Auditing AML Transactions
Screens transaction data for suspicious patterns using red flag typologies and structures SAR narrative elements for BSA/AML compliance.
When To Use
- Transaction monitoring system generates an alert requiring human review
- BSA officer receives a referral (internal, law enforcement, or examiner finding)
- Periodic look-back or enhanced due diligence review of high-risk accounts
- Continuation SAR is due on the 90-day cycle
- Independent audit requires sample transaction review
- 314(b) information-sharing request received from another institution
Inputs To Gather
Collect all items below before starting review. If transaction records are unavailable, STOP — document the gap and escalate.
Institution & Scope
- Institution type (bank, MSB, broker-dealer, credit union, insurance, casino, other) [VERIFY]
- Charter/license jurisdiction and primary regulator [VERIFY]
- BSA/AML program status (established / recently remediated / under consent order)
- Review period (start and end dates)
- Alert source and alert/case ID
Subject Information
- Subject name(s) — individuals and/or entities
- Account number(s), account type(s), and open date
- Customer risk rating (Low / Medium / High / Unrated)
- KYC profile: stated occupation, income, expected activity, source of funds
- Prior SAR history on this subject
Data Sources
Confirm availability of each: transaction records (debits/credits), wire transfer details (originator/beneficiary), cash activity and CTR history, check images and deposit slips, account statements, CDD/EDD documentation, OFAC/sanctions screening results, negative news and adverse media, law enforcement subpoenas or 314(b) requests.
Workflow
Step 1 — Transaction Profiling
Summarize account activity for the review period:
| Metric |
Value |
| Total credits (count / dollar) |
|
| Total debits (count / dollar) |
|
| Cash-in / Cash-out (count / dollar) |
|
| Wire-in / Wire-out (count / dollar) |
|
| ACH/EFT and check activity (count / dollar) |
|
| Average and largest single transaction |
|
| CTRs filed during period |
|
| Jurisdictions involved |
|
Compare observed activity against three baselines:
- KYC expected activity — Does volume/type match customer declarations?
- Peer group — Consistent with similarly situated customers?
- Historical baseline — Has pattern shifted from prior periods?
Flag material deviations with [DEVIATION] and quantify the variance.
Step 2 — Red Flag Identification
Screen activity against recognized typologies. For each red flag identified, document:
- Red flag typology — Name from reference taxonomy
- Category — Structuring / Rapid Movement / Geographic / Shell-Layering / Trade-Based / Behavioral / Other
- Transactions implicated — Date, amount, type, counterparty
- Severity — High / Medium / Low
- Explanation — Why this pattern is suspicious in context
Key thresholds:
- CTR: $10,000 cash (single or aggregate same-business-day). Transactions just below are a structuring indicator. [VERIFY current threshold]
- SAR dollar minimum: $5,000+ with known suspect; $25,000+ with no identified suspect (banks). No dollar minimum for MSBs. [VERIFY by institution type]
- Rapid movement: Funds deposited and withdrawn/transferred within 48 hours with no apparent business purpose.
- Round-dollar transfers: Unusual frequency of round-amount wires inconsistent with commercial invoicing.
Step 3 — OFAC & Sanctions Screening
Confirm whether any party to flagged transactions appears on:
- OFAC SDN List and Consolidated Sanctions List
- FinCEN 311 Special Measures (jurisdictions/institutions)
- EU/UN sanctions lists (if applicable) [VERIFY applicability]
- FATF High-Risk and Non-Cooperative Jurisdictions list
Record each counterparty/jurisdiction screened, the result, list version, and date. If a potential OFAC match is identified, escalate immediately — OFAC obligations are strict liability with a shorter timeline than SAR filing.
Step 4 — Disposition
Reach one of four dispositions:
| Disposition |
Criteria |
Action |
| File SAR |
Suspicious, unexplained, meets dollar thresholds |
Proceed to Step 5 |
| Close — Below Threshold |
Concerning but below SAR dollar minimums |
Document rationale; retain 5 years; consider enhanced monitoring |
| Close — Explained |
Legitimate purpose confirmed with documentation |
Document rationale and evidence; retain 5 years |
| Escalate |
OFAC match, law enforcement nexus, or insider involvement |
Immediate escalation per institution policy |
Document rationale for every disposition. Examiners review closed cases as closely as filed SARs.
Step 5 — SAR Narrative Drafting
The narrative must answer who, what, when, where, why, and how.
Structure:
- Subject Information — Full legal name(s), DOB, SSN/TIN (if available), address, account relationship, risk rating and basis.
- Suspicious Activity Description — Nature of activity (use FinCEN characterization codes), identify all subjects and roles, specific transactions and patterns, date range, branches/jurisdictions, why activity is suspicious, method/mechanism used.
- Transaction Detail — Chronological summary of key transactions, total dollar amount, instruments/channels (cash, wire, ACH, check, crypto).
