Wachovia's AML officer flagged cartel accounts in 2005. He was told to back off. A cocaine plane crash ended it instead.

Wachovia moved $378.4 billion for Mexican currency exchange houses between 2004 and 2007, over $4 billion of it physically trucked across the border as bulk cash.

Martin Woods joined Wachovia in 2005 as the bank's FSA-approved Money Laundering Reporting Officer in London. He flagged CDC-linked accounts. He flagged Hezbollah-connected transactions during the 2006 Lebanon war. In testimony to the UK Parliament, he described a senior colleague telling him the matter had nothing to do with him and that he shouldn't have looked at the transactions in the first place. He eventually left the bank. The FCA later had to publicly deny it had blacklisted him from the industry.

The red flags themselves weren't subtle. Multiple round-dollar wires through the same account on the same day. Sequentially numbered traveler's checks deposited in batches, structuring markings and all. Bulk cash shipments consistently running larger than the CDC's own account documentation projected. Despite all this a random event forced Wachovia to act, as a DC-9 plane that made an emergency landing in Mexico in April 2006 carrying 5.5 tons of cocaine, bought with funds traced back through a Wachovia-linked account was the last straw. Wells Fargo later admitted in court the same channel had financed four planes carrying 22 tons combined.

$160 million in penalties against $378.4 billion in unmonitored volume is its own conversation about whether the fine ever mattered to the math. An officer with the actual title and the actual authority raised the concern through the correct channel, and one colleague with no documented override authority was enough to kill it. No committee vote, no risk acceptance memo, nothing that shows up in an audit trail. Just someone telling him to stop looking.

If an analyst or compliance officer at your firm disagrees with a decision to keep an account open, where does that disagreement actually go? Is there a real path above the person who wants to say no, or does it end wherever the first person with more seniority decides it ends?

reddit.com
u/TheAMLBrief — 1 day ago

NatWest's monitoring system read cash deposits as cheque deposits for almost four years. Nobody tested the classification until regulators did it for them.

NatWest is still the only bank in UK history to plead guilty to a criminal charge for anti-money laundering failures, back in 2021. The headline number is £365 million moving through a Bradford jeweller's account against an expected £15 million a year, £264 million of it in cash, some of it delivered to branches in bin bags.

NatWest's automated transaction monitoring system had a mapping error. It marked Fowler Oldfield's cash deposits as cheque deposits. Cheques carry a lower money laundering risk weighting by design, they're traceable bank-to-bank instruments with a paper trail. Every deposit that hit the account got the wrong risk treatment from day one, and it ran that way for close to four years. Nobody built the blind spot on purpose. Somebody just never checked whether the system's transaction-type field matched what was actually happening on the account.

A relationship manager didn't override a red flag here, and compliance didn't get outvoted by the business side. The account also blew past its expected turnover by more than 20x without triggering a periodic review, which is its own gap, but the mapping error is the one that should stick with anyone doing rule testing. Verifying that a monitoring system labels transactions the way you think it does, checked against reconciled real activity instead of vendor documentation, is one of the easier tests to run and one of the easiest to assume is fine because it's never surfaced as broken.

How often does your program actually test transaction-type classification against real account activity instead of trusting the vendor's documentation of how a rule is supposed to work? Built into periodic model validation, or only checked after something like this happens?

reddit.com
u/TheAMLBrief — 15 days ago

Ruja Ignatova invented OneCoin and is still missing with a $5M bounty on her head. Her co-founder got 20 years. The lawyer who laundered $400M of the proceeds got 10.

Most of the coverage on this case treats it as one story: OneCoin, a fake cryptocurrency, took $4 billion from 3.5 million people. But DOJ prosecuted three people connected to it, and the sentences don't line up the way you'd expect if laundering were the part that mattered most.

Karl Sebastian Greenwood, OneCoin's co-founder, ran the MLM network that pulled in that $4 billion through a recruitment-based commission structure, essentially a pyramid scheme with a crypto label on it. He got 20 years. Mark Scott, the law firm partner who built the fake Fenero Funds and laundered $400 million of those proceeds through BVI, Cayman, and Ireland, got 10. Half the sentence, for the piece of the case that's usually treated as the harder crime to prove and the more sophisticated conduct.

DOJ weighted the person who built the fraud engine and pulled the money out of victims' accounts twice as heavy as the person who hid where it went afterward. Layering $400 million through three jurisdictions using a convincing fake PE structure is not simple, and it still came in as the lesser offense here. Origination beat concealment.

