Fraud at 36,000 Feet
When false legitimacy enters a regulated system

Calvert Steele Jr., CAMS
9 min
“Sometimes fraud does not sound like fraud. Sometimes it sounds like a calm voice over the intercom, welcoming you aboard.”
— Risk Ready Intelligence
At 36,000 feet, trust is not abstract.
It sits in the cockpit. It moves through checklists, credentials, uniforms, schedules, training records, and the quiet confidence passengers place in systems they will never personally inspect.
Most people do not board an aircraft thinking about licensing controls. They do not wonder whether every document behind the person at the front of the plane has been independently verified, refreshed, challenged, and reconciled. They assume the system has already done that work.
For thousands of passengers across more than 900 flights, alleged fraud may not have sounded like a forged document or a failed control. It may have sounded like something far more ordinary: "Ladies and gentlemen, welcome aboard Air Canada. The weather is currently…"
False legitimacy does not always enter a system by appearing suspicious. Sometimes it enters by sounding familiar enough to be trusted.
— Risk Ready Intelligence

Canadian authorities have charged former Air Canada captain Geoffrey Wall after alleging he operated more than 900 domestic and international flights between 2009 and 2025 without holding the Airline Transport Pilot License required for the captain role. Air Canada has said Wall held a valid commercial pilot license and completed recurrent training, but did not hold the license required to serve as captain. The issue reportedly surfaced after documentation anomalies were identified during a routine check, after which Air Canada removed him from duty and reported the matter to Transport Canada.
The headline version of this story is easy to misunderstand.
This was not simply the story of someone with no aviation background walking into a cockpit. That would be dramatic, but it would also be too simple.
Partial Legitimacy Mistaken for Full Authority
The deeper institutional lesson is more uncomfortable.
According to the reporting, Wall had enough legitimacy to be inside the system. He was not outside the gate trying to force entry. He reportedly had a commercial pilot license, had been employed by Air Canada, and had moved through the routines, training, and operational rhythms of a regulated environment. The alleged failure was not a total absence of legitimacy. It was partial legitimacy being mistaken for full authority.
That distinction matters.
In regulated systems, risk often hides in the space between what is present and what is required. A person may have a role, but not the required authorization. A vendor may have access, but not the right oversight. A customer may have documentation, but not a credible source of funds. A transaction may follow expected behavior, but still carry hidden exposure.
False legitimacy is dangerous because it gives controls something familiar to look at.
A uniform can quiet doubt. A title can reduce scrutiny. A long tenure can create comfort. A system history can become a substitute for current validation. Once someone has been accepted long enough, the institution may begin to treat their presence as evidence that verification already happened.
Not Only an Aviation Problem
That is not only an aviation problem.
Banks understand this risk well, even when it appears in different clothing. Financial crime rarely announces itself as financial crime. It enters through account openings, business relationships, payment flows, vendor arrangements, trusted employees, recurring customers, and counterparties that appear normal enough to avoid deeper review.
The danger is not always the obvious red flag. Sometimes the danger is the absence of friction.
- —John, who has banked with the institution for fifteen years.
- —The family-owned company your grandfather trusted, now submitting documents that appear complete.
- —Penny, whose system access has never been questioned because she has always been reliable.
- —The vendor whose contract renews every year without anyone revisiting the original risk decision.
- —The payment pattern that has become so familiar no one remembers when it was last challenged.
In each case, the institution may confuse continuity with confirmation.

That is how judgment weakens. Not all at once, and not because people stop caring. It weakens when systems train people to trust the last approved state more than the present risk condition.
Competency Is Not the Same as Authorization
The Air Canada case is especially instructive because the airline has emphasized that safety was not compromised, pointing to recurrent training and regular competency checks. That matters. Competency and credentialing are related, but they are not the same control. A person may demonstrate operational ability while still lacking the legal or regulatory authority required for the role.
That is where governance becomes important.
A system can validate performance and still miss authorization. It can test capability and still fail to reconcile documentation. It can observe someone doing the work and still miss whether that person has the full permission to do it.
In financial crime compliance, this is the difference between activity that appears normal and activity that has been properly understood.
- —The account is active, but who controls it?
- —The business is registered, but who benefits from it?
- —The payment is routine, but what purpose does it serve?
- —The employee has access, but does the access still match the role?
- —The vendor is approved, but when was that approval last challenged?
The question is not whether something looks legitimate. The question is whether legitimacy has been independently tested.
— Risk Ready Intelligence
When False Legitimacy Becomes Easy to Manufacture
This becomes more urgent in an era where false legitimacy is becoming easier to manufacture. Artificial intelligence can make voices sound familiar, documents appear polished, websites look official, and communications feel routine. But AI is only accelerating a problem that already existed. Institutions have always been vulnerable when they rely too heavily on appearance, continuity, and assumed trust.
The future of fraud will not always look like intrusion. It may look like authorization. It may carry the right tone, the right format, the right logo, the right language, and the right institutional rhythm.
That is why controls must be designed not only to detect suspicious behavior, but to challenge familiar behavior.
Living Inside Assumptions
The lesson from 36,000 feet is not that every system is broken. It is that regulated systems cannot afford to let routine become proof.
Passengers do not inspect the cockpit. Customers do not inspect the bank's control environment. Patients do not inspect hospital credentialing. Investors do not inspect every governance process behind an institution's public confidence.
They live inside assumptions.
They trust that someone else has checked.
That is the burden institutions carry. Not simply to appear safe, but to keep proving that the foundations of trust are still intact.
Because sometimes fraud does not sound like fraud.
Sometimes it sounds like a calm voice over the intercom, welcoming you aboard.

Calvert Steele Jr., CAMS
Founder, Risk Ready
Financial crime and institutional risk professional focused on governance, judgment, and emerging threat environments.
Learn moreSources
Related Briefings
When Cybersecurity Becomes Geopolitics
The struggle for power has moved into the systems beneath daily life. It lives inside the models that shape information, the clouds that carry institutions, the chips that power intelligence, and the invisible code that determines what people see and trust.
FraudWhen Small Bribes Open Large Doors
Sometimes the threat is not on the other side of the transaction. It is closer than anyone wants to admit. A recent TD Bank insider case shows how little money may be required to bend the right access point inside a financial institution.