A Practical Guide to Suspicious Activity Reporting
An evidence-led guide to identifying, assessing and reporting suspicious activity. It explains how to distinguish suspicion from proof, document decisions, prepare a clear SAR/STR narrative, avoid tipping-off, and apply proportionate post-filing controls while following the specific legal requirements of the relevant jurisdiction.
- Created
- Last updated
Suspicious activity reporting is one of the key controls in any AML/CFT framework. The point is not to decide whether a customer is guilty of a crime. It is to spot concerns, assess them properly, keep a clear record of the reasoning, and report them promptly when the legal threshold is met.
FATF puts it simply: if a firm suspects, or has reasonable grounds to suspect, that funds are criminal proceeds or linked to terrorist financing, it should report this to the financial intelligence unit (FIU) without delay. This also applies to attempted transactions and does not depend on the amount involved. FATF Recommendations
This is a general, jurisdiction-neutral guide. The precise reporting threshold, form, deadlines, consent regime, confidentiality rules and retention periods will always depend on local law, regulator guidance and the firm’s own policies.
Suspicion is not proof
One of the most common misunderstandings is to treat a suspicious activity report (SAR), or suspicious transaction report (STR), as an accusation. It is not.
Suspicion is an informed concern based on facts, circumstances and reasonable inferences. It may arise because activity does not fit the customer’s profile, stated purpose, expected source of wealth or funds, or normal transaction behaviour. The review needs to be evidence-based, but it does not require the institution to prove a predicate offence, identify the exact offence, or trace the ultimate origin of every euro.
In practice, these are different questions:
| Question | Appropriate standard |
|---|---|
| Has a crime been proven? | Usually a matter for law enforcement and the courts. |
| Is there a reasonable basis for concern under the reporting threshold? | This is the reporting decision. |
| Can the institution show what it knew, how it assessed it and why it escalated? | This is the quality and defensibility test. |
FATF Recommendation 21 allows good-faith reporting even where the reporter does not know the precise underlying crime, or where illegal activity is not ultimately established. FATF Recommendations
The aim is to avoid both extremes: filing every unusual transaction without thinking it through, or holding back until there is proof that the institution cannot realistically obtain and does not need.
When unusual activity becomes reportable
Unusual does not automatically mean suspicious. A large payment can make perfect sense for a particular business, and a new connection to another country can have an ordinary commercial explanation. What matters is whether that explanation still holds up when you look at the whole relationship.
A sensible review will usually consider:
- the customer’s identity, legal form, beneficial ownership and control;
- their occupation or business, expected account use and risk rating;
- source-of-funds and source-of-wealth information already held;
- transaction size, frequency, counterparties, channels, geography and timing;
- links between accounts, entities, devices, addresses or payment references;
- adverse information and internal intelligence, subject to the relevant legal and data-governance controls;
- the customer’s explanation, where it can be requested without creating a tipping-off risk; and
- whether this is a one-off anomaly or part of a wider pattern.
Usually, no single fact decides the case. The question is whether the overall picture creates suspicion, or reasonable grounds for suspicion, under the local test.
Record the reasoning, not just the decision
A good internal case file should let someone who was not involved understand what was known, when it was known, what was checked and why the decision was made. It needs to support the filing, but it should not become a dumping ground for every document ever touched.
Five things normally matter most.
1. Trigger and chronology
Note how the issue came to light: a transaction-monitoring alert, sanctions-screening result, employee referral, CDD review, external intelligence or another control. Then set out a dated timeline of the important transactions, communications, review steps and escalation decisions.
2. Customer context
Summarise the context needed to understand the activity: the customer’s profile, ownership structure, reason for the relationship, expected activity and relevant risk factors. Keep verified facts, customer statements and your own analytical inferences clearly separate.
3. Evidence reviewed
Identify the records you relied on, such as account statements, payment messages, onboarding documents, corporate records, screening results and communications. Where possible, point to the original documents rather than relying only on a narrative summary.
4. Analysis
Explain why the activity is concerning. Connect the facts to the conclusion. For example, funds may have moved quickly through a newly opened account; the payment purpose may conflict with the stated business; counterparties may be opaque or commercially hard to explain; or the customer’s explanation may not be supported by the records available.
Avoid statements such as “clearly criminal” unless that conclusion is both necessary and genuinely supported. It is usually better to write: “The institution identified the following indicators…” or “The explanation provided on [date] did not address…”.
5. Decision and governance
Record the reporting threshold used, the decision-maker or committee, the key escalation and filing dates, any local consent or defence-against-money-laundering process, and any restrictions or monitoring measures after filing. Do this whether the case is filed, closed or kept under review.
This matters even where no report is made. A clear closure rationale shows that the alert was assessed properly rather than dismissed because there was no single decisive red flag.
Writing the report
A useful SAR/STR should let an FIU analyst understand the suspected activity quickly and find the supporting material without having to play detective in the filing itself. Keep it factual, concise and structured.
The narrative should answer:
- Who? The customer, beneficial owners, connected parties, counterparties and relevant account identifiers.
- What? The activity giving rise to concern, including whether it was completed, attempted, refused or interrupted.
- When? The key dates, duration and transaction sequence.
- Where? Accounts, jurisdictions, payment channels and relevant locations.
- Why is it suspicious? The facts and pattern supporting the concern.
- How? The mechanism used: for example, layering through accounts, intermediaries, unusual cash activity, misuse of a company or inconsistent payment flows.
- What evidence exists? Relevant documents, transaction references, communications and any corroborating information.
Separate fact from assessment. Do not speculate about motives, assign criminal intent without a basis, or leave out facts that weaken the institution’s theory. If the customer gave an explanation, include it fairly and explain why it did or did not resolve the concern.
Avoiding tipping-off
Tipping-off rules protect the reporting process and may be statutory obligations. FATF requires institutions and their staff to be prohibited from telling a customer that an STR, or related information, is being filed with an FIU. FATF Recommendations
In practical terms, access to a live case and reporting information should be limited to people who genuinely need it. Clear internal communication rules are especially important when frontline staff, relationship managers, operations, legal teams and group entities are involved.
That does not mean all customer contact has to stop. Ordinary business communication, customer due diligence and lawful account-management activity can continue where permitted. The key is that nothing said or done should reveal, directly or indirectly, that a report has been filed, is being considered, or has led to investigative action. Rules on sharing information within a group, with advisers or with another institution vary by jurisdiction and should be covered by policy and specialist advice.
After filing: retain, reassess and act proportionately
Filing a report is not the end of the firm’s responsibility. Subject to the law and any instructions from the authorities, the firm should decide whether the relationship needs enhanced monitoring, restrictions, further due diligence, exit or another proportionate response.
But a SAR/STR is not, by itself, an instruction to close an account, freeze assets or refuse a transaction. Those actions have their own legal, contractual and risk consequences, and they should follow the applicable framework and documented decision process.
Post-filing controls should include:
- secure retention of the report, supporting evidence and decision record;
- restricted access and audit logging;
- review for new linked activity, customers or accounts;
- reconsideration of whether earlier risk assessments are still appropriate; and
- escalation of material developments through the organisation’s normal procedures.
The basic principle
Good suspicious activity reporting comes down to a simple discipline: establish the facts, assess them in context, record the reasoning, report when the legal threshold is met, and protect confidentiality throughout.
It is not about reaching perfection or proving guilt beyond doubt. It is about making a timely, good-faith, evidence-led judgement within a controlled process. Done well, that produces reports that are more useful to the authorities, more defensible to supervisors and more consistent for customers.
Sources
Check the original material below. How we use sources
- Primary sourceFATF Recommendations