Glossary

Suspicious Activity Report (SAR)

What Is a Suspicious Activity Report (SAR)?

suspicious activity report (SAR) is a formal disclosure that regulated businesses must submit to their country’s financial intelligence unit (FIU) whenever they suspect a customer or transaction may be connected to money laundering, terrorist financing, or other serious financial crime. In the UK, SARs are submitted to the National Crime Agency (NCA) via the UKFIU’s SAR Online portal. Across the EU, national FIUs receive reports through platforms such as goAML. In the US, the Financial Crimes Enforcement Network (FinCEN) administers SAR filing under the Bank Secrecy Act (BSA).

SARs do not require proof of wrongdoing. They are an intelligence tool and a mechanism for regulated firms to flag activity that does not add up, so that law enforcement can investigate. Failing to file when suspicion exists is a regulatory offence. Filing a vague or poorly evidenced SAR is increasingly attracting scrutiny of its own.

Key Takeaways

  • A suspicious activity report (SAR) is a mandatory disclosure filed by regulated businesses when they suspect money laundering, terrorist financing, or other financial crime. In the UK, SARs go to the NCA via SAR Online; in most EU states, via national FIUs on the goAML platform.
  • SAR, STR, CTR, and TTR are related but distinct report types. “SAR” is the UK/US term; “STR” is the FATF international standard used across most EU and Asia-Pacific jurisdictions.
  • Obliged entities include banks, payment firms, crypto platforms, legal professionals, accountants, and estate agents. The AMLR expands this list further from 2027.
  • Strong KYC at onboarding reduces SAR volume and improves the intelligence value of reports that are filed. Regulators are scrutinising SAR quality, not just quantity.
  • AMLA and AMLR will harmonise SAR obligations across EU member states from 2027. Compliance teams should begin transition planning now.

Who Must File a Suspicious Activity Report?

The obligation to file a suspicious activity report applies to a broad and expanding range of regulated businesses. In the UK and across the EU, obliged entities include:

  • Banks, building societies, and credit institutions
  • Payment institutions and e-money firms
  • Money services businesses (currency exchange, remittance)
  • Crypto-asset service providers and exchanges
  • Legal professionals (solicitors, notaries)
  • Accountants, auditors, and tax advisers
  • Estate agents and letting agents
  • Trust and company service providers
  • Casinos and gambling operators

Under the EU’s new Anti-Money Laundering Regulation (AMLR), which takes full effect from 2027, this list expands further to include certain luxury goods dealers, high-value art traders, and additional professional sectors. Crypto-asset firms face particularly detailed new obligations.

Even businesses outside this mandatory list can — and sometimes do — file voluntarily. In Germany and Italy, voluntary SARs from mobility and car rental businesses have helped uncover money laundering schemes involving fake rental services used to move illicit funds.

SAR, STR, CTR, TTR: Understanding the Report Types

“Suspicious activity report” is not a universal term. The terminology varies by jurisdiction, and compliance professionals operating internationally need to understand the distinctions.

Type Full NameWhere UsedWhat It Covers
SARSuspicious Activity ReportUK, USBroad suspicious behaviour — patterns, attempted transactions, and behavioural red flags, not just individual transactions
STRSuspicious Transaction ReportFATF standard; most EU, Asia-PacificFunctionally equivalent to a SAR; the distinction is regional convention, not substance
CTRCash Transaction ReportUS (USD 10,000 threshold), many jurisdictionsCash transactions above a defined threshold, regardless of whether suspicion exists
TTRThreshold Transaction ReportSome jurisdictionsSimilar to a CTR; filed for transactions above a regulatory amount
TFRTerrorism Financing ReportSome jurisdictionsUsed when a direct link to terrorist financing is established, rather than suspected

For consistency, this article uses “SAR” throughout. When working in a specific EU jurisdiction, always verify the local terminology and platform requirements with your national FIU. 

What Triggers a Suspicious Activity Report?

A SAR must be filed when a transaction — or attempted transaction — raises reasonable grounds for suspicion of financial crime. Some triggers are objective; many require professional judgement. The categories below draw on FATF typologies and the NCA’s published guidance.

