Blog guideUpdated 2026-05-1411 min readBy HubSecure Editorial TeamReviewed by workflow reviewers

Short summary

The detection is only half the job. A poorly written narrative makes a SAR unusable — and a useless SAR is a compliance failure, not a compliance success. This guide covers what the narrative must contain, how to structure it, and the mistakes that cause rejections.

  • What the workflow problem is.
  • What buyers should compare before choosing software.
  • How to move from research to workflow review.

How to Write a SAR Narrative: What FinCEN, FCA and EBA Actually Want to See

The detection is only half the job. A poorly written narrative makes a SAR unusable — and a useless SAR is a compliance failure, not a compliance success. This guide covers what the narrative must contain, how to structure it, and the mistakes that cause rejections.

Direct answer

How to Write a SAR Narrative: What FinCEN, FCA and EBA Actually Want to See: Most SAR rejections come down to the narrative — not the detection. A practical guide to writing a SAR narrative that meets FinCEN, FCA and EBA expectations.

HubSecure is relevant when teams need secure client records, document collection, workflow ownership, role-based access and audit-ready evidence in one governed workspace.

Written byHubSecure Editorial Team

Practical guides for compliance, AML, and regulatory filing.

Reviewed byHubSecure Security & Compliance Review

Reviewed for regulatory accuracy across FinCEN, FCA and EBA guidance.

Last updatedMay 13, 2026

Reflects current FinCEN SAR guidance (2023), FCA SAR guidance and EU AMLD requirements.

Filing a SAR is not a box-ticking exercise. A SAR that gets filed but is poorly written, vague, or internally inconsistent is worse than useless — it creates a record that you identified suspicious activity but failed to describe it clearly enough for a financial intelligence unit to act on.

The narrative section is where most SARs fail. It is also the section that no software tool can fully automate — because it requires a human analyst to synthesise information, draw reasonable conclusions, and describe behaviour in a way that reads as credible to an experienced investigator.

This guide explains what each major regulator looks for, how to structure a narrative that works, and the patterns that cause SARs to be returned or flagged as low quality.

Related HubSecure buying path

Compliance CRM guidecompliance CRM for growing companiesCRM moduleHubSpot comparisoncompliance CRM guideGuide Librarybook a workflow demo

Related HubSecure platform resources

Continue with HubSecure platform, secure client portal, compliance CRM, security and trust center, book a HubSecure demo.

Related use case

This guide belongs to the Workspace Alternatives and Tool Consolidation Guides cluster. Continue with the product hub for workspace alternatives and tool consolidation.

What a SAR narrative is actually for

A SAR narrative has one audience: a financial intelligence unit (FIU) analyst who may be reading dozens of SARs that day, looking for actionable intelligence about financial crime. They are not evaluating your compliance programme. They are trying to decide whether the activity you've described warrants investigation.

Write with that reader in mind. Your narrative should answer: what happened, why is it suspicious, who is involved, what money moved, and what do you think is going on?

Everything else — your internal ticket number, your onboarding date, your account reference — is supporting data. The narrative is the human-readable explanation that ties it together.

What FinCEN, FCA and EBA each require

FinCEN (United States)

FinCEN's SAR guidance requires narratives to include the "5 Ws and 1 H": who, what, when, where, why suspicious, and how conducted. Specifically:

FinCEN explicitly states that narratives should be written in plain English, in chronological order where possible, and should avoid abbreviations or internal jargon that the FIU analyst would not understand.

FCA (United Kingdom)

The UK's National Crime Agency (NCA), which receives SARs in the UK, and the FCA both look for narratives that are specific and evidence-based. The most common feedback on inadequate SARs is:

The FCA has also emphasised that a SAR should describe the filer's suspicion — not their certainty. You do not need to prove that a crime occurred. You need to explain why you suspect it might have.

EBA (European Union)

The EBA's joint guidelines on the characteristics of a risk-based approach to AML/CFT supervision (updated 2022) require that suspicious transaction reports contain sufficient detail to enable the FIU to assess whether the information may be relevant to a money laundering or terrorist financing investigation. This mirrors the FinCEN approach — specificity, chronology, and a clear statement of the basis for suspicion.

Key principle across all three: The narrative should describe the activity, not just the alert. "Our system flagged this transaction" is not a narrative. "The customer transferred €45,000 to an unrelated third party in a high-risk jurisdiction, inconsistent with their stated business as a domestic retail trader, two days after receiving the funds" — that is a narrative.

