Suspicious Activity Reports: A Practitioner's Guide to SARs… | YouVerify
Anti-Money Laundering (AML)
Suspicious Activity Reports: A Practitioner's Guide to SARs and STRs
ByFavour Praise
•5mins Read
Key Takeaways
A Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) helps financial institutions report suspected money laundering, fraud, terrorist financing, and other unusual activities to the relevant authorities.
Effective SAR filing depends on strong transaction monitoring, clear documentation, accurate investigation records, and timely reporting when suspicious activity is identified.
Automated AML compliance and transaction monitoring tools help businesses detect suspicious activity faster, reduce manual reviews, and streamline the SAR or STR filing process.
A customer sends four large payments from a recently opened business account in less than an hour. The transfers go to different counterparties, but the same customer has already triggered a remote-access fraud signal, and the activity does not match the transaction profile declared during onboarding.
The system flags the activity. An analyst opens a case. Customer information, transaction history, linked entities and previous alerts are reviewed. The question is no longer simply, “Is this transaction unusual?” The compliance team now has to decide whether the facts create sufficient grounds to file a suspicious activity report or STR.
That is the real challenge of suspicious activity reporting.
A suspicious activity report (SAR) is a formal report submitted when a reporting entity identifies behaviour or activity that may be connected to financial crime. In Nigeria, a Suspicious Transaction Report (STR) is used for suspicious transactions, while a SAR may cover non-transactional suspicious activity or behaviour. The report documents what happened, who was involved and why the institution considers the matter suspicious.
This guide focuses on the practical side of filing a suspicious activity report, with particular attention to Nigeria's SAR and STR framework.
What is a Suspicious Activity Report?
A suspicious activity report, often called a SAR report, is a formal report that records facts suggesting possible money laundering, terrorism financing or fraud.
The reporting entity is not required to prove that a crime has occurred. Its responsibility is to identify and report activity that creates reasonable grounds for suspicion under the applicable framework.
In Nigeria, theNFIU distinguishes between several report types, including:
Suspicious Transaction Reports (STRs): Used where the suspicion involves a transaction.
Suspicious Activity Reports (SARs): Used for suspicious non-transactional activity or behaviour, such as a customer's refusal to provide required KYC information.
Currency Transaction Reports (CTRs): Used for transactions subject to statutory reporting thresholds.
Where suspicion involves both a transaction and suspicious activity, the NFIU says the reporting entity should file an STR.
For example, a ₦2 million transfer may be perfectly normal for an established logistics company. The same transaction pattern may be far more concerning when it appears in a recently opened account with no clear business purpose and unexplained links to other risk indicators.
A practical scenario: From transaction alert to STR filing
Let's return to the customer introduced at the beginning of this article.
Chioma, a compliance analyst, is reviewing an alert involving Zenith Logistics Ltd. The company was verified during onboarding. Its business information, ownership structure and customer risk profile were reviewed, and one of its beneficial owners required additional review because of a potential risk signal.
Weeks later, transaction monitoring detects four outbound transfers totalling ₦2.4 million to a foreign counterparty within 38 minutes. The activity breaches a velocity rule and is inconsistent with the company's expected transaction pattern.
Chioma does not file an STR simply because four payments were made quickly.
She reviews the full picture:
Why were the payments made?
Who are the counterparties?
Is the beneficial owner connected to any of them?
Has the customer previously triggered fraud or AML alerts?
Does the activity fit the nature of the business?
Is there a reasonable commercial explanation?
The investigation becomes more concerning when the team discovers a recent remote-access fraud signal and an inconsistency between the customer's declared business activity and the counterparties receiving the funds.
Chioma documents the evidence and escalates the case through the institution's review workflow. The decision to file an STR is then based on the totality of the information available, not on one transaction value or one monitoring alert.
This is where effective fraud detection, customer risk intelligence and transaction monitoring come together.
There is no single transaction pattern that automatically requires a suspicious activity report.
Instead, a SAR or STR is triggered by facts and circumstances that create reasonable grounds for suspicion. Under the NFIU's current guidance, suspicious transactions can include those connected to suspected money laundering, terrorism financing or predicate offences.
Common triggers may include:
Activity inconsistent with the customer profile. A newly onboarded low-volume business suddenly begins sending high-value international payments.
Unusual transaction patterns. Multiple transfers occur within a short period without a clear economic purpose.
Structuring. A customer repeatedly splits transactions to avoid reporting or detection thresholds.
High-risk relationships. The activity involves sanctioned persons or unexplained connections between multiple accounts.
Behaviour during onboarding or account management. A customer provides inconsistent information or refuses to explain significant risk indicators.
