Skip to content
complianceofficer

Blog · 11 Aug 2026 · 11 min read

Suspicious activity report filing: the 30 day clock, the $5,000 trigger and the CTR line most guides get wrong

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The short answer: a bank must file a suspicious activity report no later than 30 calendar days after the date of initial detection of facts that may form a basis for filing, and the reporting threshold is a transaction involving or aggregating at least $5,000. If no suspect has been identified by the detection date, filing may be delayed a further 30 days, but never beyond 60 calendar days from initial detection. That clock starts when you detect, not when the customer transacted.

That last sentence is where most programs get into trouble, and it is stated backwards on a surprising number of the pages that rank for this question. This piece walks the actual regulation, 31 CFR 1020.320, alongside the currency transaction report rules in 31 CFR 1010.311 and 1010.306, and flags the three places the published summaries and the regulation part company. Everything below was checked against the eCFR on 11 August 2026.

When must a suspicious activity report be filed?

Within 30 calendar days of initial detection. The regulation at 1020.320(b)(3) says a bank must file "no later than 30 calendar days after the date of initial detection by the bank of facts that may constitute a basis for filing a SAR." It then allows one extension: "If no suspect was identified on the date of the detection of the incident requiring the filing, a bank may delay filing a SAR for an additional 30 calendar days to identify a suspect. In no case shall reporting be delayed more than 60 calendar days after the date of initial detection of a reportable transaction."

Read the extension carefully, because it is narrower than it is usually described. It is available only where no suspect was identified on the detection date. It is not a general grace period for a complicated investigation, and it is not something you elect because the analyst is busy. If you know who did it on day one, you have 30 days, full stop.

Why the detection date, not the transaction date

Suspicion is something a person or a system forms, and it usually forms long after the money moved. A pattern that surfaces in a quarterly look back may involve transactions from March. The filing is due 30 days from the day you detected the facts, so those March transactions do not put you instantly late. Equally, an alert that sat unreviewed in a queue for six weeks does not get a fresh clock when an analyst finally opens it, because detection is when the institution came into possession of the facts, not when someone got around to reading them.

This matters for tooling. Any monitoring system that anchors its due date to the transaction timestamp will show you breaches that are not real and, more dangerously, can mask ones that are. When evaluating a platform, ask directly which date field drives the countdown and whether an analyst can set the detection date with a documented reason.

What triggers a SAR?

Under 1020.320(a)(2), a transaction requires reporting if it is conducted or attempted by, at or through the bank, it involves or aggregates at least $5,000 in funds or other assets, and the bank knows, suspects, or has reason to suspect one of three things. Note that attempted transactions count, which catches the customer who walks away when asked for identification.

Cite What makes the transaction reportable
(a)(2)(i) Involves funds derived from illegal activity, or is intended or conducted to hide or disguise such funds, as part of a plan to violate or evade federal law or a transaction reporting requirement
(a)(2)(ii) Is designed to evade any requirement of 31 CFR chapter X or any other Bank Secrecy Act regulation
(a)(2)(iii) Has no business or apparent lawful purpose, or is not the sort the particular customer would normally engage in, and the bank knows of no reasonable explanation after examining the available facts

The third limb is the one that does the work in practice, and it is also the one that requires a judgment your file has to record. It is not enough that the activity looked odd. The standard asks whether you examined the available facts, including the background and possible purpose of the transaction, and found no reasonable explanation. A disposition note that says "unusual for customer" without saying what was examined is a finding waiting to happen.

The $5,000 threshold, and the $10,000 line people get wrong

The SAR threshold is at least $5,000 in funds or other assets, and it applies to transactions that aggregate to that figure rather than only to single transactions above it. The currency transaction report is a different instrument with a different number, and this is where a genuine error has propagated across the published material.

Report Threshold, in the regulation's words Deadline Cite
SAR Involves or aggregates at least $5,000 in funds or other assets 30 calendar days from initial detection, 60 maximum 31 CFR 1020.320
CTR A transaction in currency of more than $10,000 Within 15 days following the day the transaction occurred 31 CFR 1010.311, 1010.306(a)(1)

The CTR rule reads "more than $10,000." It does not read "$10,000 or more," which is how a large share of training decks and vendor pages summarize it. A currency deposit of exactly $10,000.00 does not require a CTR. This is not a technicality you can safely round: threshold configuration is examined, and a customer repeatedly transacting at exactly the round number is a structuring pattern that should be raising a SAR precisely because it is not raising a CTR.

What happens after you file

Two obligations attach immediately, and both outlive the filing itself.

