance nexus alongside a sovereign cyber-fraud incident.

The combination of confirmed Sri Lankan-national trafficking into the regional scam-crypto ecosystem and the absence of any domestic VASP or crypto-AML framework is assessed as an emerging structural risk concentration rather than an episodic incident. The narcotics-transit terrorism-finance nexus traced through Sri Lankan parcel-mail and air-cargo channels represents a CTF-pillar exposure warranting escalation alongside the more heavily weighted AML-pillar findings in this baseline.

4 evidence refs
OperationsHigh

Sanctions-screening architecture connected to Sri Lanka requires coverage of a UK-specific human-rights list not mirrored by OFAC or EU designations.

Transaction-monitoring and screening operations relying on a single sanctions list risk missing UK Global Human Rights sanctions exposure connected to the four individuals designated in March 2025, given the absence of a matching OFAC or EU designation. Operational screening workflows with Sri Lanka nexus should incorporate this specific list alongside standard sanctions feeds.

3 evidence refs
AuditHigh

The stalled CIABOC prosecutorial referral and the unremediated sovereign Treasury cyber-fraud incident represent standing gaps in documented control-testing evidence for Sri Lanka exposure.

Audit scope connected to Sri Lanka exposure should note the absence of a confirmed material prosecutorial outcome on the Pandora Papers-linked CIABOC referral, and the absence of established remediation evidence following the sovereign Treasury business-email-compromise fraud, both of which represent open control-testing gaps rather than closed items. Continued FATF and APG enhanced follow-up status further indicates that current-methodology effectiveness testing has not yet been applied to Sri Lanka since 2015.

3 evidence refs
Decision lens
MLRO

Sri Lanka baseline establishes a stalled elite-corruption referral and a sovereign Treasury BEC fraud alongside a durable beneficial-ownership register gap.

Compliance

Sri Lanka sits outside the EU AML Package perimeter and outside current EU or UK high-risk third country lists, while lacking any dedicated virtual-asset regulatory framework.

Legal

UK unilateral human-rights sanctions against four Sri Lanka civil-war era figures carry no matching OFAC or EU designation, creating a fragmented liability landscape.

Board

Sri Lanka baseline surfaces elite-protection dynamics, sanctions divergence, and a sovereign cyber-fraud incident with reputational and governance-oversight relevance.

CTO

Sri Lanka has no dedicated virtual-asset regulatory framework, alongside confirmed national exposure to a regional scam-crypto laundering ecosystem.

Risk

Sri Lanka baseline identifies a worsening crypto-trafficking exposure and an active narcotics-transit terrorism-finance nexus alongside a sovereign cyber-fraud incident.

Operations

Sanctions-screening architecture connected to Sri Lanka requires coverage of a UK-specific human-rights list not mirrored by OFAC or EU designations.

Audit

The stalled CIABOC prosecutorial referral and the unremediated sovereign Treasury cyber-fraud incident represent standing gaps in documented control-testing evidence for Sri Lanka exposure.

Shared evidence: 9 refs
Typology observations
Exposure: {'total_matched_typologies': 0, 'by_typology': {}, 'top_indicators': [], 'exposure_note': None}
Scenario sketches

Illustrative AMLA Direct-Supervision Transition and Third-Country Spillover

As illustration only, consider how the move from purely national AML supervision toward AMLA direct and indirect supervision of cross-border obliged entities in the European Union, operating alongside the directly-applicable AMLR and per-state 6AMLD transposition, could reshape the incentives facing corporate service providers that currently administer offshore structures for clients connected to non-EEA jurisdictions such as Sri Lanka. A hybrid EU-level supervisory regime with sharper direct-supervision reach over higher-risk cross-border obliged entities could, in principle, narrow the operating space for facilitator networks that route client structures through EU-adjacent corporate-services hubs, while leaving facilitator infrastructure based outside the EU, such as in Singapore or the United Arab Emirates, largely unaffected by this specific supervisory shift. This is architecture-over-incident illustration, not an observed development or a prediction of enforcement outcomes.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Illustrative Evolution of Offshore Asset-Flight Rails Toward Digital-Asset Channels

