← Blog · Compliance
Writing SARs That Survive Regulator Scrutiny

A Suspicious Activity Report (SAR) is only as useful as the narrative inside it. Financial intelligence units process large volumes of filings, and a report that omits the who, what, when, where, why, and how forces analysts to reconstruct context you already had. This is general information, not legal advice, but the patterns below reflect what examiners and FIUs consistently ask for.
Start With the Five-Part Narrative
Most quality frameworks converge on the same structure. Treat each SAR narrative as answering five questions in order:
- Who is conducting the activity: full legal names, dates of birth, account numbers, and the relationship between parties.
- What instruments and amounts are involved: transaction types, aggregate totals, and currency.
- When the activity occurred: precise date ranges, not vague periods.
- Where it took place: originating and beneficiary institutions, jurisdictions, and channels.
- Why it is suspicious: the specific red flags, tied to the customer's expected profile.
Close with how the activity was conducted and how you detected it. A reviewer who reads only the first two sentences should already understand the core concern. Bury the lede and you risk the report being deprioritized or returned.
Timeliness and the Filing Clock
Deadlines vary by jurisdiction, but the common thread is that the clock starts at the moment of determination, not the moment of detection. Under the US framework, institutions generally file within 30 days of initial detection of facts that constitute a basis for filing, with a 60-day ceiling when no suspect is identified. Continuing activity often requires review at 90-day intervals. Build these dates into your case management workflow with hard alerts rather than manual tracking.
A frequent examiner finding is not late filing itself but the absence of a documented decision trail. Record when the alert fired, when analysts escalated, when the filing decision was made, and by whom. If you decide not to file, that no-SAR rationale deserves the same rigor as a filing, because it is equally examinable.
Data Quality Feeds Narrative Quality
Weak SARs usually trace back to weak underlying records. If your onboarding captured a customer's stated occupation, expected transaction volume, and source of funds, your analysts can articulate why a pattern deviates from the baseline. If those fields are blank or stale, the narrative collapses into speculation. This is where verification design matters: structured, consistently formatted intake data is far easier to cite than free-text notes scattered across systems.
Chat-based verification can help here by capturing responses as discrete, timestamped fields rather than unstructured attachments, and by supporting data minimization so you hold what supports the investigation without accumulating unnecessary exposure. Configurable retention also matters: SAR-related records are typically subject to a five-year retention obligation and may fall under a legal hold, so your deletion schedules must recognize and pause on those records automatically.
Protect the Filing and Yourself
SAR confidentiality is not optional. In most regimes it is unlawful to disclose to the subject that a report was filed, and this tipping-off prohibition extends to how you word customer communications during and after review. Restrict SAR access to a defined compliance group, log every view, and separate the investigative case file from customer-facing systems.
Finally, treat quality assurance as a standing function, not an audit-season scramble. Sample filed SARs quarterly and score them against your narrative template. Track recurring gaps, such as missing counterparties or unquantified amounts, and route them back into analyst training. For a broader control view, see the FATF recommendations on reporting obligations. A SAR program that pairs disciplined narratives with clean source data and enforced confidentiality gives investigators something they can act on, and gives you a record that holds up under review.
General information, not legal advice. Talk to your compliance counsel for guidance on your specific obligations.