On 16 July 2026, a former TD Bank assistant branch manager was sentenced to 46 months in federal prison for helping a criminal network move $474 million through bank accounts between 2019 and 2021. His compensation for facilitating one of the largest insider money laundering schemes in recent US banking history was $11,000 in retail gift cards.
The sentencing of Wilfredo Aquino is the latest development in a case that connects directly to TD Bank's landmark 2024 guilty plea and $3.09 billion penalty, the largest fine ever imposed under the Bank Secrecy Act and the first time in US history that a major bank pleaded guilty to conspiracy to commit money laundering. The institutional case established the scale of the failure. The Aquino sentencing illustrates the human layer within it: a bank employee with system access and a willingness to look the other way, exploited for far less than the damage he enabled.
What the Court Found
Wilfredo Aquino, 47, was an assistant manager at TD Bank's Midtown Manhattan branch. According to prosecutors, between 2019 and 2021 he helped a criminal network led by Da Ying Sze, also known as David, move $474 million through TD Bank accounts. Specifically, Aquino processed 1,680 official bank checks worth more than $92 million and deliberately concealed Sze's identity as the leader of the criminal ring from the bank's compliance systems. In exchange, he received retail gift cards valued at $11,000.
Prosecutors noted that Aquino did not act alone in terms of available information. A colleague specifically warned Aquino that Sze's activity "looks like money laundering." He ignored it. Moreover, Aquino received regular training on TD Bank's AML, anti-bribery, and anti-corruption policies throughout the scheme period. That training did not produce a different outcome. Rather than filing suspicious activity reports or escalating internally, he continued processing transactions and, critically, deliberately failed to identify Sze as the conductor on the Currency Transaction Reports the bank was required to file. That CTR falsification is a distinct BSA violation on top of the SAR non-filing, and it is what allowed Sze's identity and role to remain concealed from compliance systems for years.
"Bank employees are the first line of defense against money laundering, fraud, and other financial crimes. When bank employees ignore their obligations and instead use their positions to commit crimes and line their own pockets, we will not hesitate to hold them accountable."
Jenifer L. Piovesan, Special Agent in Charge, IRS Criminal Investigation Newark Field Office, July 2026
On the same day as Aquino's sentencing, a second former TD Bank employee, Edward Low, 31, received a 24-month prison term for a separate but related scheme. Low accepted at least $26,700 in bribes to provide confidential account information to thieves who subsequently stole from the bank's customers. Notably, after leaving TD Bank, Low moved to another financial institution where he continued facilitating fraud, falsifying bank records to open an account in the name of a shell company between May and August 2022. Together, the two sentences on the same day underscore that the employee-level misconduct at TD Bank was not an isolated incident, and that it did not stop at the bank's door.
Sze, the leader of the criminal network, had already pleaded guilty in February 2022 to coordinating a $653 million money laundering scheme. He also admitted to operating an unlicensed money transmitting business and to bribing bank employees in connection with financial transactions.
The Institutional Backdrop: TD Bank's $3.09 Billion Penalty
The Aquino sentencing does not exist in isolation. In October 2024, TD Bank pleaded guilty to conspiring to violate the Bank Secrecy Act and to conspiracy to commit money laundering, becoming the largest US bank ever to plead guilty to BSA program failures and the first bank in US history to plead guilty to conspiracy to commit money laundering. The total penalty across the DOJ, FinCEN, the Federal Reserve, and the OCC amounted to $3.09 billion.
As part of the settlement, TD Bank admitted it had failed to monitor $18.3 trillion in customer activity over a six-year period, allowing three separate money laundering networks to transfer more than $670 million through its accounts. The OCC imposed an asset cap limiting the bank's US growth. A compliance monitor was appointed to oversee remediation for three years.
"By making its services convenient for criminals, it became one."
US Attorney General Merrick Garland, October 10, 2024
The Aquino and Low sentences are therefore not a separate story from the $3.09 billion institutional fine. They are part of the same underlying failure, now being addressed at the individual level through criminal prosecution alongside the institutional resolution.
Three Compliance Lessons the Case Illustrates
Insider threat is an AML risk, not only a cybersecurity risk.
Most AML program design focuses on external threats: detecting suspicious customer behavior, screening against watchlists, and monitoring transaction patterns. The TD Bank case demonstrates that a significant portion of the risk can come from within. An employee with system access, processing rights, and a willingness to ignore compliance obligations can facilitate hundreds of millions in criminal flows while remaining invisible to controls designed to catch customer-side activity. Insider threat management, including behavioral monitoring of employee actions within AML systems, is a distinct and necessary component of a complete compliance program.
The cost of corrupting a bank employee can be extraordinarily low relative to the damage enabled.
