Skip to content
DELCOS Financial Infrastructure

No Rule Requires It: What an Alert Disposition Record Still Has to Contain

Practitioner NotesBy Philipp Shvedov14 min read

In October 2025 five US agencies answered the question directly: an institution does not have to document a decision not to file a SAR. Everything the record is used for survived the answer.

Monitor showing a closed transaction-monitoring alert beside a printed record of the review and closure decision.
A closed monitoring alert and its disposition record connect the decision to the evidence reviewed and the responsible investigator.DELCOS / Practitioner Notes

What the October 2025 answer removed

On 9 October 2025 FinCEN, the Federal Reserve, the FDIC, the NCUA and the OCC published joint FAQs on suspicious activity reporting. Question 4 asks whether a financial institution is required to document its decision not to file a SAR. The answer is no: there is no requirement or expectation under the BSA or its implementing regulations, FinCEN had previously encouraged the practice without requiring it, and where an institution chooses to document, a short and concise statement will in most cases suffice. Two neighbouring answers cut the same way, removing any expectation of a separate post-filing review to check whether activity continued, and confirming that currency activity at or near the $10,000 CTR threshold is not on its own sufficient to require a filing.

The FFIEC BSA/AML Examination Manual has not caught up. As at 7 September 2026 its Suspicious Activity Reporting section still states that banks should document SAR decisions including the specific reason for filing or not filing, while adding that no single form of documentation is required when a bank decides not to file. The same section carries a header directing examiners to the interagency FAQs of 19 January 2021 and 9 October 2025 and stating that the section is to be updated to reflect them. The most recent revision, on 27 February 2026, removed references to reputation risk to align the manual with Executive Order 14331 of 7 August 2025, and left the documentation text in place. The examiner opens the manual and the institution reads the FAQ, and both documents are current.

The record still starts the clock

A SAR is due no later than 30 calendar days after initial detection of facts that may constitute a basis for filing, extended to 60 days only where no suspect has been identified on the date of detection. The manual is explicit that initial detection is not the moment a transaction is highlighted for review: a system-generated report flagging activity does not start the period, which begins when an appropriate review has been conducted and the activity is determined to be suspicious within the meaning of the rule. The date the clock started is therefore a finding about a review, and the only place that finding exists is the review file: when the alert was assigned, when it was worked, when the determination was made.

The manual gives the key factor as adequate procedures for reviewing and assessing the facts identified as potentially suspicious, documented and followed. For alerts that end in a filing, the working papers are already a regulated record. Under 31 CFR 1020.320(d) a bank keeps the SAR and the original or business-record equivalent of supporting documentation for five years, that documentation is deemed to have been filed with the SAR, and it must be produced to FinCEN, law enforcement or the federal banking agency on request, with no legal process required. Supporting documentation means the records that assisted the bank in determining that the activity required a filing, which places the alert file in the same evidence regime as the rest of regulatory operations. What the October FAQs changed applies to one population only: the alerts that close.

What a disposition carries

A disposition is not a status on a queue. It is a dated statement of what was reviewed, which rule produced the alert, who decided, on what reasoning, and which escalation was available and not used. The escalation path, the investigation steps and the closure itself sit inside case management.

Investigators are to document their conclusions after research and analysis, including any recommendation on whether to file. Management is to establish a clear and defined escalation process running from the point of initial detection to the disposition of the investigation. The decision maker, individual or committee, must hold the authority to make the final filing decision, and a committee must have a defined way to resolve differences of opinion. Examination procedure 13 asks whether the decision process appropriately considers all available CDD and EDD information, which makes the customer information the reviewer actually looked at part of the record rather than context for it. Where the assessment is split across functions, AMLA’s draft guidelines require roles, responsibilities and independence safeguards to be defined in policy, an allocation question that belongs to compliance architecture.

FinCEN’s consent order against Canaccord Genuity LLC, issued in March 2026, records what the absence of those elements looks like. An assessment of the firm as of November 2023, cited in the order, found no written guidance or procedures for trade surveillance or transaction monitoring, no specific requirements covering reviews of potentially suspicious activity, investigation steps or supporting-documentation standards, and no quality assurance over the consistency and quality of investigations. The two people reviewing the firm’s principal reports documented their work inconsistently. The firm admitted the statement of facts. FinCEN imposed an $80 million civil money penalty, suspended $5 million pending an undertaking and credited $20 million paid to the SEC and $20 million paid to FINRA, leaving $35 million payable to Treasury.

AMLA’s draft guidelines on ongoing monitoring, published on 3 June 2026 under Article 26(5) of the AML Regulation, turn the same fields into a stated expectation. Obliged entities are to document the governance of monitoring and its decision-making so that it is traceable: what was assessed, what was decided, and the reasoning behind it. Paragraph 75 states the operative test. An entity must be able to explain, on request, how monitoring outputs were assessed, escalated and acted on, including the documented rationale for the decisions taken. The consultation closed on 3 September 2026, final guidelines are expected in Q4 2026, and the Regulation they sit under applies from 10 July 2027.

