|
Banking Act Direction 05 of 2024 on Corporate GovernanceCBSL
|
Licensed commercial banks and licensed specialised banks |
Board and committee governance, risk appetite, internal controls, compliance, internal audit and supervisory accountability. |
|
Source
|
|
Banking Act Direction 16 of 2021 on Technology Risk Management and ResilienceCBSL
|
Licensed banks in Sri Lanka |
Technology governance, risk assessment, critical systems, cybersecurity, incident response, continuity and independent review. |
|
Source
|
|
Circular 02 of 2025 on Reporting IT and Cybersecurity IncidentsCBSL
|
Licensed banks within the circular’s scope |
Incident classification, regulatory notification, progress reporting, root-cause analysis and closure evidence. |
|
Source
|
|
Banking Act Direction 01 of 2026 on OutsourcingCBSL
|
Licensed banks using outsourced services |
Third-party risk, due diligence, contracts, monitoring, concentration, exit plans, incidents and board oversight. |
|
Source
|
|
Personal Data Protection Act No. 9 of 2022DPA
|
Controllers and processors within the Act’s scope |
Data governance, impact assessment, security, processor oversight, breach response and accountability records. |
|
Source
|