| Course | FIN 341 Financial Regulations and Ethics |
|---|---|
| Module | Module 5 |
| Paper type | undergraduate milestone analyzing the internal control and system flaws behind a compliance failure |
| Length | About 1,020 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Finance |
| Updated | October 2026 |
Free sample paper for FIN 341 Module 5
System Flaws Analysis: How TD Bank's Controls Failed
[Student Name]
Southern New Hampshire University
FIN 341: Financial Regulations and Ethics
Milestone Three
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
System Flaws Analysis: How TD Bank's Controls Failed
Introduction
Milestone One described TD Bank's anti-money laundering failures, and Milestone Two analyzed the ethical choices behind them. This milestone asks why the bank's systems did not stop those choices from becoming a decade-long failure. For the Hartford bank's risk committee, this is the most practical part of the analysis: system flaws can be tested and fixed in a way that culture cannot be ordered into existence.
Framework
The analysis uses two familiar lenses. The first breaks a control system into five working parts: the example leaders set and the oversight they give, how the bank judges where its risks lie, the specific checks that answer those risks, the way warnings travel and the follow-up that tests whether the checks still work. The second is the three lines of defense: business units that own risk, independent compliance and risk functions that set standards and challenge, and internal audit that reports to the board. Ellul and Yerramilli (2013) found that U.S. bank holding companies with stronger, more independent risk management functions took less risk and fared better in the 2007-2009 crisis, evidence that the structure of control functions matters, not only the people in them.
Governance and Tone
The board and senior executives received internal and regulatory warnings that the anti-money laundering program was falling behind, yet kept its budget roughly flat (U.S. Department of Justice, 2024). Governance failed in two ways. Information reached leaders but did not change decisions, and no one with authority was accountable for matching compliance resources to the bank's growth. Every other flaw below follows from this one.
Risk Assessment
A bank's anti-money laundering risk assessment should be updated as products, customers and volumes change. TD expanded its branches and payment volume for years, but its assessment of where money laundering risk sat did not keep pace, so the program was sized for a smaller, simpler bank. Levi and Reuter (2006) note that the system depends on banks assessing their own risks honestly; a stale assessment quietly lowers every control built on it.
Control Activities
The most striking flaw was in automated monitoring. For years, domestic ACH transfers and most check activity were excluded from transaction monitoring, and over a six-year period about $18.3 trillion of activity went unmonitored. Rules that did exist were not updated as criminals adapted. At the branch level, controls relied on employees to notice and escalate unusual cash deposits; when some of those employees were paid in gift cards, there was no second control, such as an automatic review of large repeated cash deposits by someone outside the branch.
Information and Escalation
Even when systems produced alerts, investigation teams were too small to work them quickly, so queues grew and alerts aged. Patterns that analysts flagged were not always escalated, and suspicious activity reports were sometimes late or missing. Information existed inside the bank; it did not travel to people who would act on it.
Monitoring and Audit
Internal audit and regulators identified weaknesses, but remediation was slow and findings stayed open. The third line of defense did its job of finding problems, while the first and second lines did not fix them, and the board did not insist on deadlines.
Flaws, Evidence and Tests
System flaws at TD Bank and tests for the client bank
| Flaw | Evidence in the TD case | Test for the Hartford bank |
|---|---|---|
| Governance did not act on warnings | Flat compliance budget despite reviews | Compare compliance spending growth with asset and transaction growth over five years |
| Stale risk assessment | Program sized for a smaller bank | Check the date and scope of the last enterprise-wide risk assessment |
| Monitoring coverage gaps | ACH and check activity excluded; $18.3 trillion unmonitored | Measure the share of transaction volume, by payment type, covered by monitoring rules |
| Understaffed investigations | Growing alert queues | Review alert aging and investigator caseloads each month |
| Single-point branch controls | Employees bribed with gift cards | Confirm that large repeated cash deposits are reviewed outside the branch |
| Slow remediation | Findings left open | Track the number and age of open audit and exam findings at every board meeting |
How the Flaws Reinforced Each Other
The flaws did not act one at a time. A flat budget meant fewer investigators, so alert queues grew; long queues pushed managers to close alerts quickly, which taught analysts that speed mattered more than judgment. Gaps in monitoring coverage meant that the alerts which did fire came mostly from cash activity at branches, where the front-line control was weakest. Slow remediation meant that each year's audit findings were added to the last year's, so the backlog itself became a reason not to start. And because governance treated each finding as a separate cost request rather than evidence of a failing program, no one added up the picture. This chain is the most useful lesson for the Hartford client: its committee should look at the six tests together, because a modest weakness in each can combine into the same kind of failure TD suffered. A quarterly dashboard that puts budget growth, coverage, alert aging and open findings on one page would let the board see the chain forming rather than one link at a time.
Ranking the Flaws
The flaws are connected, but they are not equal. Governance ranks first, because a board that funded compliance in step with growth and held executives to deadlines would have fixed the other five. Monitoring coverage ranks second, because it allowed the largest volume of activity to escape review. Single-point branch controls rank third: they let a handful of corrupted employees move hundreds of millions of dollars. The remaining flaws made matters worse but would have been caught if the first three had been sound.
