ACAMS Suspicious Activity Investigation 2 — Questions and Answers
Question 1: What are the key components of a well-documented SAR investigation file?
- Only the transaction data that triggered the alert and the SAR filing date
- Documentation of the alert trigger, research conducted (internal and external), timeline of suspicious activity, analysis of the activity, the filing decision rationale, and records of any law enforcement communications (Correct answer)
- Only the SAR filing confirmation number and the compliance officer's signature
- Customer identity documents only, with a brief notation that suspicious activity occurred
Correct answer: Documentation of the alert trigger, research conducted (internal and external), timeline of suspicious activity, analysis of the activity, the filing decision rationale, and records of any law enforcement communications
A complete SAR investigation file must document the entire investigation lifecycle: the triggering event, all research steps, the analytical findings, the SAR filing decision rationale, and all communications with law enforcement — providing a clear, defensible record.
A well-documented SAR investigation file should include: Alert documentation — what triggered the investigation (system alert, referral, law enforcement inquiry); Research log — all internal systems reviewed (transaction history, CDD file, prior SARs, relationship manager notes) and external sources searched (adverse media, public records, OFAC, FinCEN 314(a)); Activity description — clear narrative of the suspicious transaction pattern; Analysis — why the activity is suspicious and what ML typology it most resembles; SAR filing decision — rationale for filing or not filing, with supervisor approval; SAR supporting documentation — all evidence used to complete the SAR narrative; Timing — dates of initial detection, investigation steps, and filing (demonstrating compliance with 30/60 day requirement); and Law enforcement contacts — any 314(b) requests, subpoenas, or voluntary disclosures. Regulators review investigation file quality during examinations.
Question 2: What is the 'no tipping off' rule and how does it affect account management decisions after a SAR is filed?
- The rule prevents compliance staff from telling front-line employees about customer risk ratings
- Financial institutions cannot notify a customer that a SAR has been filed or is being considered about them, which means account closure decisions and customer communications must be managed carefully to avoid revealing SAR-related concerns (Correct answer)
- The rule prevents law enforcement from notifying suspects that they are under investigation
- Financial institutions must immediately close accounts for which a SAR has been filed
Correct answer: Financial institutions cannot notify a customer that a SAR has been filed or is being considered about them, which means account closure decisions and customer communications must be managed carefully to avoid revealing SAR-related concerns
The tipping off prohibition means institutions must handle any account management actions — including account closures, product restrictions, or customer inquiries — in ways that do not reveal or suggest that a SAR has been filed.
The tipping off prohibition (31 USC 5318(g)(2)) creates complex account management challenges: Account closure — cannot cite 'suspicious activity,' 'compliance concerns,' or reference to SAR as reasons for closure; must use generic language like 'business decision'; Exit of customer — front-line staff must not suggest AML concerns are involved; Response to subpoenas — when customers learn of law enforcement interest, institutions must carefully avoid confirming SAR filings; Internal communication — SAR information must be restricted on need-to-know basis to prevent inadvertent disclosure; Law enforcement coordination — if law enforcement requests account remain open, institution must maintain the relationship without revealing to the customer why. Institutions should have written procedures for these scenarios and provide specific training to staff who may interact with customers about whom SARs have been filed.
Question 3: What is the difference between a 'voluntary SAR' and a 'mandatory SAR'?
- Voluntary SARs are filed at the institution's discretion for any suspicious activity; mandatory SARs are required only for transactions over $10,000
- All SAR filings by covered financial institutions are mandatory when the filing threshold is met; 'voluntary' SARs refer to filings below the mandatory threshold or by non-covered entities filing on a discretionary basis (Correct answer)
- Voluntary SARs are filed with FinCEN; mandatory SARs are filed with the relevant bank regulator
- Mandatory SARs require law enforcement approval; voluntary SARs can be filed without review
Correct answer: All SAR filings by covered financial institutions are mandatory when the filing threshold is met; 'voluntary' SARs refer to filings below the mandatory threshold or by non-covered entities filing on a discretionary basis
Covered financial institutions are required to file SARs when the mandatory filing threshold and criteria are met. 'Voluntary' SARs are filed at an institution's discretion — either below the mandatory dollar threshold or by entities not legally required to file — as a good-faith disclosure of suspicious activity.
Under 31 CFR 1020.320, covered financial institutions (depository institutions) must file SARs when: they know, suspect, or have reason to suspect the transaction involves criminal funds, evasion of BSA requirements, or a transaction with no apparent lawful purpose; AND the transaction involves at least $5,000. Voluntary SARs may be filed: when transaction amounts fall below the $5,000 mandatory threshold but activity is still suspicious; by entities not covered by mandatory SAR requirements (some small businesses, individuals); to document activity that might be relevant to law enforcement even if below threshold. FinCEN accepts voluntary SARs through the BSA E-Filing System. Both mandatory and voluntary SARs receive the same Safe Harbor protection from civil liability under 31 USC 5318(g)(3). Voluntary SARs may be valuable for building patterns relevant to law enforcement investigations.
