2024-01-17 | Circular No. 1 of 2024The Central Bank of Sri Lanka issued Circular No. 01 of 2024 to mandate enhanced security measures for mobile payment applications under the Payment and Settlement Systems Act. The regulation requires all mobile payment apps to request a One-Time Password sent to the registered mobile number for JustPay transactions equal to or exceeding Rs. 10,000. These additional safeguards are effective from 01 April 2024 and supplement existing compliance standards.
f.ùï iy mshùï fomd¾;fïka;=j nfhLg;gdTfs;> jPh;g ;gdTfs; jpizf;fsk; Payments and Settlements Department 8 jk uy," wxl 30" ckdêm;s udj;" 8 Mk; khb> ,y. 30 rdhjpgjp khtj ;ij nfhOk;G 1 Level 8, No. 30, Janadhipathi Mawatha, Colombo 1 ;e ' fm ' 590" fld<U 01" Ys% ,xldj j. ng. ,y. 590> nfhOk;G 01> ,yq;if P . O. Box. 590, Colombo 01, Sri Lanka. 94 11 2477042 94 11 2387009 psd@cbsl.lk www.cbsl.gov.lk 17 January 2024 Payment and Settlement Systems Circular No. 01 of 2024 To: Chief Executive Officers of Licensed Banks, Licensed Finance Companies and Licensed Operators of Mobile Phone Based e-Money Systems Facilitating safer and more secure transactions via mobile payment applications This Circular is issued in terms of Section 44 of the Payment and Settlement Systems Act No.28 of 2005 (Act) read with Section 5 of the Act to promote and facilitate safer digital payment transactions via mobile payment applications. 2. To ensure that transactions executed via mobile payment applications are safer and more secure, the Central Bank of Sri Lanka mandates all mobile payment applications to adopt the following in addition to the safeguards outlined in the Guidelines on Minimum Compliance Standard for Payment Related Mobile Applications No. 1 of 2020. i. For all JustPay transactions, mobile payment application initiating the transaction shall request a One-Time Password (OTP) from the Issuer of the account that has been linked to the mobile payment application via JustPay, if the transaction amount equals or exceeds Rs. 10,000/=. Issuer in this instance shall refer to any institution that maintains the account of the customer, from which the debit is made. ii. This OTP should be sent to the mobile number registered with the Issuer. iii. The above shall come into operation with effect from 01 April 2024. K V K Alwis Director Payments and Settlements