Conclusion
TD's failures were not the product of one bad system but of a governance choice that starved every system downstream. The Hartford bank can test all six areas within one quarter, using data it already holds: budget history, monitoring rule inventories, alert aging reports and the audit tracker. None of the tests requires outside consultants, though an independent review would add credibility with examiners. The final project will turn these findings into prioritized recommendations.
References
Ellul, A., & Yerramilli, V. (2013). Stronger risk controls, lower risk: Evidence from U.S. bank holding companies. The Journal of Finance, 68(5), 1757-1803. https://doi.org/10.1111/jofi.12057
Levi, M., & Reuter, P. (2006). Money laundering. Crime and Justice, 34(1), 289-375. https://doi.org/10.1086/501508
U.S. Department of Justice. (2024, October 10). TD Bank pleads guilty to Bank Secrecy Act and money laundering conspiracy violations in $1.8B resolution [Press release]. https://www.justice.gov/archives/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-and-money-laundering-conspiracy-violations-18b
What the FIN 341 Module 5 instructions ask for
Milestone Three of the FIN 341 project typically asks you to analyze the system flaws that allowed the incident to happen or continue: weaknesses in governance, internal controls, technology, policies, training, oversight or incentives. Some versions ask you to evaluate how the company's compliance program was designed and why it failed, or to identify which flaws were most responsible. The goal is to show how the organization's systems turned individual decisions into a lasting failure, so the analysis should be concrete, naming the specific control or process that broke. This milestone feeds directly into the final project's recommendations, so each flaw should be described in a way that suggests a fix.
How this FIN 341 Module 5 milestone three example is built
This sample organizes TD's system flaws around the parts of an internal control system and the three lines of defense. It describes a governance flaw, in which the board and executives heard warnings but kept budgets flat; a risk assessment that never caught up with the bank's growth; monitoring rules that left whole categories of payments unexamined; investigation queues without enough staff; branch controls that bribed employees could bypass; and audit findings that stayed open. A table pairs each flaw with evidence and a test the composite Hartford bank can run, such as comparing transaction volume covered by monitoring with total volume. The paper ends by ranking the flaws and identifying governance as the root.
Where the FIN 341 Module 5 rubric puts the points
The milestone rubric generally evaluates identification of system flaws, use of evidence from the case, analysis of how the flaws contributed to the incident, use of a framework or structure, and clarity. High-scoring work names specific processes and controls, shows how flaws interacted and ranks them by importance rather than listing them. It also distinguishes the system flaw from the individual misconduct it enabled. Points are lost for repeating the ethical analysis from Milestone Two, for vague flaws such as "lack of oversight" with no evidence, and for flaws that do not connect to the facts of the case. Tables that link each flaw to evidence are often rewarded.
FIN 341 Module 5 help: the mistakes that cost points
Many students repeat Milestone One's facts under new headings. Instead, ask of each fact: which system should have stopped this, and why did it not? A cash deposit pattern that went unreported points to monitoring rules, staffing or escalation. A budget decision points to governance and risk assessment. Use a recognized structure, such as the parts of internal control or the three lines of defense, so the reader can see you have covered the whole system. Rank the flaws and say which one, if fixed, would have prevented the most harm. Write each flaw as a testable statement, because the final project's recommendations will be stronger if they answer clear findings.
Get FIN 341 Module 5 written to your instructions
Send the Milestone Three directions for FIN 341 along with the case work from earlier parts of the project. The sample identifies the system and control failures in your case, sorts them by a recognized framework and links each to a test or fix. Usually two days; your first milestone is free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More FIN 341 papers and related BS Finance samples
- FIN 341 Module 1 Discussion: Why a Bank's Convenience Needs Rules
- FIN 341 Module 2 Milestone One: The TD Bank Incident and Its Compliance Challenges
- FIN 341 Module 3 Milestone Two: The Ethical Violations Behind the Case
- FIN 341 Module 4 Regulatory Framework Assignment: Who Regulates a Bank Like TD
- FIN 341 Module 6 Discussion: Speaking Up Inside a Bank
- ACC 201 Module 6 Receivables and Long-Term Assets Short Paper
- ACC 421 Module 4 Project One: A Revenue and Receivables Audit Program
- ACC 423 Module 1 Discussion: Why Good Managers Bend the Numbers
- FIN 335 Module 7 Project Two: A Plan to Manage Interest Rate Risk
FIN 341 Module 5 questions, answered
Where can I find a free FIN 341 Module 5 Milestone Three sample?
This page has the full FIN 341 Module 5 Milestone Three: the system and control flaws behind TD Bank's failures, each paired with a test for a client bank.
What are the three lines of defense?
A model in which business units own and manage risk, independent risk and compliance functions set standards and monitor, and internal audit gives independent assurance to the board.
What are the parts of an internal control system?
Common frameworks look at leadership's oversight and example, how risks are identified, the checks that respond to them, how information moves and whether anyone tests that the checks still work.
What is transaction monitoring in banking?
Automated systems that scan customer transactions against rules or models to flag activity that may indicate money laundering or fraud for investigation.
Why do compliance systems fail?
Usually because they are underfunded, poorly designed for the firm's actual risks, not tested, or ignored when their findings conflict with business goals.