August 03, 2026
15 min read

Suspicious Activity Report FinCEN: Complete Crypto Guide

Learn when crypto firms must file a Suspicious Activity Report with FinCEN. This guide explains the $2,000 MSB threshold, 30-day deadline, crypto red flags, blockchain investigation steps, SAR narratives, Form 111 filing and common compliance mistakes.

Ian Hart
Suspicious Activity Report FinCEN guide graphic featuring a dark blue background and a digital transaction-monitoring screen.

Crypto transactions move quickly across wallets, exchanges, blockchains, bridges, and decentralized platforms. Although blockchain records can improve traceability, they can also create complex investigations for compliance teams.

When activity suggests money laundering, fraud, sanctions evasion, structuring, ransomware, or another form of financial crime, a US-regulated crypto business may need to submit a Suspicious Activity Report to the Financial Crimes Enforcement Network.

However, filing a Suspicious Activity Report with FinCEN involves more than describing an unusual transaction. Compliance teams must determine whether the activity meets the reporting criteria, complete the report within the correct deadline, include useful blockchain information, and protect the confidentiality of the filing.

This guide explains how FinCEN SAR requirements apply to crypto businesses, including common thresholds, deadlines, investigation steps, red flags, narrative requirements, and filing mistakes.

Important: This article provides general educational information. It is not legal advice. A firm should assess its obligations based on its regulatory classification, products, customers, and operating model.

What Is a FinCEN Suspicious Activity Report?

A Suspicious Activity Report, normally called a SAR, is a confidential regulatory report submitted by certain financial institutions to FinCEN.

The purpose of a SAR is to notify authorities about transactions or attempted transactions that may involve illegal funds, efforts to evade Bank Secrecy Act requirements, activity without an apparent lawful purpose, or the use of a financial institution to facilitate crime.

A SAR is not a criminal accusation. Instead, it provides information that may help law enforcement identify patterns, connect related subjects, trace financial activity, and support investigations.

For crypto firms, a SAR may involve:

  • Money laundering through multiple wallets
  • Fraud or scam proceeds
  • Ransomware payments
  • Sanctions exposure
  • Darknet marketplace transactions
  • Use of mixers or tumblers
  • Unregistered peer-to-peer exchange activity
  • Account takeovers
  • Structuring
  • Mule accounts
  • Rapid cross-chain movement
  • Unusual crypto ATM activity

Nevertheless, one unusual transaction does not automatically justify a filing. FinCEN advises financial institutions to consider the complete context, including the customer’s history and whether several indicators appear together. FinCEN’s convertible virtual currency advisory specifically warns that a single crypto red flag is not necessarily evidence of illicit conduct.

Which Crypto Businesses May Have SAR Obligations?

FinCEN generally treats a person or business that accepts and transmits convertible virtual currency as a money transmitter when its activities meet the relevant regulatory definition.

Therefore, many centralized crypto exchanges, crypto payment providers, custodial platforms, and crypto ATM operators may qualify as money services businesses, or MSBs. These businesses may be required to register with FinCEN and comply with applicable AML, recordkeeping, monitoring, and suspicious activity reporting rules.

However, classification depends on the firm’s activities rather than the words it uses to describe itself. A business cannot avoid an obligation simply by calling itself a technology platform, marketplace, or software provider.

Likewise, not every person using or developing crypto technology is automatically an MSB. FinCEN distinguishes between users of virtual currency and businesses that operate as administrators, exchangers, or money transmitters. Firms should assess their specific business model using FinCEN’s guidance for convertible virtual currency businesses.

Additionally, a crypto business may have reporting obligations under another regulatory category. For example, a registered broker-dealer, bank, mutual fund, or futures business may be subject to different SAR thresholds and rules.

When Must a Crypto MSB File a SAR?

Under 31 CFR § 1022.320, a covered MSB must report a transaction or attempted transaction when it:

  • Is conducted by, at, or through the MSB
  • Involves or aggregates at least $2,000 in funds or other assets
  • Meets at least one category of suspicious activity

The MSB must know, suspect, or have reason to suspect that the activity:

  1. Involves funds derived from illegal activity or attempts to hide illegal proceeds.
  2. Is designed to evade Bank Secrecy Act requirements, including through structuring.
  3. Has no business or apparent lawful purpose and has no reasonable explanation after review.
  4. Uses the MSB to facilitate criminal activity.

These requirements apply to completed and attempted transactions. Therefore, rejecting or blocking a crypto transfer does not automatically remove the need to review whether the attempted activity was reportable.

