ACAMS CAMS: Writing Useful Suspicious Activity Reports
A suspicious activity report is not the place to reproduce an investigation file verbatim. Its job is to give the receiving authority a clear, concise, fact-based explanation of the suspicious activity and the context needed to understand why it matters. The narrative should help a reader reconstruct the pattern without guessing which transactions or relationships drove the decision.
Within AML operations, SAR writing sits at the end of a chain that begins with customer understanding and monitoring. A strong report depends on evidence gathered during alert triage, investigation, and escalation. Weak notes upstream cannot be repaired merely by polishing the final narrative.
Good writing is structured around facts: who was involved, what occurred, when and where the activity happened, how it moved, and why it was suspicious. The explanation of why is what transforms a transaction list into actionable intelligence.
Open with the reason for suspicion
The first lines should establish the essential pattern and why it is being reported. A reader should quickly understand whether the concern involves structuring, rapid movement, unexplained counterparties, suspected fraud, sanctions concerns, or another pattern. Background belongs after the core issue is clear.
Avoid conclusory statements that outrun the evidence. The narrative should describe observed behavior and the institution’s basis for suspicion without asserting a criminal offense that the investigation did not establish.
Use chronology to make complex activity readable
When multiple transactions matter, organize them into a timeline or logical sequence. Identify the relevant account, date range, amounts, counterparties, locations, and transaction types. Aggregate repetitive activity when that preserves clarity, and call out unusual peaks or patterns that demonstrate the concern.
Customer information from due diligence should be included when it explains why the activity differs from the expected relationship. The reader needs enough context to see the contrast.
Explain relationships among subjects and accounts
If several customers, accounts, beneficial owners, addresses, devices, merchants, or counterparties are related, state the relationship clearly. Do not assume the reader will infer it from repeated names or transaction references. A short description of ownership, control, or payment flow can make the pattern understandable.
When identifiers are relevant, use the appropriate structured fields and reinforce the relationships in the narrative. Consistent identifiers help law-enforcement users connect the filing with other information.
Describe why normal explanations were insufficient
A strong narrative can state which plausible explanations were considered and what evidence made them inadequate. For example, transaction behavior may be inconsistent with the stated business purpose, counterparties may not fit the customer profile, or repeated activity may continue after prior inquiries.
This reasoning should remain grounded in evidence. Risk-based AML means that context affects judgment, not that higher-risk customers are presumed suspicious.
Keep investigative detail proportional to usefulness
Include supporting facts that help the reader understand the activity, but avoid burying the key pattern under every investigative step. Internal case-management details, duplicated fields, and long descriptions of routine searches can make the narrative harder to use.
Supporting documentation should be retained according to applicable requirements and institutional procedure. The narrative can identify that supporting records are available without attempting to embed an entire case file into the report.
Quality review should test both facts and readability
A second reviewer should verify names, dates, amounts, account identifiers, transaction totals, and the consistency of the story. The review should also test whether a reader unfamiliar with the case can understand why the activity is suspicious.
If the narrative reveals missing customer context, weak transaction reconstruction, or unexplained screening results, the issue may belong upstream in customer due diligence or sanctions screening rather than being treated only as a writing problem.
Use filing outcomes to improve the program
SAR quality findings should feed training, scenario design, case templates, and customer-data remediation. If narratives repeatedly lack clear timelines, case tools may need better transaction summaries. If ownership relationships are often unclear, onboarding data may need improvement.
That feedback is part of AML governance. Reporting is not merely a regulatory endpoint; it is evidence about how well the rest of the financial-crime control system understands and explains risk.
Write the narrative from a verified case chronology
Before drafting, create a short chronology that lists the material events in order. This can include account opening, changes in customer profile, key transactions, outreach, prior alerts, and the event that caused escalation. The chronology helps prevent inconsistent dates and makes it easier to decide which details are essential to the final narrative.
