When Controls Fail: Vigilance Lessons from the Punjab National Bank Fraud
Vigilance in banking is often associated with investigations, disciplinary proceedings and action taken after misconduct has been detected. Its more important role, however, is preventive. An effective vigilance framework should identify vulnerable processes, unusual employee behaviour, control overrides and suspicious transactions before they develop into a major financial loss.
The fraud reported by Punjab National Bank in 2018 provides an important case study of what can happen when operational controls, supervisory vigilance and technology systems fail simultaneously. The case was not merely an instance of external fraud. It exposed serious weaknesses in transaction recording, employee access, reconciliation, job rotation, audit and management oversight.
The Reserve Bank of India described the matter as a case of operational risk arising from delinquent behaviour by one or more bank employees and failure of internal controls. The fraud initially reported in February 2018 involved approximately USD 1.77 billion and was connected with unauthorised Letters of Undertaking issued from Punjab National Bank’s Brady House branch in Mumbai.
Background of the Case
A Letter of Undertaking was a form of bank guarantee used to enable an importer to obtain short-term credit from the overseas branch of another Indian bank. The issuing bank effectively assured the lending bank that the borrower’s obligation would be honoured.
In the Punjab National Bank case, certain firms associated with jewellers Nirav Modi and Mehul Choksi allegedly obtained overseas buyers’ credit on the strength of Letters of Undertaking transmitted through the Society for Worldwide Interbank Financial Telecommunication, commonly known as SWIFT.
The central weakness was that the messages were allegedly issued without corresponding entries being properly recorded in the bank’s core banking system. Consequently, the contingent liabilities created through these transactions did not become visible through the normal accounting and monitoring process.
When the borrowing firms later sought renewal or issuance of further facilities, officials at the branch discovered that the transactions were not supported by sanctioned limits, adequate security or proper records. The matter was subsequently reported to investigative and regulatory authorities.
Punjab National Bank’s annual reporting for 2017–18 recorded the impact of the fraud and the substantial provisioning burden arising from it. The bank’s annual reports continue to be available through its official investor disclosures.
Failure of System Integration
One of the most significant lessons from the case concerns the failure to integrate SWIFT operations with the core banking system.
A financial message generated through SWIFT could create a binding commitment for the bank. If the same transaction was not automatically reflected in the core banking platform, the control framework depended excessively on employees making accurate manual entries.
This created a serious gap. Transactions could potentially be transmitted through one system while remaining invisible in another. Consequently, regular reports on sanctioned limits, outstanding liabilities and customer exposure might not present the bank’s true position.
In a well-controlled environment, every external financial message should be linked with an authorised transaction in the core banking system. Any mismatch should immediately generate an exception alert. High-value messages without corresponding accounting entries should be blocked or escalated for independent review.
The case demonstrated that digitalisation by itself does not ensure control. When banking applications operate in isolation, technology can create opportunities for concealment rather than transparency.
Employee Access and Collusion Risk
The case also highlighted the risks arising from excessive dependence on a small number of employees.
Sensitive financial activities require strict segregation of duties. The employee initiating a transaction should not be able to authorise it independently. Access rights must be aligned with designation, responsibility and sanctioned authority. Every transaction should leave an auditable trail showing who initiated, verified and approved it.
Where employees remain in the same sensitive position for a prolonged period, they may acquire detailed knowledge of control gaps. They may also develop close relationships with particular customers and gain the ability to influence or bypass routine checks.
Periodic job rotation, mandatory leave and surprise verification are therefore essential components of preventive vigilance. During the absence or transfer of an employee, another officer may discover irregular practices that had previously remained concealed.
The lesson is not that long-serving employees should automatically be viewed with suspicion. Rather, banking systems should never become so dependent on particular individuals that routine business cannot be independently verified.
Weaknesses in the Maker-Checker Mechanism
The maker-checker principle is fundamental to banking operations. One employee initiates a transaction, while another independently verifies its accuracy, authority and supporting documents.
However, the control becomes ineffective when verification is treated as a procedural formality. A checker who merely approves a transaction on the system without examining the underlying sanction, security, customer exposure and purpose does not provide meaningful oversight.
For transactions involving substantial contingent liabilities, the checker must establish that the customer has an approved limit, adequate documentation and proper authority. The reviewer must also confirm that the transaction has been recorded in all relevant systems and reflected in the customer’s total exposure.
Vigilance therefore requires more than the existence of maker-checker controls. It requires verification to be genuinely independent, documented and capable of challenging an irregular transaction.