The $2,000 threshold may also be met through a pattern of related transactions. Consequently, analysts should not examine every transfer in isolation. Several smaller transfers involving related wallets, accounts, devices, or customers may collectively meet the threshold.

The complete rule is available in 31 CFR § 1022.320.


What Is the FinCEN SAR Filing Deadline?

A covered money services business must generally file its SAR no later than 30 calendar days after initially detecting facts that may form the basis for a report.

The filing clock does not necessarily begin when an automated monitoring alert is generated. An alert may only indicate that the activity requires further review. Instead, the clock normally begins when the institution’s review reaches the point where it knows or has reason to suspect that the activity meets a SAR reporting category.

Nevertheless, firms should not use the investigation process to create avoidable delays. Case management systems should record:

  • Alert generation date
  • Investigation opening date
  • Date reportable facts were identified
  • Escalation date
  • Filing decision date
  • Quality assurance date
  • SAR submission date

For violations requiring immediate attention, such as an active money laundering scheme, the MSB must notify an appropriate law enforcement authority in addition to submitting the SAR on time. The MSB-specific filing timeline and emergency requirements appear in FinCEN’s current MSB regulation.

How to Investigate Suspicious Crypto Activity

A strong investigation connects customer information, account behavior, blockchain evidence, and transactional context.

Step 1: Review the original alert

First, determine why the transaction monitoring or wallet screening system created the alert. Identify the rule, risk score, blockchain exposure, transaction amount, and triggering event.

An alert is a starting point. It is not a SAR decision.

Step 2: Review the customer profile

Compare the activity with the customer’s:

  • Stated occupation or business
  • Expected transaction volume
  • Source of funds
  • Account age
  • Geographic location
  • Previous account behavior
  • Risk classification
  • KYC and enhanced due diligence records

For example, a customer who reported a modest annual income but suddenly receives large amounts of crypto from unrelated wallets may require further investigation.

Step 3: Analyze the blockchain activity

Use available blockchain analytics to examine:

  • Sending and receiving wallet addresses
  • Transaction hashes
  • Direct and indirect exposure
  • Wallet clusters
  • Transaction values and timestamps
  • Asset conversions
  • Cross-chain bridges
  • Mixers or tumblers
  • Darknet exposure
  • Scam or ransomware attribution
  • High-risk services and jurisdictions

However, analysts should understand the difference between direct and indirect exposure. A wallet with distant exposure to a risky service may not present the same risk as a direct transfer from a known illicit address.

Step 4: Review account and device information

Crypto investigations should also consider off-chain data, including:

  • IP addresses
  • Device identifiers
  • Login history
  • Email addresses
  • Phone numbers
  • Linked accounts
  • Beneficiary details
  • Payment cards
  • Bank accounts
  • Customer communications

This information may connect several apparently unrelated accounts or show that one person controls multiple identities.

Step 5: Request information when appropriate

Depending on the risk and the firm’s procedures, the analyst may request an explanation or supporting evidence from the customer.

The response should be tested against the available evidence. A customer’s explanation should not be accepted automatically, nor should a lack of response alone be treated as proof of a crime.

Step 6: Make and document the decision

The investigator should explain whether the activity meets the institution’s SAR criteria.

The decision should connect the facts to a reporting category. It should also distinguish verified information from analytical conclusions and unresolved concerns.


How to File FinCEN Form 111

FinCEN SARs are submitted electronically using FinCEN Form 111 through the BSA E-Filing System. FinCEN does not accept legacy paper reports. FinCEN’s filing information page provides access to the current form and filing system.

A standard filing process should include the following steps.

1. Collect the required information

Gather all known information about the subject, institution, suspicious activity, transaction amounts, dates, locations, products, and financial instruments.

Do not leave a field blank merely because the information requires additional internal research. However, do not guess when information is genuinely unknown.

2. Select the relevant activity categories

Choose every applicable suspicious activity category. Depending on the case, this may include money laundering, structuring, fraud, terrorist financing, or cyber-related activity.

Additionally, check whether FinCEN has published a current advisory term for the activity. FinCEN maintains an updated list of requested SAR advisory key terms.

3. Draft the SAR narrative

The narrative should explain the suspicious activity clearly and in chronological order. It should provide enough information for an investigator unfamiliar with the customer or platform to understand the concern.

4. Complete quality assurance

A reviewer should confirm that:

  • Names and identifying information are accurate
  • Amounts match the investigation records
  • Dates are consistent
  • Relevant activity categories are selected
  • The narrative matches the structured fields
  • Wallet addresses and hashes are copied correctly
  • The filing does not contain unsupported conclusions

5. Validate, sign, save, and submit

For a discrete filing, FinCEN instructs filers to complete and validate the report, sign it using the assigned PIN, save a copy, and submit it through BSA E-Filing.

After submission, the filer should confirm that the report has been accepted and later acknowledged. FinCEN explains these steps in its SAR filing FAQs.

6. Retain the report and evidence

A covered MSB must retain a copy of the SAR and the original or business-record equivalent of supporting documentation for five years from the filing date.

Supporting evidence may include:

  • Transaction records
  • Blockchain analysis
  • Wallet screenshots
  • KYC documents
  • Customer communications
  • Device and IP records
  • Alert details
  • Investigation notes
  • Internal approvals

The BSA E-Filing System is not a permanent recordkeeping platform. Therefore, firms must securely save their own copies.

What Should a Crypto SAR Narrative Include?

A useful narrative answers six questions: who, what, when, where, why, and how.

For a crypto case, the narrative should normally identify:

  • The subject and relevant accounts
  • The date range of the activity
  • The total value involved
  • The cryptoassets used
  • Relevant wallet addresses
  • Transaction hashes
  • Originating and destination platforms
  • IP addresses or device information
  • The flow of funds
  • Relevant blockchain risk findings
  • The customer’s explanation
  • Why the activity is suspicious
  • Whether law enforcement was contacted
  • Where supporting documents are stored

FinCEN has specifically identified wallet addresses, account information, transaction hashes, originator and recipient details, transaction history, IP addresses, device information, and relevant online information as potentially valuable in crypto-related SARs.

The narrative should remain factual. Avoid vague statements such as “the customer appears suspicious.” Instead, explain the behavior that created the concern.

For example:

Between May 4 and May 9, the customer received $18,750 in USDT through 14 externally hosted wallets. The customer converted the funds to BTC within 20 minutes of receipt and transferred them to two addresses with direct exposure to a mixing service. This activity was inconsistent with the customer’s stated purpose and expected monthly activity.

Common Crypto Red Flags

Crypto compliance teams should watch for combinations of indicators rather than relying on one signal.

Common warning signs include:

  • Direct transactions with darknet-linked wallets
  • Use of Tor or unusual IP locations
  • Multiple rapid crypto conversions without an apparent purpose
  • Immediate withdrawal after a fiat or crypto deposit
  • Transfers involving mixers or obfuscation services
  • Links to ransomware, scams, hacks, or stolen funds
  • Multiple customers using the same device or wallet
  • Accounts receiving funds from many unrelated parties
  • Sudden activity inconsistent with the customer’s profile
  • Repeated transactions below internal or regulatory thresholds
  • Rapid movement through several blockchains or bridges
  • Use of forged or inconsistent KYC information
  • Large transactions unsupported by known income or wealth
  • Unusual crypto ATM deposits
  • Transactions involving high-risk or sanctioned services

Importantly, the use of a VPN, privacy tool, mixer, or bridge is not automatically criminal. The investigator must consider the broader facts and determine whether the combined activity creates a reasonable basis for suspicion.

Crypto SAR Case Study

Consider a customer who opens a retail exchange account and states that the account will be used for occasional personal investment.

Three weeks later, the account receives $24,000 in USDC from 18 wallets. The funds are converted into Bitcoin and withdrawn within minutes. Blockchain analysis identifies links to a fraud cluster and indirect exposure to a mixer.

Additionally, the customer logs in through several IP addresses, changes the registered phone number twice, and cannot explain the source of the funds.

The compliance team should:

  1. Review the customer’s KYC and expected activity.
  2. Map the incoming and outgoing wallet flows.
  3. Confirm the strength and distance of the fraud exposure.
  4. Review linked accounts, devices, bank details, and IP addresses.
  5. Record the customer’s explanation.
  6. Determine whether the pattern meets the SAR criteria.
  7. File within the applicable deadline if the decision is to report.
  8. Consider account restrictions separately under the firm’s risk policy.

The SAR decision should be based on the full pattern—not simply the use of multiple wallets or a mixer.

Common FinCEN SAR Filing Mistakes

Waiting for proof of a crime

A financial institution does not need to prove the underlying offense. The standard is whether it knows, suspects, or has reason to suspect that the activity meets a reporting category.

Ignoring attempted transactions

A rejected withdrawal, blocked transfer, or failed crypto purchase may still be reportable if it meets the applicable criteria.

Reviewing transactions individually

Several smaller transactions may form a related pattern and meet the $2,000 MSB threshold when aggregated.

