August 21, 2026
6 min read

What Happens After Filing a FinCEN SAR?

Learn what crypto firms must do after filing a FinCEN SAR. This guide covers five-year record retention, supporting evidence, filing acknowledgments, confidentiality controls, corrected reports and FinCEN’s updated continuing activity guidance.

Ian Hart
What Happens After Filing a FinCEN SAR?

Submitting a Suspicious Activity Report is not the end of the compliance process.

After filing, a crypto money services business must preserve the report, secure its supporting evidence, protect its confidentiality, and remain prepared to provide records to an authorized agency.

The firm may also need to correct inaccurate information or respond when monitoring identifies further suspicious activity.

This guide explains the main steps crypto compliance teams should take after filing a SAR with FinCEN.

Confirm That the SAR Was Accepted

A filer should not assume that clicking the submit button completed the process.

After a discrete SAR is submitted through the BSA E-Filing System, the filer should receive confirmation that the report was accepted. The filing should later move to an acknowledged status and receive an official BSA identification number.

Compliance teams should retain:

  • Submission confirmation
  • Tracking information
  • Filing date and time
  • Filing owner
  • BSA identification number
  • Acknowledgment record
  • Any technical error messages
  • Evidence of corrected submissions

If the confirmation screen does not appear, the submission may not have been accepted.

FinCEN’s SAR filing FAQs explain how filers can check whether a discrete filing was submitted successfully.

Save a Copy Before Submission

The BSA E-Filing System is not a permanent recordkeeping system. FinCEN does not provide filers with copies of previously submitted reports.

Therefore, the institution must save its own copy securely.

FinCEN recommends saving the filing before submission. The filer may also print a copy if permitted by the institution’s security and retention procedures.

The report should not be stored on:

  • Personal devices
  • Public computers
  • Unapproved cloud storage
  • Shared folders with broad access
  • Email accounts without appropriate protection

Instead, SAR records should be held within a controlled case management or document storage environment.

How Long Must an MSB Retain a SAR?

A covered money services business must retain a copy of the SAR and the original or business-record equivalent of supporting documentation for five years from the filing date.

This requirement appears in 31 CFR § 1022.320.

The five-year period begins on the date the SAR was filed, not the date the alert was generated or the investigation began.

A retention schedule should also account for corrected, amended and continuing reports. Each filing should be connected to the appropriate case and earlier BSA identification number.

For a wider explanation of the reporting process, link to the complete FinCEN SAR guide for crypto firms.

What Counts as Supporting Documentation?

Supporting documentation includes records used to investigate the activity and reach the filing decision.

For a crypto SAR, this may include:

  • Customer KYC records
  • Enhanced due diligence findings
  • Transaction monitoring alerts
  • Fiat transaction records
  • Crypto transaction histories
  • Wallet addresses
  • Transaction hashes
  • Blockchain analytics reports
  • Wallet-clustering analysis
  • Screenshots or exported evidence
  • IP addresses and device data
  • Customer communications
  • Source-of-funds documents
  • Internal investigation notes
  • Escalation and approval records
  • Law enforcement contact information

FinCEN explains that supporting documentation is considered to have been filed with the SAR even though the records are normally retained by the financial institution.

The institution must make that documentation available when requested by FinCEN or an appropriate law enforcement, regulatory or supervisory authority. FinCEN’s guidance on SAR supporting documentation explains this obligation.

Protect SAR Confidentiality

A SAR and any information that would reveal its existence are confidential.

MSBs and their employees must not tell a customer or transaction participant that:

  • A SAR has been filed
  • A SAR is being prepared
  • The institution is considering a SAR
  • A regulator requested SAR documentation
  • A continuing SAR has been submitted

This restriction is often called the prohibition against tipping off.

However, confidentiality does not prevent employees from discussing the underlying facts when necessary for an authorized investigation. Staff may ask a customer about the source of funds or purpose of a transaction, provided the communication does not reveal or imply the existence of a SAR.

FinCEN’s MSB suspicious activity reporting guidance confirms both the five-year retention requirement and the prohibition on disclosing a filing to a person involved in the transaction.

Limit Internal Access

SAR access should follow a strict need-to-know principle.

Authorized users may include:

  • SAR investigators
  • AML compliance officers
  • Designated quality assurance staff
  • Senior compliance decision-makers
  • Legal advisers
  • Internal audit teams where appropriate
  • Authorized regulatory or law enforcement contacts

Customer support, sales, marketing and general operations staff do not normally need access to the report itself.

Systems should record who viewed, downloaded, changed or shared a SAR file. In addition, firms should restrict printing and external transfer.

Training is equally important. An employee may understand that the document is confidential but still disclose its existence by writing an inappropriate customer account note.

What If the Filed SAR Contains an Error?

A filer may discover that a previously submitted report contains incorrect or incomplete information.

Depending on the circumstances, the institution may need to submit a corrected or amended SAR.

FinCEN instructs filers to:

  1. Select the corrected or amended report option.
  2. Enter the previous document control number or BSA ID.
  3. Complete the report in full.
  4. Explain the correction at the beginning of the narrative.
  5. Save and submit the revised filing.

The corrected report receives a new BSA ID. Therefore, institutions should preserve the relationship between both filings in the case record.

What About Continuing Suspicious Activity?

FinCEN clarified its approach to continuing suspicious activity in October 2025.

A financial institution is not required to conduct a separate manual or automated review after every SAR solely to determine whether the activity continued.

Instead, the institution may rely on risk-based monitoring policies, procedures and controls that are reasonably designed to identify further suspicious activity.

FinCEN also clarified that the traditional continuing activity timeline is guidance rather than an absolute requirement. Institutions may file according to the timelines applicable to newly detected reportable activity.

Where an institution chooses to follow the traditional model, the timeline may include:

  • Day 0: Initial detection
  • Day 30: Initial SAR filing
  • Day 120: End of the following 90-day activity period
  • Day 150: Continuing activity SAR filing

The updated position appears in FinCEN’s October 2025 SAR FAQs.

Post-Filing Checklist

After filing a SAR, confirm that:

  • The report was accepted and acknowledged.
  • A secure copy was retained.
  • The BSA ID was recorded.
  • Supporting evidence was preserved.
  • A five-year retention date was applied.
  • Access was restricted.
  • Confidentiality controls were followed.
  • Relevant monitoring remained active.
  • Any errors were escalated.
  • Corrected or continuing filings were linked to the original case.

Strengthen Your SAR Governance

The Suspicious Activity Reporting (SAR) for Crypto Under FinCEN course explains investigation documentation, SAR narratives, confidentiality, recordkeeping and governance expectations for crypto-related suspicious activity.

It is suitable for crypto compliance officers, AML analysts, SAR teams, transaction monitoring professionals and financial crime investigators.

Frequently Asked Questions

How long must a crypto MSB retain a SAR?

A covered MSB must generally retain the report and supporting documentation for five years from the filing date.

Can a customer be told that a SAR was filed?

No. A SAR and information revealing its existence are confidential.

Does FinCEN store a copy for the filer?

The BSA E-Filing System is not a recordkeeping platform. Firms must securely preserve their own copies.

Must supporting documents be attached to the SAR?

Supporting documents are generally retained by the institution and must be produced when requested by an authorized agency.

Is a separate continuing activity review always required?

No. FinCEN clarified in 2025 that institutions are not required to conduct a separate review solely to determine whether suspicious activity continued. Risk-based monitoring may be used.