· KLEPTIK.COMGlobal Corruption Investigative Reporting Project (GCIRP)
Join
← BACK TO FILES
◆ EXCLUSIVEMONEY TRAIL / BANK INTEGRITY / COMPLIANCE FAILURESOPEN FILEunited-statesglobalExclusive

WHEN THE BANK BECOMES THE LAUNDERING RISK

TD Bank was supposed to detect suspicious money. U.S. authorities said its systems instead left trillions of dollars largely unmonitored while criminal networks moved hundreds of millions through the institution.
On 10 October 2024, TD Bank, N.A., then the tenth-largest bank in the United States, pleaded guilty in federal court to conspiring to violate the Bank Secrecy Act, fail to file accurate Currency Transaction Reports and launder money.
CLASSIFICATION Money Laundering • Banking • AML • Bank Secrecy Act • Insider Risk • Transaction Monitoring • Compliance Governance
PUBLISHED 10/10/20248 min · 5 sources · SCOOP 80
WHEN THE BANK BECOMES THE LAUNDERING RISK
▚ KEY FINDINGS
  • Its parent, TD Bank US Holding Company, simultaneously pleaded guilty to related offences.
  • The Justice Department imposed a criminal financial resolution totaling approximately $1.887 billion, including a $1.434 billion criminal fine and approximately $452.4 million in forfeiture.
  • Coordinated civil and regulatory actions brought the total U.S. financial consequences to roughly $3 billion.
  • But the most consequential number was not the penalty.
  • According to DOJ, from 1 January 2018 through 12 April 2024, 92% of TD Bank’s total transaction volume was not automatically monitored by its transaction-monitoring system.

EXECUTIVE FINDING

On 10 October 2024, TD Bank, N.A., then the tenth-largest bank in the United States, pleaded guilty in federal court to conspiring to violate the Bank Secrecy Act, fail to file accurate Currency Transaction Reports and launder money.

Its parent, TD Bank US Holding Company, simultaneously pleaded guilty to related offences.

The Justice Department imposed a criminal financial resolution totaling approximately $1.887 billion, including a $1.434 billion criminal fine and approximately $452.4 million in forfeiture. Coordinated civil and regulatory actions brought the total U.S. financial consequences to roughly $3 billion.

The numbers were historic.

But the most consequential number was not the penalty.

It was:

92%

According to DOJ, from 1 January 2018 through 12 April 2024, 92% of TD Bank’s total transaction volume was not automatically monitored by its transaction-monitoring system.

The amount represented approximately:

$18.3 TRILLION

in transaction activity.

That gap existed because the bank intentionally excluded categories including:

  • domestic ACH payments
  • most check activity
  • and numerous other transaction types

from automated monitoring.

Authorities also said the bank’s monitoring scenarios remained essentially static for years despite warnings from regulators, consultants and its own internal audit function.

This was therefore not simply another case in which clever criminals slipped through sophisticated bank controls.

The central allegation—accepted through the guilty plea—was much more serious.

The institution responsible for identifying illicit money had allowed its own control environment to deteriorate so substantially that criminal networks found the bank particularly convenient to use.

DOJ said three money-laundering networks moved more than $670 million through TD Bank accounts from 2019 through 2023.

One network moved more than $470 million largely through large cash deposits into nominee accounts.

A second moved nearly $120 million through accounts associated with a high-risk jewellery business.

A third involved rapid ATM withdrawals in Colombia and five TD Bank employees who conspired with the network in laundering approximately $39 million.

The central question of this dossier is therefore:

WHAT HAPPENS WHEN THE BANK THAT IS SUPPOSED TO POLICE MONEY LAUNDERING BECOMES THE INFRASTRUCTURE THROUGH WHICH THE LAUNDERING WORKS?

THE FINDING

Anti-money-laundering regulation is built around a basic assumption.

Banks are the financial system’s principal control points.

Customers may lie.

Shell companies may conceal ownership.

Criminals may structure cash.

Fraudsters may disguise payments.

But the bank sits between those actors and the wider financial system.

It possesses:

  • identity information
  • transaction histories
  • deposit records
  • account relationships
  • beneficial-ownership data
  • geographic information
  • counterparties
  • cash records

and potentially years of customer behaviour.

That makes a bank exceptionally well positioned to identify anomalous activity.

It also means that when the bank’s own controls fail, the consequences extend far beyond one institution.

The control point becomes the vulnerability.

THE REVERSAL

The conventional AML model looks like:

The TD Bank case exposed the opposite possibility:

That reversal is what makes the case institutionally significant.

THE BANK

TD BANK, N.A.

TD Bank operated one of the largest retail-banking franchises in the United States.

Its business depended heavily on convenience.

Branches.

Cash services.

Consumer accounts.

Business accounts.

ATM access.

Electronic transfers.

Checks.

Peer-to-peer payments.

The same convenience attractive to legitimate customers can also be attractive to financial criminals.

The question is whether controls grow alongside access.

According to DOJ, they did not.

Between 2014 and 2023, TD Bank had long-standing and systemic deficiencies in its U.S. AML programme and failed to remediate them adequately.

THE FLAT COST PARADIGM

One phrase from the criminal case is particularly important:

“FLAT COST PARADIGM”

DOJ said senior executives operated under a budget mandate requiring that costs remain broadly flat year over year, even while the bank’s profits and risk profile increased.

AML resources were subject to the same pressure.

This turns the case into an economics problem.

If the bank grows:

  • more customers
  • more products
  • more transfers
  • more countries
  • more transaction volume

more digital channels.

Then financial-crime risk also grows.

If the compliance budget remains static while transactional complexity increases, controls inevitably become thinner relative to the business.

COMPLIANCE CAPACITY

A useful ratio is:

COMPLIANCE CAPACITY ÷ BUSINESS COMPLEXITY

If business complexity doubles while compliance capacity stays flat, effective coverage declines.

This is true even if the absolute compliance budget remains large.

The relevant question is not:

How many dollars does the bank spend?

It is:

Is the compliance system proportionate to the activity it must supervise?

