GRC and GCN: When the Control Works but the Money Still Does Not Arrive

Last Updated on 16/09/2026 by 75385885

What the IBK China case teaches us about third-party risk, independent evidence and Governance Reality

Third-party risk management – A reconciliation is one of the most familiar instruments of financial control. One set of records is compared with another. Differences are identified, investigated and resolved.

It sounds reassuringly straightforward.

But what if the records say that customers have repaid their loans while the money does not actually reach the bank?

And what if the control designed to compare repayments with deposits is being performed every day?

That is the uncomfortable governance question raised by a recent case involving the Chinese subsidiary of Industrial Bank of Korea (IBK).

According to The Korea Times, IBK’s Chinese subsidiary provided non-face-to-face loans to local borrowers in partnership with a non-bank financial institution. An online lending platform recruited borrowers and collected repayments. Borrowers transferred their repayments to an account designated by the platform, which was then supposed to transfer the money to IBK.

The platform allegedly changed the repayment account without authorisation, diverted the money instead of transferring it to IBK and falsified records to make it appear that borrowers had repaid their loans. Some borrowers were consequently classified as delinquent despite having made their payments. The reported incident ran from December 2025 until June 2026 and IBK disclosed a loss of approximately 83.4 billion won, although the ultimate amount remained subject to investigation and recovery efforts.

But from a governance perspective, perhaps the most remarkable fact is another one.

IBK reportedly told the Financial Supervisory Service that it had checked repayment records against actual deposits every day. Yet the bank said it first became aware of the problem on 24 June, after settlement funds failed to arrive and borrower complaints accumulated.

This article does not attempt to reconstruct exactly how IBK’s controls operated, nor does it conclude why those controls did not identify the alleged diversion earlier. The publicly available information is insufficient for that.

Instead, the case provides an excellent basis for a much broader governance question:

What exactly does a control prove when part of the evidence on which it relies may itself be part of the risk?

That is where Governance, Risk & Compliance (GRC) and Governance Control Navigator (GCN) can complement each other.

GRC establishes the control framework.

GCN asks whether the combined evidence still supports the Governance Reality that framework was intended to create.


1. The control was performed — so why was the money missing?

The immediate temptation after a financial loss is to ask which control failed.

Sometimes that is precisely the right question.

But it may also be too simple.

A bank operating a lending process can have policies governing loan origination, customer identification, credit assessment, repayment processing, third-party relationships, reconciliations, exception handling and financial reporting.

Controls can exist around all of them.

And those controls can generate evidence.

A loan was approved.

A repayment was recorded.

A reconciliation was performed.

An exception report was reviewed.

A third-party relationship had been authorised.

Yet the economic outcome may still be different from the reality represented by those individual records.

The IBK case makes that distinction unusually tangible.

According to the reporting, borrowers made repayments. The lending platform allegedly redirected those payments and falsified records. IBK consequently did not receive money it expected to receive.

There are therefore several potentially different realities:

what the borrower did,

what the platform recorded,

what the bank recorded,

and

where the cash actually went.

Governance becomes interesting when those realities stop agreeing.

Read the case as published in The Korea TimesIBK under scrutiny over internal controls after major fraud case at China unit.


2. A third party can create a parallel reality

Third parties are indispensable to modern business.

Banks use payment processors, brokers, platforms, valuers, technology providers, cloud services and countless other specialists. Industrial companies rely on distributors and logistics providers. Retailers depend on marketplaces and payment services.

Outsourcing an activity, however, does not outsource accountability for understanding its consequences.

The IBK arrangement described by The Korea Times illustrates why.

The online platform was not merely providing background technology. It reportedly recruited borrowers and collected loan repayments through a designated account before funds were transferred to IBK.

That places the third party within both the information flow and the economic flow.

Conceptually, the chain might be represented as:

Borrower → Repayment → Platform account → Settlement → IBK → Loan balance

Now imagine that one participant in this chain can influence both what happens to the money and what information is subsequently reported about it.

A dangerous possibility emerges:third-party risk management

economic reality and recorded reality can separate.

The records can continue telling one story while the cash tells another.

This is not unique to banking.

It is a fundamental third-party governance problem.


3. GRC controls the process — but what if the evidence is manipulated?

Traditional GRC remains indispensable in precisely this environment.

The organisation needs policies for third-party selection, due diligence, contractual obligations, access, authorisation, reconciliation, incident management, risk assessment and monitoring.

The question is not whether those controls should exist.

They should.

The more difficult question is what evidence demonstrates that they are achieving their intended purpose.

