Compliance
Oct 9, 2026

Suspicious Activity Report (SAR): How SAR Filing Works

What a suspicious activity report is, US SAR filing rules ($2,000, 30 days), EU and UK equivalents, tipping-off, and what a SAR means for users.

Suspicious Activity Report (SAR): How SAR Filing Works

A suspicious activity report (SAR) is a confidential report that a bank, crypto exchange or other regulated business files with the government when it knows or suspects that a transaction is linked to money laundering, terrorist financing or another crime. In the US, a crypto exchange registered as a money services business must file a SAR for suspicious transactions of USD 2,000 or more within 30 calendar days of first detecting the facts, under 31 CFR 1022.320.

Outside the US the same thing is usually called a suspicious transaction report (STR) and goes to the national financial intelligence unit (FIU). This guide explains the rules in the US, EU and UK, how a SAR is put together inside a compliance team, why the customer is never told, and what it means if your own account is caught up in one.

SAR, STR: what the terms mean

The global standard is FATF Recommendation 20: if a financial institution "suspects or has reasonable grounds to suspect that funds are the proceeds of a criminal activity, or are related to terrorist financing", it should be required by law to report its suspicions promptly to the FIU. The interpretive note adds that all suspicious transactions, including attempted ones, should be reported "regardless of the amount of the transaction". The FATF applies the same duty to virtual asset service providers; see what is a VASP.

Countries use different names. The US and UK say suspicious activity report; the EU and the FATF say suspicious transaction report or "reporting of suspicions". The idea is identical: a regulated firm passes its suspicion, with supporting facts, to an authority that can investigate.

A SAR is not an accusation or a criminal charge. It is intelligence. Most never lead to any action against the customer.

US SAR rules for crypto businesses

FinCEN's 2019 guidance treats crypto exchangers and hosted wallet providers as money transmitters, a type of money services business (MSB). That puts them under the MSB SAR rule, 31 CFR 1022.320. A transaction must be reported if it is conducted or attempted through the MSB, involves or aggregates at least USD 2,000, and the MSB knows, suspects or has reason to suspect that it:

  • involves funds from illegal activity, or is meant to hide or disguise such funds;
  • is designed, through structuring or other means, to evade Bank Secrecy Act requirements;
  • serves no business or apparent lawful purpose, with no reasonable explanation after examining the facts; or
  • involves use of the MSB to facilitate criminal activity.

Key deadlines and duties:

  • 30 calendar days from initial detection of the facts to file.
  • Immediate phone call to law enforcement, in addition to the SAR, for violations needing urgent attention, such as ongoing laundering schemes.
  • Five years of record-keeping for the SAR and its supporting documents.
  • Voluntary filing is allowed below the threshold or where reporting is not required.

Banks follow a parallel rule, 31 CFR 1020.320, with a USD 5,000 threshold. A bank that has not identified a suspect may take an extra 30 days, but must never file later than 60 days after initial detection.

EU and UK rules

European Union. Today the duty sits in Article 33 of the Anti-Money Laundering Directive (EU) 2015/849, as implemented in each member state. From 10 July 2027 it moves into the directly applicable AML Regulation (EU) 2024/1624, which lists crypto-asset service providers among obliged entities. Its Article 69 requires firms to report to the FIU promptly, "regardless of the amount involved", including attempted transactions and suspicions that arise because customer due diligence could not be completed. Firms must answer FIU follow-up requests within 5 working days, which the FIU can shorten in urgent cases, to less than 24 hours if needed. Article 71 requires a firm to hold back a transaction it suspects until it has reported; it may then proceed, after assessing the risk, if the FIU gives no contrary instruction within 3 working days.

United Kingdom. SARs go to the UK Financial Intelligence Unit (UKFIU), part of the National Crime Agency, which says it receives more than 850,000 SARs a year. Regulated firms that fail to report when required can be prosecuted under sections 330 to 331 of the Proceeds of Crime Act 2002, with penalties on indictment of up to five years in prison, a fine, or both. UK firms can also request a "defence against money laundering" (DAML) before proceeding with a suspicious transaction, which starts a 7 working day notice period.

How a SAR is filed, step by step

Inside a crypto exchange, a SAR is usually the end of a pipeline:

  1. Alert. A rule in transaction monitoring, an on-chain analytics hit, a sanctions or adverse media match, or a tip from staff flags activity.
  2. Investigation. An analyst reviews the customer's profile, declared income, history and counterparties, and may ask the customer for documents. The US 30-day clock starts when the firm detects facts that may justify a SAR, not when the alert fires.
  3. Decision. The analyst or a senior reviewer decides whether the suspicion is cleared or reportable, and records the reasoning either way.
  4. Narrative. The report explains who, what, when, where and why the activity is suspicious, with wallet addresses and transaction hashes for crypto.
  5. Filing. The SAR goes to FinCEN through its designated filing system, the UKFIU's SAR Portal or the national FIU's system.
  6. Follow-up. The firm decides whether to restrict, keep monitoring or exit the relationship, and answers any requests from the authorities.

