The question nobody thought to ask
In the physical world, nobody would ask an employee that question. The answer is obvious — the organisation makes the keys, not the people who use them.
In the digital world, we forgot to ask. So every employee, contractor, and vendor answered for themselves. Millions of keys, made by millions of hands, for systems nobody fully controls.
The moment you ask who is making the keys, the answer to the security problem becomes obvious.