Suppose a control requires a repayment report to be reviewed every morning.

The report arrives.

The control owner reviews it.

The review is documented.

The control is therefore demonstrably executed.

But what has actually been demonstrated?

That the report was reviewed.

Not necessarily that the economic event represented by the report occurred exactly as represented.

This distinction is fundamental.

Control evidence is evidence that a control activity occurred. Economic evidence is evidence that the underlying economic reality occurred.

Often the two support each other perfectly.

Sometimes they do not.

GCN is particularly interested in that gap.


4. Governance Design, Governance Execution and Governance Reality

The Three Governance Realities™ help explain the distinction.

Governance Design

This is the intended architecture.

Borrowers repay their loans through an authorised mechanism. The intermediary transfers the funds to the bank. Repayment records are processed. Balances are updated. Reconciliations are performed. Exceptions are investigated.

Policies, contracts, responsibilities and controls define how this should work.

Governance Execution

This is the observable execution of that design.

Repayment records arrive.

Records are processed.

Reconciliations are performed.

Loan balances are updated.

Reviews are documented.

These activities can provide substantial evidence that controls are operating.

third-party risk management third-party risk, third-party fraud, internal controls, bank internal controls, reconciliation controls, external fraud risk, Governance Intelligence, Governance Control Navigator, Governance Reality

third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management third-party risk management

Collective Governance Behaviour™

Then there is the accumulated economic and operational behaviour created by all these individual events.

Do recorded repayments correspond with actual settlement cash?

Are settlement delays increasing?

Are borrower complaints changing?

Do borrowers classified as delinquent claim that they have already paid?

Does the intermediary’s actual behaviour remain consistent with its contractual role?

Do independent external signals concerning the third party begin to change?

When these realities start diverging, a transaction-by-transaction view may no longer be enough.

That is Governance Divergence.

There are more banks having difficulties in governing their internal controls: JPMorgan and Weak Internal Controls: When Governance Design Is Not Enough.


5. A reconciliation is only as strong as its independent evidence

This leads to perhaps the most important governance lesson from the case.

We often speak about reconciliation as though comparison itself creates assurance.

It does not.

Its strength depends substantially on the quality and independence of the evidence being compared.

Imagine two reports.

Report A says that a borrower paid €10,000.

Report B says that the €10,000 repayment was processed.

The reports agree perfectly.

But suppose both ultimately derive from information controlled by the same intermediary.

Their agreement may be less powerful than it appears.

Now add a third source:

the bank’s independently controlled settlement account.

If the first two sources say €10,000 was paid but the corresponding settlement cash never appears, the third source tells a different story.

That discrepancy matters.

This does not mean that every reconciliation requires completely independent systems. Real processes are far more complicated.

It does mean that governance should understand data lineage and evidence dependency.

Where did the information originate?

Who can change it?

Which systems transform it?

Which evidence is genuinely independent?

Which supposedly different records ultimately share the same source?

This produces a useful governance principle:

A reconciliation provides the strongest assurance when the realities being reconciled are sufficiently independent to challenge each other.

Otherwise, an organisation risks reconciling a representation of reality with another representation derived from the same reality.


6. Follow the economic chain, not only the records

This is where GCN changes the unit of analysis.

Instead of analysing only a repayment record, it can reconstruct the relationships surrounding the economic event:

Borrower → Loan → Scheduled repayment → Borrower payment → Platform account → Settlement → Bank account → Loan balance

Each object contributes evidence.

Suppose a borrower has a scheduled repayment.

A repayment record appears.

The loan administration marks the instalment as satisfied.

So far, the administrative chain appears coherent.

But the expected settlement does not arrive.

That missing relationship changes the interpretation of everything before it.

GCN therefore does not need to ask:

“Is this repayment fraudulent?”

It can ask:

“Does the complete evidence chain support the conclusion that the economic event represented by this repayment record has been completed?”

That is a much safer and more useful governance question.

Also read our blog: When One Salesperson Can Distort Corporate Reality – What the WANdisco Case Teaches Us About the Next Step from GRC to Governance Intelligence.


7. The Missing Settlement Footprint

This case introduces another useful Governance Intelligence concept:

the Missing Settlement Footprint

A recorded economic event normally creates consequences elsewhere.

This idea has appeared repeatedly in other governance contexts.

A genuine sale should usually create some combination of customer activity, contractual evidence, delivery, invoicing, receivables and cash.

A genuine purchase creates procurement, receipt, invoice and payment relationships.third-party risk management

A legitimate business expense should have some connection to business purpose.

