Behind every major financial-crime prosecution sits a paper trail of suspicious activity reports filed by banks, fintechs, insurers, and other regulated firms. These reports are how the private sector signals risk to law enforcement, and how Financial Intelligence Units stitch together the signals that turn into investigations. A poorly written suspicious activity report can sit untouched in a queue for months. A well-written one can trigger a multi-jurisdiction operation. Learning the discipline of SAR filing is one of the highest-leverage skills any AML professional can build.
This guide walks through what a SAR is, when to file, how to write a narrative that actually helps investigators, and the operational practices that distinguish strong reporting programmes from weak ones. Whether you investigate cases, run a SAR team, or audit financial-crime controls, the playbook below covers the rules, the workflow, and the craft of effective reporting.
What Is a Suspicious Activity Report?
A Suspicious Activity Report, or SAR, is a formal disclosure filed by a regulated entity to the relevant Financial Intelligence Unit when the firm forms a reasonable suspicion that a customer’s activity is connected to money laundering, terrorist financing, fraud, sanctions evasion, or other predicate offences. In some jurisdictions the equivalent is called a suspicious transaction report or STR. The mechanics differ, but the function is the same: bring suspected illicit activity to the attention of authorities through a structured, confidential channel.

Crucially, a SAR is not an accusation. It is a report of suspicion based on the firm’s knowledge of the customer and the activity. The legal threshold is low; the investigative consequence can be high.
SAR vs STR: The Naming Map
| Region | Term | Filing Authority |
|---|---|---|
| United States | Suspicious Activity Report (SAR) | FinCEN |
| United Kingdom | Suspicious Activity Report (SAR) | National Crime Agency (UKFIU) |
| European Union | Suspicious Transaction Report (STR) | National FIUs (each member state) |
| Singapore | Suspicious Transaction Report (STR) | Suspicious Transaction Reporting Office (STRO), CAD |
| Australia | Suspicious Matter Report (SMR) | AUSTRAC |
| Canada | Suspicious Transaction Report (STR) | FINTRAC |
| UAE | Suspicious Transaction Report (STR) | UAE FIU via goAML |
When to File a SAR
The legal threshold for filing differs slightly across jurisdictions, but the spirit is consistent: file when you have a reasonable basis to suspect the activity may be linked to financial crime. You do not need proof. You do not need to identify the underlying offence with certainty. You need a documented, articulable suspicion.
Common Filing Triggers
- Transaction monitoring alerts confirmed as suspicious after investigation.
- Unusual cash activity inconsistent with the customer profile.
- Structuring or smurfing patterns just below reporting thresholds.
- Rapid in-and-out movement of funds with no commercial logic.
- Sanctions or PEP exposure combined with adverse activity patterns.
- Adverse media linking the customer to financial crime.
- Information from law-enforcement requests, subpoenas, or grand-jury notices.
- Insider tips, employee reports, or whistleblower disclosures.
- Account takeover, fraud, or identity-theft incidents above thresholds.
- Cross-border activity inconsistent with the customer’s declared business.
Filing Deadlines and Confidentiality
- United States: SARs must be filed with FinCEN within 30 days of detection (60 days if no suspect identified).
- United Kingdom: SARs are filed as soon as practicable; for activity requiring consent (a Defence Against Money Laundering, or DAML), filing precedes the transaction.
- European Union: STRs are filed without delay under the AMLD framework.
- Most other jurisdictions: filings are required promptly, often within 1 to 30 days depending on the rule.
SARs are confidential. Tipping off the customer, directly or indirectly, is a criminal offence in most jurisdictions. Internal handling must therefore be tight, with strict access controls, no surface in customer-facing systems, and disciplined communication.
How to File a SAR: Step-by-Step
- Detect and document: capture the trigger, whether an alert, internal tip, or external request, with timestamps and source.
- Investigate: pull KYC, EDD, transaction history, counterparty data, adverse media, and any prior SARs on the same party.
- Form the suspicion: identify the typology that best explains the activity and articulate why the activity is suspicious.
- Apply the threshold: confirm the activity meets the jurisdictional standard for filing; document the rationale.
- Draft the narrative: explain the activity clearly, link it to the typology, and reference supporting evidence.
