Jurisdicción de Estados Unidos,
explicada con claridad.

U.S. jurisdiction,
explained clearly.

Suspicious Activity Report (SAR): When You Must File and What Happens Next

suspicious activity report

The Suspicious Activity Report is a central document in U.S. anti-money laundering practice, but its legal effect is narrower than an accusation or criminal referral. It is not an accusation. It is not a referral to prosecutors. The filing institution must not tell the customer about the report.

Created by the Annunzio-Wylie Anti-Money Laundering Act of 1992 — which replaced the earlier Criminal Referral Forms — the SAR is the mechanism by which private institutions transfer an observation to the government without judging it. This article explains the trigger, the deadline and the limits on what the filer may say afterward. Compliance Officers supports institutions and individuals on both sides of that process.

The Two-Part Trigger

Both a dollar threshold and a state-of-mind test trigger a SAR obligation.

The threshold depends on what kind of institution you are:

InstitutionThresholdCitation
BanksAt least $5,000 in funds or other assets31 CFR 1020.320(a)(2)
Money services businessesAt least $2,00031 CFR 1022.320(a)(2)
Issuers of money orders or traveler's checks, when the issuer detects the activity by reviewing clearance or similar recordsAt least $5,00031 CFR 1022.320(a)(3)

The state of mind is the same across both: the institution knows, suspects, or has reason to suspect that the transaction — or a pattern of transactions of which it forms part — falls into one of these categories:

  • The transaction involves illegal proceeds or seeks to hide or disguise those funds, including their ownership, nature, source, location or control.
  • A person structures or otherwise designs the transaction to evade a Bank Secrecy Act requirement.
  • The transaction lacks an apparent lawful purpose or falls outside the customer’s expected activity, and the institution finds no reasonable explanation after examining the available facts.
  • For money services businesses, it involves use of the business to facilitate criminal activity.

Note the words “or attempted”. The duty covers transactions conducted or attempted by, at or through the institution. A transaction the customer abandoned when asked for identification is still reportable.

The 30-Day Deadline

A SAR is generally due no later than 30 calendar days after initial detection of facts that may constitute a basis for filing. The clock runs from initial detection of the relevant facts—not automatically from the transaction date and not from the end of an open-ended internal investigation.

The rule also contains a narrow extension that the earlier draft omitted. If the institution cannot identify a suspect on the detection date, the applicable bank and money-services-business provisions permit another 30 days for identification. The filer must submit the report no later than 60 calendar days after initial detection. Immediate threats can also require prompt contact with appropriate law enforcement in addition to a timely SAR.

Internal escalation should therefore preserve the detection date, the facts known at that point, the reviewer, the decision and any reason an extension applies. A thorough narrative does not cure a missed deadline.

Filing is not the end of the obligation

The filer must retain each SAR and the original or business-record equivalent of its supporting documentation for five years from the filing date. The filer must identify and maintain the supporting documentation; the rules treat those records as part of the SAR filing (31 CFR 1020.320(d); 1022.320(c)).

suspicious activity report

Confidentiality: What the Rule Protects

The regulations keep a SAR and any information that would reveal its existence confidential and prohibit disclosure except as specifically authorized (31 CFR 1020.320(e); 1022.320(d)).

The protection extends beyond the report document itself. The protection covers both the report and the fact that it exists. An institution may not tell the customer, may not hint, and may not explain a declined transaction by reference to a filing. Staff who reveal it create liability for the institution and for themselves.

For a customer, the practical consequence is worth stating plainly: you will not be notified, and asking will not produce an answer. Treat any claim that someone filed a SAR about you with caution; the speaker may lack that knowledge or may violate a confidentiality duty by sharing it.

What Follows a SAR Filing

The report goes to FinCEN, which makes SAR data available to law enforcement and regulatory authorities. Several things do not follow automatically, and confusion about them causes real distress:

  • A SAR is not a criminal charge, a finding, or evidence of wrongdoing.
  • A SAR does not by itself freeze an account or block a transaction. Those are separate decisions an institution may take for its own reasons.

The FFIEC examination manual directs management to focus on reporting suspicious activity rather than deciding whether a transaction actually connects to money laundering, terrorist financing or a particular crime. The framework separates the duty to report suspicious facts from any government determination that a crime occurred.