A loan repayment should eventually create a settlement consequence.

The precise footprint depends on the business model.

But economic events rarely exist in isolation.

In the IBK case, the reported contradiction is particularly clear: borrowers could have made payments while IBK nevertheless failed to receive the corresponding money.

The governance question therefore becomes:

If this repayment is economically complete, where is its settlement footprint?

One missing settlement may have countless innocent explanations.

A payment can be delayed.

Banking infrastructure can fail.

A reference can be incorrect.

A reconciliation can have timing differences.

But when missing settlement footprints accumulate, remain unresolved or begin correlating with other signals, the population starts telling a different story from the individual transaction.

That is where Governance Intelligence becomes valuable.


8. The earlier IBK property case reveals a broader challenge

The China-unit incident did not occur in isolation from other external-party fraud concerns reported around IBK.

Two months earlier, The Korea Times reported a separate IBK case involving 4.78 billion won connected with a commercial-property presales scheme. According to the regulatory filing described by the newspaper, borrowers allegedly misled the bank about property values and presales prices in order to obtain larger loans than they would otherwise have qualified for. That incident occurred between May and December 2024 and was reportedly uncovered after investigative authorities requested related documents.

The same article also reported a separate incident at Woori Bank involving allegedly fraudulent documents submitted by an external party. Industry officials quoted in the article argued that, while stricter internal controls had helped curb insider-related misconduct, schemes involving external parties and falsified documentation remained difficult for banks to detect in advance.

The two IBK incidents are therefore not the same case.

But together they illustrate a common governance challenge.

In the property case, the risk concerned information describing the underlying asset and presales economics.

In the China-unit case, the alleged manipulation concerned the repayment and settlement process.

Different processes.

Different events.

The same fundamental question:

How does an organisation independently establish that information received from outside its controlled environment still corresponds with economic reality?

Read more in The Korea TimesHousing loan scams hit IBK, Woori Bank.


9. Third-party risk is more than vendor due diligence

Third-party risk management often begins before the relationship starts.

Who is the counterparty?

Is it financially stable?

Does it comply with relevant regulation?

How strong is its cybersecurity?

What contractual protections exist?

What service levels apply?

Those questions remain important.

But a third party that passed due diligence yesterday can behave differently tomorrow.

Governance therefore needs to move beyond third-party approval towards third-party reality monitoring.

GCN could add questions such as:

Does actual transactional behaviour remain consistent with the expected operating model?

Are settlement patterns changing?

Are exceptions increasing?

Are complaints concentrating?

Are reconciliation breaks becoming longer-lived?

Are new bank accounts, routing structures or counterparties appearing?

Does external risk information change?

The objective is not to continuously suspect the third party.

It is to understand whether the relationship itself remains consistent with Governance Design.

That is a much more dynamic interpretation of third-party governance.


10. External warning signs belong to Governance Reality too

One detail in the China-unit reporting deserves particular attention.

According to documents cited by The Korea Times, five Chinese financial institutions had already removed the local lending platform from their partner lists in March and April. The article says IBK’s problem continued until June.

That fact should be handled carefully.

It does not establish that IBK knew, should have known, or had access at the relevant time to the reasons behind those decisions.

But conceptually it demonstrates something important.

Governance Reality does not necessarily end at the boundary of the organisation.

A material third party exists within an ecosystem.

Regulatory events, credit deterioration, legal proceedings, cybersecurity incidents, partner withdrawals or other appropriately sourced external risk indicators may become relevant governance evidence.

GCN therefore need not be confined to ERP records.

The principle is broader:

The more material the dependency on a third party, the more relevant changes in that third party’s observable Governance Reality may become.

Again, this does not mean automatically reacting to every external signal.

It means connecting relevant evidence rather than allowing it to remain isolated.


11. GCN does not say “fraud”

This boundary is crucial.

GCN should not transform a settlement delay into a fraud accusation.

Nor should it assign a suspicious-person score to an employee, borrower or third party.

A professional GCN observation might instead say:

Within the loan-repayment population, recorded repayment activity is increasingly diverging from corresponding settlement cash flows. The divergence is concentrated within transactions involving a specific third-party processing route and coincides with an increase in unresolved borrower-status exceptions. Further assessment of settlement completeness, source-data reliability and third-party control execution is warranted.

That is very different from saying:

“The platform is committing fraud.”

The first statement is evidence-led, reproducible and investigable.

The second is a conclusion requiring evidence and due process far beyond an anomaly pattern.

GCN identifies where reality deserves professional attention.

