SAR Filing

SAR Filing Best Practices for UK Payment Firms

SAR Filing Best Practices for UK Payment Firms

Filing a Suspicious Activity Report is one of the most consequential acts a compliance team performs. It initiates a process that may result in law enforcement investigation, asset restraint, or prosecution. It also carries legal weight: a SAR filed in time provides the reporting institution with a statutory defence against the money laundering offences in the Proceeds of Crime Act 2002. A SAR filed late — or not filed at all when one was required — does not.

For MLROs at UK payment processors and challenger banks, the SAR process is also one of the most visible indicators of compliance programme quality during FCA supervisory review. The regulator examines SAR volumes, timeliness, investigation quality, and the completeness of the audit trail around each filing decision. This guide covers the end-to-end SAR lifecycle and the standards that distinguish a well-run SAR programme from one that creates regulatory risk.

The Legal Framework

The obligation to file a SAR in the UK derives primarily from the Proceeds of Crime Act 2002 (POCA). Under POCA s.330, a person in the regulated sector commits an offence if they know or suspect — or have reasonable grounds for knowing or suspecting — that another person is engaged in money laundering, and they fail to disclose that information to the National Crime Agency as soon as practicable. The same section creates the defence for those who do make a timely disclosure.

POCA s.336 provides the "consent SAR" mechanism: where a reporting institution wishes to complete a transaction that it suspects may constitute money laundering, it may file a SAR and seek consent from the NCA before proceeding. The NCA has seven days from the day after receipt of the SAR to refuse consent; if no refusal is received within that period, the institution may proceed. The "moratorium period" — if the NCA does refuse — extends the holding period to 31 days from the day of refusal.

In practice, most payment firm SARs are "disclosure SARs" rather than "consent SARs" — they are filed after the transaction has completed, to discharge the reporting obligation. Consent SARs are used where the firm suspects ongoing money laundering and needs to decide whether to continue a customer relationship or complete a specific transaction.

What Triggers a SAR Obligation

The statutory trigger — knowledge or suspicion, or reasonable grounds to know or suspect — is intentionally broad. POCA does not require certainty, and it does not require proof of criminality. Suspicion in the context of money laundering means something more than mere curiosity or unease, but something considerably less than proof on the balance of probabilities.

The MLR 2017 and the JMLSG Guidance flesh out what "reasonable grounds" means in practice. Relevant indicators include: transactions that are inconsistent with the customer's stated business purpose; unusual transaction structures (for example, structured deposits just below the cash reporting threshold); customers who are evasive about the source of funds or who provide documentation that cannot be verified; and transactions involving counterparties in high-risk jurisdictions without an obvious legitimate business explanation.

Transaction monitoring systems — whether automated or manual — are the primary detection mechanism for most payment firms. An alert from the transaction monitoring system is not itself a SAR trigger; it is the investigation of that alert that determines whether a SAR obligation arises. The distinction matters: the FCA has found firms where all alerts were being filed as SARs without adequate investigation, and firms where alerts were being cleared without documentation of why the investigation did not identify suspicious activity. Both represent inadequate SAR processes.

The SAR Lifecycle: Stage by Stage

Stage 1: Alert Generation

The SAR process begins when a transaction monitoring alert is generated, or when information is received through another channel — customer due diligence review, staff referral, or third-party notification. The alert should be logged with its source, the rule or scenario that generated it, and the transaction data on which it is based.

Stage 2: Triage

Not every alert warrants full investigation. Triage — the initial assessment of whether an alert warrants detailed review — should be documented and should involve a suitably qualified person. The triage decision should record why the alert was prioritised for investigation or cleared at triage, with specific reference to the transaction data.

The FCA has criticised firms where triage was effectively a checklist exercise with no documented reasoning. Particularly where alerts are being cleared at volume, the documentation standard for triage decisions must be sufficient to demonstrate that a genuine assessment took place.

