Skip to main content
Category: Suspicious Activity Reporting

Internal Suspicious Activity Report

Also known as: Internal SAR, Internal SAR, Internal suspicious activity report form, Internal disclosure
Simply put

An internal suspicious activity report is a report that an employee or member of a firm submits within their own organization when they notice activity they consider suspicious. It is directed to a designated person inside the firm, such as a nominated officer, rather than to an outside authority. That designated person then decides whether an external report to the relevant authority is warranted.

Formal definition

An internal suspicious activity report is an intra-organizational disclosure through which staff escalate knowledge or suspicion of potentially suspicious activity to a firm's nominated officer (or equivalent internal reporting function), forming the first stage of a two-tier reporting process. It is operationally and legally distinct from an external Suspicious Activity Report (SAR) filed with a competent authority such as FinCEN in the US: the internal report feeds the nominated officer's assessment, who then determines whether an external SAR/disclosure is required. Templates and standardized forms (for example, those developed by professional bodies such as CIMA, or precedent forms) are commonly used to formalize this internal reporting channel and route disclosures to the nominated officer. The existence of an internal report reflects a suspicion or escalation and does not, in itself, establish that any wrongdoing has occurred; the specific triggers, thresholds, and downstream external filing obligations should be confirmed against the applicable regime, as these vary by jurisdiction and obliged-entity type.

Why it matters

The internal suspicious activity report is the operational cornerstone of the two-tier reporting model that many AML regimes rely on. Rather than expecting every employee to make a direct filing to an external authority, firms channel staff knowledge or suspicion to a single designated person, such as a nominated officer, who is positioned to weigh the information against the firm's wider risk picture and legal obligations. This design concentrates expertise and consistency at the point of external decision-making, while ensuring that front-line staff who often observe suspicious activity first have a clear, low-friction route to escalate what they see.

The distinction between an internal report and an external SAR matters because it separates escalation from disclosure. An internal report reflects a suspicion or a decision to escalate; it does not by itself establish that money laundering, terrorist financing, or any other wrongdoing has occurred, and it is not the same as a filing made to a competent authority. Treating the two as interchangeable can create both compliance and legal risk, because the external filing obligation and its triggers generally rest with the nominated officer's assessment and vary by jurisdiction and obliged-entity type.

Because the internal report drives whether an external SAR/disclosure is ultimately made, weaknesses in this internal channel can undermine an entire reporting program. Professional bodies have responded by developing standardized tools: CIMA has developed a template internal suspicious activity report to help Members-in-Practice formalize the internal reporting process, and precedent internal SAR forms are used to make submitting reports to the nominated officer as straightforward as possible. The specific thresholds and downstream external filing obligations should be confirmed against the applicable regime, as these differ across frameworks.

Who it's relevant to

Front-line and operational staff
Employees and members of a firm are often the first to observe activity that appears suspicious. The internal reporting channel gives them a defined route to escalate knowledge or suspicion to the nominated officer, and standardized forms are commonly used to make that submission as easy as possible.
Nominated officers and internal reporting functions
The designated person receiving internal reports assesses each escalation and determines whether an external SAR or disclosure to a competent authority is warranted. This role sits at the pivot point between internal escalation and external filing, and the applicable triggers and obligations should be confirmed against the relevant regime.
Members-in-Practice and professional-services firms
Professional bodies such as CIMA have developed template internal suspicious activity reports to help Members-in-Practice formalize their internal reporting process, making these tools particularly relevant to accountants and similar practitioners operating as obliged entities.
Compliance and AML program owners
Those responsible for designing and maintaining AML programs rely on a functioning internal reporting channel to ensure suspicions reach the nominated officer consistently. Precedent internal SAR forms support this by standardizing how disclosures are captured and routed, though the specific external filing obligations they feed into vary by jurisdiction and entity type.

Inside Internal SAR

Reporting Employee Details
Identifies the staff member who first observed and escalated the suspicious activity, enabling follow-up questions and an audit trail of who raised the concern and when.
Subject Identification
Details of the customer or party whose activity or transactions prompted the report, including available identifying information held by the obliged entity.
Description of the Suspicious Activity
A factual narrative of the observed behaviour, transactions, or circumstances that gave rise to suspicion, distinguishing observation from conclusion.
Grounds for Suspicion
The reasoning, indicators, or red flags that led the employee to consider the activity unusual or inconsistent with expected customer behaviour, presented as concerns rather than proof of criminality.
Supporting Documentation
Attachments or references such as transaction records, account information, or correspondence that substantiate the concern and assist the internal reviewer.
Routing to the MLRO or Nominated Officer
The internal report is directed to the designated compliance function (for example, the MLRO or nominated officer under the UK Money Laundering Regulations and Proceeds of Crime Act framework) who decides whether an external disclosure is warranted.

Common questions

Answers to the questions practitioners most commonly ask about Internal SAR.

