A subject holds an undisclosed financial interest in an organization, individual, transaction, investment, asset, or commercial outcome affected by their organizational responsibilities. The interest may include company ownership, shares, debt, commission, referral payments, profit-sharing arrangements, creditor relationships, beneficial ownership, or another financial position through which the subject may gain or avoid loss. The interest may be held directly or indirectly through a family member, associate, trust, company, or other intermediary. The conflict becomes operationally significant where the subject can influence procurement, supplier selection, pricing, investment decisions, contract awards, customer treatment, regulatory review, access permissions, or the handling of confidential information. The subject may favor a connected entity, suppress unfavorable information, disclose commercially useful material, or manipulate a decision while presenting their actions as ordinary professional judgment. Investigators should identify the financial relationship, determine when it began, establish whether disclosure was required, and compare the subject’s decisions with objective organizational criteria. Evidence may include corporate ownership records, declared-interest registers, procurement records, payment data, communications, approval history, and repeated decisions benefiting the same external entity.
Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active.
Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active....
Organizations should maintain a formal policy requiring subjects to disclose actual, potential, or perceived conflicts between their personal, financial, professional, or external business interests and their organizational responsibilities. Disclosures should be required when a conflict arises and through periodic attestations. They should be reviewed by an authorized function such as Human Resources, Legal, Compliance, or Ethics, with the outcome and any management measures formally recorded. Controls may include recusal, independent approval, reassignment, segregation of duties, access restrictions, or removal from the affected activity. Subjects should not participate in relevant decisions while a material conflict remains undisclosed or unresolved. The policy should define consequences for deliberate non-disclosure, false declarations, failure to follow an agreed management plan, and retaliation against individuals who report suspected conflicts.
Organizations should maintain a formal policy requiring subjects to disclose actual, potential, or perceived conflicts between their personal, financial, professional, or external business interests a...
An individual’s prior employment history may be verified through formal reference checks conducted prior to their onboarding with the organization. This process aims to validate key aspects of the subject’s professional background, including dates of employment, job titles, responsibilities, and performance, as well as behavioral or conduct-related concerns. Reference checks serve as a critical layer in assessing an individual’s suitability for a given role, particularly where access to sensitive systems, data, or personnel is involved. When conducted thoroughly, this process can help identify discrepancies in a candidate’s reported history, uncover patterns of misconduct, or reveal concerns related to trustworthiness, reliability, or alignment with organizational values. Employment reference checks are particularly relevant to insider threat prevention when evaluating candidates for positions involving privileged access, managerial authority, or handling of confidential information. These checks may also uncover warning signs such as unexplained departures, disciplinary actions, or documented integrity issues that elevate the risk profile of the individual. Organizations may perform this function internally or engage trusted third-party screening providers who specialize in pre-employment due diligence. When combined with other vetting measures—such as criminal background checks and social media screening—reference checks contribute to a layered approach to workforce risk management and help mitigate the likelihood of malicious insiders gaining access through misrepresentation or concealment.
An individual’s prior employment history may be verified through formal reference checks conducted prior to their onboarding with the organization. This process aims to validate key aspects of the sub...
The financial approval process is a structured procedure used by organizations to review and authorize financial transactions. It includes segregation of duties, authorization levels, and documentation and audit trails to prevent financial abuse and ensure adherence to policies and budgets.
The financial approval process is a structured procedure used by organizations to review and authorize financial transactions. It includes segregation of duties, authorization levels, and documentatio...
The process for having software installed on a corporate endpoint by IT should require approval from the employee's line manager to ensure the request is legitimate and appropriate.
The process for having software installed on a corporate endpoint by IT should require approval from the employee's line manager to ensure the request is legitimate and appropriate....
