2018-01-18 | Guideline No. 01/2018

Guidelines on Minimum Compliance Standards for Payment Related Mobile Applications

The Central Bank of Sri Lanka issued these guidelines to establish minimum compliance standards for all payment service providers operating mobile payment applications. The document mandates strict security controls including server-side authentication, multi-factor authentication, data encryption, and device registration to protect sensitive financial information. It further requires PSPs to obtain regulatory approval, implement robust secure coding and anti-tampering measures, and undergo independent third-party audits before deploying any application.

Central Bank of Sri Lanka logo

Sri Lanka

Central Bank of Sri Lanka

Click to view full text