All posts
Compliance·· 10 min read

Suspicious Activity Reports (SARs): Complete 2027 Guide

Miss the 30-day SAR window and your compliance program is the story. Here's exactly when to file, what to write, and what triggers regulators' attention most.

By AtlasForge Financial Editorial
Suspicious Activity Reports (SARs): Complete 2027 Guide

The number that should be on every compliance officer's wall: 3.8 million. That's how many Suspicious Activity Reports FinCEN received in fiscal year 2026, up 11% from 2024, according to the agency's annual filing statistics. Behind each report is a decision tree that took minutes — or, at some institutions, months — to navigate. File too late and you've handed examiners a willful-blindness argument. File too broadly and you've trained your own system to cry wolf.\n\nThis guide cuts through both failure modes. Whether you're a community bank, a licensed money-services business, or a fintech building on top of a bank partner, the mechanics of SAR filing are non-negotiable. Get them right.\n\n## What a SAR Actually Is — and What It Isn't\n\nA Suspicious Activity Report is a confidential disclosure filed through FinCEN's BSA E-Filing System whenever a financial institution detects a transaction or pattern of behavior that may involve money laundering, fraud, terrorist financing, or other financial crimes. The operative word is may — the legal threshold is reasonable suspicion, not probable cause.\n\nWhat a SAR is not:\n\n- An accusation. Filing does not constitute a finding of guilt, and courts have consistently upheld that point.\n- Public. SAR confidentiality is mandated by 31 U.S.C. § 5318(g)(2). Tipping off a subject — even inadvertently — is a federal offense.\n- A substitute for a Currency Transaction Report (CTR). CTRs cover cash transactions above $10,000 and are filed on a different schedule with different triggers.\n\nThe legal authority sits in the Bank Secrecy Act as amended by the USA PATRIOT Act (Section 356) and is implemented through FinCEN's regulations at 31 CFR Part 1020 for banks and Part 1022 for money-services businesses.\n\n## The 30-Day Clock (and the 60-Day Extension)\n\nMost practitioners know there's a deadline. Fewer know the two-tier structure:\n\n1. Standard deadline: 30 calendar days from the date you first detected the suspicious activity — not from the date the transaction occurred.\n2. Extended deadline: If no subject has been identified, you get an additional 30 days (60 calendar days total from detection) to identify a subject before filing.\n3. No extension beyond 60 days: Even if you still haven't identified anyone, the SAR must be filed by day 60.\n4. Continuing activity SARs: If the suspicious behavior is ongoing, a follow-up SAR is required every 90 days as long as the institution has a reportable basis to believe the activity continues.\n\n> Examiner's note: The OCC's 2026 BSA/AML Comptroller's Handbook update explicitly flags institutions that "routinely file at or near the 60-day outer limit" as warranting heightened review of their monitoring programs. Earlier is almost always safer.\n\nThe clock starts at detection, but "detection" isn't always obvious. A transaction monitoring alert on March 1 that sits in a queue, gets reviewed on March 10, escalated on March 18, and approved for filing on March 28 — your clock arguably started March 1, not March 28. Build queue SLAs that account for this.\n\n## The Six Red Flags Behind 80% of SAR Filings\n\nFinCEN's own typologies research, combined with 2025–2026 SAR data published in its SAR Stats reports, consistently shows that the following six categories account for roughly 80% of all filed reports. Know them cold.\n\n1. Structuring (smurfing): Multiple cash deposits or withdrawals just below the $10,000 CTR threshold, often across multiple branches or accounts. Pattern recognition is table stakes here — the red flag is the series, not the individual transaction.\n\n2. Unusual wire activity: Rapid movement of funds in and out of an account (often called "layering"), particularly to or from high-risk jurisdictions on FinCEN's or FATF's watch lists. Round-dollar international wires with no apparent business purpose are a classic trigger.\n\n3. Inconsistency with customer profile: A small landscaping business suddenly receiving $200,000 monthly ACH credits. A retail account transacting in patterns that mirror a money-services business. Know your customer — because examiners will ask whether you did.\n\n4. Third-party check cashing: Checks made payable to one party but cashed or deposited by another, especially in high volume. This pattern is disproportionately associated with payroll fraud and check kiting schemes.\n\n5. Crypto-to-fiat conversion spikes: As of 2027, FinCEN's virtual asset guidance (updated January 2026) treats large or rapid conversions from self-custodied wallets to bank accounts as a distinct red-flag category, particularly when the originating wallet address has exposure to mixing services or sanctioned entities.\n\n6. Loan proceeds used atypically: A borrower who draws down a business line of credit and immediately wires the full amount offshore, or converts it to cash — especially when combined with early repayment from an unclear source — is one of the most durable fraud patterns in commercial banking.\n\n## How to Write a SAR Narrative That Actually Works\n\nThe narrative field is where most SARs succeed or fail. FinCEN and law enforcement are not looking for prose; they are looking for an investigative roadmap. A strong narrative answers five questions in order:\n\n- Who: Full legal name, date of birth, account number(s), EIN or SSN if available, and any known aliases or related entities.\n- What: The specific transactions or behaviors that triggered the filing. Dollar amounts, dates, channels, and counterparties.\n- When: A chronological account — not just the dates of suspicious transactions but when the pattern emerged relative to known account history.\n- Where: Jurisdictions involved, branch locations, IP geolocation data if available, correspondent bank chains for wire activity.\n- Why: Your institution's reasoned basis for suspicion. This is not a legal conclusion — it's a documented inference. "Account holder's stated business is a sole-proprietor consulting firm with average monthly revenue of $8,000; account received $340,000 in ACH credits from 14 distinct originators during Q3 2026, inconsistent with any known business purpose."