In January 2008, Société Générale disclosed a loss of about €4.9 billion from unwinding unauthorized positions taken by a single trader, Jérôme Kerviel. He did not hack the bank’s systems. He used them. Before he was a trader, Kerviel worked in the middle office. He knew the reconciliation processes and how the control systems operated. He concealed his positions behind fictitious offsetting trades. For people who run enterprise IT, the offsetting trades are where the story gets specific.

A fictitious offsetting trade is not an exotic financial instrument. It is a standard IT pattern. The mechanism is always the same: create a second object that cancels the first, so the control sees zero. The control was designed to detect the first object, not the pair. In enterprise IT, this takes the shape of a fake change record that closes a problem ticket without fixing the underlying issue. It is a test transaction in production that balances the nightly batch. It is a manual journal entry that makes the reconciliation tie. The system looks at the ledger, sees a net-zero profile, and moves on. The reconciliation tied. That was the problem.

Segregation of duties matrices assume the person subject to the control does not know how the control samples, when it runs, who reviews it, and what the reviewer actually looks at. Kerviel knew all four because he used to administer the process. When a person moves from a control function to an operational function, they bring a complete mental map of the control architecture. They know the batch job runs at 02:00 and auto-clears exceptions under a certain threshold. They know which transaction flags require a second signature and which fall under the automated limit. They structure their activity to stay just below the threshold or populate the exact dummy data required to bypass the hold. The access system does not capture this knowledge. The risk register does not capture it either.

Enterprise IT treats internal mobility as a human resources function. An employee transfers from clearing to trading, or from infrastructure support to product development. The onboarding ticket opens, new hardware is provisioned, and new access groups are assigned. What gets left behind is the memory of the old role, both in the employee’s head and in the directory service. Roles in enterprise systems are typically additive. When human resources updates a job title, the provisioning system adds the new access groups. It rarely triggers a mandatory review and deletion of the old ones. The user becomes a composite of every job they have ever held at the institution. A senior engineer moves to a new product group but keeps root access to the legacy servers because the infrastructure team is understaffed and needs them to troubleshoot. Three years later, the access remains.

This accumulation is masked by the quarterly access review. Every access review in a large institution has a completion rate above 95 percent and a revocation rate below 1 percent. Both numbers are true. Only one of them is a control. The manager who approves 400 entitlements in a batch at 23:00 on the deadline day is not reviewing access. They are clearing a queue. The auditor samples 25 approvals, sees they are signed, and checks the box. The control is marked effective because the queue is cleared. If the revocation rate is under 5 percent, the review is theater. Identity and access management must be subtractive, not just additive.

The other half of the failure is the unmonitored queue. A daily reconciliation batch job fails to match a set of synthetic trades. The system behaves exactly as designed. It generates an exception report and routes it to the operations support queue. The queue currently has 14,000 unassigned tickets. The exception report is automatically archived after thirty days. An alert that fires and is not triaged is a log entry. The SIEM, the reconciliation exception report, the segregation of duties conflict report—these produce output. The control is the follow-up. The follow-up is where the budget, the headcount, and the accountability live. If a system generates hundreds of false positives a day, it trains the operations team to click acknowledge without looking. An alert without a triage SLA is a log entry with better formatting. You cannot audit your way out of a control that nobody follows up on.

Controls often compare records generated inside the same workflow. Those comparisons catch mistakes, but a fabricated offset can make internal records agree. A matching entry is not the same thing as an independent confirmation. A stronger check asks for evidence from a separate process or counterparty, with a clear path when that evidence is absent. If your reconciliation matches on a single key and not on the relationship between objects, the pair is invisible.

The person who designed the control and the person who operates it should not be the same person. The person who operated it and the person subject to it should not be the same person either. When an employee moves from a control function to an operational function, the access system records the new entitlements. It does not record the knowledge they bring with them.