Skip to main content
Category: Suspicious Activity Reporting

Suspicious Transaction Filing Deadline

Also known as: SAR Filing Deadline, Suspicious Activity Report Filing Deadline
Simply put

The suspicious transaction filing deadline is the time limit within which a financial institution must submit a report about suspicious activity to the authorities after it first identifies the concerning facts. In the US system, this is generally 30 calendar days from when the institution initially detects the relevant facts. Meeting the deadline is a compliance requirement and does not itself indicate that any wrongdoing occurred.

Formal definition

In the US Bank Secrecy Act framework, the SAR rules generally require that a Suspicious Activity Report be filed electronically through the BSA E-Filing System no later than 30 calendar days from the date of initial detection of facts that may constitute a basis for filing. Where no suspect can be identified, the timeframe for filing may be extended in accordance with the applicable rules. For continuing suspicious activity, institutions are generally expected to review and, where appropriate, report at least every 90 days, with up to an additional 30 days to file following the end of a review period, producing an overall review-and-filing window that can extend to approximately 120 calendar days. These deadlines derive from US regulatory instruments (for example, the SAR rules reflected in provisions such as 12 CFR 208.62 for member banks) and FinCEN guidance; scope is limited to obliged US financial institutions subject to the BSA SAR requirements. Terminology and deadlines differ in other jurisdictions (for example, suspicious transaction reports (STRs) under other regimes), and exact timeframes and any extensions should be confirmed against the applicable regulation.

Why it matters

The suspicious transaction filing deadline sits at the intersection of an institution's investigative process and its legal reporting obligations. Under the US Bank Secrecy Act framework, a Suspicious Activity Report generally must be filed no later than 30 calendar days from the date of initial detection of facts that may constitute a basis for filing. Missing or misapplying this timeframe is one of the more common and clearly measurable ways an institution can fall short of its SAR obligations, because the clock is tied to a specific triggering event, initial detection, rather than to the conclusion of a full investigation.

The deadline also creates operational tension that compliance functions must actively manage. Institutions need enough time to review alerts, gather facts, and reach a reasoned decision, yet they cannot delay a filing indefinitely while seeking perfect certainty. Determining the precise date of "initial detection" is frequently a matter of judgment, and getting it wrong can compress or expand the available window in ways that examiners may scrutinize. For continuing suspicious activity, the layered structure, reviewing at least every 90 days with up to an additional 30 days to file, can extend the overall review-and-filing window to approximately 120 calendar days, adding further complexity to how institutions calendar and document their decisions.

It is important to keep the compliance meaning distinct from any criminal-law implication. Filing a SAR, or filing it within the deadline, does not establish that a customer or transaction is connected to wrongdoing; a report reflects suspicion and a regulatory obligation, not a finding of guilt. The deadline is a procedural requirement designed to ensure timely information reaches authorities, and adherence to it should be understood as a compliance control rather than a substantive judgment about the underlying activity.

Who it's relevant to

AML Compliance Officers and BSA Officers
Those responsible for a US institution's BSA/AML program must operationalize the 30-day filing deadline, establish clear procedures for identifying the date of initial detection, and ensure continuing activity is reviewed at least every 90 days with filings made within the applicable window. They typically own the policies, workflows, and escalation paths that keep filings timely and documented.
Financial Intelligence Analysts and SAR Investigators
Analysts who review alerts and build the factual basis for a filing work directly against the clock, needing to complete their assessment and reach a reasoned decision within the timeframe measured from initial detection. Clear documentation of when facts were detected is central to demonstrating that filings met the deadline.
Compliance Testing, Audit, and Quality Assurance Teams
Independent testing and audit functions assess whether filings are made within the required timeframes and whether the institution consistently and defensibly identifies the date of initial detection. Timeliness is a discrete, testable control that these teams commonly examine.
Regulatory Examiners and Legal/Risk Advisors
Examiners from bodies such as the OCC and other functional regulators review adherence to SAR timing requirements as part of BSA compliance assessments, and legal and risk advisors interpret how initial-detection dates and continuing-activity rules apply to specific fact patterns. Both should confirm exact timeframes and any extensions against the applicable regulation.

Inside Suspicious Transaction Filing Deadline

Triggering Event
The point from which a filing deadline typically begins to run, which in many jurisdictions is the moment an obliged entity forms knowledge, suspicion, or reasonable grounds to suspect that funds or a transaction are linked to money laundering or terrorist financing. The precise trigger differs by regime and should be confirmed against the applicable regulation.
Prescribed Filing Period
The defined window within which a report must be submitted to the relevant Financial Intelligence Unit (FIU) or competent authority after the triggering event. Some regimes express this as a fixed number of days, while others require filing 'promptly' or 'without delay'; exact values vary by jurisdiction and should be verified against the governing instrument.
Report Type and Terminology
The nature of the filing to which the deadline applies. Terminology differs by regime: a Suspicious Activity Report (SAR) under the US Bank Secrecy Act and FinCEN rules, a Suspicious Transaction Report (STR) under many FATF-aligned frameworks, or a suspicious activity disclosure under the UK Proceeds of Crime Act. These are related but not identical instruments with distinct submission expectations.
Recipient Authority
The designated body to which the report is filed, generally a national FIU or equivalent competent authority. The identity of the recipient and its submission channel are set by the applicable regime.
Interaction with Prohibited-Action Rules
In some regimes, particularly those following the UK POCA consent (defence against money laundering) model, timing obligations interact with requirements to seek authorisation before proceeding with a transaction and with 'no tipping-off' prohibitions. These are distinct from a simple filing clock and should be assessed under the specific regime.
Scope and Applicability
The deadline applies to obliged entities as defined by the relevant regime and may vary depending on the entity type, transaction, or nature of the suspicion. Whether a matter falls in scope, and which timing rule applies, depends on the governing law rather than a single global standard.

