The LKR 13 billion ‘electronic robbery’ did not affect NDB banks customer deposits included in LKR 990 billion liability. They were lucky this time. Whose funds were then robbed? It is the shareholders fund that were ‘robbed’.
As per the NDB 2025 annual statement, shareholders’ fund is LKR 86 billion. LKR 13 billion was ‘robbed’ from the shareholders, a loss of 15%. It would have affected the customers’ fund, if thieves have robbed more than LKR 86 billion. Had the young, brilliant whistleblower not leaked to the press, the money of the customers could also have been robbed.
Corporate Responsibility
The NDB board of directors and the CEO’s professional negligence allowed this robbery to take place. Shareholders trusted the board and CEO with their money but they allowed it to be robbed. It is not a criminal negligence to be charged in court of law, but definitely a professional negligence.
It is no different from the professional negligence of Ranil Wickremasinghe allowing alleged LKR 10 billion – only an estimate not yet quantified – ‘robbery’ of government funds in the bond scam. In any other country, people resign for management negligence, political or professional, not in Sri Lanka.
It is professional negligence of Ranil Wickremasinghe because he appointed people who may or may not have followed illegal processes but definitely followed unethical processes. In the case of Ranil Wickremasinghe, he had no control over the processes of the Central Bank, an independent body. However, in the case of NDB, systems and processes are within the control of the CEO and the board of directors. One cannot say controls were in place, but oversight was missing. Oversight is part of controls. Differentiating between control and oversight is jargon to cover up management lapses. If oversight was absent, who was responsible? It is the board and the CEO.
According to some sources, this fraud was brought up by the whistle blower to the notice of the CEO and board but they chose to ignore it. It was leaked to the media and then it came to light. I am not sure of that part of the story.
Trying to justify the lapse by saying, it was in done in relatively small amounts, is ridiculous. It would have been alright in the early days of banking computing. There have been enough incidents of repeated usage of small amounts to ‘rob’ in the banking industry.
A programmer collecting the fractions of interest in his account in the interest computing process. A teller posting bogus transactions of foreign currency sales and purchase depending on the exchange rate to collect cash. With these experiences, several standard controls have been evolved in the banking Industry for IT systems.
System Access by IT Personnel
I have worked with branches of multinational banks for around twenty years, from early 1980 to early 2000. In those bank branches, IT staff do not have any access to the bank’s live system either to view or post transactions. Only banking staff can.
In the 1980s where computers did not have access from elsewhere, if an IT person of the bank has to visit to the bank location where the live IT system is housed, he needs to get a written permission from heads of the system development division and the head of the operation division. IT people are the best equipped to perpetrate frauds. I believe, in most of the banks in Sri Lanka, the IT division has access to the production system.
There are instances where resolving system issues caused by bugs or improper use necessitates data to be amended directly. These are known as data patches. Even these data patches in the international banks are performed by banking people based on a document prepared by the IT division, explaining the reason for it in a way that can be understood by the banking personnel.
They are signed off by three to four people, one of which will be from the IT division. Then it is performed in the system, by banking people. It will produce change details in serially numbered logs so that they can be reviewed even at a later date.
Posting to Internal Accounts
Posting contra entries to internal accounts to hide fraud is not a new thing at all. Entries to internal accounts such as ‘interest accrued not realized’ are generated by the system. However, in rare instances, due mostly to incidents that are not covered by system scope or system issues, manual entries have to be posted.
These manual entries to internal accounts are designated as exceptional transactions. They should be listed at the end of the day by the system and should be reviewed by Internal audit. Internal audit needs to verify that proper authorization procedures have been obtained for these exceptional transactions.
I wonder whether such functionality was available in the core banking system of NDB and whether this daily review was performed.
With the increased power of machines today these controls can be further improved by making sure every asset and liability is a subledger of personnel accounts, except very few which should become zero at the end of the period by system processes.
For example, Interest accrued but not realized, instead of carrying only a total figure should have the detail of each account for which interest is accrued but not realized. This will make fraudulent posting to these internal accounts more difficult and verification becomes very easy. In posting error correction entries, specific accounts should be specified and review will be easier. Previously, it may have been difficult to implement given slower speed of the machines but now with powerful machines, every asset and Liability account can be made a subledger
My belief is that this weakness in controls does exist in the core banking system of many, if not all banks in Sri Lanka. We will wake up only when smart person makes use of the weakness. Nether management nor the bank supervision division of the Central Bank or the external auditors are bothered as any fraud will not affect them personally, directly or by accountability. Only the depositors and shareholders are affected by it.
Central Bank Supervision
The bank supervision division of the Central Bank is responsible for safeguarding the depositors/stake holder’s interests. Today, a major factor in banking operation is the IT systems and processes that are implemented in the bank. If the systems and processes are not in place, banks can fail. The quality of the loans is not the only reason for failure.
