ESG SEC Sri Lanka reviews mandatory ESG disclosure timeline  |  CSR Dialog Axiata expands digital literacy programme to 50,000 students  |  POLICY CBSL Sustainable Finance Roadmap: Q2 2026 update  |  DATA 47 CSE-listed companies now publish standalone sustainability reports  |  ESG SEC Sri Lanka reviews mandatory ESG disclosure timeline  |  CSR Dialog Axiata expands digital literacy programme to 50,000 students  |  POLICY CBSL Sustainable Finance Roadmap: Q2 2026 update  |  DATA 47 CSE-listed companies now publish standalone sustainability reports  | 

Preventing the Next Banking Fraud: A Governance Blueprint for Sri Lankan Boards

GOVERNANCE · ANALYSIS · 10 min read

Sri Lanka already has the rules. A new corporate-governance framework for banks took effect in January 2025. Yet the country’s largest disclosed banking fraud surfaced months later. The uncomfortable lesson is that governance failures are rarely failures of the rulebook — they are failures of implementation. Here is what boards must actually do.

By the ESGNexus Editorial Team · July 2026 · Estimated reading time: 10 minutes

KEY TAKEAWAYS

  • The framework already exists. CBSL’s Banking Act Directions No. 05 of 2024 on Corporate Governance took effect on 1 January 2025, replacing rules that had stood since 2007 — requiring, among other things, that at least half of a bank’s board be independent and that the chairperson be an independent non-executive director.
  • Rules are necessary but not sufficient. The UK’s Parliamentary Commission on Banking Standards warned in 2013 that the widely used “three lines of defence” control model can promote “a wholly misplaced sense of security” when adopted on paper but not in practice.
  • Most large frauds exploit mundane controls. Segregation of duties, the “four-eyes” principle, and disciplined account reconciliation are the unglamorous mechanisms that stop internal fraud — and their absence is where it thrives.
  • The board’s job is assurance, not administration. A board audit committee’s role is to independently verify that controls work — not to accept management’s assurance that they do.
  • The NDB case is a catalyst, not the subject. A parliamentary committee has publicly flagged apparent governance lapses; the forensic audit is ongoing. This article uses it to illustrate a sector-wide question, not to pre-judge findings.

When a fraud is uncovered at a bank, the instinct is to ask who did it. The more important question for everyone else in the sector is different: how did the controls that were supposed to catch it fail — and would ours have caught it? For Sri Lanka’s banking boards in 2026, that question is not hypothetical. It is the single most useful thing they can be asking right now.

The Catalyst: A Fraud That Grew

In early April 2026, National Development Bank PLC disclosed an internal fraud. According to the bank’s own market filings and contemporaneous reporting, an initial loss estimate of around Rs. 380 million was revised within days to Rs. 13.2 billion — described in reporting as the largest disclosed banking fraud in the country and roughly 35 times the first figure. Trading in the bank’s shares was briefly suspended by the Colombo Stock Exchange. The bank has stated that the incident was confined to a specific operational area and involved certain employees allegedly acting in collusion with external parties; that the implicated staff were suspended; and that law enforcement was engaged.

Source: NDB PLC corporate disclosures, April 2026 — ndbbank.com; Daily FT, ‘Rs. 13 b fraud-hit NDB numbs banking sector,’ 6 April 2026 — ft.lk; Lanka News Web, 6 April 2026

An independent forensic review by Deloitte Touche Tohmatsu India LLP was commissioned in consultation with the Central Bank of Sri Lanka. Per CBSL’s public statement, that review is examining not only the fraud itself but any failures in control, oversight, and governance during the relevant period. Reporting indicates the review’s scope was widened to examine transactions over a roughly ten-year window. Separately, Parliament’s Committee on Public Finance is on record as observing what it described as considerable lapses in corporate governance at the bank and delays in reporting material information.

Source: CBSL, ‘Update on National Development Bank PLC,’ April 2026 — cbsl.gov.lk; The Island, ‘Rs 13 bn NDB fraud: Int’l forensic audit ordered,’ 21 April 2026 — island.lk; EconomyNext, 18 April 2026

Two points of discipline before going further. First, the forensic audit is ongoing; causes and individual accountability are matters for that review and the courts, not for speculation here. Second, the purpose of this article is not to adjudicate NDB. It is to ask the question every other Sri Lankan bank board should now be asking of itself — because the conditions that allow a fraud to grow undetected are rarely unique to one institution.

