NDB Fraud Reveals EY, the Board Audit Committee and CBSL utter Negligence

    0
    6
    Screenshot

    The Banker

    The National Development Bank PLC (NDB) fraud has raised a question that goes far beyond the loss suffered by one institution: How could suspicious transactions ultimately valued at Rs.13.58 billion pass through a regulated banking system without triggering an effective institutional response?

    The question is particularly serious because the warning signs were not necessarily buried in obscure transaction data. Publicly available financial statements showed a dramatic increase in NDB’s “Other Financial Assets” and CEFT-related receivables. The reported balance rose from around Rs.1.4 billion historically to Rs.12.22 billion by end-2025.

    That should prompt uncomfortable questions for management, internal audit, the Board Audit Committee, the Board Integrated Risk Management Committee, the external auditor and the banking supervisor.

    The control system appears to have been defeated

    The fraud involved NDB’s Common Electronic Fund Transfer Switch (CEFTS) settlement process. According to allegations reported in connection with the shareholder derivative action, the control environment was compromised through misuse or misappropriation of credentials and weaknesses in segregation of duties and supervisory oversight. The allegations are now subject to legal and forensic processes and should not be treated as finally established findings.

    But the bigger governance question is this: even if the perpetrator succeeded in bypassing transaction-level controls, why did the balance-sheet consequences not trigger an escalation?

    A sophisticated fraud may defeat an individual control. It should be considerably harder to defeat the combined defences of management, internal audit, risk committees, the Board Audit Committee and an external statutory audit.

    The balance-sheet warning was staring the system in the face

    The most troubling feature is the reported growth in CEFT-related receivables.

    NDB’s 2025 Annual Report disclosed that “Other Financial Assets” included receivables arising from CEFT transactions. The reported balance had increased dramatically over the preceding reporting periods.

    This raises fundamental audit and governance questions.

    Who challenged the increase? Who reconciled the underlying balances? Who independently verified them? What explanations were presented to the Audit Committee? What evidence did the external auditor obtain? And at what point did the Board conclude that the movement required escalation?

    These are not merely questions about hindsight. They go to the purpose of a bank’s control and assurance architecture.

    The EY question

    EY was NDB’s external auditor for the 2025 financial year and issued an independent auditor’s report on the financial statements. Subsequent reporting indicates that EY did not detect the fraud during the 2025 audit cycle.

    That creates a fundamental question for the auditing profession: What did the audit procedures actually test when confronted with a balance that had increased so materially?

    An external audit is not designed to guarantee that every fraud will be detected. Fraud can involve collusion, management override and deliberate concealment. But where an unusual and material balance develops over multiple reporting periods, the adequacy of the audit response deserves rigorous examination.

    This is precisely why the forensic review must go beyond identifying who committed the fraud. It must establish why the assurance mechanisms did not identify the accumulating financial anomaly earlier.

    The Board Audit Committee cannot escape scrutiny

    The Board Audit Committee Chair is a former Partner Sujewa Rajapakse. The committee is a critical component of a bank’s governance framework. It is not merely a recipient of financial statements after management and auditors have completed their work.

    The reported circumstances raise questions about whether the Committee received sufficient information, challenged significant movements adequately and ensured that unusual balances were independently verified.

    A shareholder derivative action has specifically alleged that the Board, acting through its Board Audit Committee and Board Integrated Risk Management Committee, failed to detect, assess or respond to the abnormal escalation in CEFT-related receivables. Those are allegations before the courts, not established findings.

    Nevertheless, they raise issues that cannot simply be dismissed as an operational failure.

    If a Rs.12 billion-plus balance can accumulate in a bank without effective challenge, the issue is not only whether an employee circumvented controls. It is whether the governance system was sufficiently alert to detect the consequences.

    This is also a regulatory question

    The Central Bank of Sri Lanka has said it is closely monitoring NDB and that the forensic review will specifically assess failures relating to regulatory compliance, controls, oversight and governance. CBSL has also directed NDB to strengthen its internal controls and governance processes and undertake an independent third-party review.

    Importantly, CBSL informed Parliament’s Committee on Public Finance that no unusual activity had been flagged during the period in which the fraud occurred, prompting questions from the Committee about internal controls, audit mechanisms and banking supervision.

    The issue therefore extends beyond NDB. It is a test of the effectiveness of Sri Lanka’s entire three-lines-of-defence model—management controls, risk and compliance functions, and independent assurance.

    The Rs.13.58 billion question

    Deloitte’s interim forensic review subsequently identified suspicious transactions of Rs.13.579 billion, higher than NDB’s initial estimated financial impact of Rs.13.2 billion. NDB has stressed that the interim findings are preliminary and confidential.

    That distinction matters. The forensic process is not yet the same as a final determination of responsibility.

    But the scale is undeniable.

    A Rs.13.58 billion anomaly is not a minor accounting irregularity. It is a governance stress test of the highest order.

    Accountability must follow the facts

    The answer cannot simply be to strengthen passwords, introduce new software or replace an operational procedure.

    The more important questions are:

    Who was responsible for reconciliation? Who reviewed the exceptions? Who challenged the balance? Who verified the underlying assets? What did internal audit report? What did the risk committees know? What did the Audit Committee ask? What did EY test? And what did the regulator see?

    The forensic investigation should provide clear answers to each of these questions.

    CBSL has so far emphasised that NDB remains above minimum capital and liquidity requirements and that customer deposits have not been affected. That is important for financial stability, but capital adequacy does not answer the governance question.

    Nor should accountability be determined by public pressure or assumption. It should follow the evidence.

    If the forensic findings establish failures by individuals, committees, management, auditors or other parties, appropriate action should follow in accordance with law, regulation and due process.

    The bigger lesson for all Banks

    The NDB episode should become a watershed moment for banking governance in Sri Lanka.

    The strongest banking control is not the software alone. It is the combination of reconciliation, segregation of duties, independent challenge, competent internal audit, an alert Audit Committee, rigorous external audit and effective regulatory supervision.

    Technology can prevent some fraud. Controls can deter some fraud. But only an organisation with a culture of questioning can reliably detect what controls miss.

    The ultimate test is therefore not whether NDB can recover the money or whether the bank remains adequately capitalised.

    It is whether Sri Lanka can ensure that the next Rs.13.58 billion anomaly is questioned before it becomes a Rs.13.58 billion fraud. CBSL and the Directors hopes it will go away ; but it won’t .