Skip to main content
Should You Wait for Feedback Before Changing Your SAR Process?Compliance Program Governance
5 min readFor AML Compliance Officers

Should You Wait for Feedback Before Changing Your SAR Process?

The Question at Hand

You file hundreds of Suspicious Activity Reports (SARs) each year. They're compliant, timely, and checked by your QA process. But here's the uncomfortable question: does law enforcement actually use them?

Most AML teams operate in a feedback vacuum. You submit FinCEN SARs through the BSA E-Filing System, and then... silence. No confirmation that the intelligence was actionable. No indication whether your narrative helped investigators connect dots or just added to the noise.

This raises a practical dilemma: Should you proactively redesign your SAR process to make reports more useful, or should you wait for explicit feedback from law enforcement before changing anything? Your answer determines whether you invest resources in SAR quality improvements now or stick with your current approach until someone tells you it's broken.

The Case for Waiting

The "wait for feedback" camp makes legitimate arguments rooted in compliance reality.

First, you're already meeting your regulatory obligations. The Bank Secrecy Act requires you to file SARs within specific timeframes when you detect suspicious activity. Your current process achieves that. If regulators haven't cited SAR quality issues in your last three exams, why fix what isn't broken?

Second, law enforcement feedback is hard to obtain. FinCEN doesn't routinely tell you whether your SARs contributed to investigations. Local FBI field offices don't have the bandwidth to provide systematic feedback to every financial institution in their territory. The feedback loop everyone talks about doesn't actually exist for most institutions.

Third, you face resource constraints. Your team already struggles to clear the alert queue, complete periodic reviews, and respond to law enforcement requests. Adding a project to "make SARs more actionable" competes with those core obligations. Without clear direction on what law enforcement needs, you risk spending weeks on improvements that miss the mark entirely.

Fourth, SAR confidentiality rules complicate feedback. You can't discuss specific SARs with law enforcement without their initiation. You can't compare notes with peer institutions about what works. This regulatory constraint makes it nearly impossible to learn what "actionable" actually means in practice.

The practical argument here: focus your limited resources on clear regulatory requirements rather than speculative improvements to SAR utility.

The Case for Proactive Improvement

The "improve now" advocates argue that waiting is a false economy that costs you more in the long run.

Start with what Sarah Beth Felix noted: "a clean audit is not a good audit." If your only goal is passing exams, you're optimizing for the wrong outcome. Your SAR process should detect and report financial crime effectively, not just check regulatory boxes.

Consider what happens when you wait for feedback. You're essentially betting that your current SAR narratives contain the details investigators need. But if you're filing reports that lack context about why the activity is suspicious, what the customer's stated business purpose was, or how the pattern evolved over time, you're producing compliant but low-value intelligence. By the time a regulator or law enforcement contact tells you this, you've potentially missed years of opportunities to contribute to actual investigations.

The fintech-bank partnership space illustrates this risk. These arrangements create complex transaction flows where suspicious activity can be harder to detect and describe. If you're a bank providing infrastructure to multiple fintech partners, your SARs need to explain not just what happened, but which partner's customers were involved and what controls failed. Waiting for feedback means you might be filing reports that investigators can't even parse without additional context you didn't provide.

Feedback doesn't come as a polite suggestion letter. It comes during an exam when a regulator questions why your SAR narratives are generic, or during an enforcement action when your entire AML/CFT Framework is under scrutiny. At that point, you're not just fixing your SAR process; you're remediating under a consent order.

The proactive approach means establishing your own quality metrics now. You can review a sample of your SARs quarterly and ask: Would an investigator who's never heard of this customer understand what happened and why it matters? Does the narrative explain the suspicious indicators in plain language? Did you include account opening information, beneficial owner details, and transaction counterparties?

Where Practitioners Actually Land

Most AML teams operate in the middle. They don't wait passively, but they don't overhaul their entire process either.

The common pattern: you make incremental improvements to SAR narratives based on what you learn from examiner questions, law enforcement inquiries about past SARs, and peer discussions at ACAMS conferences. When a detective calls asking for additional details about a SAR you filed six months ago, you note what was missing and adjust your template.

You also focus improvements where you have the most uncertainty. If you're seeing an uptick in cryptocurrency-related suspicious activity but your narratives don't clearly explain the blockchain indicators you're seeing, that's a place to invest in better documentation now rather than later.

The middle path also means being realistic about resources. You can't make every SAR a masterpiece of investigative narrative. But you can identify your highest-risk SAR categories and ensure those get enhanced review and more detailed narratives.

Our Take

Don't wait for feedback that may never come. The cost of improving SAR quality now is lower than the cost of remediating later.

Here's why: the regulatory environment is moving toward effectiveness, not just compliance. When FinCEN and other regulators emphasize "actionable" intelligence, they're signaling that box-checking won't be enough. If your SARs consistently lack the context law enforcement needs, you're building a compliance liability even if you're technically meeting filing deadlines.

Start with a quarterly SAR quality review. Pull ten SARs at random and evaluate them against a simple test: could an investigator who's never seen your customer understand what happened and why you thought it was suspicious? If the answer is no, you've identified your improvement target.

Second, document what you don't know. If you're filing SARs on activity where you genuinely can't determine the underlying purpose, say that explicitly in the narrative. "Customer stated the wire transfers were for consulting services, but we could not verify the existence of the stated counterparty or the nature of services provided." That's more useful than a generic "unusual pattern" statement.

Third, create your own feedback mechanism. When law enforcement contacts you about a SAR, ask what additional information would have been helpful upfront. Document those insights and share them with your SAR writing team. It's not systematic feedback, but it's better than operating blind.

The tradeoff is real: you'll spend more time on SAR narratives now. But you're buying insurance against a more expensive problem later, and you're actually contributing to financial crime detection rather than just filing reports into a void.

You Might Also Like