Unit 04 · Chapter 5 · 10 min read

Investigations, reporting, and confidentiality

Build a defensible case without confusing suspicion with proof.

A case narrative should read like a clear account of events, not a pile of copied alerts. The reader needs to know what happened, why it matters, what evidence supports it, and what the institution decided.

Build the case from facts

Start with the triggering activity, relevant customer context, transaction timeline, and source records. Separate observed facts from customer statements and analyst inferences. Record alternative explanations and the evidence used to accept or reject them.

A defensible case can conclude that the activity is explained, remains uncertain, or warrants further action. It does not need dramatic language. Avoid unsupported statements about criminal intent. Preserve the actual references and amounts so another authorized reviewer can reproduce the analysis. Good writing is an operational control because it reduces ambiguity at handoff.

A case narrative should let another trained person distinguish observations from conclusions. “Five payments arrived within ten minutes” is an observation supported by records. “The payments are coordinated” is an inference that needs further evidence. “The account was used for crime” is a stronger conclusion that may exceed the available facts. Precise language improves both the investigation and the quality of downstream decisions.

Build a timeline from retained source records and note gaps explicitly. A case can explain that a counterparty’s identity is unresolved without filling the gap with an assumption. Include facts that weaken the initial suspicion as well as facts that support it. The objective is a defensible assessment of activity, not a persuasive story assembled from only one side of the evidence.

Build the case from facts — the flow
Build the case from facts Build the case from facts — the flow Follow the sequence. State the supported disposition. Facts Collect referenced observations Analysis Test explanations and inconsistencies Conclusion State the supported disposition
  1. FactsCollect referenced observations
  2. AnalysisTest explanations and inconsistencies
  3. ConclusionState the supported disposition
Follow the sequence. State the supported disposition. Chapter sources · Open image
Build the case from facts — the distinction
Build the case from facts Build the case from facts — the distinction These concepts answer different questions. Read each definition in the context of the section. Observation What a record directly shows Inference Interpretation drawn from several facts
Observation
  • What a record directly shows
Inference
  • Interpretation drawn from several facts
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Case note structure
Build the case from facts Case note structure Fictional teaching record. Analyst conclusion with limits. Case note structure Illustrative data; not a real customer record or a prescribed policy. Observed three linked transfers Direct transaction evidence Claim customer supplier payments Customer explanation Inference purpose unresolved Analyst conclusion with limits The reader must know their evidentiary status
Fictional educational excerpt / Not for execution

Case note structure

Illustrative data; not a real customer record or a prescribed policy.

  1. Observedthree linked transfers

    Direct transaction evidence

  2. Claimcustomer supplier payments

    Customer explanation

  3. Inferencepurpose unresolved

    Analyst conclusion with limits

The reader must know their evidentiary status

Fictional teaching record. Analyst conclusion with limits. Chapter sources · Open image
Build the case from facts — control and failure modes
Build the case from facts Build the case from facts — control and failure modes The reader must know their evidentiary status. The branches show why alternative designs fail. Control design Label facts claims and inferences. The reader must know their evidentiary status. Failure mode 1 Use accusations without support. That exceeds the available facts. avoid Failure mode 2 Copy alerts without analysis. The case still lacks reasoning. avoid Failure mode 3 Omit alternative explanations. The conclusion becomes harder to assess. avoid
Control design

Label facts claims and inferences. The reader must know their evidentiary status.

Failure mode 1avoid
Use accusations without support. That exceeds the available facts.
Failure mode 2avoid
Copy alerts without analysis. The case still lacks reasoning.
Failure mode 3avoid
Omit alternative explanations. The conclusion becomes harder to assess.
The reader must know their evidentiary status. The branches show why alternative designs fail. Chapter sources · Open image

Separate the reporting decision

A suspicious activity report is not a criminal conviction. The institution applies the relevant reporting criteria using its investigation and procedures. A decision not to file also needs a documented basis where required by the program.

Keep reporting disposition distinct from account restriction, customer refund, and relationship exit. One action does not automatically dictate the others. The authorized decision maker should review the evidence and unresolved issues. Preserve approvals and the version of the narrative submitted. A draft saved in a case tool is not evidence that a filing was received.

