What I find astonishing is that these machines have working USB ports at all. And even if there are some external media connections like DVD burner or USB, wouldn't it make sense to at least hardwire them to some tamper-resistant logging device that protocols who used them at which time?
You have to trust your employees at some point. If he was writing code he also could have written back doors to access and download it from somewhere else.