The only thing I wonder about here is how it's possible that the infosec/GRC team didn't notice this.
This sort of fraud is quite common in white collar crime
Good infosec teams keep inventory of all the software used in the org. If they see that the org already pays a vendor for software doing X, a question should be raised, why we need another one for doing the same thing.
Also, each new vendor or software provider needs go get a "security clearance", after the infosec teams checks their state of security.
These kinds of practices would probably discover the shady intents.