By Kebba A.F. Touray
The National Audit Office (NAO) has flagged suspected fraud involving D297,941.43 in deleted rate transactions at the Kanifing Municipal Council (KMC), saying the money remained unrecovered and the matter had not been reported to the appropriate authorities for investigation.
The finding is contained in the NAO’s report and final management letter on the audit of KMC for the years ended 31 December 2020 and 31 December 2021, published on 26 June 2026.
The auditors classified the matter as “Suspected Fraud” and said it related to the deletion of rate transactions for the 2020 financial year.
According to the NAO, the deleted transactions were removed from the Council’s Matrix data system, resulting in the money not being banked.
“We noted suspected fraud of GMD 297,941.43 in respect to rates for the year 2020. These were deleted transactions from the Matrix data system which resulted to non-banking of these transactions as per memo dated 28 December 2020 with reference number Ref: KMC/FIN/342,” the auditors said.
The auditors said KMC had established a task force to investigate the matter.
However, they said no report from the task force was provided to the audit team to confirm the outcome of the investigation.
“A task force was set up by the Council to investigate the matter but no investigative report was provided to confirm the conclusion of the investigation,” the NAO said.
The auditors said discussions with members of the task force showed that the matter remained unresolved and that the money had not been recovered.
“Our discussion with the task force members revealed that the matter was still unresolved and the amount un-recovered,” the auditors said.
The NAO also raised concern that the matter had not been reported to the appropriate authorities, including the Gambia Police Force, for further investigation.
The auditors warned that failure to properly investigate the matter could result in the Council losing funds that could otherwise be used to finance its activities.
The NAO therefore recommended that KMC management provide the task force’s investigative report for audit review.
It also recommended that the Council report the matter to the appropriate authorities for investigation because the amount involved could be higher.
The Council, however, said an investigation had been carried out at the time the issue arose.
Management said the investigation was handled by the then Chief Executive Officer and Director of Finance, with assistance from the Finance Committee and the Establishment and Appointment Committee.
Management said the minutes of the investigation were available for inspection.
“Management have carried an investigation on the matter at the time but was handle by then CEO and Director of Finance with help of the Finance Committee and Establishment and Appointment Committee of which the minutes of the investigation is available for inspection,” the Council said.
Management also provided information about access to the Council’s computer system.
According to the Council, information obtained from the system developer indicated that only a system administrator could access the database and carry out the type of transaction in question.
“Based on the information from the system developer it is only the system Administrator could have access to the data base to perform such transactions and the former IT Manager was the system Administrator to the Data base,” management said.
The Council said the former IT Manager was contacted during the investigation but denied involvement in the deletion of the transactions.
Management said the IT Manager had the necessary system access but that his involvement could not be established because an audit trail was not available.
“The IT Manager denied any involvement in the act despite having all the right to the system but could not be ascertain due to the unavailability of the audit trail,” management said.
The Council said it subsequently reviewed the user rights within the system and amended them to reduce the access available to the IT Manager.
Management said the changes were intended to prevent similar incidents from occurring again.
The Council also said the cashier involved had been transferred and replaced.
“The Cashier was also transferred from the post and replaced with another cashier and daily monitoring of the reports from the system is ongoing to ensure that all revenue collected through the system is accounted for accordingly on a daily basis,” management said.
Management said it was also working to improve the system’s audit trail and introduce additional security features.
It said changes were being made to user authorisations to prevent manipulation of the ledger.
The Council also planned to introduce a notification system to alert users when transactions were manipulated.
Management said several other measures had been introduced to strengthen the system.
These included an activity log through which changes to transactions could be seen by other users, a daily system reconciliation process, encrypted receipt columns and an encrypted receipt log table.
The Council said these measures were intended to reduce the risk of manipulation and strengthen controls over revenue collection.
However, the NAO said the additional measures outlined by management did not resolve all of the questions raised by the audit.
The auditors said their review of the audit evidence showed that another senior finance official had high-level access to the system.
“Despite the above management responses, the audit evidence we have revealed that the Deputy Director of Finance indeed had Super Admin rights to the system,” the NAO said.
The auditors said they could not confirm whether the former IT Manager also had the system rights claimed by management.
“We could not confirm if the IT manager had the rights as alleged in the management response as he was relieved from council before the current audit commence,” the auditors said.
The NAO’s finding therefore centres on the deletion of rate transactions worth D297,941.43 from KMC’s Matrix system and the failure to establish through available audit evidence who carried out the deletions.
The auditors also questioned the absence of a task force investigation report and the failure to refer the matter to the appropriate authorities.
The Council has said it took internal measures following the incident, including reviewing user access rights, transferring the cashier and strengthening its system controls. The audit finding remains focused on the suspected deletion of revenue transactions, the unrecovered amount and the inability of the audit team to establish responsibility from the available audit trail.