Suspicious Activity Reports: When to File, What to Include, and Common Mistakes
Every compliance officer eventually has the same moment. A transaction crosses their desk that doesn't sit right, and now there's a decision to make: file a Suspicious Activity Report, or don't. Get it wrong in one direction and a regulator later asks why obvious activity went unreported. Get it wrong in the other direction and the institution buries its own investigators under low-value filings that make it harder to spot the reports that actually matter. FinCEN has said as much itself, most recently in guidance issued in October 2025 aimed specifically at cutting down on defensive, low-signal filings. This is a practical walkthrough of when a SAR is actually required, what a strong one contains, and the mistakes that show up again and again in the ones that get flagged as low quality.

What a SAR Actually Is, and What It Isn't
A Suspicious Activity Report is not an accusation. It is not a finding of guilt, and it is not proof that a crime occurred. It is a confidential report to FinCEN flagging a transaction or pattern of activity that an institution knows, suspects, or has reason to suspect is connected to illegal activity, or that has no clear lawful purpose given what the institution knows about the customer.
That distinction matters more than it sounds like it should, because it shapes how a narrative gets written. A SAR narrative describes what was observed and why it looked suspicious. It does not need to conclude that a crime definitely happened, and filers who try to build an airtight case before filing often end up filing too late, or not at all.
AMLI Analysis: A SAR is a flag. Filers who wait for certainty before reporting are usually waiting for something that never arrives.
When You're Actually Required to File
The filing obligation depends on two things: a dollar threshold, and a knowledge or suspicion standard. Both have to be present.
For most banks, a SAR is required when a transaction involves at least $5,000 and the institution knows, suspects, or has reason to suspect the funds are connected to illegal activity, or is designed to evade reporting requirements. If a suspect can be identified, that threshold drops to $5,000. If no suspect can be identified, many institutions apply a $25,000 threshold instead. Money services businesses generally work with lower thresholds, often around $2,000, reflecting the smaller average transaction sizes typical of that sector.
None of this means every transaction near a threshold needs a SAR. In FAQs issued jointly with the Federal Reserve, the FDIC, and credit union regulators in October 2025, FinCEN made a point of clarifying something compliance teams had been getting wrong for years: the mere presence of a transaction at or near the $10,000 Currency Transaction Report threshold is not, by itself, grounds to file a SAR. A SAR is only required where there is actual knowledge, suspicion, or reason to suspect that the transaction is structured specifically to dodge that reporting requirement.
Legal requirement: SAR obligations are set out in 31 CFR 1020.320 and related provisions, with thresholds varying by institution type and, in some cases, by whether a suspect has been identified.
Operational expectation: A transaction sitting just under a reporting threshold is a data point, not an automatic trigger. The suspicion has to come from something real, whether that's a pattern, a customer's explanation not adding up, or activity inconsistent with what the institution knows about the account.
AMLI Analysis: FinCEN spent real effort in 2025 telling institutions to stop filing SARs just because a number looked close to $10,000. That guidance exists because too many programs were doing exactly that.
The 30-Day Clock: Filing Deadlines You Can't Miss
Once you're obligated to file, the clock starts, and it doesn't stop for a good explanation. A SAR must be filed no later than 30 calendar days after the date an institution first detects facts that may constitute a basis for filing. If no suspect has been identified by that point, the institution may take an additional 30 days to try to identify one, for a maximum of 60 days before filing becomes mandatory regardless.
This is where a lot of institutions stumble, because "date of initial detection" gets interpreted inconsistently. The clock starts when the facts suggesting suspicious activity first come to light, not whenever the investigation happens to wrap up.

