Unit 04 · Chapter 5 · 15 min read

Investigations, reporting, and confidentiality

Build a defensible case without confusing suspicion with proof.

The concept at a glance

Build one case. Keep decisions separate.

Three evidence strips identify observed facts, customer statements, and analyst inference. They feed a case record with chronology, alternative explanations, evidence references, and unresolved issues. That record branches to a restricted reporting decision and a separate account-action decision. Reporting is not proof of a crime.

Enlarge to read every label and explore the connections

A defensible investigation separates facts, statements, and inference. Reporting and account actions require their own reasoned decisions.

  1. Keep evidence classes distinct.

  2. Use the case record to explain the reasoning.

  3. Separate reporting access from routine account actions.

A case narrative should read like a clear account of events, not a pile of copied alerts. The reader needs to know what happened, why it matters, what evidence supports it, and what the institution decided.

Build the case from facts

Build the case from facts — the flow
Build the case from facts Build the case from facts — the flow Follow the sequence. State the supported disposition. Facts Collect referenced observations Analysis Test explanations and inconsistencies Conclusion State the supported disposition
  1. FactsCollect referenced observations
  2. AnalysisTest explanations and inconsistencies
  3. ConclusionState the supported disposition
Follow the sequence. State the supported disposition. Chapter sources · Open image

Start with the triggering activity, relevant customer context, transaction timeline, and source records. Separate observed facts from customer statements and analyst inferences. Record alternative explanations and the evidence used to accept or reject them.

A defensible case can conclude that the activity is explained, remains uncertain, or warrants further action. It does not need dramatic language. Avoid unsupported statements about criminal intent. Preserve the actual references and amounts so another authorized reviewer can reproduce the analysis. Good writing is an operational control because it reduces ambiguity at handoff.

A case narrative should let another trained person distinguish observations from conclusions. “Five payments arrived within ten minutes” is an observation supported by records. “The payments are coordinated” is an inference that needs further evidence. “The account was used for crime” is a stronger conclusion that may exceed the available facts. Precise language improves both the investigation and the quality of downstream decisions.

Build a timeline from retained source records and note gaps explicitly. A case can explain that a counterparty’s identity is unresolved without filling the gap with an assumption. Include facts that weaken the initial suspicion as well as facts that support it. The objective is a defensible assessment of activity, not a persuasive story assembled from only one side of the evidence.

Inside the mechanism. Build a chronology that separates source facts, customer explanations, analyst inferences, and unresolved gaps. Each material claim should point to evidence that another authorized reviewer can inspect. Preserve contradictory facts rather than selecting only those that support the initial alert. The case should explain the relevant activity and decision, not merely paste a long transaction list.

A concrete example. An investigator assembles a timeline from retained source records. Observations, alternative explanations, and conclusions must remain distinguishable. The case identifies 1,288 eligible records from a source population of 1,480. The required workflow completes for 1,249, but 19 completed records miss the illustrative internal target. Another 39 remain incomplete. Communication evidence covers 1,237 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. The narrative states criminal intent where the evidence supports only an unusual pattern. Use precise factual language, cite records, and retain evidence that weakens as well as supports the concern. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

An investigator assembles a timeline from retained source records. Observations, alternative explanations, and conclusions must remain distinguishable.

Build the case from facts — the distinction
Build the case from facts Build the case from facts — the distinction These concepts answer different questions. Read each definition in the context of the section. Observation What a record directly shows Inference Interpretation drawn from several facts
Observation
  • What a record directly shows
Inference
  • Interpretation drawn from several facts
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Case note structure
Build the case from facts Case note structure Fictional teaching record. Analyst conclusion with limits. Case note structure Illustrative data; not a real customer record or a prescribed policy. Observed three linked transfers Direct transaction evidence Claim customer supplier payments Customer explanation Inference purpose unresolved Analyst conclusion with limits The reader must know their evidentiary status
Fictional educational excerpt / Not for execution

Case note structure

Illustrative data; not a real customer record or a prescribed policy.