Question 4: What are 'transaction monitoring scenarios' (rules) and how are they developed?
- Fixed regulatory requirements mandating specific detection thresholds for all financial institutions
- Algorithmic rules or analytical models within a transaction monitoring system designed to detect specific suspicious activity patterns; developed based on regulatory guidance, known ML typologies, the institution's risk profile, and historical SAR data (Correct answer)
- Manual review procedures for investigating customer complaints about transaction errors
- Automated systems that automatically file SARs without human review based on transaction amounts
Correct answer: Algorithmic rules or analytical models within a transaction monitoring system designed to detect specific suspicious activity patterns; developed based on regulatory guidance, known ML typologies, the institution's risk profile, and historical SAR data
Transaction monitoring scenarios are detection rules or models designed to identify specific suspicious patterns — such as structuring, rapid fund movement, or unusual cash activity — developed based on the institution's business model, ML typologies, and regulatory guidance.
Transaction monitoring scenarios are typically developed through: Regulatory guidance — FFIEC examination manual, FinCEN advisories, SAR activity reviews identifying common typologies; Industry resources — CAMS study materials, ACAMS typologies, Wolfsberg guidance, FinCEN SAR data; Internal SAR analysis — reviewing prior SAR filings to identify patterns that should generate alerts; Risk assessment findings — scenarios targeting the institution's specific high-risk products, customers, and geographies; Emerging typologies — updates for new schemes (virtual currency, pandemic fraud, beneficial ownership evasion). Effective scenario management requires: regular tuning to reduce false positives; backtesting against known suspicious activity; annual review of threshold effectiveness; documentation of scenario rationale; and validation by qualified model risk management. Regulators review scenario adequacy as part of AML examinations.
Question 5: How should an institution handle a FinCEN 314(a) inquiry for a customer who has a current SAR investigation open?
- Immediately close the customer's account to avoid liability
- Respond to the 314(a) inquiry as required (confirm or deny the match), continue the internal investigation, and ensure confidentiality is maintained for both the SAR and the 314(a) response (Correct answer)
- Notify the customer that they have been identified in a law enforcement inquiry
- Halt the internal SAR investigation and wait for law enforcement to contact the institution directly
Correct answer: Respond to the 314(a) inquiry as required (confirm or deny the match), continue the internal investigation, and ensure confidentiality is maintained for both the SAR and the 314(a) response
Institutions must respond to 314(a) inquiries confirming or denying whether the named individual has current accounts or conducted transactions, while simultaneously maintaining confidentiality of both the SAR investigation and the 314(a) response — they are separate, confidential processes.
FinCEN's Section 314(a) program allows law enforcement to submit requests through FinCEN to all registered financial institutions to query their records for named individuals, entities, and accounts. When a 314(a) inquiry overlaps with an open SAR investigation: The institution must respond to the 314(a) within the required 14-day window (confirming or denying a match); The 314(a) response is separate from and does not substitute for a SAR filing; Both the 314(a) response and any existing SAR investigation must be kept confidential; Staff handling the 314(a) should be aware of the existing SAR investigation but not merge the two processes; The institution should continue its SAR investigation and file if warranted; and No disclosure should be made to the customer. The 314(a) match may provide additional context supporting the SAR investigation and may inform the decision to file a continuing activity SAR.
Question 6: What is 'alert disposition' in a transaction monitoring system and what documentation is required?
- The technical process of routing alerts to the correct compliance analyst
- The process of reviewing transaction monitoring alerts and documenting the outcome — either closing the alert with documented rationale or escalating to a full investigation — required to demonstrate the appropriateness of AML decisions to regulators (Correct answer)
- An automated system that closes alerts without human review if no prior SAR history exists
- The process of adjusting alert thresholds based on false positive rates
Correct answer: The process of reviewing transaction monitoring alerts and documenting the outcome — either closing the alert with documented rationale or escalating to a full investigation — required to demonstrate the appropriateness of AML decisions to regulators
Alert disposition is the analyst review of each transaction monitoring alert, resulting in either a documented close (with clear rationale why the activity is not suspicious) or escalation to a formal investigation. All dispositions must be documented to support regulatory examination.
Alert disposition processes should include: Analyst assignment — alerts distributed based on risk level, business line expertise, or workload balancing; Review steps — analyst reviews transaction details, customer profile, account history, and prior alert/SAR history; Documentation — clear, specific documentation of why the alert was closed (e.g., 'transaction consistent with customer's documented business activity as a retail merchant with regular large cash deposits') or why it was escalated (e.g., 'unusual wire transfers inconsistent with documented business profile, refer to Level 2 investigation'); Supervisor review — higher-risk dispositions may require supervisor approval; Metrics — alert volume, disposition rates, average completion time, and SAR conversion rates tracked for program effectiveness; Quality assurance — periodic sampling of closed alerts to verify disposition quality. Regulators expect to see alert dispositions that are timely, well-reasoned, and consistently applied.
What are the key components of a well-documented SAR investigation file?