Suspicious activity vs suspicious transaction

Suspicious activity vs suspicious transaction

Suspicious activity vs suspicious transaction

Suspicious activity and suspicious transaction describe two overlapping but distinct reporting concepts, and the difference is more than naming. A suspicious transaction report is anchored to a completed transaction; a suspicious activity report can cover behaviour, attempted transactions, or a relationship pattern even without one. Most of the time the terms get used interchangeably, which is exactly where the confusion starts.

Key takeaways

  • A suspicious transaction report needs a completed transaction; a suspicious activity report can cover behaviour or attempts without one.
  • FATF Recommendation 20 sets the international baseline that most STR-terminology countries built their law around.
  • The US uses SAR terminology under the Bank Secrecy Act, filing with FinCEN using Form 111.
  • The UK uses SAR terminology too, despite following the same FATF standard that produced STR elsewhere, a reminder that naming doesn’t reliably signal scope.
  • Monitoring systems need calibrating to whichever model actually applies locally, not treated as one global rule set.
  • The 2024 TD Bank case, over $3 billion in combined penalties, shows the real cost of a monitoring gap in this area.

$5,000 / $2,000

US SAR filing thresholds for most banks vs money services businesses

Source: Bank Secrecy Act / FinCEN

$3bn+

Combined FinCEN/DOJ penalty against TD Bank in 2024 for suspicious transaction monitoring failures

Source: FinCEN / US Department of Justice

What each term actually covers

A suspicious transaction report is tied to a transaction that actually happened. The filing has to identify the specific transaction and explain what made it suspicious; the trigger is the transaction itself. A suspicious activity report has broader scope: it can cover behaviour, a pattern across a relationship, or even an attempted transaction that never completed, without needing one specific transaction to point to.

In practice, this means an activity-based regime can catch things a purely transaction-based one would miss: someone probing account limits without ever moving money, for instance, or a pattern of behaviour that only becomes suspicious once you see it across several interactions rather than one.

Why the same underlying obligation has two names

The reason there are two names for what’s functionally the same underlying obligation, tell your financial intelligence unit when something looks wrong, comes down to which standard a country built its reporting regime around. FATF’s Recommendation 20 sets the international baseline, requiring financial institutions to report suspicious transactions to their national FIU. Most countries that built their AML law directly around FATF’s standard adopted STR as the formal term.

The United States went a different route. Its reporting obligation grew out of the Bank Secrecy Act rather than being drafted straight from FATF’s language, and it settled on “activity” rather than “transaction” as the defining word.

The US SAR model

Under the US Bank Secrecy Act, financial institutions file SARs with FinCEN using FinCEN Form 111. Thresholds vary by institution type: $5,000 for most depository institutions, $2,000 for money services businesses. Because the obligation is activity-based, a SAR can be filed over a pattern of conduct or an attempted transaction, not only a completed one.

FinCEN’s own SAR Stats database tracks filing volumes by institution type, activity category, and geography, giving a rare public window into how many of these reports actually get filed and for what reasons across the US financial system.

The FATF STR model most other countries follow

Most other jurisdictions built their reporting obligation directly around FATF Recommendation 20’s language and call the resulting document a suspicious transaction report. India is a clear example: STRs are filed under the Prevention of Money Laundering Act 2002 with FIU-IND, using that exact terminology in law. The EU’s Anti-Money Laundering Directives and many Asian jurisdictions follow the same pattern.

FATF itself doesn’t mandate a specific threshold or form. Recommendation 20 sets the principle, report promptly when there are reasonable grounds to suspect proceeds of crime or terrorist financing, and leaves the mechanics of implementation to each country.

Where the UK sits in this split

The UK sits in an interesting middle position. It uses the term SAR, filed with the National Crime Agency under POCA and the Terrorism Act, following US-style terminology. But UK law was still shaped by the same FATF standard as STR-based jurisdictions, and in practice UK guidance treats the obligation broadly enough to cover suspicious activity, not strictly a completed transaction.

That’s a useful reminder that the name a jurisdiction uses doesn’t reliably tell you the actual scope of what needs reporting. Firms operating across borders need to check the substance of each jurisdiction’s obligation, not assume from the label alone.