Then there's Ignatova. She's the one who was actually running the company, the public face, the person both of these men worked for. She flew from Sofia to Athens on October 25, 2017, and never surfaced again. FBI Ten Most Wanted since 2022, one of the only women ever added to that list, $5 million on her name now. Whatever sentence she'd get is theoretical. Nine years later, the only person with real accountability attached to their name is the one who never got caught.

Anyone here worked a case where the sentencing outcome surprised you relative to what each defendant actually did, fraud origination versus the laundering execution after the fact? Curious if this kind of gap is common or if OneCoin is an outlier.

The laundering mechanics behind the $400M ran in Issue #14 of The AML Brief, free at theamlbrief.com.

reddit.com
u/TheAMLBrief — 17 days ago

A law firm equity partner laundered $400M of OneCoin proceeds through fake private equity funds. The banks that moved the money never needed to know OneCoin existed.

Most of the coverage on this case is fraud related; OneCoin took $4 billion from 3.5 million people and never had an actual blockchain behind it. The more useful story is what happened to $400 million of those proceeds afterward, because that part didn't involve a crypto exchange or a bank's transaction monitoring system missing anything. Mark Scott, an equity partner at the international law firm Locke Lord LLP, built a series of fake private equity funds in the British Virgin Islands called the Fenero Funds, and used them to move that money through the regular banking system.

None of the banks that touched Fenero's accounts needed to recognize OneCoin as a Ponzi scheme. They just needed to look at the fund itself. A newly formed fund entity with no operating history, raising and moving hundreds of millions of dollars. Capital sourced from "wealthy European families," described in exactly that vague a way. Money layered across three jurisdictions, BVI for formation, Cayman and Ireland for banking, for no operational reason beyond adding distance. And the person personally directing the structuring was a licensed attorney, not someone the client had been referred to a regulated financial intermediary through.

That last point is the one I'd actually push back on. In a lot of onboarding workflows, "outside counsel is involved" reads as a mitigating fact. Counsel on the wire memo, counsel on the fund docs, and the file gets treated as more buttoned-up than a comparable account with no attorney in sight. This case is a pretty clean argument that it should run the other way. A lawyer personally directing structuring and fund formation for a client isn't a compliance layer standing between the money and the bank. He's the client's own advisor, and here he was the one building the vehicle.

Scott was convicted on all counts in November 2019 and got 10 years. By the time that happened, the $400 million had already moved.

Anyone here handled onboarding or periodic review on PE fund or professional-intermediary structures where counsel was directing the transaction personally rather than just advising the client? Does your program actually treat that as a reason for more source-of-wealth follow-up, or does it tend to soften scrutiny in practice the way this case suggests it did?

reddit.com
u/TheAMLBrief — 22 days ago
▲ 18 r/moneylaundering+1 crossposts

Some Western Union agents weren't slow to catch the fraud. They were splitting the proceeds with the scammers.

Most of the coverage on this case is about Western Union failing to act on its own compliance findings. That's true, but it undersells what was actually happening at the agent level. Per DOJ's own statement of facts, this wasn't only a company sitting on a list of risky locations. Some of those agents were active participants in the fraud they were supposedly just processing payments for.

The pattern DOJ laid out: agents paid out transfers using fictitious identifying information for the recipient, split the fraud proceeds directly with the scammers running the schemes on the other end, and structured payouts to stay under recordkeeping thresholds so the transactions wouldn't generate the paper trail they were supposed to. That's not negligence. That's an agent acting as the placement and layering mechanism for someone else's fraud, taking a cut for the service.

It changes what this case actually is. A wire transmitter with a fraud-complaint problem at some locations is a monitoring failure. A wire transmitter whose agents are structuring transactions and falsifying recipient ID to move scam proceeds is a laundering network wearing a licensed MSB as a shell. The $586M forfeiture and the aiding-and-abetting wire fraud charge make a lot more sense once you separate "agents Western Union should have terminated" from "agents who were functionally working for the fraud crews."

The geography lines up with how these schemes actually ran. UK, Nigeria, Ghana, Jamaica, Spain — that's the standard footprint for lottery, sweepstakes, and grandparent scam cash-out at that point in the 2000s, and remittance corridors with weak agent-level ID verification are exactly where a scam crew wants its payout point to sit. The victims wired to real MSB locations with a real brand name on the door. The laundering happened at the counter.

Anyone here worked cases where a licensed money transmitter agent turned out to be complicit rather than just careless? Where's the line examiners actually draw between "this agent has a bad book of business" and "this agent is part of the laundering operation"?

The full breakdown of the compliance side of this case ran in Issue #13 of The AML Brief, free at theamlbrief.com.

reddit.com
u/DeliciousAirline5302 — 24 days ago

Western Union paid $586M for wire fraud running through its agents. Compliance had already named 214 of those agent locations in writing and told the company to cut them off. They stayed open anyway.

