If you run a fintech, crypto platform, payment business, or gambling operation, you’ve probably heard some version of this: “If something looks off, file a SAR.” Nice slogan. Pretty useless in real life.
The hard part isn’t knowing SARs exist. It’s knowing what actually triggers one, what doesn’t, and what happens after you press submit. That’s where founders get twitchy. Fair enough. Nobody wants to over-report, annoy customers, or miss something serious and end up explaining it to a regulator six months later.
So let’s make this simpler.
A Suspicious Activity Report, or Suspicious Transaction Report in some places, is what you file when you suspect funds, activity, or behaviour may be linked to crime, money laundering, terrorist financing, fraud, sanctions evasion, or some other illicit mess. The exact format depends on the jurisdiction. The core idea doesn’t.
And no, suspicion does not mean proof. That misunderstanding causes alot of delay.
What actually triggers a SAR?
Short answer: suspicion based on facts, behaviour, context, or a pattern.
Not a gut feeling on its own. Not “the customer seemed weird on Zoom.” And not every large transaction either. Big transaction does not automatically mean suspicious. Small ones can be worse if they’re structured cleverly.
Usually, a SAR trigger comes from a mix of things. A transaction monitoring alert. A failed source of funds check. A customer who changes their story three times. A merchant model that doesn’t match actual flows. A wallet interacting with risky counterparties right before fiat off-ramping. You get the idea.
Here are common triggers I see in the wild:
- Transactions with no obvious economic purpose
- Activity inconsistent with the customer profile or stated business model
- Use of mule accounts, third-party payments, or unexplained pass-through behaviour
- Sudden volume spikes, especially across borders or across multiple payment rails
- Structuring – lots of smaller transactions designed to avoid thresholds or review
- Adverse media, sanctions concerns, law enforcement contact, or links to high-risk geographies
- Customer reluctance to provide KYC, source of funds, source of wealth, or ownership information
- In crypto, wallet exposure to mixers, darknet flows, scam proceeds, or chains of hop-and-drop transfers
- In gambling, unusual deposit-play-withdraw patterns, collusion indicators, chip dumping, or account networks that don’t make commercial sense
Notice what’s missing? Certainty.
You do not need to prove the predicate offence. You’re not the police. Your job is to spot, assess, document, and escalate.
Suspicious doesn’t always mean illegal. Still file it.
This is where people freeze.
A customer can give you partial documents, behave evasively, move money in a way that makes no commercial sense, and still turn out to be technically legit. Maybe. But if your team had reasonable grounds for suspicion at the time, that can still justify filing.
Honestly, founders often wait too long because they want a perfect answer. Big mistake. SAR decisions are usually made with imperfect information. What matters is whether your reasoning was defensible and recorded properly.
If your internal notes say, “customer felt dodgy,” that’s bad. If they say, “customer stated they operate a SaaS business in Germany, but incoming funds came from unrelated individuals in four countries, then moved out to a VASP account within hours; customer refused to explain beneficial ownership links,” that’s a real rationale.
If your AML setup still feels vague, read Your first AML programme: the 6 documents every regulator wants to see. It’ll save you from building a policy set that looks nice but doesn’t help your team make actual decisions.
Examples by sector
Because “suspicion” looks different depending on what you do.
Fintech and payments
You onboard a UK company saying it sells software subscriptions. Fine. Then your monitoring shows lots of incoming transfers from unrelated retail payers, several refunds to third parties, and outbound wires to a high-risk jurisdiction with vague invoice references. That’s not normal SaaS billing. It may be hidden remittance activity. Or fraud proceeds. Or something else unpleasant.
That needs escalation.
Crypto
A customer buys crypto with a debit card, sends it through a chain of fresh wallets, then cashes out to a bank account under a relative’s name. Blockchain analytics flags exposure to sanctioned or darknet-related addresses two hops back. Is two hops always enough by itself? Nope. But mixed with evasive answers and unusual transaction behaviour, it can absolutely support a SAR review.
If you’re still figuring out your regulated crypto setup, VASP Registration & MiCA Compliance is the service page to look at. Structure first. Panic later.
Gambling and gaming
A player deposits heavily, places low-risk bets with minimal variance, then withdraws most of the balance quickly. Another cluster of accounts logs in from related devices and moves value in a pattern that looks more like transfer activity than gaming. That could be laundering, bonus abuse, or collusion. Different risk. Same reporting question.
