SAR filing requirements under the BSA are specific, deadline-driven, and non-negotiable. Here is a complete breakdown of what triggers a SAR, what the deadlines are, and what your program must include to stay compliant.
SAR Filing Requirements: What Every Fintech Needs to Know
Suspicious Activity Report filing is one of the most critical and most frequently misunderstood BSA compliance obligations for fintechs. The requirements are specific — there are defined dollar thresholds, specific deadlines, required content, and strict confidentiality rules. Getting any of these wrong is a BSA violation.
This article provides a complete breakdown of SAR filing requirements so your program is built correctly from the start.
The Legal Basis for SAR Filing
SAR filing requirements come from the Bank Secrecy Act and its implementing regulations administered by FinCEN. The requirement applies to financial institutions — a category that includes most fintechs that move money, particularly those registered as Money Services Businesses.
The obligation is straightforward in concept: when a covered institution detects activity that meets the definition of suspicious activity and exceeds the applicable dollar threshold, it must file a SAR with FinCEN within the required timeframe.
Who Is Required to File SARs?
SAR filing requirements apply to:
Money Services Businesses — including money transmitters, prepaid card issuers, cryptocurrency businesses, and other MSB categories — that have detected suspicious activity meeting the filing criteria.
Banks and credit unions — subject to their own parallel SAR filing requirements under bank-specific BSA regulations.
Broker-dealers — subject to FINRA and SEC parallel requirements.
Fintechs operating under sponsor bank arrangements — where the filing obligation may rest with the fintech, the bank, or both depending on the terms of the program agreement. Clarify this in writing before you launch.
The Dollar Threshold
For most MSBs and fintechs, a SAR must be filed for transactions of $2,000 or more that meet the suspicious activity criteria. This threshold applies to individual transactions or to aggregated transactions involving the same person within a 30-day rolling period.
For banks and broker-dealers the threshold is $5,000.
The threshold applies to the amount involved in the suspicious activity — not the total balance or transaction history of the account.
What Counts as Suspicious Activity
A SAR must be filed when your institution knows, suspects, or has reason to suspect that a transaction:
Involves funds from illegal activity — including proceeds of crime, drug trafficking, fraud, corruption, or tax evasion.
Is designed to evade BSA reporting requirements — including structuring transactions to stay below reporting thresholds.
Has no apparent lawful purpose — and cannot be reasonably explained after investigation.
Involves use of your institution to facilitate criminal activity — including situations where an employee may be complicit.
The legal standard is suspicion — not certainty. You do not need to know that a crime occurred. You need a documented, reasonable basis to suspect it might have.
The 30-Day Filing Deadline
SARs must be filed within 30 calendar days of the date suspicious activity was initially detected.
If additional time is specifically needed to identify a subject — the individual or entity conducting the suspicious activity — a maximum extension of 60 calendar days is available. This extension applies to identifying the subject, not to completing the investigation generally.
There is no extension process, no grace period, and no exception. Missing the 30-day deadline is a BSA violation regardless of the reason.
The Confidentiality Requirement
Once a SAR is filed — or even once the decision to file is under consideration — disclosure to the subject of the SAR, to any related party, or to any outside person is prohibited by federal law. This prohibition applies to every person in your organization.
Violation of the SAR confidentiality rule is a separate federal offense independent of any underlying SAR violation.
What Must Be in the SAR
A properly completed SAR includes subject information — name, address, date of birth, identification numbers, and account information for the person or entity whose activity is being reported — transaction information covering amounts, dates, and transaction types, the category of suspicious activity, and a narrative.
The narrative is the most important element and the most commonly inadequate. It must describe what happened, who was involved, when and how the suspicious activity occurred, and why it is suspicious — clearly and specifically enough for a law enforcement agent with no prior knowledge of the account to understand the situation.
Avoid generic language. Specific facts — amounts, dates, transaction types, counterparties, and the specific reasons for suspicion — make a SAR useful. Generic descriptions make it nearly useless.
Recordkeeping Requirements
Every SAR filed must be retained, along with all supporting investigation documentation, for a minimum of five years from the filing date. This includes monitoring alerts, investigation notes, account history reviewed, and any communications related to the filing decision.
Documentation for alerts that were cleared without a SAR filing must also be retained — your reasoning for not filing is as important as your reasoning for filing in an examination context.
Building a Compliant SAR Program
A compliant SAR program requires four operational elements before your first customer transaction: a transaction monitoring system that generates alerts for potentially suspicious activity, a documented investigation workflow for reviewing alerts and reaching filing decisions, a designated BSA Officer with authority to make final SAR decisions, and enrollment in FinCEN's BSA E-Filing System.
Do not wait until you encounter suspicious activity to build this infrastructure.
Frequently Asked Questions
What is the SAR filing threshold for cryptocurrency businesses?
Cryptocurrency businesses that qualify as money transmitters under FinCEN's guidance are subject to the same $2,000 SAR filing threshold as other MSBs. The nature of the asset — cryptocurrency versus fiat — does not change the filing threshold.
Do we need to file a SAR for every suspicious alert?
No. A monitoring alert requires investigation and documentation — not automatic SAR filing. Many flagged transactions have legitimate explanations when reviewed in full context. What is required is that every alert is investigated, the reasoning is documented, and a SAR is filed when the conclusion is that the activity is suspicious and meets the threshold.
Can we be held liable for filing a SAR in good faith?
No. The BSA provides safe harbor protections for good-faith SAR filers. A financial institution that files a SAR in good faith cannot be held civilly liable for the filing even if the underlying activity turns out not to involve criminal conduct.
How ComplyOne Helps
ComplyOne helps fintechs build SAR filing programs that meet BSA requirements — from investigation workflow design to SAR narrative quality to deadline management — through advisory services, compliance technology, or both.
Talk to the ComplyOne team to get started.
The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.