Suspicious activity vs suspicious transaction
Suspicious activity and suspicious transaction describe two overlapping but distinct reporting concepts, and the difference is more than naming. A suspicious transaction report is anchored to a completed transaction; a suspicious activity report can cover behaviour, attempted transactions, or a relationship pattern even without one. Most of the time the terms get used interchangeably, which is exactly where the confusion starts.
Key takeaways
- A suspicious transaction report needs a completed transaction; a suspicious activity report can cover behaviour or attempts without one.
- FATF Recommendation 20 sets the international baseline that most STR-terminology countries built their law around.
- The US uses SAR terminology under the Bank Secrecy Act, filing with FinCEN using Form 111.
- The UK uses SAR terminology too, despite following the same FATF standard that produced STR elsewhere, a reminder that naming doesn’t reliably signal scope.
- Monitoring systems need calibrating to whichever model actually applies locally, not treated as one global rule set.
- The 2024 TD Bank case, over $3 billion in combined penalties, shows the real cost of a monitoring gap in this area.
On this page
What each term actually coversWhy the same underlying obligation has two namesThe US SAR modelThe FATF STR model most other countries followWhere the UK sits in this splitWhy the distinction matters for transaction monitoring designA real case that shows what gets missedWhat this means for a global compliance programmeFAQsRead more
$5,000 / $2,000
US SAR filing thresholds for most banks vs money services businesses
Source: Bank Secrecy Act / FinCEN
$3bn+
Combined FinCEN/DOJ penalty against TD Bank in 2024 for suspicious transaction monitoring failures
What each term actually covers
A suspicious transaction report is tied to a transaction that actually happened. The filing has to identify the specific transaction and explain what made it suspicious; the trigger is the transaction itself. A suspicious activity report has broader scope: it can cover behaviour, a pattern across a relationship, or even an attempted transaction that never completed, without needing one specific transaction to point to.
In practice, this means an activity-based regime can catch things a purely transaction-based one would miss: someone probing account limits without ever moving money, for instance, or a pattern of behaviour that only becomes suspicious once you see it across several interactions rather than one.
Why the same underlying obligation has two names
The reason there are two names for what’s functionally the same underlying obligation, tell your financial intelligence unit when something looks wrong, comes down to which standard a country built its reporting regime around. FATF’s Recommendation 20 sets the international baseline, requiring financial institutions to report suspicious transactions to their national FIU. Most countries that built their AML law directly around FATF’s standard adopted STR as the formal term.
The United States went a different route. Its reporting obligation grew out of the Bank Secrecy Act rather than being drafted straight from FATF’s language, and it settled on “activity” rather than “transaction” as the defining word.
The US SAR model
Under the US Bank Secrecy Act, financial institutions file SARs with FinCEN using FinCEN Form 111. Thresholds vary by institution type: $5,000 for most depository institutions, $2,000 for money services businesses. Because the obligation is activity-based, a SAR can be filed over a pattern of conduct or an attempted transaction, not only a completed one.
FinCEN’s own SAR Stats database tracks filing volumes by institution type, activity category, and geography, giving a rare public window into how many of these reports actually get filed and for what reasons across the US financial system.
The FATF STR model most other countries follow
Most other jurisdictions built their reporting obligation directly around FATF Recommendation 20’s language and call the resulting document a suspicious transaction report. India is a clear example: STRs are filed under the Prevention of Money Laundering Act 2002 with FIU-IND, using that exact terminology in law. The EU’s Anti-Money Laundering Directives and many Asian jurisdictions follow the same pattern.
FATF itself doesn’t mandate a specific threshold or form. Recommendation 20 sets the principle, report promptly when there are reasonable grounds to suspect proceeds of crime or terrorist financing, and leaves the mechanics of implementation to each country.
Where the UK sits in this split
The UK sits in an interesting middle position. It uses the term SAR, filed with the National Crime Agency under POCA and the Terrorism Act, following US-style terminology. But UK law was still shaped by the same FATF standard as STR-based jurisdictions, and in practice UK guidance treats the obligation broadly enough to cover suspicious activity, not strictly a completed transaction.