Management, Risk, Compliance, Internal Audit or, where appropriate, specialist investigators determine what the evidence ultimately means.


12. From isolated exceptions to relationship reconstruction

A single settlement failure is an exception.

Ten may be an operational issue.

A hundred might indicate something systemic.

But even numbers alone are insufficient.

The real intelligence comes from relationships.

Imagine that over time GCN observes:

repayment records continue to arrive;

settlement delays increase;

cash receipts decline relative to recorded repayments;

borrower complaints increase;

some borrower statuses conflict with claimed payment behaviour;

exceptions concentrate around one processing route;

external partner-risk signals deteriorate.

None of these facts independently proves wrongdoing.

Together, however, they describe a changing Governance Reality.

This is why GCN’s relationship reconstruction is more important than simple anomaly detection.

An anomaly says:

“This looks unusual.”

A governed relationship analysis asks:

“Which business objects are connected, what should their relationship be, how is that relationship actually behaving and how is it changing over time?”

That produces a far more explainable basis for management action.


13. Why stronger controls alone may not solve the problem

The conventional response to a control incident is understandable:

add another control.

Sometimes that is exactly what is needed.

But imagine responding to unreliable repayment information by introducing a second review of the same repayment information.

The organisation now has two controls.

If both depend on the same compromised source, has Governance Reality become more reliable?

Perhaps not.

The number of controls has increased.

Evidence independence has not.

That distinction matters far beyond banking.

A procurement manager and controller may review two documents that originated with the same supplier.

Two systems may contain data ultimately fed from the same interface.

Two management reports may appear independent while sharing the same underlying dataset.

Governance maturity therefore cannot be measured simply by counting controls.

Sometimes the better solution is not another review.

It is a better independent evidence source, stronger data lineage, redesigned settlement architecture, direct confirmation, improved exception escalation or a different third-party operating model.

The question should always be:

What additional evidence would genuinely challenge our current understanding of reality?


14. From signal to improvement

Even that is not the end.

GCN should not become another monitoring platform producing an ever-growing queue of red alerts.

Governance becomes valuable when observations lead to learning.

The cycle should be:

observe → understand → solve → authorise → measure → learn

First, identify the divergence.

Then understand its cause.

Perhaps the third-party arrangement is poorly designed. Perhaps settlement timing is misunderstood. Perhaps data lineage is unclear. Perhaps an interface has failed. Perhaps an external party has acted improperly.

Only after understanding the cause should the organisation design an appropriate response.

That response must then be authorised and implemented.

And subsequently GCN asks another question:

Did Governance Reality actually improve?

Did settlement completeness recover?

Did unresolved exceptions decline?

Did reconciliation breaks shorten?

Did complaints return to normal levels?

Did the relationship between repayment records and cash become consistent again?

Closing a remediation action is not the same as proving that the underlying reality has changed.

The implementation of a control is not the final evidence of improvement. The change in Governance Reality is.


15. GRC and GCN: from control evidence to economic evidence

The IBK China case is still subject to investigation, and public reporting cannot tell us precisely how every relevant internal control operated. It would therefore be inappropriate to claim that GCN would have detected the alleged fraud, prevented the loss or identified the third party responsible.

That is not the point.

The case matters because it exposes a fundamental governance problem that exists in almost every complex organisation.

We rely on representations of reality.

Invoices represent purchases.

Delivery records represent goods received.

CRM records represent sales activity.

Loan records represent obligations.

Repayment records represent payments.

Management reports represent organisational performance.

Controls then test those representations.

Usually, that works.

But when the evidence source itself becomes unreliable, governance must be capable of looking beyond the record to the economic footprint that record should have created elsewhere.

That is where GRC and GCN belong together.

GRC asks:

Was the required control properly designed and performed?

GCN adds:

Does the evidence across independent parts of the organisation still support the economic reality that the control is intended to demonstrate?

The distinction is subtle, but profound.

A control can confirm that a repayment was recorded.

A reconciliation can confirm that two records agree.

A workflow can confirm that the correct approval occurred.

All are valuable.

But Governance Reality ultimately asks something harder:

Did the economic event actually happen as the organisation believes it did?

The reported IBK China case brings that question back to its simplest possible form.

The records can say that borrowers paid.

The controls can process those records.

The systems can update their balances.

But eventually governance must still be able to answer:

Where did the money actually go?

That is not an argument against GRC.

It is an argument for connecting GRC with Governance Intelligence.

Because good governance does not merely require evidence that controls were performed.

It requires sufficient independent evidence that the reality those controls are intended to govern still exists.

Third-party risk management