Suspicious Activity Reporting (SAR/STR) in Fintech: A 2026 Compliance Guide to Detecting, Filing, and Managing Reports

Every anti-money laundering program eventually converges on a single, high-stakes moment: the decision to file a report on a customer or transaction. Onboarding checks, screening, and monitoring all exist to surface risk — but it is the suspicious activity report that turns a suspicion inside a fintech into intelligence in the hands of the authorities. Get this process right and a firm meets its legal duty while feeding useful signals into the fight against financial crime. Get it wrong — by filing late, filing noise, or accidentally alerting the customer — and the same firm exposes itself to enforcement, reputational damage, and, in some jurisdictions, criminal liability for individuals.

This guide explains suspicious activity reporting for fintech decision-makers and compliance leaders. It covers what the terms mean, what triggers an obligation, how the reporting lifecycle should work, the confidentiality rules that surround it, and how the European framework is changing in 2026 and beyond. It is general information, not legal advice; specific obligations depend on your licenses, jurisdictions, and regulators, and should be confirmed with qualified counsel.

SAR, STR, and Why the Words Differ

The terminology varies by country, which causes needless confusion. A Suspicious Activity Report (SAR) is the term used in jurisdictions such as the United States and the United Kingdom. A Suspicious Transaction Report (STR) is the term favored across much of the world and in international standards, and it is sometimes broadened to “suspicious transaction and activity report.” The distinction is mostly linguistic: an STR is often framed around a specific transaction, while a SAR can also capture patterns of behavior or activity that never resulted in a completed transaction. In practice, most modern regimes expect firms to report suspicion whether or not money actually moved, including attempted transactions. Throughout this guide, “report” refers to both.

What Triggers a Report

The international baseline comes from the Financial Action Task Force (FATF). Under FATF Recommendation 20, financial institutions must report promptly to the national Financial Intelligence Unit (FIU) when they suspect, or have reasonable grounds to suspect, that funds are the proceeds of crime or are related to terrorist financing. Two features of that standard are essential for decision-makers to internalize.

First, the threshold is suspicion, not proof. A firm does not need evidence that would stand up in court, and it is not the firm’s job to investigate the underlying crime. Reasonable grounds to suspect are enough to trigger the obligation. Second, there is no monetary floor. Unlike threshold-based reports (such as large cash transaction reports), a suspicious activity report can and must be filed regardless of amount — a small transaction can be just as reportable as a large one if the surrounding facts raise suspicion.

What actually raises suspicion is context-specific, but common red flags in fintech include transactions with no apparent economic purpose, activity inconsistent with a customer’s known profile, rapid movement of funds through an account (layering), structuring to avoid thresholds, links to high-risk jurisdictions or sanctioned parties, reluctance to provide information, and use of the product in ways that suggest a mismatch with the stated purpose. These signals rarely arrive fully formed; they emerge from transaction monitoring, screening, and frontline observations that need to be brought together.

The Reporting Lifecycle

A defensible reporting process is a chain in which each link is clear and documented. While the details differ by firm, the lifecycle generally follows the same path.

1. Detection and internal escalation

Suspicion can originate from an automated monitoring alert, a screening hit, a customer due diligence review, or a member of staff noticing something unusual. Whatever the source, employees need a simple, well-understood internal route to raise concerns — typically to a nominated officer — without having to judge the legal question themselves.

2. Investigation and decision

The nominated officer (often called the MLRO, or in some regimes a designated compliance officer) reviews the case: the customer profile, the activity, prior alerts, screening results, and any explanation. The output is a documented decision either to file or not to file. Crucially, the reasoning behind a decision not to file matters as much as a decision to file; regulators expect to see that the judgment was considered, not ignored. This step benefits from context built during customer risk assessment and, for higher-risk cases, enhanced due diligence.

3. Filing with the FIU

If suspicion stands, the firm files a report with the relevant national FIU, in the required format and within the required timeframe. Many jurisdictions use standardized electronic channels — goAML, developed by the United Nations, is one of the most widely adopted FIU reporting systems worldwide. Timeliness is a legal expectation: reports should be made promptly once suspicion is formed.

4. Post-filing: freeze, consent, and recordkeeping

Depending on the jurisdiction and the facts, a firm may need to await consent before proceeding with a transaction, may be directed to freeze funds, or may simply continue monitoring the relationship for further activity. Every step — the alert, the analysis, the decision, and the filing — must be recorded and retained for the statutory period, because this documentation is the firm’s evidence that it met its obligations.

Tipping-Off and Confidentiality

One rule sits above all others in the reporting process: confidentiality. Under FATF Recommendation 21, firms and their staff are prohibited by law from disclosing to the customer, or to any third party, that a report has been or is being filed. This is the “tipping-off” prohibition, and breaching it is a serious offense in most regimes because it can destroy an investigation before it begins.