Transaction-based red flags

  • Structuring: breaking large sums into multiple smaller transactions to fall below reporting thresholds (also known as “smurfing”)
  • Rapid cycling of funds between unrelated accounts
  • Large cash deposits or withdrawals inconsistent with the customer’s profile or stated business purpose
  • Frequent or high-value international wire transfers with no clear commercial rationale
  • Payments to or from high-risk or sanctioned jurisdictions

Customer behaviour red flags

  • Inconsistent, changing, or unverifiable identity information
  • Complex ownership structures with no plausible business explanation
  • Customers who appear nervous, unusually knowledgeable about reporting thresholds, or attempt to discourage verification

Business relationship red flags

  • Transactions that are inconsistent with the declared nature of the business
  • Third-party payers with no evident connection to the account holder
  • Activity patterns matching known money laundering typologies published by FATF or the NCA
  • Sudden, unexplained activity in previously dormant accounts

Other triggers

  • Suspected insider trading or market abuse
  • Any transaction where the customer appears to be concealing ownership, source of funds, or the ultimate beneficiary of the activity

For a full list of common money laundering red flags and how to identify them at onboarding, see our guide to AML red flags.

How to File a SAR: Step-by-Step

In the US, the BSA requires SARs to be filed within 30 days of the date of initial detection of suspicious activity. If no suspect has been identified, institutions may take up to an additional 30 calendar days, but in no case may filing be delayed more than 60 calendar days in total from initial detection. In the UK, the obligation is to file “as soon as practicable”. There is no fixed statutory deadline, but regulators and the NCA expect prompt submission. The EU’s AMLR will introduce more explicit timeframes as it is implemented from 2027.

Delaying a SAR filing — or failing to file altogether — is a regulatory offence that can result in substantial fines, reputational damage, and, in serious cases, criminal liability.

The UK process (UKFIU / NCA SAR Online)

  1. Detection. Suspicious activity is identified — either by automated transaction monitoring systems, by a member of staff, or during a periodic review.
  1. Internal escalation. The employee who identifies the suspicion reports it to the firm’s Money Laundering Reporting Officer (MLRO) or Nominated Officer. Any employee can raise a concern; the MLRO makes the filing decision.
  1. Investigation and decision. The MLRO reviews the information, gathers additional context (transaction history, customer records, open-source checks), and determines whether the SAR threshold is met.
  1. Filing via SAR Online. If the MLRO decides a SAR is required, it is submitted electronically through the NCA’s SAR Online portal. The SAR must include: the subject’s identity details, the transactions in question, and — critically — a narrative section explaining what was observed and why it is considered suspicious.
  1. Consent SAR (if applicable). If the transaction has not yet taken place, the MLRO may file a “consent SAR” and wait for the NCA’s response before proceeding. Consent is deemed given if the NCA does not respond within 7 working days.
  1. Recordkeeping. The firm must retain a copy of the SAR and all supporting documentation for a minimum of five years.

The EU process (national FIUs / goAML)

Most EU member state FIUs receive suspicious activity reports through the goAML platform, developed by the UN Office on Drugs and Crime (UNODC) and adopted widely across Europe.

CountryFIUPlatformNotes
GermanyFIU (hosted at BKA)goAMLVerdachtsmeldung; reported under the GwG (Geldwäschegesetz)
FranceTRACFINTRACFIN portalDéclaration de soupçon; TRACFIN does not use goAML
NetherlandsFIU-NLgoAMLReports under the Wwft (Wet ter voorkoming van witwassen)
AustriaA-FIU (BMF)goAMLVerdachtsmeldung; regulated under FM-GwG
UKUKFIU (NCA)SAR OnlineOutside the EU; POCA 2002 and Terrorism Act 2000

Under AMLA and the AMLR, these national systems will converge toward harmonised reporting formats and submission standards, with the new AMLA authority in Frankfurt coordinating cross-border intelligence sharing via FIU.net.

