How to Write a Crypto SAR or STR Report

Assemble an Onchain Narrative That Survives Regulator Scrutiny

KYTComplianceSAR / STR
August 15, 202610 min read

The moment a KYT alert escalates from a flagged transaction to a real exposure, a clock starts on the filing that has to follow. A crypto suspicious activity report is how a VASP makes that escalation visible to a financial intelligence unit. Whether filed as a SAR or an STR, it covers onchain behavior that crosses a threshold no longer looking like ordinary customer activity. It is also the document regulators ask for first when they examine an AML program. That is because it is where monitoring, investigation, and the decisions analysts make become visible on paper. This guide covers what a crypto SAR or STR contains and why these filings take longer in crypto. It also shows what a defensible narrative looks like, and how to assemble one faster without cutting the evidence. For the broader transaction monitoring workflow that produces these alerts, see Phalcon Compliance. This page is part of the KYT Resource Center.

What a Crypto SAR Is and When VASPs Must File

A suspicious activity report is a structured disclosure to a financial intelligence unit. In the United States the document is the FinCEN SAR. Under the Bank Secrecy Act, FinCEN requires financial institutions, including crypto exchanges, to file a SAR for transactions that meet its reporting thresholds. Internationally, FATF Recommendation 20 sets the suspicious transaction reporting obligation for virtual asset service providers. It requires each VASP to report suspicious transactions to its national financial intelligence unit. Many jurisdictions refer to this as a STR rather than a SAR. The function is the same: convert an internal alert into a disclosure that law enforcement can act on.

The trigger is risk-based, not purely numeric. FinCEN SAR reporting attaches to transactions the institution knows, suspects, or has reason to suspect involve funds from illegal activity. The same standard covers transactions designed to evade reporting, serving no apparent business purpose, or using the institution to help carry out criminal activity. For money services businesses, including crypto exchanges, the USD 2,000 aggregated threshold is the floor for SAR filing in the US, but the obligation is the suspicion, not the amount. A cluster of sub-threshold transfers structured to avoid detection is itself the red flag. FATF Rec 20 mirrors this for VASPs internationally and ties it back to the risk-based approach in FATF Recommendation 1. That recommendation obliges VASPs to identify, assess, and understand their money laundering and terrorist financing risks, and to apply controls proportionate to those risks.

Filing is also time-bound. FinCEN expects a SAR within 30 calendar days of initial detection of facts that may constitute a basis for filing. A possible extension to 60 days applies when no suspect is identified. STR deadlines vary by jurisdiction but sit in the same range. That clock is what makes the drafting burden acute in crypto. The evidence that supports a defensible filing is onchain and assembled under the same deadline pressure.

Why Crypto SARs Take Longer Than Traditional Ones

The drafting burden in crypto is structurally heavier than in traditional finance, and the gap is not a tooling preference. It is a property of how funds move on a public ledger. A traditional SAR describes a set of transactions inside the institution: account numbers, dates, amounts, and a narrative that ties them together. A crypto SAR has to describe a graph. Funds move across addresses with no known owner, hop between chains, and pass through mixers or cross-chain bridges. They split or recombine before reaching a cash-out point. The narrative has to trace that path and explain why each hop matters. It has to do so in a document a reader who is not a blockchain analyst can follow.

The practitioner experience reflects that gap. SAR drafting is widely experienced as a heavy, manual task, and a single filing routinely consumes hours of analyst time. The underlying mechanics are consistent with the structural gap above. The bottleneck is the onchain narrative, which a generic SAR template cannot help with.

The cost of getting it wrong runs both ways. A filing that under-supports the suspicion invites a regulator to ask why the institution filed at all. A filing that overstates the evidence invites the opposite question. A defensible crypto SAR has to land in between. That means the drafter needs a coherent onchain story, the exposure figures that quantify it, and the risk indicators that triggered the alert.

What Goes Into a Defensible SAR

A defensible crypto SAR rests on four evidence blocks. Each one answers a question a reviewer is going to ask. Each one has to come from the onchain investigation rather than from a template.

The first block is the multi-hop fund flow. This is the trace from the customer address through the addresses it transacted with, across as many hops as the analyst can follow. It ends when the funds reach a known exit point or a counterparty already flagged as high risk. The trace has to show the addresses, the transaction hashes, and the sequence. A reviewer who cannot follow the path cannot evaluate the suspicion.

The second block is the exposure value and exposure percentage. Exposure value is the dollar figure of funds that touched addresses the platform has classified as risky, such as addresses tied to known illicit activity. Exposure percentage expresses that figure relative to the total flow through the customer address. It lets a reviewer see whether the risk is a fringe contamination or the dominant source of the funds. Both figures quantify what would otherwise be a vague assertion that the address is risky.

The third block is the set of risk indicators that triggered the alert. A risk indicator is a labeled attribute attached to an address or transaction in the platform's risk engine. It is drawn from a set of 17 risk indicator categories. Those categories cover sources such as darknet markets, scams, stolen funds, ransomware, mixers, sanctions, and child sexual abuse material. The SAR narrative has to name which indicators fired, on which addresses, and at which hop. The indicators connect the onchain evidence to the suspicion standard. A SAR that says the address looked risky without naming the indicators is asking the reviewer to take the conclusion on trust.