Everyone tells the Western Union story like it's about a fraud network the company failed to catch. That's not what DOJ's statement of facts actually says. Western Union's own U.S. compliance people found the bad agent locations, wrote them down, and told the company to cut them off. Western Union kept processing through them anyway. Between 2006 and 2010, 214 agent locations across the UK, Nigeria, Ghana, Jamaica, and Spain stayed open, and every single one had already racked up $100,000+ in reported fraud. There's even a specific line in the statement of facts where U.S. Compliance flagged two UK agents by name and recommended suspending them, and Western Union kept both of them on anyway.

Here's the thing, any agent network big enough is going to produce a list like this eventually. Complaints pile up in a handful of locations, and if your program's doing its job, it'll find them. That's not the failure here. Western Union's compliance team did exactly what they were supposed to do. The failure is that finding the problem and having the power to fix it turned out to be two completely different things, and the second one lost every time there was money on the table.

That's a worse failure than "the monitoring system didn't catch it." At least that story is about a tool not working. This one's about a person doing their job correctly, in writing, and it not mattering at all. If a documented recommendation to shut something down just gets ignored, you don't really have a control. You have a paper trail nobody with authority ever reads.

This case still isn't closed. DOJ reopened the victim fund this past June, nine years after the original settlement, because people are still filing claims for transfers going back to 2004. That gap, between when compliance saw the problem and when the last victim actually gets made whole, is basically two decades.

Has anyone who's worked agent or correspondent oversight had a termination recommendation get shot down by the business side? What actually happens after that? Does it go anywhere, or does it just sit in a file until someone digs it up years later?

reddit.com
u/TheAMLBrief — 29 days ago

Danske's Estonia branch was a known exit point for the Russian Laundromat and the Azerbaijani Laundromat before its own scandal ever broke.

Most coverage of Danske Bank treats the €200 billion in transactions as one undifferentiated pile of "suspicious non-resident activity." That's wrong, as a real share of it already had a name and a paper trail, mapped by OCCRP years before Danske's own scandal ever broke.

The Russian Laundromat was OCCRP's 2014 investigation into at least $20.8 billion moved out of Russia between 2010 and 2014. Shell companies faked debts against each other, sued in Moldovan courts, and got complicit judges to rubber-stamp those debts as real judgments, paper cover that let the money move as legal debt repayment instead of an unexplained wire. Danske's Tallinn branch was one of the exit banks that received that money and let it re-enter the legitimate financial system looking clean.

Three years later, OCCRP broke the Azerbaijani Laundromat scheme: a $2.9 billion slush fund controlled by Azerbaijan's ruling elite, run through four anonymous UK shell companies that banked at Danske's Estonian branch. That money didn't just sit there. Reporting traced it to European politicians, luxury goods purchases, and reputation-laundering payments to lobbyists and journalists, on top of ordinary asset concealment.

And Danske's own internal investigation, the Bruun & Hjejle report the bank commissioned in 2018 after the scandal broke publicly, found transactions connected to the Magnitsky case running through the same branch. That's the $230 million Russian tax fraud Sergei Magnitsky exposed before he died in pretrial detention in 2009. The bank that let his case's proceeds move through its own books is the same bank that spent the next several years telling US correspondent banks its AML program was fine.

None of these three networks were secret when Danske was still representing its controls as adequate. OCCRP had already published on two of them. A branch moving money for entities connected to state-level slush funds and a fraud tied to a dead whistleblower isn't a gap in a monitoring system. It's a bank that had every external signal it needed and kept the account relationships open anyway.

Anyone here traced Laundromat-linked entities through a downstream institution years after OCCRP's original reporting came out? Curious how much of that money is still findable versus fully integrated by now.

The Danske Bank Estonia case was the main feature in Issue #12 of The AML Brief, free at theamlbrief.com.

reddit.com
u/TheAMLBrief — 1 month ago

Danske Bank's board got a written warning in January 2014 that a branch might be "knowingly dealing with criminals." The suspicious volume didn't stop until 2016.

Everyone defaults to reading the Danske case as a detection failure, however it wasn't. The head of the Baltic trading desk sent management an email after Christmas 2013 with the subject line "knowingly dealing with criminals in the Estonia branch." The board discussed it the first week of January 2014. He was never told what happened next, and the suspicious volume through that branch kept moving for roughly two more years.

That's not a monitoring gap; the program that should have stopped this already existed. Someone inside the bank handled it correctly, escalated to the right people, and got nothing back for two years. Compare that to the usual case study where a transaction monitoring system just didn't fire an alert, and this is a worse failure, because it means the escalation control itself was not operating effectively.

