Monday Jul 27, 2026
Monday, 27 July 2026 07:07 - - {{hitsCtrl.values.hits}}
The United National Party (UNP) yesterday accused the Government of failing to accept responsibility for the $ 2.5 million foreign debt payment fraud, alleging that the Parliament’s Committee on Public Finance (CoPF) report into the incident documents operational shortcomings while shielding senior officials responsible for public financial management.
Issuing a statement, the UNP described the CoPF report as “a document that tells only half the truth,” arguing that while it explains how the funds were fraudulently transferred, it fails to identify those politically and administratively accountable for the loss.
The party said the report repeatedly attributes the incident to “system-wide failures” and “procedural gaps” but contended that decisions authorising multi-million-dollar foreign payments ultimately rested with individuals rather than systems.
It argued that the report identifies deficiencies in governance, internal controls, and oversight during the transition of public debt management responsibilities, yet does not assign responsibility to the Finance Minister or Treasury Secretary, despite their respective political and administrative roles.
The UNP also questioned what it described as a disparity in accountability, noting that four mid-level officials had been suspended for alleged dereliction of duty while senior management was criticised only for “coordination issues.”
The party further alleged that the cyber fraud resulted from failures in information technology governance rather than an unavoidable cyber attack.
It claimed that the External Resources Department (ERD) continued to operate an email server dating from 2016 after mainstream support had ended and emergency security updates ceased on 14 October 2025. According to the UNP, the fraudulent transfers commenced in mid-November 2025, shortly after security support had lapsed.
The statement further alleged that independent audits conducted by KPMG and the Sri Lanka Computer Emergency Readiness Team (SLCERT) had warned the Finance Ministry a year earlier that its information technology systems lacked essential safeguards, including multi-factor authentication, but that those recommendations had not been implemented.
The UNP also criticised the transition of sovereign debt management from the Central Bank of Sri Lanka (CBSL) to the Public Debt Management Office (PDMO), established under the Public Debt Management Act, No. 33 of 2024.
It noted that the PDMO commenced operations in December 2024 and assumed legal responsibility for public debt, while Section 8 of the Act established a Coordinating Committee with functions assigned by the Minister. However, the party alleged that the Minister failed to exercise his powers under Section 7 of the Act to issue written guidelines governing the 18-month transition period between November 2024 and March 2026.
The UNP further pointed out that the Memorandum of Understanding (MoU) governing operational coordination between the CBSL and the PDMO was signed only on 9 March 2026, after the fraudulent transactions had allegedly taken place between November 2025 and January 2026.
It also argued that, under Article 52(2) of the Constitution, the Finance Ministry Secretary is responsible for supervising departments and institutions falling under the Minister, including both the CBSL and the PDMO, and therefore should have ensured that the operational framework governing the transfer of responsibilities had been formalised much earlier.
The statement further claimed that the transition removed the multi-layered verification process previously maintained by the CBSL without replacing it with equivalent safeguards, creating what it described as a high-risk environment that was subsequently exploited.
The UNP also criticised the Government’s handling of the matter after the fraud was discovered, alleging that information about the incident was withheld from the public for several months under the pretext of protecting the investigation while political fallout was managed.
The party further alleged that the Treasury Secretary initially declined to appear before the CoPF when first summoned in April 2026, describing this as a failure to uphold parliamentary accountability.
The UNP noted that the CoPF report states its mandate is confined to examining public finance and does not extend to determining criminal or legal liability. However, it argued that, under Article 148 of the Constitution, Parliament exercises control over public finance and that the Committee therefore had a duty to identify those directly responsible for the loss.
The party alleged that the omission of any reference to the Finance Minister and Finance Ministry Secretary allowed the report to serve as an “institutional shield” rather than a mechanism for accountability.
The UNP maintained that the loss of $ 2.5 million was not the result of an isolated technical failure but stemmed from inadequate supervision of the transfer of public debt management responsibilities, ignored cybersecurity warnings, and failures in institutional governance. It said responsibility for the loss should rest with those who oversaw the transition from the CBSL to the PDMO.