- Quality assurance: a peer or supervisor reviews the narrative for clarity, accuracy, and completeness.
- File electronically: submit through the FIU’s portal (e-Filing for FinCEN, SAR Online for the NCA, goAML for UAE, FINTRAC’s F2R, etc.).
- Receive confirmation: store the BSA-ID or filing reference in the case-management system.
- Maintain confidentiality: enforce no-tipping-off rules across all internal systems and communications.
- Continue monitoring: enhanced monitoring continues after filing; consider continuing-activity SARs at the appropriate cadence.
Anatomy of a Strong SAR Narrative
The narrative is the heart of any SAR. Investigators read narratives, not metadata. A strong narrative answers five questions clearly and concisely.
The Five Ws of SAR Writing
- Who is the customer or counterparty, and what is their profile.
- What activity occurred, in plain language, with amounts, currencies, and counterparties.
- When did the activity occur, with date ranges and patterns over time.
- Where did the activity occur, including channels, jurisdictions, and originating or beneficiary banks.
- Why is the activity suspicious, with an articulated typology and reference to supporting evidence.

Narrative Quality Markers
- Clear chronological flow, not a dump of transaction lists.
- Plain English, no internal jargon or acronyms without expansion.
- Specific amounts, dates, and counterparties; no vague generalities.
- Reference to relevant typologies, such as structuring, layering, or trade-based laundering.
- Articulated suspicion: not just what happened, but why the firm believes it is suspicious.
- Supporting evidence flagged as appendices or attachments.
- No personal opinion or speculation beyond the documented suspicion.
- No tipping-off content: nothing the customer would learn from.
Real-World Use Cases
Structuring at a Retail Bank
A retail bank detects a customer making 18 cash deposits, each between 9,000 and 9,800 dollars, across multiple branches over three weeks. The pattern aligns with structuring to avoid Currency Transaction Reports. The bank investigates, finds no legitimate explanation, and files a SAR with FinCEN within 30 days, citing the structuring typology and providing the deposit log.
Trade-Based Laundering at a Correspondent Bank
A correspondent bank receives a series of letters of credit for shipments of generic electronics at prices five times the market rate, between unrelated entities in three high-risk jurisdictions. The bank files an STR, citing trade-based laundering and over-invoicing typologies, with copies of the LCs and shipping documents.
Sanctions Evasion at a Fintech
A payment institution detects a customer routing payments through a chain of newly incorporated entities with addresses in three jurisdictions. Network analytics surfaces a coordinated pattern. The fintech files a SAR citing potential sanctions evasion, with the network diagram, transaction history, and registry data.
Insider Activity at a Broker
A broker-dealer detects a registered representative receiving wire transfers from clients into a personal account. The pattern violates internal policy and may indicate fraud. The firm investigates, terminates the representative, and files a SAR with FinCEN, with the wire log and HR documentation.
Crypto Exposure at an Exchange
A crypto exchange detects a customer receiving funds from a wallet identified by chain analytics as exposed to a sanctioned mixer. The exchange freezes activity, investigates, and files a SAR citing potential sanctions exposure, with the on-chain trail attached.
Common SAR Mistakes to Avoid
- Vague narratives with phrases like “activity appears suspicious” without explaining why.
- Transaction dumps instead of structured chronological flow.
- Internal jargon and undefined acronyms that confuse FIU readers.
- Speculation beyond what the firm can evidence from its records.
- Missing typology: not naming the suspected pattern (structuring, layering, etc.).
- Late filing beyond the statutory deadline.
- Tipping off through customer-facing systems or communications.
- Failure to update: not filing continuing-activity SARs when the activity persists.
- Inconsistent quality: variability across analysts erodes FIU trust in the firm’s output.
- Ignoring 314(b) opportunities: in the US, missing chances to share information with peer banks lawfully.
Benefits vs Challenges of Strong SAR Programmes
| Benefits | Challenges |
|---|---|
| Better intelligence for law enforcement | Resource-intensive investigation per case |
| Stronger regulator confidence in the AML programme | Variability in quality across analysts |
| Clearer audit trail for examiners | Tight statutory deadlines |
| Sharper feedback into TM tuning and risk rating | No-tipping-off discipline requires controls across systems |
| Enables information-sharing with peer banks under safe-harbour rules | FIU systems vary in usability |
Best Practices for SAR Programmes
- Standardise the narrative template with the Five Ws and a typology section.