Danske pleaded guilty to conspiracy to commit bank fraud, for misrepresenting its AML program to the US correspondent banks holding its dollar accounts, not for failing to catch laundering it didn't know about. Group management told American banks the controls were adequate while the board had a written warning sitting in the minutes saying otherwise.

If you sit anywhere in an EDD or correspondent banking review, the check here doesn't require trusting anyone's self-attestation. A branch moving €200 billion while holding a sliver of group deposits is a volume-to-footprint mismatch you can measure independently of whatever the relationship manager tells you about program adequacy.

For anyone who's actually worked an internal escalation: once something gets raised to board level, what's the real SLA before it either gets acted on or someone documents why it didn't? Because two years suggests there wasn't one.

reddit.com
u/TheAMLBrief — 1 month ago

$4.5 billion left 1MDB through shell companies. It came back as a superyacht, a Scorsese movie, and a supermodel's jewelry.

Jho Low never held a formal position at 1MDB. No title, no seat on the board, nothing that would show up in a corporate registry search. The DOJ's own language is that he was "regularly consulted" on the fund's biggest decisions anyway. That's the whole scheme in one sentence: the person directing where billions moved had no paper trail connecting him to the money.

Goldman underwrote three 1MDB bond deals in 2012 and 2013, worth about $6.5 billion combined, and collected close to $600 million in fees. Bond proceeds that were supposed to fund Malaysian development projects got routed into shell companies almost immediately after settlement. Once the money was inside those entities, it stopped looking like sovereign wealth fund capital and started looking like whatever the next transaction needed it to look like.

Layering took it through structures spanning Malaysia, Abu Dhabi, Switzerland, Singapore, and the US. BSI, a Swiss private bank, moved 1MDB-linked funds for years. One of its own employees wrote to management in 2012 that the team executing these transactions didn't understand what it was doing or why. Nobody acted on that until Singapore shut down BSI's entire local operation in 2016, the first time in three decades its regulator had closed an international bank's unit there.

Integration is where the money stopped being suspicious and started being assets. Red Granite Pictures, co-founded by the Malaysian prime minister's stepson, used diverted funds to help finance The Wolf of Wall Street. Other proceeds bought the Equanimity, a 300-foot superyacht later seized off Bali and sold for $126 million, plus jewelry for a supermodel and paintings by Van Gogh and Monet. Real assets, real markets, no obvious connection back to a state investment fund.

DOJ's Kleptocracy Asset Recovery Initiative calls this the largest case in the program's history: more than $1.7 billion clawed back through 41 separate civil forfeiture actions. That number is the cost of unwinding placement, layering, and integration after the fact instead of catching it at any single stage while it was happening.

Anyone here worked asset tracing or civil forfeiture on a case with this many jurisdictions stacked on top of each other? Genuinely curious how you even decide where to start pulling the thread.

The 1MDB scandal was the main feature in Issue #11 of The AML Brief, free at theamlbrief.com.

reddit.com
u/TheAMLBrief — 1 month ago

Goldman's 1MDB banker wasn't convicted for missing the risk. He was convicted for personally routing around the firm's own controls to get the deal done.

Most Foreign Corrupt Practices Act (FCPA) cases you read about are bribery cases with a compliance footnote. This one flips that. Roger Ng, a Goldman managing director, was convicted on a charge that specifically named circumventing Goldman's own internal accounting controls. Not "the controls didn't catch it." He and Tim Leissner went around them on purpose.

Goldman underwrote three 1MDB bond deals in 2012 and 2013 worth about $6.5 billion combined and collected close to $600 million doing it. Underwriting economics scale with deal risk and complexity, and $600 million on $6.5 billion for a sovereign-adjacent issuer isn't what a routine credit profile produces. Somewhere in Goldman's deal-approval chain, that number should have triggered a second look independent of whatever KYC had already signed off on the client relationship.

It didn't, because the two people positioned to flag it were the same two people who wanted the deal closed. Leissner was Goldman's Southeast Asia chairman. He had the standing to override the process, not just influence it. That's a different failure mode than a monitoring system with a blind spot or an analyst who missed a pattern.

Goldman ended up paying $2.9 billion to DOJ and SEC and another $3.9 billion to Malaysia directly. $600 million in fees turned into $6.8 billion in liability.

Genuine question for anyone who's sat in capital markets or deal-approval compliance: does your fee/risk outlier review actually have authority to kill a deal a senior banker wants closed, or does it just produce a memo that gets overridden three levels up?

reddit.com
u/TheAMLBrief — 1 month ago

Transaction monitoring didn't catch Deutsche Bank's mirror trading scheme because the risk only existed at the relationship level, not the transaction level.

