These are some of the main projects I’ve led or worked on across my career in banking. Most of them started with the same situation: a control gap, limited budget and no ready-made system to fix it. In each case, I researched how the problem was handled elsewhere, then built a practical solution that fitted the bank’s size and resources.
The institution had no central record of operational incidents, so recurring problems and control weaknesses went unnoticed. The Chief Risk Officer asked me to design a solution. After researching how UK banks capture and classify risk events, I built a cloud-based incident log that recorded each incident’s type, root cause, financial impact, control failure, remediation and owner. The harder part was getting people to use it. I ran sessions with Heads of Department, issued guidance on what counts as an incident, and followed up until reporting became routine. I then used the log to produce quarterly operational risk reports for the Board, covering trends, root causes and where controls needed strengthening.
The bank’s AML policies were well documented, but thresholds, escalation and controls weren’t being applied consistently on the front line. Automated monitoring wasn’t affordable. I spent two months observing frontline practice, testing staff understanding of thresholds and escalation, reviewing audit findings and benchmarking against UK high street banks. From that, I designed a manual, risk-based monitoring framework. It covered voucher-level transaction reviews, daily reconciliation against policy thresholds, a central log of findings, formal escalation routes and weekly reporting to business units. The results fed into monthly MLRO reports, ExCo discussions and quarterly Board reporting. I brought staff along by showing them the evidence of control failures and training them on real scenarios instead of forcing sudden change. Over time, identified gaps fell by around 90%.
A compliance audit found a large backlog of periodic customer reviews, many accounts dormant for over ten years, and zero-balance accounts that had never been used. Working with IT, I extracted and segmented the customer data by activity, account age and balance, then set up a phased remediation plan. Zero-balance accounts went through a formal notification and closure process. Dormant account holders were asked either to update their documents and reactivate, or to close the account. Where customers couldn’t be traced, I investigated further and submitted a memo to ExCo to approve closure and transfer of balances under internal procedures. Every step was logged for audit. This cut the review backlog significantly and improved data quality. Along the way, I also set up the bank’s first central PEP register.
I joined as one of 22 founding members after the branch received its licence from the Central Bank of Sri Lanka, and was responsible for setting up the Trade Finance Department before launch. I wrote the Trade Finance Policy, procedure manuals and trade-specific AML policies, and designed workflows for letters of credit, collections, guarantees and telegraphic transfers. I also developed the customer application forms and legal documents, which went through external legal review, and helped set the department’s tariff structure through competitor benchmarking. The core banking and trade systems came from Head Office with limited English documentation, so I studied the manuals myself and spent about eight weeks testing them end to end with IT before go-live. The department launched on time, and I processed the branch’s first letter of credit, telegraphic transfer and bank guarantee.
I represented the Trade Finance Department in user acceptance testing during the bank’s move from Globus to Finacle. My role covered end-to-end testing, validating workflows, raising and resolving issues with IT, and taking part in data migration and reconciliation to make sure trade data moved across accurately.