Filing an unclear narrative

A narrative that merely repeats risk scores or alert names provides little value. Explain the actual transaction flow and the reason for concern.

Leaving out blockchain identifiers

Wallet addresses and transaction hashes can help investigators trace the funds. Copy them carefully and identify the relevant blockchain.

Treating an analytics score as conclusive

A blockchain risk score should support the investigation, not replace it. Analysts should review exposure type, attribution quality, transaction distance, timing, and customer context.

Missing the filing deadline

Firms should track the point at which reportable facts were detected. Delays caused by poor escalation or quality assurance controls can create compliance failures.

Disclosing the SAR

A SAR and information that would reveal its existence are confidential. Employees must not tell the customer that a SAR was filed or is being considered.

Failing to retain supporting evidence

A submitted SAR does not remove the need to preserve the report and its supporting documentation for the required five-year period.

Continuing Suspicious Activity: Important 2025 Clarification

FinCEN clarified in October 2025 that a financial institution is not required to conduct a separate manual or automated review of a customer after filing a SAR solely to determine whether the activity continued.

Instead, firms may use risk-based monitoring policies and controls that are reasonably designed to identify and report suspicious activity.

FinCEN also explained that the traditional continuing activity timeline is guidance rather than an absolute requirement. Institutions that choose to follow it may review a 90-day activity period and file the continuing SAR within the following 30 days. The initial and continuing SAR deadlines must still be managed according to the rules applying to the institution. The clarification appears in FinCEN’s October 2025 SAR FAQs.

Crypto SAR Compliance Checklist

Before closing a crypto SAR investigation, confirm that:

  • The institution’s regulatory classification is understood.
  • The correct reporting threshold has been applied.
  • Related transactions have been aggregated where appropriate.
  • Attempted transactions have been considered.
  • Customer and KYC information has been reviewed.
  • Wallet addresses and transaction hashes have been checked.
  • Direct and indirect exposure have been distinguished.
  • The customer’s activity has been compared with expected behavior.
  • The filing decision is based on documented facts.
  • The narrative follows a clear chronological structure.
  • Relevant FinCEN advisory terms have been considered.
  • The filing deadline has been recorded.
  • The report has been validated and acknowledged.
  • Supporting evidence will be retained for five years.
  • SAR confidentiality controls are in place.

Strengthen Your Crypto SAR Skills

Strong suspicious activity reporting requires more than knowing how to complete a form. Analysts must understand crypto transaction monitoring, wallet exposure, customer behavior, investigation records, escalation procedures, and narrative structure.

The Suspicious Activity Reporting (SAR) for Crypto Under FinCEN course from Crypto Compliance Academy helps AML analysts, SAR teams, compliance officers, and financial crime professionals build their understanding of crypto SAR investigations and US reporting expectations.

The self-paced course covers crypto red flags, scams, ransomware, mixers, bridges, high-risk wallets, transaction monitoring, investigation documentation, SAR narratives, confidentiality, and recordkeeping.

Frequently Asked Questions

What is a FinCEN Suspicious Activity Report?

A FinCEN Suspicious Activity Report is a confidential report used by certain financial institutions to notify FinCEN about known or suspected suspicious transactions.

What is the SAR threshold for a crypto MSB?

For a covered money services business, the general threshold is at least $2,000 in funds or other assets. Related transactions may be aggregated. Different thresholds can apply to other types of financial institutions.

How long does a crypto MSB have to file a SAR?

A covered MSB must generally file no later than 30 calendar days after initially detecting facts that may provide a basis for reporting.

Must a crypto firm prove money laundering before filing?

No. The firm does not need to prove a crime. It must determine whether it knows, suspects, or has reason to suspect that the activity meets an applicable reporting category.

Can a crypto firm file below the $2,000 threshold?

Yes. An MSB may voluntarily report suspicious activity that it considers relevant to a possible legal or regulatory violation even when mandatory reporting criteria are not met.

Should wallet addresses and transaction hashes be included?

Yes, when available and relevant. These identifiers can help investigators trace crypto transactions and connect related activity.

Can a customer be told that a SAR was filed?

No. A SAR and information that would reveal its existence are confidential. Customer communications should not disclose or imply that a SAR has been prepared, considered, or filed.

How long must SAR records be retained?

A covered MSB must generally retain the SAR and its supporting documentation for five years from the filing date.

Does filing a SAR mean the customer’s account must be closed?

Not automatically. The SAR decision and the customer relationship decision are separate. Account restrictions or closure should be considered under the firm’s risk-based policies and the facts of the case.