Yeah, obviously my answer assumes that "legal" is an actual well-defined category; but since the original question seemed to as well, and in this case there was an actual simple answer within that framework that didn't require dissolution of the question, I figured it was OK. :)
A recent post by Bruce Schneier on control fraud.
Can the same approaches used to build FAI be used to improve other types of systems?