  1. Observedthree linked transfers

    Direct transaction evidence

  2. Claimcustomer supplier payments

    Customer explanation

  3. Inferencepurpose unresolved

    Analyst conclusion with limits

The reader must know their evidentiary status

Fictional teaching record. Analyst conclusion with limits. Chapter sources · Open image
Build the case from facts — control and failure modes
Build the case from facts Build the case from facts — control and failure modes The reader must know their evidentiary status. The branches show why alternative designs fail. Control design Label facts claims and inferences. The reader must know their evidentiary status. Failure mode 1 Use accusations without support. That exceeds the available facts. avoid Failure mode 2 Copy alerts without analysis. The case still lacks reasoning. avoid Failure mode 3 Omit alternative explanations. The conclusion becomes harder to assess. avoid
Control design

Label facts claims and inferences. The reader must know their evidentiary status.

Failure mode 1avoid
Use accusations without support. That exceeds the available facts.
Failure mode 2avoid
Copy alerts without analysis. The case still lacks reasoning.
Failure mode 3avoid
Omit alternative explanations. The conclusion becomes harder to assess.
The reader must know their evidentiary status. The branches show why alternative designs fail. Chapter sources · Open image

Separate the reporting decision

Separate the reporting decision — the flow
Separate the reporting decision Separate the reporting decision — the flow Follow the sequence. Record submission and receipt evidence. Investigate Develop the supported case Decide Apply the relevant reporting criteria Confirm Record submission and receipt evidence
  1. InvestigateDevelop the supported case
  2. DecideApply the relevant reporting criteria
  3. ConfirmRecord submission and receipt evidence
Follow the sequence. Record submission and receipt evidence. Chapter sources · Open image

A suspicious activity report is not a criminal conviction. The institution applies the relevant reporting criteria using its investigation and procedures. A decision not to file also needs a documented basis where required by the program.

Keep reporting disposition distinct from account restriction, customer refund, and relationship exit. One action does not automatically dictate the others. The authorized decision maker should review the evidence and unresolved issues. Preserve approvals and the version of the narrative submitted. A draft saved in a case tool is not evidence that a filing was received.

Inside the mechanism. An alert, investigation, reporting decision, filing, and account action are distinct states with different authority. The reporting conclusion should follow the applicable facts and standard, not an automatic conversion from an alert score. Preserve the decision and its supporting rationale even when no report is filed. Account restrictions or closure may require separate consideration and should not be inferred solely from the report state.

A concrete example. An alert, escalation, customer exit, and reporting decision are distinct actions. A case conclusion should identify which action was actually considered and authorized. The case identifies 648 eligible records from a source population of 820. The required workflow completes for 629, but 9 completed records miss the illustrative internal target. Another 19 remain incomplete. Communication evidence covers 623 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. A scenario hit automatically becomes a reportable conclusion. Apply the institution-specific review, rationale, approval, and reporting requirements. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

An alert, escalation, customer exit, and reporting decision are distinct actions. A case conclusion should identify which action was actually considered and authorized.

Separate the reporting decision — the distinction
Separate the reporting decision Separate the reporting decision — the distinction These concepts answer different questions. Read each definition in the context of the section. Draft report Prepared content awaiting the process Filed report Submission has the required receipt evidence
Draft report
  • Prepared content awaiting the process
Filed report
  • Submission has the required receipt evidence
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Reporting lifecycle
Separate the reporting decision Reporting lifecycle Fictional teaching record. Filing completion unproven. Reporting lifecycle Illustrative data; not a real customer record or a prescribed policy. Narrative draft-v3 Prepared text Approval complete Internal authorization Receipt pending Filing completion unproven Approval and filing receipt are different states
Fictional educational excerpt / Not for execution

Reporting lifecycle

Illustrative data; not a real customer record or a prescribed policy.

  1. Narrativedraft-v3

    Prepared text

  2. Approvalcomplete

    Internal authorization

  3. Receiptpending

    Filing completion unproven

Approval and filing receipt are different states

Fictional teaching record. Filing completion unproven. Chapter sources · Open image
Separate the reporting decision — control and failure modes
Separate the reporting decision Separate the reporting decision — control and failure modes Approval and filing receipt are different states. The branches show why alternative designs fail. Control design Track reporting as its own lifecycle. Approval and filing receipt are different states. Failure mode 1 Call a draft filed. That overstates completion. avoid Failure mode 2 Treat filing as proof of guilt. Reporting concerns suspicion under the rule. avoid Failure mode 3 Automatically refund or close from filing alone. Those actions require their own basis. avoid
Control design

Track reporting as its own lifecycle. Approval and filing receipt are different states.

