Knowing when to file a Suspicious Activity Report is one of the most critical — and most nuanced — BSA compliance obligations. Here is what triggers a SAR, how to recognize suspicious activity, and how to build a defensible filing decision process.
What Triggers a Suspicious Activity Report? A Guide for Fintechs
Fintechs that qualify as Money Services Businesses are required to file Suspicious Activity Reports with FinCEN when they know, suspect, or have reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA requirements, lacks a lawful purpose, or involves the use of the financial institution to facilitate criminal activity.
Understanding what triggers a SAR — and what does not — is one of the most consequential compliance decisions a fintech makes. Over-filing creates false intelligence burden. Under-filing creates regulatory and legal exposure. The goal is a calibrated, defensible filing program.
The Legal Standard for SAR Filing
The SAR filing obligation is triggered when a fintech knows, suspects, or has reason to suspect that a transaction of $5,000 or more involves illicit activity. "Has reason to suspect" is a lower standard than "knows" or "believes" — it means that based on available information, a reasonable compliance professional would suspect illegal activity.
This is a lower bar than most people expect. You do not need to prove criminal activity to file a SAR. You need to have reasonable grounds for suspicion based on the information available to you. Waiting for certainty is almost always waiting too long.
Common SAR Triggers
Structuring
Structuring — breaking up transactions to stay below reporting thresholds — is one of the most common SAR triggers. Signs include multiple transactions just below $10,000, multiple same-day transactions that together would exceed a threshold, and customers who ask about reporting thresholds before transacting.
Unusual Transaction Patterns
Transactions that are inconsistent with the customer's stated business purpose, profile, or transaction history — sudden volume spikes, transactions that do not match the customer's declared occupation or business, activity that makes no apparent economic sense.
High-Risk Geographies
Transactions involving countries or jurisdictions on the FATF's high-risk list, OFAC-sanctioned countries, or jurisdictions known for money laundering or drug trafficking activity.
Layering Patterns
Rapid movement of funds through multiple accounts, frequent round-dollar transfers, or patterns designed to obscure the origin or destination of funds.
Identity Issues
Customers who provide inconsistent or suspicious identity information, refuse to provide required documentation, present forged or altered documents, or whose identity cannot be verified.
Politically Exposed Persons
Transactions involving Politically Exposed Persons — particularly those involving large amounts or transfers to high-risk jurisdictions — may trigger SAR filing even when no single transaction appears definitively suspicious.
OFAC Hits and Near-Misses
Confirmed OFAC hits must be blocked and reported to OFAC — but near-misses and fuzzy matches that are resolved without a confirmed hit may still merit SAR consideration if the overall customer profile presents other risk factors.
Crypto-Specific Triggers
In the cryptocurrency context, additional triggers include use of mixing or tumbling services, transactions involving sanctioned wallet addresses, high-velocity wallet-hopping patterns, and funds from addresses associated with darknet markets or ransomware.
What Does NOT Automatically Trigger a SAR
A transaction being large is not by itself a SAR trigger. A customer being in a high-risk business category is not by itself a SAR trigger. An alert from your transaction monitoring system is not by itself a SAR trigger — it is the starting point for an investigation that may or may not result in a SAR filing.
SAR filing decisions must always be based on an investigation and analysis — not an automated threshold.
SAR Filing Requirements
When the decision to file is made, the SAR must be filed with FinCEN within 30 days of the date the suspicious activity was first detected. If the subject of the SAR cannot be identified, the filing deadline extends to 60 days. SARs must not be disclosed to the subject of the filing. See our article on SAR filing requirements for a full guide to the mechanics.
Frequently Asked Questions
Do I need to file a SAR if the customer is not a criminal?
Yes, if the transaction triggers the filing standard. The SAR filing obligation is based on the transaction — not on whether the customer is definitively a criminal. Reasonable suspicion about a transaction is sufficient to trigger filing regardless of the customer's actual status.
What if I filed a SAR and the customer turns out to be innocent?
SAR filers are protected from civil liability for SAR filings made in good faith. Good-faith filing of a SAR does not create legal exposure to the filer, even if the customer later turns out to have not been engaged in criminal activity.
How ComplyOne Helps
ComplyOne helps fintechs design SAR filing programs — from monitoring rule calibration through investigation workflows, filing decision frameworks, and SAR narrative quality — through advisory services, compliance technology, or both.
Talk to the ComplyOne team to get started.
The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.