That’s a useful reminder that the name a jurisdiction uses doesn’t reliably tell you the actual scope of what needs reporting. Firms operating across borders need to check the substance of each jurisdiction’s obligation, not assume from the label alone.
Why the distinction matters for transaction monitoring design
This distinction has a direct, practical consequence for how transaction monitoring gets built. A system designed around US SAR logic generates activity-based alerts, patterns, behaviours, attempted actions, that don’t map cleanly onto a strictly transaction-anchored STR threshold used elsewhere. Applying one global rule set built for one model to a jurisdiction that uses the other risks either over-reporting or under-reporting relative to what local law actually expects.
Firms running programmes across multiple countries need alert logic and escalation workflows calibrated to whichever standard actually applies in each jurisdiction, rather than assuming SAR and STR are close enough to treat as one global rule set.
A real case that shows what gets missed
The 2024 settlement between TD Bank and US authorities is a useful illustration of what falling short on this obligation actually costs. FinCEN and the Department of Justice found the bank had failed to identify and act on a substantial volume of suspicious transactions over several years, resulting in a combined penalty exceeding $3 billion, roughly $1.3 billion to FinCEN and $1.8 billion to the Department of Justice.
The case is a reminder that the distinction between activity-based and transaction-based reporting isn’t just academic. A monitoring programme calibrated too narrowly, catching only obvious individual transactions and missing the broader pattern of activity around them, can leave exactly the kind of gap regulators are now willing to penalise at this scale.
What this means for a global compliance programme
For a global compliance programme, the practical takeaway is to treat SAR and STR as functionally related but not interchangeable when it comes to actually building controls. What counts as reportable, what threshold applies, and whether an uncompleted or attempted action needs reporting all depend on which model a given jurisdiction actually follows, not on which term happens to appear in the local regulation’s title.
Calibrate monitoring to local reporting rules
Check which suspicious activity or transaction standard actually applies before tuning alert logic.
Frequently asked questions
What is the difference between a suspicious activity report and a suspicious transaction report?
A suspicious transaction report is anchored to a completed transaction and must identify what made that specific transaction suspicious. A suspicious activity report has broader scope, covering behaviour, patterns, or attempted transactions even without one completed transaction to point to.
Why do different countries use different terms for the same obligation?
It depends on which standard a country built its reporting regime around. Countries that drafted their law directly from FATF Recommendation 20 tend to use “suspicious transaction report.” The US, whose obligation grew from the Bank Secrecy Act, uses “suspicious activity report” instead.
What does the UK call its suspicious reporting obligation?
The UK uses the term SAR, filed with the National Crime Agency, following US-style naming, even though its law was shaped by the same FATF standard that produced STR terminology elsewhere.
Does FATF require a specific SAR or STR threshold?
No. FATF Recommendation 20 sets the principle that suspicious transactions must be reported promptly to the national financial intelligence unit, but leaves specific thresholds and forms to each country to implement.
Why does the SAR vs STR distinction matter for transaction monitoring?
A monitoring system built around activity-based SAR logic generates different kinds of alerts than one built around transaction-anchored STR logic. Applying one model’s rule set in a jurisdiction that follows the other risks over- or under-reporting relative to what local law expects.
What happened in the TD Bank case?
In 2024, US authorities found TD Bank had failed to identify and act on a substantial volume of suspicious transactions, resulting in a combined penalty of more than $3 billion between FinCEN and the Department of Justice.
Can an attempted transaction be reportable even if it never completes?
Under an activity-based regime like the US SAR model, yes. Under a strictly transaction-anchored regime, the legal trigger is the completed transaction itself, so an uncompleted attempt may fall outside the formal reporting requirement depending on how the local law is written.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 9 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Suspicious activity and suspicious transaction describe two overlapping but distinct reporting concepts, and the difference is more than naming. A suspicious transaction report is anchored to a completed transaction; a suspicious activity report can cover behaviour, attempted transactions, or a relationship pattern even without one. Most of the time the terms get used interchangeably, which is exactly where the confusion starts.