- Investigation Summary — Detection method, investigation steps, CDD/EDD reviewed, third-party information (314(b), public records, adverse media).
- Supporting Documentation — Exhibit list, reference to prior SARs if continuation filing.
Narrative rules:
- Factual, not conclusory — state what happened; never assert a crime was committed
- Chronological presentation
- Specific — dates, amounts, account numbers, counterparty names
- Self-contained — reader with no prior knowledge should understand the case
- Quantified — total suspicious amounts and transaction counts
- No SAR-tipping language — never indicate the customer was or will be notified (31 USC 5318(g)(2)) [VERIFY current statutory cite]
Filing deadlines [VERIFY current FinCEN guidance]:
| Scenario |
Deadline |
| Standard SAR |
30 calendar days from initial detection |
| No suspect identified |
30 days; may extend to 60 days to identify suspect |
| Ongoing activity |
Continuing SARs every 90 days |
| Criminal referral |
Notify law enforcement immediately; SAR still due within 30 days |
Output
Deliverables for each review:
- Transaction summary table with profiling metrics and baseline comparisons
- Red flag log — each flag with typology, category, severity, implicated transactions, and explanation
- OFAC/sanctions screening record with list versions and dates
- Disposition memo — selected outcome with written rationale
- SAR narrative (if filing) — structured per the template above, ready for BSA officer review
- Filing deadline tracker — calculated deadline with calendar entry
Quality Checks
Completeness
Accuracy
Regulatory Compliance
Professional Standards
Reference Files
| File |
Description |
references/AML-RED-FLAGS.md |
Categorized AML red flag typologies with indicators and activity patterns for transaction screening |
1---2name: auditing-aml-transactions3description: Screens transaction data for suspicious patterns using red flag typologies and structures SAR narrative elements. Use when reviewing transactions for AML, identifying suspicious activity, or drafting SAR narratives.4---5# Auditing AML Transactions67Screens transaction data for suspicious patterns using red flag typologies and structures SAR narrative elements for BSA/AML compliance.89## When To Use1011- Transaction monitoring system generates an alert requiring human review12- BSA officer receives a referral (internal, law enforcement, or examiner finding)13- Periodic look-back or enhanced due diligence review of high-risk accounts14- Continuation SAR is due on the 90-day cycle15- Independent audit requires sample transaction review16- 314(b) information-sharing request received from another institution1718## Inputs To Gather1920Collect all items below before starting review. If transaction records are unavailable, STOP — document the gap and escalate.2122### Institution & Scope2324- Institution type (bank, MSB, broker-dealer, credit union, insurance, casino, other) [VERIFY]25- Charter/license jurisdiction and primary regulator [VERIFY]26- BSA/AML program status (established / recently remediated / under consent order)27- Review period (start and end dates)28- Alert source and alert/case ID2930### Subject Information3132- Subject name(s) — individuals and/or entities33- Account number(s), account type(s), and open date34- Customer risk rating (Low / Medium / High / Unrated)35- KYC profile: stated occupation, income, expected activity, source of funds36- Prior SAR history on this subject3738### Data Sources3940Confirm availability of each: transaction records (debits/credits), wire transfer details (originator/beneficiary), cash activity and CTR history, check images and deposit slips, account statements, CDD/EDD documentation, OFAC/sanctions screening results, negative news and adverse media, law enforcement subpoenas or 314(b) requests.4142## Workflow4344### Step 1 — Transaction Profiling4546Summarize account activity for the review period:4748| Metric | Value |49|---|---|50| Total credits (count / dollar) | |51| Total debits (count / dollar) | |52| Cash-in / Cash-out (count / dollar) | |53| Wire-in / Wire-out (count / dollar) | |54| ACH/EFT and check activity (count / dollar) | |55| Average and largest single transaction | |56| CTRs filed during period | |57| Jurisdictions involved | |5859Compare observed activity against three baselines:60- **KYC expected activity** — Does volume/type match customer declarations?61- **Peer group** — Consistent with similarly situated customers?62- **Historical baseline** — Has pattern shifted from prior periods?6364Flag material deviations with `[DEVIATION]` and quantify the variance.6566### Step 2 — Red Flag Identification6768Screen activity against recognized typologies. For each red flag identified, document:6970- **Red flag typology** — Name from reference taxonomy71- **Category** — Structuring / Rapid Movement / Geographic / Shell-Layering / Trade-Based / Behavioral / Other72- **Transactions implicated** — Date, amount, type, counterparty73- **Severity** — High / Medium / Low74- **Explanation** — Why this pattern is suspicious in context7576Key thresholds:77- **CTR**: $10,000 cash (single or aggregate same-business-day). Transactions just below are a structuring indicator. [VERIFY current threshold]78- **SAR dollar minimum**: $5,000+ with known suspect; $25,000+ with no identified suspect (banks). No dollar minimum for