PROFIT GROWTH VERSUS CONTROL GROWTH

The DOJ’s theory was that TD Bank prioritised its flat-cost model and customer experience while AML risks expanded.

A responsible control model should look approximately like:

The alternative is:

That is how compliance debt accumulates.

$18.3 TRILLION

The scale of the monitoring gap is difficult to conceptualise.

DOJ said approximately $18.3 trillion in transaction activity went outside TD Bank’s automated monitoring coverage from January 2018 through April 2024.

This does not mean $18.3 trillion was criminal money.

That distinction is essential.

It means the transactions were not automatically subjected to monitoring scenarios within the bank’s principal surveillance system.

Most of the underlying activity was almost certainly legitimate.

The compliance failure was that the system did not evaluate it systematically for patterns associated with suspicious activity.

MONITORING VERSUS CRIMINALITY

Kleptik distinguishes:

  • UNMONITORED
  • from
  • SUSPICIOUS
  • from

CRIMINAL.

They are not interchangeable.

$18.3 trillion unmonitored does not equal $18.3 trillion laundered.

The correct interpretation is:

The bank lacked automated visibility over an enormous portion of transactional activity in which suspicious patterns could potentially have existed.

That is a control problem.

THE 92% BLIND SPOT

The relevant transaction types excluded from automated monitoring included:

domestic ACH;

most checks;

and numerous other transaction categories.

That created an extraordinary contradiction.

A bank could possess the data.

Yet the principal surveillance engine might not be analysing it.

The activity existed.

The monitoring intelligence did not.

DATA EXISTS ≠ CONTROL EXISTS

A common misconception is that banks “see everything.”

Technically, they may store extensive transactional information.

Operationally, detection depends upon whether that data enters:

  • monitoring scenarios
  • risk models
  • alerts
  • investigations

and reporting systems.

Data sitting inside a database without being analysed is not a control.

It is merely stored information.

THE STATIC MONITORING SYSTEM

DOJ said TD Bank added no new transaction-monitoring scenarios and made no material changes to existing scenarios from at least 2014 through late 2022.

That period saw dramatic evolution in financial crime.

Peer-to-peer payments expanded.

Fraud became more digital.

Fentanyl trafficking grew.

Cybercrime expanded.

Money-mule networks evolved.

New products entered the bank.

Yet the monitoring framework remained essentially static.

This is equivalent to running modern cybersecurity with a rule set last materially updated nearly a decade earlier.

THE SCENARIO PROBLEM

Transaction-monitoring systems rely on scenarios.

Examples:

Large cash activity.

Rapid movement of funds.

Structuring.

High-risk geography.

Dormant-account activation.

Round-dollar wires.

Cash followed by outgoing wire.

Unusual ATM activity.

Multiple accounts sharing identifiers.

Rapid movement through shell entities.

Each scenario searches for a pattern.

If new risks arise but no scenarios are added, the system remains blind to the new behaviour.

FALSE COMFORT FROM AUTOMATION

An automated AML system can create confidence simply because it exists.

Dashboard.

Alerts.

Cases.

Analysts.

Reports.

But the true question is:

WHAT ACTIVITY DOES THE SYSTEM NOT SEE?

The missing data is often more important than the alerts generated from included data.

THE ZELLE PROBLEM

DOJ said TD Bank introduced new products and services, including Zelle, without ensuring appropriate transaction-monitoring coverage.

This illustrates a common institutional failure:

product launches faster than compliance adaptation.

In finance, that sequencing can be dangerous.

COMPLIANCE BY DESIGN

A mature bank should integrate compliance before launch.

Not:

Compliance should be part of product engineering.

THE $5 BILLION AFTER CLOSURE

One of the most striking facts in DOJ’s account concerns accounts the bank had already decided to close.

Authorities said TD Bank permitted more than $5 billion in transactional activity to occur in accounts after the bank had decided to close them.

That reveals the difference between:

risk decision

and

risk execution.

The institution can correctly determine:

“This customer is too risky.”

But if the account remains operational for months, the control has not actually occurred.

EXIT DOES NOT MEAN DECISION

A bank exit has several stages.

If the period between approval and closure is long, risk persists.

For high-risk customers, that period can itself become valuable.

THE CLOSURE-WINDOW PROBLEM

A criminal customer who learns an account will be closed may accelerate activity.

Transfer balances.

Withdraw cash.

Move funds to another institution.

The exit window should therefore be treated as a distinct high-risk phase.

THE FIRST NETWORK: $470 MILLION

DOJ said one laundering network processed more than $470 million through TD Bank between January 2018 and February 2021.

The method was strikingly unsophisticated.

Large quantities of cash were deposited into nominee accounts.

This was not primarily a sophisticated crypto-mixer problem.

It was piles of physical cash moving into bank accounts.

That is what makes the alleged control failure especially significant.

THE NOMINEE ACCOUNT

A nominee account is controlled or used for someone other than the apparent beneficial economic actor.

The structure can look like:

The account name changes.

The economic owner may not.

CASH REMAINS THE ORIGINAL ANONYMITY TECHNOLOGY

Financial crime discussions increasingly focus on:

  • crypto
  • mixers
  • privacy coins

shell companies.

But physical cash retains enormous laundering utility.

It is:

  • portable
  • fungible
  • difficult to attribute

and widely accepted.

The problem appears when large amounts need to enter the banking system.

That is the placement stage.

PLACEMENT

Traditional laundering is often described in three stages:

PLACEMENT

Getting cash into financial system.

LAYERING

Moving it through transactions and entities.

INTEGRATION

Turning it into apparently legitimate wealth.

TD Bank’s branch infrastructure made the placement stage especially relevant.

THE GIFT CARDS

DOJ said operators of the $470 million network provided TD Bank employees with gift cards worth more than $57,000 to ensure transactions continued to be processed.

This reveals another layer:

INSIDER FACILITATION

The financial institution’s controls can be strong.

But an insider with access can help bypass them.

That makes employee integrity an AML control.