Common questions

Answers to the questions practitioners most commonly ask about Suspicious Transaction Filing Deadline.

Does filing a suspicious transaction report mean the customer has committed a crime?
No. A suspicious transaction or activity report is a compliance filing that communicates a reasonable suspicion to the relevant financial intelligence unit; it is not a finding or accusation of criminal wrongdoing. The obligation to report is generally triggered by suspicion, not by proof, and the determination of whether any offence occurred rests with law enforcement and, ultimately, the courts. Obliged entities should be careful not to treat a filing as establishing guilt, and in most jurisdictions the reporting entity is not required to prove that money laundering or another predicate offence took place before filing.
Is there a single global deadline for filing a suspicious transaction report?
No. There is no universally applicable filing deadline. The FATF Recommendations set the standard that reports should be made promptly to the national financial intelligence unit, but they are standards rather than binding law, and the specific timeframe is set by each jurisdiction's implementing framework. Deadlines and their triggers differ across regimes, and some frameworks express the requirement qualitatively (for example, 'promptly' or 'without delay') rather than as a fixed number of days. Exact timeframes should be confirmed against the applicable regulation in the relevant jurisdiction.
When does the clock for filing typically start running?
The starting point generally depends on the applicable regime. In many jurisdictions the timeframe is measured from the point at which the obliged entity forms the relevant suspicion or knowledge, or from the moment an internal review concludes that a report is warranted, rather than from the date of the underlying transaction itself. Because the trigger event varies, firms should document how they determine the start of the period under their governing framework and confirm the precise trigger against the applicable regulation.
How should a firm handle the internal escalation process so it does not miss the filing timeframe?
Firms typically establish an internal escalation pathway from front-line staff or transaction monitoring alerts to a nominated officer or the money laundering reporting officer, who assesses whether an external report is warranted. To manage the applicable timeframe, many programs build defined internal service levels for each step so that the internal review does not consume the time available for the external filing. The specific roles, thresholds, and internal timelines depend on the entity's obligations and jurisdiction, and should be aligned with the deadline set by the governing framework.
What documentation should be retained around the timing of a filing?
It is generally advisable to record when suspicion was formed or identified, the internal decision-making steps, and the date the report was submitted, so the firm can demonstrate that it acted within the applicable timeframe. Record-keeping obligations for reports and supporting information vary by regime, and the required retention periods and formats should be confirmed against the applicable regulation. Maintaining a clear audit trail supports supervisory review and helps demonstrate the reasonableness of the timing decision.
How does the filing deadline interact with tipping-off and transaction-processing decisions?
Meeting the filing timeframe and complying with tipping-off restrictions are separate obligations that operate together. In many jurisdictions, an obliged entity must avoid disclosing to the customer that a report has been or may be made, while still filing within the required period. Whether a transaction may proceed, must be delayed, or requires consent from an authority before completion depends on the specific regime, and these rules should be confirmed against the applicable regulation. Firms should treat the timing of the filing, the tipping-off prohibition, and any transaction-handling requirements as distinct but coordinated steps.

Common misconceptions

There is a single, universal deadline for filing suspicious transaction reports worldwide.
No single global deadline exists. Filing timeframes derive from the applicable regime, for example FinCEN rules under the US Bank Secrecy Act, national laws implementing FATF standards, or the UK Proceeds of Crime Act, and these diverge in both length and how the clock is defined. The FATF Recommendations are standards rather than binding law, and each jurisdiction transposes timing obligations differently. Exact periods should be confirmed against the applicable regulation.
The deadline always begins to run from the date the transaction occurred.
In many jurisdictions the clock typically starts when the obliged entity forms knowledge or suspicion, not necessarily when the transaction took place. The precise triggering event varies by regime, so practitioners should identify the trigger under the governing instrument rather than assuming a fixed transaction-date rule.
Filing a report by the deadline is an accusation that establishes the customer's wrongdoing.
A suspicious transaction filing is a compliance disclosure reflecting suspicion; it does not establish that a crime has occurred and is not a criminal-law finding. Meeting the deadline satisfies a reporting obligation and should not be treated as proof of criminality.

Best practices

Identify the exact triggering event and prescribed filing period under each applicable regime in which the entity operates, and document these in internal procedures rather than relying on a generic timeframe; confirm precise values against the governing regulation.
Maintain a clear, timestamped internal escalation and decision-making trail from initial detection to the reporting decision, so the point at which suspicion was formed and the resulting deadline can be evidenced.
Distinguish operationally between report types (for example SAR versus STR) and route each to the correct FIU or competent authority using the required channel and format.
Where the regime links filing to prohibited-action or consent requirements (such as the UK POCA model), build controls that address both the timing obligation and any need to seek authorisation before proceeding, while observing tipping-off restrictions.
Set internal deadlines earlier than the regulatory maximum to allow time for quality review, and use monitoring or workflow tooling to flag approaching deadlines and prevent late submissions.
Periodically review procedures against current versions of the applicable instruments, since timing rules and terminology can change and vary across the jurisdictions in which the entity is an obliged entity.