Bangladesh Bank Compliance Solutions.
Sorted by urgency. Criminal penalties first.
Bangla QR -- June 30, 2026
82 daysCriminal penalties: BDT 30 lakh fine + up to 3 years imprisonment. All proprietary QR codes must be replaced.
Cyber Security Framework -- December 31, 2026
266 days7-pillar framework. MFA mandatory. SIEM required. 72-hour incident reporting. 89% of banks are NOT AI-ready.
BB Partner Network -- December 31, 2026
266 daysBRPD-2 No-01. Secure extranet for all external partners. 61 banks, 100+ organizations. OAuth 2.1, RBAC, VPN, audit trails.
PDPO Data Protection -- May 2027
~395 daysBangladesh's first data protection law. 1-5% annual turnover penalties. Applies to ALL organizations, not just financial.
Every regulation. Mapped to working products.
Each Bangladesh Bank circular maps directly to KaritKarma products. No custom development needed. Deploy in days, not months.
Bangla QR
Mandatory QR Code Adoption
Remove all proprietary QR codes. Adopt unified Bangla QR standard. Criminal penalties for non-compliance under the Payment Systems Act.
Cyber Security Framework
BB CSF v1.0 (2026)
7-pillar cybersecurity framework mandating MFA, access control, SIEM, incident reporting, and AI-ready security posture for all financial institutions.
BB Partner Network
BRPD-2 No-01 (2026)
Secure centralized extranet for all external partners. OAuth 2.1 authentication, RBAC authorization, encrypted VPN, audit trails, fraud monitoring.
PDPO 2025
Personal Data Protection
Bangladesh's first comprehensive data protection law. Data localization, consent management, breach notification, right to erasure. Applies to ALL organizations.
ICT Security v4.0
Bangladesh Bank Guideline
Updated ICT security guidelines covering access management, network security, application security, and incident management for all banks.
AML/CFT
Anti-Money Laundering
Know Your Customer, transaction monitoring, suspicious transaction reporting, and sanctions screening requirements under BFIU directives.
19 frameworks. Line-by-line to our products.
We map our platform capabilities to specific regulatory clauses, not generic framework readiness. The table below lists every BB regulator-issued framework that touches bank IT and shows which of Wenme, Darwan, Aegis, or another KaritKarma product helps satisfy it.
| Framework | Key clauses / scope | Wenme | Darwan | Aegis | Other products |
|---|---|---|---|---|---|
Bangla QR BPSS / NPSD circular, 2026 | Unified EMV-QR standard. All proprietary QR codes must be replaced with Bangla QR by June 30, 2026. Criminal penalties under the Payment Systems Act. | Out of scope | Out of scope | Out of scope | LoneSock Pay + IntraPay QR switching |
Cyber Security Framework v1.0 BB CSF, 2026 | 7-pillar framework: governance, IAM/MFA, network + endpoint, appsec, SIEM, 72-hr incident response, third-party risk. Mandatory by Dec 31, 2026. | MFA + OAuth 2.1 + WebAuthn (Pillar 2) | RBAC + SoD + audit (Pillar 2, 7) | SIEM + AI threat detection (Pillar 5) | BitsPath 72-hr incident alerts |
BB Partner Network Guideline BRPD-2 No-01, 29 Mar 2026 | Secure centralized extranet for all external partners of scheduled banks. OAuth 2.1 authentication, RBAC, encrypted VPN, audit trails, fraud monitoring. | OAuth 2.1 partner auth | Partner RBAC + audit trail | Partner traffic monitoring | PV encrypted partner data |
Personal Data Protection Ordinance (PDPO) PDPO Act, 2025 (effective May 2027) | Bangladesh's first comprehensive data protection law. Data localization, consent, breach notification, right to erasure. Applies to ALL data controllers. | Consent + identity records | Access audit + purpose binding | Breach anomaly detection | Professional Vault DC localization |
ICT Security Guideline v4.0 BB ICT Guideline v4.0 | Foundational ICT security controls for scheduled banks: network, endpoint, application, access, and incident management. Superseded in part by CSF v1.0 but still referenced. | Centralized identity + MFA | Access management + audit | Log aggregation + detection | Out of scope |
Guidelines on ICT Security for Scheduled Banks and Financial Institutions BRPD, foundational | Umbrella ICT-risk guideline covering governance, policy, physical + logical security, and outsourcing for scheduled banks and NBFIs. | Logical access controls | Policy + SoD + audit | Security monitoring | Out of scope |
Guidelines on Cloud Computing BRPD cloud circular | Risk, data-residency, exit, and control requirements for banks using public / private / hybrid cloud. Data must stay in Bangladesh for regulated workloads. | Sovereign identity | Cloud access policy | Cloud log monitoring | APNIC-member Dhaka DC |
Cyber Incident Reporting Framework BB incident reporting circular | Mandatory reporting of cyber incidents to Bangladesh Bank within defined windows (72 hours for significant events). Standard incident taxonomy. | Identity-event feed | Tamper-evident audit trail | Incident detection + correlation | BitsPath 72-hr notification |
Outsourcing Guidelines (BRPD) BRPD outsourcing circular | Vendor due-diligence, contract, oversight, and exit-plan requirements when banks outsource IT or business functions. | Vendor SSO federation | Vendor ABAC + access review | Vendor activity monitoring | Out of scope |
