Supporting documentation for a Suspicious Activity Report is every record that helped a financial institution decide the activity warranted a filing, and it carries four obligations that outlast the filing itself: identify it when the SAR is submitted, keep it confidential, retain it for five years, and hand it to law enforcement on request without waiting for a subpoena.
What Qualifies as Supporting Documentation
FinCEN defines the category broadly as “all documents or records that assisted a financial institution in making the determination that certain activity required a SAR filing.”1Financial Crimes Enforcement Network. Suspicious Activity Report Supporting Documentation The guidance lists transaction records, new account information, tape recordings, email messages, and correspondence as common examples. In practice this reaches wire transfer confirmations, processed check images, account statements showing unusual patterns, customer identification materials, and Know Your Customer profiles.
Internal records count too. Analyst notes, alerts generated by the automated monitoring system, and email threads between compliance staff are supporting documentation if they shaped the filing decision, regardless of whether the SAR narrative names them. FinCEN’s guidance is explicit on that point: a document qualifies even when the narrative does not identify it, so long as it assisted in the determination.1Financial Crimes Enforcement Network. Suspicious Activity Report Supporting Documentation Spreadsheets used to total transactions, adverse media reports that raised red flags, and surveillance footage all fall inside the definition when they played a role in the analysis.
Identifying Documentation at the Time of Filing
Supporting documentation must be identified when the SAR is filed, not reconstructed later. The narrative should reference the key documents that drove the filing. Filers can attach a single Excel file, up to one megabyte, to hold transaction records too numerous to describe in the narrative. Nothing else goes with the SAR. Everything else stays in the institution’s own files, tied to the SAR by internal records so it can be located later.
Waiting until a deadline is close to gather the evidence creates real risk. Compliance teams that assemble documentation after the fact tend to mislabel what qualifies, and monitoring data that was available when the analyst first opened the case may have been overwritten by the time someone tries to preserve it.
The Five-Year Retention Rule
Federal regulations require banks to keep a copy of every filed SAR and the original or business record equivalent of all supporting documentation for five years from the date of filing.2eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions The clock starts on the filing date, not the date of the suspicious activity. Supporting documentation retained under this rule is legally deemed to have been filed with the SAR itself, so these are not optional archives. The obligation survives account closures and customer departures.
Storage can be paper or electronic. Either format has to remain readable and retrievable through the entire five years. Technology upgrades cannot be allowed to strand old digital files in formats no one can open. When an examiner or agent asks for the records, a delay caused by a corrupted archive or an incompatible legacy system is indistinguishable from noncompliance.
Confidentiality and How It Shapes Storage
A SAR and any information revealing its existence are confidential. Institutions cannot disclose that a SAR has been filed, that one has not been filed, or share the SAR’s contents with the subject or any unauthorized party.3FFIEC BSA/AML. Suspicious Activity Reporting – Overview If subpoenaed to produce a SAR, the institution must decline and cite the confidentiality provisions in 31 CFR 1020.320(e) and 31 U.S.C. 5318(g)(2)(A)(i).
Supporting documentation sits in a different legal space than the SAR. FinCEN has stated that “SAR information does not include the underlying facts, transactions, and documents upon which a SAR is based.”4Federal Register. Confidentiality of Suspicious Activity Reports The underlying transaction records, account statements, and similar documents can be shared with another financial institution for a joint SAR filing or in certain employment reference contexts. The documents themselves are not SAR information, but sharing them in a way that reveals a SAR exists still violates the confidentiality rule. You can share a wire transfer record. You cannot share it with a note explaining that it was part of a SAR.
That distinction drives how the records get stored. FinCEN does not mandate a single method, but the guidance suggests segregating all SAR-related files in a dedicated folder or scanning and maintaining them in a separate data file.1Financial Crimes Enforcement Network. Suspicious Activity Report Supporting Documentation The point is to keep staff who do not need access from stumbling onto material that would tell them a SAR exists. Digital records typically need password protection, encryption, and access logging; physical documents belong in locked cabinets in restricted areas. Written procedures should say who can access the files, when, and how each access is tracked. Examiners can verify the five-year retention easily. An ad hoc storage approach with no documented access controls invites harder questions about whether confidentiality was actually maintained.
Producing Documentation to Law Enforcement
When FinCEN, a federal banking agency, or any federal, state, or local law enforcement agency requests SAR supporting documentation, the institution must produce it. No subpoena, court order, or other legal process is required.2eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions FinCEN’s guidance reinforces the rule, stating that supporting documentation must be provided “even in the absence of legal process.”1Financial Crimes Enforcement Network. Suspicious Activity Report Supporting Documentation
The exception is narrow. It reaches only records that qualify as supporting documentation under the Bank Secrecy Act. When law enforcement asks for customer financial records that go beyond that scope, the Right to Financial Privacy Act applies again, and the institution must follow its notice and challenge provisions unless another exception, such as a grand jury subpoena, is available.5Office of the Law Revision Counsel. 12 USC Ch. 35 – Right to Financial Privacy An overly broad production that sweeps in non-supporting records without proper legal process can expose the institution to RFPA liability; an overly narrow one can look like obstruction.
Before releasing anything, the institution should confirm that the requester actually works for FinCEN or an authorized law enforcement or supervisory agency. FinCEN recommends building verification into the BSA compliance program, whether by independently confirming employment through a field office or by reviewing credentials in person. Once the requester is verified, documents typically move by secure electronic transfer or encrypted physical media, and the institution should log the date, time, method, and recipient.
Safe Harbor for the Disclosure
Federal law provides broad immunity to institutions and their employees who report suspicious activity. Under 31 U.S.C. 5318(g)(3), an institution that makes a disclosure under the BSA, and any director, officer, employee, or agent who makes the disclosure or requires another to make it, cannot be held liable under any federal or state law, regulation, or private contract for the disclosure itself or for failing to notify the subject.6Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority The protection extends to voluntary disclosures of possible legal violations to any government agency, not only mandatory SAR filings.
Two limits are worth noting. The safe harbor does not block actions brought by a government agency to enforce its own laws, so a filing does not cure an underlying compliance program deficiency. And it covers the disclosure and the provision of supporting documentation; it does not shield claims unrelated to the disclosure, such as negligent handling of a customer account.
Penalties for Getting It Wrong
Failing to maintain supporting documentation, missing the five-year retention window, or breaching confidentiality creates both civil and criminal exposure. The civil tiers depend on intent and severity:
- Negligent violations: up to $500 per violation at the statutory base, adjusted for inflation to $1,430 as of 2025.7Federal Register. Financial Crimes Enforcement Network – Inflation Adjustment of Civil Monetary Penalties
- Pattern of negligent violations: up to $50,000 per violation at the statutory base, adjusted to $111,308.
- Willful violations: the greater of the transaction amount (up to $100,000) or $25,000 per violation at the statutory base, with adjusted amounts running from $71,545 to $286,184. For violations of section 5318(a)(2), a separate violation accrues each day the violation continues and at each office where it occurs.8Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties
The 2026 inflation adjustment was canceled, so the amounts published in January 2025 remain in effect.7Federal Register. Financial Crimes Enforcement Network – Inflation Adjustment of Civil Monetary Penalties
Criminal penalties apply on top of the civil scheme. A willful violation of BSA requirements can bring fines up to $250,000 and imprisonment up to five years. If the violation is part of a pattern of illegal activity involving more than $100,000 in a 12-month period, the maximums double to $500,000 and ten years. Unauthorized disclosure of a SAR carries the same $250,000 and five-year exposure. Convicted partners, directors, officers, or employees of a financial institution must also repay any bonus received during the calendar year of the violation or the year that follows.9Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties Civil penalties for tipping off can reach $100,000 per violation, and anti-money laundering program deficiencies that lead to a disclosure can run up to $25,000 per day.10Financial Crimes Enforcement Network. SAR Confidentiality Reminder for Internal and External Counsel of Financial Institutions