Failure mode 1avoid
Call a draft filed. That overstates completion.
Failure mode 2avoid
Treat filing as proof of guilt. Reporting concerns suspicion under the rule.
Failure mode 3avoid
Automatically refund or close from filing alone. Those actions require their own basis.
Approval and filing receipt are different states. The branches show why alternative designs fail. Chapter sources · Open image

Protect confidential reporting information

Protect confidential reporting information — the flow
Protect confidential reporting information Protect confidential reporting information — the flow Follow the sequence. Monitor access and permitted disclosure. Restrict Separate protected reporting records Review Control searches exports and messages Audit Monitor access and permitted disclosure
  1. RestrictSeparate protected reporting records
  2. ReviewControl searches exports and messages
  3. AuditMonitor access and permitted disclosure
Follow the sequence. Monitor access and permitted disclosure. Chapter sources · Open image

SARs and information that would reveal their existence are subject to strict confidentiality rules, with specific permitted disclosures. Do not expose a SAR flag to general customer support, ordinary exports, or customer-facing explanations. Underlying facts can have a different sharing analysis, but that does not make every disclosure permissible.

Implement separate permissions, audit access, and review exports. Use customer wording approved for the situation without revealing protected reporting information. Test search, notifications, analytics, and backups for accidental disclosure. Confidentiality is a system property; a policy cannot protect a field copied into every event stream.

The September 2, 2026 joint agency statement clarifies that SAR confidentiality does not prevent banks from discussing potentially fraudulent transactions, other suspicious activity, or account closures with customers. Protecting the report does not require silence about every underlying customer problem.

Inside the mechanism. Protect information whose disclosure would reveal confidential reporting while preserving permitted operational communication. Access controls should distinguish source transaction facts from protected reporting material and record the purpose of access. Customer communication needs approved boundaries tied to the actual facts. The existence of a reporting workflow should not cause staff to treat every ordinary factual customer conversation as categorically prohibited.

A concrete example. Customer communication can explain appropriate account or fraud facts without disclosing protected reporting information. The access model needs to separate those materials. The case identifies 1,281 eligible records from a source population of 2,100. The required workflow completes for 1,243, but 19 completed records miss the illustrative internal target. Another 38 remain incomplete. Communication evidence covers 1,231 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. A support export includes confidential reporting status and internal filing discussion. Separate factual customer communications from protected reporting records and restrict access by role. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

Customer communication can explain appropriate account or fraud facts without disclosing protected reporting information. The access model needs to separate those materials.

Protect confidential reporting information — the distinction
Protect confidential reporting information Protect confidential reporting information — the distinction These concepts answer different questions. Read each definition in the context of the section. Underlying transaction facts May have a separate lawful sharing basis SAR existence Protected information with specific disclosure limits
Underlying transaction facts
  • May have a separate lawful sharing basis
SAR existence
  • Protected information with specific disclosure limits
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Access design
Protect confidential reporting information Access design Fictional teaching record. Approved wording only. Access design Illustrative data; not a real customer record or a prescribed policy. General support transaction status Limited operational view Reporting team restricted case Authorized purpose Customer message no SAR flag Approved wording only Copies and search indexes can leak the same fact
Fictional educational excerpt / Not for execution

Access design

Illustrative data; not a real customer record or a prescribed policy.

  1. General supporttransaction status

    Limited operational view

  2. Reporting teamrestricted case

    Authorized purpose

  3. Customer messageno SAR flag

    Approved wording only

Copies and search indexes can leak the same fact

Fictional teaching record. Approved wording only. Chapter sources · Open image
Protect confidential reporting information — control and failure modes
Protect confidential reporting information Protect confidential reporting information — control and failure modes Copies and search indexes can leak the same fact. The branches show why alternative designs fail. Control design Restrict reporting status across all data paths. Copies and search indexes can leak the same fact. Failure mode 1 Show SAR status in support badges. That broadens access to protected information. avoid Failure mode 2 Assume internal sharing is always unrestricted. Permissions and legal limits still matter. avoid Failure mode 3 Put filing reasons in customer email. That can reveal protected information. avoid
Control design

Restrict reporting status across all data paths. Copies and search indexes can leak the same fact.

