"How do we know you're not just paying yourself that untraceable money?"
You don't.
But 99% of the time it becomes obvious when the perp turns up to work in a new Jag and starts going on fancy holidays.
In the event you suspect someone internally being involved, it might actually be better to pay the ransom, because eventually they will slip and get caught. The kind of person that would do this sort of thing from the inside is usually the sort of person that can't resist spending the money on dumb shit eventually.
There is one universal constant that you can always rely on in cybersecurity...people are dumb.
I wouldn't at all be surprised if some law enforcement suggested paying the ransom or at least part of it, because it gives them something to follow to track down the perp. Outside of "following the money" there probably isn't a lot to go on for LEA.
They may not catch them straight away, but eventually the perp will feel "safe" and the law will catch up.
https://www.bbc.co.uk/news/articles/cvg4w1g9ezko
You have to remember, these cybercrims that pull various shit off rely on the fact that the organisations they target care more about their data, optics and bottom line than actually bringing a crim to justice...it's this fact that allows this shit to keep happening.
Cybersecurity should not be an internalised singular mission of an organisation. It should be something that works more broadly than that. Your cyber guys should be working with other cyber guys out there as a collective army sharing knowledge and intelligence openly...otherwise it's just feudal Game of Thrones style bullshit with an even crappier ending.