For the night-shift reenactment, Aisha imposed one rule before anyone touched a keyboard: no historical journal file would be run in production.
Wekesa prepared a sandbox with masked sample data. Finance control, IT security and internal audit observed.
“We begin with a normal night,” he said.
Real customer-style repayments, ordinary reserve movements, reversals and treasury top-ups reconciled cleanly.
Then Wekesa opened the shared folder used for emergency journal files.
“Who can write here?” the auditor asked.
“An executive-operations service account.”
“Who approves?”
“Maker-checker. Treasury plus executive ops under normal conditions.”
They loaded a synthetic file with the same structure as Mama Atieno's disputed batch.
The system generated borrower repayment entries from reserve allocations.
“That can be by design,” Njeri said.
“Yes,” Aisha replied. “The question is approval and classification.”
They moved to the real historical log.
The emergency file arrived at 2:09.
Checker request at 2:11.
Executive override at 2:13.
That was the exact timestamp of Mama Atieno's “repayment.”
“So there was no customer action at 2:13,” the auditor said.
“Not in this case. The source was a reserve journal.”
They tested the path a second time with a different operator. It behaved the same. Then they changed one variable at a time.
With a modern closure code, the historical identity did not reactivate.
With the reserve journal classified only as treasury movement, the repayment KPI did not rise.
The chain required multiple shortcuts.
They also tested a legitimate emergency-override scenario. The policy did permit an executive to bypass a checker when customer funds faced immediate risk—but it required a reason code, incident link and later review.
Mama Atieno's batch had no reason code and no incident ticket.
Wekesa admitted the deeper operational weakness.
“When a file comes from upstairs at two in the morning, the junior operator runs it.”
“Could you refuse safely?” the auditor asked.
No one gave a convincing answer.
So the new second-approver request included a protected escalation route. The control could not depend on a junior employee becoming brave enough to fight an executive every night.
IT security reviewed Victor Odede's credential use. The managed device and MFA token matched his account. Again, Aisha recorded the limit: evidence consistent with use of Victor's credential, not a camera proving who touched the keyboard.
Wekesa saved the sandbox configuration, code version and logs so the reenactment could be repeated later.
Then he submitted a policy change: disputed customer-impacting journals required a second approver outside the commercial KPI chain.
“If they reject it?” Aisha asked.
“The rejection becomes part of the record.”
For the first time, the person who once treated an executive file as an instruction was choosing process ownership instead.
The batch history remained visible on the screen.
The auditor saved not only the reenactment output but the sandbox configuration, code version and source files. A demonstration that could not be repeated later would become another memory contest. Wekesa also documented the operator culture around the shared folder: files arriving from executive operations were routinely treated as instructions, even when the policy technically allowed questions. Internal audit separated that cultural weakness from the software defect. Aisha wanted both in the record. Fixing the code while leaving junior operators afraid to stop an unexplained customer-impacting journal would preserve the same risk under a cleaner interface.
Internal audit also traced who had permission to alter the shared-folder workflow itself. Victor's role could approve emergency journals, but changing the maker-checker configuration required an IT-controlled release. That distinction limited the theory: the evidence did not show Victor had personally created the identity bug or designed the reserve engine. It showed his credential used an existing pathway at the moment the disputed batch needed performance support. Aisha insisted the final review keep those levels separate. A person can exploit a weak system without having built every weakness, and a weak system can exist before anyone chooses to exploit it.
At the center of it, the approval credential associated with Victor Odede sat on the event that ran at 2:13.