Structure: how to organise a SAR narrative

There is no mandatory structure, but this framework works well across jurisdictions and is consistent with FIU analyst expectations:

  1. Subject summary — who is the customer, what type of entity, when did the relationship start, what is their stated business or profile
  2. Description of suspicious activity — what happened, in chronological order. Specific dates, amounts, counterparties, transaction types. Not "multiple large transfers" — name the dates, the amounts, the recipients
  3. Why it is suspicious — the mismatch between the activity and the customer's known profile. This is the most important section. Be specific about what you expected and what you observed
  4. Aggravating factors — any additional risk indicators: PEP links, adverse media, high-risk jurisdictions, previous suspicious activity, unusual explanation offered by the customer
  5. Action taken — what your firm has done in response: account review, escalation, exit, restriction. Do not include details that could constitute tipping off

Example: weak vs strong narrative

Weak — do not use
Customer made several large transactions that appeared unusual. The transactions were inconsistent with the customer's profile and triggered our monitoring system. We were unable to obtain a satisfactory explanation from the customer. We are filing this SAR as a precaution.
Strong — this is what FIUs want to see
Subject: Meridian Trading Ltd, registered UK company (company no. 12345678), onboarded March 2025 as a domestic wholesale food distributor. Expected transaction profile: regular supplier payments within the UK, monthly receipts from UK retail clients, average monthly turnover £80,000.

On 4 April 2026, the account received an inbound transfer of £340,000 from an entity named Talbot Capital SRL, registered in Romania (unknown beneficial owner). No prior transactions with this counterparty. The transfer was not consistent with the customer's stated business activity.

Between 5–7 April 2026, three outbound transfers totalling £335,000 were made to accounts in Lithuania, Cyprus, and UAE respectively. The customer was contacted by telephone on 9 April 2026 and stated the transfers were for "import orders" but could not name the suppliers or provide any supporting documentation.

The pattern — a large inbound transfer from an unfamiliar source, immediately broken into multiple outbound transfers to different high-risk jurisdictions, with no supporting documentation — is consistent with layering activity. The customer's explanation was not credible given their stated business profile.

We have restricted the account pending this filing and do not intend to continue the business relationship.

Common mistakes that weaken a SAR

1. Describing the alert, not the activity

A SAR that says "our system generated an alert on this customer" tells the FIU nothing useful. They cannot act on a software flag. They can act on a description of what actually happened. Always translate the alert into human-readable behaviour.

2. Using internal terminology

References to your internal systems, code names, case numbers, or product codes are meaningless to an FIU analyst. Write as if the reader has no knowledge of your organisation or systems.

3. Hedging excessively

Phrases like "it is possible that", "we cannot rule out", or "this may potentially suggest" weaken the narrative. You are not required to be certain. You are required to explain why you are suspicious. State your suspicion clearly and support it with facts.

4. Omitting amounts, dates and counterparties

Vague narratives — "several large transfers to foreign accounts over a period of weeks" — are consistently flagged as inadequate. If you know the amounts, dates, and counterparty names, include them. If you don't know, say so explicitly.

5. Including tipping-off risk

Do not include information in the narrative that could alert the subject to the filing. Descriptions of investigation activity, account monitoring measures, or planned actions against the customer can constitute tipping off in some jurisdictions.

Timelines: when you must file

Filing deadlines vary by jurisdiction:

On CTRs vs SARs: A Currency Transaction Report (CTR) is a different filing — required for transactions above a threshold (e.g., $10,000 in the US), regardless of whether they are suspicious. CTR filing is largely automatic once the threshold is met. SAR filing is judgment-based and requires a narrative. Do not confuse the two obligations.

Can AI write my SAR narrative?
AI can draft a narrative based on the case data — and that draft can be a useful starting point. But a human analyst must review, correct, and sign off the final narrative. A SAR that has been AI-drafted and submitted without human review is a regulatory risk: if the narrative contains inaccuracies or mischaracterises the activity, the filer is responsible. Use AI to speed up the drafting process, not to replace the judgment that a quality narrative requires.
What happens if we file a SAR and nothing comes of it?
Nothing adverse. Regulators expect that many SARs will not result in investigations — the system only works if firms file when they have reasonable suspicion, not only when they are certain. The risk of not filing when you should have is far greater than the risk of filing when nothing comes of it.
Does filing a SAR discharge our AML obligations for that customer?
No. Filing a SAR is a reporting obligation — it does not resolve the underlying risk. You must still decide what to do with the customer relationship, whether to continue transactions, and whether the risk can be managed. In many cases, a SAR filing leads to an exit of the relationship — but that is a separate decision from the filing itself.

SAR filing — without leaving your compliance workflow

HubSecure Sentinel includes a guided SAR workflow with case evidence, narrative drafting, filing deadlines, and a complete audit trail. Your team focuses on the judgement; Sentinel handles the documentation.

Start free trial → See it in action
Free for 14 days

File with confidence.

Sentinel keeps your evidence, tracks your deadlines, and supports the narrative — so every SAR you file is defensible.

No credit card · Singapore-hosted · GDPR-aligned · ISO 27001-ready controls

Next useful pages

Continue the workflow evaluation

These links connect this page to the most relevant buyer, migration, template and signup paths.

secure client portalsecure document collectioncompliance crm for growing companiesmodules / sentinelguides
Canonical hubs

Source-of-truth pages for this topic

These hub pages tell buyers and search engines how this page fits into the wider HubSecure information architecture.

Recommended next step

Continue the evaluation path

The next page should move the buyer from information to comparison, workflow review, template use or private rollout readiness.