Case Study
How Disasters Like Sri Lanka's 2025 Floods Expose Weaknesses in AML Risk Management Systems
Cyclone Ditwah displaced over two million people and triggered a multi-billion-dollar relief effort. Large-scale disasters don't just test emergency response — they test every assumption a KYC/AML program makes about identity, cash, and oversight.
July 22, 2026 · 11 min read
On 28 November 2025, Cyclone Ditwah made landfall in eastern Sri Lanka and triggered flooding and landslides across all 25 districts — by most measures the country’s worst flood disaster in two decades. The World Bank estimated direct physical damage at roughly $4.1 billion, about 4% of GDP, with total economic losses running $6–7 billion. Weeks later, UN agencies reported more than a million people, over half of them children, still in need of humanitarian assistance.
To be clear at the outset: this piece is not alleging that fraud or relief-fund diversion occurred in Sri Lanka’s 2025 response — at the time of writing there’s no public reporting establishing that. The point is structural, not accusatory: disasters of this scale reliably create a specific, well-documented set of AML control gaps, regardless of the jurisdiction or the integrity of the responders involved. FATF’s own guidance acknowledges this directly, noting that natural disasters and resource scarcity tend to see an increase in predicate offenses — corruption, fraud, and related crimes — precisely because normal controls get suspended under pressure to move money and aid quickly. Sri Lanka has been here before: relief funds after the 2004 Indian Ocean tsunami were the subject of extensive corruption and mismanagement reporting from anti-corruption monitors and international media in the years that followed. The pattern is the risk. The question worth asking is what a KYC/AML program can do, structurally, before the next disaster hits.
Why disasters specifically break AML controls
Four things happen simultaneously in almost every major disaster response, and each one independently strains a different part of a standard AML program:
- Identity documentation gets destroyed or becomes inaccessible. Displaced people lose the physical IDs, utility bills, and address proof that standard CDD relies on — through no fault of their own, at exactly the moment they most need financial access.
- Money moves faster than verification can keep up. Emergency cash transfers, mobile money disbursements, and donor funds are built to move in hours or days, not the weeks a normal onboarding or vendor-vetting cycle assumes.
- Oversight capacity itself is disrupted. Compliance staff, branch infrastructure, and monitoring systems in the affected region are dealing with the same disaster as everyone else — reduced headcount and degraded infrastructure arrive exactly when scrutiny needs to increase.
- Legitimate humanitarian flows spike alongside opportunistic ones. A genuine surge in real NPO activity, charitable giving, and government relief spending is the perfect cover for the illegitimate version of the same thing — and FATF is explicit that overcorrecting here has its own cost, disrupting the legitimate aid people depend on.
None of this is unique to Sri Lanka. It’s the same pattern documented after Hurricane Katrina, the 2004 tsunami, and most large-scale disaster responses since — which is exactly why it’s a fixable, plannable weakness rather than a surprise every time.
A prevention framework: what a resilient AML program does differently
-
Build the disaster protocol before the disaster, not during it. The single biggest failure mode is improvising CDD exceptions in real time under pressure. A resilient program has a pre-approved, board-signed-off disaster CDD policy sitting on the shelf — what identity evidence is acceptable when standard documents are unavailable, who can authorize it, and for how long — so frontline staff aren’t making ad hoc judgment calls during the worst week of their year.
-
Calibrate CDD for displaced applicants instead of suspending it. The right response to lost documentation isn’t “skip verification,” it’s substituting alternative, still-independent evidence — biometric matching against pre-disaster records where available, attestation plus a second independent data source (mobile carrier records, employer confirmation, community leader attestation used as one factor among several), or provisional accounts with hard transaction caps until standard documentation can be restored. The goal is a lower bar that’s still a bar.
-
Ring-fence relief and NPO flows for visibility without freezing them. FATF’s guidance is explicit that enhanced monitoring should not mean disrupting humanitarian assistance or NPO activity. The practical version of this is tagging disaster-relief-linked accounts and transaction corridors for closer automated monitoring and faster manual review — not slower processing or blanket holds that a delayed relief payment can genuinely cost lives.
-
Screen reconstruction vendors and contractors like any other high-risk counterparty. Post-disaster reconstruction spending is where beneficial-ownership opacity and shell-company risk concentrate — newly formed contracting entities winning outsized government or NGO contracts with no prior operating history are a pattern worth the same scrutiny given to any new high-value corporate customer, not a pass because the work is urgent.
-
Apply targeted monitoring to emergency cash-transfer and mobile-money channels. Government relief payments and mobile disbursements are the channels most likely to see duplicate claims, ghost beneficiaries, and agent-level skimming. Deduplication against national identity or beneficiary registries, and transaction monitoring rules specifically tuned for these disbursement corridors, catch this without requiring recipients to jump through onboarding hoops they can’t currently clear.
-
Time-box every relaxed control and require it to expire on its own. Provisional accounts, relaxed CDD thresholds, and expedited vendor onboarding should carry a built-in review date — thirty, sixty, ninety days out — after which the file is either brought up to full standard or closed. Relaxed disaster-era controls that quietly become permanent are how legitimate emergency measures turn into a standing vulnerability.
-
Coordinate with the FIU and regulator on a shared disaster posture, in advance. Ask your financial intelligence unit or regulator — the NCA and FCA in the UK, FinCEN elsewhere — before the next event, whether there’s a disaster-specific reporting approach, an expedited SAR channel, or sector-wide guidance for exactly this scenario. A shared, pre-agreed posture beats every institution independently guessing at the right balance mid-crisis.
-
Run the look-back review once the dust settles — and actually feed it back into the program. Every account opened, every vendor onboarded, and every relaxed-control decision made during the disaster window deserves a retrospective review once normal operations resume. The output isn’t just remediation of individual files — it’s the next version of the disaster protocol in step one, updated with what this specific event actually taught the program.
The broader point for anyone building AML judgment
Disaster response is where a program’s risk-based approach gets tested against a scenario the standard playbook wasn’t written for. An analyst who understands why controls bend under disaster pressure — and what a deliberately designed exception looks like versus an uncontrolled one — is bringing exactly the kind of judgment this space is short on. The technical controls matter, but the underlying skill is the same one that shows up everywhere else in KYC/AML: knowing which corners can be cut safely, which can’t, and being able to explain the difference in writing.
Further reading:
- Sri Lanka: Floods and Landslides, November 2025 — ReliefWeb
- More than a million still need aid weeks after Ditwah floods — UN News
- World Bank / ILO reporting on Cyclone Ditwah’s economic impact — WSWS
- FATF Recommendations and guidance on NPOs, humanitarian assistance, and financial inclusion — fatf-gafi.org