← Regulations / Sri Lanka / Operating Models / Remote VASP

Remote VASP serving residents in Sri Lanka

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Sri Lanka without local incorporation, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • General AML/CFT obligations under the Financial Transactions Reporting Act No. 6 of 2006 (FTRA) apply to any entity operating in Sri Lanka, including VASPs, requiring suspicious transaction reporting (STRs) to the FIU regardless of amount.
  • Customer due diligence (CDD) required: obtain and verify full name, permanent address, date of birth, nationality, and unique ID (NIC/passport) for individuals; legal name, form, proof of existence, and senior management info for legal persons.
  • Beneficial ownership identification and verification required.
  • Ongoing monitoring of business relationships and transactions to ensure consistency with risk profile.
  • Travel Rule obligations under FIU Directive No. 01 of 2023: for domestic transfers ≥ LKR 150,000 and for ALL cross-border transfers, collect and transmit originator name, wallet address, physical address/ID, and beneficiary name and wallet address.
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, complex/unusual transactions, and situations where beneficial ownership is difficult to ascertain.
  • Record-keeping of transaction data and originator/beneficiary information for at least 5 years.
  • No tipping-off prohibition on disclosing STR submissions to customers or third parties.
  • No specific capital thresholds for VASP operations.

Key Restrictions

  • CBSL has repeatedly warned that virtual currencies and VASPs are not licensed or regulated, and engaging in crypto transactions may violate foreign exchange regulations (outward remittances for crypto purchases) and payment laws.
  • No formal VASP licensing framework has been enacted; the only applicable regulatory instrument is FIU Directive No. 01 of 2023 on AML/CFT Obligations for VASPs, which imposes AML/travel-rule compliance but does not create a licensing pathway.
  • Any company operating in Sri Lanka must comply with the Companies Act No. 07 of 2007, which typically involves local incorporation or registration as an overseas company — though this is a general corporate law requirement, not VASP-specific.

Key Risks

  • High enforcement risk: CBSL has issued multiple public warnings (2021, 2022) stating that crypto activities are unregulated, high-risk, and potentially illegal under foreign exchange and payment laws.
  • No clear licensing pathway exists — operating as a remote VASP serving Sri Lankan residents without local authorization carries risk of being declared unlawful by CBSL.
  • Financial institutions and payment gateways in Sri Lanka are prohibited from facilitating crypto-related transactions, creating de facto banking/fiat on-ramp barriers.
  • Penalties for non-compliance with FIU Directive No. 01 of 2023 include significant monetary fines, imprisonment for individuals, and suspension/revocation of any registration or license.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

The Prevention of Money Laundering Act, No. 5 of 2006 (PMLA): This Act criminalizes money laundering and establishes the legal framework for its prevention.

licensing 60% confidence

The Financial Transactions Reporting Act, No. 6 of 2006 (FTRA): This Act mandates reporting institutions (which would include regulated VASPs) to report suspicious transactions and sets out customer due diligence (CDD) and record-keeping requirements. It also established the Financial Intelligence Unit (FIU).

licensing 60% confidence

Financial Intelligence Unit (FIU) of Sri Lanka:

licensing 60% confidence

Central Bank of Sri Lanka (CBSL):

licensing 60% confidence

Identification and Verification of Customers:

licensing 60% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal persons, identifying natural persons who ultimately own or control the customer.

licensing 60% confidence

Ongoing Due Diligence:

licensing 60% confidence

Reporting Threshold: Any transaction (regardless of amount) or attempted transaction where there are reasonable grounds to suspect that it may be linked to money laundering, terrorist financing, or other criminal activities.

licensing 60% confidence

"No Tipping-Off": VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR or related information is being or has been submitted to the FIU.

aml 40% confidence

AML/KYC Requirements (Specific to VASPs): No specific AML/KYC regulations are tailored for VASPs under a licensing framework. However, any entity operating in Sri Lanka would still be subject to general anti-money laundering and combating the financing of terrorism (AML/CFT) laws, such as the Financial Transactions Reporting Act No. 6 of 2006 (FTRA), if their activities fall within the scope of "financial institutions" or "designated non-financial businesses and professions (DNFBPs)" and trigger reporting obligations for suspicious transactions. The applicability to purely virtual asset businesses without fiat gateways is a grey area in the absence of explicit VASP definitions in the FTRA.

aml 40% confidence

Local Presence: While no specific VASP license mandates local presence, any company wishing to operate legally in Sri Lanka, regardless of its business type, would need to comply with the Companies Act No. 07 of 2007, which typically involves local incorporation or registration as an overseas company branch.

travel-rule 60% confidence

For domestic transfers between VASPs: Information must be collected and transmitted for transactions equal to or exceeding LKR 150,000 (approximately USD 470-500, depending on the current exchange rate).

travel-rule 60% confidence

For cross-border transfers between VASPs: Information must be collected and transmitted for all transactions, with no de minimis threshold.

travel-rule 60% confidence

For transfers to/from unhosted wallets (private wallets): VASPs must also conduct due diligence and risk assessments, regardless of the amount, and collect relevant information to the extent possible, especially for higher-risk transactions.

travel-rule 60% confidence

FIU Directive No. 01 of 2023 on AML/CFT Obligations for Virtual Asset Service Providers (VASPs):

travel-rule 60% confidence

Fines: Significant monetary penalties for institutions and individuals.

travel-rule 60% confidence

Imprisonment: For individuals found guilty of serious offenses.

enforcement 60% confidence

Violation Type: Continuing to engage with or facilitate virtual asset transactions, despite previous warnings, and engaging in activities outside the regulatory framework. Penalty Amount: No specific monetary penalty. The "penalty" remains the official declaration of their unregulated status and the potential application of broader financial or criminal laws for illicit activities.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a remote VASP serving Sri Lankan residents is not formally prohibited under a VASP-specific statute, but CBSL has declared crypto activities unregulated and high-risk, and FIU Directive No. 01 of 2023 imposes AML/CFT and travel-rule obligations on VASPs; in practice, there is no licensing pathway, significant enforcement risk exists, and foreign exchange restrictions effectively block fiat on-ramps.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?