Section 9 · Lesson 9.5
Suspicious Activity and Reporting (SAR/STR)
A regulated business does not merely "refuse suspicious clients" — it is obliged to report its suspicions to the state. This mechanism is called a suspicious activity report. In this lesson we cover what a SAR/STR is, who files it and when, how the process looks inside a VASP, which signs push an analyst to escalate a case, and why you cannot tell the client that a report has been filed.
What a SAR/STR is
SAR (Suspicious Activity Report) and STR (Suspicious Transaction Report) — a report that a financial organisation or VASP files with the financial intelligence unit (FIU — Financial Intelligence Unit) of its country when there is a reasonable suspicion that an operation is linked to money laundering, terrorist financing or another crime. The name differs across jurisdictions (SAR — more common in the US/UK, STR — in many other countries), but the essence is the same.
It is important to grasp the nature of the report:
- It is a report of suspicion, not a verdict. The organisation is not obliged to prove a crime — reasonable grounds to suspect are enough.
- The threshold is "suspicion," not "certainty." That is precisely why it is better to report and be wrong than to stay silent and become an accomplice.
- It is a protection for the organisation itself. A timely report relieves the VASP of liability for missing a suspicious operation.
Why this matters: failing to file a report when grounds exist is a violation with serious penalties for the organisation and personally for the compliance officer. A SAR/STR is not bureaucracy but a legal shield.
SAR/STR ≠ CTR: don't confuse it with threshold reporting
Threshold report (e.g. CTR)
Filed automatically when an amount is exceeded (for example, a large operation), regardless of suspicion. This is "by the numbers."
SAR/STR
Filed on the substance of an operation — when there is suspicion, regardless of the amount. It can be filed even for a small sum.
The key difference: a threshold report triggers on size, a SAR/STR on nature and context. Even a small transaction can be suspicious if its structure hints at a scheme (for example, splitting — structuring/smurfing: breaking a large sum into many small ones to get around thresholds).
Signs for escalation (red flags)
The first-line analyst does not decide everything alone — on triggers they escalate the case to the compliance officer, who decides whether to file a SAR/STR. Typical grounds:
- A direct link between the address and crime: funds go to/from mixers (Tornado and the like), darknet markets, known scam/phishing addresses, exchange hacks.
- Sanctions. Any contact with addresses from sanctions lists (OFAC SDN and others) — immediate escalation.
- Splitting operations below reporting thresholds (structuring).
- Mismatch with the client's profile: a student with turnover like a large business's; a sharp spike in activity.
- Transit with no economic sense: funds come in and immediately go out, a "pass-through" wallet.
- Evasion of KYC: refusal to confirm the source of funds, forged documents, payment by third parties.
- Use of privacy tools to hide the trail (mixers, privacy coins on the way in/out).
- Behavioural signals: the client is nervous about questions on the source, is in a hurry, asks you "not to check."
No single flag is a "verdict" on its own. The analyst's job is to gather context: one signal may be a coincidence, but their combination forms a reasonable suspicion.
How the process looks inside a VASP
- Detection. A trigger fires automatically (the monitoring/address-scoring system) or manually (an analyst spotted an anomaly).
- Initial review. The first-line analyst gathers data: the client's profile, operation history, address scoring, source of funds.
- Escalation. If the suspicion is confirmed, the case goes to the compliance officer (MLRO — Money Laundering Reporting Officer).
- Decision. The MLRO weighs the grounds and decides: to file a SAR/STR or not; and at the same time — to freeze/restrict the operation.
- Filing. The report is sent to the FIU in the prescribed form and time frame, with a description of the facts and attachments.
- Retention and follow-up. The case is documented and stored; if necessary — responses to authorities' requests, a decision to continue/terminate the relationship with the client.
The role of AML analytics: tools like AMLConsensus provide the very evidence base for steps 1–2 — risk scoring, links to sanctions/darknet/mixers, a report to attach to the SAR/STR.
"Do not disclose": the tipping-off rule
A critically important point that newcomers often break. There is a prohibition on tipping-off — you cannot tell the client (or third parties) that a SAR/STR has been filed on them or that an operation is being investigated. The reason: a forewarned subject will destroy the trail, move the funds out and derail the investigation.
- You cannot write to the client "we have filed a report on you."
- You cannot hint that "the financial intelligence unit is interested in you."
- You can and should act formally: apply standard procedures (a request for documents, a restriction) without revealing the fact of the report.
Breaching tipping-off is a standalone offence for which the employee is personally liable. The safety formula: "act by the procedure, but stay silent about the fact of the report."
An internal escalation template (SAR triage)
A mini-form the analyst fills in when handing a case to the compliance officer:
Client/ID: ...
Date of detection: ...
Trigger (how identified): auto-scoring / manual / complaint
Operations (dates, amounts, addresses/hashes): ...
Red flags (list): ...
Address scoring (risk, links): ...
Source of funds stated/confirmed: yes/no
Actions taken: restriction / freeze / document request
Analyst's conclusion: recommend SAR/STR — yes/no, why
Attachments: reports, screenshots, statements
A form like this makes the MLRO's decision fast and well-grounded, and the case defensible under a later inspection.
Lesson summary
- A SAR/STR is a report of suspicion (not of a proven crime), filed with the FIU.
- The threshold is "reasonable suspicion," not "certainty"; an amount is not required.
- Distinguish SAR/STR (by substance) from threshold reports (by size).
- Red flags are assessed together; the compliance officer makes the decision.
- The process: detection → review → escalation → decision → filing → retention.
- The tipping-off prohibition applies: the client is not told of the fact of the report.
The main idea: the reporting system works only if the rank-and-file analyst can recognise the flags and escalate correctly. That is exactly why the skill of AML-checking an address is not "technical" but built directly into the defence of the financial system.
This material is educational and does not constitute legal or tax advice.