EMPLOYEE GIFTS AS CORRUPTION

A gift card may sound trivial compared with hundreds of millions of dollars.

The importance lies in the exchange.

Employee receives economic benefit.

employee continues facilitating activity.

The mechanism resembles public-sector bribery.

Only the institutional setting changes.

THE BANK-EMPLOYEE PEP ANALOGY

Public corruption asks:

What can the official provide?

Bank corruption asks:

What can the employee provide?

Examples:

  • account opening
  • cash processing
  • CTR handling
  • ATM cards
  • override
  • internal information
  • warning about compliance review

delayed closure.

Access itself is valuable.

CTR FAILURES

Banks must file Currency Transaction Reports for qualifying cash transactions, generally involving more than $10,000 in currency in a business day.

DOJ said employees failed in relevant circumstances to correctly identify the person conducting transactions in required reports.

This is more serious than mere paperwork.

CTR information forms part of the government’s financial-intelligence architecture.

Incorrect data degrades that intelligence.

DATA QUALITY IS LAW-ENFORCEMENT CAPACITY

Consider:

$50,000 cash deposit.

Report identifies nominee.

Actual cash conductor omitted.

Law enforcement sees the wrong network node.

The money remains visible.

The person may not.

Thus data quality matters as much as filing volume.

THE SECOND NETWORK: THE JEWELLERY BUSINESS

DOJ said a second network involving a high-risk jewellery business moved nearly $120 million through shell accounts from March 2021 through March 2023 before the bank reported the activity.

Jewellery businesses can present elevated AML risk because they may involve:

  • portable value
  • high-ticket transactions
  • international trading
  • cash
  • commodities

and resale markets.

That does not make jewellery businesses inherently suspicious.

It makes effective risk-based monitoring important.

HIGH-RISK CUSTOMER ≠ CRIMINAL CUSTOMER

The AML designation “high risk” should never be confused with criminality.

A legitimate jewellery business may be high risk because of the nature of its transactions.

High risk means:

more due diligence.

More monitoring.

More understanding.

Not automatic account closure.

The issue in this case was whether known risk was appropriately controlled.

SHELL ACCOUNTS

DOJ described money moving through shell-company accounts.

Shell companies can be entirely legitimate.

Their AML significance comes from the mismatch between:

limited operating substance

and

very large financial activity.

A company with:

  • no employees
  • no inventory
  • no obvious customers
  • minimal operating footprint
  • but
  • $100 million in flows

deserves explanation.

THE THIRD NETWORK: COLOMBIA

The third network operated differently.

Money was deposited in the United States and then rapidly withdrawn using ATMs in Colombia.

DOJ said five TD Bank employees conspired with the network and issued dozens of ATM cards used by the money launderers.

Approximately $39 million was laundered through this architecture.

This is an unusually vivid example of transaction patterns that should appear abnormal.

THE ATM MULTIPLIER

Prosecutors described withdrawals occurring at levels 40 to 50 times higher than the daily limit ordinarily associated with personal accounts.

That raises a basic control question:

HOW CAN A LIMIT EXIST IF THE SYSTEM ALLOWS ACTIVITY 50 TIMES ABOVE IT?

A limit that is routinely overridden without meaningful escalation is not a limit.

It is a recommendation.

THE CROSS-BORDER CASHOUT MODEL

The architecture was:

This allows value to cross borders through the banking network without a traditional international wire.

The ATM network becomes a money-transfer system.

MULTIPLE CARDS

Issuing numerous ATM cards can increase withdrawal capacity.

If one account or network controls many cards, individual transaction limits become less meaningful.

The correct surveillance system should identify:

  • common owner
  • common funding source
  • common device
  • common withdrawal geography

and aggregate limits.

THE AGGREGATION PROBLEM

Financial controls often operate per account.

Criminal networks operate across accounts.

That creates a gap.

Account A withdraws $5,000.

Account B withdraws $5,000.

Account C withdraws $5,000.

Each appears within a limit.

Network total:

$15,000.

The AML system must aggregate economically connected behaviour.

FIVE BANK INSIDERS

DOJ said five TD Bank employees conspired with the Colombia-linked network.

This should change how banks think about AML staffing.

Employees are not merely control operators.

They are also potential attack surfaces.

The institution must monitor:

  • conflicts
  • unusual employee-customer relationships
  • gifts
  • override patterns
  • account-opening patterns

and unusual branch behaviour.

THE INSIDER-THREAT MODEL

A bank insider can provide criminal organisations with something external customers cannot easily obtain:

knowledge of controls.

The employee may know:

  • which transaction triggers alerts
  • which manager asks questions
  • what documents are required
  • how long reviews take
  • how limits can be overridden

when an account is being investigated.

That information itself has value.

EMPLOYEE TRANSACTION ANALYTICS

Banks should therefore analyse employees as part of the control environment.

Questions include:

  • Which employees repeatedly serve high-risk customers?
  • Who overrides alerts?
  • Who issues unusual numbers of cards?
  • Which branches show extreme cash volumes?
  • Who receives customer complaints or gifts?
  • Which employees access accounts without business reason?

Insider-risk analytics can be as important as customer analytics.

“EASY TARGET”

DOJ quoted internal communications in which TD Bank personnel characterised the institution as an “easy target” for the “bad guys.”

This is one of the most important facts in the case.

It suggests awareness inside the bank that weaknesses were not merely theoretical.

Employees understood criminals could exploit them.

Knowledge followed by inaction is qualitatively different from an unknown vulnerability.

THE KNOWLEDGE TEST

For any systemic compliance failure, investigators should reconstruct:

  • When was the risk first identified?
  • Who knew?
  • What was recommended?
  • What was funded?
  • What was postponed?
  • What was cancelled?
  • Why?

The timeline determines whether the institution experienced:

unexpected failure

or

known control debt.

INTERNAL AUDIT

DOJ said both regulators and TD Bank’s own internal-audit function repeatedly identified transaction-monitoring concerns.

That raises a governance question broader than AML.

What is the purpose of internal audit if repeated findings do not produce timely remediation?

