Skip to main content
Filing SARs 30 Days Late Cost One Bank $390 MillionAML and KYC
5 min readFor Bank Information Security Officers

Filing SARs 30 Days Late Cost One Bank $390 Million

Your AML reporting system might have a problem you don't know about yet. Many compliance teams discover this through enforcement actions.

The pattern is clear. Banks set up transaction monitoring systems, hire compliance officers, and establish SAR filing processes. They pass internal audits. Then regulators find thousands of missed reports, delays, or incomplete data trails. The fines follow.

These failures aren't random. They result from predictable implementation mistakes that technology alone can't fix. Here's what goes wrong and how your team can prevent it.

Why These Mistakes Keep Happening

AML reporting is complex, involving regulatory requirements, operational scale, and technology limits. The Bank Secrecy Act requires Suspicious Activity Reports within 30 days of detection. FINRA mandates firms verify customer identities, monitor transactions, and maintain records. Meanwhile, your transaction volume grows, and your monitoring rules multiply.

Most teams see this as a technology issue. They buy monitoring software, set alert rules, and assume compliance will follow. It doesn't. These mistakes happen because teams underestimate the discipline needed to turn alerts into filed reports on time.

Mistake 1: Treating Alert Volume as a Configuration Problem

Why it happens: Your system generates 10,000 alerts monthly, but your team can investigate only 3,000. The instinct is to adjust rules, raise thresholds, or add filters to manage the volume.

Real consequence: You're not reducing false positives; you're suppressing true positives. Capital One's $390 million penalty was partly due to failing to file thousands of SARs and Currency Transaction Reports on time. Tuning rules to match capacity rather than risk creates blind spots that regulators will find.

The fix: Work backward from your investigative capacity. If your team can handle 3,000 investigations monthly, you need more investigators or a risk-based triage system to prioritize alerts. Document your prioritization logic. When you suppress an alert category, document why that risk is acceptable and get sign-off from your AML Compliance Officer. Regulators want to see risk decisions, not just volume management.

Mistake 2: Separating Monitoring from Case Management

Why it happens: You use different vendors for transaction monitoring and case management, or you track investigations with spreadsheets. The systems don't share data, so analysts manually copy information.

Real consequence: You lose the audit trail proving you filed within 30 days of detection. When did your system first flag the activity? When did an analyst review it? If these timestamps are in different systems, you can't prove compliance. HSBC paid $85 million partly for failures in transaction monitoring systems related to AML processes.

The fix: Your monitoring and case management systems must share a unified timeline. Every alert, investigation step, escalation, and filing decision needs a timestamp in one system. If you're using separate tools, build an integration that synchronizes case status and timestamps. Your AML Compliance Officer should be able to pull a report showing days-to-resolution for every SAR filed in the past year.

Mistake 3: Assuming Customer Due Diligence Happens Once

Why it happens: You collect customer data at account opening, verify it, and file it away, thinking your CDD obligation is complete.

Real consequence: Customer risk profiles change. A low-risk customer might start receiving wire transfers from high-risk areas. Your system flags unusual activity, but analysts lack current customer context to make SAR decisions. You either file defensive SARs on legitimate activity or miss reportable transactions due to outdated risk assessments.

The fix: Build ongoing monitoring into your CDD process. Set triggers for CDD refresh: changes in transaction patterns, new product adoption, periodic reviews based on initial risk rating. FINRA requires ongoing monitoring to detect and report suspicious activities. Ensure analysts can see when a customer's CDD was last updated and if recent activity justifies a refresh before closing an alert.

Mistake 4: Underestimating the AML Compliance Officer's Operational Role

Why it happens: You designate an AML Compliance Officer as required, but treat the role as strategic: policy development, board reporting, regulatory liaison. Day-to-day SAR decisions happen at the analyst level.

Real consequence: SARs get filed inconsistently. One analyst files on structuring at $9,000, another dismisses it at $8,500. Your narrative quality varies. When regulators review your SAR filings, they see no coherent decision framework. Deutsche Bank paid $130 million for AML program failures, and NatWest paid £265 million for failing to prevent money laundering.

The fix: Your AML Compliance Officer must review every SAR before filing or delegate that authority with clear guidelines. Build a decision framework: what facts require a SAR, what facts make it discretionary, what additional investigation is needed. Document it. Train analysts on it. Your Compliance Officer should audit a sample of closed-without-filing cases monthly to verify consistent application.

Mistake 5: Filing Through the BSA E-Filing System Without Internal QA

Why it happens: SARs must be filed through the BSA E-Filing System or by submitting FinCEN Form 111. Analysts complete the form fields, attach a narrative, and submit. Once the system accepts the filing, you're compliant.

Real consequence: FinCEN accepts incomplete or inaccurate SARs, but regulators will find them. Missing subject information, vague narratives, incorrect reporting periods, or unchecked boxes undermine your program's effectiveness. You filed on time but didn't provide useful information to law enforcement.

The fix: Implement a pre-filing review checklist. Before any SAR enters the BSA E-Filing System, a second person verifies: all subject identification fields are complete, the narrative explains what happened and why it's suspicious, the activity types are checked correctly, supporting documentation is attached, and the 30-day timeline is met. This adds one day to your process but prevents quality failures that lead to penalties.

Prevention Checklist

Use this as a quarterly review with your AML Compliance Officer:

  • Alert-to-investigator ratio: Can your team investigate every alert within 10 business days? If not, document your prioritization methodology and get executive sign-off.

  • Unified timeline: Can you generate a report showing detection date, assignment date, investigation completion date, SAR decision date, and filing date for every case in the past 90 days from a single system?

  • CDD refresh triggers: Do you have documented rules for when customer due diligence must be updated based on transaction pattern changes?

  • SAR decision authority: Does your AML Compliance Officer review every SAR or delegate with written guidelines? Can you produce the delegation memo?

  • Pre-filing QA: Who performs the second review before SARs enter the BSA E-Filing System? Is there a checklist?

  • Closed-without-filing audit: Does your Compliance Officer review a sample of dismissed alerts monthly to verify decision consistency?

Technology helps catch patterns humans miss, but the mistakes leading to enforcement actions occur between alert generation and SAR filing. That's where your attention should be focused.

You Might Also Like