The fourth block is the disposition decision and its rationale. The SAR documents what the institution did, whether that was freezing funds, restricting the account, exiting the relationship, or referring the case to law enforcement. It also documents why that disposition was proportionate to the risk. The disposition is where monitoring, investigation, and policy meet, and the SAR is the record of that meeting.

STR report showing structured suspicious transaction report

How to Assemble the Onchain Narrative Faster

The bottleneck in SAR drafting is not the writing. It is the assembly of the four evidence blocks into a coherent narrative under the filing deadline. Doing that by hand means re-running traces, copying address and transaction identifiers, recomputing exposure, and re-listing risk indicators into a separate document. That is exactly the manual lift that stretches a single filing past two hours.

Phalcon Compliance collapses that assembly into a single export. The platform already holds the multi-hop fund flow, the exposure value and percentage, and the 17-category risk indicator set for each case it tracks. The case export, available on the Essential tier and above, assembles those blocks into a structured suspicious transaction report. It carries the trace, the exposure figures, and the risk indicators together, with the audit trail attached. The export is the document a compliance officer would otherwise build by hand, generated from the same case file the investigator already worked in.

The point of the export is not to skip the human judgment. The compliance officer still decides whether the case meets the suspicion threshold. The officer writes the narrative that ties the evidence to that conclusion, and signs off on the disposition. What the export removes is the transcription work between the investigation and the filing. That transcription work is where the time and the error risk concentrate. A case that took two hours to draft by hand can move to a faster workflow. The investigator reviews the assembled evidence, confirms the narrative, and exports, with the audit trail captured alongside.

Address screening risk summary feeding SAR narrative decisions

Keep the Audit Trail Regulators Expect

A SAR is not the only artifact a regulator asks for during an examination. The audit trail behind it carries equal weight, because it shows the filing was the product of a real investigation rather than a template-fill. FATF Recommendation 11 obliges VASPs to maintain records that demonstrate the risk-based controls were applied. Recommendation 20 extends recordkeeping to the suspicious transaction reporting process itself. Examiners read the absence of an audit trail as the absence of a control.

A defensible audit trail has three layers. The first is the alert trail: which screening triggered the alert, when, on which address or transaction, and what risk indicators fired. The second is the investigation trail: who picked up the case, what traces they ran, what exposure figures they observed, and what conclusions they reached. The third is the disposition trail: who reviewed the conclusion, who approved the filing, what was filed, when, and what action followed.

Phalcon Compliance captures all three layers through its Audit Trails, Audit Logs, and Risk Engine Details, each exportable to PDF or CSV. The Audit Trail records the sequence of investigative actions on the case. The Audit Logs record who took each action and when. The Risk Engine Details record which risk indicators fired and how the risk score was computed. Exported together, they form the record a regulator can follow from alert to filing without a gap. They also travel with the SAR export so the evidence package and the audit package do not drift apart.

The practical test of an audit trail is whether a second analyst, or an examiner, can reconstruct the decision from the records alone. If the trail forces them to ask the original analyst to remember what happened, the trail is incomplete. The export model is designed so that the reconstruction is possible from the artifacts. That is also what protects the institution if the original analyst has left the team.

Exposure path audit trail attached to SAR evidence package

Filing Workflow and Multi-Jurisdiction Tips

The filing workflow that holds up under examination is a sequence rather than a sprint. Detection raises the alert. Triage confirms it is not a false positive. Investigation builds the onchain narrative, quantifies exposure, and identifies the risk indicators. Review confirms the case meets the suspicion threshold. Approval signs off on the disposition. Filing submits the SAR or STR to the financial intelligence unit within the jurisdictional deadline. Recordkeeping retains the case file, narrative, and audit trail for the retention period, which is five years under FinCEN and comparable elsewhere.

Multi-jurisdiction VASPs face an additional layer. A VASP licensed in the US files with FinCEN. A VASP operating in the European Economic Area files with its national FIU. That filing happens under the framework set by the European Banking Authority and the relevant national transposition of the AML directives. Other jurisdictions have their own FIUs, thresholds, and forms, though FATF Rec 20 is the common backbone. The practical move is to keep the investigation and the evidence package jurisdiction-agnostic, because the onchain narrative does not change across borders. The jurisdiction-specific filing format can be mapped at the final step. A case file assembled from a single export with the audit trail attached can be remapped to a different jurisdiction's form without redoing the investigation. That is what makes the export model durable across a multi-jurisdiction footprint.

The defensible standard is the same in every jurisdiction. Show the multi-hop fund flow, quantify the exposure, name the risk indicators, document the disposition, and retain the audit trail. Get those five right and the filing reads as the output of a working program. Get any of them wrong and the filing reads as a gap the program has to explain. Explore how Phalcon Compliance assembles the SAR evidence package and audit trail for the STR and SAR export on the Essential tier and above.

Frequently Asked Questions

Build Real-Time, Automated, and Auditable KYT Compliance Capabilities

Systematically improve virtual asset transaction risk monitoring capabilities, from understanding regulatory obligations to implementing technical architecture.