FIN-06 Financial Regulation & Digital Assets Money Movement Controls Federal
Suspicious Activity Reports: Filing Standards and the Confidentiality Rule
A SAR is the one filing a customer must never learn about. This brief sets out what triggers the obligation, how the 30-day clock runs, who may lawfully be told, and what the statutory safe harbour actually protects.
Briefing in 60 seconds
- A SAR is due within 30 calendar days of initial detection of facts that may form a basis for filing, extendable to 60 if no suspect is identified.
- Federal law makes both the report and its very existence confidential; a bank may not tell the customer, and disclosure carries its own penalties.
- The statute grants a safe harbour from liability to the filer and its people for reporting a possible violation, whether or not the suspicion proves correct.
- Dollar thresholds differ by institution type, and the trigger is a reasonable suspicion standard rather than proof of an underlying crime.
Controlling variables
- Status
- What kind of institution is filing. Banks, money services businesses, broker-dealers, and casinos sit under different FinCEN rules with different dollar thresholds.
- Timing
- When initial detection occurred. The clock runs from the date facts putting the institution on notice arise, not from the date an investigation closes.
- Facts
- Whether a suspect has been identified. Identification fixes the 30-day window; the absence of a suspect can support the additional 30 days.
- Documents
- What the supporting file contains. Supporting documentation is deemed part of the filing and must be produced to FinCEN or law enforcement on request.
- Procedural posture
- Whether a subpoena, civil discovery demand, or customer request seeks the report. The confidentiality rule does not bend to a private litigant's subpoena.
General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.
A Suspicious Activity Report is the only major regulatory filing a financial institution makes that the subject of the filing may never be told about. That single feature drives almost everything difficult about the obligation: the deadline runs quietly, the decision cannot be explained to the customer, and the file that supports it becomes evidence the institution does not control.
Two rules do the heavy lifting. FinCEN's reporting regulations set who files, at what dollar level, and by when. 31 U.S.C. §5318(g) supplies the confidentiality command and the safe harbour that makes filing survivable — the filer, and its directors, officers, and employees, are shielded from liability to any person for making the report.
What actually triggers the obligation
The standard is suspicion, not proof. An institution files when it knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity, is designed to evade Bank Secrecy Act requirements, has no business or apparent lawful purpose, or involves the use of the institution to facilitate criminal activity. Nobody has to establish that a crime occurred. The question is whether the facts in front of the institution would put a reasonable compliance function on notice.
Dollar thresholds then filter which suspicions become filings, and they differ by industry. Treating a bank threshold as universal is a common and expensive error at multi-charter groups and at fintechs that operate through several regulated entities.
| Filer | General threshold | Notes on application |
|---|---|---|
| Banks and other depository institutions | $5,000 where a suspect can be identified; $25,000 regardless of suspect | Insider abuse is reportable at any amount; aggregation across related transactions is expected |
| Money services businesses | $2,000 | A lower entry point that catches many payment and remittance operators by surprise |
| Broker-dealers in securities | $5,000 | Applies to transactions conducted or attempted by, at, or through the firm |
| Casinos and card clubs | $5,000 | Includes patron activity structured to avoid recordkeeping |
Attempted transactions count. So does activity the institution declines to process. A wire the bank refuses, an account application abandoned when identity questions start, a card load reversed before settlement — each can be reportable, and none produces a completed transaction record that a threshold report would capture.
How the 30-day clock runs
The filing window starts at initial detection of facts that may constitute a basis for filing — not at the point where an analyst reaches a conclusion. An institution may review activity to determine whether a basis exists, but that review does not stop the clock once the underlying facts are known.
- Day 0 — initial detection
Facts arise that may form a basis for filing: an alert, a law-enforcement inquiry, a colleague's escalation, an adverse media hit tied to an existing relationship, or a declined transaction.
- Days 0–30 — investigate and file
The report is generally due no later than 30 calendar days after initial detection. Calendar days, not business days, and no built-in tolling for holidays or staffing gaps.
- Days 31–60 — the no-suspect extension
Where no suspect has been identified on the date of detection, the institution may take up to an additional 30 days to identify one. The outer limit is 60 calendar days from initial detection.
- Ongoing — continuing activity
Where suspicious activity continues, FinCEN guidance contemplates periodic follow-up reports on a defined review cycle rather than a single filing that goes stale.
- Five years — retention
The institution keeps a copy of the report and its supporting documentation for five years from the filing date, and makes both available to FinCEN and law enforcement on request.
Deadline discipline: the single most common examination finding in this area is not a missed filing. It is a filing made on time by the compliance team's own reckoning, from a detection date the examiner measures differently. Record the detection date at the moment of detection, in the alert record itself.
The confidentiality rule and its narrow exceptions
No person may disclose a SAR, or any information that would reveal the existence of a SAR, except as authorized. That prohibition reaches the institution, its employees, and its agents, and it applies to a customer who asks directly, a customer's lawyer who asks politely, and a civil litigant who asks with a subpoena. The rule protects the fact of the filing as much as its contents, which is why "we cannot confirm or deny" is the only safe response — and why a written policy should give staff that exact sentence.
