A financial services company is implementing a unified audit policy named `FIN_AUDIT_POLICY` to monitor all `SELECT`, `INSERT`, and `UPDATE` operations on the `CUSTOMERS` table. After enabling the policy, the security officer notices that actions performed by the `SYS` user are not being captured. What must be done to ensure `SYS` user actions are also audited by this policy?