Is an internal Suspicious Activity Report the same thing as a SAR or STR filed with the authorities?
No. An internal SAR is a report raised by an employee to their firm's nominated officer or MLRO (or equivalent internal function) to escalate a suspicion or concern for review. It is an internal escalation document, not a regulatory filing. Whether that internal report results in an external disclosure to the relevant Financial Intelligence Unit, such as a SAR to FinCEN in the US or an STR in many other jurisdictions, is a separate decision typically made by the nominated officer or MLRO after assessment. Terminology varies: some jurisdictions and firms use "internal report," "internal disclosure," or similar terms. The exact process and naming should be confirmed against the applicable regime and the firm's own procedures.
Does raising an internal SAR mean the employee has confirmed that money laundering or another crime has occurred?
No. An internal SAR reflects a suspicion, knowledge, or reasonable grounds for suspicion, depending on the standard applicable in the relevant jurisdiction, and is a trigger for further review, not a finding of wrongdoing. It does not establish that a customer or transaction is criminal. The purpose of the internal report is to bring information to the attention of the person responsible for assessing it, who then decides whether an external disclosure is warranted. The compliance act of reporting a suspicion is distinct from any criminal-law determination, which is a matter for investigators and courts.
Who within a firm should employees submit an internal SAR to?
In many jurisdictions, internal reports are directed to the firm's nominated officer or Money Laundering Reporting Officer (MLRO), or an equivalent designated function, who is responsible for evaluating them and deciding on any external disclosure. The precise title and reporting line depend on the applicable regime and the firm's internal governance. Firms generally set out the designated recipient and the submission channel in their internal policies and procedures, and staff should follow those documented arrangements rather than assuming a single universal route.
What information should typically be included in an internal SAR?
Internal reports generally capture the facts giving rise to the suspicion or concern, such as the customer or account involved, the relevant transactions or activity, the reason the employee considers the matter unusual, and any supporting context or documentation, so that the reviewing officer can make an informed assessment. The specific fields and level of detail expected are usually defined in the firm's own procedures. Employees are typically expected to record their observations factually and avoid drawing conclusions of criminality, since the internal report is a basis for review rather than a determination.
How quickly should an internal SAR be raised after a concern arises?
Firms generally expect internal reports to be raised promptly once an employee forms a suspicion or concern, so that the nominated officer or MLRO can assess the matter and consider any external disclosure obligations in a timely way. Exact expectations on timing are typically set out in internal procedures and may be shaped by the requirements of the applicable regime. Because delays can affect the firm's ability to meet any external reporting timeframes, staff are usually instructed not to defer escalation while they gather additional certainty.
Can an employee discuss an internal SAR with the customer or with colleagues?
Employees should be cautious here, because many AML regimes contain tipping-off or disclosure restrictions that may apply once a suspicion has been reported or an investigation may be underway. In general, staff are instructed to keep internal reports confidential, to limit discussion to those with a legitimate need to know, and not to alert the subject of the report. The precise scope of any tipping-off prohibition depends on the applicable regime, and firms typically address permitted internal disclosures in their policies. Where there is doubt, employees should consult the nominated officer or MLRO before communicating about a report.

Common misconceptions

An internal SAR is the same as a report to the authorities.
An internal SAR is a report made by an employee to the firm's internal compliance function (such as the MLRO or nominated officer). It is distinct from an external SAR or STR filed with a Financial Intelligence Unit, which is typically the decision of the designated officer after review. Terminology and the external counterpart's name vary by jurisdiction, and exact obligations should be confirmed against the applicable regime.
Filing an internal SAR means the subject has committed a crime.
An internal SAR records a suspicion or concern for review; it does not establish wrongdoing. Whether activity is criminal is a matter for investigation and, ultimately, the criminal-law process, not for the compliance filing itself.
An employee should investigate and confirm the activity is suspicious before escalating.
The internal SAR mechanism generally exists so that staff escalate concerns promptly to the compliance function, which then assesses them. Employees are typically expected to report reasonable grounds for suspicion rather than to independently conclude or prove that money laundering occurred.

Best practices

Escalate concerns promptly to the designated compliance function (such as the MLRO or nominated officer) rather than delaying to gather conclusive proof, since the internal report is intended to trigger review, not to establish criminality.
Document the factual observations and the specific grounds for suspicion clearly, separating what was observed from any conclusions drawn.
Attach or reference relevant supporting documentation so the reviewer can assess the concern efficiently.
Maintain confidentiality and be alert to tipping-off risks, avoiding disclosure of the report to the subject or unauthorised parties in line with the applicable regime.
Preserve a clear audit trail recording who raised the report, when, and how it was routed to the compliance function.
Frame red flags and indicators as concerns to be assessed rather than as proof of wrongdoing, recognising that typologies are not exhaustive and do not by themselves establish criminality.