Separate the reporting decision — the flow
Separate the reporting decision Separate the reporting decision — the flow Follow the sequence. Record submission and receipt evidence. Investigate Develop the supported case Decide Apply the relevant reporting criteria Confirm Record submission and receipt evidence
  1. InvestigateDevelop the supported case
  2. DecideApply the relevant reporting criteria
  3. ConfirmRecord submission and receipt evidence
Follow the sequence. Record submission and receipt evidence. Chapter sources · Open image
Separate the reporting decision — the distinction
Separate the reporting decision Separate the reporting decision — the distinction These concepts answer different questions. Read each definition in the context of the section. Draft report Prepared content awaiting the process Filed report Submission has the required receipt evidence
Draft report
  • Prepared content awaiting the process
Filed report
  • Submission has the required receipt evidence
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Reporting lifecycle
Separate the reporting decision Reporting lifecycle Fictional teaching record. Filing completion unproven. Reporting lifecycle Illustrative data; not a real customer record or a prescribed policy. Narrative draft-v3 Prepared text Approval complete Internal authorization Receipt pending Filing completion unproven Approval and filing receipt are different states
Fictional educational excerpt / Not for execution

Reporting lifecycle

Illustrative data; not a real customer record or a prescribed policy.

  1. Narrativedraft-v3

    Prepared text

  2. Approvalcomplete

    Internal authorization

  3. Receiptpending

    Filing completion unproven

Approval and filing receipt are different states

Fictional teaching record. Filing completion unproven. Chapter sources · Open image
Separate the reporting decision — control and failure modes
Separate the reporting decision Separate the reporting decision — control and failure modes Approval and filing receipt are different states. The branches show why alternative designs fail. Control design Track reporting as its own lifecycle. Approval and filing receipt are different states. Failure mode 1 Call a draft filed. That overstates completion. avoid Failure mode 2 Treat filing as proof of guilt. Reporting concerns suspicion under the rule. avoid Failure mode 3 Automatically refund or close from filing alone. Those actions require their own basis. avoid
Control design

Track reporting as its own lifecycle. Approval and filing receipt are different states.

Failure mode 1avoid
Call a draft filed. That overstates completion.
Failure mode 2avoid
Treat filing as proof of guilt. Reporting concerns suspicion under the rule.
Failure mode 3avoid
Automatically refund or close from filing alone. Those actions require their own basis.
Approval and filing receipt are different states. The branches show why alternative designs fail. Chapter sources · Open image

Protect confidential reporting information

SARs and information that would reveal their existence are subject to strict confidentiality rules, with specific permitted disclosures. Do not expose a SAR flag to general customer support, ordinary exports, or customer-facing explanations. Underlying facts can have a different sharing analysis, but that does not make every disclosure permissible.

Implement separate permissions, audit access, and review exports. Use customer wording approved for the situation without revealing protected reporting information. Test search, notifications, analytics, and backups for accidental disclosure. Confidentiality is a system property; a policy cannot protect a field copied into every event stream.

The September 2, 2026 joint agency statement clarifies that SAR confidentiality does not prevent banks from discussing potentially fraudulent transactions, other suspicious activity, or account closures with customers. Protecting the report does not require silence about every underlying customer problem.

Protect confidential reporting information — the flow
Protect confidential reporting information Protect confidential reporting information — the flow Follow the sequence. Monitor access and permitted disclosure. Restrict Separate protected reporting records Review Control searches exports and messages Audit Monitor access and permitted disclosure
  1. RestrictSeparate protected reporting records
  2. ReviewControl searches exports and messages
  3. AuditMonitor access and permitted disclosure
Follow the sequence. Monitor access and permitted disclosure. Chapter sources · Open image
Protect confidential reporting information — the distinction
Protect confidential reporting information Protect confidential reporting information — the distinction These concepts answer different questions. Read each definition in the context of the section. Underlying transaction facts May have a separate lawful sharing basis SAR existence Protected information with specific disclosure limits
Underlying transaction facts
  • May have a separate lawful sharing basis
SAR existence
  • Protected information with specific disclosure limits
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Access design
Protect confidential reporting information Access design Fictional teaching record. Approved wording only. Access design Illustrative data; not a real customer record or a prescribed policy. General support transaction status Limited operational view Reporting team restricted case Authorized purpose Customer message no SAR flag Approved wording only Copies and search indexes can leak the same fact
Fictional educational excerpt / Not for execution

Access design

Illustrative data; not a real customer record or a prescribed policy.