Much of this is now handled in case-management tools. iDenfy's transaction monitoring software, for example, combines velocity rules and sanctions, PEP and adverse media screening with a tiered alert investigation workflow that ends in a SAR export. For a comparison of vendors, see the best crypto transaction monitoring software in 2026.

Confidentiality, tipping-off and safe harbour

Every regime makes SARs secret:

  • US. A SAR, and any information that would reveal its existence, is confidential under 31 CFR 1022.320(d). An MSB that is subpoenaed for a SAR must decline and notify FinCEN.
  • EU. Article 73 of the AMLR forbids telling the customer or third parties that transactions are being assessed, that a report has been or will be made, or that an analysis is under way.
  • UK. The NCA reminds reporters of the tipping-off and prejudicing-an-investigation offences in sections 333A and 342 of the Proceeds of Crime Act.

In return, firms that report in good faith are protected. FATF Recommendation 21 calls for protection from criminal and civil liability for good-faith reports, "even if they did not know precisely what the underlying criminal activity was". The US version is the safe harbour in 31 U.S.C. 5318(g)(3), referenced in 1022.320(e); the EU's is Article 72 of the AMLR.

What crypto SARs look like

The FATF's Virtual Assets Red Flag Indicators report (September 2020) is built from real cases, several of which started with a report:

  • A South African crypto platform filed STRs after noticing many individuals, some sharing the same address and IP address, buying large amounts of crypto and immediately sending it to overseas platforms. The scheme involved more than 150 people and about USD 108 million.
  • A bank filed an STR on a personal account that received payments and immediately forwarded them in split amounts to a company that converted them into Bitcoin. The account holder appeared to be a money mule recruited on social media. The bank also suspended the transfers, which made a later seizure possible.

Typical triggers are the ones listed in our guide to AML red flags in crypto: structuring, deposits far above a customer's profile, funds from mixers or sanctioned addresses, and deposit-and-withdraw cycles with no trading.

What a SAR means for you as a user

You will almost never know if a SAR has been filed about you, because the firm is legally barred from saying so. What you may see is a withdrawal hold, a request for source-of-funds documents, or an account closure with little explanation. Vague answers from support staff are often a sign they cannot legally say more, not that they are hiding a mistake.

If that happens, answer document requests fully through official channels, keep records of where your funds came from, and do not open a second account to get around a restriction. Ignore anyone who offers to "clear" a flag for a fee; see crypto recovery scams. JewelSwap's DeFi apps are non-custodial and do not hold customer accounts or run KYC themselves; see KYC in DeFi explained.

Frequently asked questions

What is a suspicious activity report?

It is a confidential report a regulated business, such as a bank or crypto exchange, files with the government when it knows or suspects a transaction is linked to money laundering, terrorist financing or another crime.

What is the SAR threshold for crypto exchanges in the US?

Crypto exchanges registered as money services businesses must file a SAR for suspicious transactions involving or aggregating at least USD 2,000. Banks have a USD 5,000 threshold. Firms may also file voluntarily below these amounts.

How long does a business have to file a SAR?

In the US, 30 calendar days from first detecting the facts. Banks that have not identified a suspect can take up to 30 more days, to a maximum of 60. EU rules require reporting promptly, with no minimum amount.

Will I be told if a SAR is filed about me?

No. US, EU and UK law all prohibit the firm from revealing that a report has been or will be filed. This tipping-off ban is why exchanges often give little explanation for an account review.

Does a SAR mean I am being investigated?

Not necessarily. A SAR is intelligence for the authorities, not a charge. Many are stored and analysed without any action against the customer, though some lead to investigations or requests for more information.

What is the difference between a SAR and an STR?

They are the same kind of report under different names. The US and UK say suspicious activity report; the FATF and EU usually say suspicious transaction report or reporting of suspicions.

Keep reading

This article is educational and is not legal advice. US references are to 31 CFR 1022.320, 31 CFR 1020.320 and FinCEN guidance FIN-2019-G001; EU references are to Directive (EU) 2015/849 and Regulation (EU) 2024/1624; UK figures are from the National Crime Agency's SARs page; FATF references are to Recommendations 20 and 21 and the September 2020 red flag indicators report. All were checked on 9 October 2026.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.