FIN 341 Module 5 Milestone Three Example

Reviewed by Portia Lambrick, MBA

This FIN 341 Module 5 Milestone Three sample identifies the system flaws that allowed a financial firm's legal and ethical failures to continue, completing the analysis before the final project's recommendations. SNHU FIN 341 (FIN-341) uses this third milestone of its BS Finance project to ask how an organization's structures, processes and technology failed. For the TD Bank case, the paper sorts the flaws by the main components of internal control and by the bank's three lines of defense, from board oversight to transaction monitoring and branch controls. For each flaw it proposes a specific test the composite Connecticut client bank can run on its own anti-money laundering program.

CourseFIN 341 Financial Regulations and Ethics
ModuleModule 5
Paper typeundergraduate milestone analyzing the internal control and system flaws behind a compliance failure
LengthAbout 1,020 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramBS Finance
UpdatedOctober 2026

Free sample paper for FIN 341 Module 5

1

System Flaws Analysis: How TD Bank's Controls Failed

[Student Name]

Southern New Hampshire University

FIN 341: Financial Regulations and Ethics

Milestone Three

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe client bank and advisory firm are composites; facts about TD Bank come from public enforcement records.
2

System Flaws Analysis: How TD Bank's Controls Failed

Introduction

Milestone One described TD Bank's anti-money laundering failures, and Milestone Two analyzed the ethical choices behind them. This milestone asks why the bank's systems did not stop those choices from becoming a decade-long failure. For the Hartford bank's risk committee, this is the most practical part of the analysis: system flaws can be tested and fixed in a way that culture cannot be ordered into existence.

What this page is doingStates what this milestone adds to the first two.
3

Framework

The analysis uses two familiar lenses. The first breaks a control system into five working parts: the example leaders set and the oversight they give, how the bank judges where its risks lie, the specific checks that answer those risks, the way warnings travel and the follow-up that tests whether the checks still work. The second is the three lines of defense: business units that own risk, independent compliance and risk functions that set standards and challenge, and internal audit that reports to the board. Ellul and Yerramilli (2013) found that U.S. bank holding companies with stronger, more independent risk management functions took less risk and fared better in the 2007-2009 crisis, evidence that the structure of control functions matters, not only the people in them.

What this page is doingExplains the two lenses used.
4

Governance and Tone

The board and senior executives received internal and regulatory warnings that the anti-money laundering program was falling behind, yet kept its budget roughly flat (U.S. Department of Justice, 2024). Governance failed in two ways. Information reached leaders but did not change decisions, and no one with authority was accountable for matching compliance resources to the bank's growth. Every other flaw below follows from this one.

What this page is doingThe root flaw.
5

Risk Assessment

A bank's anti-money laundering risk assessment should be updated as products, customers and volumes change. TD expanded its branches and payment volume for years, but its assessment of where money laundering risk sat did not keep pace, so the program was sized for a smaller, simpler bank. Levi and Reuter (2006) note that the system depends on banks assessing their own risks honestly; a stale assessment quietly lowers every control built on it.

What this page is doingThe program did not grow with the bank.
6

Control Activities

The most striking flaw was in automated monitoring. For years, domestic ACH transfers and most check activity were excluded from transaction monitoring, and over a six-year period about $18.3 trillion of activity went unmonitored. Rules that did exist were not updated as criminals adapted. At the branch level, controls relied on employees to notice and escalate unusual cash deposits; when some of those employees were paid in gift cards, there was no second control, such as an automatic review of large repeated cash deposits by someone outside the branch.

What this page is doingMonitoring that missed whole categories.
7

Information and Escalation

Even when systems produced alerts, investigation teams were too small to work them quickly, so queues grew and alerts aged. Patterns that analysts flagged were not always escalated, and suspicious activity reports were sometimes late or missing. Information existed inside the bank; it did not travel to people who would act on it.

What this page is doingAlerts that did not lead to action.
8

Monitoring and Audit

Internal audit and regulators identified weaknesses, but remediation was slow and findings stayed open. The third line of defense did its job of finding problems, while the first and second lines did not fix them, and the board did not insist on deadlines.

What this page is doingFindings that stayed open.
9

Flaws, Evidence and Tests

System flaws at TD Bank and tests for the client bank

FlawEvidence in the TD caseTest for the Hartford bank
Governance did not act on warningsFlat compliance budget despite reviewsCompare compliance spending growth with asset and transaction growth over five years
Stale risk assessmentProgram sized for a smaller bankCheck the date and scope of the last enterprise-wide risk assessment
Monitoring coverage gapsACH and check activity excluded; $18.3 trillion unmonitoredMeasure the share of transaction volume, by payment type, covered by monitoring rules
Understaffed investigationsGrowing alert queuesReview alert aging and investigator caseloads each month
Single-point branch controlsEmployees bribed with gift cardsConfirm that large repeated cash deposits are reviewed outside the branch
Slow remediationFindings left openTrack the number and age of open audit and exam findings at every board meeting
What this page is doingThe table the client can act on.
10

How the Flaws Reinforced Each Other

The flaws did not act one at a time. A flat budget meant fewer investigators, so alert queues grew; long queues pushed managers to close alerts quickly, which taught analysts that speed mattered more than judgment. Gaps in monitoring coverage meant that the alerts which did fire came mostly from cash activity at branches, where the front-line control was weakest. Slow remediation meant that each year's audit findings were added to the last year's, so the backlog itself became a reason not to start. And because governance treated each finding as a separate cost request rather than evidence of a failing program, no one added up the picture. This chain is the most useful lesson for the Hartford client: its committee should look at the six tests together, because a modest weakness in each can combine into the same kind of failure TD suffered. A quarterly dashboard that puts budget growth, coverage, alert aging and open findings on one page would let the board see the chain forming rather than one link at a time.

