AML controls are designed to stop criminals moving illicit money through the financial system. But what happens when the person helping to move that money understands those controls better than anyone trying to detect the abuse?
A recent US case offers a clear example.
On 25 August, the US Department of Justice announced the indictment of Christopher A. Bravo Marin, a 46-year-old Minnesota man accused of conspiring to launder at least $750K in drug proceeds for the Cártel de Jalisco Nueva Generación (CJNG). Prosecutors allege that he used his position at a Minnesota-based money transmitting business and, crucially, his knowledge of its AML procedures, to help move the money to Mexico while deliberately avoiding the company’s safeguards.
The allegations are a reminder that AML controls do not operate in a vacuum. The people subject to those controls may understand exactly how they work, what triggers them and where their weaknesses lie.
Knowing the rules and working around them
According to the indictment, the activity took place between February 2023 and February 2026.
Prosecutors say Bravo worked with members of a CJNG drug distribution cell to transfer drug proceeds through the money transmitter where he was employed. He was paid approximately $40 to $50 for each transfer he helped process.
The method he used was systematic.
Transfers were kept just below $1,000, the company’s threshold for collecting and verifying customer identification. Rather than making one large transfer, the money was broken down into multiple transactions designed to stay beneath that threshold.
Fake sender names were created, while straw beneficiaries in Mexico were used to receive the funds. The indictment says that Bravo forged the senders’ signatures on payment confirmation receipts and sent screenshots of those receipts to his co-conspirators so the money could be collected in Mexico.
The scheme was built around an understanding of how that system worked.
Is the insider threat different?
Financial crime controls are usually designed around predictable risk indicators like transaction thresholds, customer verification requirements, automated alerts, approval processes and escalation procedures.
While those mechanisms are necessary, predictability can also create vulnerability.
Someone who understands the controls from the inside will likely know which transactions attract attention, which information is checked, which processes are automated and where human intervention is required.
A criminal outsider would have to discover those weaknesses through trial and error. An insider knows them.
That makes insider-enabled financial crime a difficult risk to manage. The problem is not necessarily that a control is absent. It is that someone with privileged knowledge may be able to structure activity so that the control is never activated in the first place.
A threshold should not become a target
The $1,000 threshold is one of the lessons here for compliance teams.
A threshold creates a control point. But if customers or employees know exactly what happens above and below that number, it can also become a target for structuring.
Organisations need to look at the behaviour around the threshold. Repeated transactions just below a reporting or verification limit can be more informative than a single transaction that crosses it. The same applies to activity deliberately split across accounts, customers, branches, employees or jurisdictions.
Did this transaction cross the threshold? is an important question. But the more important question is, Why does this customer keep coming close to the threshold without crossing it?
The human element
The case also highlights the issue of insider risk.
AML programmes often focus heavily on customers. But employees have access to systems, information and processes that customers don’t.
That means companies need to think about whether their internal controls are capable of detecting an employee deliberately facilitating suspicious activity, particularly where that employee has the knowledge and authority to make transactions appear legitimate.
Segregation of duties, access controls, transaction monitoring and management oversight all have a role to play. So does employee training.
Companies also need to consider whether staff can override, bypass or manipulate controls, whether those actions are logged and independently reviewed, and whether unusual patterns associated with individual employees would be visible to compliance teams.
Beyond the transaction
This case highlights why transaction monitoring cannot operate entirely at the level of individual transactions. A series of transactions may each appear unremarkable in isolation. The pattern can look very different.
Multiple transfers just below a known threshold. Repeated use of apparently unrelated senders. The same employee processing an unusual concentration of transactions. Recipients who repeatedly appear in apparently unrelated transfers. Documentation that consistently looks legitimate but is generated or signed in unusual circumstances.
These are not necessarily proof of criminal activity. But they can be indicators. The challenge for companies is to connect the dots.
The bigger lesson
The effectiveness of an AML programme cannot be measured solely by the existence of policies, thresholds and procedures. Companies need to think about how those controls behave when someone actively tries to circumvent them, especially someone who knows exactly how they work.
The strongest AML systems are designed to recognise when someone is deliberately operating just inside the rules. Sometimes the biggest vulnerability in a control system is not the person trying to break through it. It is the person who already knows where the gaps are.
Watch our on-demand webinar, The 2026 AML Regulations: What firms need to change now
Get it here →