DataVisuals The decision governance company Score your institution

Employee fraud at two banks points to a foundational failure in access governance: the decision to grant system privileges was never documented as a formal decision artifact with a named approver and business justification. Without structured re-certification records that force periodic review of who has access and why, insider activity goes undetected until the damage is visible. The enforcement actions confirm that access control is not an IT task—it is a governance decision that demands the same rigor as credit approval or model validation, with owner, rationale, evidence, and scheduled outcome review produced at the moment of the grant.

From the FED release

Federal Reserve Board issues enforcement actions with former employee of East Cambridge Savings Bank and former employee of United Bank

Read the original FED release →

Get these in your inbox.

The weekly executive summary — regulator actions scored for decision-governance relevance. Or follow daily via RSS.

Free. Only when there's activity — quiet weeks, no email.

← Back to all Watch items