The key question for the analyst is not whether the activity looks strange in isolation. It is whether the available facts, taken together, create reasonable grounds for suspicion.
Importance of SARs in Anti-Money Laundering
SARs and STRs are a critical part of an effective AML/CFT program because they convert suspicious behaviour identified inside a financial institution into information that can be analysed by the relevant financial intelligence authority.
FATF Recommendation 20 requires financial institutions to report suspicious transactions promptly where there are reasonable grounds to suspect that funds are the proceeds of criminal activity or are linked to terrorist financing.
For a bank or fintech, filing a suspicious activity report serves several practical purposes:
It creates a formal record of the institution's assessment.
It allows the relevant financial intelligence unit to analyse patterns across multiple reporting entities.
It demonstrates that the institution's AML controls identified, investigated and escalated suspicious conduct.
It can support law enforcement and regulatory investigations.
Poor-quality SAR filing, however, can reduce the value of the report. A vague narrative that simply states “unusual activity was detected” gives the reviewer very little to work with.
What does a Suspicious Activity Report include?
A strong suspicious activity report should allow a regulator or financial intelligence analyst to understand the case without reconstructing the investigation from scratch.
Although filing formats vary by jurisdiction, the report should generally explain:
What to include
What the reviewer needs to understand
Subject information
Who is involved and how they are connected
Transaction or activity details
What happened, when, where and through which channel
Basis for suspicion
Why the activity appears suspicious
Customer context
Whether the conduct matches the customer's known profile
Investigation findings
What the institution reviewed and discovered
Supporting evidence
Relevant alerts, transactions, counterparties and linked entities
The narrative should explain the suspicious pattern clearly. A good SAR report tells the reader what happened, why it matters and how the reporting entity reached its conclusion.
How do you write a Suspicious Activity Report?
Writing a suspicious activity report starts with the investigation, not the report form.
1. Establish the facts
Confirm what actually happened. Identify the relevant customer, accounts, transactions, dates, counterparties and channels.
2. Review the activity in context
Compare the behaviour with the customer's KYC information, risk profile and expected activity. Review previous alerts and relevant relationships.
3. Explain the suspicious indicators
This is the heart of the SAR filing process. Clearly state why the activity is suspicious and avoid unsupported conclusions.
For example:
Multiple outbound transfers were initiated within 38 minutes to previously unrelated foreign counterparties. The activity was inconsistent with the customer's expected transaction profile and occurred after a remote-access fraud alert.
The statement is more useful than simply writing, “The transactions were suspicious.”
4. Document the investigation and decision
Record the information reviewed, the findings, escalation steps and final decision. A complete audit trail is important for both regulatory examination and internal quality review.
What is the difference between a SAR and an STR?
The terminology differs across jurisdictions, and the distinction matters in Nigeria.
SAR
STR
Focuses on suspicious activity or behaviour
Focuses on suspicious transactions
Can include non-transactional conduct
Covers suspicious completed or attempted transactions
May apply where suspicious behaviour exists without a specific transaction
Used when the suspicion involves a transaction
The NFIU specifically states that a SAR can cover non-transactional suspicious behaviour, while an STR is used where the suspicion involves a transaction. If both are involved, the NFIU instructs reporting entities to file an STR.
This distinction is especially important for Nigerian compliance teams working with automated case management and regulatory reporting workflows.
Nigeria's framework requires reporting entities to report suspicious transactions and activities to the NFIU.
According to the NFIU, the general requirement is that suspicious transactions should be reported immediately and no later than 24 hours after reasons for suspicion are established. The NFIU's current guidance also gives financial institutions 48 hours for internal examination and an additional 24 hours to file after suspicion is confirmed. This makes investigation speed a genuine operational challenge.
A financial institution that relies on spreadsheets, disconnected data sources and email-based approvals may struggle to reconstruct the full case quickly enough. The compliance team needs customer information, transaction history, linked entities and previous alerts in one investigation workflow.
That is why strong SAR and STR processes begin before the report itself. They depend on effective monitoring, structured investigations and clear escalation rules.
Managing suspicious activity should not mean switching between multiple tools to investigate an alert, manage a case and prepare an STR. Youverify Cowork brings these workflows into one compliance workspace.
Teams can investigate suspicious activity, manage cases and use Vyra AI to assist with preparing regulatory reports from available case information. The report can then be reviewed, edited and approved by the relevant compliance team before filing.
Favour Praise is a compliance researcher and writer at Youverify, where she creates educational content on KYC, AML, fraud prevention, identity verification, and regulatory technology. She focuses on helping financial institutions and regulated businesses understand complex compliance topics through practical, research-backed insights.