Who Owns the Insider Threat? The Executive Does
29 September 2026
The numbers do not explain themselves
At the IAFCI Symposium in Sydney on 29 September, I presented a session titled ‘The Numbers Don’t Lie — Or Do They?’ It dealt with one of the most persistent problems in financial and misconduct investigations: proving intent. A transaction record can be precise. It can show that money moved, when it moved, where it went and who had access to the account. That evidence matters. But the transaction does not, by itself, explain why a person made the decision behind it.
That distinction is important because an investigation can establish a sequence of events without establishing the state of mind that gave those events meaning. The same payment may be an error, a poorly controlled exception, an undisclosed conflict, a deliberate misuse of authority or part of a wider criminal arrangement. The number is real in every version. The investigative task is to determine which explanation is supported by the evidence.
Intent is usually established through context. Communications may show what was discussed before and after a transaction. Timing may connect an action to a warning, approval, opportunity or personal benefit. Concealment, false explanations and departures from process may demonstrate knowledge that the conduct was wrong. A person’s role and experience may show what they knew or were expected to know. Repeated patterns and corroborating conduct can distinguish a mistake from a deliberate course of action.
None of that diminishes transactional evidence. It makes it useful. The numbers provide the architecture of the case; the surrounding evidence connects them to the human decision. Good investigations test competing explanations rather than assuming that an unusual transaction proves dishonesty. They also avoid the opposite mistake: accepting an innocent explanation without checking whether it is consistent with the records, communications, conduct and benefits involved.
The insider threat has changed
I also joined the symposium’s Insider Threats panel. The discussion considered how criminal groups have evolved. Organisations have invested heavily in perimeter controls designed to stop attacks from outside. Criminal groups have adapted by looking for ways to obtain legitimate access from inside. That can involve recruiting a willing participant, cultivating a relationship over time, exploiting financial or personal pressure, or coercing someone who already holds a trusted position.
An insider does not need to control an entire system. A person may only need enough access to disclose information, bypass one control, introduce a criminal associate, approve an exception or explain how an organisation detects suspicious activity. Small acts can be valuable when they reveal where scrutiny is weak or allow apparently legitimate activity to pass through ordinary processes.
This is not a reason to treat employees as suspects. Most people act honestly and want their organisation to succeed. A response built on indiscriminate suspicion damages trust and can make people less willing to report concerns. The better approach is to understand where access, discretion and pressure combine, then design proportionate safeguards around those points.
Who should own the risk?
An audience member asked who should be responsible for dealing with the insider threat: Legal, Governance, HR or Investigations? My answer was the executive.
Each specialist function has an essential role. Legal identifies obligations and advises on lawful responses. Governance establishes oversight and accountability. HR manages employment processes, workplace behaviour and support. Security protects people, information and systems. Investigations establishes facts fairly and independently. None of those functions, however, controls the organisation as a whole.
Executives own the culture, risk appetite, operating model, resources and controls. They decide how authority is delegated, which risks are tolerated, whether control failures are funded and fixed, and what happens when commercial pressure conflicts with integrity. If insider risk is assigned to one specialist function, the organisation creates gaps at the boundaries. HR may see a behavioural concern without the transaction data. Security may see unusual access without knowing the employee’s role has changed. Investigations may identify a control weakness after an incident without having the authority to redesign the process.
Executive ownership does not mean executives conduct every assessment or investigation. It means they are accountable for ensuring the parts work together, information can move lawfully between them, decisions are made at the right level and identified weaknesses are addressed rather than passed from one function to another.
What executive ownership looks like in practice
Executives should understand where access and discretion are concentrated. That includes people who can approve payments, alter customer or supplier records, override controls, access sensitive intelligence, appoint intermediaries or operate with limited supervision. The question is not simply who has system access, but who can make consequential decisions without timely review.
They should set clear expectations that concerns are raised early and taken seriously. Speak-up arrangements need credible protections for reporters, practical escalation pathways and consequences for retaliation. Reporting is weakened when staff believe a concern will be redirected to the very area implicated in it, or quietly closed because the person involved is commercially important.
Preventive and detective controls should be designed together. Segregation of duties, access reviews and approval limits can reduce opportunity. Monitoring, exception reporting and targeted assurance can identify activity that has escaped those controls. Indicators should be assessed in context and used to prompt proportionate inquiry, not to label an employee as dishonest.
Triage and investigation must be sufficiently independent. The organisation needs a clear way to decide who assesses an allegation, who manages conflicts, when external expertise is required and how evidence is protected. It should also test whether controls work in practice, not merely whether a policy exists. After an incident, executives should require lessons: what made the conduct possible, which signals were missed, whether reporting worked and who is accountable for remediation.
The central point is straightforward. Insider threat is not owned by the function that first detects it. It is an enterprise risk created by the way authority, access, incentives and oversight are designed. Specialist teams manage important parts of the response. The executive owns whether the system is capable of preventing, detecting and responding to the threat.
Continue the conversation
I speak with conferences, boards and leadership teams about investigations, organised crime, financial crime and institutional integrity. The purpose is not to create alarm. It is to help decision-makers understand how misconduct develops, what the evidence can establish and where executive responsibility begins. For formal advisory support, Integrity Solve works with organisations on integrity, investigations and risk.