by Our Correspondent in Colombo
The Central Bank of Sri Lanka (CBSL) has delivered a comprehensive and uncompromising defence of its role in one of the country’s most serious public financial fraud cases, presenting a detailed report to the Committee on Public Finance (COPF) that rejects allegations of institutional failure and instead attributes responsibility squarely to the Ministry of Finance (MOF) and its newly established Public Debt Management Office (PDMO).
At the centre of the report is a fraudulent foreign debt repayment relating to Export Finance Australia. According to the CBSL, the transaction became possible because officials responsible for verifying payment instructions failed to authenticate altered banking details against the underlying loan documentation and, when concerns were raised, sought confirmation from the fraudster rather than from the legitimate lender.
The report encapsulates this failure in one of its most striking observations: “It is unfortunate that the MOF has inquired the above from the scammer instead of the actual lender.” Throughout its submission, the CBSL presents this as the decisive mistake that allowed public funds intended for an Australian lender to be diverted into accounts controlled by criminal actors.
The report was prepared as the Central Bank’s official response to COPF regarding the fraudulent foreign debt repayment transaction. It also serves as a point-by-point rebuttal to claims made by the Ministry of Finance, systematically rejecting allegations that the Central Bank’s procedures, training or systems contributed to the fraud.
The dispute unfolds against the backdrop of Sri Lanka’s restructuring of public debt management under reforms initiated through the IMF’s Extended Fund Facility programme in March 2023. As part of those reforms, responsibility for public debt management was transferred from the Central Bank’s Public Debt Department (PDD) to the newly created Public Debt Management Office within the Ministry of Finance.
The CBSL report outlines what it describes as an extensive transition programme. It states that the authorities committed to establishing an operationally independent debt management agency in March 2023 to improve public debt management and debt transparency. The PDMO was formally established in December 2024 under the Public Debt Management Act, while the Central Bank was requested by the Ministry of Finance to provide on-the-job training to the new institution’s staff.
According to the report, three batches of PDMO officials underwent training between March and September 2025 covering Front Office, Middle Office and Back Office operations, including use of the NRM system used to generate SWIFT-compatible payment messages. The report notes that participants praised both the quality and openness of the programme, describing it as well designed and accessible to all PDMO staff.
Operational responsibility was then progressively transferred. Domestic debt servicing moved to the PDMO on 15 October 2025, followed by foreign debt servicing and government securities operations in December 2025. The Public Debt Department itself was closed on 31 December 2025 after the transition had been completed.
The report repeatedly argues that the transfer also shifted legal and operational responsibility. It stresses that maintaining lender contact details, verifying payment instructions, communicating with lenders and authenticating changes to bank account information had historically been functions of the Ministry of Finance’s External Resources Department and subsequently became the responsibility of the PDMO.
Within this framework, the Central Bank describes its own role as narrowly defined. It states that, as banker to the Government, it processes payment instructions that have already been authorised by the Ministry of Finance. The Finance Department checks payment messages against authorised invoices, verifies the technical accuracy of the SWIFT message and releases payments through the Payments and Settlements Department.
The report argues that these procedures do not include independently verifying the underlying commercial relationship between borrower and lender. It states that “CBSL’s role as the Banker to the Government does not entail” maintaining lender contact details or communicating directly with lenders, while emphasising that authorised invoices certified by Ministry of Finance officials indicating “please pay” are treated as valid payment instructions.
The events surrounding the Export Finance Australia transaction form the report’s central narrative. According to the CBSL, PDMO officials submitted a payment advice on 14 November 2025 based on a forged invoice instructing that AUD 141,739.95 be transferred to an account belonging to Mish Global LLC in care of Export Finance Australia rather than directly to the lender.
The Central Bank states that its Finance Department immediately identified the mismatch between the beneficiary and lender and instructed the Ministry of Finance “to communicate with lender to obtain the account details of Export Finance Australia for repayment of foreign loan successfully without being returned.” Instead, according to the report, the Ministry sought clarification from the fraudulent source responsible for the forged invoice, ultimately allowing the payment to proceed.
The report argues that this sequence demonstrates that the breakdown occurred before the payment entered the Central Bank’s processing system. It states that “the critical failure did not occur at the stage of processing the payment instruction through the NRM System; it occurred at the very first line of defense,” adding that once unauthenticated instructions had been authorised by the Ministry, subsequent processing systems could not reasonably detect a defect originating outside their operational mandate.
The CBSL also rejects suggestions that its training or supervision contributed to the incident. It states there was “no direct supervisory involvement” by the Central Bank after October 2025, that PDMO officials independently created Standard Settlement Instructions and conducted multiple transactions before the disputed payment, and that system logs demonstrate all relevant functions were performed solely by PDMO officers.
The report further disputes allegations concerning anti-money laundering obligations. While acknowledging provisions under the Prevention of Money Laundering Act, the CBSL argues that it falls outside the reporting obligations established under the Financial Transactions Reporting Act in its capacity as banker to the Government. It maintains that the payment originated from legitimate Government funds and therefore did not generate suspicion regarding the source of funds. According to the report, any compliance concerns related to the beneficiary bank’s obligations rather than any money laundering suspicion held by the Central Bank itself.
Throughout the submission, the CBSL repeatedly characterises Ministry of Finance assertions as “factually incorrect”, “misleading”, “untenable” or “categorically denied”. It argues that evidence, including system logs and operational records, demonstrates that the payment instructions, verification, authorisation and creation of settlement instructions were carried out independently by PDMO officials following the transfer of responsibility.
The report ultimately presents a clear institutional conclusion. It argues that the cyber theft resulted from compromised communications, governance failures and inadequate verification within the Ministry of Finance, rather than any failure of the Central Bank’s systems or statutory functions. It concludes that the “breakdown of the fundamental verification safeguards within the MOF” enabled fraudulent payment instructions to be treated as authentic, while maintaining that the Central Bank’s processing systems, training programmes and operational activities neither caused nor facilitated the fraud.

