• vashicara@gmail.com
Follow Us
Image Not Found
  • Home
  • Finance
  • Sri Lanka’s USD 2 Million Treasury Throw Away
Image

Sri Lanka’s USD 2 Million Treasury Throw Away

Not even a week since the NDB fraud was divulged, now comes a reported loss of USD 2 million from the government treasury fund. The discovery has triggered public concern over financial controls, cyber-security safeguards, and the management of public finances, adding to growing scrutiny over institutional accountability.

The incident, which reportedly remained undisclosed for nearly four months, came to light after being raised by an Opposition that has an ‘unblemished record of corruption’, in a desperate attempt to discredit Government.

Could there be other frauds that have not come to light over the years? Or is it a random happening?

Contradictions in Statements

It was a quite an interesting display of contradicting public utterances by the government that has been plagued by inefficiencies rather than by corruption.

The Treasury Secretary, a fellow member of the Institute of Chartered Management Accountants, stated that a cyber-attack on the treasury’s email system led to the transfer of funds into an incorrect bank account. It was also stated that internal staff members had been suspended pending investigation.

He stated  the incident was not divulged to the public for about four months because they did not want the culprits to learn that the Treasury had figured out that the fraud was committed. The culprits could have done things to ensure that they were not caught or get out of the country or find any other means of protecting themselves.

However, the Deputy Minister of Digital Economy reportedly described the matter differently, saying the transfer was caused by a fraudulent email impersonating the intended recipient and providing false banking details.

If there was a cyber-hacking, what is the reason for those officials to be suspended? It is a very intriguing and interesting contradiction from a professional representing the government at the highest level of officialdom.

Recovery of Funds Uncertain

Officials have expressed confidence that the transfer trail through the banking system would help trace the funds and assist recovery efforts. However, critics note that the money had not reportedly been recovered even after several months.

Deputy Minister of Digital Economy thinks that since it is a bank transfer, its trails are very clear, and they are hopeful of getting the money back. Whom do we believe? Will the money will come back or not, if it has not come back for four months?

Fraud or Lack of Controls

Compared to the previous political and bureaucratic class of several decades, I believe that the current ones are not financially corrupt, though it remains to be proven otherwise.

To date, it  has been a case of the opposition merely shouting about both the coal purchase and treasury loss. The Opposition has no standing to blame the current government for corruption, but the public has every reason to be concerned.

If public funds are lost, the government and its officials are answerable. As far as economic prosperity is concerned, it does not matter whether the loss is due to corruption or mismanagement.

Objectively, it is better to be governed by people who generate wealth of high value and take portion of it for themselves and leave a net surplus wealth to the people, rather than to be governed by people who do not generate wealth or even worse, who allow existing wealth to be robbed.

Let us look at the fundamental issues of managing the computerized systems that caused the NDB’s fraud and the Treasury loss.

Fundamentals of Computerisation

The responsibility for business systems in a manual environment lies with the business managers. They evaluate the effectiveness and reliability of the processes based on their academic background and professional experience.

When the system is computerised, they completely abdicate this responsibility to the IT personnel who have neither academic background nor experience in the business operations.

A fundamental question in system implementation is the responsibility for the system. Who takes it? Is it the business managers or the IT team?

In most Sri Lankan institutions, all the decisions are taken by the IT team, who are often external consultants in public sector organizations. They do not have the knowledge about business system requirements of the client organisations. Their focus is on technology, not on processes and systems, processes and controls. The end result is the system doesn’t meet all the requirements of the organisation, especially controls.

Examples of Computerisation in International Companies

Let me contrast this with the situation in international commercial entities with whom I have worked, where the system needs to be vetted thoroughly by the business managers. They need to do an acceptance test and agree that the system requirements of the organisation in terms of process and controls are met.

If some system controls are not available, they need to install complementing manual controls to make the total system, man and machine together, reliable and secure.

In 1982, the Colombo branch of an international bank wanted to implement a simple system to computerise their client accounting and general ledger accounting.

They got a software from one of their branches which they felt would meet the requirements. The source code was handed over to me to make rudimentary changes, like changing the branch name currency and so on.

I did those changes and installed the application for the banking personnel to use, including an IT person. I was under the impression that they would commence using the software for their banking operations immediately or a few weeks after my installing the system. 

To my surprise six months later, they called me and said they wanted to start using the system and wanted me to flush all the data they had entered for testing the system.

For six months they went through the application. None of them were used to computerised systems which was understandable in 1982. After six months, business managers and the staff selected to use the system were comfortable with the computerised systems. They performed an acceptance test and made sure it met all their requirements, and controls were in place, both system and complementary manual processes.

International banks, even in a small branch, will not use a software system that is not understood by the business managers thoroughly. IT personnel will be available to provide consulting, but the business managers should take responsibility for the operation of the system, the control aspects, and the accuracy of the data.

They cannot say something went wrong because of the software vendor, software personnel, or whatever. International banks make sure that their staff are fully equipped to manage the system that they are using without any third-party assistance for normal operations.

Until such time as the system can be managed by the business managers, the system will not be in use. The amount of training time that is provided to the staff is adequate to equip them to handle the system.

I recall the incident I experienced with one of the branches of an international bank to show how the business managers how to take the responsibility of the system. We were doing a major upgrade to software we had supplied to this bank branch. By their standard, a parallel run needed to be done.

The hardware vendor provided the alternate computer, which was not of the same model, but a different model using the same operating system. We did the parallel run for the new version in the alternate machine for three weeks. We decided to cut over on a Monday. The operation manager said “You tell me both models use the same operating system, but how do I know that they will work identically? I open the bank on a Monday using a system that was tested on a different model. How can I be sure on Monday morning I will I will not have any problems?” 

We discussed the matter. Back then banks used to work half day on Saturday. We decided that on Saturday a parallel run would be done, not on the alternate machine, but on an old machine after backing up the current system and installing the new system.

Thus, he was guaranteed the new version would work at least for one day on the machine that he was going to use on Monday. To that extent, the operation manager, not an IT person, was thorough with what he had to do. That is the kind of knowledge level that you need to have if the business managers want to use software systems.

Conclusion

Unless business managers and administrators are trained to handle IT systems on their own, we will have to face NDB type frauds and Treasury-like losses. The Government is conducting seminars on AI while very basics of IT and training on how to manage IT system is not imparted to administrators. We go after hypes and leave out the fundamentals. 

Leave a Reply

Your email address will not be published. Required fields are marked *

Sri Lanka’s USD 2 Million Treasury Throw Away - Sri Lanka News