Skip to main content
Category: Compliance Programs

Suspicious Transaction Report

Also known as: STR, Suspicious Activity Report, SAR
Simply put

A Suspicious Transaction Report is a report that a financial institution files with a designated authority when it identifies a transaction that appears inconsistent with what it knows about a customer or that may be linked to money laundering or other financial crime. It is a way for institutions to alert regulators or financial intelligence authorities to activity that warrants further scrutiny. The specific triggers, filing timelines, and receiving authority depend on the jurisdiction and applicable rules.

Formal definition

A Suspicious Transaction Report (STR), referred to in some jurisdictions as a Suspicious Activity Report (SAR), is a regulatory report submitted by a financial institution (and, in certain regimes, associated businesses or professionals) concerning a transaction, attempted transaction, or funds for which the institution has reasonable grounds to suspect a connection to money laundering or related financial crime. A transaction is generally treated as suspicious when it is not in line with the customer's established profile and exhibits possible connectivity to illicit activity. The obligation to file, the standard of suspicion applied, the reporting timeframe, and the authority to which reports are submitted vary by jurisdiction, sector, and entity type; for example, in the United States such reports are filed with the Financial Crimes Enforcement Network, while other jurisdictions define reporting duties under their own anti-money laundering frameworks. This entry is educational and not legal, audit, or compliance advice; specific filing obligations depend on applicable law and the facts of each case.

Why it matters

Suspicious Transaction Reports are a foundational mechanism in most anti-money laundering (AML) regimes, serving as a primary channel through which financial institutions alert authorities to activity that may be connected to money laundering or other financial crime. Because financial intelligence authorities cannot observe the day-to-day flow of transactions across the financial system, they generally depend on regulated institutions to identify and escalate activity that appears inconsistent with a customer's known profile. In this sense, the STR framework places front-line detection responsibility on the institutions closest to the transactions, while investigative and enforcement functions typically remain with the receiving authority.

For institutions, the reporting obligation carries meaningful compliance stakes. In many jurisdictions the duty to file where there are reasonable grounds for suspicion is a legal requirement rather than a voluntary practice, and failure to identify or report suspicious activity can expose an institution to regulatory scrutiny. At the same time, the standard applied is one of suspicion rather than proof of wrongdoing; filing an STR generally reflects a judgment that activity warrants further examination, not a determination that a crime has occurred. This distinction matters because it shapes how compliance functions calibrate detection, escalation, and documentation.

Because the specific triggers, filing timelines, standard of suspicion, and receiving authority vary by jurisdiction, sector, and entity type, the practical significance of an STR obligation depends heavily on the applicable framework. Institutions operating across borders often must navigate multiple, non-identical reporting regimes, making consistent governance over the identification and escalation process an ongoing challenge.

Who it's relevant to

Chief Compliance Officers and AML Officers
Compliance leadership generally owns the design and operation of the suspicious activity detection and reporting program, including escalation procedures, the application of the suspicion standard, and timely filing where required. Given that obligations vary by jurisdiction, cross-border institutions face the added task of reconciling differing triggers, timelines, and receiving authorities.
Financial Institutions and Associated Businesses
Banks and, in certain regimes, associated businesses or professionals may be subject to a legal duty to file reports where reasonable grounds for suspicion exist. Whether a specific entity is covered, and what its precise obligations are, depends on the applicable framework, the sector, and the entity type.
Internal Audit and Assurance Functions
Assurance functions typically assess whether the reporting program is designed appropriately and operating effectively, including whether suspicious activity is being identified, escalated, and reported consistently with policy and applicable requirements. Their role is to provide independent evaluation rather than to make individual filing decisions.
General Counsel and Legal Advisors
Legal counsel is often consulted on the interpretation of the applicable standard of suspicion, filing obligations, and jurisdiction-specific requirements, particularly in ambiguous or cross-border situations. Because filing duties depend on applicable law and case-specific facts, legal judgment is frequently relevant to close cases.
Boards and Risk Committees
While boards and their committees do not perform operational filing, they generally hold oversight responsibility for the institution's financial crime compliance framework. This typically includes satisfying themselves that management has established adequate processes and resources to meet applicable reporting obligations.

Inside STR

Subject and Party Identification
Details identifying the customer, account holder, or counterparties involved, together with available identifying information such as names, dates of birth, addresses, and account or reference numbers, to the extent held by the reporting entity.
Transaction Details
Information about the activity giving rise to suspicion, typically including dates, amounts, currencies, instruments, accounts involved, and the flow of funds, so that the receiving financial intelligence unit can understand what occurred.
Grounds for Suspicion
A narrative explaining why the activity is considered suspicious, describing the indicators, patterns, or anomalies observed. The threshold is generally suspicion rather than proof of wrongdoing, and the standard varies by jurisdiction.
Supporting Documentation
Relevant records or references that substantiate the report, such as transaction logs or account documentation, which many regimes expect the reporting entity to retain even if not all are submitted with the report itself.
Reporting Entity Information
Identification of the institution filing the report and, in many frameworks, the relevant internal contact or nominated officer responsible for anti-money-laundering reporting.