An audit finding without consequence becomes historical documentation rather than control.

THE AUDIT LOOP

Healthy governance:

Failed governance:

The second model creates regulatory evidence of knowledge.

BOARD OVERSIGHT

A problem persisting across nearly a decade eventually becomes a board question.

  • What information reached directors?
  • How were AML deficiencies reported?
  • Were remediation budgets challenged?
  • Did the board understand the scale of unmonitored transactions?
  • Were risk metrics linked to executive compensation?
  • Did compliance have direct access to independent directors?

Governance becomes especially important when commercial leadership controls the compliance budget.

WHO OWNS THE AML BUDGET?

If the same executives responsible for cost reduction determine compliance resources, structural conflict can emerge.

A stronger governance model may require:

  • independent compliance reporting
  • board risk committee oversight
  • documented resource assessments

and regulatory escalation where resources are inadequate.

The compliance officer should not be required to negotiate basic legal capability against quarterly profit targets.

THE CUSTOMER-EXPERIENCE CONFLICT

DOJ said TD Bank prioritised the “customer experience” alongside its cost discipline.

This sounds benign.

Banks should provide good service.

But compliance inevitably introduces friction.

Source-of-funds questions.

Transaction holds.

Identification requests.

Account reviews.

Cash scrutiny.

The danger arises when convenience becomes an argument against legal controls.

FRICTION IS SOMETIMES THE PRODUCT

In financial services, good friction protects:

the customer;

the institution;

and the financial system.

A five-minute AML review may be inconvenient.

It can also stop millions in criminal proceeds.

The absence of friction is not always superior service.

THE BANK OF CHOICE

DOJ said TD Bank became the bank of choice for multiple money-laundering organisations and criminal actors.

This phrase describes a phenomenon every institution should fear.

Criminal communities exchange information.

  • Which bank asks fewer questions?
  • Which branch accepts cash?
  • Which employee is helpful?
  • Which institution closes accounts slowly?

Weak controls can therefore create their own customer-acquisition loop.

THE CRIMINAL NETWORK EFFECT

This is the opposite of deterrence.

COMPLIANCE REPUTATION

Banks have reputations among legitimate customers.

They also develop reputations among illicit actors.

A strict institution may be known as difficult.

A weak one may be known as convenient.

That hidden reputation should be treated as a risk indicator.

THE $670 MILLION

The three identified networks collectively moved more than $670 million through TD Bank accounts between 2019 and 2023.

Again, that figure should be interpreted carefully.

It concerns the specific networks identified in the DOJ case.

It does not necessarily represent the complete universe of suspicious activity that passed through the bank during the control failures.

The retrospective review may reveal more.

KNOWN LOSS VERSUS CONTROL EXPOSURE

There are two different numbers:

IDENTIFIED LAUNDERING

More than $670 million connected to the three networks described by DOJ.

CONTROL EXPOSURE

Approximately $18.3 trillion not subjected to automated monitoring.

The second does not represent criminal proceeds.

It represents the size of the surveillance gap.

That distinction should appear prominently in every Kleptik presentation.

FINCEN

The Financial Crimes Enforcement Network imposed a record $1.3 billion penalty against TD Bank for Bank Secrecy Act violations.

FinCEN also required a four-year independent monitorship.

FinCEN’s role is particularly important because the agency receives financial intelligence generated by banks.

If banks fail to detect and report suspicious activity, FinCEN loses visibility.

The problem therefore propagates into the government intelligence system.

THE FINANCIAL-INTELLIGENCE SUPPLY CHAIN

If the bank fails at Step 2, every downstream step may disappear.

A weak AML programme therefore creates an intelligence blackout.

THE OCC

The Office of the Comptroller of the Currency imposed a $450 million civil monetary penalty, a cease-and-desist order and—most unusually—a restriction on TD Bank’s growth.

The growth restriction is particularly important.

Regulators effectively linked the bank’s future commercial expansion to its ability to repair the control environment.

That is stronger than a monetary penalty alone.

GROWTH AS A REGULATORY PRIVILEGE

The OCC action communicates a simple principle:

If controls cannot safely support the existing institution, the institution should not become larger.

The economic sanction is therefore:

YOU CANNOT GROW FASTER THAN YOUR CONTROLS.

That may prove one of the most consequential outcomes of the entire case.

THE PENALTY ARCHITECTURE

The coordinated resolution involved several authorities.

DOJ

Criminal guilty pleas.

Approximately $1.887 billion criminal financial resolution.

FINCEN

Record $1.3 billion BSA penalty and four-year monitorship.

OCC

$450 million penalty, cease-and-desist order and growth restriction.

FEDERAL RESERVE

Separate coordinated action addressing governance and control failures.

The agencies structured credits among overlapping penalties, so headline amounts should not simply be added without examining offsets.

THE CRIMINAL PENALTY

The DOJ resolution consisted of:

  • $1,434,513,478.40 criminal fine
  • plus
  • $452,432,302 forfeiture

for total criminal financial consequences of:

$1,886,945,780.40

The precision is worth preserving in Kleptik’s documentary record.

PARTIAL COOPERATION CREDIT

DOJ said TD Bank did not voluntarily self-disclose the misconduct.

The bank nevertheless received partial credit for cooperation and remediation.

But it did not receive full cooperation credit because it failed to timely escalate relevant AML concerns to DOJ during the investigation.

The final penalty reflected a 20% reduction based on partial cooperation and remediation.

This provides another lesson:

Remediation after discovery can reduce consequences.

It does not erase the underlying failure.

THE MONITOR

Under the DOJ resolution, TD Bank agreed to retain an independent compliance monitor for three years.

FinCEN separately imposed a four-year monitorship framework.

A monitor effectively places an external reviewer inside the remediation process.

The bank must demonstrate that change is real.

WHAT THE MONITOR SHOULD TEST

DATA COVERAGE

Are all material transaction types monitored?

SCENARIOS

Are risks updated dynamically?

STAFFING

Are analyst resources proportionate?

ALERT QUALITY

Are scenarios producing meaningful alerts?