\n\n### Template Opening Line\n\nFinCEN's own guidance recommends starting the narrative with a clear summary sentence. A proven structure:\n\n*"[Institution name] files this SAR on [subject name] for [type of suspicious activity, e.g., 'suspected structuring of cash deposits'] involving [dollar amount] across [number] transactions between [start date] and [end date]."*\n\nDo not bury the lede in background. Examiners and law enforcement analysts often read hundreds of narratives per week — put the core allegation in sentence one.\n\n### What Not to Write\n\n- Conclusions that sound like legal findings ("Subject is guilty of money laundering").\n- Vague language that could describe any customer ("Transaction activity appeared unusual").\n- Copied-and-pasted transaction logs without interpretive commentary.\n- Internal jargon, case-management system IDs, or investigator names.\n\n## Filing Mechanics: The FinCEN BSA E-Filing System\n\nAll SARs for U.S. depository institutions and MSBs must be submitted electronically through FinCEN's BSA E-Filing System. Paper filings have not been accepted since 2013. Key operational notes:\n\n- The current SAR form is FinCEN Form 111 (updated 2020, still current as of 2027).\n- Filers must maintain a copy of each SAR and supporting documentation for five years from the date of filing, per 31 CFR § 1020.320(d).\n- Law enforcement can request supporting documentation directly from the filer — have your document retention policy mirror this.\n- Joint filings are permitted and encouraged when multiple institutions are involved in the same suspicious activity; FinCEN's guidance on joint filers is detailed in its 2017 Joint SAR Guidance (still operative in 2027).\n\nFor fintech companies operating under a bank-partner model, know who owns the SAR obligation. In most sponsor-bank arrangements, the chartered institution retains primary BSA obligations, but program agreements increasingly require the fintech to maintain its own transaction monitoring, escalate findings within defined SLAs, and provide supporting documentation on demand. Regulators have made clear — most recently in the OCC's 2026 third-party risk management bulletin — that "the bank cannot outsource its BSA responsibility."\n\n## Common Filing Mistakes That Create Examiner Problems\n\n1. Filing on every alert, regardless of analysis. Volume alone does not satisfy the BSA. A SAR filed with no investigative rationale beyond "the system flagged it" suggests your institution has no meaningful AML program — just automated defensiveness.\n\n2. De-risking instead of filing. Closing an account without filing a SAR when filing is warranted is itself a potential violation, and examiners are trained to spot account-closure patterns that correlate with suspicious activity thresholds.\n\n3. Missing the continuing activity window. If the subject remains a customer and suspicious behavior continues, the 90-day continuing SAR obligation is not optional. Build calendar triggers into your case-management workflow.\n\n4. Inadequate documentation of the "no-file" decision. When your team reviews an alert and concludes no SAR is warranted, document why. An undocumented no-file decision looks, to an examiner, like willful blindness.\n\n5. Tipping off the subject. This bears repeating. Do not ask the customer to explain the suspicious transactions as part of your SAR investigation. If you need to conduct customer due diligence that might alert the subject, consult legal counsel on sequencing.\n\n## How Technology Is Reshaping SAR Compliance in 2027\n\nThe shift from rule-based transaction monitoring to machine-learning-driven behavioral analytics is now a mainstream story, not a future one. According to a February 2027 [Federal Reserve survey of [BSA compliance](/blog/bsa-aml-startup-checklist-2027) officers](https://www.federalreserve.gov/supervisionreg/topics/bank-secrecy-act-anti-money-laundering.htm), 61% of institutions with more than $10 billion in assets had deployed ML-augmented monitoring by end of 2026, up from 38% in 2023.\n\nFor smaller institutions and fintechs, the more immediate opportunity is in narrative automation — not replacing the human judgment embedded in a SAR narrative, but pre-populating the who/what/when/where with structured transaction data so investigators can focus on the "why." Platforms that expose clean, auditable transaction ledgers with enriched merchant data and categorization are materially reducing the time-to-file for compliance teams that previously spent hours reconstructing activity from raw core-banking exports.\n\nThis is an area where infrastructure matters as much as policy. If your transaction data is fragmented across systems, your SAR program will always be playing catch-up. For fintech teams building or evaluating that infrastructure, our developer documentation at AtlasForge Financial's platform details how the AtlasForge Financial API surfaces transaction metadata in a format purpose-built for downstream compliance workflows — including timestamped ledger events, counterparty enrichment, and anomaly flags that integrate directly into case-management systems.\n\nTeams building consumer-facing products on top of that infrastructure should also look at how real-time spending visibility reduces the kind of account misuse that generates SARs in the first place. Safe to Spend 365, AtlasForge Financial's budgeting and cash-flow layer, gives account holders clear, daily views of their financial picture — reducing the information asymmetry that bad actors exploit in consumer accounts and helping institutions distinguish genuine unusual activity from a customer who simply moved.\n\nFor deeper reading on structuring your compliance stack, see our post on building a defensible AML program for fintech companies and our overview of transaction monitoring architecture.\n\n---\n\nSAR compliance isn't glamorous work, but it is consequential. The 30-day clock is unforgiving. The narrative field is your institution's reputation in paragraph form. And the six red flags covered here aren't trivia — they're the patterns that show up in enforcement actions, in consent orders, and in the evening news when something goes wrong. Build the workflows, document the decisions, and file on time.

Ready to build on AtlasForge?

Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.