Failure mode 1avoid
Show SAR status in support badges. That broadens access to protected information.
Failure mode 2avoid
Assume internal sharing is always unrestricted. Permissions and legal limits still matter.
Failure mode 3avoid
Put filing reasons in customer email. That can reveal protected information.
Copies and search indexes can leak the same fact. The branches show why alternative designs fail. Chapter sources · Open image

Use quality review and feedback

Use quality review and feedback — the flow
Use quality review and feedback Use quality review and feedback — the flow Follow the sequence. Update controls and verify later cases. Sample Include different outcomes and reviewers Diagnose Find recurring quality defects Repair Update controls and verify later cases
  1. SampleInclude different outcomes and reviewers
  2. DiagnoseFind recurring quality defects
  3. RepairUpdate controls and verify later cases
Follow the sequence. Update controls and verify later cases. Chapter sources · Open image

Quality review should assess evidence, reasoning, completeness, deadlines, and confidentiality. Sample across reviewers and dispositions. Reviewing only filed cases misses weak closures and missed escalation.

Feed recurring issues back into training, data collection, and monitoring design. A missing counterparty identifier may be an onboarding defect, not an analyst problem. Track rework and root causes separately from raw case speed. The program improves when findings change the process and the change is verified on later work.

Inside the mechanism. Quality review should assess factual support, completeness, clarity, timing, and the appropriateness of the decision within the applicable framework. A returned case needs a specific correction reason and an owner. Aggregate recurring defects into upstream changes, such as better event data or clearer case guidance. Do not use filing volume alone as a measure of investigation quality or program effectiveness.

A concrete example. A quality review can identify weak evidence, missed timing, inconsistent reasoning, and data defects. The feedback should improve the upstream process as well as the individual case. The daily source population is 3,700 items, but 74 are outside the completed monitoring run. The included population creates 399 hits and 327 unique cases. With 60 cases already open and capacity for 330, the queue closes at 57. Coverage, duplicate work, and staffing are separate causes; reducing one number does not prove that the overall control improved.

When the assumption fails. Only case closure volume is measured, so rushed weak decisions appear efficient. Track defect types and corrective actions while preserving a representative review population. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

A quality review can identify weak evidence, missed timing, inconsistent reasoning, and data defects. The feedback should improve the upstream process as well as the individual case.

Use quality review and feedback — the distinction
Use quality review and feedback Use quality review and feedback — the distinction These concepts answer different questions. Read each definition in the context of the section. Case throughput How many cases were processed Case quality Whether the work supports its conclusions
Case throughput
  • How many cases were processed
Case quality
  • Whether the work supports its conclusions
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Quality finding
Use quality review and feedback Quality finding Fictional teaching record. More training alone is insufficient. Quality finding Illustrative data; not a real customer record or a prescribed policy. Defect missing counterparty evidence Repeated across cases Cause source field not collected Upstream issue Fix repair data capture More training alone is insufficient The defect may begin before the analyst sees it
Fictional educational excerpt / Not for execution

Quality finding

Illustrative data; not a real customer record or a prescribed policy.

  1. Defectmissing counterparty evidence

    Repeated across cases

  2. Causesource field not collected

    Upstream issue

  3. Fixrepair data capture

    More training alone is insufficient

The defect may begin before the analyst sees it

Fictional teaching record. More training alone is insufficient. Chapter sources · Open image
Use quality review and feedback — control and failure modes
Use quality review and feedback Use quality review and feedback — control and failure modes The defect may begin before the analyst sees it. The branches show why alternative designs fail. Control design Link quality findings to their root cause. The defect may begin before the analyst sees it. Failure mode 1 Measure only cases per hour. Speed can hide incomplete work. avoid Failure mode 2 Review only filings. Weak non-filing decisions remain unseen. avoid Failure mode 3 Close findings after training attendance. Effectiveness requires later evidence. avoid
Control design

Link quality findings to their root cause. The defect may begin before the analyst sees it.

Failure mode 1avoid
Measure only cases per hour. Speed can hide incomplete work.
Failure mode 2avoid
Review only filings. Weak non-filing decisions remain unseen.
Failure mode 3avoid
Close findings after training attendance. Effectiveness requires later evidence.
The defect may begin before the analyst sees it. The branches show why alternative designs fail. Chapter sources · Open image

Chapter connections

This chapter builds on Transaction monitoring and alert quality. Use the glossary for terminology and risk mathematics for formulas and worked calculations.

Sources

Reviewed 2026-09-17
  1. FFIEC: suspicious activity reporting
  2. FinCEN: SAR confidentiality advisory FIN-2010-A014
  3. FinCEN and banking agencies: September 2, 2026 statement on SAR confidentiality and customer communications