Multi-party approval enforcement requires that designated high-risk or sensitive actions undergo validation by two or more independent approvers before execution. This control ensures that no single subject can unilaterally authorize actions that carry elevated operational, financial, or security impact. Sensitive actions should be clearly defined and may include privilege elevation, financial transactions above defined thresholds, production changes, access to restricted data, or policy exceptions. Approval must be enforced at the system level, preventing execution unless all required approvals are obtained. To maintain effectiveness, approvers must be independent of the requesting subject, with separation enforced through role design, reporting lines, or system constraints. Approval chains should not be user-selectable where possible, and must be resistant to manipulation or bypass. This control directly mitigates behaviors associated with oversight degradation by introducing mandatory independent validation, reducing the likelihood that actions can proceed without scrutiny or through unilateral influence.
Multi-party approval enforcement requires that designated high-risk or sensitive actions undergo validation by two or more independent approvers before execution. This control ensures that no single s...
An agent capable of User Activity Monitoring (UAM) is a software agent installed on organization endpoints (such as laptops); typically, User Activity Monitoring agents are only deployed on endpoints where a human user Is expected to conduct the activity. The User Activity Monitoring agent will typically record Operating System, application, and network activity occurring on an endpoint, with a focus on activity that is or can be conducted by a human user. The purpose of this monitoring is to identify undesirable and/or malicious activity being conducted by a human user (in this context, an Insider Threat). Typical User Activity Monitoring platforms operate in an agent/server model where activity logs are sent to a server for automatic correlation against a rule set. This rule set is used to surface activity that may represent Insider Threat related activity such as capturing screenshots, copying data, compressing files or installing risky software. Other platforms providing related functionality are frequently referred to as User Behaviour Analytics (UBA) platforms.
System logs
An agent capable of User Behaviour Analytics (UBA) is a software agent installed on organizational endpoints (such as laptops). Typically, User Activity Monitoring agents are only deployed on endpoints where a human user is expected to conduct the activity. The User Behaviour Analytics agent will typically record Operating System, application, and network activity occurring on an endpoint, focusing on activity that is or can be conducted by a human user. Typically, User Behaviour Analytics platforms operate in an agent/server model where activity logs are sent to a server for automatic analysis. In the case of User Behaviour Analytics, this analysis will typically be conducted against a baseline that has previously been established. A User Behaviour Analytic platform will typically conduct a period of ‘baselining’ when the platform is first installed. This baselining period establishes the normal behavior parameters for an organization’s users, which are used to train a Machine Learning (ML) model. This ML model can then be later used to automatically identify activity that is predicted to be an anomaly, which is hoped to surface user behavior that is undesirable, risky, or malicious. Other platforms providing related functionality are frequently referred to as User Activity Monitoring (UAM) platforms.
System logs
This detection leverages structured financial auditing processes to identify potential infringement involving misuse, manipulation, or misrepresentation of organizational financial resources by a subject. It focuses on the systematic review and correlation of financial records, transactional data, and approval workflows to surface inconsistencies that may indicate deliberate or negligent misconduct. Financial auditing enables the identification of behaviors such as misuse of corporate cards, submission or approval of fictitious or inflated invoices, and manipulation of commission or revenue reporting to generate unearned financial benefit. This detection may be conducted internally by dedicated finance, audit, or insider threat functions, or externally through independent third-party auditors engaged to provide objective assessment and assurance. The use of external auditing can strengthen investigative defensibility, reduce internal bias, and introduce specialized forensic accounting capabilities in complex or high-risk cases. The detection is both retrospective and continuous in nature. It relies on periodic audits, exception reporting, and data reconciliation across finance systems (e.g., expense platforms, accounts payable, payroll, and sales commission systems) to identify deviations from expected financial controls and policy baselines.
Multiple sources
Provide a process for all staff members to report concerning and/or suspicious behaviour to the organization's security team for review. An internal whistleblowing process should take into consideration the privacy of the reporter and the subject(s) of the report, with specific regard to safeguarding against reprisals against reporters.
Multiple sources
This technique is part of the Forscie® Insider Threat Matrix™. Copyright 2026 Forscie® Limited. Licensed under Apache License 2.0.
View on Forscie® Insider Threat Matrix™