The escalation that was recorded and not performed

After a law enforcement request in July 2020 prompted additional due diligence, Canaccord filed a SAR on a Cayman Islands partnership and kept the account open under heightened supervision. An internal memorandum recorded what heightened supervision would consist of, namely reviews of the customer’s transactions, of email correspondence with the customer, and of negative news, and stated that the memorandum would be updated to reflect completion and any action taken. When the account closed in 2021, the updated memorandum listed dates and findings for the email and negative-news reviews. It contained no reference to any review of the customer’s transactions.

Staff investigating alerts were not required to search for prior alerts or investigations involving the same customer, so each alert was worked as though it were the first. Customer risk profiles were not updated after a customer appeared on an exception report or triggered an alert, so nothing the reviewer learned travelled back to the profile the monitoring was calibrated against. AMLA’s draft addresses the second gap directly, requiring monitoring outputs to be used to update customer due diligence information and risk classification, with the analysis performed and the rationale for the decision documented.

When a model closes the alert

The rules and thresholds that produce an alert are set inside transaction monitoring; what changes when software also closes the alert is the record of the closure. AMLA’s draft permits automated mechanisms to close monitoring outputs only for cases that, following automated analysis, show no suspicious or unusual activity and no other material ML/TF risk indicator, and excludes them where indicators of heightened risk are present or the situation calls for enhanced scrutiny. The underlying decision logic must be capable of being understood and documented, and the effectiveness of the mechanism must be subject to human oversight, including periodic validation through sampling and review of cases in which suspicious activity was not identified.

Three further paragraphs govern the configuration record rather than the case file. Default settings in externally developed tools are not to be used without a documented assessment of their appropriateness. Updates to detection logic and configuration are to be documented, tested and recorded, and communicated to the staff who operate or assess the framework. A material change to monitoring logic or analytical method triggers a documented transition and validation, and that validation has to go beyond comparison with the legacy output. Where a provider does not supply enough information for the entity to explain the tool’s role and outputs, the draft states that the entity should not rely on it for functions that materially influence monitoring outcomes, and responsibility for those decisions remains with the obliged entity.

FinCEN’s proposed AML/CFT program rule of 7 April 2026, on which comments closed on 9 June 2026, approaches the same technology without a documentation rule attached. It states that in deciding whether to pursue an enforcement or significant supervisory action the Director will consider, among other factors, whether the bank employs innovative tools such as artificial intelligence that demonstrate the effectiveness of its program. The precedent for machine-made filing decisions is older: OCC Interpretive Letter 1166 addressed a bank’s automated process for filing structuring SARs without individual manual review and conditioned it on risk governance around the process, not on a note in each case. The October 2025 FAQs cite that letter in a footnote to preserve the use of appropriately tailored automated monitoring.

The FCA’s second AI Live Testing cohort, announced in April 2026, includes anti-money laundering detection and KYC among its use cases and agentic models among the architectures under test. Testing began in late April 2026 and concludes at the end of the year, with an evaluation report due in the first quarter of 2027 and a good-and-poor-practice publication on AI expected earlier than that.

How this gets tested

Examiners may map the process a bank follows to monitor for, identify, research and report suspicious activity, and then follow one alert through the entire process. They verify that staffing is sufficient to review reports and alerts and to investigate items, and that the volume of system alerts and investigations is not tailored solely to meet existing staffing levels. They sample decisions not to file and assess three things about them: whether the decisions are supported and reasonable, whether the documentation is adequate, and whether the decision process is completed and filings made in time.

What protects a closure is the process, not the outcome. The manual instructs examiners to focus on whether the bank has an effective SAR decision-making process rather than on individual decisions, and to use individual decisions as a way of testing that process. Where a bank has an established decision-making process, has followed its existing policies, procedures and processes, and has determined not to file, the manual states it should not be criticised for the failure to file unless the failure is significant or accompanied by evidence of bad faith.

The failure the record catches is silence. In the March 2026 order, neither the BSA officer nor the head of trading compliance questioned, over several years, why trade surveillance reports had never led to a single escalation of potentially suspicious activity. Several of those reports were not reviewed at all, for stretches running from months to four years. The order finds that in multiple instances the reviewers set parameters it calls unreasonable, including to cut the volume of activity the reports captured, instead of working on a risk basis, and it records that the employee responsible for one report conceded selecting a filter to manage the scope of the review, without regard for whether the firm was still reviewing the activity the report was designed to detect. When FINRA requested evidence of the reviews, one compliance employee falsified nearly 400 documents, which the order describes as creating a false impression that the assigned reviews were being performed.

Arrangements to identify, monitor and address any accumulation of pending monitoring outputs are required by AMLA’s draft, which also states that effectiveness is not to be assessed solely by reference to alert or reporting volumes, or to the breadth of typology coverage, where these do not produce meaningful detection or escalation outcomes.