Continuing activity, where suspicious behavior keeps happening after an initial SAR has already been filed, used to carry an informal expectation of review roughly every 90 days, with a follow-up filing due within 120 days of the prior SAR. FinCEN's October 2025 guidance confirmed this was never a hard requirement. Institutions can instead rely on their own risk-based monitoring and reporting processes to determine when continuing activity warrants another filing, as long as those processes are reasonably designed to catch it.
Legal requirement: The 30-day filing deadline, extendable to 60 days without an identified suspect, is a firm regulatory requirement.
Operational expectation: Institutions should have a documented process for identifying the date of initial detection consistently, since this date is what the deadline is measured against.
AMLI Analysis: Deadlines don't move because an investigation is complicated. If detection happens, the clock is already running.
What Actually Belongs in a SAR Narrative
A strong narrative answers five questions clearly: who, what, when, where, and why. It should also explain how, meaning the method used to carry out the suspicious activity, since this is often the detail that gives investigators something to actually work with.
A few specifics matter more than filers tend to expect. Individual transaction dates and amounts should be included rather than a single aggregated total, since aggregation makes it harder for investigators to trace the actual flow of funds. Where funds moved from and where they ended up, meaning the source and the destination or beneficiary, should be spelled out explicitly rather than implied.
FinCEN also periodically issues advisories on specific typologies, from elder financial exploitation to sanctions evasion, and asks institutions to reference the relevant advisory's key term directly in the narrative and in the designated filing field when a SAR relates to that pattern. Skipping this step doesn't make a filing incomplete in a technical sense, but it does make it far less useful, since it strips out the exact signal that helps FinCEN and law enforcement connect related filings across institutions.
Legal requirement: The FFIEC's BSA/AML Examination Manual includes specific SAR quality guidance outlining what examiners expect a complete narrative to contain.
Operational expectation: Treat the narrative as the actual product being delivered, not paperwork attached to a decision that's already been made. A vague narrative on a correctly-filed SAR still fails the institution's real purpose here.
AMLI Analysis: Two SARs can report the same transaction and be worth completely different amounts to an investigator, purely based on how much real detail made it into the narrative.
Common Mistakes That Get SARs Flagged as Low Quality
Vague, boilerplate language:
Writings that could describe almost any transaction, with the specific account or customer details swapped in, tell an investigator very little. "Customer conducted transactions inconsistent with account history" is a conclusion.
Aggregating instead of itemizing:
Reporting one lump sum instead of the individual transactions that made it up strips out the pattern that made the activity suspicious in the first place.
Missing advisory key terms:
When a SAR relates to a typology FinCEN has issued specific guidance on, leaving out the relevant key term makes the filing harder to connect to related cases and other filings on the same pattern.
Defensive over-filing:
Filing on every transaction near a reporting threshold, absent any real suspicion, is exactly the practice FinCEN's October 2025 guidance was written to discourage. It burdens the system with low-value filings and can actually make genuinely suspicious activity harder to spot.
Missing the deadline:
Late filings, even by a few days, are a straightforward compliance failure with no ambiguity for an examiner to work with.
Under-filing:
The opposite problem: activity that should have triggered a SAR never gets escalated, often because front-line staff weren't trained to recognize red flags or didn't know how to escalate a concern internally.
AMLI Analysis: Most of these mistakes trace back to the same root cause: a program built around filling out a form correctly, rather than one built around actually communicating what was observed.

The Confidentiality Rule Nobody Can Afford to Break
A SAR, and even the fact that one was filed, is confidential. Disclosing the existence of a SAR to the person or entity it concerns, sometimes called tipping off, is a separate violation entirely from any issue with the filing itself, and it can carry serious consequences of its own.
This confidentiality requirement exists alongside a safe harbor protection: institutions that file SARs in good faith are protected from liability for that disclosure, provided they follow the rules governing how the report is made and kept confidential. That protection is a significant reason SAR filing works at all. Without it, institutions would have far less incentive to report activity involving their own customers.
Legal requirement: SAR confidentiality obligations and the associated safe harbor are established under 31 U.S.C. 5318(g).
Operational expectation: Staff involved in any part of the SAR process, not just the compliance team, need to understand that the existence of a filing cannot be discussed with the customer, and in most cases should be discussed internally only on a strict need-to-know basis.
AMLI Analysis: The safe harbor is what makes honest reporting possible. Breaking confidentiality puts that protection, and the filer, at real risk.
A Quick Pre-Filing Checklist
-
Does the activity meet both the dollar threshold and the knowledge or suspicion standard, rather than just sitting near a reporting threshold?
-
Has the date of initial detection been identified clearly, so the 30-day clock is being measured correctly?
-
Does the narrative answer who, what, when, where, why, and how, with individual transactions rather than an aggregated total?
-
Does the filing reference the correct FinCEN advisory key term, if the activity matches a typology FinCEN has flagged?
-
Has anyone outside the compliance team who touched this case been reminded that the filing itself is confidential?
-
Is there a documented, risk-based process for reviewing continuing activity, rather than an informal assumption about a 90-day cycle?
Frequently Asked Questions
What is the dollar threshold for filing a SAR?
It depends on the institution type and whether a suspect has been identified. Most banks work with a $5,000 threshold when a suspect is known, and often a $25,000 threshold when no suspect can be identified. Money services businesses typically work with a lower threshold, commonly around $2,000. In every case, the dollar threshold alone does not trigger the obligation; there must also be actual knowledge, suspicion, or reason to suspect illegal activity.
How long do I have to file a SAR after detecting suspicious activity?
Thirty calendar days from the date of initial detection. If no suspect has been identified by that point, the institution may take up to an additional 30 days to try to identify one, for a maximum of 60 days before filing becomes mandatory.
Do I need to file a SAR every time a transaction is close to $10,000?
No. FinCEN clarified this directly in October 2025 guidance: a transaction at or near the $10,000 Currency Transaction Report threshold does not, by itself, require a SAR. A filing is only required where there is actual knowledge, suspicion, or reason to suspect the activity is structured to evade that reporting requirement.
Can I tell a customer that I filed a SAR about their account?
No. SAR confidentiality is a legal requirement, not an internal policy choice. Disclosing that a SAR was filed, sometimes called tipping off, is a separate compliance violation from any issue with the underlying filing, and it also jeopardizes the safe harbor protection that shields good-faith filers from liability.
How AML Incubator Supports SAR and AML Program Quality
AML Incubator works with banks, MSBs, and fintechs to build SAR processes and broader AML programs that produce genuinely useful reporting, not just technically complete paperwork.
If your SAR filings are technically on time but you're not confident the narratives would actually hold up under an examiner's review, that's worth a second look before the next exam finds it first.