Voluntary Filing, and the Terrorism Hotline

An institution may also voluntarily report a suspicious transaction that it considers relevant to a possible legal or regulatory violation, even when no mandatory filing duty applies (31 CFR 1020.320(a)(1); 1022.320(a)(1)).

For matters that may relate to terrorist activity, FinCEN maintains a Financial Institutions Hotline at 1-866-556-3974, which money services businesses may call in addition to — not instead of — timely filing a required SAR.

What the 2026 Proposal Would and Would Not Change

FinCEN’s proposed rule of 10 April 2026 (RIN 1506-AB72) reforms AML/CFT program requirements. It does not rewrite the SAR thresholds or the 30-day deadline discussed above, which remain as stated. What it would change is the supervisory frame around the program that produces those filings — and it expressly preserves criminal enforcement liability under the Bank Secrecy Act.

Separately, FinCEN’s January 2, 2026 final rule delayed AML/CFT program and SAR duties for registered investment advisers and exempt reporting advisers until January 1, 2028.

The Decision Record Is as Important as the Filing Event

A defensible SAR process starts before anyone drafts the form. The file should identify the date of initial detection, the transactions and attempted transactions in scope, the applicable institution-specific threshold, the facts that created concern, the information reviewed and the person authorized to decide. When the institution cannot identify a suspect and uses the limited extension, the file should record that fact and the continuing review.

Supporting documentation should remain organized and retrievable for the required retention period. The filer submits the SAR to FinCEN, preserves the underlying records and gives authorized law-enforcement or supervisory authorities access when the regulations permit. Access controls should protect both the report and information that would reveal its existence.

Confidentiality does not mean that every underlying business fact becomes secret. Contracts, statements, transaction records and ordinary account communications can retain their independent character. Disclosure creates legal risk when it reveals the SAR or shows that someone prepared or filed one. Institutions should use approved, neutral customer communications and escalate subpoenas or unusual disclosure requests to qualified counsel.

Quality also matters. A SAR narrative should explain who, what, when, where and why the activity met the reporting standard without asserting more than the facts support. A suspicious activity report is not a charge, and the institution should also document a decision not to file under its procedures. Consistent decision records allow later reviewers to understand the reasoning without reconstructing it from scattered emails.

How Compliance Officers Supports You Here

Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.

The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.

A useful engagement begins with a defined subject, purpose and risk question. The client defines the review subject—a person, entity, transaction or relationship—and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The report records its scope and limitations so readers do not mistake an absence of findings for proof that no risk exists.

Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.

For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.

Frequently Asked Questions

What is the dollar threshold for filing a SAR?

It depends on the institution. Banks file at $5,000 or more (31 CFR 1020.320(a)(2)); money services businesses at $2,000 or more (31 CFR 1022.320(a)(2)); issuers of money orders or traveler’s checks identifying activity from clearance records at $5,000 or more (31 CFR 1022.320(a)(3)). The threshold alone never triggers a filing — suspicion must also be present.

No later than 30 calendar days after the date of initial detection of facts that may constitute a basis for filing. The period runs from detection of the facts, not from the transaction or from the end of an internal review.

No, and it may not. Regulations protect a SAR and any information revealing its existence and prohibit disclosure except as authorized. An institution that told you would be violating 31 CFR 1020.320(e) or 1022.320(d).

No. A SAR reports suspicious facts for authorized government users; it is not a charge, a finding or proof of wrongdoing. Whether authorities take any further action is a separate government decision. The FFIEC manual directs institutions to focus on reporting rather than on determining whether a crime occurred.

Yes. The regulation covers transactions conducted or attempted by, at or through the institution. A customer who abandons a transaction after staff request identification can still trigger the standard.

We cannot obtain a customer’s SAR from the filing institution. SAR information is restricted to disclosures and access authorized by law and regulation. We can independently review your background and legal existence, document the findings and provide a report that you can present to another institution when seeking to re-establish a banking relationship.

Establish the Facts Before Making the Decision

Do you need a counterparty examined, or an independent review of your own profile after a banking relationship ended?

Compliance Officers examines legal, financial and reputational background, verifies identity and legal existence, and delivers a written report you can present.

Request an evaluation

Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org

Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.

Related News

Compliance Officers

Consulta sin ningún costo!

Request information with no commitment

QR-Compliance Officers

Do you want to talk with us?

Últimas publicaciones