AMLConsensus · course
Programme · Lesson 9.5
Section 9 · Lesson 9.5

Suspicious Activity and Reporting (SAR/STR)

A regulated business does not merely "refuse suspicious clients" — it is obliged to report its suspicions to the state. This mechanism is called a suspicious activity report. In this lesson we cover what a SAR/STR is, who files it and when, how the process looks inside a VASP, which signs push an analyst to escalate a case, and why you cannot tell the client that a report has been filed.

What a SAR/STR is

SAR (Suspicious Activity Report) and STR (Suspicious Transaction Report) — a report that a financial organisation or VASP files with the financial intelligence unit (FIU — Financial Intelligence Unit) of its country when there is a reasonable suspicion that an operation is linked to money laundering, terrorist financing or another crime. The name differs across jurisdictions (SAR — more common in the US/UK, STR — in many other countries), but the essence is the same.

It is important to grasp the nature of the report:

Why this matters: failing to file a report when grounds exist is a violation with serious penalties for the organisation and personally for the compliance officer. A SAR/STR is not bureaucracy but a legal shield.

SAR/STR ≠ CTR: don't confuse it with threshold reporting

Threshold report (e.g. CTR)
Filed automatically when an amount is exceeded (for example, a large operation), regardless of suspicion. This is "by the numbers."
SAR/STR
Filed on the substance of an operation — when there is suspicion, regardless of the amount. It can be filed even for a small sum.

The key difference: a threshold report triggers on size, a SAR/STR on nature and context. Even a small transaction can be suspicious if its structure hints at a scheme (for example, splitting — structuring/smurfing: breaking a large sum into many small ones to get around thresholds).

Signs for escalation (red flags)

The first-line analyst does not decide everything alone — on triggers they escalate the case to the compliance officer, who decides whether to file a SAR/STR. Typical grounds:

No single flag is a "verdict" on its own. The analyst's job is to gather context: one signal may be a coincidence, but their combination forms a reasonable suspicion.

How the process looks inside a VASP

  1. Detection. A trigger fires automatically (the monitoring/address-scoring system) or manually (an analyst spotted an anomaly).
  2. Initial review. The first-line analyst gathers data: the client's profile, operation history, address scoring, source of funds.
  3. Escalation. If the suspicion is confirmed, the case goes to the compliance officer (MLRO — Money Laundering Reporting Officer).
  4. Decision. The MLRO weighs the grounds and decides: to file a SAR/STR or not; and at the same time — to freeze/restrict the operation.
  5. Filing. The report is sent to the FIU in the prescribed form and time frame, with a description of the facts and attachments.
  6. Retention and follow-up. The case is documented and stored; if necessary — responses to authorities' requests, a decision to continue/terminate the relationship with the client.
The role of AML analytics: tools like AMLConsensus provide the very evidence base for steps 1–2 — risk scoring, links to sanctions/darknet/mixers, a report to attach to the SAR/STR.

"Do not disclose": the tipping-off rule

A critically important point that newcomers often break. There is a prohibition on tipping-offyou cannot tell the client (or third parties) that a SAR/STR has been filed on them or that an operation is being investigated. The reason: a forewarned subject will destroy the trail, move the funds out and derail the investigation.

Breaching tipping-off is a standalone offence for which the employee is personally liable. The safety formula: "act by the procedure, but stay silent about the fact of the report."

An internal escalation template (SAR triage)

A mini-form the analyst fills in when handing a case to the compliance officer:

Client/ID: ... Date of detection: ... Trigger (how identified): auto-scoring / manual / complaint Operations (dates, amounts, addresses/hashes): ... Red flags (list): ... Address scoring (risk, links): ... Source of funds stated/confirmed: yes/no Actions taken: restriction / freeze / document request Analyst's conclusion: recommend SAR/STR — yes/no, why Attachments: reports, screenshots, statements

A form like this makes the MLRO's decision fast and well-grounded, and the case defensible under a later inspection.

Lesson summary

The main idea: the reporting system works only if the rank-and-file analyst can recognise the flags and escalate correctly. That is exactly why the skill of AML-checking an address is not "technical" but built directly into the defence of the financial system.

This material is educational and does not constitute legal or tax advice.