# Suspicious activity report (SAR/STR)

**A suspicious activity report (SAR) — called a suspicious transaction report (STR) in EU law — is the report a regulated firm must file promptly with its national financial intelligence unit (FIU) when it knows, suspects or has reasonable grounds to suspect that funds or activities are the proceeds of criminal activity or are related to terrorist financing, regardless of the amount involved.**

*Also called:* STR, suspicious transaction report, suspicion report. In Belgium, reports go to CTIF-CFI, the Belgian financial intelligence unit.

## Why it matters for PSPs and EMIs

Payment institutions see money move, so they are often the first to notice a pattern that does not fit. During onboarding, a suspicion can also arise before any transaction: a forged document, a concealed owner, or an inability to complete due diligence. The quality of the assessment behind a report — or behind the decision not to report — is itself a record the supervisor can ask to see.

## What the law says

- **The duty.** AMLR Art. 69(1)(a): report to the FIU on the firm's own initiative, promptly, where it knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount, are the proceeds of criminal activity or related to terrorist financing. Attempted transactions and suspicions arising from an inability to complete customer due diligence are included (Art. 69(1), second subparagraph).
- **Requests from the FIU.** AMLR Art. 69(1), third subparagraph: reply within 5 working days, or faster in urgent cases.
- **How suspicion is formed.** AMLR Art. 69(2): on the basis of the customer and counterparts, the size, nature and pattern of the activity, the origin, destination or use of funds, and its consistency with the customer's risk profile.
- **Who files.** AMLR Art. 69(6): the compliance officer transmits the report to the FIU of the Member State where the firm is established.
- **Hold the transaction.** AMLR Art. 71(1): refrain from carrying out transactions known or suspected to be related to criminal activity or terrorist financing until the report has been submitted and any specific instructions from the FIU have been complied with. The firm may proceed, after assessing the risks, if the FIU has not instructed otherwise within 3 working days of the report.
- **Do not tell the customer.** AMLR Art. 73 (see [tipping-off](/glossary/tipping-off/)).
- **Keep the assessment.** AMLR Art. 77(1)(b): keep a record of the assessment, the information and circumstances considered, and its result, whether or not a report is filed.
- **Format.** AMLR Art. 69(3): AMLA implementing technical standards on the reporting format.
- **Current law.** Directive (EU) 2015/849, Art. 33; in Belgium, Law of 18 September 2017, Art. 47 (reports to CTIF-CFI).
- **International standard.** FATF Recommendation 20.

## How ProofVolt handles it

In ProofVolt, a suspicious transaction report is prepared in the case: a draft, then the MLRO's reportability assessment (report required, not required, or more information needed), signed by someone other than the person who raised the concern. Where a report is due, ProofVolt exports it as a goAML XML file for the MLRO to submit through the FIU's own channel, and records the FIU's reference once it has been submitted. ProofVolt does not file the report itself. When a case carries a criminal, enforcement, sanctions or asset-freeze finding, customer contact waits for the signed assessment, and no officer can override that. Every source, step and decision in the case is kept in an append-only trail.

## Related

- [Tipping-off](/glossary/tipping-off/)
- [MLRO](/glossary/mlro/)
- [Adverse media](/glossary/adverse-media/)

Canonical: https://proofvolt.eu/glossary/suspicious-activity-report/
