An examiner asks your team to walk through why it didn't file a SAR on a particular customer. The answer is easy when the analyst who made the call still works there and remembers the account. It gets harder when that analyst has left, or when two people on the same team would have explained it two different ways.
The same test runs through the closed alerts an examiner pulls. Alert closing and SAR filing are separate calls at different points in the work, and examiners look at both to judge how reliable the whole program is.
What are examiners testing when they ask about a SAR decision?
The process behind the call. The FFIEC BSA/AML exam manual says the decision to file a SAR "is an inherently subjective judgment" and tells examiners to focus on whether the bank has an effective SAR decision process. Examiners may still review single decisions to test that process.[1]
That process has three parts an examiner can check. Does the reasoning trace to your written policy? Is it applied the same way across analysts? Can your team pull it up and explain it when asked?
Following your own process protects you. The manual covers a bank that has a set decision process, follows its policies, and decides not to file. That bank shouldn't be criticized for the choice unless the failure is significant or comes with evidence of bad faith.[1] We look at what judgment calls mean for AI tools in when the rule calls for judgment, the AI should say so.
Do you have to document a decision not to file?
It's your choice under the BSA. In October 2025, FinCEN, the Federal Reserve, the FDIC, the NCUA, and the OCC issued joint FAQs on SARs. The FAQs say the BSA and its rules do not require an institution to document a decision not to file. If you do, a "short, concise statement" will likely suffice in most cases.[2]
The FFIEC manual still says banks should document SAR decisions, including the reason for not filing.[1] The FAQs are the newer word on that point. Your own procedures still count, though. The exam procedures ask whether your policies cover writing down decisions not to file, and examiners check whether you followed your own policies.[3]
When is a SAR due?
A bank must file a SAR within 30 calendar days after it first detects facts that may be grounds for filing. If no suspect has been identified, the bank may take up to 30 more calendar days to identify one. Filing can never come later than 60 calendar days after first detection.[4]
For violations that need fast action, such as an ongoing money laundering scheme, the bank must also call law enforcement right away. The same rule has banks keep each SAR and its supporting documents for five years from filing. It treats those documents as filed with the SAR.[4]
Why do two analysts close the same alert differently?
They work from different versions of how your bank reads its own policy. Both may have taken the same BSA training and know the same FinCEN guidance. The gap is the unwritten layer: how your bank handles edge cases, certain customer types, and the gray middle that written procedures cover only in general terms.
Say a senior BSA officer once told a new analyst that the bank treats cash deposits just under the reporting line differently for seasonal farm accounts. That guidance never reached the written policy. It was passed along in conversation, heard differently by different people, and applied differently ever since.
The October 2025 FAQs make that kind of local rule matter more. They say cash near the $10,000 currency reporting line is not, by itself, enough to require a SAR. The duty to file comes when the bank knows, suspects, or has reason to suspect the activity was designed to evade reporting.[2] If your procedures turn that into rules for certain customer types, those rules belong in the written policy, where every analyst can find them.
Case systems record what was decided, and the narrative frames the outcome. The path to it often stays in the analyst's head: which policy language applied, which past cases looked similar, and how mixed signals were weighed. Examiners who read your case files are looking for that path.
What do examiners find when they sample closed alerts?
Patterns in how your team thinks. Under the FFIEC exam procedures, examiners may map out how the bank monitors, researches, and reports suspicious activity, then follow an alert through the whole process. In transaction testing, they sample accounts based on risk, audit findings, and past exams, and review the monitoring reports and decisions not to file for them.[3]
A sample of closed alerts tests three things at once. Is your monitoring tuned well? Do analysts apply written procedures the same way? Does the reasoning behind each closing hold up when someone outside the bank rebuilds it? When two analysts face the same alert profile and one closes it with a thin note while the other escalates it, a side-by-side sample shows the gap.
Can you explain why your thresholds are set where they are?
You should be able to. Management "should document and be able to explain filtering criteria, thresholds used, and how both are appropriate for the bank's risks," says the FFIEC manual. It should also review and test them from time to time. Changes to monitoring profiles should go through a defined approval, generally by the BSA officer or senior management.[1]
Tuning rationale builds up over years. It covers threshold changes made after the last exam, rule changes that fit your customer base, and why one business type gets different settings than another. It ends up spread across exam workpapers, committee minutes, email threads from the last model validation, and the memory of whoever led the tuning work. When that person leaves, the reasons behind your current settings get harder to rebuild and harder to defend.
Examiners also check that alert volume follows risk. The exam procedures say "the volume of system alerts and investigations should not be tailored solely to meet existing staffing levels," and they have examiners check that staff can keep up with alerts.[3] A tuning memo that explains each change in terms of risk answers that question before anyone asks it.
What does a traceable BSA decision look like?
One your team can show on demand. It names the version of the policy the analyst applied. It shows that similar profiles got similar treatment under your current written guidance. And it gives the same answer to "why" today or eighteen months from now, which takes more than a record of the outcome.
Keep the reasoning current, searchable, and grounded in your own documents. Staff may already use AI tools to research questions and draft narratives. The test is whether those tools answer from your policy, procedures, and past decisions, or from general training data. Those two sources give different answers once an examiner starts asking.
Where does AI help, and what has to be in place first?
AI helps when it answers from your own documents. An analyst asking how your policy treats structuring for business accounts with uneven cash cycles needs your bank's approved standard. A summary of public guidance is useful background, and it is a different thing from the standard your bank approved.
That means putting your BSA policy, procedures, SAR narrative library, tuning memos, committee minutes, and model validation reports in one place the tool can search. With Lumen, the private AI platform from Cognetryx, answers cite the source. Clicking a citation opens the document with the passage highlighted, so the analyst, and later the QA reviewer, sees the exact policy words behind a call.
SARs are confidential, which makes permissions a hard requirement. The rule bars a bank and its staff from disclosing a SAR or any information that would reveal one.[4] Lumen answers follow each person's existing permissions through SSO over SAML or OIDC. Someone who can't open the SAR files gets answers that draw on none of them. We cover how that works in permission-aware AI.
The Compliance Portal logs chats and sign-ins, and your compliance team can search it. That gives QA a record of what analysts asked and what they were told. It all runs on your own servers.
The goal is decisions that trace back to the same written guidance, applied the same way, by anyone who opens the case.
See a cited answer from your own BSA policy
Every answer links to the passage it came from, and chats are logged for your compliance team.
See it in actionSources
- FFIEC BSA/AML Examination Manual, Suspicious Activity Reporting, Overview. See the parts on monitoring systems, managing alerts, and SAR decision making. bsaaml.ffiec.gov
- FinCEN, Federal Reserve, FDIC, NCUA, and OCC, Frequently Asked Questions Regarding Suspicious Activity Reporting Requirements, October 9, 2025, Questions 1 and 4. fincen.gov
- FFIEC BSA/AML Examination Manual, Suspicious Activity Reporting, Examination Procedures. See the parts on managing alerts, SAR decision making, and transaction testing. bsaaml.ffiec.gov
- 31 CFR 1020.320, Reports by banks of suspicious transactions. Paragraph (b)(3) sets filing times, (d) sets record keeping, and (e) sets confidentiality. law.cornell.edu
This article is informational and not legal or compliance advice. Confirm how any rule applies to your institution with your own counsel and BSA officer.