Business Continuity Management (BCM) Guidelines BB BCM guideline | BCP/DR planning, RTO/RPO targets, annual testing, and crisis-communication requirements for banks and financial institutions. | DR-paired identity | DR-paired authZ | Failover monitoring | Out of scope |
Vulnerability Assessment & Penetration Testing (VAPT) BB VAPT requirement | Mandatory annual VAPT, quarterly vulnerability scans, remediation SLAs, and reporting to Bangladesh Bank for all critical systems. | Pen-test-ready identity | Least-privilege enforcement | Exploit-attempt detection | Out of scope |
Data Classification & Handling Sub-guideline under ICT Security | Classification tiers (Public/Internal/Confidential/Restricted), encryption-in-transit + at-rest, DLP, and handling rules per tier. | Attribute-tagged identity | ABAC on classification tags | Exfiltration detection | PV encrypted storage |
Access Management & Privileged Access Sub-guideline under ICT Security | Least-privilege, JIT elevation, PAM for administrative accounts, quarterly access reviews, and full session recording for privileged use. | WebAuthn for privileged access | JIT RBAC + access review | Privileged-session anomaly | Out of scope |
Audit Trail & Log Retention Sub-guideline under ICT Security | Immutable audit trails on all security-relevant events, minimum retention (typically 90 days online + multi-year archive), centralized log aggregation. | Auth event log | Authorization decision log | Central SIEM + retention | PV long-term archive |
Multi-Factor Authentication Mandate BB MFA directive | MFA required for all customer-facing banking, internet banking, mobile banking, and privileged admin access. Strong customer authentication for high-value transactions. | MFA enforcement + audit log | Step-up authZ policies | Auth-abuse detection | Out of scope |
e-KYC Guidelines BB e-KYC circular | Electronic KYC using NID verification, liveness checks, risk-tiered onboarding, and periodic re-KYC. Digital onboarding for banks, MFS, and financial products. | Verified identity attributes | KYC-tier-aware access | Synthetic-identity + liveness fraud | Out of scope |
Digital Financial Services (DFS) Guidelines BB DFS guideline | Prudential and operational requirements for MFS, PSPs, and digital banks: licensing, consumer protection, interoperability, transaction limits. | DFS consumer identity | DFS role model | Transaction fraud scoring | LoneSock Pay DFS rails |
AML/CFT - BFIU Circulars BFIU circulars (various) | KYC, sanctions screening, transaction monitoring, STR/SAR reporting, sanctions list updates. Applies to all reporting organizations. | KYC-bound identity | Segregation of AML duties | Transaction monitoring + STR triage | Out of scope |
Customer Interest Protection (CIPC) BB Customer Interest Protection Centre circulars | Grievance redressal, service-standard disclosures, complaint SLAs, and consumer-protection audits for banks and DFS providers. | Authenticated complainant | Grievance access controls | Out of scope | BitsPath grievance channel |
Scroll the table horizontally to see all product columns.
Circulars marked with are widely-recognised Bangladesh Bank guidelines where the current circular number, version, or enforcement date should be confirmed with a compliance officer before quoting in an audit response. KaritKarma tracks the canonical source for each row and updates this mapping as BB issues revisions.
Pre-configured stacks. Immediate compliance.
Instead of assembling point solutions, deploy a pre-integrated compliance stack. Each product is already connected to the others.
BB Compliance Suite
Core compliance stack covering authentication, authorization, and fraud detection. Meets Partner Network, Cyber Security Framework, and ICT Security requirements.
OAuth 2.1 + PKCE, WebAuthn/FIDO2, passwordless
42 endpoints, RBAC + ABAC, SoD, audit trails
3-layer AI cascade, 80+ rules, sub-50ms scoring
Digital Bank Stack
Full technology stack for banks undertaking digital transformation while meeting all regulatory requirements simultaneously.
Authentication, authorization, fraud detection
72-hour incident reporting, customer notifications
Bangla QR, domestic switching, payment processing
Encrypted storage, data localization, PDPO compliance
Data sovereignty is not optional.
PDPO 2025 mandates data localization. Bangladesh Bank requires domestic data processing. KaritKarma operates a Tier-3 data center as an APNIC member -- all compliance data stays in Bangladesh on hardware we physically own.
Data stays in Bangladesh
Authentication logs, authorization decisions, audit trails, fraud detection data, and customer PII -- all stored in Bangladesh on KaritKarma-owned infrastructure. Meets both PDPO 2025 data localization and Bangladesh Bank data sovereignty requirements.
Bangladesh Bank compliance questions
What Bangladesh Bank compliance deadlines are coming in 2026-2027?
How can KaritKarma help with Bangladesh Bank regulatory compliance?
What are the penalties for non-compliance with Bangladesh Bank regulations?
Which organizations need to comply with Bangladesh Bank regulations?
3 deadlines in 2026. Are you ready?
Bangla QR criminal penalties start June 30. Cyber Security Framework and Partner Network deadlines follow December 31. KaritKarma's compliance team is ready to assess your gaps and deliver solutions.