By Sanja de Silva Jayatilleka
The recent parliamentary debate and the Report of the Committee on Public Finance (COPF) on a cybercrime at the Finance Ministry offered a glimpse into the depths of financial and procedural confusion at the apex of the country’s institutions managing its economy, including foreign debt. The can of worms they opened was hardly to be expected in a Ministry under the President himself.
The COPF report explicitly states that “A fraud linked to cybercrime has clearly taken place. USD 2.5m of public funds has been stolen.” The report was signed by all members of the Committee representing government and opposition. There was no division of views.
Causes for Concern
Presenting the report in Parliament on behalf of the Chairman of COPF, Kabir Hashim, MP said the incident was unprecedented. What changed that caused such a breach? The relevant functions were carried out by CBSL before and were transitioned to the Ministry of Finance (MoF) in late 2025. What changed in the transition?
More losses in foreign debt payments were prevented by alerts from foreign intermediary banks, according to the report. Despite those warnings preventing at least two more sovereign debt payments (UK, India) from being transferred to a cyber-thief’s bank account, the Australian debt payments went through to a cybercriminal.
The report indicts two institutions under MoF, the External Resource Department (ERD) and the Public Debt Management Office (PDMO), of dereliction of duty:
“At the procedural level, the Directors General of the ERD and PDMO have displayed an absolute dereliction of duty on several aspects.”
At the debate, Deputy Minister Chathuranga Abeysinghe who had signed the report with the above statement said that the ERD processes had not changed after transition and came with the old lack of controls. If true, the MoF had not even noticed the very real risks in the processes they were taking on, and therefore failed to mitigate them, resulting in a massive loss to the state.
CBSL managed the process without such incident until now. If the system was the same, was it personnel, competencies, procedures or compliance that failed at the MoF?
In taking over a new process and going ‘live’ on its own, was there no one qualified or experienced enough at the MoF to do the standard thing of mapping the processes they were taking on, to identify points of risk and ensure controls were in place to minimize them?
Other warnings ignored?
Kabir Hashim reminded parliament about COPF’s early warning regarding weak coordination between CBSL and MoF.
On 11th March2025, COPF had written a letter to CBSL, copied to MoF, to raise concerns about the “coordination between fiscal and monetary authorities”, and requesting a discussion to resolve the issue. A reply to COPF on the 4th of April 2026, (signed by their respective heads Dr. Nandalal Weerasinghe and Dr. Harshana Sooriyapperuma) with the following concluding paragraph with these famous last words, was sent:
“… given several well-functioning mechanisms in already place [sic] to ensure effective & timely coordination, we are of the view that there are no such concerns regarding coordination requiring deliberation at this juncture.”
Subsequent COPF sessions with both institutions present after the discovery of the crime revealed evidence to the contrary. The Opposition Leader Sajith Premadasa pointed out at the debate that the two institutions running fiscal policy and monetary policy had no agreement regarding the responsibility for the cybercrime.
‘Confusion worse confounded’
The government has yet to achieve clarity on this matter.
At the debate, a MP Lakmali Hemachandra told parliament that the COPF report does not mention anywhere that the money was stolen. The report that this MP had signed as a member of COPF clearly states that “USD 2.5m of public funds has been stolen”. By whom, or if there was any collusion, it doesn’t say, but stolen it was.
Explaining this notion, the MP said that “this crime has been committed using the internet”. Using the internet, public funds had certainly been stolen.
She also asserted that the report doesn’t say the Governor of the Central Bank or the Secretary to the Treasury must take responsibility. However, the report says:
“At the overall governance level, senior officials at the level of Secretary to Treasury and Governor of the Central Bank bear responsibility for several lapses.”
Most worrying, she said “We cannot say with certainty that if this was done, the other could have been prevented, after the event.”
To the contrary, the Report itself points out, referring to internal controls: “If these simple tasks were done correctly, it is certain that this fraud linked to cybercrime could have been avoided.”
It’s best for the government to look the issue squarely in the face, rather than engage in denials. The COPF report is all we have to go by for now, and that is damning enough:
“This report finds system-wide failures in the debt repayment process resulting in repeated fraudulent transactions taking place over an extended period of time during the transition.”
Red Alerts
COPF had alerted the government before any of this, that the specialized task of foreign debt payment required well-qualified personnel to run its operations.
In a clear vindication of this warning by COPF the PDMO staff did not think it suspicious that Sovereign Debt payable to Australia was requested to be split and paid into accounts in the UAE and the US! The UAE payment was rejected and returned and yet no red lights went off, and the same payment went through successfully –to a criminal– a few weeks later.
The Finance Department of the CBSL had noticed the anomaly in the email addresses of the Australian government and the entity requesting payment to a bank in the UAE, and wrote to the ERD regarding its concerns.
In a series of email exchanges running parallel, an incredibly unprofessional process of receiving and processing of invoices and bank account details for payment of sovereign debt is carried out, often without seeming to refer to previous sets of communications on the same matter, nor indeed verifying them against the original agreements between the governments, nor instituting the segregation of duties essential in the circumstances to prevent fraud or error.
How deep and how wide?
MPs representing the government repeatedly asserted that these procedures were established over a long period of time and had not changed after transition to the new PDMO unit. Attention was drawn to the fact that as a prompt response to the cybercrime, robust controls had been put in place. While COPF asserted that these changes should have been established “as a baseline” before the crime occurred, that they are now in place is a relief.
However, it is important to learn the lessons of this event.
The Secretary to the Treasury explained, according to the COPF report, that:
“PDMO staff did not have a proper understanding of international fund transfer processes and AML (Anti-Money Laundering) concerns.”
He said this about the staff of an important unit within the Ministry of Finance, under his authority. Why did they employ people to take on such important responsibilities without ensuring their ability to do so?
At the COPF hearings, the MoF Heads of Divisions submitted that staff had assured them that they were ready to take over the tasks after training with CBSL officials. The MoF senior officials had accepted this at face value.
When did they discover that they “did not have a proper understanding…”, as the Secretary informed COPF later?
Is it normal practice to rely on assurances of newly trained staff without verification through testing?
It is usual in a transition process to test the staff taking on the new tasks, and more so when the process involves such complex financial transactions with multiple implications of non-compliance.
The report says:
“The Committee concludes that the risks of a fraud linked to cybercrime were heightened due to systematic lapses in internal controls of the debt repayments process.”
It also found that they were “…lapses across governance, procedural and operational aspects.”
The government repeatedly asserted in parliament that cybercrime is a global phenomenon which is increasing, inferring that this was one among many. While true, it is therefore even more important to concentrate on proper security measures including cyber security, internal controls, training and expert assistance in order to minimize these threats.
It was clear during COPF hearings that Heads of various Divisions weren’t fully cognizant of their responsibility for the systems under their authority, including the duty not to continue with flawed systems without examining their vulnerabilities and improving them by introducing the necessary changes.
The can of worms opened by this series of events including the crimes that were prevented by warnings from foreign sources should lead to an honest appraisal of the need for changes at all levels and modes of governance, and most probably not only at the Ministry of Finance.
from The Island https://ift.tt/uewZoUq
No comments:
Post a Comment