For a fintech, tipping-off risk is very real and often accidental. A well-meaning support agent explaining why an account was restricted, an automated message that reveals too much, or a poorly designed offboarding flow can all constitute tipping-off. The practical implication for decision-makers is that customer-facing teams and communication templates must be designed so that they never signal that a report exists — while still treating customers fairly. Balancing confidentiality with good customer experience is a genuine design challenge, not just a policy statement.

The European Shift: AMLR, AMLA, and 2027

The framework in the European Union is undergoing its most significant change in a generation. The EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, the “AMLR”) becomes applicable on 10 July 2027 and, as a regulation, applies directly across member states rather than being transposed differently in each. For suspicious activity reporting, several points stand out.

The AMLR reinforces that obliged entities must independently assess and report suspicion to the FIU, moving some member states away from older “unusual transaction” models toward a clearer suspicion-based standard. Reports must be made promptly, and where feasible a firm should refrain from carrying out a transaction it knows or suspects to be linked to money laundering or terrorist financing until it has reported. The suspicion threshold remains deliberately low: reasonable grounds are enough. Alongside the regulation, a new EU-level supervisor, the Anti-Money Laundering Authority (AMLA), based in Frankfurt, is standing up its functions; AMLA is expected to issue guidance on indicators of suspicious activity and to work toward a standardized reporting form, which over time should make cross-border reporting more consistent. Firms operating in the EU should treat the run-up to 2027 as a window to align their reporting processes, not a distant deadline.

Report Quality: The Defensive-Filing Trap

As enforcement pressure rises, many firms drift toward “defensive filing” — reporting almost everything to avoid ever being accused of missing something. This feels safe but is counterproductive. A flood of low-value, unsubstantiated reports burdens FIUs, buries genuinely useful intelligence in noise, and can itself attract regulatory criticism for signaling a weak decision-making process. Quality matters more than volume. A good report is timely, clearly written, and explains the specific grounds for suspicion, the activity observed, and the parties involved, so that an analyst can act on it. The goal is not to file the most reports; it is to file the right reports well.

Where Technology Helps — and Where It Does Not

The volume of alerts that fintechs generate makes a purely manual reporting process impractical, and RegTech tools genuinely help: case management systems that assemble the full picture for a reviewer, workflow that enforces escalation and documentation, integration with screening and monitoring, and direct submission into FIU channels. What technology does not do is form the suspicion or make the legal judgment. A report is ultimately a human decision, informed by context and defensible on its own terms. Automation should compress the busywork around that decision, not replace it.

Quick Reference: Do and Don’t

Do Don’t
Report on reasonable grounds to suspect, regardless of amount Wait for proof or a monetary threshold before reporting
Document decisions to file and not to file Let alerts close silently with no recorded rationale
Design customer messaging to avoid revealing a report Explain restrictions in ways that tip off the customer
Prioritize timely, well-reasoned reports File defensively to move volume off your desk
Prepare processes for EU AMLR by 2027 Treat the 2027 date as a distant, low-priority change

Frequently Asked Questions

What is the difference between a SAR and an STR?

They describe the same core obligation using different regional vocabulary. “SAR” is common in the US and UK; “STR” is used in international standards and many other countries. Modern regimes expect reporting of suspicious activity whether or not a transaction was completed.

Is there a minimum amount that triggers a report?

No. Suspicious activity reports are not threshold-based. If there are reasonable grounds to suspect money laundering or terrorist financing, the amount is irrelevant — even small or attempted transactions can be reportable.

Can we tell the customer we filed a report?

No. Disclosing that a report has been or will be filed is “tipping off,” which is prohibited by law in most jurisdictions. Customer communications must be designed so they never reveal the existence of a report.

Does filing a report mean we must close the account?

Not automatically. Depending on the jurisdiction and facts, a firm may need consent to proceed, may keep monitoring, or may exit the relationship. The reporting decision and the relationship decision are related but separate, and both should be documented.

Conclusion

Suspicious activity reporting is the point where an AML program proves whether it works. The principles are stable: report on suspicion rather than proof, regardless of amount; run a documented lifecycle from detection to filing to recordkeeping; protect confidentiality and never tip off; and value quality over volume. The context is shifting, with the EU’s AMLR and AMLA reshaping expectations toward 2027. Fintechs that treat reporting as a well-designed, well-governed process — supported but not replaced by technology — will meet their obligations and contribute real intelligence, rather than adding noise. This article is general information and not legal advice; confirm your specific obligations with qualified professionals.

If your team is reviewing how detection, screening, and reporting fit together, talk to DanuSoft about building a defensible, well-documented suspicious activity reporting process.