CASE BACKLOGS

Are investigations timely?

SAR QUALITY

Are reports accurate and useful?

EXIT MANAGEMENT

Are high-risk accounts actually closed?

INSIDER RISK

Are employee relationships monitored?

PRODUCT LAUNCHES

Is AML integrated before release?

BOARD GOVERNANCE

Does the board receive credible independent information?

MODEL RISK

Transaction-monitoring systems themselves create model risk.

Too sensitive:

millions of useless alerts.

Too weak:

criminal activity goes undetected.

The solution is continuous tuning.

Data.

Typologies.

Investigator feedback.

Law-enforcement intelligence.

New products.

New geographies.

A monitoring scenario built in 2014 cannot simply remain unchanged because it once worked.

ALERT FATIGUE

Under-resourced compliance teams can generate another failure mode:

too many alerts.

Analysts rush.

Cases close mechanically.

Important signals disappear inside noise.

Thus effective AML requires not merely more monitoring but better monitoring.

HUMAN CAPACITY

Software does not file a meaningful SAR by itself.

Analysts interpret context.

  • Who is the customer?
  • What is normal for the business?
  • Why is the activity strange?
  • What counterparties matter?
  • Could there be a legitimate explanation?

AML remains partly a human intelligence function.

Understaffing therefore directly reduces detection quality.

THE BRANCH PROBLEM

Physical branch networks create unique AML challenges.

A bank teller may see:

  • cash
  • customer behaviour
  • multiple depositors

business activity.

That local knowledge can be extraordinarily valuable.

But only if employees are trained and incentives support escalation.

A branch focused entirely on speed and customer satisfaction may become reluctant to challenge high-value customers.

CASH INTELLIGENCE

Branch staff should ask:

  • Does this business normally generate cash?
  • Why this denomination?
  • Why multiple people depositing?
  • Why different branches?
  • Why nominee accounts?
  • Why repeated amounts just above or below thresholds?

Human observations can complement automated monitoring.

“DO NOT FILE” CULTURE

DOJ said TD Bank instructed stores to stop filing certain internal unusual-transaction reports concerning some suspicious customers.

This fact deserves special attention.

A reporting system is only useful if employees believe reporting is encouraged.

If staff perceive escalation as inconvenient or discouraged, the bank loses its frontline intelligence.

SPEAK-UP CULTURE

A mature bank should reward:

  • escalation
  • questioning
  • challenge

and documentation.

Employees should never believe they will be criticised because suspicious-activity reporting delays a customer.

Culture determines whether controls are used.

THE INSIDER ECONOMY

The $57,000 in gift cards and the separate allegations concerning employees assisting the ATM network show that financial crime can develop an internal market.

Criminal organisation pays insider.

Insider supplies banking access.

The model resembles corruption elsewhere.

Only the commodity changes.

BANK ACCESS AS A COMMODITY

What can a corrupt bank employee sell?

Account access.

Cash acceptance.

ATM capability.

Internal information.

False documentation.

Alert avoidance.

Limit overrides.

Customer verification.

Account survival.

These services may be worth enormous amounts to criminal organisations.

BANK EMPLOYEE DUE DILIGENCE

Institutions conduct due diligence on customers.

High-risk employees may also require:

  • background checks
  • conflict declarations
  • financial disclosure where lawful
  • gift policies
  • mandatory leave
  • job rotation
  • system access monitoring

and lifestyle anomaly investigation where legally permissible.

The insider threat belongs inside AML governance.

THE NATIONAL-SECURITY DIMENSION

FinCEN explicitly linked TD Bank’s failures to risks involving narcotics trafficking, terrorist financing and human trafficking.

This is why BSA compliance is no longer treated merely as technical banking regulation.

Financial intelligence helps governments identify:

  • drug networks
  • sanctions evasion
  • terrorist financing
  • fraud
  • human trafficking

and organised crime.

A surveillance blind spot at a large bank can therefore become a national-security blind spot.

FENTANYL AND MONEY

Drug trafficking requires financial infrastructure.

The narcotics themselves move physically.

The proceeds must eventually:

  • enter banking system
  • pay suppliers
  • purchase assets
  • finance future shipments

or return across borders.

Financial disruption can therefore attack the criminal enterprise after the commodity sale.

That is why banks matter to narcotics enforcement.

MONEY LAUNDERING AS LOGISTICS

Kleptik treats money laundering as the financial equivalent of logistics.

Drug organisation needs:

transport for product.

and

transport for money.

Banks become potential financial transport infrastructure.

The compliance programme is supposed to determine which financial cargo should not move.

TRANSACTION MONITORING IS BORDER SECURITY FOR MONEY

A useful analogy:

Customs asks:

What is inside the container?

AML asks:

What is inside the transaction?

Both rely on:

  • risk assessment
  • intelligence
  • inspection

and escalation.

If 92% of containers bypassed automated risk screening, port authorities would consider it a major security problem.

The same principle applies to financial flows.

THE CUSTOMER JOURNEY

A robust AML investigation should follow a suspicious customer from account opening to exit.

  • ACCOUNT OPENING
  • Who introduced customer?
  • KYC
  • What business was declared?
  • EARLY ACTIVITY
  • Did transactions match expectations?
  • ALERTS
  • What was generated?
  • BRANCH OBSERVATION
  • Did staff raise concerns?
  • INVESTIGATION
  • What conclusion was reached?
  • SAR
  • Was government notified?
  • EXIT DECISION
  • When?
  • ACTUAL CLOSURE
  • How long later?

This timeline identifies control failure precisely.

THE CRIMINAL-CUSTOMER JOURNEY

For each of the three identified networks, Kleptik should reconstruct:

  • first account opened
  • total accounts
  • branches used
  • employees involved
  • cash volume
  • internal alerts
  • CTR history
  • SAR history
  • account-closure decisions

and eventual prosecution.

That is how the institution’s response can be evaluated independently.

THE BANK’S ECONOMIC BENEFIT

A difficult but important question is:

How much revenue did the bank earn from customers subsequently identified as money-laundering networks?

