← Blog · Compliance
Filing a SAR: From Alert to a Report That Holds Up

A suspicious activity report (SAR, or STR in many jurisdictions) is the point where internal detection becomes an external obligation. It is filed with a financial intelligence unit (FIU) when a firm knows, suspects, or has reasonable grounds to suspect that funds relate to criminal conduct. This is general information, not legal advice, but the mechanics of a defensible filing are consistent across most regimes.
When the Obligation Triggers
The threshold for filing is suspicion, not proof. That distinction matters: waiting for certainty usually means filing late. Most FIUs set explicit deadlines. In the United States, a SAR is generally due within 30 calendar days of initial detection, extendable to 60 if a suspect is not yet identified. In the UK, a defence-against-money-laundering SAR should precede any transaction the firm wants consent to complete.
Triggers fall into a few families:
- Transaction monitoring alerts that survive investigation
- Sanctions or adverse-media matches with a plausible link to the customer
- Behaviour inconsistent with the stated purpose captured at onboarding
- Frontline reports from staff who interacted with the customer
Not every alert becomes a SAR. The investigation between alert and filing is where most of the work lives, and its output must be documented whether or not a report is filed.
Building the Narrative
An FIU analyst reading your SAR has no access to your systems. The narrative is the entire case. A weak narrative — "customer conducted suspicious transactions" — wastes the filing. A strong one answers the five questions investigators actually use: who, what, when, where, and why it is suspicious.
Structure it in three parts. First, introduce the subject: account age, business type, expected activity, and the KYC profile established at onboarding. Second, describe the activity in specifics — dates, amounts, counterparties, and the pattern rather than a transaction dump. Third, explain the suspicion explicitly: state what you would have expected and how the observed behaviour diverges. Reference the underlying documents by identifier so the report is reproducible.
Keep facts and inference separate. "Between 3 and 17 March, the account received nine inbound transfers totaling 44,200 EUR from unrelated third parties and remitted 43,800 EUR to a single overseas account" is a fact. "This pattern is consistent with third-party layering" is your inference. Analysts need both, clearly labelled.
Confidentiality and Tipping Off
Nearly every regime prohibits tipping off — disclosing to the subject, or to anyone outside the reporting chain, that a SAR has been filed or is contemplated. This shapes system design. Case notes, filing status, and investigation flags must be access-controlled and excluded from any customer-facing channel. If your onboarding or support runs through chat, the interface should never surface an account's SAR status, and agents should not be able to infer it from behaviour like sudden freezes without a controlled script.
Data minimization helps here too. Collecting only what verification requires reduces the surface an investigator has to sift, and reduces the risk that sensitive case material leaks through logs, exports, or integrations.
Retention and What Comes After
A filed SAR does not close the file. Retain the report and its supporting evidence for the statutory period — commonly five years from filing — under access controls that survive personnel changes. This is one case where standard KYC deletion schedules bend: material tied to an active or filed SAR is typically placed under legal hold and exempted from routine purges. Configurable retention policies should treat SAR-linked records as a distinct class rather than deleting them on the customer's default timeline.
Expect continuation filings. If suspicious activity persists, most regimes require a follow-up SAR at defined intervals — often every 90 days. Track each subject so patterns across filings stay visible, and periodically review your alert-to-SAR conversion rate: a rate near zero or near one usually signals miscalibrated thresholds rather than a clean or dirty book.
General information, not legal advice. Talk to your compliance counsel for guidance on your specific obligations.