When Christopher A. Bravo Marin allegedly helped launder at least $750,000 in drug proceeds for the Cártel de Jalisco Nueva Generación, he didn't hack the system. According to the US Department of Justice indictment, he simply knew which thresholds to avoid, which forms could be forged, and which patterns wouldn't trigger alerts at the Minnesota money transmitter where he worked. He was paid $40 to $50 per transfer, and the scheme allegedly ran for three years before it was detected.
Your AML controls aren't designed to stop someone who already knows how they work. That's the problem.
Why These Mistakes Keep Happening
Most AML programs are built to catch external threats: customers who lie, transactions that look suspicious, patterns that match known typologies. The controls assume the person processing the transaction is trying to stop the crime, not enable it.
That assumption creates blind spots. An employee with system access knows exactly what triggers a review, what stays below the radar, and how to make fraudulent activity look routine. They don't need to override the controls. They just need to structure the activity so the controls never activate.
The mistakes below aren't about missing policies. They're about designing controls that treat every transaction as if it's being processed in good faith, even when the processor has every reason to circumvent them.
Mistake 1: Treating Thresholds as Binary Gates
Why it happens: Your $1,000 verification threshold exists to catch large, risky transactions. It's clear, it's measurable, and it's easy to enforce. But clarity cuts both ways.
The consequence: In the Bravo case, transfers were kept just below $1,000, the company's threshold for collecting and verifying customer identification. The control worked exactly as designed. It just never got triggered. Multiple $950 transfers from different "senders" don't look like a $10,000 laundering operation when you're only reviewing transactions that cross the line.
The fix: Monitor activity around the threshold, not just above it. Flag customers or employees with repeated transactions in the 80-95% range. If someone consistently transfers $980, they're not being cautious. They're being precise. Your monitoring system should track cumulative activity over rolling time periods and alert on patterns that suggest deliberate structuring, even when no single transaction violates policy.
Mistake 2: Siloing Transaction Reviews by Employee
Why it happens: You review transactions for suspicious patterns. You may even review them by customer. But do you review them by the employee who processed them? Most systems don't, because the assumption is that the employee is the control, not the risk.
The consequence: An insider can process dozens of suspicious transactions without detection, as long as each one looks clean in isolation. If your compliance team only sees the transaction, not who handled it, they'll miss the pattern. One employee processing an unusual concentration of just-below-threshold transfers to the same region should raise questions. But if those transactions are scattered across your review queue with no employee-level aggregation, you won't see it.
The fix: Build employee-level transaction monitoring into your compliance workflow. Track which staff members are processing high volumes of transactions that share common characteristics: same destination country, same amount range, same beneficiary naming patterns. Run quarterly reviews that flag employees whose transaction mix differs significantly from their peers. This isn't about distrust. It's about recognizing that concentration risk applies to people, not just portfolios.
Mistake 3: Assuming Documentation Accuracy
Why it happens: Your process requires a signed receipt. Your audit trail shows the receipt was generated. The system logged it. Everything looks compliant.
The consequence: According to prosecutors, Bravo forged the senders' signatures on payment confirmation receipts and sent screenshots of those receipts to his co-conspirators. The documentation existed. It just wasn't real. If your compliance review stops at "receipt on file," you're checking a box, not validating a transaction.
The fix: Implement random spot-checks that verify documentation against independent sources. Call back a sample of senders to confirm they authorized the transaction. Compare signatures across multiple transactions from the same customer. Require manager co-signature on transactions processed outside normal patterns, even if they're below the threshold. The goal isn't to catch every forged document. It's to make forgery risky enough that an insider thinks twice.
Mistake 4: Relying on Automated Alerts Without Human Pattern Recognition
Why it happens: Your transaction monitoring system is sophisticated. It scans for structuring, unusual destinations, velocity anomalies. It generates alerts. But automated systems look for deviations from normal patterns. An insider's job is to make the abnormal look normal.
The consequence: Fake sender names and straw beneficiaries in Mexico were allegedly used to receive the funds. If each sender name is unique and each beneficiary is a real person in the destination country, your system may not flag it. The algorithm sees variety. A human analyst might see a pattern: same employee, same transfer amount, same destination city, different names every time.
The fix: Schedule manual reviews of employee transaction logs, independent of automated alerts. Have a senior compliance analyst spend an hour each month reviewing a sample of transactions from each high-volume employee. Look for things machines miss: repetitive phrasing in transaction notes, beneficiaries whose names follow similar structures, or transfers that cluster around shift changes or coverage gaps. Train your team to ask, "If I wanted to launder money through this system, how would I do it?" Then look for those exact patterns.
Mistake 5: Underestimating the Value of Small Bribes
Why it happens: You think about insider risk in terms of major fraud: embezzlement, account takeovers, large-scale theft. A $40 payment per transaction doesn't sound like enough to corrupt an employee.
The consequence: Small, repeated payments add up. At $40 per transfer, processing 20 transactions a week generates $800 in untraceable cash. Over three years, that's over $120,000. More importantly, small bribes don't require the employee to make a single large, career-ending decision. They require a series of small compromises that feel manageable in the moment.
The fix: Train employees to recognize incremental corruption. Include scenarios in your annual compliance training that show how small favors escalate. Make it clear that any payment from a customer, regardless of size, must be reported. Implement confidential reporting channels where employees can disclose offers or pressure without fear of retaliation. And pay attention to lifestyle changes: an employee whose spending patterns shift without a corresponding salary increase may be receiving unreported income.
Prevention Checklist
Use this to audit your current AML controls for insider risk:
- Transaction monitoring includes employee-level aggregation and pattern analysis
- Thresholds trigger reviews of near-miss activity, not just violations
- Random documentation spot-checks verify authenticity, not just existence
- Manual compliance reviews supplement automated alerts on a regular schedule
- Employees cannot process transactions for the same customer/region repeatedly without secondary approval
- Training includes specific scenarios about incremental corruption and small bribes
- Confidential reporting channels allow employees to disclose customer pressure or inducements
- Quarterly audits compare individual employee transaction patterns against peer benchmarks
- System logs capture which employee processed each transaction, and that data is reviewable by compliance
- Segregation of duties prevents any single employee from initiating, approving, and documenting a transaction
Your AML program works when people follow the rules. Make sure it still works when someone knows exactly how to avoid them.



