Banking Transformation in Sri Lanka: A Practical 2026 Framework

Banking Transformation in Sri Lanka: A Practical 2026 Framework

Banking transformation in Sri Lanka should no longer be measured by the number of mobile applications, automated services or technology projects launched by individual institutions. The more important question is whether technology is making banks simpler, safer, more efficient and more useful to businesses and customers.

Foster is the Banking and Capital Markets Lead for KPMG Asia Pacific and leads KPMG Australia’s banking and capital-markets consulting practice. His central argument is particularly relevant to Sri Lanka: banks should simplify their operations before automating them, place technology governance at board level and make clear strategic choices instead of attempting to pursue every available innovation.

Sri Lanka does not need to copy Singapore, Hong Kong or other advanced Asian financial centres directly. Its banking system has different market conditions, income levels, infrastructure constraints and financial-inclusion requirements.

However, the principles identified by Foster can be converted into a practical framework for Sri Lankan banks.

Why Banking Transformation in Sri Lanka Has Become Urgent

Sri Lanka’s banking system entered 2026 with accelerating credit growth but increasing pressure on profitability and operating efficiency.

Banking-sector credit expanded by 24.4% year on year by the end of the first quarter of 2026, compared with growth of 7.9% one year earlier. The expansion supported economic activity, but it also increased risk-weighted assets and contributed to some moderation in capital and liquidity buffers.

Asset quality has improved. The banking sector’s Stage 3 loan ratio declined from 12.7% to 9.4%, while impairment coverage increased. Nevertheless, the Central Bank has warned that scams and cyber-related incidents remain a concern as digital transactions expand.

This creates the environment described in Foster’s analysis: banks must grow, digitise and control costs simultaneously, without weakening risk management or customer confidence.

Framework One: Simplify Before Introducing More Automation

The first lesson for Sri Lanka is that automation should not be used to preserve inefficient processes.

A bank may introduce artificial intelligence, robotic process automation or digital onboarding while retaining several approval layers, duplicate databases, manual verification and disconnected legacy systems.

The customer sees a digital front end, but the institution continues operating through fragmented processes behind it.

This can increase complexity rather than reduce it.

Sri Lankan banks should begin transformation by mapping complete customer journeys. Opening an account, applying for SME financing, obtaining a housing loan, disputing a transaction and completing Know Your Customer requirements should each be examined from beginning to end.

Unnecessary documents, repeated data requests and approvals that do not add meaningful control should be removed before automation begins.

The objective is not simply to make an existing process faster. It is to determine whether every stage of that process remains necessary.

A poorly designed lending process automated through AI becomes a faster poorly designed process. A simplified process supported by appropriate technology can reduce costs, improve turnaround times and make accountability clearer.

Framework Two: Make AI Governance a Board Responsibility

Foster’s commentary highlights a shift across Asian markets towards board-led governance of artificial intelligence.

This is highly relevant to Sri Lanka because banks may increasingly use AI and advanced analytics in fraud detection, credit assessment, customer service, collections, compliance monitoring and transaction screening.

These systems can produce meaningful efficiency gains. They can also make incorrect decisions, reproduce biased historical patterns or generate explanations that are difficult for customers and employees to challenge.

AI governance should therefore not be treated solely as an information-technology responsibility.

Bank boards should approve a formal AI policy covering permitted uses, prohibited uses, customer-data controls, testing requirements, accountability and the circumstances in which human review is compulsory.

Every high-impact system should have an identified business owner. Banks should also maintain an inventory of AI models, their data sources, decision purposes, performance limitations and external providers.

Human oversight is particularly important where technology affects access to credit, account restrictions, fraud allegations or debt recovery. Customers should have a practical route to request a review when an automated decision materially affects them.

Sri Lanka already has a foundation for this approach. The Central Bank’s technology-risk framework requires board-approved governance, the appointment of senior information-security leadership, ethical use of customer data and board oversight of new technology-driven products. The next step is to apply these principles specifically to AI models and automated decisions.

Framework Three: Prioritise Use Cases That Solve Real Banking Problems

Banks should not adopt AI merely to demonstrate that they are technologically modern.

Sri Lankan institutions should prioritise applications that address measurable operational or customer problems.

Fraud and scam detection should be a major area. Systems can analyse transaction patterns, device behaviour and unusual payment activity to identify risks earlier. However, automated alerts must be designed carefully to avoid blocking legitimate customers without an efficient review process.

Know Your Customer and anti-money-laundering work represent another opportunity. Technology can help extract information from documents, identify missing records, screen transactions and prioritise cases for investigation.

Banks can also use analytics to improve SME credit assessment. Many smaller businesses lack conventional financial statements but generate data through bank accounts, digital payments, invoices and supply relationships.

Responsible use of such information could improve access to finance. It must not become an excuse for opaque lending decisions or excessive collection of customer data.

Other practical applications include assisting contact-centre staff, identifying early signs of repayment stress, forecasting cash demand and automating repetitive internal reporting.

Each investment should be measured against a specific outcome: lower fraud losses, faster processing, fewer errors, improved customer retention or reduced unit cost.

Framework Four: Treat Cyber Resilience as Part of Customer Service

A banking application may be convenient, but it is not successful if customers fear scams, system failures or unauthorised transactions.

