Joiners, Movers and Leaver processes not effective. A manager could have triggered the process informing HR of the resignation or dismissal of the employee. HR will confirm and inform IT to disable or remove such accounts. Compliance thus require audit trail so disabling the account will be sufficient.
Oh hang on... there was a backdoor right? Is this through external email access or some kind of secured tunnel. Hmm, nothing new here..Oh well, erm, they the organisation may still be compliant with a number of regulations yet these sort of things still happens.
/me ducks again