Banks have dealt with these issues for many years, obviously over concerns about diverting assests and disguntled employees impacting service. As businesses have become more dependant on IT the issue has become bigger and crossed business lines. But the solution, albeit difficult, is to ensure that there is an audit trail of any changes of significance, and that before any change can be made it requires review and approval of someone else in authority. This does not prevent people from working in cahoots to profit or create havoc. But it does make it a little harder (now you need a conspiracy) and it also makes it easier to trace back to the guilty party.