Gift Cards for Silence: TD Bank Employee Sentencing Shows the Human Cost of a Failed AML Program

The individual prosecutions now flowing out of the TD Bank money laundering scandal are a reminder that institutional control failures are ultimately executed, or ignored, one employee at a time. This week, U.S. District Judge Esther Salas sentenced former TD Bank assistant manager Wilfredo Aquino to 46 months in prison and three years of probation for his role in a money laundering conspiracy that moved tens of millions of dollars in narcotics proceeds through his Midtown Manhattan branch. A second former TD employee, Edward Low, was sentenced separately to 24 months for selling confidential customer data to facilitate nearly $500,000 in fraud.

What Aquino Did

Aquino pleaded guilty in January to a single money laundering conspiracy charge in federal court in Newark. According to prosecutors, between 2019 and 2021 Aquino processed checks for Da Ying Sze, a Flushing, Queens-based ringleader who ultimately pleaded guilty in 2022 to laundering at least $653 million in proceeds from illicit narcotics trafficking, including fentanyl profits. Aquino failed to identify Sze as the true party behind $92 million in transactions run through the bank, even though the majority of those transactions exceeded the $10,000 threshold that should have triggered currency transaction reporting to regulators. In exchange for his cooperation, Sze gave Aquino retail gift cards. Sze’s network gravitated specifically to Aquino’s branch and to Aquino personally, prosecutors said, because he was a reliable point of failure in the bank’s controls.

Perhaps most damning for TD institutionally: the bank’s own compliance and fraud specialists began flagging the suspicious transactions as early as 2020. The suspicious activity was visible internally well before the scheme unwound, which is consistent with the broader narrative regulators have built around TD’s control environment over the past several years.

A Second Employee, A Different Scheme

Edward Low, a former TD retail employee, was sentenced separately to 24 months in prison after pleading guilty in February to charges related to stealing confidential customer information while employed at the bank in 2021 and providing it to co-conspirators in exchange for bribes, facilitating close to $500,000 in fraud. Different conduct, different scheme, same underlying vulnerability: an employee willing to trade access and information for personal payment, at an institution whose surveillance and internal controls did not stop it in time.

The Institutional Backdrop

These individual sentencings do not exist in a vacuum. TD Bank agreed in 2024 to pay more than $3 billion in penalties and accept growth restrictions in the United States to resolve sweeping regulatory and criminal investigations into its anti-money laundering control failures, a settlement that derailed the bank’s U.S. expansion ambitions after a string of regional bank acquisitions. TD has stated that AML remediation remains its top priority and that it cooperated with law enforcement throughout the investigation.

Why This Matters for Compliance Programs

The Aquino and Low cases illustrate a lesson that gets lost when the headline number is $3 billion: institutional AML failures are rarely abstract. They come down to individual employees who are either poorly trained, poorly supervised, or, in Aquino’s case, actively complicit, and who are positioned at exactly the point in the process where a transaction can be waved through instead of escalated. A bank-wide AML program is only as strong as its weakest branch-level control, and criminal networks are adept at finding and exploiting that weak point once it exists.

The fact that TD’s own compliance function flagged the suspicious activity as early as 2020, well before the scheme was fully unwound, raises the same question that recurs across bank AML failures: what happens between the moment a red flag is raised and the moment it results in an actual filed report or a closed account. A detection capability that exists on paper but does not translate into timely escalation and action provides little practical protection.

Compliance Takeaways

A few points are worth drawing out for AML and compliance professionals reviewing this case:

Branch-level personnel are a recognized attack surface, not just an operational afterthought. Criminal networks will identify and repeatedly return to specific employees who fail to escalate, and banks need monitoring that can detect that kind of employee-specific pattern, not just transaction-specific anomalies.

A currency transaction reporting threshold is only effective if the employee responsible for identifying the true party to a transaction actually does so. Structuring detection and beneficial ownership identification at the point of transaction are frontline controls that cannot be outsourced entirely to downstream automated surveillance.

Internal red flags raised by compliance and fraud specialists need a hard deadline for resolution. When a bank’s own compliance team is flagging suspicious transactions years before a scheme is fully addressed, the gap between detection and action becomes the story regulators and prosecutors will tell.

Employee vetting and ongoing monitoring for conflicts of interest, unusual patterns of client interaction, and unexplained personal enrichment (gift cards, bribes, or otherwise) should be a standing part of any bank’s internal controls, not just a response to a specific tip.

Individual accountability is now a consistent feature of bank AML enforcement, not a rare exception. Institutions that treat AML failures purely as an enterprise-level compliance program problem risk underestimating the criminal exposure facing the individual employees who touch the transactions.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *