Skip to main content
Should You Write SAR Narratives for Analysts or Agents?AML and KYC
4 min readFor AML/KYC Compliance Officers

Should You Write SAR Narratives for Analysts or Agents?

The Question at Hand

When drafting a Suspicious Activity Report (SAR) narrative, you're addressing two audiences: your compliance team and law enforcement. Your compliance team needs to understand the triggers and evidence for filing, while law enforcement assesses if the activity warrants investigation. These groups have different backgrounds and needs.

The debate: Should you write primarily for your internal compliance function, using detailed, process-oriented language, or for external law enforcement, using streamlined, chronological language? This choice affects everything from your SAR templates to your analyst training.

The Case for Compliance-Focused Narratives

Some institutions argue that SAR narratives should first serve as internal compliance records. Your narrative documents the decision-making process that led to filing, showing examiners during a BSA/AML review that your team followed procedures, escalated appropriately, and had a solid basis for the SAR.

This approach prioritizes institutional protection. When FFIEC examiners review your SAR program, they look for consistency and completeness. A narrative referencing your specific monitoring rules, internal case numbers, and escalation protocols shows a controlled process. If questions arise about why you filed (or didn't file) on similar activity, you want that institutional context preserved.

Practically, your analysts understand your systems. They know what "Rule 47 alert" means, what threshold triggered the case, and which team reviewed it. Writing in that shared language is faster and reduces ambiguity during internal reviews.

The Case for Law Enforcement-Focused Narratives

The opposing view: A SAR narrative should support criminal investigation, not document your compliance process. FinCEN forwards SARs to law enforcement agencies that don't know your institution's internal procedures. An FBI agent reading your narrative doesn't know your monitoring rules, doesn't care about your case management workflow, and can't act on information buried in institutional shorthand.

This approach treats the SAR as an intelligence product. Your narrative should answer the five Ws clearly: What suspicious activity occurred? When did it happen? Who was involved? Where did the funds move? Why does this pattern suggest illicit activity? How did you detect it?

The source material advises avoiding internal jargon and acronyms to ensure clarity for law enforcement. A narrative that reads "Subject triggered Rule 47 (high-velocity structuring) with 12 CTR-exempt deposits across 3 branches" is less useful than "Subject made 12 cash deposits between $8,000 and $9,500 at three different branches over 10 days, each below the $10,000 Currency Transaction Report threshold."

Practically, law enforcement can't investigate what they can't understand. If your narrative requires institutional knowledge to interpret, its utility as an investigative tool is reduced.

Where Practitioners Actually Land

Most institutions compromise. They write the narrative body for external readers using plain language and chronological structure, then use the conclusion section to add institutional context. The conclusion summarizes amounts and time periods (external focus) but also notes internal actions taken, related SAR filings, and contact points for supporting documentation (internal focus).

This hybrid approach acknowledges that both audiences matter. Your compliance team needs enough detail to defend the filing decision during an examination. Law enforcement needs enough clarity to determine whether the activity warrants follow-up. The narrative structure taught in school (introduction, body, conclusion) naturally accommodates both: state the violation clearly up front, present the evidence chronologically in the middle, then add institutional follow-up in the conclusion.

Training is critical here. Your analysts need to recognize which terms are institution-specific. It's difficult to spot your own jargon when you use it daily. One test: Could someone outside your organization understand this sentence without asking for definitions? If not, rewrite it.

Our Take

Write for law enforcement, then add compliance context in the conclusion.

Here's why: The primary regulatory requirement is that you file when you detect suspicious activity. The narrative's job is to communicate that suspicion clearly enough that FinCEN and law enforcement can act on it. An internal compliance record that law enforcement can't use fails the core purpose of SAR reporting under the Bank Secrecy Act.

Your institution's internal documentation needs are real, but they're better served by your case management system, not by cluttering the SAR narrative with process details. Reference your internal case number in the conclusion if you need to link back to supporting materials, but don't make law enforcement wade through your escalation workflow to find out what the subject actually did.

The practical test: If an agent reads your narrative and still needs to call you to understand the suspicious activity, you've written a compliance memo instead of an intelligence report. Your conclusion should include contact information for follow-up, but the body should stand alone.

This doesn't mean you strip out all detail. Law enforcement needs specifics: dollar amounts, dates, account numbers, transaction descriptions, geographic patterns. What you strip out is institutional process language that doesn't advance the investigative narrative.

Train your analysts to write as if they're briefing someone outside your organization. Use the chronological structure. Answer the five Ws. Define any necessary financial terms in plain language. Then use the conclusion to note internal actions, related filings, and where examiners can find your supporting documentation.

You're not choosing between compliance and law enforcement. You're recognizing that a narrative written for clarity serves both audiences better than one optimized for internal process documentation.

You Might Also Like