Threats from inside.
WHY IT MATTERS
People with legitimate access can move money, and they know the controls.
WHAT THE FORMS ARE
Direct misappropriation Unauthorised adjustments Data theft for sale or fraud Collusion with external parties Negligence causing loss
WHAT ENABLES IT
Excessive access Absence of separation between initiation and approval Unmonitored privileged actions Manual adjustment capability No independent reconciliation
WHAT CONTROLS ADDRESS IT
Least privilege, reviewed regularly Separation of duties on every money movement Approval thresholds Complete logging of privileged actions Reconciliation performed by someone not operating the system
WHAT TO MONITOR
Adjustments by operator Access outside working hours Bulk data access Repeated access to specific accounts
WHAT TO DO AT OFFBOARDING
Revoke immediately, and review recent activity.
WHY THE REVIEW
Departure is a common trigger.
WHAT TO AVOID
Shared accounts Credentials known to several people Production access as routine
WHAT TO PROVIDE INSTEAD
Tooling performing necessary tasks, with logging, rather than direct access.
WHAT TO ESTABLISH
That no single person can move money alone.