A Suspicious Activity Report is triggered when a bank spots a transaction of $5,000 or more that looks like it involves illegal funds, an attempt to evade federal reporting rules, or activity with no apparent business purpose that doesn’t match the customer’s normal behavior.1eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions Those three statutory categories cover a wide field, and the specific Suspicious Activity Report red flags that fall inside them tend to recur across cases: structuring cash to dodge the $10,000 currency reporting threshold, moving money in ways that don’t fit the account holder, hiding ownership behind shell entities, running stolen funds through pass-through accounts, and moving small sums in patterns associated with terrorist financing.
Below is what compliance teams actually look for in each category.
Structuring Cash to Stay Under $10,000
Banks must file a Currency Transaction Report on any cash transaction over $10,000. Structuring is the practice of deliberately breaking a larger sum into smaller cash transactions to keep the CTR from being filed, and it’s a federal crime on its own.2Financial Crimes Enforcement Network. Frequently Asked Questions Regarding Suspicious Activity Reporting Requirements
The classic pattern is a customer making repeated cash deposits of $9,000 or $9,500 across several days or multiple branches. But structuring isn’t limited to deposits just under $10,000. Under FinCEN rules, it covers breaking any single sum over $10,000 into smaller amounts, or conducting a series of cash transactions at or below the threshold, when the purpose is to avoid triggering the CTR.2Financial Crimes Enforcement Network. Frequently Asked Questions Regarding Suspicious Activity Reporting Requirements
Using other people to make deposits on your behalf falls into the same category. Compliance officers sometimes call these individuals smurfs. The pattern is easy for monitoring software to catch once linked transactions surface.
Money Laundering Patterns
Money laundering red flags share one trait: the movement of money doesn’t match any legitimate reason.
- Rapid fund transfers between unrelated accounts, especially when the money bounces through several accounts and then moves offshore. That layering is designed to put enough steps between the funds and their origin that the trail becomes impossible to follow.
- Activity that doesn’t match the customer’s profile. A customer whose account history shows modest direct deposits and suddenly wires large sums to foreign jurisdictions is a textbook mismatch. Banks compare actual activity against stated occupation, income, and account purpose.
- Transactions with no apparent purpose. If a bank examines the facts available and can find no reasonable explanation for the transaction, that alone is a basis for filing.1eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions
- Frequent currency exchanges or large purchases of money orders, cashier’s checks, or prepaid cards with cash, particularly in round amounts. Converting cash into less traceable instruments is a laundering staple.
Shell Companies and Hidden Ownership
Shell companies are among the most effective laundering tools because they put layers of ownership between the criminal and the money. FinCEN has flagged several corporate-structure red flags in particular.
The biggest one is complexity that serves no obvious business purpose. When a company’s ownership runs through multiple entities in different jurisdictions and the people behind it can’t be identified through standard database searches or direct inquiries, that opacity is often intentional. Nominees in every public-facing role are another warning: a shell may have a nominee officer, nominee shareholders, and even a nominee bank signatory, typically a lawyer or accountant who opens accounts and passes instructions from the actual owners without ever revealing their names.3FinCEN.gov. Potential Money Laundering Risks Related to Shell Companies
On the transaction side, institutions look for wire transfers where the originator or beneficiary can’t be identified, payments with no stated purpose, and companies whose actual transaction volume far exceeds what their business profile would suggest.3FinCEN.gov. Potential Money Laundering Risks Related to Shell Companies
Fraud and Cybercrime Red Flags
Fraud-related SARs cover a wide range of activity, but the patterns compliance teams see most often involve stolen funds moving through accounts that either belong to victims or were set up specifically to receive scam proceeds.
Account takeover is a common trigger. A criminal uses stolen credentials to access a legitimate customer’s account and initiates transfers the real account holder never authorized. Banks flag these when login behavior changes abruptly, such as access from a new device, a foreign IP address, or unusual hours, followed immediately by outgoing transfers.
Scam-related fund flows are another major category. Romance scams, elder exploitation, and business email compromise all follow a similar financial pattern: a victim deposits or wires money into an account controlled by the criminal or an unwitting intermediary, and those funds move rapidly, often overseas, before the fraud is discovered. The speed itself is a red flag. When someone receives a large deposit and immediately wires the same amount to a foreign account, that behavior is inconsistent with normal banking and suggests the account is being used as a pass-through.
Counterfeit instruments still show up too. Fraudulent checks, altered money orders, and forged cashier’s checks presented for deposit or cashing are reportable. These are often caught when routing information doesn’t match, or when a customer repeatedly deposits checks from unrelated parties that later bounce.
Terrorist Financing Indicators
Terrorist financing often looks different from traditional laundering because the amounts tend to be smaller. Rather than cleaning millions, the goal may be to move relatively modest sums across borders without detection. Red flags include frequent low-dollar purchases of prepaid cards, money orders, or stored value instruments in patterns that suggest cross-border movement.
Institutions also watch for transactions involving entities or individuals on the sanctions lists maintained by the Office of Foreign Assets Control. When a match is identified, the institution must block the transaction and file a report with OFAC within ten business days.4FinCEN.gov. Interpretation of Suspicious Activity Reporting Requirements to Permit the Unitary Filing of Suspicious Activity and Blocking Reports FinCEN treats the OFAC blocking report as satisfying the SAR obligation in those cases, avoiding duplicate filings.
Charitable organizations whose use of funds doesn’t match their stated mission, or whose financial activity shows transfers to high-risk jurisdictions with no clear connection to charitable work, are another indicator. When a bank suspects a customer may be linked to terrorist activity, FFIEC guidance directs the bank to immediately call FinCEN’s Financial Institutions Hotline in addition to filing a SAR.5FFIEC BSA/AML InfoBase. FFIEC BSA/AML Manual – Suspicious Activity Reporting The phone call gets the information to law enforcement faster than standard electronic filing.
What Happens After a Red Flag Is Spotted
Detecting a red flag is the start of a process, not the end. Once an institution decides the activity is reportable, it files FinCEN Report 111 electronically through the BSA E-Filing System within 30 calendar days of initial detection. If no suspect has been identified in that window, the institution gets another 30 days, but the filing cannot be delayed beyond 60 calendar days from detection.1eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions The bank keeps a copy of the report and supporting documents for five years.
SARs are strictly confidential. Federal law bars the institution and its personnel from telling anyone involved in the transaction that a SAR has been filed or even that one exists.6Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority A customer who is the subject of a SAR will never be notified, and asking the bank directly won’t produce an answer.
Institutions also have a safe harbor. Any financial institution that reports a possible legal violation to a government agency, along with the individuals who make or require the disclosure, is protected from civil liability under federal, state, and local law and under private contracts including arbitration agreements.6Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority The institution doesn’t have to prove the suspicion was well-founded; the act of reporting is what’s protected. That’s why, when a red flag surfaces, banks generally file.