MSBs. [VERIFY by institution type]79- **Rapid movement**: Funds deposited and withdrawn/transferred within 48 hours with no apparent business purpose.80- **Round-dollar transfers**: Unusual frequency of round-amount wires inconsistent with commercial invoicing.8182### Step 3 — OFAC & Sanctions Screening8384Confirm whether any party to flagged transactions appears on:85- OFAC SDN List and Consolidated Sanctions List86- FinCEN 311 Special Measures (jurisdictions/institutions)87- EU/UN sanctions lists (if applicable) [VERIFY applicability]88- FATF High-Risk and Non-Cooperative Jurisdictions list8990Record each counterparty/jurisdiction screened, the result, list version, and date. If a potential OFAC match is identified, **escalate immediately** — OFAC obligations are strict liability with a shorter timeline than SAR filing.9192### Step 4 — Disposition9394Reach one of four dispositions:9596| Disposition | Criteria | Action |97|---|---|---|98| **File SAR** | Suspicious, unexplained, meets dollar thresholds | Proceed to Step 5 |99| **Close — Below Threshold** | Concerning but below SAR dollar minimums | Document rationale; retain 5 years; consider enhanced monitoring |100| **Close — Explained** | Legitimate purpose confirmed with documentation | Document rationale and evidence; retain 5 years |101| **Escalate** | OFAC match, law enforcement nexus, or insider involvement | Immediate escalation per institution policy |102103**Document rationale for every disposition.** Examiners review closed cases as closely as filed SARs.104105### Step 5 — SAR Narrative Drafting106107The narrative must answer **who, what, when, where, why, and how**.108109**Structure:**1101111. **Subject Information** — Full legal name(s), DOB, SSN/TIN (if available), address, account relationship, risk rating and basis.1122. **Suspicious Activity Description** — Nature of activity (use FinCEN characterization codes), identify all subjects and roles, specific transactions and patterns, date range, branches/jurisdictions, why activity is suspicious, method/mechanism used.1133. **Transaction Detail** — Chronological summary of key transactions, total dollar amount, instruments/channels (cash, wire, ACH, check, crypto).1144. **Investigation Summary** — Detection method, investigation steps, CDD/EDD reviewed, third-party information (314(b), public records, adverse media).1155. **Supporting Documentation** — Exhibit list, reference to prior SARs if continuation filing.116117**Narrative rules:**118- Factual, not conclusory — state what happened; never assert a crime was committed119- Chronological presentation120- Specific — dates, amounts, account numbers, counterparty names121- Self-contained — reader with no prior knowledge should understand the case122- Quantified — total suspicious amounts and transaction counts123- **No SAR-tipping language** — never indicate the customer was or will be notified (31 USC 5318(g)(2)) [VERIFY current statutory cite]124125**Filing deadlines** [VERIFY current FinCEN guidance]:126127| Scenario | Deadline |128|---|---|129| Standard SAR | 30 calendar days from initial detection |130| No suspect identified | 30 days; may extend to 60 days to identify suspect |131| Ongoing activity | Continuing SARs every 90 days |132| Criminal referral | Notify law enforcement immediately; SAR still due within 30 days |133134## Output135136Deliverables for each review:1371381. **Transaction summary table** with profiling metrics and baseline comparisons1392. **Red flag log** — each flag with typology, category, severity, implicated transactions, and explanation1403. **OFAC/sanctions screening record** with list versions and dates1414. **Disposition memo** — selected outcome with written rationale1425. **SAR narrative** (if filing) — structured per the template above, ready for BSA officer review1436. **Filing deadline tracker** — calculated deadline with calendar entry144145## Quality Checks146147### Completeness148- [ ] Intake items fully populated or gaps explicitly documented149- [ ] Transaction profiling covers all activity types in the review period150- [ ] Every red flag has severity rating and supporting transactions151- [ ] Disposition is one of the four defined outcomes with written rationale152153### Accuracy154- [ ] Dollar amounts cross-referenced to source transaction data155- [ ] Dates confirmed against bank records (not estimated)156- [ ] Counterparty names verified against wire details / account records157- [ ] OFAC screening uses current list version158159### Regulatory Compliance160- [ ] SAR narrative answers all six questions (who/what/when/where/why/how)161- [ ] No SAR-tipping or customer-notification language anywhere in output162- [ ] Filing deadline documented and within regulatory window [VERIFY]163- [ ] CTR analysis included for cash-intensive accounts164- [ ] 5-year record retention requirement noted165166### Professional Standards167- [ ] Findings distinguish confirmed facts from inferences168- [ ] All inferences and assumptions marked with `[VERIFY]`169- [ ] Terminology consistent throughout170- [ ] Output actionable for BSA officer / compliance committee171- [ ] Escalation triggers clearly identified172173## Reference Files174175| File | Description |176|---|---|177| `references/AML-RED-FLAGS.md` | Categorized AML red flag typologies with indicators and activity patterns for transaction screening |