- Train writers continuously on FIU expectations, typologies, and red flags.
- Implement two-tier review: analyst draft, supervisor QA, before filing.
- Track filing metrics: time to file, narrative quality scores, FIU feedback if available.
- Use case management with structured fields: counterparties, jurisdictions, amounts, typology tags.
- Integrate adverse media, sanctions, and KYC data directly in the case file.
- Document continuing-activity protocols: when to file follow-up SARs and at what cadence.
- Engage with the FIU where guidance and feedback channels exist.
- Retain records per jurisdictional requirements (typically 5 to 10 years post-filing).
- Test confidentiality controls: ensure no SAR information leaks to customer-facing systems.
Frequently Asked Questions
What is a Suspicious Activity Report?
A SAR is a confidential disclosure filed by a regulated entity to the local Financial Intelligence Unit when the firm forms a reasonable suspicion that a customer’s activity may be linked to money laundering, fraud, sanctions evasion, or other financial crime.
What is the difference between a SAR and an STR?
The terms are largely interchangeable. The US and UK use SAR; the EU, Singapore, Canada, and others use STR. The legal substance and investigative purpose are equivalent.
How long do firms have to file a SAR?
Deadlines vary. The US requires SAR filing within 30 days of detection (60 days if no suspect identified). Most other jurisdictions require filing without undue delay, typically within 1 to 30 days.
Can a customer find out a SAR was filed?
No. Tipping off the customer, directly or indirectly, is a criminal offence in most jurisdictions. SAR information must be tightly controlled and never appear in customer-facing systems.
Does filing a SAR mean the customer is guilty?
No. A SAR is a report of suspicion, not an accusation. The threshold is reasonable suspicion based on documented activity, not proof of wrongdoing.
What information goes into a SAR narrative?
Who the customer is, what activity occurred, when and where, and why the firm believes it is suspicious, with reference to a typology and supporting evidence such as transaction logs and KYC data.
How long are SAR records retained?
Most jurisdictions require retention for at least 5 years from the filing date, often longer for high-risk relationships or where law enforcement engagement is ongoing.
What happens after a SAR is filed?
The FIU triages the report, may share it with law-enforcement partners, and may use it to identify patterns across multiple firms. The reporting firm receives no routine feedback; ongoing monitoring continues.
Can a firm be penalised for filing too many SARs?
Generally not. Regulators expect firms to file based on suspicion, with proportionality to risk. Defensive filing without articulated suspicion is discouraged, but under-reporting is treated as a more serious failing.
What is a continuing-activity SAR?
When the suspicious activity persists after an initial SAR, firms typically file follow-up SARs at defined intervals (often 90 days in the US) to update the FIU with the latest pattern.
Can SAR information be shared with peer banks?
Yes, in the US under the 314(b) safe harbour, registered firms may share information with each other to identify potential financial crime. Equivalent regimes exist in some other jurisdictions; check local rules.
Conclusion and Key Takeaways
A strong SAR filing programme is a craft, not a checklist. The investigation must be thorough, the suspicion must be articulated, and the narrative must read as if a busy investigator at the FIU has 90 seconds to grasp the case. Get those right and your reports become signals that drive real outcomes; get them wrong and they sit in queues, contributing to noise rather than to law enforcement.
The discipline scales with investment. Standardised templates, two-tier review, structured case management, and continuous training are what separate firms whose SARs trigger investigations from firms whose SARs trigger only paperwork. Treat SAR writing as core craft, not afterthought, and the entire AML programme strengthens.
Key takeaways:
- SARs (and STRs) are confidential disclosures to the FIU, not accusations.
- The threshold is reasonable suspicion, not proof of wrongdoing.
- The narrative must answer who, what, when, where, and why suspicious.
- Tipping off is a criminal offence; confidentiality controls must be robust.
- Quality, not just volume, is what regulators and FIUs increasingly expect to see.
Want more practical, regulator-ready insights on SAR writing, AML investigations, and financial-crime compliance? Subscribe to the petafusion.com newsletter for weekly deep dives written for compliance leaders, MLROs, and fintech operators who need clarity, depth, and zero jargon.