And yes, source of funds matters here more than many operators want to admit.
So what should your team do before filing?
Not much theatre. Just a clean internal process.
- Escalate internally – frontline staff or analysts flag the case to the MLRO or nominated compliance lead.
- Review the facts – customer profile, transaction history, KYC file, open-source checks, sanctions screening, device data, blockchain analytics, gaming behaviour, whatever is relevant.
- Document the suspicion clearly – what happened, why it’s abnormal, what information was requested, what the customer said, and where the gaps are.
- Decide whether to file – based on reasonable suspicion, not certainty.
- Restrict tipping off – don’t tell the customer a SAR was filed, and don’t say anything that effectively tells them.
That last bit matters more than people think. I’ve seen support staff send “we have reported your activity” style emails. Don’t do that. Ever.
If you don’t have a capable MLRO yet, or your team is making this up as they go, outsourced support is usually the sensible fix. Outsourced AML Officer & Compliance as a Service exists for exactly this problem.
What happens after you file one?
This part is less dramatic than movies suggest.
In most cases, you file the report through the relevant national reporting portal or authority channel, keep the filing confidential, and continue managing the account based on your legal obligations and internal risk appetite. Sometimes you maintain the relationship under monitoring. Sometimes you restrict activity. Sometimes you exit the customer. It depends on the risk, the jurisdiction, and whether there’s a legal requirement to pause or seek consent before proceeding with a transaction. Check current requirements in the country you’re operating in.
You may hear nothing back. That’s normal.
A SAR doesn’t usually trigger a friendly call saying “thanks, good job.” It goes into a law enforcement or financial intelligence workflow. It may be analysed, matched against other reports, used to build a wider picture, or parked unless more intelligence comes in later.
Sometimes the authority asks follow-up questions. Sometimes they issue a production order or information request. Sometimes banking partners ask what controls you applied around the case, especially if the pattern is ugly and visible in account traffic. And sometimes, quietly, the customer just becomes part of a much larger investigation you’ll never fully see.
That’s why your recordkeeping needs to be tidy. Not fancy. Tidy.
Do you have to freeze the account?
Usually, not automatically. But don’t take that as a free pass.
Filing a SAR and freezing funds are different decisions. In some cases you may be allowed – or required – to continue normal processing unless there’s a legal instruction, asset freeze obligation, sanctions issue, or specific mechanism requiring consent before completing the transaction. In other cases, keeping the account active is nuts because the risk is obvious and immediate.
This is where founders get themselves in trouble by using a single rule for every case.
A suspicious gambling account with possible collusion risk? You may suspend under your terms while reviewing. A fintech client using your rails for possible unlicensed remittance? You might restrict outbound transfers fast. A crypto customer with stale adverse media but no live transactional concern? Maybe enhanced monitoring is enough while compliance reviews the file.
Context. Always context.
What regulators and banks care about
Here’s the blunt version: they care less about whether you filed a huge number of SARs and more about whether your decisions make sense.
They’ll look at things like:
- Did alerts get reviewed promptly?
- Did staff know how to escalate concerns?
- Was the suspicion explained with actual evidence?
- Were linked accounts and related parties considered?
- Did you avoid tipping off?
- Did you keep monitoring after the filing where appropriate?
And yes, they’ll also notice if you file almost nothing despite obvious high-risk activity. That’s a red flag on its own.
If banking is part of your headache too, this piece is worth your time: Why banks decline crypto and gambling companies – and how to get approved anyway. I’ve seen weak SAR handling kill a banking application faster than a bad forecast deck.
A simple rule founders can actually use
If activity is unusual, inconsistent, evasive, or commercially irrational, and you can’t get comfortable after reviewing the facts, escalate it.
If the review creates reasonable suspicion, file.
Don’t wait for certainty. Don’t file based on vibes alone either. Build a case file that another person can read later and say, “Yep, I see why this was suspicious.” That’s the standard you’re aiming for.
Simple. Not always easy.
And if your current process lives in Slack messages and someone’s memory, fix that before the volume picks up. Honestly most founders leave SAR mechanics too late, then act surprised when the first banking review or regulator due diligence pack turns into a 40-question interrogation. Very avoidable. Mostly.