What needs to be in a suspicion report?

An external suspicion report, known as a SAR in the UK and US, an STR under FATF terminology and an SMR in Australia, is the formal notification you send to your national financial intelligence unit (FIU) when you know or suspect money laundering, terrorist financing or proliferation financing.
FATF’s Recommendation 20 requires countries to make this reporting a legal obligation. This means that wherever you’re regulated, the principle is the same: once you have suspicion, reporting isn’t optional and it can’t be delayed.
A suspicion report represents your professional judgement, rather than being an accusation or a legal conclusion.
Your FIU needs enough information to quickly understand what’s happened, assess the risk, connect it to other reports it holds and decide what action to take next.
That means your report should answer six simple questions clearly:
- Who is involved
- What has happened
- When it happened
- Where it happened
- How the activity was carried out
- Why it is suspicious
If those six elements are present and well explained, you’re already a long way towards a good-quality report.
Internal reports and the role of the MLRO
In regulated businesses, staff don’t submit SARs externally. They submit an internal report to the MLRO or equivalent nominated officer.
A good internal suspicion report should contain the same core information as an external report. That allows the MLRO to:
- assess the suspicion properly;
- decide whether an external report is required;
- add context or additional information if needed; and
- document the decision-making process.
This is where having a structured internal report process really matters. If information is missing at the internal stage, it often leads to delays, follow-up questions or weaker external reports.
The core information every report must include
Who is involved
You should identify all relevant parties, not just your client. This includes:
- the main subject of suspicion;
- any associated individuals or entities;
- beneficial owners, directors or trustees where relevant; and
- third parties involved in transactions.
Use full names, dates of birth, addresses, company numbers and account details where you have them. If you don’t know something, don’t guess. Just leave it out. Clarity matters more than completeness. Accurate identifiers help the FIU connect your report with others.
What is suspicious
This is the factual description of the activity that caused concern. Focus on what you observed, not what you think it means. Avoid emotive language. Stick to what happened and what you’ve witnessed. For example:
- unusual transactions or payment patterns;
- inconsistencies between the client’s profile and their activity;
- reluctance or refusal to provide information;
- explanations that change over time; or
- transactions that appear to have no clear economic or legal purpose.
When it happened
Dates and timeframes are critical, and if the activity is ongoing say so clearly. Be as specific as you can with:
- exact transaction dates;
- periods during which suspicious behaviour occurred; and
- when concerns first arose.
Where it happened
This includes:
- relevant jurisdictions;
- bank accounts and financial institutions;
- property addresses; and
- countries involved in transactions or ownership structures.
Jurisdictional detail is particularly important where overseas entities, high-risk countries or sanctions exposure may be relevant.
How the activity was carried out
This is where many internal suspicion reports are weak. The FIU needs to understand the mechanics. Explain:
- how funds moved from A to B;
- how structures were set up or used;
- how the client interacted with you or others; and
- how transactions were funded or routed.
Why it is suspicious
This is the most important section. You should clearly explain why, in your professional judgement, the activity raised suspicion. This is not the place to quote legislation or guidance. It’s about showing your reasoning. Link it to:
- the client’s known profile;
- what you would normally expect to see;
- relevant red flags or risk indicators; and
- gaps, inconsistencies or implausible explanations.
The importance of a clear narrative
The FIU strongly encourages reporters to use the free-text narrative section properly. This is where you pull everything together. A good narrative:
- follows a logical order;
- uses plain language;
- avoids jargon and internal abbreviations; and
- explains context, not just transactions.
Imagine you’re explaining the situation to someone who has never seen the client before. That’s effectively what you’re doing.
What not to include in a report
There are some common mistakes that reduce internal suspicion report quality. Avoid:
- speculation about criminal offences you can’t evidence;
- irrelevant background information;
- copying internal risk assessments verbatim;
- defensive language explaining why you acted correctly; and
- mentioning that a report has been or will be filed.
Never let a client know that a report has been made, known as ‘tipping off’. This includes subtle hints or changes in behaviour that could reasonably alert them. It’s an offence and could see you being prosecuted too.
Record keeping and audit trails
Submitting a report is not the end of the process. FATF’s Recommendation 11 requires you to keep records of your suspicious activity reporting and the decisions behind it, so you can demonstrate a risk-based approach.
You must keep clear records of:
- the internal suspicion reports raised by staff, along with the information they provided;
- your MLRO’s decisions after reviewing each internal report;
- the reasoning behind submitting, or not submitting, an external suspicion report to your FIU;
- any consent or safe harbour request made to your FIU and its outcome, where your jurisdiction operates this kind of regime.
Keep these records securely so you can produce them promptly if needed. Supervisors routinely review report logs and decision records during AML inspections, to assess whether suspicions are being identified, escalated and handled appropriately.
Using technology to support better reports
Technology can’t replace professional judgement, but it can support consistency and completeness.
A structured internal suspicion reporting process helps staff know what information to include and prompts them to think through the six key questions. It also helps MLROs manage reports, track decisions and maintain clear audit trails.
For businesses using AMLCC, the Internal Suspicion Reporting feature mirrors the questions your FIU is likely to ask, guiding staff through the information needed, centralising reporting and linking each report to the client’s risk assessment and records.
That makes it easier to produce higher-quality external SARs and demonstrate compliance during reviews.
Final thoughts
A good internal suspicion report is clear, focused and grounded in professional judgement. It doesn’t need to be long or legalistic, but it does need to explain the story behind the suspicion.
If you can clearly answer who, what, when, where, how and why, you are meeting the FIU’s expectations and protecting both your firm and the wider financial system.
Treat reporting as part of your risk management process, not a last-minute task. The quality of your reports says a lot about the quality of your AML framework overall.
What others have said
Making compliance easier








