Fundamentals
What Makes a SAR Narrative Defensible (Not Just Filed)
A suspicious activity report that reads as a summary of a gut feeling doesn't hold up to regulatory review. One that reads as a chain of specific, dated observations does. The difference is almost entirely structural.
May 22, 2026 · 8 min read
A Suspicious Activity Report exists to do one job: give the National Crime Agency’s UK Financial Intelligence Unit enough specific, factual information to decide whether the activity described warrants investigation — or, where a defence against money laundering is being sought, whether to grant consent to proceed. It is not a place to record suspicion as a feeling — it’s a place to record suspicion as evidence, laid out so a reader with zero prior context on the case can follow the reasoning to the same conclusion the analyst reached.
The single most common failure: conclusions without observations
The weakest narratives I’ve seen (and, early on, written) read something like: “Customer’s transaction pattern is inconsistent with stated business purpose and appears suspicious.” That sentence is a conclusion wearing the grammar of an observation. It tells a reviewer nothing about what was actually seen, when, or why it mattered.
A defensible version of the same underlying concern reads closer to: “Between 3 and 28 March 2026, the customer’s account received eleven incoming transfers ranging from £7,200 to £7,900, from eleven different individuals with no apparent business relationship to the customer’s stated import/export activity. Funds were withdrawn as cash or converted to a bank draft within 24 hours of each deposit in nine of the eleven instances.” No adjectives, no editorializing — just what happened, when, and the specific pattern (structuring into amounts designed to look unremarkable individually, rapid conversion to a less traceable instrument) that a trained reviewer will recognize without being told to.
The structure that holds up
Regardless of the specific software or the exact SARs Online form fields, a strong narrative consistently does five things, roughly in order:
- States who and what, unambiguously — the account(s), the customer(s), and the specific activity in scope, without assuming the reader already has the case file open.
- Lays out the chronology of observed facts — dates, amounts, counterparties, channels — in the order they occurred, not the order they were noticed.
- Names the specific indicator(s) that make the pattern suspicious, tied to recognized typologies where applicable (structuring, rapid movement of funds, unexplained third-party involvement, transactions inconsistent with stated occupation or business purpose) rather than a generic “unusual activity” label.
- States what due diligence was performed before filing — was the customer asked to explain the activity? Was the explanation, if any, checked against other account information? This is often the section that’s skipped, and it’s the section that most demonstrates the analyst did the work rather than pattern-matched a rule hit.
- States the conclusion last, as a natural consequence of everything above it — not as the headline the rest of the narrative is built to justify.
What to leave out, deliberately
- Legal conclusions. “This constitutes money laundering under POCA 2002” is not the analyst’s determination to make in a narrative — describe the activity and let the indicator speak.
- Speculation about intent beyond what the facts support. “Customer is likely laundering proceeds from narcotics trafficking” is a leap the evidence usually doesn’t license; “activity is consistent with a structuring typology commonly associated with efforts to avoid scrutiny of the aggregate amount moved” stays inside what was actually observed.
- Internal deliberation as if it were evidence. The fact that three analysts discussed the case and disagreed isn’t itself suspicious activity — only the underlying transactional facts are.
The part of the consent regime most junior analysts never see explained
If the SAR is a DAML — a Defence Against Money Laundering, filed under section 335 of the Proceeds of Crime Act 2002 when the institution itself would otherwise be handling (and therefore potentially laundering) criminal property by completing the transaction — the narrative isn’t just informing an investigation, it’s starting a clock. Once the NCA receives the DAML, it has seven working days to respond. Say nothing, and consent is deemed to have been given automatically at the end of that window — the transaction can proceed. Refuse consent, and a further 31-calendar-day moratorium begins, which law enforcement can extend in further 31-day blocks up to a statutory maximum, giving them time to investigate, restrain assets, or build a case, without ever having told you why.
The practical consequence: a vague DAML narrative doesn’t just risk a poor-quality intelligence record, it risks the NCA not having enough to act within seven working days — meaning consent is deemed granted by default and the transaction proceeds regardless of how suspicious it actually was. A precise, fact-dense narrative is what gives the UKFIU enough to actually engage with the request inside a deadline that exists whether or not the writing is good enough to meet it.
Why this discipline matters beyond the individual filing
A narrative built this way survives two things a vaguer one doesn’t: regulatory examination of your program’s SAR quality, and your own ability to re-establish the reasoning six months later when the same customer resurfaces in a different context. Case files get reread far more often than they get written — a narrative that only makes sense to the person who filed it, on the day they filed it, has already failed at half its job.