Worth knowing. The name a jurisdiction uses for this report doesn’t reliably tell you its actual scope. The UK calls its filing a SAR, following US-style naming, but the underlying obligation was shaped by the same FATF standard that produced STR terminology in most other countries.

Why the distinction matters for transaction monitoring design

This distinction has a direct, practical consequence for how transaction monitoring gets built. A system designed around US SAR logic generates activity-based alerts, patterns, behaviours, attempted actions, that don’t map cleanly onto a strictly transaction-anchored STR threshold used elsewhere. Applying one global rule set built for one model to a jurisdiction that uses the other risks either over-reporting or under-reporting relative to what local law actually expects.

Firms running programmes across multiple countries need alert logic and escalation workflows calibrated to whichever standard actually applies in each jurisdiction, rather than assuming SAR and STR are close enough to treat as one global rule set.

A real case that shows what gets missed

The 2024 settlement between TD Bank and US authorities is a useful illustration of what falling short on this obligation actually costs. FinCEN and the Department of Justice found the bank had failed to identify and act on a substantial volume of suspicious transactions over several years, resulting in a combined penalty exceeding $3 billion, roughly $1.3 billion to FinCEN and $1.8 billion to the Department of Justice.

The case is a reminder that the distinction between activity-based and transaction-based reporting isn’t just academic. A monitoring programme calibrated too narrowly, catching only obvious individual transactions and missing the broader pattern of activity around them, can leave exactly the kind of gap regulators are now willing to penalise at this scale.

What this means for a global compliance programme

For a global compliance programme, the practical takeaway is to treat SAR and STR as functionally related but not interchangeable when it comes to actually building controls. What counts as reportable, what threshold applies, and whether an uncompleted or attempted action needs reporting all depend on which model a given jurisdiction actually follows, not on which term happens to appear in the local regulation’s title.

Calibrate monitoring to local reporting rules

Check which suspicious activity or transaction standard actually applies before tuning alert logic.

Try the Country Risk Checker →

Frequently asked questions

What is the difference between a suspicious activity report and a suspicious transaction report?

A suspicious transaction report is anchored to a completed transaction and must identify what made that specific transaction suspicious. A suspicious activity report has broader scope, covering behaviour, patterns, or attempted transactions even without one completed transaction to point to.

Why do different countries use different terms for the same obligation?

It depends on which standard a country built its reporting regime around. Countries that drafted their law directly from FATF Recommendation 20 tend to use “suspicious transaction report.” The US, whose obligation grew from the Bank Secrecy Act, uses “suspicious activity report” instead.

What does the UK call its suspicious reporting obligation?

The UK uses the term SAR, filed with the National Crime Agency, following US-style naming, even though its law was shaped by the same FATF standard that produced STR terminology elsewhere.

Does FATF require a specific SAR or STR threshold?

No. FATF Recommendation 20 sets the principle that suspicious transactions must be reported promptly to the national financial intelligence unit, but leaves specific thresholds and forms to each country to implement.

Why does the SAR vs STR distinction matter for transaction monitoring?

A monitoring system built around activity-based SAR logic generates different kinds of alerts than one built around transaction-anchored STR logic. Applying one model’s rule set in a jurisdiction that follows the other risks over- or under-reporting relative to what local law expects.

What happened in the TD Bank case?

In 2024, US authorities found TD Bank had failed to identify and act on a substantial volume of suspicious transactions, resulting in a combined penalty of more than $3 billion between FinCEN and the Department of Justice.

Can an attempted transaction be reportable even if it never completes?

Under an activity-based regime like the US SAR model, yes. Under a strictly transaction-anchored regime, the legal trigger is the completed transaction itself, so an uncompleted attempt may fall outside the formal reporting requirement depending on how the local law is written.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 9 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Suspicious activity and suspicious transaction describe two overlapping but distinct reporting concepts, and the difference is more than naming. A suspicious transaction report is anchored to a completed transaction; a suspicious activity report can cover behaviour, attempted transactions, or a relationship pattern even without one. Most of the time the terms get used interchangeably, which is exactly where the confusion starts.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.