Revenue might include:

  • deposit spread
  • transaction fees
  • wire fees
  • ATM fees
  • account fees

FX income.

The amount may be small relative to the ultimate penalty.

But understanding it reveals the warped economic incentives.

BAD REVENUE

Not all revenue has equal quality.

A dollar earned from a criminal customer’s activity may create:

  • legal liability
  • capital cost
  • monitoring burden
  • reputational damage

and eventual penalty.

Banks should therefore measure:

RISK-ADJUSTED REVENUE

rather than gross customer profitability.

THE TRUE P&L

Revenue from risky customer:

+$1 million.

Compliance avoidance:

+$500,000 saved.

Then:

Legal costs.

Remediation.

Monitor.

Fine.

Forfeiture.

Growth restriction.

Management distraction.

Reputational damage.

The apparent profitable customer can become economically catastrophic.

COMPLIANCE AS CAPITAL PROTECTION

Compliance departments are often viewed as costs.

The TD Bank resolution demonstrates that they protect enterprise value.

The approximately $3 billion coordinated enforcement consequences were dramatically larger than any plausible savings achieved through years of underinvestment.

Compliance is therefore closer to insurance or risk capital than administrative overhead.

THE GROWTH CAP AS ENTERPRISE DAMAGE

The OCC’s growth restriction may be economically more consequential over time than a portion of the cash penalties.

A penalty is paid once.

A growth restriction can affect:

  • deposits
  • loans
  • market share
  • strategy
  • acquisitions

and valuation.

That means control failure can alter corporate strategy itself.

“TOO BIG” DOES NOT MEAN IMMUNE

TD Bank’s size is part of the significance.

It was not a fringe institution.

It was a major national bank.

The prosecution demonstrates the government’s willingness to impose criminal liability on a systemically important financial company even where the institution must continue operating afterward.

CORPORATE CRIMINAL LIABILITY WITHOUT CORPORATE DEATH

Prosecuting a bank creates a challenge.

Government must punish misconduct.

But regulators do not necessarily want to destabilise depositors or the financial system.

The resolution therefore combines:

  • criminal plea
  • financial penalties
  • monitoring
  • remediation
  • growth restriction

and continued operation.

This is corporate punishment designed around financial stability.

CHRONOLOGY

January 2014

DOJ identifies the beginning of a period of long-term and systemic deficiencies in TD Bank’s U.S. AML programme.

2014–2022

The bank adds no new automated transaction-monitoring scenarios and makes no material changes to existing scenarios despite evolving risks and repeated concerns.

January 2018

Period begins during which DOJ later calculates that 92% of transaction volume is outside automated monitoring coverage.

January 2018–February 2021

One laundering network moves more than $470 million through TD Bank, largely using large cash deposits into nominee accounts.

2019–2023

The three money-laundering networks identified in the DOJ resolution collectively move more than $670 million through TD Bank accounts.

March 2021–March 2023

A high-risk jewellery business moves nearly $120 million through shell accounts before the bank reports the activity.

2021–2023

A separate network deposits money in the United States and uses numerous ATM cards for rapid withdrawals in Colombia.

Five TD Bank employees conspire with the network, which launders approximately $39 million.

Late 2022

TD Bank begins materially updating transaction-monitoring scenarios after years of limited change.

October 2023

DOJ identifies the end of the principal charged period concerning systemic AML deficiencies.

12 April 2024

The period used by DOJ to calculate the $18.3 trillion automated-monitoring gap ends.

10 October 2024

TD Bank, N.A. and TD Bank US Holding Company plead guilty to federal criminal charges.

DOJ announces the approximately $1.887 billion criminal resolution.

10 October 2024

FinCEN announces a record $1.3 billion penalty and four-year monitorship.

10 October 2024

OCC announces a $450 million penalty, cease-and-desist order and growth restriction.

As of this dossier’s archive date, the guilty pleas and coordinated regulatory actions are operative.

DOCUMENTARY RECORD

DEPARTMENT OF JUSTICE — 10 OCTOBER 2024

The DOJ criminal resolution is the primary source for:

  • the guilty pleas
  • the flat-cost model
  • transaction-monitoring deficiencies
  • the $18.3 trillion monitoring gap
  • the three laundering networks
  • employee involvement

and criminal penalties.

FINCEN — 10 OCTOBER 2024

FinCEN’s record establishes the $1.3 billion BSA penalty and four-year independent monitorship.

OCC — 10 OCTOBER 2024

The OCC action establishes the $450 million civil penalty, cease-and-desist order and restriction on future bank growth while remediation proceeds.

DOJ CASE RECORD

The case overview specifies that 92% of transaction volume—approximately $18.3 trillion—was excluded from automated monitoring during the identified period and that the three networks moved more than $670 million through the institution.

WHAT THE AUTHORITIES SAY

The Justice Department says TD Bank maintained an AML programme that appeared adequate in certain respects on paper but contained fundamental and widespread flaws.

Authorities say executives prioritised cost control and customer convenience while known transaction-monitoring weaknesses persisted.

DOJ concluded that the deficiencies made TD Bank attractive to criminal actors and allowed multiple laundering networks to move hundreds of millions of dollars through the institution.

FinCEN characterised the failures as historically serious and imposed the largest penalty it had ever levied against a depository institution at the time.

The OCC concluded that TD Bank had persistently prioritised growth over controls and imposed a growth restriction in addition to financial penalties.

WHAT TD BANK ADMITTED

Because TD Bank entered criminal guilty pleas, the core conduct described in the plea agreements occupies a materially different evidentiary position from unresolved allegations against individual customers or employees.

TD Bank, N.A. pleaded guilty to conspiring to:

  • fail to maintain a BSA-compliant AML programme
  • fail to file accurate CTRs
  • and

launder monetary instruments.

Its U.S. holding company pleaded guilty to related charges concerning the AML programme and CTR failures.

Kleptik should therefore describe these corporate offences as admitted conduct.

