A suspicious activity report (SAR) is a confidential filing that federally regulated banks must submit to the Financial Crimes Enforcement Network under 31 C.F.R. § 1020.320 within 30 calendar days of detecting a transaction involving at least $5,000 tied to suspected criminal activity, a deadline that FinCEN and four federal banking regulators reaffirmed and narrowed the interpretation of in joint FAQs issued October 9, 2025.
The deadline itself did not move. What changed is the interpretive gloss around it: FinCEN, the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the National Credit Union Administration, and the Office of the Comptroller of the Currency jointly issued four FAQs narrowing when a report is required, not when it is due. For compliance officers running alert-disposition and structuring-review programs, that distinction — required versus discretionary — is the operative one, and it is where most of the practical work in this area now sits.
What Counts as a Suspicious Transaction Under the Rule?
Under 31 C.F.R. § 1020.320, a bank must file a SAR when it knows, suspects, or has reason to suspect that a transaction of at least $5,000 evades Bank Secrecy Act reporting, has no lawful purpose apparent after reasonable inquiry, or otherwise involves the bank in a violation of law. The regulation sets a $5,000 aggregate threshold; it does not require certainty, only a reasonable basis for suspicion.
For national banks and federal savings associations, the Office of the Comptroller of the Currency applies a parallel framework under 12 C.F.R. § 21.11, describing reportable conduct as known or suspected criminal offenses at specified thresholds, or transactions over $5,000 tied to suspected money laundering or other Bank Secrecy Act violations. A filed SAR is not an accusation of wrongdoing and is not evidence that any violation occurred — it is a bank's internal determination that a transaction merits law-enforcement review, made under a reasonable-suspicion standard rather than a finding of fact.
When Must the SAR Be Filed?
A bank must file no later than 30 calendar days after the date it initially detects facts that may constitute a basis for filing. If the bank has not identified a suspect by that point, it may delay filing for an additional 30 calendar days to do so — but in no case can the total delay exceed 60 calendar days from the date of initial detection. Filing has been electronic-only since April 1, 2013, through FinCEN's BSA E-Filing System; paper SAR filings are no longer accepted.
This 30/60-day structure is the one fixed point in the framework, and it was not altered by the October 2025 FAQs. Institutions that treat the FAQs as changing the filing clock are misreading them: every clarification issued that month addressed the threshold for whether a report is required, or how long an institution may keep filing on the same continuing conduct, not the initial detection-to-filing window.
What Did FinCEN's October 2025 FAQs Actually Change?
On October 9, 2025, FinCEN and the four federal banking regulators released four FAQs addressing recurring sources of over-filing: structuring near the $10,000 currency-transaction-report threshold, whether a SAR filing obligates continued account monitoring, how long an institution may keep filing on the same continuing conduct, and whether a decision not to file must be documented. Announcing the release, FinCEN Under Secretary John K. Hurley said SARs "should deliver better outcomes by providing law enforcement the most useful information — not by overwhelming the system with noise."
None of the four FAQs adds a new filing obligation. Each narrows an existing one or confirms that a widely assumed obligation does not exist. The table below compares the ambiguity the FAQs were written to resolve against FinCEN's stated position.
| Question Addressed | Ambiguity the FAQ Resolves | FinCEN's October 2025 Position |
|---|---|---|
| Transactions at or near the $10,000 CTR threshold | Whether proximity to the threshold alone requires a SAR | A SAR is required only where the institution knows, suspects, or has reason to suspect the transaction is structured to evade CTR reporting; the $5,000 aggregation threshold applies to structuring specifically |
| Continuing account review after a SAR is filed | Whether filing triggers a mandatory dedicated follow-up review | No separate mandatory review is required; institutions may rely on risk-based internal policies, procedures, and controls |
| Filing on the same continuing conduct | How long an institution may keep filing without a new triggering event | Institutions that elect a continuing-activity approach file an initial SAR by day 30 and, if the activity continues, a follow-up SAR by day 150; the approach is elective, not required |
| Decisions not to file a SAR | Whether non-filing decisions must be documented | "There is no requirement or expectation" to document a decision not to file, though brief documentation may be appropriate when an institution chooses to keep one |
Do Institutions Have to Keep Watching an Account After Filing?
No. The FAQs state that filing a SAR does not, by itself, trigger a mandatory dedicated review of the customer or account going forward. Institutions may instead rely on their existing risk-based internal policies, procedures, and controls to decide whether and when further review is warranted — the same governance structure that generated the original alert, rather than a separate review track created by the act of filing.
Where an institution does choose to keep filing on activity that continues past the initial SAR, the FAQs describe — but do not mandate — a specific cadence. For institutions that elect it, the sequence runs as follows:
- Day 0: the institution detects facts that may constitute a basis for filing.
- Day 30 (deadline): the institution files the initial SAR, consistent with the standard 31 C.F.R. § 1020.320 timeline.
- Days 31 through 149: the institution monitors the account under its ordinary risk-based policies, without a separate mandatory review requirement.
- Day 150 (deadline, if elected): if the suspicious activity has continued, the institution files a follow-up SAR — 90 days after the initial filing, plus the standard 30-day filing window.
An institution may instead simply treat any new, separately reportable activity under the standard 30/60-day timeline in 31 C.F.R. § 1020.320, without adopting the elective 150-day continuing-activity cadence at all.
What Protections and Obligations Attach to a Filed SAR?
SARs are confidential. Under 31 C.F.R. § 1020.320, a bank and its directors, officers, employees, and agents may not disclose that a SAR has been filed, except as specifically authorized, and must decline to produce a SAR in response to a subpoena or other legal demand, citing the regulation. A safe harbor — a statutory shield from liability for the disclosure — separately protects institutions and their personnel from liability to any person for filing a SAR or for the underlying disclosure, including for any failure to give notice that a report was made. The regulation also imposes a five-year retention duty: a bank must keep a copy of any SAR it files, along with the original or business-record equivalent of its supporting documentation, for five years from the date of filing.
What This Means in Practice for Compliance Teams
Four operational consequences follow directly from the sourced record, bounded to what FinCEN and the banking agencies actually said on October 9, 2025.
First, alert-disposition logic tuned to flag every transaction near the $10,000 CTR threshold is now explicitly broader than the standard requires; recalibrating detection rules to the evasion-intent standard in FAQ one may reduce filings that FinCEN itself has said add noise rather than value. Second, institutions that maintain a dedicated post-SAR account-review track can now point to FAQ two to fold that track back into ordinary risk-based monitoring, if their own risk appetite supports doing so. Third, any institution using — or considering — the elective day-30/day-150 continuing-activity cadence should document that election as a deliberate policy choice, since the FAQs frame it as optional rather than default. Fourth, none of this changes the underlying 30/60-day filing deadline or the five-year retention duty in 31 C.F.R. § 1020.320; recordkeeping and e-filing systems built to that regulation require no redesign on account of the October 2025 guidance.
This article explains regulatory requirements as reflected in the sourced record. It is information, not legal advice, and institutions should consult qualified counsel about how these obligations apply to their own facts and circumstances.
For a related digital perspective, read CFPB's Section 1033 Open Banking Rule: What Its 2026 Compliance Stay Means for Data Providers.
For more context, read Why Profitable Small Businesses Still Run Out of Cash.
For more context, read What a 7.50% Prime Rate Does to Your Business Credit Line.
For more context, read How Does SIPC Protect Investors When a Brokerage Fails?.