What goes in the SAR narrative?

The narrative section of a SAR report should clearly set out: what activity was observed; the dates, amounts, and accounts involved; any relevant customer background; and the specific reasons the activity was assessed as suspicious. Vague language (“transactions appeared unusual”) without supporting context significantly reduces the report’s value to investigators. FinCEN and national regulators have increasingly cited SAR narratives lacking required detail as the basis for enforcement action and regulatory penalties, in most cases, because the underlying customer record was inadequate.

SAR vs STR: What’s the Difference?

Both terms refer to the same type of mandatory financial crime disclosure. “SAR” is the terminology used in the UK and the United States; “STR” is the FATF-standard term used across the EU, Asia-Pacific, and most other jurisdictions. Some frameworks further distinguish between a report covering broad patterns of suspicious activity (SAR) and one specifically tied to a suspicious transaction (STR) — but in practice the terms are used interchangeably and the legal obligation is identical.

When operating across multiple jurisdictions, always confirm the local term and the local FIU portal with your compliance team or legal counsel.

How Strong KYC Reduces SAR Volume — and Improves SAR Quality

Every SAR filed represents a failure somewhere in the customer lifecycle — either a bad actor who was onboarded, or a legitimate customer whose transactions became unexplainable. Compliance teams focused purely on SAR filing are addressing the symptom rather than the cause.

The firms with the strongest SAR programmes share one characteristic: they invest heavily in identity verification and AML screening at the point of onboarding, before a customer relationship begins.

Prevention: Robust document verification, biometric identity checks, and real-time AML screening at onboarding catch high-risk individuals before they transact. Fewer bad actors enter the customer base; fewer suspicious transactions require disclosure. This is not a marginal effect — the volume of SARs a firm generates is directly correlated with the quality of its onboarding controls.

Quality: When a SAR does need to be filed, the underlying KYC record determines its usefulness to investigators. A SAR backed by a verified identity, confirmed address, documented source of funds, and a complete transaction history provides actionable intelligence. A SAR filed against an anonymous, inadequately verified customer tells investigators very little. Given that regulatory scrutiny of SAR quality is increasing — as regulators and FIUs increasingly signal — the strength of your KYC programme is now a SAR quality issue as much as an onboarding one.

The compliance implication: Regulators and FIUs increasingly assess not just whether firms file SARs, but whether the disclosures they receive are useful. Firms that treat KYC as a compliance checkbox rather than an intelligence-gathering exercise will find their SAR programme harder to defend at audit. AML screening at onboarding is the foundation of a defensible SAR programme — not an optional enhancement.

For a full explanation of the three stages of money laundering that SAR programmes are designed to disrupt, see our guide to the three stages of money laundering.

AMLA and AMLR: What Changes for SAR Reporting?

The European Union is in the middle of its most significant overhaul of anti-money laundering regulation in a generation. For compliance teams responsible for SAR reporting, two developments stand out.

AMLR (Anti-Money Laundering Regulation) is the first directly applicable EU-wide AML rulebook. Unlike previous directives, which allowed member states to implement rules differently, the AMLR will apply identically across all 27 member states from 2027. For SAR reporting, this means: harmonised definitions of what constitutes suspicious activity, standardised reporting formats, and — for the first time — consistent thresholds and timeframes across EU borders.

AMLA (Anti-Money Laundering Authority), headquartered in Frankfurt, will directly supervise the highest-risk obliged entities across the EU and coordinate intelligence sharing between national FIUs through FIU.net. AMLA’s mandate explicitly includes improving the quality and consistency of SAR reporting across member states.

What this means in practice: Firms operating in multiple EU markets currently navigate different national SAR formats, different FIU portals, and different interpretations of reporting obligations. AMLA and AMLR will progressively standardise this — but transition planning is needed now, as national implementations will vary in the interim.

For a detailed breakdown of the AMLR’s obligations and timelines, see our AMLR explained guide.

Frequently Asked Questions about Suspicious Activity Report (SAR)

What is a suspicious activity report?