WHAT THIS DOSSIER DOES NOT ESTABLISH

This dossier does not establish that:

  • 92% of TD Bank’s transactions were suspicious
  • $18.3 trillion was laundered
  • every TD Bank employee participated in misconduct
  • every high-risk jewellery customer was criminal
  • all TD Bank branches were equally deficient
  • every transaction connected to Colombia was suspicious
  • every cash-intensive business using TD Bank engaged in laundering
  • all senior executives personally knew every operational deficiency

or every customer affected by an eventual account closure engaged in wrongdoing.

It also does not equate employee participation in identified criminal schemes with the conduct of the bank’s broader workforce.

The figures must remain properly classified.

$18.3 trillion = unmonitored transaction volume.

$670+ million = identified movement associated with the three networks described by DOJ.

They are not interchangeable.

RIGHT OF REPLY

Before publication, Kleptik should seek comment from:

TD Bank, N.A.

TD Bank US Holding Company

The Toronto-Dominion Bank

former or current executives specifically identified in any expanded original reporting

employees individually named in criminal proceedings

customers or businesses whose conduct is examined beyond the adjudicated corporate record

For any named jewellery business, money-service company or other private entity, Kleptik should distinguish:

charged conduct;

convicted conduct;

and unexplained transaction activity.

Where bank employees are accused but not convicted, their legal status should be stated precisely.

UNANSWERED QUESTIONS

The guilty plea establishes major institutional failures.

A deeper Kleptik investigation should examine how those failures survived for so long.

1. BOARD KNOWLEDGE

When did TD Bank’s board first receive clear information that transaction monitoring was materially inadequate?

2. AML BUDGET

How did AML spending change relative to revenue, assets and transaction volume from 2014 onward?

3. FLAT COST PARADIGM

Which executives established and enforced the policy?

4. INTERNAL AUDIT

How many unresolved AML findings accumulated?

5. REGULATOR WARNINGS

What specific deficiencies did federal regulators identify before the criminal investigation?

6. PRODUCT GOVERNANCE

Why were products such as Zelle launched without complete transaction-monitoring coverage?

7. 92% COVERAGE GAP

Which precise transaction classes constituted the $18.3 trillion?

8. ACH

How much suspicious activity was later identified in domestic ACH transactions?

9. CHECKS

How much relevant activity had occurred in previously unmonitored check traffic?

10. $5 BILLION AFTER CLOSURE DECISIONS

Which customers generated this activity, and how long did closure take?

11. $470 MILLION NETWORK

How many nominee accounts were involved?

12. EMPLOYEE GIFTS

Which controls failed to detect repeated customer benefits provided to staff?

13. JEWELLERY NETWORK

Why did nearly $120 million move before activity was reported?

14. COLOMBIA

How were ATM limits repeatedly exceeded?

15. INTERNAL EMPLOYEES

How were the five employees connected to the laundering network recruited or compensated?

16. BRANCH CONCENTRATION

Were certain branches disproportionately responsible for high-risk cash activity?

17. SAR BACKLOG

How many historic SARs must be filed as part of remediation?

18. CUSTOMER PROFITABILITY

How much revenue did the bank earn from the three identified networks?

19. ACCOUNT MIGRATION

Where did customers go after TD Bank eventually closed their accounts?

20. THE CENTRAL QUESTION

Was the bank’s failure primarily caused by:

  • underinvestment
  • poor technology
  • weak governance
  • bad incentives
  • employee corruption
  • management culture

or the interaction of all five?

The guilty plea strongly suggests the answer is systemic rather than singular.

KLEPTIK INTELLIGENCE ASSESSMENT

ASSESSMENT: ESTABLISHED

TD Bank pleaded guilty to criminal Bank Secrecy Act and money-laundering-related offences on 10 October 2024.

ASSESSMENT: ESTABLISHED

Approximately 92% of transaction volume—about $18.3 trillion—was excluded from automated transaction-monitoring coverage during the period identified by DOJ.

ASSESSMENT: ESTABLISHED

The three money-laundering networks identified by DOJ collectively moved more than $670 million through TD Bank accounts between 2019 and 2023.

ASSESSMENT: ESTABLISHED

One identified network moved more than $470 million through large cash deposits into nominee accounts, while operators provided bank employees with more than $57,000 in gift cards.

ASSESSMENT: ESTABLISHED

Five TD Bank employees conspired with a separate network involving rapid ATM cash withdrawals in Colombia and approximately $39 million in laundering.

ASSESSMENT: HIGH CONFIDENCE

The AML failure was systemic rather than the result of a single rogue employee or isolated defective rule.

The failures extended across years, transaction types, products, internal-audit warnings, staffing, technology and executive budgeting.

ASSESSMENT: HIGH CONFIDENCE

TD Bank illustrates why transaction-monitoring coverage should be measured quantitatively.

A system can exist formally while large portions of the institution’s economic activity remain outside surveillance.

ASSESSMENT: HIGH CONFIDENCE

Employee corruption can transform a control failure into active facilitation.

The bank’s insider-risk programme should therefore be viewed as part of AML governance, not a separate HR issue.

ASSESSMENT: HIGH CONFIDENCE

The OCC growth restriction demonstrates that regulators increasingly view adequate controls as a prerequisite for commercial expansion, not merely an obligation to be remedied after growth occurs.

THE KLEPTIK VIEW

Banks spend billions telling governments:

We know our customers.

We monitor transactions.

We identify suspicious behaviour.

We file reports.

We protect the financial system.

That trust gives banks extraordinary privileges.

They can accept deposits.

Move money.

Convert currencies.

Issue cards.

Connect businesses.

Connect countries.

And make dirty money progressively more useful simply by allowing it to move through legitimate financial infrastructure.

That is why the TD Bank case is more consequential than another compliance fine.

The bank was supposed to be the checkpoint.

Instead, according to its own guilty plea and the government’s case, substantial parts of the checkpoint were not functioning.

Ninety-two percent of transaction volume outside automated monitoring.

An estimated $18.3 trillion.

No material new monitoring scenarios for years.

Products launched without adequate coverage.

Billions in transactions continuing through accounts already selected for closure.

