DeFi protocol frontend in Sri Lanka
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is not permitted in Sri Lanka.
Verdict Details
- Permitted
- no
- Local entity required
- No
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- General AML/CFT laws apply (FTRA, PMLA, CSTFA) if the operator is considered a reporting institution in Sri Lanka.
- The Financial Transactions Reporting Act No. 6 of 2006 mandates suspicious transaction reporting to the Financial Intelligence Unit (FIU).
- Customer Due Diligence (CDD) obligations under the FTRA would apply: obtain full name, permanent address, date of birth, nationality, and unique ID number (NIC/passport) for individuals.
- Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusual transactions.
- Ongoing monitoring and record-keeping obligations apply.
- No tipping-off: cannot disclose to customer that a suspicious transaction report has been filed.
Key Restrictions
- The CBSL has repeatedly warned that virtual currencies are unregulated in Sri Lanka and engaging in or facilitating crypto transactions is high-risk and potentially illegal under broader financial laws.
- The CBSL's 2021 and 2022 press releases declared that VASPs are not licensed or regulated, and facilitating crypto transactions may violate foreign exchange and payment laws.
- No VASP licensing framework exists in Sri Lanka — operating any crypto service, including a DeFi frontend, falls outside the regulatory perimeter.
Key Risks
- No legal pathway to operate a compliant DeFi frontend in Sri Lanka — CBSL has declared crypto-related activities unregulated and warned the public against them.
- Enforcement risk: CBSL press releases (2021, 2022) explicitly warned financial institutions and the public against engaging with crypto, and facilitating transactions may violate foreign exchange regulations.
- Operator could be deemed to be engaging in unregulated financial activity, with potential penalties under foreign exchange and payment laws.
- Regulatory ambiguity: no specific VASP licensing framework exists, and general AML laws are not tailored for crypto — creating uncertainty about compliance obligations.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
The Prevention of Money Laundering Act, No. 5 of 2006 (PMLA): This Act criminalizes money laundering and establishes the legal framework for its prevention.
The Financial Transactions Reporting Act, No. 6 of 2006 (FTRA): This Act mandates reporting institutions (which would include regulated VASPs) to report suspicious transactions and sets out customer due diligence (CDD) and record-keeping requirements. It also established the Financial Intelligence Unit (FIU).
The Convention on the Suppression of Terrorist Financing Act, No. 25 of 2005 (CSTFA): This Act criminalizes terrorist financing and implements the international convention.
Financial Intelligence Unit (FIU) of Sri Lanka:
Central Bank of Sri Lanka (CBSL):
Identification and Verification of Customers:
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons, identifying natural persons who ultimately own or control the customer.
Enhanced Due Diligence (EDD): Must be applied in higher-risk situations, such as:
Reporting Threshold: Any transaction (regardless of amount) or attempted transaction where there are reasonable grounds to suspect that it may be linked to money laundering, terrorist financing, or other criminal activities.
"No Tipping-Off": VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR or related information is being or has been submitted to the FIU.
AML/KYC Requirements (Specific to VASPs): No specific AML/KYC regulations are tailored for VASPs under a licensing framework. However, any entity operating in Sri Lanka would still be subject to general anti-money laundering and combating the financing of terrorism (AML/CFT) laws, such as the Financial Transactions Reporting Act No. 6 of 2006 (FTRA), if their activities fall within the scope of "financial institutions" or "designated non-financial businesses and professions (DNFBPs)" and trigger reporting obligations for suspicious transactions. The applicability to purely virtual asset businesses without fiat gateways is a grey area in the absence of explicit VASP definitions in the FTRA.
Reference: Financial Transactions Reporting Act No. 6 of 2006 (Note: This is a general AML/CFT law, not specific to VA licensing).
Regulator Name: Central Bank of Sri Lanka (CBSL), Financial Intelligence Unit (FIU)
Date: 2021-07-28 (Issued a press release)
Outcome: Heightened public awareness of the CBSL's prohibitive stance. Discouragement of engagement with cryptocurrencies and virtual asset service providers (VASPs). Reiterated that VASPs are not licensed or regulated by CBSL.
Significance: This was a strong and clear warning, setting the tone for the country's approach to virtual assets. It emphasized that crypto falls outside the existing regulatory perimeter, making any related activities high-risk and potentially illegal under broader financial laws.
Date: 2022-04-12 (Issued a press release)
Outcome: Reiteration of the prohibitive stance. Further clarification that facilitating or promoting cryptocurrencies is a violation of current foreign exchange regulations (especially related to outward remittances for crypto purchases) and payment laws.
Significance: This further solidified the CBSL's position, clarifying that not only are cryptocurrencies unregulated, but engaging in transactions involving foreign exchange for crypto can violate the country's stringent foreign exchange laws. This acts as a stronger deterrent for financial institutions.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
No — operating a DeFi protocol frontend in/for Sri Lanka is effectively impermissible because the CBSL has declared virtual currencies unregulated, warned the public against engaging with them, and no VASP licensing framework exists, making any crypto facilitation activity high-risk and potentially a violation of foreign exchange laws.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?