FinCEN’s April 2026 proposal splits program deficiencies in two, distinguishing failures of design, which it calls establishment, from failures of execution, which it calls maintenance, and would generally reserve enforcement and significant supervisory action against a bank that has established its program for a significant or systemic failure to maintain it. Maintenance is the program run in practice, and at the level of one alert it leaves exactly one artifact.

Source register

  • FinCEN, Board of Governors of the Federal Reserve System, FDIC, NCUA, OCCFrequently Asked Questions Regarding Suspicious Activity Reporting Requirements, 9 October 2025. Supports: no requirement or expectation to document a decision not to file a SAR; sufficiency of a short, concise statement where an institution chooses to document; no required post-filing continuing-activity review; near-threshold currency activity is not itself a basis to file; footnote preserving the use of appropriately tailored automated monitoring.
  • FFIECBSA/AML Examination Manual, Suspicious Activity Reporting, core section, text as at 7 September 2026. Supports: banks should document SAR decisions with the specific reason for filing or not filing; no single form of documentation on a decision not to file; header stating the section is to be updated to reflect the 2021 and 2025 interagency FAQs; documentation of investigators’ conclusions and recommendations; escalation process from initial detection to disposition; authority of the decision maker and resolution of committee disagreement; meaning of initial detection and the start of the filing period; examiner focus on process rather than individual decisions, and the conditions under which a decision not to file is not criticised; five-year retention and production of supporting documentation.
  • FFIECBSA/AML Examination Manual, Suspicious Activity Reporting examination procedures, text as at 7 September 2026. Supports: following one alert through the entire process; staffing sufficiency and the prohibition on sizing alert volume to available staff; consideration of CDD and EDD information in the decision process (procedure 13); sampling of decisions not to file and assessment of support, documentation adequacy and timeliness.
  • FFIECBSA/AML Examination Manual change history log, 27 February 2026. Supports: the scope of the most recent revision, limited to removal of reputation risk references, consistent with Executive Order 14331 of 7 August 2025.
  • US Department of the Treasury, FinCEN31 CFR 1020.320, Reports by banks of suspicious transactions, current regulation text. Supports: 30-day filing deadline with a 60-day extension where no suspect is identified; five-year retention of the SAR and supporting documentation; supporting documentation deemed filed with the SAR.
  • FinCENConsent Order Imposing Civil Money Penalty No. 2026-01, Canaccord Genuity LLC, 6 March 2026, conduct period 2 March 2018 to 30 June 2024. Supports: third-party findings on absent written review procedures, investigation-step and supporting-documentation standards, and quality assurance; inconsistent documentation by report reviewers; the heightened-supervision memorandum and the review it does not record; investigators not required to search prior alerts; risk profiles not updated after alerts; reports unreviewed for months to four years; parameters the order calls unreasonable, set to cut captured volume rather than on a risk basis; absence of escalations never questioned; falsification of nearly 400 review documents in response to a FINRA request; penalty of $80 million with $5 million suspended and $20 million each credited to the SEC and FINRA, leaving $35 million payable to Treasury.
  • AMLAConsultation Paper: Draft Guidelines on ongoing monitoring of a business relationship under Article 26(5) of Regulation (EU) 2024/1624, 3 June 2026, consultation closed 3 September 2026, final guidelines expected Q4 2026. Supports: documentation of monitoring governance and decisions for traceability; the obligation to explain on request how outputs were assessed, escalated and acted on with documented rationale; conditions on automated closure of monitoring outputs; documented decision logic and human oversight through sampling and review of missed cases; documented assessment of default settings; documentation and testing of detection-logic changes; transition and validation on material change; limits on reliance where provider information is insufficient; retained responsibility for monitoring decisions; feedback of outputs into CDD and risk classification; arrangements for pending-output accumulation; effectiveness not measured by alert or reporting volume alone; defined roles and independence safeguards where assessment is split across functions.
  • European Parliament and CouncilRegulation (EU) 2024/1624 (AMLR), Article 90. Supports: application of the Regulation from 10 July 2027.
  • FinCENFact Sheet: Proposed Rule to Fundamentally Reform Financial Institution AML/CFT Programs, NPRM of 7 April 2026, RIN 1506-AB72, comments closed 9 June 2026. Supports: the establishment and maintenance distinction and the significant-or-systemic threshold for action against a bank that has established its program; consideration of innovative tools including artificial intelligence in enforcement and supervisory decisions.
  • OCCInterpretive Letter 1166, 2019. Supports: automated filing of structuring SARs without individual manual review, conditioned on risk governance around the automated process.
  • FCAFCA announces second cohort for AI Live Testing, April 2026, and the AI Lab programme pages. Supports: inclusion of anti-money laundering detection and KYC use cases and agentic models; testing from late April 2026 to the end of 2026; evaluation report due in Q1 2027; good-and-poor-practice publication on AI expected during 2026.

· Practitioner Notes

All Insights