The narrative is the free-text section of a Suspicious Activity Report, filed under 31 CFR 1020.320 and 31 CFR 1010.320, that explains what the structured fields mean and why the reported activity is suspicious. It is the section law enforcement reads first. A complete narrative answers five questions plainly (who, what, when, where, why) plus how, opens with a one-sentence summary of what was filed and why, and supports every claim with specific, chronological facts. A conclusory narrative, one asserting that the activity appeared suspicious with nothing behind the assertion, is a common source of examination findings.
A SAR narrative is the free-text section of a Suspicious Activity Report in which the filing institution states what the reported activity was and why the institution considers it suspicious. It is the one part of the report that cannot be reduced to a structured field, and it carries the institution's reasoning to any investigator or examiner who reads the filing later.
This guide covers the standard elements regulators expect, the anatomy of a complete narrative, a before-and-after example, the mistakes that draw scrutiny, and a checklist to run before filing.
What a SAR narrative is, and why it carries the filing
A Suspicious Activity Report, filed under 31 CFR 1020.320 for banks and 31 CFR 1010.320 more generally, has two halves. The structured fields record the facts a system can categorize: subjects, accounts, dates, dollar amounts, instrument types. The narrative is the free-text section that explains what those facts mean and why they're suspicious. FinCEN has been explicit for years that the narrative is the heart of the report. A thorough, accurate narrative is what makes a SAR useful to law enforcement, and a thin one can render an otherwise-complete filing useless.
The structured data records what happened while the narrative records why it matters. Examiners read narratives as evidence of whether a program reasons about risk or only produces filings.
The five W's and how
The durable standard, drawn from FinCEN's guidance on preparing complete and sufficient narratives, requires that the reader be able to answer six questions without leaving the page:
| Element | What it answers |
|---|---|
| Who | Who is conducting the activity? Subjects, their roles, account relationships, and any connected parties. |
| What | What instruments or mechanisms were used? Wires, ACH, cash, cards, crypto, and the dollar amounts. |
| When | When did the activity occur? The date range, and the sequence of events in order. |
| Where | Where did it happen? Branches, channels, counterparties, jurisdictions, and beneficiary locations. |
| Why | Why is it suspicious? The specific deviation from expected behavior or known typology. This is the crux of the filing. |
| How | How was the activity carried out? The method: structuring, rapid movement, pass-through, layering. |
The "why" is the element narratives most often leave underdeveloped. A description of the activity alone does not satisfy it: the narrative has to connect the activity to what made it suspicious, whether the KYC profile it contradicts, the typology it matches, or the pattern that has no business explanation.
Anatomy of a complete narrative
A narrative that reads well has a shape: a summary at the top, the facts in the middle, and a clear close. The conclusion comes first, because investigators triage hundreds of filings and decide in the first two sentences whether to keep reading.
| Part | Job |
|---|---|
| Introduction | One or two sentences: who the institution is, what type of activity is being reported, the total amount, and the period, with a plain statement that the institution is filing because the activity is suspicious. |
| Body | The chronological account. Specific dates, amounts, account numbers, counterparties, and, alongside the facts, the explanation of why each element is suspicious against the customer's known profile. |
| Conclusion | What the institution did (account actions, prior filings on the same subject), whether activity is continuing, and any information available on request. Law-enforcement contact is noted only where applicable. |
A before-and-after example
Specificity and a stated reason for suspicion are what separate the two versions below.
"The customer conducted several large transactions that appeared suspicious. The activity was inconsistent with normal account behavior. A SAR is being filed."
"Between March 3 and March 19, 2026, the customer received nine incoming wires totaling $487,000 from three unrelated entities in two jurisdictions, then moved 96% of the funds out via same-day outgoing wires to a single beneficiary. The account, opened as a sole-proprietor consulting business with stated monthly revenue under $20,000, shows no prior activity at this scale and no apparent business rationale for the pass-through pattern."
The strong version names dates, amounts, counterparties, the pattern of rapid pass-through, and the specific reason it is suspicious, namely that it contradicts the stated KYC profile. It is actionable as written, whereas the weak version requires the investigator to return with follow-up questions.
The mistakes that draw scrutiny
- Conclusory statements. "The activity was suspicious" asserts the conclusion without the facts that support it; the facts have to be stated and left to carry the conclusion.
- Missing specifics. No dates, no amounts, no account identifiers. A vague narrative cannot be investigated, and it reads as a program that did not look closely.
- Unexplained jargon and internal codes. Alert IDs, model scores, and internal shorthand carry no meaning for an outside reader and are translated into plain language.
- No stated reason for suspicion. The activity is described but never tied to the profile, typology, or pattern that triggered the filing.
- Boilerplate that does not match the facts. Copy-pasted templates carrying language from a different case indicate that the narrative was not written for this filing.
- Placing the reason for filing last. The reason for the filing appears in the closing paragraph rather than the first sentence.
A pre-filing checklist
The items below are confirmed before a SAR leaves the queue:
- The first sentence states what is being filed and why.
- All five W's and the "how" are answered without the reader leaving the page.
- Every claim is backed by a specific date, amount, account, or counterparty.
- The narrative explains why the activity is suspicious, tied to the KYC profile or a known typology.
- It reads chronologically and a stranger could follow it cold.
- Internal jargon, alert codes, and model scores are translated into plain language.
- Dollar amounts in the narrative reconcile with the structured fields.
- It states what the institution did and whether activity is continuing.
- No boilerplate from a different matter survived the draft.
- A qualified human has reviewed and owns the final narrative.
The standard is not stylistic. The objective is a record a busy investigator can act on and a future examiner can read as evidence that the institution's program reasons: that someone looked closely and explained what they found.