2020-06-01 | Guideline No. 1 of 2020

Guidelines on Minimum Compliance Standard for Payment Related Mobile Applications

The Central Bank of Sri Lanka issued these guidelines to establish minimum security and operational standards for licensed Payment Service Providers operating mobile payment applications. The document mandates strict controls across the entire ecosystem, including device registration, multi-factor authentication, data encryption, and secure coding practices to prevent fraud and data leakage. Compliance requires annual policy reviews, pre-launch and periodic third-party security audits, and the submission of certified reports to the regulator.

Central Bank of Sri Lanka logo

Sri Lanka

Central Bank of Sri Lanka

Click to view full text