Deutsche Bank's Moscow desk moved roughly $10 billion out of Russia through a scheme that looked, transaction by transaction, like ordinary equity trading. A client buys Russian shares in Moscow for rubles. A related, undisclosed counterparty sells the same shares in London for dollars. Both trades settle normally. The laundering isn't in either trade individually, it's in the relationship between the two sides.

That's why transaction monitoring missed it. No structuring pattern in the payment flow. No anomalous volume for a bank with significant Russian institutional business. No sanctions hits on the trades themselves. The risk only becomes visible when someone looks across the Moscow and London books at the same time and asks why the same client network keeps showing up on both sides of the same trades. That cross-desk, cross-jurisdiction view wasn't built into the monitoring architecture.

What makes this case different from a pure detection failure is that Deutsche Bank's own compliance staff in Moscow identified the mirror trading program as high-risk and escalated those concerns internally. The NYDFS consent order states plainly that the bank's management was aware of the compliance concerns associated with the program. The program continued anyway, for roughly four years, until the NYDFS and the FCA issued findings on the same day in January 2017: $425 million from New York, £163 million from London.

Compliance had enough visibility to identify the risk and ask the question. It didn't have enough authority to change the answer once the business decided to not act on the transactions. That's a different problem than "the monitoring system couldn't see it," and it requires a different fix; an escalation path that can actually stop activity, not just document that someone raised a concern.

How does escalation work at your institution when a risk gets flagged at the analyst or compliance officer level but the business wants to keep the relationship? Does the program have real stop authority, or does escalation mostly produce a paper trail?

reddit.com
u/TheAMLBrief — 2 months ago

Most TBML policies say the institution will monitor for indicators. Almost none of them say what flags an over-invoiced letter of credit.

Most TBML policies say the institution will monitor for indicators, however almost none of them specify what the actual detection mechanism is.

That gap is magnified because transaction monitoring wasn't built for trade-based laundering. TM is designed for behavioral anomalies in payment flows: structuring, velocity changes, unusual counterparties, sanctions hits. TBML doesn't produce structuring patterns, it produces normal-volume, normal-frequency payments for international trade. A $500,000 payment against a letter of credit doesn't alert. Neither does one that's 30% above the benchmark price for that commodity, because the TM system doesn't know what the market price is. The anomaly is in the invoice, not the payment.

Most TM platforms don't ingest trade documentation. Letters of credit, bills of lading, and commercial invoices are processed by trade finance teams, not fed into the AML platform. This results in TBML moving through a bank's trade finance operation in one lane while compliance monitors transactions in a separate lane, with no visibility into the documents behind the payments.

The three underlying operational typologies are over/under-invoicing (invoice price above or below market, with the difference representing value transferred outside the financial system), multiple invoicing against the same shipment, and phantom shipments where the supporting documentation is fabricated but the payment is real. Each of these is detectable, but none of them generate a TM alert on their own.

Programs with meaningful TBML detection capability generally have three things most don't: some mechanism for comparing invoice values against market prices for the commodities and corridors they're exposed to, a defined escalation path from trade finance staff to the SAR process, and corridor-based risk logic that applies heightened documentary scrutiny to the channels where TBML concentrates (South America to the U.S., China to Latin America, Middle East to Europe).

FinCEN's advisory on TBML is from 2010 and FATF's foundational typologies report is from 2006. A bank that's never filed a SAR citing TBML indicators hasn't necessarily avoided the exposure. It may have avoided the scrutiny that would make the exposure visible.

What have you all seen within your institutions on how TBML is monitored and handled when compared to your policy documentation?

reddit.com
u/TheAMLBrief — 2 months ago

HSBC didn't fail because it lacked a compliance program. It failed because the program couldn't close profitable accounts or override business decisions.

In December 2012, HSBC entered a deferred prosecution agreement and paid $1.9 billion after FinCEN and the DOJ found that HSBC Mexico had laundered $881 million for the Sinaloa and Norte del Valle cartels. The transaction monitoring system was operational throughout, CTRs were filed, and alerts were generated. The Senate Permanent Subcommittee on Investigations released a 340-page report documenting how it happened.

The report's finding wasn't that HSBC had no AML infrastructure. The problem was what happened when compliance findings conflicted with revenue.

