Learn more about the latest security and privacy threats
Back

The TD Bank $3 Billion Lesson: What 92% Unmonitored Volume Actually Means

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published August 21, 2026 Updated August 21, 2026
Classical bank facade with columns representing the TD Bank three-billion-dollar AML enforcement lesson

TD Bank paid about $3 billion in 2024 for AML failures, with most volume unmonitored. Here's the scope gap, and what every bank should audit this quarter.

Table of contents
  • In October 2024, TD Bank pleaded guilty and paid about $3 billion across US authorities for Bank Secrecy Act and money-laundering failures, the largest bank ever to plead guilty to conspiracy to commit money laundering.
  • The penalties split roughly into about $1.8 billion to the Department of Justice, $1.3 billion to FinCEN (its largest ever penalty on a depository institution), $450 million to the OCC, and $123.5 million to the Federal Reserve.
  • The defining failure: from January 2018 to April 2024, TD Bank left more than 90 percent of its transaction volume, around $18.3 trillion, outside its monitoring scope.
  • Whole product categories, including domestic automated clearing house and check activity, were excluded from automated monitoring, a scope decision, not a missed alert.
  • Three money-laundering networks moved more than $670 million through the bank as a result, and a multi-year independent monitorship was imposed.
  • The TD Bank AML fine is a coverage-and-architecture lesson: the most dangerous gap is the activity your monitoring never looks at.

The TD Bank AML fine refers to the roughly $3 billion in penalties US authorities imposed in October 2024 after the bank admitted Bank Secrecy Act and money-laundering failures, having left more than 90 percent of its transaction volume unmonitored. Its core lesson is about monitoring scope, not alert quality.

TL;DR

In October 2024, TD Bank pleaded guilty and paid about $3 billion to US authorities, the largest bank ever to plead guilty to conspiracy to commit money laundering. The numbers split into roughly $1.8 billion to the DOJ, $1.3 billion to FinCEN (its largest penalty ever on a depository institution), $450 million to the OCC, and $123.5 million to the Federal Reserve, with a multi-year monitorship attached.

The headline that matters most is not the dollar figure but the coverage figure: from January 2018 to April 2024, TD Bank left more than 90 percent of its transaction volume, around $18.3 trillion, outside automated monitoring, with whole categories like domestic automated clearing house and check activity excluded from scope. Three laundering networks exploited the gap, moving more than $670 million. This piece breaks down what unmonitored volume means, how the scope gap happened, where it could have been caught, and what every bank should audit now.

9 min read. Last updated 21 October 2026.

What happened in the TD Bank AML case?

In October 2024, TD Bank entered guilty pleas and agreed to pay approximately $3 billion across four US authorities for systemic Bank Secrecy Act and anti-money-laundering failures. It was the largest bank ever to plead guilty to conspiracy to commit money laundering, a landmark in US enforcement. The penalties comprised roughly $1.8 billion to the Department of Justice (including a criminal fine and forfeiture), $1.3 billion to FinCEN, which FinCEN noted was its largest penalty ever against a depository institution, $450 million to the Office of the Comptroller of the Currency, and $123.5 million to the Federal Reserve, alongside a multi-year independent monitorship.

The authorities found that for years TD Bank's AML program was fundamentally inadequate, and the most striking finding was the scale of what went unwatched. The TD Bank AML fine became the reference case of 2024 precisely because the failure was not a single missed transaction but a structural gap in what the bank monitored at all, which our AML transaction monitoring guide treats as the foundational control.

What does 90 percent unmonitored actually mean?

The figure that defines the case is coverage. US authorities found that from January 2018 to April 2024, TD Bank did not monitor more than 90 percent of its transaction volume, an amount totalling around $18.3 trillion. That does not mean the monitoring system generated too many false positives or missed subtle patterns; it means the activity was never fed into automated monitoring in the first place.

This is a different and more dangerous failure than a tuning problem. A bank with a noisy monitoring system at least looks at the activity; a bank with a scope gap is blind to it entirely. No amount of analyst effort or model sophistication helps with transactions the system never sees. That is why the TD Bank AML fine is best understood as a coverage failure: the question every bank should ask is not only how good is our monitoring, but what percentage of our actual transaction volume does it even cover.

How did the monitoring-scope gap happen?

The gap came from scope exclusions. According to the authorities, whole categories of activity, including domestic automated clearing house transactions and certain check activity, were left outside the automated transaction-monitoring program. Once a category is excluded from scope, every transaction in it passes unwatched, no matter how suspicious, and the exclusions persisted for years.

The uncomfortable part is that a scope exclusion is a decision, made and approved at some point, not an accident. Someone configured the monitoring boundaries, and the categories outside them grew into the majority of the bank's volume. This is how a coverage gap of this magnitude forms quietly: not through a dramatic failure but through scope choices that are never revisited as the business grows, the same architectural blind spot we describe in why your KYC vendor is your biggest data breach risk. The lesson is to treat monitoring scope as a living, audited decision, not a set-and-forget configuration.

Where could TD Bank have caught it?

A failure this large had many points where it could have surfaced. A periodic independent review of the AML program would have been expected to test coverage, not just alert quality, and ask what proportion of volume was monitored. A model-validation or program-effectiveness exercise should have flagged that whole product categories sat outside scope. And ongoing governance, the kind of program oversight a board and senior management owe, should have caught a coverage figure drifting toward a minority of total volume.

The recurring theme is that the gap was discoverable by anyone who measured coverage rather than assuming it. Most AML assurance focuses on whether alerts are handled well; far fewer routinely measure what share of activity generates alerts at all. The TD Bank AML fine is a reminder that the cheapest, highest-value control review is often the simplest question: what are we not monitoring, and why. That governance discipline is the same one behind model validation for AI in compliance.