Sri Lanka Already Rewrote the Rulebook — in 2025

Here is the detail that reframes the entire discussion. Sri Lanka did not lack a modern bank-governance framework when this fraud surfaced. It had just installed one. CBSL issued Banking Act Directions No. 05 of 2024 on Corporate Governance for Licensed Banks on 30 September 2024, effective 1 January 2025 — revoking the directions that had governed the sector since 2007. The revision was explicitly driven by international governance failures and Basel Committee principles.

Among the strengthened requirements CBSL introduced:

  • Board independence: at least half of the board of directors must comprise independent directors, with tightened criteria for what “independent” means.
  • An independent chair: the chairperson must be an independent non-executive director, and may not chair any of the board’s sub-committees.
  • Stronger sub-committees: improved composition and independence of board committees, including audit and risk.
  • Clearer control-function mandates: explicit requirements on the board’s oversight of senior management and on the responsibilities of the risk management, compliance, and internal audit functions.

Source: CBSL, Banking Act Directions No. 05 of 2024 on Corporate Governance for Licensed Banks — cbsl.gov.lk; Daily FT and Daily Mirror, October 2024

CBSL also amended its directions on the assessment of the fitness and propriety of bank directors and chief executives in 2024. So the tools to vet who sits on a bank board, and to define how that board must oversee controls, were freshly sharpened. This is what makes the sector’s current moment instructive rather than merely alarming: the question is no longer “do we need rules?” It is “why do strong rules, on paper, still coexist with control failures in practice?”

Why Good Rules Still Fail: The Implementation Gap

The honest answer, drawn from decades of international banking-scandal post-mortems, is that governance frameworks fail at implementation far more often than at design. The most widely adopted control architecture in banking — the “three lines of defence” — illustrates the problem precisely.

Under the Basel Committee’s model, the first line of defence is the business unit that owns and manages its risks day-to-day. The second line comprises the independent risk management and compliance functions that monitor and challenge the first. The third line is the internal audit, which reports directly to the board’s audit committee and independently assures that the whole system works. On paper, it is elegant.

The “three lines of defence” system for controlling risk … appears to have promoted a wholly misplaced sense of security.

— UK Parliamentary Commission on Banking Standards, 2013

In practice, as the UK’s Parliamentary Commission on Banking Standards found after the last financial crisis, the model can blur responsibilities and dilute accountability — leaving risk, compliance, and internal audit officers without the standing to challenge front-line staff effectively. A control that exists on an organisation chart but cannot, within the institution’s culture, actually say “no” to a revenue-generating business line is not a control. It is a decoration. The lesson is not that the model is wrong, but that adopting it is the beginning of governance, not the end.

The Governance Blueprint: What Boards Must Actually Do

Turning framework into protection comes down to a set of concrete, mostly unglamorous disciplines. None of these is novel. Their absence, not their obscurity, is what allows fraud to grow.

1. Insist on segregation of duties and the “four-eyes” principle

The oldest control in banking remains one of the most effective: no single individual should be able to initiate, approve, execute, and reconcile the same transaction. The “four-eyes” principle — dual control, double signatures, cross-checking — exists specifically to ensure that fraud requires collusion rather than a single point of failure. Boards should ask management to demonstrate, not merely assert, that no critical process concentrates these functions in a single person or unit.

Source: Basel-aligned internal-control standards, e.g. CBUAE Rulebook, ‘Internal Controls, Compliance and Internal Audit Standards’ — rulebook.centralbank.ae

2. Treat reconciliation and suspense accounts as high-risk, not housekeeping

Account reconciliation — the routine matching of internal records against external ones — is where discrepancies surface if anyone is looking. Suspense and settlement accounts, which temporarily hold unmatched transactions, are a classic hiding place for concealment because unreconciled balances can be rolled forward. These are not glamorous areas, and that is precisely why they are dangerous when under-supervised. A board’s risk and audit committees should expect specific, regular reporting on ageing unreconciled items and suspense-account balances.

3. Give the third line real independence and teeth

Internal audit must report to the board’s audit committee, not to the management it audits, and must have the seniority, resources, and cultural backing to escalate uncomfortable findings. The board’s task is to protect that independence actively — to make it safe and expected for the internal audit to bring bad news. An audit function that only confirms what management wants to hear provides no assurance at all.

4. Run the audit committee as a verifier, not an audience

Under the strengthened CBSL directions, the independence of board sub-committees was deliberately reinforced. The spirit of that reform is that an audit committee’s job is to independently test whether controls work — by probing reconciliations, questioning why exceptions occurred, and following up on prior findings — rather than simply receiving management assurances and moving on. Committee members need the financial literacy, the time, and the temperament to ask the second and third questions, not just the first.