Totals need careful handling. If the report describes a pattern across many transactions, confirm the aggregate amount, date range, count, and direction of funds. Avoid adding unrelated transactions merely because they occurred during the review period. The total should reflect the activity being reported so investigators do not have to reverse-engineer which numbers matter.
Use customer labels consistently. If several subjects, accounts, businesses, or counterparties appear, assign clear names in the narrative and do not switch between abbreviations without explanation. Consistent references reduce ambiguity, especially when legal names are similar or one person controls several entities.
The narrative should distinguish institution knowledge from customer claims. “The customer stated that…” is different from “records show that…”. This distinction helps the reader understand which facts were independently verified and which explanations remain assertions. It also protects the filing from sounding more certain than the underlying evidence permits.
Explain the unusual pattern in relation to expected activity. A transaction is rarely suspicious because of amount alone. It becomes more informative when the report explains that the customer had no stated business in the destination country, the activity was inconsistent with prior volume, funds moved rapidly through several accounts, or the pattern resembled an apparent attempt to avoid a reporting threshold.
Where a prior SAR or related filing exists, follow institutional and regulatory guidance for referencing it and make the relationship clear. Repeated activity may represent continuation of a previously reported pattern, a materially changed pattern, or a separate concern. The narrative should not make the reader guess whether the institution sees continuity.
After drafting, perform a “cold read.” A reviewer who did not participate in the investigation should be able to state the subjects, pattern, date range, important amounts, and reason for suspicion after one reading. If the reviewer cannot, the narrative likely contains too much procedural detail or not enough explanation.
Writing quality also depends on the case-management workflow. Templates can prompt the essential facts, but they should not force every case into identical language. The strongest report is concise because the investigator understands the pattern, not because the organization has reduced the narrative to standardized boilerplate.
Confidentiality requirements should shape the reporting workflow. Staff who interact with the customer need clear instructions about what can be requested or discussed without revealing that a SAR was filed or is being considered. Case systems should also limit access appropriately because the filing decision and narrative can contain sensitive investigative information.
Standardized narrative prompts are helpful when they encourage completeness rather than canned prose. Prompts can ask for the subject, suspicious pattern, date range, amounts, explanation of unusual behavior, relevant counterparties, and supporting information. Reviewers should remove boilerplate that does not contribute to the specific filing.
Continuing activity requires disciplined comparison with prior reporting. Investigators should understand what was previously reported, what changed, and whether the new filing represents continuation, expansion, or a different pattern. This prevents narratives from becoming repetitive copies that add little new information.
Supporting documentation should be indexed so it can be produced efficiently when law enforcement or regulators request it. The index can identify statements, transaction extracts, communications, customer records, and investigative notes without embedding all of that content in the narrative. Good evidence organization makes the report more useful after filing.
Program leaders can perform thematic review of SAR narratives to identify emerging typologies, recurring customer-data gaps, or repeated analyst-writing weaknesses. Aggregated review turns reporting into intelligence about the institution’s own control environment, not merely an obligation completed case by case.
Names, amounts, dates, and transaction directions should be reconciled with the structured SAR fields before submission. Inconsistency between the narrative and form fields can confuse downstream analysis even when each value is correct in isolation. A final validation step should therefore compare the narrative with the case summary and filing fields, confirm that attachments or supporting records are referenced appropriately, and ensure that acronyms are defined when they are not obvious. The discipline is similar to audit reporting: clarity is created by accurate relationships among facts, not by adding more words.
Institutions can improve narrative quality by maintaining an internal library of anonymized examples that demonstrate different patterns without turning them into copy-and-paste templates. Examples can show how to describe structuring, rapid movement, unusual counterparties, unexplained cash activity, or cyber-enabled transactions while still requiring analysts to write the facts of the actual case. Training is most useful when reviewers explain why an example is clear, not merely when they provide a model paragraph to imitate.
A final editorial pass should remove vague phrases such as “suspicious behavior was observed” when the narrative can state the actual behavior. Precision improves both usefulness and accountability because every assertion can be traced to evidence in the case file.