Aquino received $11,000 in retail gift cards in exchange for facilitating $474 million in criminal flows. That is a bribe-to-crime ratio of approximately 0.002%. The criminal network's cost of corrupting a well-positioned bank employee was negligible relative to the value of the access that employee provided. Furthermore, that access was not technical. It was procedural: an employee who processed transactions, identified account holders, and chose not to file the SARs the law required. Compliance programs that assume employees will self-report suspicious activity without supporting controls, monitoring, and accountability structures are exposed to exactly this type of exploitation.
When colleagues flag suspicious activity and it is not acted on, the compliance system has failed at the human layer.
Prosecutors specifically noted that a colleague explicitly told Aquino that Sze's activity "looks like money laundering." He ignored it. That detail is significant from a compliance design perspective. The information needed to detect and stop the scheme was available within the institution. It did not reach the compliance function. A reporting culture that relies solely on voluntary escalation, without structured internal reporting channels, documented follow-up obligations, and whistleblower protections, creates a gap between the knowledge that exists in an organization and the compliance action that knowledge should trigger.
AML training alone is not a control. It is a prerequisite for one.
According to court documents, Aquino received regular training on TD Bank's AML, anti-bribery, and anti-corruption policies throughout the scheme period. That training did not prevent the scheme. Furthermore, Aquino did not just fail to file SARs. He actively falsified Currency Transaction Reports by omitting Sze's identity as the conductor of the transactions. That is a distinct and deliberate BSA violation that training alone was never going to catch. A compliance program that relies on training as a primary control for insider risk, rather than as a foundation for structural monitoring and accountability mechanisms, is not adequately designed for the threat this case describes.
What This Means for Your AML Program
The TD Bank insider sentencing raises four practical questions for compliance and BSA officers at financial institutions of any size:
Does your AML program include monitoring of employee behavior within compliance systems? Transaction monitoring designed to detect suspicious customer activity will not catch an employee who is actively facilitating that activity. Consequently, a complete program should include controls around employee access rights, transaction processing authority, SAR filing patterns, and alert disposition behavior. Anomalies in employee activity within the AML system are themselves risk signals.
Are your internal reporting channels structured, documented, and independent of direct management? In the TD Bank case, colleagues had flagged suspicious activity. That information did not reach the compliance function. Effective internal reporting requires more than an open-door policy. It requires structured channels, documented receipt of reports, follow-up obligations, and protections for the people making reports that are independent of the management chain in the relevant branch or business unit.
Does your transaction monitoring cover the volume and pattern of bank checks and similar instruments? Aquino processed 1,680 bank checks worth more than $92 million across the scheme period. At any reasonable monitoring threshold, that volume should have generated alerts independent of whether the employee processing them chose to escalate. Controls that generate alerts based on transaction volume, instrument type, and counterparty patterns provide a layer of detection that does not depend on employee good faith.
Is your institution's SAR filing rate monitored at the branch and employee level? One of the clearest signals in a case like this is a pattern of SAR non-filing by a specific employee or branch relative to comparable peers. An employee who processes high volumes of transactions but files significantly fewer SARs than expected is generating a statistical anomaly that should be visible in a well-designed compliance monitoring program. Tracking SAR filing rates at the individual and branch level, and investigating outliers, is a control that the TD Bank case demonstrates was absent or insufficient.
The Sentinel Perspective
The TD Bank insider case is a reminder that AML compliance is not only a technology problem. The monitoring system at TD Bank was present. However, an employee with processing rights could route transactions, conceal identities, and suppress SAR filings in a way that the system alone could not catch without the right governance controls in place.
Sentinel's AML compliance platform addresses this from multiple angles. Continuous customer monitoring generates alerts based on transaction behavior independent of the employee processing the transaction. SAR filing workflows create documented decision trails that flag non-filing and require disposition records at each stage. And configurable alert thresholds ensure that volume patterns, such as 1,680 bank checks processed by a single account relationship, surface for review rather than clearing silently through the system.
The question the TD Bank sentencing raises for every compliance program is straightforward: if an employee in your institution chose to ignore suspicious activity today, how many transactions would clear before your controls detected the gap independent of that employee's actions?
See How Sentinel Supports AML Controls That Work Independent of Employee Discretion
Request a demonstration tailored to your institution's AML program and BSA compliance requirements.
Official References and Sources
- Two TD Bank Insiders Sentenced for Facilitating Money Laundering, Fraud — US Attorney's Office, District of New Jersey, July 16, 2026
- Two TD Bank Insiders Sentenced to Prison for Facilitating Money Laundering, Fraud — US Department of Justice Office of Public Affairs, July 16, 2026
- Former TD Bank Manager Pleads Guilty to Money Laundering Conspiracy — IRS Criminal Investigation, January 2026
- Ex-TD Bank Employees Sentenced in Money Laundering Scheme — American Banker, July 21, 2026
Truth Technologies provides AML, KYC, OFAC, and sanctions screening compliance solutions through the Sentinel platform. This post is published for informational purposes only and does not constitute legal advice. All facts are sourced from court records, official DOJ releases, and publicly available reporting linked above.