Some disclosures are permitted. Sharing with FinCEN, with the institution's federal functional regulator, and with appropriate law enforcement is contemplated by the regime itself. FinCEN guidance has also addressed sharing within a corporate structure in defined circumstances, and separate provisions allow certain information sharing between institutions to identify money laundering or terrorist financing. Those channels are narrow; none authorizes telling the customer.
- Tipping off through operations. A relationship manager explaining an exit as "a compliance thing we filed" discloses the existence of a report. Train exit scripts, not just filing procedures.
- Discovery leakage. Alert queues, case notes, and investigator emails describing a filing can be swept into civil discovery. Segregate the investigative file and log who touches it.
- Vendor exposure. Outsourced monitoring and case management put report data on third-party systems. Contract terms must carry the confidentiality obligation and forbid customer-facing disclosure.
- Subpoena mishandling. Responding to a private subpoena by producing the file, rather than notifying FinCEN and asserting the prohibition, converts a compliance function into a defendant.
- Detection-date drift. Reopening a closed alert without preserving the original detection date makes an on-time filing look late on examination.
What the safe harbour does and does not cover
The statute provides that an institution making a voluntary or required disclosure of a possible violation of law, and any director, officer, employee, or agent of that institution, is not liable to any person under any law or contract for making the disclosure or for failing to notify the subject of it. Courts have generally read that protection broadly, and it applies whether or not the suspicion turns out to be well founded.
What it does not do is insulate the surrounding conduct. It does not protect a decision to close an account if that decision independently breaches a contract or a fair-lending duty, it does not answer state-law claims about how customer funds were held, and it does not excuse a failure to file. Institutions sometimes reason backwards from the safe harbour to a "file everything" posture. Defensive over-filing has its own costs — it degrades the value of the reports to law enforcement, and a pattern of low-quality filings is itself an examination finding.
Customer identification and ownership work feeds directly into this analysis: the identity of the person behind an entity often decides whether activity looks suspicious at all. The verification duties around a beneficial owner and the reporting regime layered on top of them are covered in beneficial ownership reporting. Where funds sit in pooled structures, the question of whose activity is being monitored gets harder — see custodial and FBO account structures.
Building a file that survives review
The narrative is the product. Examiners and law enforcement judge a filing on whether a reader who knows nothing about the customer can understand who did what, through which accounts, in what amounts, over what period, and why it looked wrong. Internal shorthand and conclusions without the underlying transaction detail reduce a report to noise.
Supporting documentation is treated as part of the filing, so account opening records, transaction detail, alert history, and analyst work product sit in the same protected category and must be producible. Where an institution runs a broader inquiry under counsel — for instance because the same facts suggest an internal control failure — the boundary between the regulatory file and a privileged investigation needs to be drawn before documents are created, not after.
Data protection obligations run alongside. Alert files are dense with nonpublic personal information, and the security program requirements that apply to it are set out in GLBA privacy notices and the Safeguards Rule. Payment-side evidence — authorization records, return histories, and freeze decisions — usually lives in a different system again, as described in ACH authorization, returns, and account-freezing risk.
Questions the desk gets
Can a bank tell a customer why an account was closed?
It can give a reason drawn from the account agreement, and it must avoid any statement that reveals a report exists or was considered. Those two duties collide in practice, which is why exit communications should be scripted centrally and kept short. Telling a customer that "the file was referred to compliance and we had to report it" is a disclosure. Saying the relationship was closed under the terms of the account agreement is not.
Does the deadline restart when new activity appears?
New facts can create a new detection date and a new obligation, but they do not retroactively cure a missed deadline on the earlier activity. Where behaviour continues, the practical approach is a defined review cycle producing follow-up reports that describe the additional activity and cross-reference prior filings, rather than an open case that never resolves. Document the cycle in policy so the examiner sees a design rather than a habit.
What happens if a court orders production?
A private litigant's subpoena does not override the statutory prohibition. The established practice is to decline production, notify FinCEN of the request, and let the agency respond, rather than producing under protest or seeking the customer's consent. Consent is irrelevant — the confidentiality duty is not the customer's to waive. Treat any such request as an immediate escalation to counsel.
Do state regulators change the analysis?
The reporting regime itself is federal, and it is uniform across the country. State law still matters at the edges: state-licensed money transmitters answer to state examiners who review anti-money-laundering programs, and state banking departments participate in coordinated examinations. No state can authorize disclosure that federal law prohibits, but state licensing conditions can add program requirements on top of the federal baseline.
Sequencing the work
Start with the detection date, because every deadline argument turns on it. Confirm that the alerting system stamps the moment facts arrive, that reopened alerts preserve the original stamp, and that the case record cannot be edited without an audit trail. Then check the threshold matrix against every regulated entity in the group — a holding company with a bank and a licensed money transmitter is running two different rulebooks.
Next, rehearse the disclosure boundary. Give front-line staff a fixed sentence, give relationship managers a closure script, and give the legal team a written protocol for subpoenas and regulator requests. Then audit narrative quality on a sample of filings against the plain-reader test rather than against a template checklist. Confirm the current rule text and any recent FinCEN guidance at FinCEN and the supervisory expectations published by the OCC, the FDIC, and the Federal Reserve for your charter. Related material sits on the Financial Regulation & Digital Assets desk.
Sources
Atlas Research Desk
ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.