  1. General supporttransaction status

    Limited operational view

  2. Reporting teamrestricted case

    Authorized purpose

  3. Customer messageno SAR flag

    Approved wording only

Copies and search indexes can leak the same fact

Fictional teaching record. Approved wording only. Chapter sources · Open image
Protect confidential reporting information — control and failure modes
Protect confidential reporting information Protect confidential reporting information — control and failure modes Copies and search indexes can leak the same fact. The branches show why alternative designs fail. Control design Restrict reporting status across all data paths. Copies and search indexes can leak the same fact. Failure mode 1 Show SAR status in support badges. That broadens access to protected information. avoid Failure mode 2 Assume internal sharing is always unrestricted. Permissions and legal limits still matter. avoid Failure mode 3 Put filing reasons in customer email. That can reveal protected information. avoid
Control design

Restrict reporting status across all data paths. Copies and search indexes can leak the same fact.

Failure mode 1avoid
Show SAR status in support badges. That broadens access to protected information.
Failure mode 2avoid
Assume internal sharing is always unrestricted. Permissions and legal limits still matter.
Failure mode 3avoid
Put filing reasons in customer email. That can reveal protected information.
Copies and search indexes can leak the same fact. The branches show why alternative designs fail. Chapter sources · Open image

Use quality review and feedback

Quality review should assess evidence, reasoning, completeness, deadlines, and confidentiality. Sample across reviewers and dispositions. Reviewing only filed cases misses weak closures and missed escalation.

Feed recurring issues back into training, data collection, and monitoring design. A missing counterparty identifier may be an onboarding defect, not an analyst problem. Track rework and root causes separately from raw case speed. The program improves when findings change the process and the change is verified on later work.

Use quality review and feedback — the flow
Use quality review and feedback Use quality review and feedback — the flow Follow the sequence. Update controls and verify later cases. Sample Include different outcomes and reviewers Diagnose Find recurring quality defects Repair Update controls and verify later cases
  1. SampleInclude different outcomes and reviewers
  2. DiagnoseFind recurring quality defects
  3. RepairUpdate controls and verify later cases
Follow the sequence. Update controls and verify later cases. Chapter sources · Open image
Use quality review and feedback — the distinction
Use quality review and feedback Use quality review and feedback — the distinction These concepts answer different questions. Read each definition in the context of the section. Case throughput How many cases were processed Case quality Whether the work supports its conclusions
Case throughput
  • How many cases were processed
Case quality
  • Whether the work supports its conclusions
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Quality finding
Use quality review and feedback Quality finding Fictional teaching record. More training alone is insufficient. Quality finding Illustrative data; not a real customer record or a prescribed policy. Defect missing counterparty evidence Repeated across cases Cause source field not collected Upstream issue Fix repair data capture More training alone is insufficient The defect may begin before the analyst sees it
Fictional educational excerpt / Not for execution

Quality finding

Illustrative data; not a real customer record or a prescribed policy.

  1. Defectmissing counterparty evidence

    Repeated across cases

  2. Causesource field not collected

    Upstream issue

  3. Fixrepair data capture

    More training alone is insufficient

The defect may begin before the analyst sees it

Fictional teaching record. More training alone is insufficient. Chapter sources · Open image
Use quality review and feedback — control and failure modes
Use quality review and feedback Use quality review and feedback — control and failure modes The defect may begin before the analyst sees it. The branches show why alternative designs fail. Control design Link quality findings to their root cause. The defect may begin before the analyst sees it. Failure mode 1 Measure only cases per hour. Speed can hide incomplete work. avoid Failure mode 2 Review only filings. Weak non-filing decisions remain unseen. avoid Failure mode 3 Close findings after training attendance. Effectiveness requires later evidence. avoid
Control design

Link quality findings to their root cause. The defect may begin before the analyst sees it.

Failure mode 1avoid
Measure only cases per hour. Speed can hide incomplete work.
Failure mode 2avoid
Review only filings. Weak non-filing decisions remain unseen.
Failure mode 3avoid
Close findings after training attendance. Effectiveness requires later evidence.
The defect may begin before the analyst sees it. The branches show why alternative designs fail. Chapter sources · Open image

Chapter connections

This chapter builds on Transaction monitoring and alert quality. Use the glossary for terminology and risk mathematics for formulas and worked calculations.

Sources

Reviewed 2026-09-17
  1. FFIEC: suspicious activity reporting
  2. FinCEN: SAR confidentiality advisory FIN-2010-A014
  3. FinCEN and banking agencies: September 2, 2026 statement on SAR confidentiality and customer communications