HSBC Mexico was classified as the highest-risk affiliate in the bank's global network. The institutional response was a management initiative called the "Simplification Project," which reduced compliance requirements for that customer base and lowered enhanced due diligence thresholds. The cartels adapted, even going so far as manipulating cash deposit boxes to fit through HSBC Mexico's teller windows. Between 2007 and 2010, approximately $7 billion in physical currency moved from Mexico to the United States. More than 373,000 transactions without adequate monitoring. CTRs were filed on some of those deposits, however SARs weren't.

The OCC flagged AML deficiencies at HSBC for four consecutive examination cycles before the DOJ acted. The compliance function kept generating documentation. The findings kept moving through the system and the business relationship continued.

What distinguishes this case from TD Bank or Binance is the character of the failure. TD Bank's leadership documented its contempt for the compliance function. Binance built a platform with no AML infrastructure and made deliberate decisions not to register with FinCEN. HSBC's program existed, ran, and produced findings. It couldn't close a profitable account. It couldn't file a SAR on a relationship the business wanted to keep. It couldn't get a finding to someone with authority and will to act on it.

A program that can detect risk but can't produce consequences when detection conflicts with revenue isn't a functioning AML program. It's a documentation program. The two look identical from the outside. Both have policies, both generate reports, both satisfy examination requirements. They diverge at the point where a finding would require the business to do something it doesn't want to do.

Most compliance programs can identify unusual activity. Fewer have tested whether the escalation path from detection to consequence actually functions when the consequence involves business disruption. Has anyone seen this occur at your current or prior companies?

reddit.com
u/TheAMLBrief — 2 months ago

Four months for $4.3 billion. Probation for $11 billion. No charges for $3.09 billion. The personal liability question in AML enforcement isn't settled.

Changpeng Zhao pled guilty to willful failure to maintain an effective AML program. Binance as a company paid $4.3 billion. He was sentenced to only four months. The three BitMEX co-founders who operated a crypto exchange with no AML controls on $11 billion in trading volume received probation. TD Bank paid $3.09 billion, the largest BSA penalty in U.S. history for a bank, and no senior executives were criminally charged in connection with the AML program failures.

The Yates Memo, published September 2015, directed prosecutors to pursue individuals behind corporate misconduct, not just the institution. It's been cited in enforcement announcements for a decade. What it's produced in AML cases is a narrower set of individual charges than the policy language suggested, mostly concentrated where prosecutors had documented evidence of personal knowledge and a deliberate decision not to act. CZ's own written legal risk assessment ended up in the federal filing. The BitMEX founders documented their approach to avoiding U.S. regulators. The evidence was their own records.

Where that documentation existed but criminal charges didn't follow, the institutional penalty may be functioning as a substitute for individual accountability rather than a complement. As regaultory enforcement continues, it will be interesting to see if this pattern shifts.

The more practical question for compliance professionals isn't whether the C-suite gets charged, it's where individual liability shows up, if at all.

Cases where individuals at the BSA officer and compliance manager level have appeared in enforcement records don't usually involve billion-dollar institutions. They involve documented findings that weren't escalated, escalations that stalled without a recorded resolution, and SAR decisions made without a detailed rationale. The Yates Memo's logic doesn't stop at the executive level. Individual accountability follows the person whose name is on the decision.

If your program documents what was found but not what was decided about it; if an escalation routes upward and the record goes quiet, or a SAR decision is made without a written rationale, that's the structure that creates individual exposure. The compliance officer's risk is in the documentation trail at the case level.

For practitioners in SAR review or escalation governance, how complete is your documentation chain from identification through decision?

reddit.com
u/TheAMLBrief — 2 months ago

Binance, TD Bank, and Capital One were each damaged by their own compliance team's records. The instinct to document less after reading them is the wrong takeaway.

The Binance CCO wrote in 2018 that the company was "operating as a f***ing unlicensed securities exchange in the USA." The message was accurate. Binance continued operating in the U.S. for years after that, filing zero SARs throughout. That internal message was documented within the DOJ's published statement of facts in 2023.

TD Bank's OCC consent order referenced internal communications showing compliance concerns were treated as obstacles to business growth. "Convenience over compliance" wasn't a regulator's phrase imposed from the outside. It reflected language and posture that was documented inside the institution.

FinCEN's 2021 action against Capital One turned on what the consent order called "documented knowledge." The bank's own risk files, the Genovese associate's conviction, and the Check Cashing Group's high-risk classification were what elevated SAR non-filing from negligent to willful. Without that documentation, FinCEN would have had a harder case.

The natural reaction when you read all three is to think more carefully about what gets written down. That reaction is understandable and wrong.

Undocumented decisions don't protect programs. A risk assessment with no written record of follow-up looks, in retrospect, like a risk assessment that produced no action. A concern raised in a meeting but not captured looks like a concern that was never raised. Regulators and auditors evaluate programs through their documentation. It's the primary evidence of what a program actually does.