A suspicious activity report (SAR) is a formal document that regulated businesses must file with their country’s financial intelligence unit when they suspect a customer or transaction is connected to money laundering, terrorist financing, or serious financial crime. In the UK, SARs are submitted to the National Crime Agency (NCA) via the UKFIU’s SAR Online portal. SARs do not require proof of wrongdoing — a reasonable suspicion is sufficient and, in itself, sufficient grounds for the legal obligation to file.

What is the deadline for filing a SAR?

In the US, the Bank Secrecy Act requires SARs to be filed within 30 days of initial detection, with an additional 30 calendar days permitted if no suspect has been identified (maximum 60 calendar days total from initial detection). In the UK, the obligation is to file “as soon as practicable” following the formation of a suspicion. EU member states have varying national rules, which the AMLR will standardise from 2027. Failure to file within the required timeframe is a regulatory offence that can attract significant financial penalties.

Who files a suspicious activity report?

Within an obliged entity, the Money Laundering Reporting Officer (MLRO) or Nominated Officer is responsible for formally filing the SAR. Any employee can — and should — identify and escalate suspicious activity internally. The MLRO reviews the internal report, investigates if necessary, and decides whether to submit a SAR to the relevant FIU.

What would trigger a suspicious activity report?

A SAR is triggered whenever a regulated firm has reasonable grounds to suspect money laundering or terrorist financing. Proof is not required. Common triggers include transactions with no obvious lawful purpose, customer behaviour inconsistent with their stated profile or income, reluctance to provide identity documents, use of shell companies to obscure fund origins, links to high-risk jurisdictions, and matches against sanctions or politically exposed person (PEP) lists. Failure to file when suspicion arises is a criminal offence in most jurisdictions.

What is considered suspicious activity?

Suspicious activity is any financial conduct that is inconsistent with a customer’s normal, legitimate behaviour and could indicate money laundering, fraud, tax evasion, or a related crime. Typical examples include structuring cash deposits just below reporting thresholds, rapid unexplained movement of funds across accounts or jurisdictions, payments to sanctioned parties, and high-value asset purchases using funds of unclear origin. What counts as suspicious always depends on context — the same transaction can be routine for one business type and alarming for another.

What happens after a suspicious activity report is filed?

The SAR is received by the relevant FIU, which analyses it alongside other intelligence to decide whether to refer the matter to law enforcement. The reporting firm is legally prohibited from tipping off the customer. In the UK, a consent SAR (DAML request) gives the NCA seven working days to approve or block a transaction. In the US, FinCEN shares SAR data with authorised law enforcement agencies. Most SARs do not trigger immediate action but contribute to intelligence that supports investigations over time.

What are examples of suspicious activity?

Real-world SAR examples include: depositing cash in amounts just below the $10,000 reporting threshold across multiple branches on the same day (structuring); a new company receiving large international wire transfers and immediately withdrawing the funds in cash; a customer with a modest stated income who regularly transacts in six-figure sums; rapid buy-sell cycles of real estate at prices far from market value; and a customer asking whether transactions will be reported to authorities. FATF typologies reports and FinCEN advisories publish regularly updated sector-specific examples.

How do banks detect suspicious activity?

Banks use a combination of automated transaction monitoring and human review. Rule-based systems flag activity that deviates from expected patterns — such as structuring, unusual geographic flows, or high transaction velocity — while machine learning models identify subtler anomalies across large data sets. These alerts feed into a customer risk profile built during onboarding through KYC checks, identity verification, document verification, and PEP and sanctions screening. When an alert is raised, a compliance analyst reviews the full account context before deciding whether to file a SAR.


Reduce SAR Risk at the Source

Effective SAR compliance does not begin at the point of reporting. It begins at onboarding. IDnow’s AML screening and identity verification solutions help regulated businesses verify identities accurately, screen against global sanctions and PEP lists, and build the customer records that make SAR programmes defensible. Fewer bad actors onboarded. Better intelligence when disclosure is required.

Learn how IDnow supports AML compliance across the UK, Germany, France, and other countries in the EU.