The Treasury’s sweeping overhaul of Sri Lanka’s Public Debt Management Office (PDMO) marks more than an administrative response to the US$2.5 million cyber fraud. It represents an attempt to rebuild confidence in the country’s sovereign debt management framework after Parliament concluded that systemic weaknesses not simply a cyberattack had exposed vulnerabilities in the way public debt was administered.
While Parliament’s Committee on Public Finance (COPF) identified governance failures, blurred institutional responsibilities and inadequate technical capacity, the Finance Ministry’s response has been to redesign the entire operating architecture of the PDMO. The question now is whether structural reforms alone can address the deeper institutional weaknesses highlighted by the Committee.
The cyber fraud occurred during the transition of debt management functions from the Central Bank of Sri Lanka (CBSL) to the Treasury, when responsibilities were divided and accountability remained unclear. COPF concluded that those governance gaps created an environment where fraudulent payment instructions could slip through existing controls.
The Treasury has responded by removing many of the operational weaknesses identified during the investigation.
Perhaps the most significant reform is the abolition of the previous approval system, under which a single senior official could authorize major foreign debt payments. The PDMO now operates through separate Front, Middle and Back Office functions, introducing independent reviews and multiple levels of approval before government funds are transferred overseas.
Equally significant is the shift away from manual processes. Email instructions, which investigators identified as a key vulnerability, have effectively been replaced with mandatory verification protocols requiring officers to authenticate lender email domains, validate invoices against original loan agreements and independently confirm payment instructions with foreign creditors through diplomatic or direct communication channels.
The Treasury has also moved aggressively to strengthen its digital infrastructure. The migration to the Commonwealth Meridian Debt Management System and the introduction of an automated Debt Management Information System by the end of August are expected to create a fully integrated platform capable of electronically verifying loan documentation before payments are released.
Taken together, these reforms substantially reduce operational risks associated with manual processing and fragmented information systems.
However, COPF’s concerns extended beyond technology.
Parliament repeatedly questioned whether the PDMO possesses the specialist expertise required to manage a Rs. 31.1 trillion debt portfolio. Members pointed to staffing shortages, the absence of a comprehensive Training Needs Assessment and a training budget they considered inadequate for an institution responsible for billions of dollars in sovereign borrowing.
These concerns highlight an important distinction. Modern software can strengthen internal controls, but it cannot replace professional judgment in managing sovereign borrowing, evaluating market risks or designing financing strategies. Debt management remains a highly specialised discipline requiring experienced professionals capable of navigating volatile international financial markets.
The Committee also challenged the Office’s medium-term debt strategy, arguing that reducing reliance on Treasury Bills and increasing longer-term borrowing cannot depend solely on favourable interest rate movements. Instead, it urged the PDMO to develop stronger market intelligence and analytical capability to operate effectively under changing financial conditions.
The Finance Ministry has acknowledged many of these concerns. Recruitment continues to fill vacant positions, staff training is expanding with IMF technical assistance, and a new Memorandum of Understanding with the Central Bank has clarified institutional responsibilities that were previously disputed. New escalation procedures now ensure that payment anomalies reported by correspondent banks are immediately referred to senior Treasury officials and the Central Bank’s Financial Intelligence Unit.
The Treasury’s reforms therefore address many of the operational deficiencies exposed by the fraud. Yet COPF’s investigation suggests that restoring confidence in Sri Lanka’s debt management framework requires more than stronger cybersecurity or better technology.
The long-term success of the reforms will ultimately depend on whether the Treasury can build an institution with the professional expertise, governance culture and operational discipline expected of a modern sovereign debt management office. That is not simply new systems or procedures will determine whether the lessons from the cyber fraud translate into lasting institutional reform.