Failure of Reconciliation and Exception Monitoring
Regular reconciliation is one of the most powerful tools for detecting banking fraud.
SWIFT messages should be reconciled with the core banking system, general ledger, customer accounts, contingent liability registers and correspondent banking records. Any transaction appearing in one system but not another should be investigated without delay.
High-value transactions, repeated renewals, unusual transaction timing, facilities granted without sanctioned limits and significant business concentrated in one branch or customer group should generate exception reports.
Such reports must not simply be produced and archived. They should be reviewed by officers with sufficient authority and independence to demand explanations and initiate corrective action.
The Reserve Bank of India has repeatedly emphasised timely fraud detection, reporting, staff accountability and the need to examine systemic weaknesses. Its fraud-reporting framework requires banks to identify control failures, analyse delays in detection, strengthen preventive measures and report significant matters to the Board and its committees.
Limitations of Audit and Inspection
The continuation of irregular transactions over an extended period raised questions about the effectiveness of branch inspection, concurrent audit, internal audit and supervisory review.
Audits can fail when they rely excessively on system-generated reports without independently confirming whether all transactions have entered the system. If an obligation is deliberately kept outside the core banking platform, an auditor examining only core banking records may not detect it.
Auditors must therefore understand how transactions originate, move across systems and create liabilities for the bank. They should reconcile source systems, test access logs, examine unusual messages and independently verify contingent liabilities.
Audit programmes must also evolve as banking technology changes. A checklist designed for a largely manual branch environment may not identify risks arising from disconnected digital platforms, privileged system access or unauthorised messaging.
Role of Preventive Vigilance
Preventive vigilance seeks to reduce opportunities for misconduct before a loss occurs. In banking, this requires continuous examination of systems, employee behaviour, transaction patterns and control exceptions.
A strong vigilance framework should identify branches handling unusually high volumes of specialised transactions, employees occupying sensitive positions for extended periods, customers repeatedly receiving exceptions and transactions bypassing normal credit approval.
The vigilance function should work closely with risk management, internal audit, information security, compliance and human resources. Fraud frequently develops across functional boundaries. No department may possess the complete picture unless information is shared and analysed collectively.
Whistle-blower mechanisms are equally important. Employees must have confidential and credible channels through which they can report suspected misconduct without fear of retaliation. Complaints involving senior officials or sensitive customers should be examined independently and promptly.
Board and Senior Management Accountability
Large banking frauds are rarely caused by a single failed control. They generally involve a chain of weaknesses across operations, supervision, technology, audit and governance.
Boards and senior management must therefore examine not only who committed the misconduct but also why the institution’s systems failed to detect it. They should ask whether alerts were generated, whether reports were reviewed, whether staff rotation was enforced and whether earlier warning signs were ignored.
RBI’s fraud-monitoring framework requires significant frauds to be reviewed at Board level, with attention to systemic deficiencies, delays in detection, staff accountability and remedial measures. It also requires banks to assess whether their systems can detect frauds within the shortest possible time and whether vigilance action is initiated where staff involvement is identified.
Key Lessons for Banks
The Punjab National Bank case offers several enduring vigilance lessons.
Sensitive transaction systems must be fully integrated with the core banking platform. Access privileges should be restricted, periodically reviewed and immediately withdrawn when an employee changes role. Maker-checker controls must involve genuine scrutiny rather than mechanical approval. Employees in sensitive positions should be rotated, and mandatory leave should be enforced.
Banks must reconcile all transaction channels and investigate exceptions immediately. Audit teams should verify information independently rather than depend solely on reports generated by the system being audited. High-value guarantees, contingent liabilities and trade finance transactions require centralised monitoring and senior-level oversight.
Most importantly, vigilance should not be confined to punishing employees after a fraud has occurred. It must influence process design, technology architecture, employee deployment, customer monitoring and governance.
Conclusion
The Punjab National Bank fraud demonstrated how employee misconduct can combine with weak internal controls and disconnected technology systems to create a major institutional exposure. It also showed that the presence of policies, audits and approval mechanisms is insufficient unless they function effectively in practice.
The real purpose of vigilance is not merely to identify the guilty after a loss. It is to reduce opportunities for wrongdoing, detect warning signals early and ensure that no employee or customer can operate beyond the reach of independent oversight.
For the banking industry, the lasting lesson is clear: effective vigilance must be preventive, technology-enabled, independent and embedded across every level of governance. A bank becomes resilient not when misconduct is considered impossible, but when its systems are designed to detect and contain misconduct before it threatens the institution.

