>IMO this is more of a "don't ask don't tell" thing.I assure you isn't. If your company (in the law abiding west) has any suspicion you're using another company's illegally obtained proprietary IP, they won't see you as some hero doing God's work and put you on the promotion track wile closing a blind eye to what you're doing, but they immediately ask you to delete everything and every trace related to that.
Foreign IP is radioactive and they don't want to get sued because you're bringing some source code and PDFs from their competitor, which might not even be that useful for them anyway.
There were even cases of companies ratting out their employees they found using IP they stolen from their previous employers and getting them arrested, because if you stole IP from their competitor what's stopping you from also stealing from them?
>not audit the new employee's dev environment
Audit how? Against what? Stolen foreign source code you don't have? That's just not realistically possible to audit every employees work and accurately determine if they are or not reusing source code they stolen form a competitor, especially if the employee doing this is careful to change or redact what he's checking in.
Only thing you can audit is against FOSS code that is public, but not if it's stolen proprietary code and the employee made sure to not check-in anything giving away the origin of the original IP holder. They didn't catch this guy until he got sloppy and made this huge blunder.
You can never secure everything and audit everyone, especially if you want people to get any work done and not feel violated, so everything boils down to trusting employees they won't steal from you, and trusting the legal framework and law enforcement they'll do their job when in need, so you just have everyone sign NDAs and hope for the best.