5. Build a whistleblower channel people actually trust

Frauds involving collusion are often known, or suspected, by someone before they are formally detected. A confidential, credibly independent whistleblowing mechanism — one that staff believe will protect them — is among the most cost-effective fraud controls a bank can operate. Its value depends entirely on trust: a channel that employees fear to use is worthless.

6. Own the culture — the control that sits above all others

CBSL’s 2024 directions open, tellingly, with a requirement that boards inculcate a sound corporate culture reinforcing professional, ethical, and prudent behaviour throughout the bank. This is not soft framing. Every technical control depends on a culture in which raising concerns is rewarded rather than punished, and in which no individual or business line is too important to be challenged. Culture is set at the top, and it is the one control that cannot be outsourced to a committee.

The Stakes: Why This Is Not Just NDB’s Problem

It is worth being clear-eyed about what is actually at risk, because it is larger than any single bank’s balance sheet. Sri Lanka’s banking sector is funded overwhelmingly by deposits — around 81.5% of its funding structure as at end-2023, according to CBSL’s own figures. That is public money. The banking system runs on a form of trust that is slow to build and quick to lose, and confidence in one institution is not perfectly insulated from confidence in the system as a whole.

Source: CBSL, Banking Act Directions No. 05 of 2024, background note — cbsl.gov.lk

This is why bank governance is not a private matter for shareholders. When a control framework fails, the people most exposed are depositors who had no way of knowing and no seat at the board table. The regulatory response — CBSL’s strengthened directions, its direct engagement with boards, the fitness-and-propriety regime for directors — reflects exactly that public interest. The obligation those rules create does not end at compliance. It ends at a board that treats the protection of depositor money as its first duty, and behaves accordingly between crises, not only after them.

What This Means If You Sit on a Bank Board

If you are a director, the practical question is not whether your bank has an audit committee, a risk function, and a three-lines-of-defence policy — it almost certainly does. The question is whether those structures have teeth: whether your internal audit function can and does escalate uncomfortable findings; whether anyone reports to you on ageing unreconciled and suspense-account balances; whether a junior employee who suspected wrongdoing would have a channel they trusted enough to use. If you cannot answer those confidently, the framework on your organisation chart is not yet protecting your depositors.

If you are a depositor or an investor, the signal to look for in a bank’s disclosures is not the presence of governance language — every bank has that — but evidence of governance that is tested: independent board composition, an audit committee that demonstrably follows through, and candour when things go wrong.

What ESGNexus Will Track

Governance is the “G” in ESG, and it is often the one that decides whether the E and the S are real or performative. We will continue to follow the strengthening of bank governance in Sri Lanka — the implementation of CBSL’s 2024 directions, the outcomes of the fitness-and-propriety regime, and how boards across the sector respond to a moment that has put governance under the spotlight. To follow this coverage, subscribe to The ESGNexus Weekly.

Sources & Further Reading

Central Bank of Sri Lanka — Banking Act Directions No. 05 of 2024 on Corporate Governance for Licensed Banks — cbsl.gov.lk

Central Bank of Sri Lanka — ‘Update on National Development Bank PLC,’ April 2026 — cbsl.gov.lk

Basel Committee on Banking Supervision — Corporate Governance Principles for Banks, 2015 — bis.org

UK Parliamentary Commission on Banking Standards — ‘Changing Banking for Good,’ 2013

NDB PLC — Corporate disclosures and official statements, April 2026 — ndbbank.com

Daily FT — ‘Rs. 13 b fraud-hit NDB numbs banking sector; CBSL reassures,’ 6 April 2026 — ft.lk

The Sunday Times — ‘NDB fiasco: Risk and audit committees on the radar,’ 11 April 2026 — sundaytimes.lk

ESGNexus — ‘Where Sri Lanka’s Banks Stand on ESG: A Sector Snapshot,’ July 2026 — esgnexus.lk

About ESGNexus

ESGNexus is Sri Lanka’s independent platform for ESG, CSR, and sustainability intelligence. We track company-level ESG performance, regulatory developments, and sustainability data across Sri Lanka’s listed companies, large unlisted corporates, and state-owned enterprises. All editorial content is independently produced. Sponsored content is clearly labelled.

Data disclaimer: Information in this article is sourced from publicly available documents and is provided for general information only. It does not constitute legal, financial, or investment advice, and is not a statement of fact about any individual’s conduct. Matters referred to as under investigation remain unproven. ESGNexus corrects errors promptly; to flag one, contact the editorial team. Errors and omissions excepted.

Discover more from ESGNexus

Subscribe now to keep reading and get access to the full archive.

Continue reading

Stay ahead of Sri Lanka's ESG agenda

Join sustainability officers, investors, and policy professionals who read The ESGNexus Weekly every Friday.