Cybersecurity should therefore be considered part of the customer experience rather than an invisible technical function.

Sri Lanka’s regulatory framework already places substantial responsibilities on bank boards. Licensed banks must identify critical systems, maintain information-security governance, monitor third-party providers and establish disaster-recovery arrangements.

The framework requires recovery-time targets of less than four hours for critical systems at domestic systemically important banks and less than six hours for other licensed banks. It also requires annual disaster-recovery testing using critical systems for a continuous period of at least seven days.

In 2025, CBSL strengthened reporting requirements for information-technology and cybersecurity incidents. This reflects the growing importance of rapid regulatory visibility when failures or attacks occur.

Banks should now expand the focus from infrastructure resilience to customer resilience.

Transaction alerts should be understandable. Fraud-reporting channels should be available at all times. Customers whose accounts are compromised should receive a clear explanation of the investigation and recovery process.

Banks should also conduct regular simulations involving ransomware, payment disruption, data breaches and failures at outsourced technology providers.

The question should not be whether a disruption can occur. The question should be whether the institution can contain it without causing a wider loss of trust.

Framework Five: Reduce Cost Through Productivity, Not Only Staff Cuts

Higher operating expenses and declining profitability increase pressure on banks to control costs.

The easiest response may be to reduce branches or staff numbers. That can produce immediate savings but may not resolve structural inefficiency.

Cost transformation should focus on reducing unnecessary work.

Shared processing centres, standardised documentation, automated reconciliation and centralised procurement can reduce duplication across departments.

Relationship managers can spend more time supporting customers when administrative work is simplified. Compliance teams can concentrate on high-risk cases when technology handles routine screening.

Branches should also be redesigned according to customer need rather than eliminated through a uniform policy.

In urban areas, customers may prefer self-service and mobile banking. In rural or ageing communities, branches and assisted digital services may remain essential for financial inclusion.

The aim should be a lower cost per reliable transaction, not merely a smaller workforce.

Banks must also invest in retraining. Employees affected by automation can move into data quality, fraud investigation, cybersecurity, customer advisory and technology-control roles.

Without workforce planning, banks may remove operational knowledge faster than new systems can replace it.

Framework Six: Decide What to Build, Buy or Share

Foster warns that attempting to compete in every area can produce strategic dilution and uncontrolled costs.

This is an important lesson for Sri Lankan institutions operating in a smaller market.

Not every bank needs to develop every system internally.

Core capabilities involving customer relationships, credit decisions, risk appetite and proprietary data may justify internal ownership. Other services can be purchased from specialist providers or developed through partnerships with fintech companies.

Industry-level collaboration may also be appropriate for areas such as digital identity verification, scam intelligence, common compliance utilities and payment infrastructure.

Partnerships still create risk. Banks remain accountable for customer outcomes even when a cloud provider, fintech company or external vendor operates part of the service.

Contracts must therefore cover data ownership, audit rights, business continuity, incident reporting and arrangements for transferring the service if the provider fails.

Digital Assets Require Testing, Not a Race to Launch

Foster also identifies tokenisation and digital assets as an important development in Asian banking.

Sri Lanka should study this area, but it should not treat speculative cryptocurrency activity as the starting point.

A more practical approach would be to explore regulated tokenisation of identifiable assets, securities or financial claims within controlled environments.

Tokenisation could eventually support more efficient settlement, fractional ownership or improved recordkeeping for assets such as bonds, investment funds or property interests.

However, the legal ownership represented by a token must be enforceable outside the technology platform. Cybersecurity, investor protection, custody, valuation and anti-money-laundering requirements must also be resolved.

Sri Lanka’s regulatory sandbox can be used for limited experiments before public deployment. The country should prioritise use cases that improve capital-market efficiency or financial inclusion rather than launching products simply because other Asian centres are doing so.

What Businesses Should Gain From Banking Transformation

This framework is not only about protecting banks.

A successful transformation should produce measurable improvements for the wider business sector.

SMEs should experience faster onboarding and clearer credit decisions. Exporters should receive more efficient trade-finance and foreign-exchange services. Retailers should benefit from reliable, lower-cost digital payments.

Companies should also receive better cash-flow tools, real-time transaction information and early support when repayment difficulties emerge.

Businesses should not be required to submit the same information repeatedly to different departments of the same bank.

Technology should reduce that burden rather than transfer more administrative work to the customer.

The true measure of transformation is therefore not how advanced a bank’s technology appears. It is whether customers can complete legitimate transactions more quickly, securely and predictably.

Confidence Must Be the Final Measure

Sri Lankan banks already have several foundations required for the next stage, digital payment infrastructure, a regulatory sandbox, technology-risk rules and a banking system that remains adequately capitalised.

The challenge is implementation.

Banks should simplify before automating, govern AI at board level, prioritise real operational problems, strengthen cyber resilience and make deliberate decisions about partnerships.

Innovation should not be separated from regulation, customer protection or financial stability.

For Sri Lanka, adapting confidently does not mean moving faster than every other market. It means ensuring that every new system makes the banking sector more trustworthy, more productive and more useful to the economy.


This article is for educational, business analysis and news purposes only.


Share this post :

Facebook
Twitter
LinkedIn
Pinterest