What a suspicious activity report is, US SAR filing rules ($2,000, 30 days), EU and UK equivalents, tipping-off, and what a SAR means for users.

A suspicious activity report (SAR) is a confidential report that a bank, crypto exchange or other regulated business files with the government when it knows or suspects that a transaction is linked to money laundering, terrorist financing or another crime. In the US, a crypto exchange registered as a money services business must file a SAR for suspicious transactions of USD 2,000 or more within 30 calendar days of first detecting the facts, under 31 CFR 1022.320.
Outside the US the same thing is usually called a suspicious transaction report (STR) and goes to the national financial intelligence unit (FIU). This guide explains the rules in the US, EU and UK, how a SAR is put together inside a compliance team, why the customer is never told, and what it means if your own account is caught up in one.
The global standard is FATF Recommendation 20: if a financial institution "suspects or has reasonable grounds to suspect that funds are the proceeds of a criminal activity, or are related to terrorist financing", it should be required by law to report its suspicions promptly to the FIU. The interpretive note adds that all suspicious transactions, including attempted ones, should be reported "regardless of the amount of the transaction". The FATF applies the same duty to virtual asset service providers; see what is a VASP.
Countries use different names. The US and UK say suspicious activity report; the EU and the FATF say suspicious transaction report or "reporting of suspicions". The idea is identical: a regulated firm passes its suspicion, with supporting facts, to an authority that can investigate.
A SAR is not an accusation or a criminal charge. It is intelligence. Most never lead to any action against the customer.
FinCEN's 2019 guidance treats crypto exchangers and hosted wallet providers as money transmitters, a type of money services business (MSB). That puts them under the MSB SAR rule, 31 CFR 1022.320. A transaction must be reported if it is conducted or attempted through the MSB, involves or aggregates at least USD 2,000, and the MSB knows, suspects or has reason to suspect that it:
Key deadlines and duties:
Banks follow a parallel rule, 31 CFR 1020.320, with a USD 5,000 threshold. A bank that has not identified a suspect may take an extra 30 days, but must never file later than 60 days after initial detection.
European Union. Today the duty sits in Article 33 of the Anti-Money Laundering Directive (EU) 2015/849, as implemented in each member state. From 10 July 2027 it moves into the directly applicable AML Regulation (EU) 2024/1624, which lists crypto-asset service providers among obliged entities. Its Article 69 requires firms to report to the FIU promptly, "regardless of the amount involved", including attempted transactions and suspicions that arise because customer due diligence could not be completed. Firms must answer FIU follow-up requests within 5 working days, which the FIU can shorten in urgent cases, to less than 24 hours if needed. Article 71 requires a firm to hold back a transaction it suspects until it has reported; it may then proceed, after assessing the risk, if the FIU gives no contrary instruction within 3 working days.
United Kingdom. SARs go to the UK Financial Intelligence Unit (UKFIU), part of the National Crime Agency, which says it receives more than 850,000 SARs a year. Regulated firms that fail to report when required can be prosecuted under sections 330 to 331 of the Proceeds of Crime Act 2002, with penalties on indictment of up to five years in prison, a fine, or both. UK firms can also request a "defence against money laundering" (DAML) before proceeding with a suspicious transaction, which starts a 7 working day notice period.
Inside a crypto exchange, a SAR is usually the end of a pipeline:
Much of this is now handled in case-management tools. iDenfy's transaction monitoring software, for example, combines velocity rules and sanctions, PEP and adverse media screening with a tiered alert investigation workflow that ends in a SAR export. For a comparison of vendors, see the best crypto transaction monitoring software in 2026.
Every regime makes SARs secret:
In return, firms that report in good faith are protected. FATF Recommendation 21 calls for protection from criminal and civil liability for good-faith reports, "even if they did not know precisely what the underlying criminal activity was". The US version is the safe harbour in 31 U.S.C. 5318(g)(3), referenced in 1022.320(e); the EU's is Article 72 of the AMLR.
The FATF's Virtual Assets Red Flag Indicators report (September 2020) is built from real cases, several of which started with a report:
Typical triggers are the ones listed in our guide to AML red flags in crypto: structuring, deposits far above a customer's profile, funds from mixers or sanctioned addresses, and deposit-and-withdraw cycles with no trading.
You will almost never know if a SAR has been filed about you, because the firm is legally barred from saying so. What you may see is a withdrawal hold, a request for source-of-funds documents, or an account closure with little explanation. Vague answers from support staff are often a sign they cannot legally say more, not that they are hiding a mistake.
If that happens, answer document requests fully through official channels, keep records of where your funds came from, and do not open a second account to get around a restriction. Ignore anyone who offers to "clear" a flag for a fee; see crypto recovery scams. JewelSwap's DeFi apps are non-custodial and do not hold customer accounts or run KYC themselves; see KYC in DeFi explained.
It is a confidential report a regulated business, such as a bank or crypto exchange, files with the government when it knows or suspects a transaction is linked to money laundering, terrorist financing or another crime.
Crypto exchanges registered as money services businesses must file a SAR for suspicious transactions involving or aggregating at least USD 2,000. Banks have a USD 5,000 threshold. Firms may also file voluntarily below these amounts.
In the US, 30 calendar days from first detecting the facts. Banks that have not identified a suspect can take up to 30 more days, to a maximum of 60. EU rules require reporting promptly, with no minimum amount.
No. US, EU and UK law all prohibit the firm from revealing that a report has been or will be filed. This tipping-off ban is why exchanges often give little explanation for an account review.
Not necessarily. A SAR is intelligence for the authorities, not a charge. Many are stored and analysed without any action against the customer, though some lead to investigations or requests for more information.
They are the same kind of report under different names. The US and UK say suspicious activity report; the FATF and EU usually say suspicious transaction report or reporting of suspicions.
This article is educational and is not legal advice. US references are to 31 CFR 1022.320, 31 CFR 1020.320 and FinCEN guidance FIN-2019-G001; EU references are to Directive (EU) 2015/849 and Regulation (EU) 2024/1624; UK figures are from the National Crime Agency's SARs page; FATF references are to Recommendations 20 and 21 and the September 2020 red flag indicators report. All were checked on 9 October 2026.