Internal Suspicious Activity Report
An internal suspicious activity report is a report that an employee or member of a firm submits within their own organization when they notice activity they consider suspicious. It is directed to a designated person inside the firm, such as a nominated officer, rather than to an outside authority. That designated person then decides whether an external report to the relevant authority is warranted.
An internal suspicious activity report is an intra-organizational disclosure through which staff escalate knowledge or suspicion of potentially suspicious activity to a firm's nominated officer (or equivalent internal reporting function), forming the first stage of a two-tier reporting process. It is operationally and legally distinct from an external Suspicious Activity Report (SAR) filed with a competent authority such as FinCEN in the US: the internal report feeds the nominated officer's assessment, who then determines whether an external SAR/disclosure is required. Templates and standardized forms (for example, those developed by professional bodies such as CIMA, or precedent forms) are commonly used to formalize this internal reporting channel and route disclosures to the nominated officer. The existence of an internal report reflects a suspicion or escalation and does not, in itself, establish that any wrongdoing has occurred; the specific triggers, thresholds, and downstream external filing obligations should be confirmed against the applicable regime, as these vary by jurisdiction and obliged-entity type.
Why it matters
The internal suspicious activity report is the operational cornerstone of the two-tier reporting model that many AML regimes rely on. Rather than expecting every employee to make a direct filing to an external authority, firms channel staff knowledge or suspicion to a single designated person, such as a nominated officer, who is positioned to weigh the information against the firm's wider risk picture and legal obligations. This design concentrates expertise and consistency at the point of external decision-making, while ensuring that front-line staff who often observe suspicious activity first have a clear, low-friction route to escalate what they see.
The distinction between an internal report and an external SAR matters because it separates escalation from disclosure. An internal report reflects a suspicion or a decision to escalate; it does not by itself establish that money laundering, terrorist financing, or any other wrongdoing has occurred, and it is not the same as a filing made to a competent authority. Treating the two as interchangeable can create both compliance and legal risk, because the external filing obligation and its triggers generally rest with the nominated officer's assessment and vary by jurisdiction and obliged-entity type.
Because the internal report drives whether an external SAR/disclosure is ultimately made, weaknesses in this internal channel can undermine an entire reporting program. Professional bodies have responded by developing standardized tools: CIMA has developed a template internal suspicious activity report to help Members-in-Practice formalize the internal reporting process, and precedent internal SAR forms are used to make submitting reports to the nominated officer as straightforward as possible. The specific thresholds and downstream external filing obligations should be confirmed against the applicable regime, as these differ across frameworks.
Who it's relevant to
Inside Internal SAR
Common questions
Answers to the questions practitioners most commonly ask about Internal SAR.