And IT has time to check alarms, very unrealistic.
The first thing I do with credentials is find out what they open. Seems like if you have the resources to follow up on access attempts, you have the resources to set ACLs correctly so you’re not scared of them.
The security of banks is certainly not in their IT departments.