Common questions

Answers to the questions practitioners most commonly ask about STR.

Is filing a Suspicious Transaction Report the same as accusing a customer of a crime?
No. A Suspicious Transaction Report (often called a Suspicious Activity Report in some jurisdictions) is not a determination or accusation of criminal conduct. It typically reflects a reporting entity's reasonable grounds to suspect that a transaction or activity may be linked to money laundering, terrorist financing, or another predicate offence, based on the standard set by the applicable regime. The purpose is to provide information to the relevant financial intelligence unit or competent authority, which then decides whether and how to investigate. The reporting obligation generally does not require the filer to prove or conclude that a crime has occurred, and the applicable threshold for suspicion varies by jurisdiction.
Does filing a report mean the reporting entity has met all of its anti-money laundering obligations?
Not on its own. Filing is one component of a broader anti-money laundering and counter-terrorist financing program, which in many jurisdictions also includes customer due diligence, ongoing monitoring, record-keeping, internal controls, training, and independent testing. A report addresses a specific identified concern; it does not substitute for the wider control framework. Whether an entity's obligations are satisfied depends on the applicable law, the entity's regulatory status, and the design and operating effectiveness of its overall program. This entry is educational and not legal or compliance advice.
Who within an organization is typically responsible for deciding whether to file a report?
Responsibility for filing decisions commonly rests with a designated compliance function, frequently a nominated officer or money laundering reporting officer where a regime requires such a role. Front-line staff generally identify and escalate potential concerns, while the designated officer or compliance team typically evaluates whether the applicable suspicion threshold is met and makes the reporting decision. Precise roles, titles, and delegation depend on the jurisdiction, sector, and the entity's own governance structure and internal procedures.
How should a reporting entity handle confidentiality and the risk of alerting the customer?
Many regimes include prohibitions on disclosure, sometimes described as tipping-off restrictions, that limit informing the subject or third parties that a report has been or may be filed. Reporting entities typically manage this through controlled internal access, defined escalation channels, and documented procedures so that only authorized personnel are aware of a filing. The specific scope of any disclosure prohibition, and any permitted exceptions, depends on the applicable law and should be confirmed against the governing regime and, where appropriate, professional advice.
What documentation is generally expected to support a filing decision?
Reporting entities commonly maintain records of the activity or transaction reviewed, the rationale for the decision to file or not to file, the information relied upon, and the date and outcome. Record-keeping requirements, including retention periods, vary by jurisdiction and regime. Contemporaneous, consistent documentation typically supports both the entity's own quality assurance and its ability to demonstrate the reasonableness of decisions to supervisors. Entities should align their documentation practices with the specific requirements applicable to them.
How do reports interact with an organization's assurance and oversight functions?
Filing decisions are generally an operational and compliance responsibility carried out within management and the compliance function. Independent assurance functions, such as internal audit, typically do not make filing decisions but may assess whether the reporting process is appropriately designed and operating effectively. The board or a relevant committee generally exercises oversight of the anti-money laundering program as a whole rather than reviewing individual filings. The allocation of these roles depends on the entity's governance model and the applicable regulatory expectations.

Common misconceptions

Filing a Suspicious Transaction Report requires proof that a crime has occurred.
In many jurisdictions the applicable threshold is a suspicion or reasonable grounds to suspect, not evidence or proof of an offence. The precise standard is set by local law and can differ; determining whether it is met is a matter of professional judgment based on the facts.
A Suspicious Transaction Report and a routine threshold-based currency or cash transaction report are the same thing.
They are generally distinct filings. Threshold reports are triggered automatically by transactions exceeding a set value, whereas a suspicious report is triggered by suspicion regardless of amount. The specific triggers and forms depend on the jurisdiction and regime.
Submitting a report ends the reporting entity's obligations.
Depending on the jurisdiction, obligations such as ongoing monitoring, record retention, responding to authority requests, and restrictions on tipping off the subject may continue after filing. What applies depends on local law and the entity's own policies.

Best practices

Confirm the specific reporting threshold, form, timeframe, and destination authority applicable in each relevant jurisdiction, as these requirements vary by country, sector, and entity type.
Assign a clearly identified nominated officer or equivalent function with defined accountability for reviewing internal escalations and deciding whether to file, keeping this responsibility distinct from front-line staff who raise the initial concern.
Document the grounds for suspicion in a clear, factual narrative and retain supporting records in line with applicable retention requirements, so the rationale can be reconstructed later.
Maintain strict confidentiality around filings and observe any prohibition on tipping off the subject, restricting knowledge of the report to those who need it.
Establish and periodically test internal escalation procedures so that front-line concerns reach the responsible officer promptly and consistently, and calibrate them against evolving typologies and guidance.
Treat filing as one step in an ongoing process, continuing monitoring and cooperating with any follow-up requests from the relevant authority as permitted or required by local law.