What made these records damaging wasn't that compliance teams wrote things down. It was the gap between what was identified and what was done about it. The Binance CCO's message was damaging because an accurate written assessment of regulatory risk was followed by a business-as-usual response. Capital One's risk files were damaging because their thoroughness produced a willful finding when the SARs didn't follow.

The practical discipline isn't "be careful what you write." It's "does your documentation show a finding and then a decision?"

A written high-risk finding paired with no documented escalation or SAR rationale creates a record of knowledge without response. An escalation memo that stalls without a documented resolution shows risk routed upward and stopped there. Meeting notes that capture a concern but not the decision made about it tell half the story, and the missing half is usually what examiners want most.

For anyone who works in escalation governance or SAR review, how does your program document the decision itself, not just the identification of risk? And how do you verify that the chain is complete?

reddit.com
u/TheAMLBrief — 3 months ago

Capital One correctly identified its highest-risk customers. Then didn't build a program to cover them.

Capital One paid $390 million to FinCEN in January 2021 for BSA violations tied to its Check Cashing Group, a business unit the bank had internally classified as high-risk. The violations ran from 2008 through 2014.

FinCEN's finding on SAR non-filing was willful failure, not negligence and not a systems gap. Capital One also failed to file approximately 50,000 CTRs on roughly $16 billion in cash. Two different legal standards, but both trace back to the same root problem of a high-risk portfolio operating without an AML program built to match its risk classification.

The case is worth studying because Capital One didn't skip the risk assessment step. CCG customers were designated high-risk. The classification was documented and internally applied. What the bank didn't do was build monitoring and SAR review processes to match that classification. The risk matrix and the AML program weren't connected.

How far did the gap go? Capital One continued processing over 20,000 transactions worth approximately $160 million for a customer's businesses after that customer had been convicted as an associate of the Genovese organized crime family. The bank had documented knowledge of the conviction. FinCEN's consent order noted that proceeds connected to organized crime, tax evasion, and fraud entered the US financial system unreported through those accounts.

Capital One admitted to the findings. Most enforcement actions are resolved on a neither-admit-nor-deny basis. When an institution admits, the internal documentation evidences that contesting the facts isn't viable. Six years of deficient SAR filing on a portfolio already designated high-risk produced that record.

Are your high-risk designations actually driving program design, or are they sitting in a risk matrix?

A business line or customer segment rated high-risk should generate lower alert thresholds, more monitoring activity, and closer SAR review than a standard account. If your enterprise AML program is calibrated to your typical customer and high-risk segments are layered on without dedicated configuration, the structure that produced the Capital One gap is replicable. The risk rating alone doesn't protect you. What matters is whether that rating is connected to the monitoring program running against those accounts every day.

For anyone who works in transaction monitoring or risk rating governance: how do you verify that high-risk classifications are actually reflected in your alert logic, or is that connection mostly assumed?

reddit.com
u/TheAMLBrief — 3 months ago

The November 2023 Binance settlement gets covered as a crypto story, however compliance professionals treat it as a typical tone-at-the-top failure with a paper trail most enforcement actions don't have.

Binance registered with FinCEN as a money services business in 2019, which served as a written acknowledgment of Bank Secrecy Act obligations. Binance then filed zero SARs with FinCEN while processing more than 100,000 transactions between Binance users and people in sanctioned jurisdictions.

FinCEN identified over $898 million in transactions flowing to Iranian parties. As a result, OFAC fined Binance $968 million due to the heavy transaction flow to a sanctioned country.

Binance's compliance team wasn't operating in the dark, as the DOJ revealed internal messages that documented awareness of criminal activity flowing through the platform. Former CCO Samuel Lim's assessment was direct: "Like come on. They're here for crime."

Binance's lack of SAR filings seemed to be influenced by their leadership team. If other institutions had any crypto-related exposure (e.g.; correspondent relationships, payment rails, wire transfers touching Binance's US entity), their failure to file created upstream gaps in their SAR coverage as well.

For compliance teams still treating crypto as a minor concern, FinCEN has been clear since 2013 that virtual currency exchanges operating as money transmitters carry BSA obligations. The Binance settlement was proof that regulators will take this seriously, compounded by deliberate inaction by Binance's leadership team.

For those working in traditional banking and crypto, did your institution go back and review SAR gaps that might trace to exchanges like Binance that weren't filing? It would be interesting to hear perspectives on how your teams handled the downstream exposure and whether your transaction monitoring was actually catching activity that should have come from Binance's side first.

reddit.com
u/TheAMLBrief — 4 months ago

Out of nowhere, the TD Bank case exploded into headlines, mainly because of the massive $3.09 billion penalty levied against them. Hidden beneath the penalty was roughly $18.3 billion tied to suspicious transactions. All this resulted in TD becoming the first US bank in history to plead guilty to conspiracy to commit money laundering.

