Writing a suspicious activity report an FIU can act on
A useful SAR or STR narrative answers who, what, when, where, why and how in one chronological account, explains why the activity is unusual for this customer, and gives facts an analyst can follow without opening your systems.

Charles Archibong, Co-founder
· 6 min read

Key takeaways
- Answer who, what, when, where, why and how, in date order, with individual amounts and dates.
- Explain why the activity is unusual for this customer; a rule name is not a reason.
- In Nigeria, the Money Laundering Act 2022 requires a written report with reasons within 24 hours of the transaction.
- Have a second person review every report before it is filed, and keep the evidence on your own file.
A suspicious activity report (SAR) or suspicious transaction report (STR) is useful to a financial intelligence unit (FIU) when its narrative lets an analyst understand the case without calling you. That means answering who, what, when, where, why and how, in date order, with individual transactions rather than totals, and explaining why the activity is unusual for this customer in particular.
A common failure is a report that states a conclusion without the facts behind it: "Customer engaged in suspicious transactions consistent with money laundering." An FIU analyst cannot use that sentence. They can use "Between 3 and 9 March 2026, 41 transfers from 37 different senders were received and 94% of the value left within 20 minutes to one account at another bank." (That figure is illustrative.)
Why does the narrative matter when the report already has structured fields?
Structured fields carry data: names, account numbers, amounts, dates. The narrative carries reasoning, and reasoning is what turns data into intelligence.
The goAML reporting format used by Nigeria's FIU shows the split clearly. Its schema guide (opens in a new tab) (schema 5.0.2, 28 October 2022) has structured nodes for transactions, parties and accounts, plus a free-text reason field ("why the report was reported, especially for STRs") and an action field describing action taken, each up to 4,000 characters. Report indicators are codes from an FIU-defined list. The indicators say what kind of case it is. The reason says why you believe it.
This article is general information, not legal advice, and reporting requirements differ by jurisdiction. Check your own FIU's guidance and your regulator's rules for format, content and deadlines.
What should the narrative contain?
The clearest public statement of the elements comes from the US FIU. FinCEN's Guidance on Preparing a Complete and Sufficient SAR Narrative (opens in a new tab) (November 2003) says a narrative should identify the "five essential elements of information" (who, what, when, where and why) and adds that the method of operation, or how, "is also important". It is written for US filers, but the elements travel well.
Element | What to include |
|---|---|
Who | The subject and every related party, with identifiers, occupation or business type, and known relationships between them |
What | The instruments and channels used: transfers, cards, wallets, cash, crypto |
When | When the activity started, when you noticed it, and how long it lasted |
Where | Branches, channels, other institutions and any foreign jurisdictions involved |
Why | Why the activity is unusual for this customer, compared with what they told you and with similar customers |
How | The method: how money moved, in what order, through which accounts |
FinCEN also asks filers to include "individual dates and amounts of transactions" rather than "just the aggregated amount", and not to write "see attached", because attachments may not be read with the narrative. Keep supporting documents on your own file and describe what you hold.
How should the narrative be organised?
FinCEN suggests three parts, and they work well for any FIU:
Introduction. One paragraph: what kind of activity you are reporting, any earlier reports on the same subject, your internal case reference, and a summary of the red flags.
Body. The facts in date order: the parties, the accounts, the transactions with dates and amounts, the relationships you observed, and anything the customer told you.
Conclusion. What you did next (restricted the account, exited the relationship, kept monitoring), what further information you can provide, and who to contact.
Write for a reader who has never seen your product. Explain internal terms once. "Wallet" and "virtual account" can mean different things at different institutions.
What does a usable narrative look like?
A fictitious, illustrative example for a consumer wallet in Nigeria:
Introduction. This STR concerns suspected use of a personal wallet as a pass-through account for funds from multiple unrelated senders. Internal investigation reference INV-0417. No previous report has been filed on this customer.
Body. The subject, a 23-year-old individual, opened a Tier 3 wallet on 14 January 2026 and declared the purpose as "personal savings" and occupation as "student". From 14 January to 2 March the wallet received eleven credits totalling ₦86,000, all from the subject's own bank account. Between 3 and 9 March, it received 41 credits from 37 different senders, individual amounts between ₦45,000 and ₦480,000 (full list in the transaction section). Within 20 minutes of each credit, funds were sent to a single account at another bank in the name of a third party with no disclosed relationship to the subject. The subject logged in from four devices during this period, one of which is linked to two other customers of ours. When contacted on 10 March, the subject said the funds were "business proceeds" but could not name the business.
Conclusion. The wallet was restricted on 10 March. We hold device, login and contact records and can provide them on request. Contact: MLRO, reference INV-0417.
Every sentence in the body is a fact that can be checked. The "why" comes through the comparison: declared purpose and history on one side, observed behaviour on the other.
What makes a narrative hard to act on?
These patterns come up often in weak reports:
Rule names instead of reasons. "Rule
custom:high_value_cryptofired" means something inside your systems and nothing to an FIU. Translate it: "a single inbound crypto transfer worth 60 times the customer's previous monthly volume".Totals without transactions. "₦14 million received over six days" hides the pattern that makes it suspicious.
Conclusions without facts. Words like "fraudulent" or "laundering" should follow from facts in the report, not replace them.
Missing counterparties. If you know where money went, say so, including the receiving institution.
Contradictions between fields and narrative. If the narrative says 41 credits and the transaction section lists 38, the analyst has to work out which is right.
No statement of what you did. The FIU needs to know whether the account is still open and whether funds are still there.
How fast does a report need to be filed in Nigeria?
Section 7 of the Money Laundering (Prevention and Prohibition) Act 2022 (opens in a new tab) deems a transaction suspicious if, among other things, it has an unjustifiable frequency, unusual complexity, no apparent economic justification, or is inconsistent with the known pattern of the account. Institutions must report to the NFIU "immediately", and within 24 hours after the transaction must draw up a written report "containing all relevant information… together with the reasons and identity of the principal and, where applicable, of the beneficiary", take appropriate action, and report the transaction and actions taken. The Act says this applies "whether the transaction is complete or not".
A 24-hour window leaves no room for a narrative written from scratch. It rewards investigation records that already hold the facts in order: alerts, transactions, customer statements and actions taken, each with a timestamp.
Who should review a report before it is filed?
A second person, every time. The reviewer checks that every statement in the narrative is supported by evidence on file, and that the fields and the narrative agree.
Myaza Cases & SAR Filing builds this into the workflow. A SAR or STR is drafted from an investigation in goAML format and can be exported as XML. The person who drafts a report cannot file it, filing records a unique FIU reference, and an amended report links back to the one it amends. Drafting, filing and cancelling are recorded in the organisation's audit log. The investigations and reporting documentation covers the lifecycle. The narrative itself remains the analyst's work: software can assemble the facts, but it cannot decide what they mean.
A pre-filing checklist
Who, what, when, where, why and how are all answered.
Transactions are listed with individual dates and amounts.
The "why" compares observed behaviour with what the customer declared.
Internal rule names and jargon are translated into plain facts.
Counterparties and receiving institutions are named where known.
The report says what action you took and what else you can provide.
Fields and narrative agree, and a second person has reviewed both.
The timeline meets your jurisdiction's deadline.
Sources

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


