A crypto transaction monitoring alert can begin a complex investigation. Analysts may need to review wallets, customer records, transaction histories, IP addresses and blockchain exposure before deciding whether a Suspicious Activity Report is required.
However, the investigation cannot remain open indefinitely. Covered money services businesses must understand when the FinCEN SAR filing deadline begins and how to control the process.
Missing the deadline can create a regulatory problem even when the investigation and final SAR are otherwise accurate.
What Is the FinCEN SAR Filing Deadline for an MSB?
Under 31 CFR § 1022.320, a covered money services business must generally file a SAR no later than 30 calendar days after initially detecting facts that may form the basis for reporting.
The rule applies when a conducted or attempted transaction:
- Occurs by, at or through the MSB
- Involves or aggregates at least $2,000
- Meets one or more suspicious activity categories
For example, the activity may involve suspected illegal proceeds, structuring, an effort to evade Bank Secrecy Act requirements or the use of the MSB to facilitate crime.
The deadline uses calendar days rather than business days. Therefore, weekends and public holidays do not automatically extend the filing period.
The complete MSB requirement appears in 31 CFR § 1022.320.
Does the Clock Start When an Alert Is Generated?
Not necessarily.
An automated alert normally shows that a transaction requires review. It does not always establish that the activity is reportable.
For example, an alert may be generated because a customer used a new wallet, made a larger-than-normal withdrawal or had indirect exposure to a high-risk service. After investigation, the activity may have a reasonable explanation.
FinCEN guidance has explained that the filing period generally starts when the institution reaches the point where it knows or has reason to suspect that the activity meets a suspicious activity definition. Therefore, the clock does not automatically start whenever monitoring software generates an alert.
However, firms must not use this distinction to delay investigations. A large alert backlog or weak case allocation process can prevent reportable facts from being identified on time.
What Counts as Initial Detection?
Initial detection is the point at which the institution has identified facts that may constitute a basis for filing.
This may occur when an analyst confirms that:
- The transaction meets the applicable threshold
- Several related transactions form a suspicious pattern
- Wallet analysis identifies meaningful illicit exposure
- The customer’s explanation conflicts with verified evidence
- The activity has no reasonable lawful purpose
- The account appears to facilitate fraud or money laundering
- Several accounts are controlled by the same person or group
Initial detection should not depend entirely on the final approval date. If an investigator identifies reportable facts on May 5 but a committee approves the filing on May 18, the firm should not automatically treat May 18 as the start of the filing period.
Therefore, compliance procedures should define how the initial detection date is identified and recorded.
For a wider explanation of reporting thresholds and requirements, link to the complete Suspicious Activity Report FinCEN guide.
A Better Timeline for Crypto SAR Investigations
Crypto firms should use a controlled workflow that leaves enough time for investigation, drafting and quality assurance.
Day 1–5: Alert triage
The analyst should review the triggering activity, customer risk, transaction value and relevant wallet exposure.
Clearly non-suspicious alerts may be closed according to the firm’s procedures. Higher-risk cases should be escalated quickly.
Day 5–15: Investigation
The investigator may review:
- Customer KYC information
- Expected account activity
- Source-of-funds evidence
- Blockchain transaction flows
- Wallet addresses and clusters
- Transaction hashes
- Device and IP information
- Linked customer accounts
- Customer communications
The exact timeline will depend on the case. Nevertheless, firms should set internal service levels so cases do not remain unattended.
Day 15–22: Filing decision
The investigator or designated decision-maker should determine whether the activity meets the firm’s reporting criteria.
The decision should explain the facts, threshold, suspicious activity category and reason for filing or not filing.
Day 22–27: Drafting and review
The SAR narrative should be drafted and checked against the investigation records.
A reviewer should confirm that names, dates, amounts, wallet addresses and transaction hashes are accurate.
Before Day 30: Submission
The report should be validated, signed, saved and submitted through the BSA E-Filing System.
The filer should also confirm that the submission was accepted and later acknowledged.
Internal deadlines should normally fall before the regulatory deadline. This provides time to correct technical errors or missing information.
Attempted and Aggregated Transactions Still Matter
A transaction does not need to be completed before it becomes relevant to a SAR review.
For example, a customer may attempt to withdraw funds to a wallet linked to ransomware or a sanctioned service. Blocking the withdrawal does not automatically remove the need to consider suspicious activity reporting.
Likewise, analysts must consider related activity in aggregate. Ten suspicious transfers of $300 may collectively exceed the $2,000 MSB threshold.
Related transactions may be connected by:
- Customer identity
- Wallet ownership
- Device or IP address
- Funding source
- Transaction pattern
- Beneficiary
- Common scam or fraud indicators
Therefore, reviewing every transfer separately may cause an analyst to miss both the threshold and the wider suspicious pattern.
What If the Activity Requires Immediate Attention?
Some situations cannot wait for the standard filing process.
Under the MSB rule, violations requiring immediate attention—such as an active money laundering operation—must be reported to an appropriate law enforcement authority by telephone in addition to the timely SAR filing.
An urgent notification does not replace the SAR. Both actions may be required.
Firms should define which cases require urgent escalation and identify who has authority to contact law enforcement.
Common Deadline Mistakes
Treating the approval date as initial detection
The filing clock should not automatically begin when a committee approves the SAR. Reportable facts may have been detected earlier.
Waiting for proof of a crime
A SAR does not require proof beyond doubt. The reporting standard is based on knowledge, suspicion or reason to suspect.
Allowing cases to sit in queues
Unassigned alerts and delayed investigations can create late filings. Firms should monitor the age of every open case.
Forgetting weekends
The deadline is measured in calendar days. Internal systems should calculate the date correctly.
Ignoring attempted transactions
Blocked or rejected transactions can still require review.
Failing to track changes
Analysts should record when important evidence was discovered. Without a clear audit trail, the institution may struggle to defend its filing date.
Improve Your Crypto SAR Workflow
The Suspicious Activity Reporting (SAR) for Crypto Under FinCEN course explains how crypto alerts, investigations, documentation, escalation and reporting decisions connect within a FinCEN-focused SAR process.
It is suitable for AML analysts, SAR teams, transaction monitoring staff and crypto compliance professionals who want to strengthen their understanding of US reporting expectations.
Frequently Asked Questions
Is the FinCEN SAR deadline based on calendar days?
Yes. The MSB rule requires filing within 30 calendar days of initial detection.
Does every alert start the SAR clock?
No. An alert may only identify activity requiring review. However, firms must investigate promptly and record when facts supporting a filing are identified.
Can an MSB wait until its investigation is perfect?
No. The institution should conduct a reasonable investigation but must still meet the applicable deadline.
Does blocking a transaction remove the reporting obligation?
Not necessarily. Attempted transactions are included in the MSB reporting rule.
Can several smaller crypto transactions meet the threshold?
Yes. Related transactions or patterns may be aggregated when applying the $2,000 threshold.


