# [SL] Authority map — who to take loan-app evidence to (2026-09-20)

For Kavinda's "authorities against micro-lending fraud" question. Every claim sourced; verified 2026-09-20.

## The big change this year: MCRA

- **Microfinance and Credit Regulatory Authority Act, No. 9 of 2026** — passed by Parliament 4 Mar 2026, in force **20 Mar 2026** ([parliament.lk](https://www.parliament.lk/en/business-of-parliament/act-details/G6408), [FT column](https://www.ft.lk/columns/MCRA-Act--2026-%E2%80%93-Aspirations--expectations--and-the-road-ahead/4-790612), [paralegal.lk text](https://www.paralegal.lk/legislations/legislation_M_101), gazette PDF via [documents.gov.lk](https://documents.gov.lk/api/content-file-proxy?file=%2Fact-content%2F09-2026_E_1784552873.pdf)).
- Establishes the **Microfinance and Credit Regulatory Authority** to license/supervise moneylending and microfinance — closing the exact gap CBSL itself admitted: "moneylenders do not come under a licensing and regulatory regime, unless they accept deposits" ([CBSL Public Awareness on Moneylending Activities](https://www.cbsl.gov.lk/en/news/public-awareness-on-moneylending-activities) — same page acknowledges loan scams, harassment complaints, misuse of customer data).
- **CBSL Directions No. 01 of 2026** under the Act effective **25 May 2026** (reported via SL Microfinance group, [Facebook](https://www.facebook.com/groups/slmfc/posts/1419362726601749) — verify against official gazette before citing).
- Actionable: apps operating without MCRA registration once implementation matures = the cleanest regulatory hook, same as the India "check the NBFC registry" move in our playbook.

## CBSL (Central Bank of Sri Lanka)

- Licenses banks / specialised banks / finance companies (Finance Business Act No. 42 of 2011) and Licensed Microfinance Companies (Microfinance Act No. 6 of 2016, operative 15 Jul 2016) ([cbsl.gov.lk](https://www.cbsl.gov.lk/en/node/2175), [licensing page](https://www.cbsl.gov.lk/en/laws/licensing-registration-appointment-and-authorisation-procedures/finance-company)).
- Quarterly "authorised to mobilise deposits" public notice = the whitelist to check any app's claimed lender against (latest as at 31.12.2025, republished by [guruwaraya](https://www.guruwaraya.lk/2026/03/licensed-banks-and-finance-companies-in.html)).
- **Financial Consumer Protection** department + **Financial Intelligence Unit** exist within CBSL ([site nav](https://www.cbsl.gov.lk/en/laws/licensing-registration-appointment-and-authorisation-procedures/finance-company)); FIU accepts complaints (used in the Apr 2026 finance-ministry breach report, [Xinhua via Big News Network](https://www.bignewsnetwork.com/news/279006355/sri-lanka-probes-cyber-breach-at-finance-ministry-system)).
- Enforcement teeth demonstrated: Nation Lanka Finance licence cancelled + wound up 3 Jul 2026 under Banking (Special Provisions) Act No. 17 of 2023 ([Newswire](https://www.facebook.com/newswireLK/posts/the-central-bank-of-sri-lanka-cbsl-has-cancelled-the-finance-business-licence-of/1623544316448619)).

## Police / cybercrime

- **Computer Crime Investigation Division (CCID)** + Sri Lanka CERT — standard complaint route ([finance-ministry breach report names both](https://www.bignewsnetwork.com/news/279006355/sri-lanka-probes-cyber-breach-at-finance-ministry-system)).
- **Tell IGP** portal (Sinhala/Tamil/English): https://telligp.police.lk · telligp@police.gov.lk — accepts public harassment/crime complaints, escalates to station level ([Lanka Newspapers, Feb 2026](https://www.lankanewspapers.com/2026/02/27/sri-lanka-police-launches-tell-igp-online-platform-for-public-complaints)).
- New **dedicated cyber-crime police division** announced Feb 2026; 23–25 cyber incidents/day nationally ([Newswire](https://www.newswire.lk/2026/02/07/sri-lanka-to-establish-new-police-division-to-tackle-cyber-crime)).
- Legal basis: **Computer Crime Act No. 24 of 2007** (+ Electronic Transactions Act No. 19 of 2006) ([academic survey](https://www.davidpublisher.com/Public/uploads/Contribute/56c2c3a43eeed.pdf)).

## Other levers

- **CRIB** (Credit Information Bureau) — licensed-lender credit reporting; unregistered lenders can't lawfully report, another authenticity test.
- **eROC / Department of Registrar of Companies** (eroc.lk) — verify each `developerLegalName` (our DB supplies the exact strings, addresses, phones).
- **Consumer Affairs Authority** — consumer protection route for fees/hidden charges.
- **Google Play** — financial-services policy takedowns (worked in India: 100+ removals after our submissions); policy now *requires* the legal-entity disclosures we harvested, so mismatches (fake entities, foreign shells) are themselves reportable violations.
- Play app hosts/registrar abuse contacts for off-Play APKs (Koodous hits).

## Complaint-path for a harassed borrower (plain words)

1. Preserve evidence: screenshots, loan agreement, SMS/WhatsApp threats, contact-list messages.
2. File via **Tell IGP** (or nearest police station, CCID for cyber elements).
3. Complaint to **CBSL Financial Consumer Protection** if the lender claims to be licensed; **FIU** for money-laundering patterns.
4. From MCRA rollout: unregistered moneylending goes to the **MCRA**.
5. Cross-border shells (UAE/other): complain with the foreign corporate registry in parallel (e.g. UAE licence lookup for Quantix).

## Gaps / caveats

- MCRA authority operational details (registry public-facing? complaint intake?) not yet published as of 2026-09-20 — monitor gazette + CBSL.
- Lendivo marketing citing "MCRA registration" predates implementation; treat licence claims by lenders as unverified until a public register exists.