The number practitioners keep coming back to is smaller, which was that five TD branch employees took $57,000 in gift cards and cash to open fake accounts and suppress escalations. Even though federal agents caught them, the bank’s private investigative team missed it entirely.

An institution processing that volume of suspicious activity had insiders actively facilitating it and nobody inside caught them. It could mean blind spots in tracking staff behavior. Or perhaps warnings were ignored when spotted. Compliance teams often wait until after trouble surfaces before moving, performing investigations from a reactionary stance rather than proactively addressing red flags.

Resetting norms, the deal shifted how examiners view bank behavior nationwide. Since then, at every major US bank, compliance teams have faced repeated requests which focus on proving where their systems would’ve spotted this failure. Lately, phrases like “convenience over compliance,” pulled straight from the DOJ’s critique of TD, pop up often in federal reviews. Examiners specifically look for the facts to fit this pattern.

What shifted how TD's board acted was the Fed’s limit on assets. Fines are just taken in stride in the highly regulated banking industry. But when a bank can’t grow because operations are boxed in till fixes meet Fed standards, things feel different and pressure to comply rises.

Has your organization re-examined its insider threat program since the TD Bank settlement? Specifically how you monitor employee conduct rather than just external typologies. I'm curious to see what that looks like in practice within your company.

*We break down enforcement actions like this every Tuesday in The AML Brief. Free at theamlbrief.com*

reddit.com
u/TheAMLBrief — 4 months ago
▲ 38 r/moneylaundering+1 crossposts

In October 2024, TD Bank became the first US bank ever to plead guilty to conspiracy to commit money laundering. $3.09 billion in combined penalties. $18.3 billion in suspicious transactions processed. Three criminal networks operating simultaneously through the same institution.

The scale gets the headlines. The failures are what practitioners should be studying.

---

**What actually went wrong**

Three distinct networks moved money through TD accounts at the same time; a Colombian drug trafficking network (~$100M), a fentanyl proceeds network, and the Da Hua Xu network ($653M via shell companies and structured cash deposits). None of them were using particularly sophisticated methods. They didn't need to.

**Failure 1 — Transaction monitoring frozen in time**

TD's TM system hadn't been meaningfully updated since 2014. Hundreds of thousands of transactions fell completely outside monitoring parameters, not because the patterns were novel, but because nobody updated the rules. A decade of deferred maintenance, $18B in suspicious volume.

**Failure 2 — Internal incentives suppressed escalation**

When analysts did flag suspicious activity, the bank's internal culture, which the DOJ characterized as prioritizing "convenience over compliance", actively worked against SAR filings. Customer retention mattered more than escalation. That's not a training problem. That's a governance problem.

**Failure 3 — Bribery at the branch level**

Five TD branch employees were bribed with approximately $57,000 in gift cards and cash to open fraudulent accounts and suppress escalations. That's not an isolated rogue actor situation, that's a cultural environment that made bribery feel like a viable option.

**Failure 4 — No meaningful independent testing**

The consent orders make clear that TD's independent testing function wasn't catching any of this. Either the testing wasn't genuinely independent, wasn't sufficiently scoped, or the findings weren't being escalated effectively.

**Failure 5 — The Fed noticed what the fines couldn't fix**

The Federal Reserve imposed an asset cap on TD Bank, only the second time that penalty has been applied to a major US bank. An asset cap isn't a fine. It's an operational constraint that limits growth until the Fed is satisfied with remediation. That's the penalty that actually changes board-level behavior.

---

**The "convenience over compliance" problem**

That phrase, appearing explicitly in the DOJ consent order, is worth sitting with. It's not just a characterization of TD Bank. It's a signal about how the DOJ intends to frame AML failures going forward.

If your institution's SAR filing volumes don't correlate with its risk profile, if escalation rates are anomalously low, if frontline staff understand that customer retention matters more than escalation, that pattern now has a name in federal enforcement documents. And that name is going to show up in the next examination.

---

**Discussion question:** The TM system not being updated for a decade is the detail that stands out most to us. In your experience, what's the actual barrier to keeping TM rules current; is it budget, competing priorities, model validation requirements, or something else?

---

*We cover enforcement actions like this one every Tuesday in The AML Brief — free newsletter at theamlbrief.beehiiv.com if this kind of breakdown is useful to you.*

u/TheAMLBrief — 3 months ago