Barings Bank, Account 88888, and the LATAM Control Environment

Camila Gomez September 28, 2026

Barings Bank did not collapse solely because of a rogue trader. It collapsed because of a critical institutional assumption.

Many significant financial crimes begin long before the first fraudulent transaction. They begin with a belief that is too often left unchallenged: “That could never happen here.”

  • Different countries
  • Different regulators
  • Different business models
  • The same blind spot

Founded in 1762, Barings Bank was one of the oldest and most respected financial institutions in the United Kingdom. By the early 1990s, the bank had expanded its derivatives trading operations in Asia through its Singapore office, where trader Nick Leeson held responsibility for both trading and settlement activities. Between 1992 and 1995, Leeson concealed growing losses in an internal error account known as Account 88888. Following significant market volatility after the Kobe earthquake in January 1995, his unauthorized positions contributed to losses totaling approximately USD 1.4 billion. Barings was declared insolvent on February 26, 1995, and was subsequently acquired by ING for the nominal sum of £1.

When people discuss the collapse of Barings Bank, attention is typically directed toward the rogue trader at the center of the scandal rather than the governance and control failures that made the misconduct possible. In my view, that interpretation is incomplete. Leeson was not the only failure; the control environment failed as well.

One detail from the story illustrates this perfectly: Account 88888.

Originally established as a legitimate error account, Account 88888 was later used by Leeson to hide losses, distort reporting, and conceal the institution’s true exposure. But the existence of the account was not, by itself, the problem. The more important question is: How was a single individual able to misuse it for years without being stopped?

The answer is surprisingly familiar.  

There was no sophisticated cyberattack, no artificial intelligence-enabled fraud or scheme, and no complex criminal network. There were simply fundamental control failures that remained unaddressed for too long:

  • Inadequate segregation of duties.
  • Weak supervisory oversight.
  • Excessive trust in a high performer.
  • Lack of independent challenge.
  • A culture that valued results more than controls.

More than thirty years later, those same weaknesses continue to appear within financial institutions across Latin America.

Organizations often ask whether compliance justifies the investment. That question is too narrow. The cost of compliance is visible in the budget; the cost of weak controls is often recognized only after the damage has been done. The consequences are familiar:

  • Fraud losses.
  • Regulatory investigations and sanctions.
  • Customer remediation. 
  • Reputational damage
  • Years spent rebuilding trust.

What we have observed through multiple investigations and control reviews across Latin America is not merely a diversity of fraud schemes. It is the consistency of the weaknesses that make them possible:

  • Different products.
  • Different countries.
  • Different actors.
  • The same control failures.

Similar patterns across LATAM

Over the years, the Guidepost Solutions team has observed situations in which organizations created special operational structures to respond to business pressures, operational incidents, or growth objectives. These decisions were often made with good intentions.

The unintended consequence was that temporary exceptions slowly evolved into permanent operating models. In several situations, highly respected employees gained significant influence because they consistently delivered results. Supervisors trusted them and colleagues relied on them. As a result, questions became less frequent. Over time, that trust became stronger than the controls themselves.

In one instance, an employee exploited such an environment to create a process that systematically bypassed control activities and generated fraudulent gains amounting to hundreds of thousands of dollars per day.

What concerned us the most was not the sophistication of the scheme. It was how many employees unknowingly participated in it. Many were not dishonest; they simply operated in an environment where challenging unusual requests was not part of the culture. Compliance existed as a function, but it did not exist as a mindset.

We have also observed another recurring pattern involving senior employees and executives with deep institutional knowledge. Organizations often view these individuals as invaluable assets, and in reality, they are.  But from a fraud risk perspective, they also represent a unique concentration of knowledge:

  • They understand product design.
  • They understand the processes.
  • They understand the control gaps.
  • They also understand which controls exist only on paper.

In environments where independent challenge is weak, that knowledge can become extremely dangerous. We have seen situations where individuals leveraged their understanding of lending processes, approval workflows and third-party ecosystems to facilitate large-scale credit fraud involving intermediaries, nominee borrowers and external networks operating across multiple regions.

The resulting losses were not driven by a single control failure. Rather, they emerged from the simultaneous breakdown of multiple safeguards:

  • Automated preventive controls were ineffective or absent.
  • Documentary verification controls were routinely ignored.
  • Segregation of duties was not consistently applied.
  • Risk-based testing programs were insufficiently developed.
  • Targeted training for high-risk roles was never delivered.
  • Management placed excessive reliance on reputation and historical performance.

The reason these experiences remind us of Barings Bank is not because the fraud schemes were similar. They were not. The similarities lay in the underlying control of weaknesses. Nick Leeson understood the operational reality of Barings’ Singapore office better than the people responsible for overseeing him. The trusted employees and executives involved in the situations we observed possessed a similar advantage. 

They knew where documented processes differed from operational reality. They understood which controls could be bypassed, which exceptions would not be questioned and where trust had effectively replaced verification.

The most dangerous control weakness is rarely the one already identified in an audit report. It is the weakness that everyone assumes is being managed. Barings had Account 88888. Every institution may have its own version of Account 88888.

Finding your institution’s “Account 88888” before it becomes a crisis

The lesson from Barings is that every institution should be willing to look closely at the places where trust, habit and business pressure may have weakened the ability to challenge established practices effectively. That starts with an honest conversation:

Which critical controls have been genuinely tested this year rather than simply reviewed? Where would an employee with deep knowledge of the organization try first to bypass the control framework? Which exceptions have become so routine that no one questions them anymore?

The answers may be uncomfortable. A high performer may be receiving less scrutiny than the role requires. A senior executive may be able to approve a high-risk transaction without meaningful challenge. Employees may see warning signs but hesitate to escalate them. The control environment that a regulator would observe tomorrow may be different from the one management believes exists today.

This is where independent challenge becomes essential. An experienced and independent compliance adviser can assess how controls operate in practice, test assumptions that internal teams may no longer recognize, and identify gaps that familiarity can obscure. Guidepost Solutions helps organizations bring that independent perspective to complex control environments. This outside perspective helps leadership move beyond confidence to evidence—confirming that safeguards are effective, exceptions are understood, and concerns can be raised before they become crises.

Barings Bank demonstrates the consequences of a control environment left unchallenged. The better course is to find your institution’s version of Account 88888 while there is still time to address it. Independent compliance expertise provides the objectivity, rigor and practical insight needed to do exactly that, and to give management, boards, and regulators greater confidence that the controls on paper are the controls operating every day.

MSU Institutional Assessment + RA
MAGELLAN Monitorship
Empire/Liberty Review