8+ years of experience in Risk & Compliance, Forensic Accounting, Finance, and Data Analytics — delivering high-impact engagements across banking, insurance, NGO, manufacturing, and gaming sectors.
Financial modelling, management reporting, budgeting, variance analysis, and strategic planning for Big Four clients and growth-stage companies.
ERM frameworks, IIA-aligned audits, AML/CFT, FATF standards, ISO 27001, SOX testing, and ITGC assessments across banks and insurers.
Power BI dashboards, Python automation, SQL forensic analytics, IDEA/ACL data analysis, and anomaly detection for regulated entities.
20+ complex forensic engagements — SAP HANA fraud analysis, procurement irregularities, donor fund investigations, and BI claim audits.
Hover to reveal
Led complex SAP HANA forensic audit uncovering vendor manipulation and payment anomalies across 18 months. Legal-ready report delivered.
Led AML/CFT compliance review and TMS assessment under FATF and CBSL requirements. Zero findings at subsequent regulatory examination.
Designed and implemented an ERM framework — risk register, heat maps, appetite statements, KRIs, and a live Power BI board dashboard.
Available for international engagements, remote advisory, and forensic consulting. Let's discuss your challenge.
📍 Sri Lanka · Available internationally · Immediate availability
I'm Sanjeevi Bandara — Financial Forensic Manager at KPMG Sri Lanka, with 8+ years of Big Four experience spanning forensic investigations, risk-based internal audits, AML/CFT compliance, and data analytics across banking, insurance, gaming, and NGO sectors.
I've managed a LKR 35M+ services portfolio, led 20+ complex forensic engagements, and built data tools using Python, Power BI, and SAP HANA that make financial crime visible and auditable.
Currently completing an MSc in Data Science (University of Wolverhampton) — sharpening the technical edge that separates good forensic accountants from great ones.
Forensic & Analytics
Data & Programming
ERP & Systems
Compliance Tools
Big Four rigour, certifications across all four domains, and a data science layer that most forensic professionals don't have. I find the fraud, quantify the risk, model the impact, and build the system to prevent it.
Book a Free Call ↗Big Four methodology, practical outcomes. Available for project-based, retainer, and international remote engagements.
Problem: Control gaps, regulatory exposure, and unmapped enterprise risk.
Approach: IIA-aligned methodology, COSO/COBIT, ERM framework design.
Deliverables: Audit plans, ERM frameworks, risk registers, board reports.
Problem: Regulatory compliance gaps and TMS weaknesses.
Approach: FATF alignment, GoAML audit, TMS assessment, STR framework review.
Deliverables: Compliance reports, remediation roadmaps, policy documentation.
Problem: IT control weaknesses, SOX non-compliance, access management failures.
Approach: COBIT/NIST framework, ITGC testing, SOX IT controls documentation.
Deliverables: ITGC reports, SOX evidence packages, NFR assessments.
Problem: ISO 27001 certification gaps, GDPR/PDPL non-compliance.
Approach: Controls gap assessment, policy development, audit-readiness roadmap.
Deliverables: GRC frameworks, DPIAs, policy suites, certification support.
Problem: Manual reporting, invisible fraud patterns, siloed financial data.
Approach: ETL pipeline design, anomaly detection models, Power BI builds.
Deliverables: Automated dashboards, Python scripts, KPI monitoring systems.
Problem: Suspected fraud, asset misappropriation, or financial misconduct.
Approach: IDEA, ACL, and SAP HANA forensic analysis with legal-ready documentation.
Deliverables: Investigation reports, legal-ready evidence packages, control recommendations.
Representative analytics deliverables from real client engagements.
Problem: A financial institution suspected systematic procurement fraud across SAP HANA MM, FICO, and SD modules.
Solution: Led a complex SAP forensic audit — analysing vendor master data manipulation, payment processing anomalies, and revenue recognition irregularities using IDEA and ACL across 18+ months.
Outcome: Identified systematic irregularities, produced a legal-ready investigation report, and designed a preventive ITGC control framework.
Problem: A regulated financial institution needed a comprehensive AML/CFT review under FATF and CBSL requirements ahead of a regulatory examination.
Solution: Executed GoAML audit, TMS assessment, and FATF standards alignment review using World-Check, Refinitiv, and LexisNexis with full STR framework evaluation.
Outcome: Full compliance framework delivered — zero regulatory findings at subsequent CBSL examination.
Problem: A mid-size manufacturer had no formal ERM structure — risks identified ad hoc with no consistent methodology or board-level visibility.
Solution: Designed a COSO ERM framework — risk register, risk heat maps, appetite statements, KRIs, and a Power BI board reporting dashboard.
Outcome: Board adopted the framework at first presentation. Live risk dashboard gave management real-time visibility for the first time.
Problem: A private healthcare group required ISO 27001 certification to secure a government contract with a 14-week window.
Solution: Controls gap assessment against ISO Annex A, prioritised remediation roadmap, policy suite development, and staff awareness training.
Outcome: Achieved audit readiness in 14 weeks. Passed Stage 1 certification audit with zero major non-conformities.
Problem: An international development agency suspected misappropriation of donor funds across multiple implementing partners.
Solution: Forensic review of procurement systems and cost structures — data analytics to detect overpricing, bid rigging, and non-compliant fund flows.
Outcome: Irregularities confirmed and quantified. Report used to reform procurement controls across the programme.
Problem: A reinsurer disputed the quantum of a BI claim submitted following an operational shutdown event.
Solution: Conducted a reinsurer BI calculation audit — evaluating loss quantum methodology, projected revenue, saved costs, and mitigation measures.
Outcome: Identified methodological errors in quantum calculation. Revised settlement figure accepted by both parties.
Defined scope, fixed deliverables, and timeline. Best for forensic investigations, audits, and compliance frameworks.
Custom quote
Ongoing risk and compliance advisory — ideal for organisations without a full-time Head of Risk or Internal Audit.
Monthly model
Expert input for reviews, second opinions, or strategic sounding. Available remotely for international clients.
Flexible hourly
International engagements welcome. Remote advisory available.
I write on Substack and Medium about forensic accounting, financial crime, risk, and the technology transforming how we detect fraud.
Available on Substack
Financial crime, forensic technology, and data-driven risk — decoded for practitioners.
Free · No spam · Unsubscribe anytime
How large language models are being applied in fraud detection and investigative workflows — and where the real limitations lie.
Read on Medium ↗The gap between traditional financial crime frameworks and Web3 reality — a practical framework for compliance teams navigating crypto exposure.
Read on Medium ↗What works, what doesn't, and how to build a business case that survives board scrutiny.
Read on Substack ↗A data-led approach to uncovering vendor fraud, access abuse, and payment anomalies inside SAP HANA.
Read on Medium ↗Curated reading for finance, forensic, investment, and analytics professionals.
The definitive guide to value investing — timeless principles through every market cycle.
How analysts saw through the greatest fraud in financial history. Essential for risk professionals.
A forensic look at high-frequency trading and market manipulation. Reads like a thriller.
Statistics made intuitive — ideal for finance and audit professionals building data literacy.
How to turn data into persuasive visuals — every audit report gets sharper after this.
Why most predictions fail — critical for anyone building risk models.
Forensic accounting, financial crime, data science, and risk — every few weeks, in your inbox.