What this page is doingShows the interaction, which the rubric rewards.
11

Ranking the Flaws

The flaws are connected, but they are not equal. Governance ranks first, because a board that funded compliance in step with growth and held executives to deadlines would have fixed the other five. Monitoring coverage ranks second, because it allowed the largest volume of activity to escape review. Single-point branch controls rank third: they let a handful of corrupted employees move hundreds of millions of dollars. The remaining flaws made matters worse but would have been caught if the first three had been sound.

What this page is doingSays which flaw mattered most.
12

Conclusion

TD's failures were not the product of one bad system but of a governance choice that starved every system downstream. The Hartford bank can test all six areas within one quarter, using data it already holds: budget history, monitoring rule inventories, alert aging reports and the audit tracker. None of the tests requires outside consultants, though an independent review would add credibility with examiners. The final project will turn these findings into prioritized recommendations.

What this page is doingSets up the final project.
13

References

Ellul, A., & Yerramilli, V. (2013). Stronger risk controls, lower risk: Evidence from U.S. bank holding companies. The Journal of Finance, 68(5), 1757-1803. https://doi.org/10.1111/jofi.12057

Levi, M., & Reuter, P. (2006). Money laundering. Crime and Justice, 34(1), 289-375. https://doi.org/10.1086/501508

U.S. Department of Justice. (2024, October 10). TD Bank pleads guilty to Bank Secrecy Act and money laundering conspiracy violations in $1.8B resolution [Press release]. https://www.justice.gov/archives/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-and-money-laundering-conspiracy-violations-18b

What the FIN 341 Module 5 instructions ask for

Milestone Three of the FIN 341 project typically asks you to analyze the system flaws that allowed the incident to happen or continue: weaknesses in governance, internal controls, technology, policies, training, oversight or incentives. Some versions ask you to evaluate how the company's compliance program was designed and why it failed, or to identify which flaws were most responsible. The goal is to show how the organization's systems turned individual decisions into a lasting failure, so the analysis should be concrete, naming the specific control or process that broke. This milestone feeds directly into the final project's recommendations, so each flaw should be described in a way that suggests a fix.

How this FIN 341 Module 5 milestone three example is built

This sample organizes TD's system flaws around the parts of an internal control system and the three lines of defense. It describes a governance flaw, in which the board and executives heard warnings but kept budgets flat; a risk assessment that never caught up with the bank's growth; monitoring rules that left whole categories of payments unexamined; investigation queues without enough staff; branch controls that bribed employees could bypass; and audit findings that stayed open. A table pairs each flaw with evidence and a test the composite Hartford bank can run, such as comparing transaction volume covered by monitoring with total volume. The paper ends by ranking the flaws and identifying governance as the root.

Where the FIN 341 Module 5 rubric puts the points

The milestone rubric generally evaluates identification of system flaws, use of evidence from the case, analysis of how the flaws contributed to the incident, use of a framework or structure, and clarity. High-scoring work names specific processes and controls, shows how flaws interacted and ranks them by importance rather than listing them. It also distinguishes the system flaw from the individual misconduct it enabled. Points are lost for repeating the ethical analysis from Milestone Two, for vague flaws such as "lack of oversight" with no evidence, and for flaws that do not connect to the facts of the case. Tables that link each flaw to evidence are often rewarded.

FIN 341 Module 5 help: the mistakes that cost points

Many students repeat Milestone One's facts under new headings. Instead, ask of each fact: which system should have stopped this, and why did it not? A cash deposit pattern that went unreported points to monitoring rules, staffing or escalation. A budget decision points to governance and risk assessment. Use a recognized structure, such as the parts of internal control or the three lines of defense, so the reader can see you have covered the whole system. Rank the flaws and say which one, if fixed, would have prevented the most harm. Write each flaw as a testable statement, because the final project's recommendations will be stronger if they answer clear findings.

Get FIN 341 Module 5 written to your instructions

Send the Milestone Three directions for FIN 341 along with the case work from earlier parts of the project. The sample identifies the system and control failures in your case, sorts them by a recognized framework and links each to a test or fix. Usually two days; your first milestone is free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More FIN 341 papers and related BS Finance samples

FIN 341 Module 5 questions, answered

Where can I find a free FIN 341 Module 5 Milestone Three sample?

This page has the full FIN 341 Module 5 Milestone Three: the system and control flaws behind TD Bank's failures, each paired with a test for a client bank.

What are the three lines of defense?

A model in which business units own and manage risk, independent risk and compliance functions set standards and monitor, and internal audit gives independent assurance to the board.

What are the parts of an internal control system?

Common frameworks look at leadership's oversight and example, how risks are identified, the checks that respond to them, how information moves and whether anyone tests that the checks still work.

What is transaction monitoring in banking?

Automated systems that scan customer transactions against rules or models to flag activity that may indicate money laundering or fraud for investigation.

Why do compliance systems fail?

Usually because they are underfunded, poorly designed for the firm's actual risks, not tested, or ignored when their findings conflict with business goals.