What is a suspicious activity report (SAR)?

A suspicious activity report (SAR) is a confidential filing that financial institutions submit to the Financial Crimes Enforcement Network (FinCEN) to report known or suspected illegal activity, such as money laundering, fraud, or terrorist financing. SARs are a cornerstone of the U.S. anti-money laundering (AML) framework established under the Bank Secrecy Act (BSA).

When a bank, credit union, or other regulated entity detects a transaction or pattern that has no clear lawful purpose—or that appears designed to disguise illicit funds—it files a report describing what it observed. These reports give law enforcement agencies and regulators an early-warning system for financial crime, turning frontline observations at financial institutions into actionable intelligence.

Crucially, such a report is not an accusation. It is a report of suspicion, filed when activity meets a regulatory threshold for being unusual or potentially illegal, even if no crime is ultimately confirmed.

Who must file a suspicious activity report?

SAR obligations under the BSA apply to a wide range of financial institutions, including:

  • Banks, credit unions, and other depository institutions
  • Money services businesses (MSBs)—including cryptocurrency exchanges and other virtual asset service providers (VASPs)
  • Casinos and card clubs
  • Insurance companies and broker-dealers

Each institution must maintain an AML program and designate a compliance officer responsible for identifying suspicious activity and ensuring reports are filed correctly and on time. In some jurisdictions and professions, reporting obligations extend to gatekeepers such as law firms.

When must a SAR be filed?

A financial institution must file a SAR within 30 calendar days of the initial detection of facts that may constitute a basis for filing. If no suspect can be identified, the deadline may be extended to 60 days. Common triggers include:

  • Structuring — breaking large transactions into smaller amounts to evade reporting thresholds.
  • Insider abuse — suspected wrongdoing by employees, regardless of amount.
  • Criminal violations — activity tied to fraud, identity theft, tax evasion, or other illegal activity.
  • Red flags — transactions with no apparent economic purpose, or inconsistent with a customer’s known profile.

A key rule accompanies every filing: institutions must not “tip off” the subject. Disclosing that a report has been filed is itself a violation, because it could compromise an investigation.

How is a SAR filed?

In the United States, SARs are submitted electronically through FinCEN’s BSA E-Filing System. A complete filing includes a structured report and a written narrative explaining the who, what, when, where, and why of the suspicious activity, along with supporting documentation that the institution retains and provides to law enforcement on request. Banking regulators such as the Office of the Comptroller of the Currency (OCC) examine institutions to confirm reports are filed properly. The quality of the narrative matters: a clear, well-evidenced filing is far more useful to investigators than a vague one.

SAR vs. CTR: what’s the difference?

SARs are often confused with currency transaction reports (CTRs), but they serve different purposes:

  • A currency transaction report (CTR) is filed automatically for cash transactions above a set threshold (in the U.S., more than $10,000). It is threshold-based and requires no suspicion.
  • A suspicious activity report (SAR) is filed whenever activity appears suspicious, regardless of amount. It is suspicion-based and requires judgment.

In short: a CTR reports a fact (a large cash transaction); a SAR reports a concern.

How do SARs work in cryptocurrency compliance?

As money services businesses, cryptocurrency exchanges and other VASPs carry the same reporting obligations as traditional financial institutions. When transaction monitoring flags activity tied to illicit sources—ransomware wallets, darknet markets, sanctioned entities, or laundering patterns—the VASP must investigate and, where warranted, file a SAR.

Crypto SARs have a distinct advantage: blockchain evidence. Because activity is recorded permanently on public ledgers, a crypto SAR narrative can include transaction hashes, wallet addresses, and the on-chain connections that tie a customer’s funds to known illicit entities. This makes crypto reports uniquely specific and traceable compared with traditional narrative reporting. Crypto-related SAR filings have grown rapidly as more institutions adopt blockchain analytics.

How do SARs support law enforcement?

FinCEN acts as the United States’ financial intelligence unit (FIU)—the agency that collects SARs and shares relevant intelligence with the FBI and other law enforcement agencies. Most countries operate their own FIU and an equivalent filing, often called a suspicious transaction report (STR). The Financial Action Task Force (FATF) sets the international standards that require these reporting regimes, making suspicious activity reporting a global pillar of AML and counter–terrorist financing efforts.

How Chainalysis helps with suspicious activity reporting

Chainalysis gives compliance teams the detection and evidence they need to file higher-quality SARs faster.

Chainalysis KYT (Know Your Transaction) provides real-time transaction monitoring that flags exposure to illicit activity—generating the alerts that initiate the SAR process and helping teams meet filing deadlines.

Chainalysis Reactor lets investigators trace funds across blockchains and assemble the transaction-level evidence—hashes, address clusters, and exposure to known entities—that strengthens a SAR narrative. Reactor’s analysis is validated under the Daubert standard in U.S. courts.

Together, these tools turn on-chain activity into clear, defensible suspicious activity reports that stand up to regulatory and law enforcement scrutiny.

Frequently asked questions about suspicious activity reports

Q: What is a suspicious activity report (SAR)?

A: A suspicious activity report (SAR) is a confidential filing that financial institutions submit to FinCEN under the Bank Secrecy Act to report known or suspected money laundering, fraud, terrorist financing, or other illegal activity. It is a report of suspicion, not proof of a crime.

Q: Who is required to file a SAR?

A: Banks, credit unions, money services businesses (including crypto exchanges and VASPs), casinos, and insurance companies are among the institutions required to file SARs. Each must maintain an AML program and a designated compliance officer responsible for reporting suspicious activity.

Q: When must a SAR be filed?

A: A SAR must generally be filed within 30 calendar days of initial detection of the suspicious activity, extendable to 60 days if no suspect is identified. Institutions are also prohibited from “tipping off” the subject that a SAR has been filed.

Q: What is the difference between a SAR and a CTR?

A: A currency transaction report (CTR) is filed automatically for cash transactions over a set threshold (over $10,000 in the U.S.) and requires no suspicion. A suspicious activity report (SAR) is filed whenever activity appears suspicious, regardless of amount. A CTR reports a fact; a SAR reports a concern.

Q: How do SARs apply to cryptocurrency?

A: Crypto exchanges and other VASPs are money services businesses and must file SARs like traditional institutions. Blockchain analytics helps them detect suspicious activity through transaction monitoring and strengthen SAR narratives with on-chain evidence such as wallet addresses and transaction hashes.

See how Chainalysis helps you stay compliant and secure.

Request a demo.

Chainalysis enables stronger suspicious activity reporting by flagging crypto transactions tied to illicit activity in real time and giving compliance teams the on-chain evidence—wallet addresses, transaction hashes, and entity exposure—to file clear, defensible SARs.