AML
SAR
Compliance
FinCEN
Financial Crime

How to Write an Effective SAR: A Suspicious Activity Report Writing Guide

A step-by-step guide to writing Suspicious Activity Reports that satisfy regulatory expectations, support law enforcement investigations, and survive examiner scrutiny — with annotated examples.

RiskLex EditorialJuly 1, 2026
How to Write an Effective SAR: A Suspicious Activity Report Writing Guide

The SAR as a Compliance Artefact

The Suspicious Activity Report (SAR) sits at the intersection of regulatory obligation, investigative utility, and institutional risk management. In the US, the Bank Secrecy Act requires that financial institutions file SARs with FinCEN within 30 days of detecting suspicious activity (60 days if no suspect is identified at the time of detection). In the UK, Suspicious Activity Reports are filed with the National Crime Agency under the Proceeds of Crime Act 2002. The EU's AML Directives impose equivalent obligations on member state institutions.

Despite decades of established practice, SAR quality remains a persistent supervisory concern. FinCEN's 2020 guidance on improving SAR quality explicitly noted that many reports lack sufficient narrative detail, use boilerplate language, or fail to articulate why activity was deemed suspicious. A low-quality SAR creates regulatory risk for the institution and reduces the intelligence value of the report to law enforcement.

This guide walks through the structural requirements, narrative best practices, and common failure modes of SAR filing.

---

The Legal and Regulatory Framework

United States:
The BSA SAR requirement applies to banks, money services businesses (MSBs), broker-dealers, mutual funds, insurance companies, casinos, and certain other covered institutions. SARs must be filed electronically through FinCEN's BSA E-Filing System within 30 calendar days of the date the suspicious activity was initially detected (or 60 days if no suspect can be identified). Institutions must retain a copy of the filed SAR and all supporting documentation for five years.

The SAR confidentiality rule is absolute: the existence of the SAR, its content, and the fact that it was filed must not be disclosed to the subject of the report or any unauthorised party. This applies to all employees of the institution, not just compliance staff.

United Kingdom:
UK SARs (properly called Suspicious Activity Reports under POCA 2002 and the Terrorism Act 2000) are filed with the National Crime Agency's UK Financial Intelligence Unit (UKFIU). Institutions filing a SAR may request a Defence Against Money Laundering (DAML), which provides a 7-day window (extendable to 31 days) during which law enforcement can seek a moratorium order before a transaction is completed.

European Union:
EU member states implement the AMLD framework through national Financial Intelligence Units. The establishment of AMLA (the Anti-Money Laundering Authority, which began operations in Frankfurt in mid-2025) is expected to drive convergence in STR (Suspicious Transaction Report) standards across the bloc, though national FIUs retain primary operational responsibility in the near term.

---

Structure of a High-Quality SAR Narrative

The SAR narrative is the most critical component. It must answer five questions comprehensively:

1. Who is involved? Identify all subjects fully: full legal name, date of birth, taxpayer identification or passport number, address, and any known aliases. For business entities: legal name, tax ID, registered address, jurisdiction of incorporation, and ultimate beneficial owners to the natural person level if known.

Do not use initials or job titles as substitutes for proper identification. If a subject's identity cannot be confirmed with certainty, state clearly what is known and what remains unverified.

2. What activity occurred? Describe the specific transactions or behaviours at issue — including amounts, dates, accounts, counterparties, and the payment rails used. Be precise: "approximately USD 250,000 in ten wire transfers" is insufficient. List each transaction with its date, amount, and reference number where available.

If the suspicious activity spans multiple accounts, products, or institutions, the narrative should map the flow of funds explicitly — ideally with a chronological transaction log as a supporting exhibit.

3. Where did it occur? Identify the account(s) involved, the branch or channel through which transactions were processed, and any geographic dimension (jurisdiction of wire counterparties, location of cash deposits, etc.).

4. When did it occur? The narrative must establish the timeframe of the suspicious activity clearly. For ongoing activity that is the subject of a continuing activity SAR, state the date of the prior SAR(s) filed on the same subject and summarise what has changed since the last filing.

5. Why is it suspicious? This is where most SARs fall short. The narrative must articulate, specifically and concretely, why the described activity constitutes a departure from expected behaviour and why it is consistent with one or more money laundering, fraud, or other financial crime typologies.

Do not write: "The transactions were inconsistent with the customer's profile."

Write: "The account was opened 45 days ago and declared a transaction volume of USD 5,000 per month at onboarding. Within the first 30 days of operation, the account received 14 wire transfers totalling USD 342,000 from seven different counterparties in Panama, Colombia, and the UAE, and the full balance was wired to a single account in a jurisdiction on FinCEN's primary concern list within 24 hours of each receipt. This activity is consistent with the funnel account typology documented in FinCEN advisory FIN-2022-A002."

---

Citing Typologies and Guidance

Referencing specific FinCEN advisories, FATF typology reports, or supervisory guidance strengthens the SAR's analytical basis and demonstrates that the institution's suspicion is grounded in documented financial crime intelligence — not speculation.

Useful references include:
- FinCEN Advisories (FIN-XXXX-AYYY): Published on FinCEN's website, covering specific crime types (human trafficking, ransomware, real estate, virtual assets, etc.)
- FATF Guidance and Typologies Reports: Available at fatf-gafi.org, covering cross-border typologies and sector-specific risks
- Egmont Group Typologies: Cross-jurisdictional case studies published by the Egmont Group of FIUs
- Sector-specific FATF Guidance: Real estate, lawyers, accountants, VASPs — each sector has dedicated typology documentation

---

The "5 Ws + How" Test

Before filing, run every SAR narrative through this checklist:

| Question | What to verify |
|---|---|
| Who | All subjects fully identified with ID numbers |
| What | Every suspicious transaction listed with amount, date, direction |
| Where | Accounts, branches, jurisdictions named |
| When | Specific date ranges; prior SARs cited if applicable |
| Why | Explicit connection to a recognised typology or pattern |
| How | Payment rail, method, any evasion technique described |

---

Continuing Activity SARs

When suspicious activity continues after an initial SAR is filed, institutions are expected to file continuing activity SARs every 90 days. These must:
- Reference the prior SAR filing (by BSA ID or confirmation number)
- Summarise the activity that has occurred since the last filing
- Update subject information if any new identification has been obtained
- Note any law enforcement contact related to the prior SAR(s)

---

Common SAR Drafting Errors

Boilerplate language. Phrases like "the activity was inconsistent with the customer's profile" or "the transactions lacked apparent business purpose" without elaboration are insufficient. Examiners and law enforcement have both flagged this as a persistent quality problem.

Missing counterparty information. Even partial information — a partial account number, a country of origin, a business name from a wire memo field — should be included. Law enforcement often uses this to connect SARs across institutions.

Filing too late. The 30-day clock runs from detection, not from when the investigation is complete. If a complete picture cannot be assembled in time, file with what is known and supplement with a continuing activity SAR.

Over-redacting. Some institutions suppress transaction details out of concern for the confidentiality rule. The rule protects the existence of the SAR — it does not require institutions to file vague reports.

Assuming the reviewer knows the context. Every SAR narrative must be self-contained. A FinCEN analyst reviewing the SAR has no access to your customer's file, internal memos, or prior compliance team discussions.

---

RiskLex and SAR Intelligence

Effective SAR narratives are grounded in current typology intelligence. RiskLex aggregates financial crime intelligence from regulatory advisories, law enforcement publications, and industry typology research, giving compliance analysts the context they need to write analytically grounded SARs. Start your free trial to see how RiskLex can improve your SAR programme.