What is the architectural lesson for banks?

The architectural lesson is that coverage is a first-class control, equal to detection quality. A monitoring program is only as good as the proportion of activity it actually sees, and a sophisticated engine watching half your volume is weaker than a simple one watching all of it. Banks tend to invest in better detection while assuming coverage is complete; TD Bank shows the assumption is the risk.

The corollary is that monitoring scope must be governed and re-validated as the business changes. New products, new channels, and growth in existing categories all change what should be in scope, and a boundary set years ago will not still be right. Building the program so coverage is measured continuously, with any exclusion documented, justified, and reviewed, turns the silent scope gap into a visible, managed decision. That is the difference between TD Bank's posture and a defensible one.

What should a mid-market bank audit this quarter?

The TD Bank AML fine translates into a concrete checklist any bank can run now. Measure monitoring coverage: what percentage of transaction volume, by count and value, actually flows through automated monitoring, and what is excluded. Inventory every scope exclusion: which product categories, channels, or transaction types are outside monitoring, when each was excluded, who approved it, and whether the justification still holds. Test the exclusions against current volume: an exclusion that covered a trivial category five years ago may now hide a large share of activity.

Then validate governance: is coverage reported to senior management and the board, and is it re-assessed when products or volumes change. A bank that can answer these, with documentation, is in a fundamentally stronger position than one that assumes its monitoring sees everything. The audit is not glamorous, but it is the one that would have caught the TD Bank gap, and it pairs with the broader audit-ready compliance stack approach.

When is a monitoring scope decision defensible?

Not every exclusion is a failure; some scoping is legitimate and necessary, and the lesson is not to monitor literally everything identically. A risk-based program can reasonably apply different monitoring intensity to genuinely low-risk, low-value activity, and can scope certain internal or non-customer transactions differently, provided the decision is risk-assessed, documented, and proportionate.

What makes a scope decision defensible is exactly what TD Bank lacked: a documented risk rationale, senior approval, and periodic review against current volume and risk. What makes it indefensible is an undocumented, unrevisited exclusion that quietly grows to cover the majority of activity. The test is whether you can show a regulator, for everything outside monitoring, why it is out and that you check the decision still holds. If you cannot, that is the gap to close before it becomes your TD Bank moment. Book a coverage review to pressure-test your scope.

The bottom line

The TD Bank AML fine is remembered for its size, but its real lesson is about coverage. A bank can run a sophisticated monitoring engine and still fail catastrophically if most of its volume never enters scope, and that is exactly what happened: more than 90 percent of activity, around $18.3 trillion, unmonitored for years because whole categories were excluded by a decision no one revisited.

Treat monitoring coverage as a governed, measured, first-class control. Inventory and justify every exclusion, test it against current volume, and report it up. The audit that would have caught TD Bank is simple and unglamorous, and it is the one most worth running this quarter.

Book a monitoring-coverage review, or see how it works.

Cited sources

  • US Department of Justice, TD Bank guilty plea (October 2024): https://www.justice.gov/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-and-money-laundering-conspiracy-violations-23-billion
  • FinCEN, TD Bank enforcement action: https://www.fincen.gov/news/news-releases
  • Office of the Comptroller of the Currency, enforcement actions: https://www.occ.gov/news-issuances/news-releases/index-news-releases.html
  • Federal Reserve, enforcement actions: https://www.federalreserve.gov/newsevents/pressreleases.htm
  • FATF Recommendations: https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

In October 2024, TD Bank pleaded guilty and agreed to pay about $3 billion to US authorities for Bank Secrecy Act and money-laundering failures, the largest bank ever to plead guilty to conspiracy to commit money laundering. The total split roughly into $1.8 billion to the DOJ, $1.3 billion to FinCEN, $450 million to the OCC, and $123.5 million to the Federal Reserve, with a multi-year monitorship.

It means that from January 2018 to April 2024, more than 90 percent of TD Bank's transaction volume, around $18.3 trillion, was never fed into automated transaction monitoring. This is a coverage failure, not a tuning one: the activity was outside scope entirely, so no alert could ever fire on it, regardless of how suspicious individual transactions were.

A false-positive problem means your system is at least looking at the activity and generating too many alerts. A scope gap means the activity is invisible to monitoring, so genuinely suspicious transactions pass entirely unexamined. No analyst effort or model improvement helps with transactions the system never sees, which is why coverage is a more fundamental control than detection quality.

Authorities found that whole categories were excluded from automated monitoring, including domestic automated clearing house transactions and certain check activity. Because these categories were outside scope, transactions in them passed unwatched for years, and they grew to represent the large majority of the bank's total volume, enabling laundering networks to exploit the gap.

Authorities found that three money-laundering networks moved more than $670 million through TD Bank accounts during the period of the failures. This activity flowed through precisely because the relevant transactions sat outside the bank's monitoring scope, illustrating how a coverage gap translates directly into facilitated illicit flows rather than remaining a theoretical control weakness.

That monitoring coverage is a first-class control, equal to detection quality. Banks should measure what percentage of transaction volume actually flows through monitoring, inventory and justify every scope exclusion, test exclusions against current volume, and report coverage to senior management. The cheapest high-value review is simply asking what is not being monitored and why.

It was among the largest and set records: FinCEN described its $1.3 billion component as its largest ever penalty against a depository institution, and TD Bank was the largest bank to plead guilty to conspiracy to commit money laundering. The roughly $3 billion total across agencies made it one of the most significant US AML enforcement outcomes to date.

Measure coverage continuously, document and risk-justify every exclusion, assign senior approval to scope decisions, and re-validate scope whenever products, channels, or volumes change. Treat the monitoring boundary as a living, audited decision rather than a set-and-forget configuration, so any category that grows in significance is reassessed before it becomes a blind spot.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML