Latest Posts

NDB Fraud Reveals How Audits Missed Billions in Plain Sight

The National Development Bank PLC fraud has raised a question extending far beyond the fate of one institution: how could Rs.13.58 billion disappear through a regulated banking system without triggering an effective institutional response? The answer suggested by the investigative findings is a chain of failures involving transaction controls, accounting classifications, internal governance and external audit scrutiny.

The fraud allegedly began with the manipulation of Common Electronic Fund Transfer Switch suspense accounts. These accounts are intended to serve as temporary transit points for electronic fund movements between domestic commercial banks. Their purpose is administrative and technical, but the investigation indicates that they were exploited to conceal liabilities and facilitate unauthorised transfers.

The alleged central operator worked within NDB’s Department of Payments and Settlements and acquired the credentials of senior authorising officers. This allowed the individual to bypass the practical protection offered by the maker-checker system. Transactions could be created and approved using credentials that appeared to represent separate officials, although the process was allegedly controlled by one person.

The operation was reportedly structured to avoid detection. Transfers were kept below established risk thresholds and processed during weekends and bank holidays, when compliance personnel and senior managers were less likely to intervene. Thousands of transactions could therefore move through the system without immediately attracting the attention that a single large transfer might have generated.

However, the accounting trail appears to have been even more consequential than the transaction trail. The document states that the resulting liabilities were concealed through “other receivables” and “other assets”. Over an 18-month period, these categories reportedly grew from routine balances into a multi-billion-rupee anomaly.

That expansion should have represented a major warning signal. Financial institutions rely on balance-sheet classifications to identify unusual exposures, reconcile outstanding amounts and assess emerging risks. A sudden and unexplained increase in a broad ledger category can indicate misclassification, unreconciled transactions or potential fraud. Yet the document states that internal risk committees and external statutory auditors failed to investigate the unprecedented variance and continued approving the financial statements.

This raises serious questions about the effectiveness of NDB’s internal control environment. Were suspense accounts reconciled regularly? Were unusual movements independently verified? Did risk committees receive complete information? Were auditors given sufficient transaction-level evidence to test the balances? And why did the growth in “other assets” not result in an immediate escalation?

The criminal investigation has reportedly identified more than 26,000 telegraphic transfers, hundreds of dummy accounts across 13 domestic commercial banks and cryptocurrency operations allegedly used to move illicit proceeds onto international exchanges. These findings suggest that the fraud was not a series of isolated accounting errors but a coordinated operation involving multiple financial channels.

The Central Bank of Sri Lanka has adopted a guarded public posture, pointing to capital adequacy and emergency liquidity arrangements while avoiding details that could intensify concern among depositors and investors. Nevertheless, the regulator has reportedly frozen shareholder dividends, halted physical expansion and demanded an autonomous structural overhaul of NDB’s digital infrastructure.

The institutional consequences are significant. If auditors and internal committees cannot identify a multi-billion-rupee anomaly, confidence in published financial statements becomes difficult to sustain. The NDB case therefore demands more than criminal prosecutions. It requires an examination of whether banking supervision, audit independence, ledger reconciliation and accountability mechanisms are capable of detecting fraud before it becomes catastrophic.

The central lesson is clear: a bank’s strongest defence is not its software, but the independence and vigilance of the people responsible for questioning it.

Latest Posts

spot_imgspot_img