The Central Bank cannot wait till financial institutions collapse, after which nothing can be done to safeguard the interest of depositors and shareholders. In a manual environment, it is difficult to check the systems and process, but in a computing environment, it is very easy. Even in the 1980s, regional Internal auditors of multinational bank spent 90% of their audit on IT systems to ensure system controls to safeguard banks’ assets.
What Central Bank supervision does is sit back and when the horse has bolted the stable, declare it and leave the depositors in distress. It was so in Pramuka bank and several finance companies. My understanding is that even now with the type of systems in finance companies’, asset impairments are not completely handled by IT systems. I stand to be corrected. Central Bank, even if they are monitoring, what is reported by the finance companies may not be accurate.
In 2000, I was implementing a system for core banking for one of the banks in Bangladesh. It was a small bank with around thirty branches. The communication facilities were poor and each branch had it is own system. When we did implementation in these four branches, several process issues of the branches came to light. It was brought to the attention of the managing director. One branch manager was demoted and transferred, as it appeared his initiation of posting of wrong figures were intentional. The fifth branch manager was against introducing our system to his branch and they got a system from India which would not operate without an IT person who had full access to the system. He patched data, practically every day, till very late in the night due to system issues.
A few months later, during a bank audit, frauds amounting to BDT 800 million perpetrated by the branch manager was detected. He did not want our system because he thought, mistakenly, our system controls would expose his frauds. I say mistakenly, because systems should have facilities to report unusual transactions but have to be followed up by the processes of the bank to prevent any fraudulent activities. He was arrested and put behind bars. The Central Bank declared that MD who had no part in fraud, should be removed and that he cannot work in any bank for next five years, that is how Central Bank of Bangladesh back in early 2000 acted. Sri Lanka ignores ‘command responsibility’ in every sphere whether it is business, politics or war.
External Audit
Fraud has been perpetrated by posting to internal accounts one media report says, and suspense account says another media report. In any organization in a computerized environment, suspense accounts cannot exist. If media reports about suspense account is true, it is really disastrous.
But, I believe, it is one of the internal accounts such as ‘interest accrued not realized’ which is a convenient place to post contra entry for fraudulent transactions.
The external auditors’ job is to verify the accuracy of all assets and liabilities accounts in the balance sheet and make sure they are correct. Today’s accounting standard requires them to be stated in historical cost and then restated in fair value.
However, I wonder why external auditors who have focused on refining the asset and liability values to come up with fair value, did not bother to verify the correctness of internal account balances on historic cost.
Normally external auditors should verify by requesting a schedule that gives the breakdown of transaction or partner accounts balances to verify the correctness of asset and liability. If these balances are funds of third party, they obtain confirmation from the third parties at least some of them. If it is internal accounts, it can be verified with other and liabilities and individual transaction details.
For example, if it was interest accrued not realized, balances can be verified from the details of the individual third-party accounts. Otherwise, transaction detail of the balances should be given. If the breakdown is not given by the client, external auditors should qualify the accounts. If external auditors have done this exercise for internal accounts, it would have come to light at the time of auditing of 2024 when the fraud was supposed to have started.
However, external auditors could be absolved if the perpetrators of fraud were extremely smart and made sure that on 31st March, or each day, no fraudulent transactions were left in the Internal account without being transferred out.





















Mr Ramathas’s analysis and preseentation is sound and understandable.
Wonderful article!
It is an unfortunate incident that could have been avoided through simple governance.
The saddest part is that there is literally “nothing new under the sun”. Meaning, on one hand, “Financial Governance” has been around for centuries. On the other hand, IT solutions built on those said principles have been in the industry for almost a half a century.
These IT empowered governance have proven to work across intersection, and over the passage of time. Despite these known facts (in my not so humble opinion), the real question one must ask is “why do these frauds keep happening?”. A few possibilities come to mind:
1. Incompetent leadership: (I do not mean the president nor the government – which seem to be the one-size-fit all scapegoat). The head of the institution “the leader” should have the credentials to lead (knowledge of the industry, getting the right person for the right job, bravery to act accordingly, accountability, etc.).
2. Lack of repercussions & rapid forgetfulness: nothing happens. Life goes on!
3. Shameless, immoral mindset.
4. List can go on…..!
All that to say, knowing “what is going on around us” is not sufficient. Firstly, the ability to discern civilized from uncivilized should be proliferated among the society. Secondly, members of the same society should feel safe to side with civilized & moral conduct. Until then, this plague of immoral conduct that is been normalized within our society will prevail – which, in turn will result in incidents of this nature.
Hi Kaushilya Weerapura
Thank you for your comments. Vasee Rajadurai