As illustration only, consider a hypothetical trajectory in which enabler-jurisdiction corporate-services structures of the kind used to obscure beneficial ownership for politically exposed persons increasingly incorporate digital-asset custody or settlement rails alongside traditional trust and shell-company structures, converging asset-flight typologies with the kind of crypto-enabled laundering infrastructure already documented in the regional scam-crypto ecosystem. Such convergence, if it occurred, would complicate tracing efforts that currently rely on separating corporate-structure opacity from on-chain laundering as distinct typology categories. This is illustration for analytical orientation only, not an observed development or a statement of current fact.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion ArchitecturestableNo confirmed direct involvement of Sri Lankan-flagged vessels, Sri Lanka-domiciled shipping entities or Colombo-based intermediaries in Russian shadow-fleet or oil-price-cap evasion; latent structural exposure exists via Colombo's role as a regional transshipment hub proximate to Indian Sikka/Vadinar Russian-crude receiving ports.
T2 · EU AML Package / AMLAstableSri Lanka sits outside AMLA's direct/indirect supervisory perimeter and outside the AMLR's directly-applicable scope as a non-EU third country; no 6AMLD transposition question applies. Exposure runs via the EU high-risk third country delegated regulation (not listed) and GSP+ trade conditionality (renewed regulation signed June 2026, applies 2027-01-01).
T3 · FATF Grey ListstableSri Lanka is not on the FATF grey or black list, removed from grey-list monitoring in October 2019; remains in APG enhanced follow-up with latest technical-compliance update December 2025 and next full Mutual Evaluation estimated mid-2027.
T4 · Beneficial-Ownership Register StatusstableNo centralized, publicly accessible beneficial-ownership register for legal persons or trusts exists; Pandora Papers-linked CIABOC referral into Rajapaksa-family offshore trusts remains without confirmed material outcome.
T5 · Crypto and Digital-Asset IntegrityworseningNo dedicated VASP registration or crypto-specific AML framework exists; Sri Lankan nationals are confirmed trafficking victims within the Southeast Asian scam-crypto laundering ecosystem per the February 2026 OHCHR report.
T6 · Sanctions Regime DivergencestableUK unilaterally sanctioned four Sri Lanka civil-war era figures under its Global Human Rights regime (March 2025) with no parallel OFAC or EU asset-freeze designation identified; US/EU engagement instead runs through UNHRC Core Group diplomacy and GSP+ conditionality, illustrating sharper UK/US/EU divergence on human-rights-driven designations than on Russia-related listings.
Registers

Enforcement actions

  • The UK imposed asset-freeze and travel-ban sanctions on 4 individuals for serious human rights violations and abuses during the Sri Lankan civil war, including extrajudicial killings, torture and sexual violence. 24 Mar 2025
  • Investigation launched into a business-email-compromise scheme that diverted approximately $2.5m in payments intended for Australian export-finance counterparties between December 2025 and March 2026. 23 Apr 2026
  • Following UNODC anti-smuggling training, Customs officers seized 4.2kg of synthetic drugs (MDMA, crystal methamphetamine, synthetic cannabinoids) at the Colombo Central Postal Mail Exchange, and 17.5kg of hashish and cocaine at Bandaranaike International Airport, including the airport's first slab-form cocaine interdiction. 30 Jul 2025
  • Continued enhanced follow-up monitoring and technical-compliance re-rating process for Sri Lanka under the FATF/APG mutual evaluation follow-up mechanism, with the latest published update dated December 2025. 1 Dec 2025

Sanctions changes

  • UK Global Human Rights sanctions regime listing of 4 individuals, including former senior Sri Lankan military commanders and former LTTE/Karuna Group leader Vinayagamoorthy Muralitharan, for civil-war era extrajudicial killings, torture and sexual violence. 24 Mar 2025
  • No matching US Treasury OFAC or EU Global Human Rights Sanctions Regime asset-freeze designation against the Sri Lankan civil-war era figures sanctioned by the UK in March 2025 was identified; US and EU engagement on Sri Lanka accountability has instead run through UNHRC Core Group diplomacy and GSP+ trade conditionality rather than Treasury-style designations. 24 Mar 2025

Regulatory horizon (register)

  • FATF/APG next Mutual Evaluation onsite and plenary discussion for Sri Lanka
  • New EU GSP Regulation applies, continuing Sri Lanka's GSP+ conditionality
  • National strategy to counter organized crime moves to implementation phase

Active schemes

  • [HIGH] PEP offshore structuring via Singapore/UAE corporate service providers
  • [HIGH] Migrant-worker trafficking into Southeast Asian scam-centre forced criminality
  • Indian Ocean maritime narcotics-transit financing organized crime/terror nexus
  • Central Bank/Treasury cyber-enabled payment diversion (BEC fraud)
Sources
  1. FATF
  2. FATF
  3. FATF / Asia/Pacific Group on Money Laundering
  4. Financial Intelligence Unit, Central Bank of Sri Lanka
  5. UK Foreign, Commonwealth & Development Office
  6. ICIJ
  7. OCCRP
  8. Bloomberg
  9. UNODC
  10. UN News / OHCHR
  11. European Commission
  12. European Commission
Coverage gaps
The Pandora Papers investigation into offshore trusts and sh…
The Pandora Papers investigation into offshore trusts and shell companies linked to a former deputy minister of the ruling Rajapaksa family and her husband, referred to CIABOC in 2021, has shown no confirmed material prosecutorial progress within the 18-month baseline window.
No dedicated virtual-asset/VASP licensing or AML-specific re…
No dedicated virtual-asset/VASP licensing or AML-specific regulatory framework for Sri Lanka was identified in this review, in contrast to regional peers advancing crypto-specific oversight in 2025-26 (e.g. Pakistan's technical committee, India's evolving posture).
The Central Bank/Finance Ministry business-email-compromise …
The Central Bank/Finance Ministry business-email-compromise incident (Dec 2025-March 2026) exposed weak email-authentication and payment-verification controls in sovereign treasury processes, compounded by delayed disclosure to Parliament that opposition figures characterized as concealment.
Sri Lanka's FATF-related standing rests on its 2015 Mutual E…
Sri Lanka's FATF-related standing rests on its 2015 Mutual Evaluation Report plus subsequent technical-compliance follow-up reports (latest update December 2025) rather than a current effectiveness assessment; no full re-evaluation incorporating the FATF's 2025-revised methodology (including virtual-asset effectiveness testing) has yet occurred.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.