Piles of cash.

Nominee accounts.

Gift cards to employees.

A jewellery network.

ATM cards used to extract money in Colombia.

Five employees participating in one laundering scheme.

Those are not variations of one technical defect.

They describe a control environment.

And the most revealing phrase may not be contained in any regulation.

Employees reportedly called the bank an:

“easy target.”

That is the nightmare scenario for a financial institution.

Criminals discover weaknesses before management repairs them.

Then they tell others.

The bank develops a second reputation—one that never appears in advertising.

Convenient.

Flexible.

Few questions.

High limits.

Helpful employees.

Slow closure.

Eventually the institution’s greatest competitive advantage for legitimate customers becomes an advantage for illegitimate ones as well.

Convenience.

This is why compliance cannot simply be measured by:

  • headcount
  • software
  • policies

or dollars spent.

A bank can possess all four and still fail.

The correct questions are operational:

  • What percentage of transactions is monitored?
  • How quickly do models change?
  • What happens when internal audit finds a weakness?
  • Can compliance obtain more money when risk grows?
  • Can a branch refuse a profitable customer?
  • Can an employee override a limit?
  • How long does it actually take to close a dangerous account?
  • Does anyone aggregate activity across accounts?
  • Does the board see the real numbers?

And perhaps the most important:

DO CRIMINALS THINK THE BANK IS EASY TO USE?

The financial industry often treats AML as a regulatory obligation.

The TD Bank case demonstrates that it is something more fundamental.

It is infrastructure security.

The bank is a transportation network for money.

The monitoring system is the inspection system.

The employees operate the gates.

The board funds the security.

If the inspection system sees only 8% of the traffic, the existence of the checkpoint provides very little comfort.

That is the lesson.

Not that banks can prevent every crime.

They cannot.

Not that every suspicious customer should be rejected.

They should not.

The lesson is that an institution cannot credibly claim to defend the financial system if its own architecture prevents it from seeing what is moving through it.

WHEN THE BANK STOPS WATCHING THE MONEY, THE MONEY FINDS THE BANK.

KLEPTIK METHODOLOGY

This dossier is dated 10 October 2024 and is intentionally fixed to the legal and regulatory position existing on that date.

The principal evidentiary sources are:

  • the U.S. Department of Justice criminal resolution and plea records
  • the Financial Crimes Enforcement Network enforcement action
  • the Office of the Comptroller of the Currency enforcement action
  • and

related federal regulatory records concerning TD Bank’s AML deficiencies.

Because TD Bank entered criminal guilty pleas, Kleptik treats conduct expressly admitted through those pleas as established corporate conduct.

Kleptik nevertheless distinguishes the corporate plea from:

charges against individual employees;

allegations concerning individual customers;

and broader transaction patterns not separately adjudicated.

Numbers are categorised according to their evidentiary meaning.

UNMONITORED TRANSACTION VOLUME

Activity outside automated surveillance.

Not synonymous with suspicious or criminal money.

SUSPICIOUS ACTIVITY

Transactions displaying characteristics warranting investigation.

Not synonymous with criminal conduct.

IDENTIFIED LAUNDERING NETWORK ACTIVITY

Transactions prosecutors attribute to particular criminal networks.

CRIMINAL PROCEEDS

Funds established through evidence or adjudication as connected to criminal activity.

These categories must never be collapsed.

For transaction-monitoring analysis, Kleptik should examine:

  • data ingestion
  • scenario coverage
  • model changes
  • risk typologies
  • alert generation
  • case disposition
  • SAR filing
  • staffing

and backlogs.

The existence of software is not treated as proof of effective monitoring.

For insider-risk analysis, employees should not be characterised as compromised merely because they serviced high-risk customers.

Relevant evidence may include:

  • gifts
  • unusual overrides
  • repeated relationships
  • unauthorised system access
  • criminal charges
  • communications

or adjudicated conduct.

For account-closure analysis, Kleptik distinguishes:

decision to exit

from

effective termination.

The time between the two should be measured.

For bank-governance analysis, material claims concerning executives or directors should be based on:

  • board minutes
  • risk reports
  • budget records
  • internal audit findings
  • regulatory correspondence

or other primary documentation.

Corporate culture should not be inferred solely from isolated internal phrases unless supported by wider evidence.

Any individual, customer or business facing material criticism beyond the corporate guilty plea should receive a detailed right-of-reply opportunity.

EVIDENTIARY LABELS

ESTABLISHED — CORPORATE GUILTY PLEA
Conduct admitted by TD Bank through criminal proceedings.

REGULATORY FINDING
Conclusion stated by FinCEN, OCC or another competent regulator.

UNMONITORED VOLUME
Transactions outside automated AML surveillance; not evidence of illegality by itself.

IDENTIFIED LAUNDERING ACTIVITY
Transaction volume attributed by prosecutors to specified criminal networks.

INSIDER-CORRUPTION INDICATOR
Evidence potentially showing a bank employee assisted customer misconduct.

TRANSACTION-MONITORING GAP
Material transaction category excluded from effective surveillance.

CONTROL-EXECUTION FAILURE
Correct risk decision not implemented operationally, such as delayed account closure.

KLEPTIK VERIFIED
Fact independently corroborated through primary documentation.

KLEPTIK ASSESSMENT
Analytical conclusion derived from identified evidence.

INVESTIGATIVE LEAD
Issue requiring further transaction, governance or employee-level verification.

UNVERIFIED
Information insufficiently corroborated for factual publication.

DOCUMENT STATUS

KLTK-2024-012

Subject: TD Bank / Bank Secrecy Act / AML and Money-Laundering Control Failure
Archive date: 10 October 2024
Status at archive date: Criminal guilty pleas entered; coordinated federal enforcement actions announced
Historical treatment: Fixed to report date

© KLEPTIK — Investigations into Power, Money and the Systems Designed to Hide Both

▚ THE KLEPTIK BRIEF

Follow the money — in your inbox.

A regular briefing on corruption, sanctions and illicit finance. No spam, unsubscribe anytime.