Suspicious activity vs suspicious transaction
Suspicious activity vs suspicious transaction Suspicious activity and suspicious transaction describe two overlapping but distinct reporting concepts, and the difference is more than naming. A suspicious transaction report is anchored to a completed transaction; a suspicious activity report can cover behaviour, attempted transactions, or a relationship pattern even without one. Most of the time the terms get used interchangeably, which is exactly where the confusion starts. Key takeaways A suspicious transaction report needs a completed transaction; a suspicious activity report can cover behaviour or attempts without one. FATF Recommendation 20 sets the international baseline that most STR-terminology countries built their law around. The US uses SAR terminology under the Bank Secrecy Act, filing with FinCEN using Form 111. The UK uses SAR terminology too, despite following the same FATF standard that produced STR elsewhere, a reminder that naming doesn’t reliably signal scope. Monitoring systems need calibrating to whichever model actually applies locally, not treated as one global rule set. The 2024 TD Bank case, over $3 billion in combined penalties, shows the real cost of a monitoring gap in this area. On this page What each term actually coversWhy the same underlying obligation has two namesThe US SAR modelThe FATF STR model most other countries followWhere the UK sits in this splitWhy the distinction matters for transaction monitoring designA real case that shows what gets missedWhat this means for a global compliance programmeFAQsRead more $5,000 / $2,000 US SAR filing thresholds for most banks vs money services businesses Source: Bank Secrecy Act / FinCEN $3bn+ Combined FinCEN/DOJ penalty against TD Bank in 2024 for suspicious transaction monitoring failures Source: FinCEN / US Department of Justice What each term actually covers A suspicious transaction report is tied to a transaction that actually happened. The filing has to identify the specific transaction and explain what made it suspicious; the trigger is the transaction itself. A suspicious activity report has broader scope: it can cover behaviour, a pattern across a relationship, or even an attempted transaction that never completed, without needing one specific transaction to point to. In practice, this means an activity-based regime can catch things a purely transaction-based one would miss: someone probing account limits without ever moving money, for instance, or a pattern of behaviour that only becomes suspicious once you see it across several interactions rather than one. Why the same underlying obligation has two names The reason there are two names for what’s functionally the same underlying obligation, tell your financial intelligence unit when something looks wrong, comes down to which standard a country built its reporting regime around. FATF’s Recommendation 20 sets the international baseline, requiring financial institutions to report suspicious transactions to their national FIU. Most countries that built their AML law directly around FATF’s standard adopted STR as the formal term. The United States went a different route. Its reporting obligation grew out of the Bank Secrecy Act rather than being drafted straight from FATF’s language, and it settled on “activity” rather than “transaction” as the defining word. The US SAR model Under the US Bank Secrecy Act, financial institutions file SARs with FinCEN using FinCEN Form 111. Thresholds vary by institution type: $5,000 for most depository institutions, $2,000 for money services businesses. Because the obligation is activity-based, a SAR can be filed over a pattern of conduct or an attempted transaction, not only a completed one. FinCEN’s own SAR Stats database tracks filing volumes by institution type, activity category, and geography, giving a rare public window into how many of these reports actually get filed and for what reasons across the US financial system. The FATF STR model most other countries follow Most other jurisdictions built their reporting obligation directly around FATF Recommendation 20’s language and call the resulting document a suspicious transaction report. India is a clear example: STRs are filed under the Prevention of Money Laundering Act 2002 with FIU-IND, using that exact terminology in law. The EU’s Anti-Money Laundering Directives and many Asian jurisdictions follow the same pattern. FATF itself doesn’t mandate a specific threshold or form. Recommendation 20 sets the principle, report promptly when there are reasonable grounds to suspect proceeds of crime or terrorist financing, and leaves the mechanics of implementation to each country. Where the UK sits in this split The UK sits in an interesting middle position. It uses the term SAR, filed with the National Crime Agency under POCA and the Terrorism Act, following US-style terminology. But UK law was still shaped by the same FATF standard as STR-based jurisdictions, and in practice UK guidance treats the obligation broadly enough to cover suspicious activity, not strictly a completed transaction. That’s a useful reminder that the name a jurisdiction uses doesn’t reliably tell you the actual scope of what needs reporting. Firms operating across borders need to check the substance of each jurisdiction’s obligation, not assume from the label alone. Worth knowing. The name a jurisdiction uses for this report doesn’t reliably tell you its actual scope. The UK calls its filing a SAR, following US-style naming, but the underlying obligation was shaped by the same FATF standard that produced STR terminology in most other countries. Why the distinction matters for transaction monitoring design This distinction has a direct, practical consequence for how transaction monitoring gets built. A system designed around US SAR logic generates activity-based alerts, patterns, behaviours, attempted actions, that don’t map cleanly onto a strictly transaction-anchored STR threshold used elsewhere. Applying one global rule set built for one model to a jurisdiction that uses the other risks either over-reporting or under-reporting relative to what local law actually expects. Firms running programmes across multiple countries need alert logic and escalation workflows calibrated to whichever standard actually applies in each jurisdiction, rather than assuming SAR and STR are close enough to treat as one global rule set. A real case that shows what gets missed The 2024 settlement between TD Bank and US authorities is a useful illustration of what falling short on this obligation … Read more