Stage 3: Investigation

Where an alert passes triage, the investigation stage involves examining the customer's full transaction history, CDD records, risk assessment, and any previous SAR activity. The purpose is to assess whether the transaction or pattern is consistent with a plausible legitimate explanation, and whether a suspicious activity reporting obligation has arisen.

Good investigation documentation records: the specific transaction(s) under review; the customer's historical transaction pattern; the CDD information reviewed (including source of funds); the analysis of whether the transaction is consistent with the customer's profile; and the conclusion — either that no suspicion arises, that a SAR should be filed, or that further information should be sought before a decision is made.

Stage 4: MLRO Decision

Under the MLR 2017 and POCA, the decision to file or not file a SAR must be made by the nominated officer — in most firms, the MLRO. The nominated officer may not delegate this decision, though they may seek input from others. The MLRO's decision must be documented, with a specific record of the information considered and the reasoning applied.

Where the MLRO decides not to file, the documentation must be sufficient to demonstrate that the decision was based on adequate investigation rather than inadequate review. This is the documentation that the FCA will examine most closely if a subsequent enforcement investigation reveals financial crime activity that the firm's monitoring had detected.

Stage 5: Filing

SARs must be submitted through the NCA's SARs Online system. The NCA provides detailed guidance on the information that should be included in a SAR, including the category of suspect activity, identifying information for the subjects of the SAR, financial information, and supporting narrative.

The narrative section is where SAR quality most visibly varies. The NCA has been explicit that SARs with vague narratives — "unusual transaction pattern identified" without further specificity — add limited intelligence value and are less likely to be actioned. A good SAR narrative should include: the specific conduct or transaction that gave rise to suspicion; the typology it represents; the parties involved; the time period and transaction values; any steps taken to verify the activity; and, where relevant, the reason why the consent process was or was not used.

Stage 6: Post-Filing Record-Keeping

The firm must retain a complete record of the SAR and the supporting investigation for at least five years from the date of filing. MLR 2017 Regulation 40 sets out the record-keeping requirements. The retention record should include the original alert, the investigation notes, the MLRO's decision documentation, a copy of the SAR as submitted, and the NCA's receipt confirmation.

Where the firm has sought consent under POCA s.336, the record must also include the date of the consent request, the NCA's response (or the expiry of the seven-day period without response), and any moratorium period correspondence.

Timing: The Most Common Compliance Gap

The phrase "as soon as practicable" in POCA s.330 is not defined. The FCA's supervisory practice is to examine the elapsed time between alert generation and SAR filing as an indicator of whether the obligation is being discharged promptly. Where delays extend to weeks or months, the FCA will ask for explanation. Valid explanations include genuine investigative complexity requiring third-party information; explanations that amount to queue management — the alert sat uninvestigated because of analyst capacity constraints — are treated as evidence of inadequate systems and controls.

Payment firms operating at scale should have documented SLA targets for the alert triage and investigation cycle, with escalation procedures where cases cannot be resolved within the target window. The target itself is a compliance decision that should reflect the nature of the firm's transaction types and risk profile — but it should exist and be actively monitored.

Tipping-Off and Information Sharing

Once a SAR has been filed, POCA s.333A creates an offence of tipping off: disclosing to the subject of the SAR (or to any other person) that a SAR has been filed or that an investigation is in progress. Payment firms must ensure that customer-facing staff, relationship managers, and anyone who might interact with a SAR subject is aware of the tipping-off prohibition and understands what it means in the context of routine customer communications.

The Proceeds of Crime Act 2002 (Business in the Regulated Sector and Supervisory Authorities) Order 2003 provides exemptions for information sharing between regulated entities within a group, and for sharing between firms to establish whether a joint SAR is appropriate. These exemptions require careful management and should be subject to documented procedures.

This article is published for informational purposes. RegSynq Ltd is not authorised or regulated by the Financial Conduct Authority. Nothing in this article constitutes legal advice. Firms should seek qualified legal counsel for advice specific to their regulatory obligations.