Retention. Under 1020.320(d), a bank keeps a copy of any SAR filed plus the original or business record equivalent of the supporting documentation for five years from the date of filing. Supporting documentation must be identified and maintained as such, and it is deemed to have been filed with the SAR. That deeming clause matters: it means the supporting file is part of the report, not a working paper you can tidy up later.

Confidentiality. Under 1020.320(e), a SAR and any information that would reveal its existence are confidential. The rule goes further than most people expect. A bank that is subpoenaed or otherwise asked to produce a SAR "shall decline to produce the SAR or such information, citing this section and 31 U.S.C. 5318(g)(2)(A)(i), and shall notify FinCEN of any such request and the response thereto." You do not comply and you do not quietly refuse. You decline on the record with the citation, and you tell FinCEN. Every institution should have that response drafted before it is needed, because the moment it is needed there is a deadline attached to someone else's process.

There are sensible carve outs. You may share the underlying facts, transactions and documents on which a SAR is based, including with another institution to prepare a joint SAR, and you may share the SAR itself within your corporate organizational structure for purposes consistent with the Bank Secrecy Act, provided nobody involved in the reported activity is told it was reported. The distinction is between the report and the facts. The facts were always yours.

What is not reportable

1020.320(c) carves out two situations that trip up new BSA staff. A bank is not required to file a SAR for a robbery or burglary, committed or attempted, that is reported to the appropriate law enforcement authorities. Nor is one required for lost, missing, counterfeit or stolen securities where the bank files a report under 17 CFR 240.17f-1. Both exceptions are conditional on the other report actually being made, so the exception disappears if the underlying filing does not happen.

Separately, a bank may voluntarily file on a transaction it believes relevant to a possible violation even where reporting is not required. Voluntary filings carry the same confidentiality protection, which is often the reason to make one.

Building a SAR narrative that survives review

The filing itself is a form. The part that gets examined is the narrative and the file behind it, and the failure mode is almost never a missing rule. It is a reconstruction problem: months later, nobody can show which data the decision rested on. Three habits fix most of it.

First, record the detection event as its own dated fact, separate from the alert and separate from the transaction. That single field is what makes your 30 day calculation defensible.

Second, assemble the transaction trail before you write, not while you write. This is genuinely tedious where activity spans a core banking system, a card processor and a payments partner, and institutions routinely discover that the same movement of funds appears three times in three formats. Getting those records matched and dated first, whether by hand or with software that reconciles bank and processor records, turns a narrative argument into a timeline anyone can follow.

Third, write down what you examined and rejected. The 1020.320(a)(2)(iii) standard is explicitly about having examined the available facts and found no reasonable explanation, so a narrative that names the explanations considered is stronger than one that only asserts suspicion, even when it reaches the same conclusion.

Who this applies to, and one date that moved

1020.320 sits in the part of the regulations covering banks, and parallel SAR rules exist for money services businesses, broker dealers, casinos, mutual funds and others, each in its own part of 31 CFR chapter X with the same 30 day structure. One population's date recently changed and the change is still not widely reflected.

FinCEN's rule bringing registered investment advisers and exempt reporting advisers under AML program and SAR filing requirements was published on 4 September 2024 at 89 FR 72156, with an effective date of 1 January 2026. A final rule published on 2 January 2026 delayed that effective date by two years, to 1 January 2028. Advisers reading a 2025 vintage compliance calendar are working from a date that no longer applies. Checked against the Federal Register API on 11 August 2026, the two year delay stands.

Worth noting alongside it: FinCEN's broader AML/CFT program rule, proposed on 10 April 2026 with comments closed on 9 June 2026, has not been finalized. 31 CFR 1020.210 as currently written remains the operative program requirement.

Where software helps and where it does not

Detection, case management and the filing clock are all genuinely mechanical, and there is no reason to run them by hand at any real volume. Our AML compliance software page walks the four different products sold under that label and what each one actually covers, and the AML transaction monitoring page covers the detection layer specifically. The wider program, including the five minimum contents of 31 CFR 1020.210, is walked in the anti money laundering program guide.

What software does not do is hold the accountability. 1020.210(a)(2)(iii) requires designation of an individual responsible for coordinating and monitoring day to day compliance, and that individual signs off on the judgment behind every filing. The useful division of labor is to let the system carry the volume, the clock and the record, and to spend the officer's attention on the calls that are genuinely close.

The other thing worth automating is the rulebook. Thresholds, forms and deadlines in this area move, as the adviser population just discovered, and a program that only learns about a change at its next independent test has already been non compliant for a while. That is the specific gap regulatory change management exists to close.

General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.