AI-Assisted SAR Narrative Drafting
It is Thursday afternoon and James, a senior BSA analyst at a mid-sized commercial bank, has just completed a three-week investigation into a network of accounts showing coordinated layering activity: cash deposits split across multiple accounts in the same beneficial owner structure, followed by rapid outbound wire transfers to three foreign correspondent accounts. The investigation is solid. The suspicious activity is documented, the connection between the accounts is established, the pattern matches a known typology in the FinCEN (Financial Crimes Enforcement Network) advisory library, and James has made the judgment call that a Suspicious Activity Report (SAR) filing is required. Now he has to write the narrative. The SAR narrative is where many investigations stall. It is a structured regulatory document that must accurately describe the suspicious activity, name every involved party, cite specific dates and dollar amounts, identify the method of transaction, and include a clear statement of why the activity was deemed suspicious. For a complex multi-account investigation, a complete and well-written narrative might run 1,500 to 2,500 words. At an institution that files 50 to 150 SARs per month, narrative drafting consumes a significant share of BSA analyst time. James opens an AI drafting tool and pastes the structured case data. What happens next, and what must not happen next, is the subject of this lesson.
What a SAR Is and Why the Narrative Matters
A Suspicious Activity Report (SAR) is a federal regulatory filing submitted to the Financial Crimes Enforcement Network (FinCEN), a bureau of the Treasury Department, when a bank suspects that a customer has engaged in a financial transaction involving funds from illegal activity, is attempting to avoid BSA reporting requirements, or is otherwise engaged in financial crime. The BSA (Bank Secrecy Act) requires banks to file SARs within 30 days of detecting suspicious activity, or within 60 days if no suspect was identified at the time of initial detection, to allow identification of a subject. The SAR carries significant legal consequences: it is protected from disclosure to subjects under safe-harbor provisions, it goes directly into FinCEN's financial intelligence database (which law enforcement uses to build cases), and knowingly filing a SAR with false information is a federal crime.
The SAR has four major data components. The header section identifies the filing institution, the reporting officer, and the filing date. The subject information section identifies every person or entity involved in the suspicious activity with as much identifying information as the bank can provide. The transaction information section records the specific transactions that constitute the suspicious activity, with amounts, dates, types, and account numbers. The narrative section is where the analyst explains, in plain and complete prose, what the suspicious activity was, why it was considered suspicious, who was involved, what transactions occurred, and what investigative steps were taken.
The narrative is the most consequential part of the SAR for two reasons. First, it is the section that law enforcement actually reads when they use a SAR as an investigative lead. A narrative that is vague, incomplete, or poorly organized may cause a SAR that represents important intelligence to be deprioritized or ignored. A narrative that is clear, specific, and well-organized can directly support an investigation. Second, the narrative is the section that examiners read when they review a bank's SAR filings for program quality. A narrative that does not describe the suspicious activity coherently, that omits parties or transactions, or that states the wrong reason for suspicion may indicate that the underlying investigation was inadequate regardless of what the case file contains.
The Bank Secrecy Act does not prescribe the exact format of a SAR narrative, but FinCEN guidance and the FFIEC (Federal Financial Institutions Examination Council) BSA/AML Examination Manual both describe what a complete narrative must address: the specific activity that raised the suspicion (who, what, when, where, and how), the reason the activity was considered suspicious rather than lawful, any explanations offered by the subject and why they were rejected or insufficient, and a statement of the type of suspicious activity using the appropriate activity category from the SAR form. An examiner who opens a SAR narrative and cannot quickly identify those elements is looking at an incomplete filing.
How AI Drafting Works in a SAR Workflow
Generative AI, specifically large language model (LLM) tools that can process structured input and produce coherent narrative prose, can assist BSA analysts with SAR narrative drafting in a workflow that captures significant time savings while preserving the human oversight that the regulatory framework requires.
The AI drafting workflow begins with structured case data, not an open-ended conversation. The analyst (or the case management system, if the institution has integrated AI with its BSA platform) provides the model with the key structured elements of the case: the subject names and identifying information, the account numbers involved, the specific transactions (dates, amounts, types, counterparties), the alert types that triggered the investigation, the BSA analyst's notes on what was found and why it was considered suspicious, and the conclusion of the investigation including the SAR activity category selected. The AI model is then prompted to draft a SAR narrative from these inputs, organized according to the standard SAR narrative structure.
A well-structured prompt for SAR narrative drafting includes explicit constraints: the output should cover who was involved, what transactions occurred, when they occurred, why the activity was considered suspicious, what investigative steps were taken, and what conclusion was reached. The prompt should also specify the tone (regulatory, factual, not interpretive), the level of detail (specific amounts and dates are required, not approximations), and the boundary of what the model should not do (do not infer information not in the provided case data, do not add context from general knowledge about financial crime, do not speculate about the subject's intent beyond what the facts support).
A well-executed AI-drafted SAR narrative, starting from complete and accurate case data, can be ready for analyst review in under two minutes. For a narrative that would otherwise take 45 to 90 minutes to draft manually, that represents a substantial time saving. At an institution filing 100 SARs per month, the drafting time reduction alone can free up 60 to 120 analyst hours per month for investigative work. That is the operational argument for AI-assisted SAR drafting.
The Verification Requirement: Every Fact in the Draft
The operational argument for AI drafting is real and the efficiency gain is genuine. But the verification requirement that follows AI drafting is absolute, and understanding why is essential to running a compliant SAR program.
A SAR is a sworn regulatory document. The BSA officer who certifies the SAR is attesting, under penalty of law, that the information in the filing is accurate and complete to the best of their knowledge. Certifying a SAR narrative that contains inaccurate information, even if the inaccuracy was introduced by an AI tool, is the certifying officer's legal problem. The AI vendor does not certify SARs. The AI model does not face penalty exposure for false filings. The named compliance officer does.
This is not a hypothetical risk. AI-generated narratives can introduce errors through several mechanisms. The model may misread structured data (transposing a date, swapping an amount between two transactions, attributing a wire to the wrong account). The model may generate plausible-sounding sentences about the investigation that are not grounded in the specific case data (inferring that the subject "appears to have knowledge of BSA reporting thresholds" when the case notes contain no evidence of that). The model may omit relevant facts that were in the case notes but did not match the model's expectations of what a SAR narrative should emphasize. The model may, in composing a coherent narrative, smooth over ambiguities or uncertainties that should be explicitly acknowledged rather than resolved in the draft.
Every one of these error types has the potential to produce a SAR that contains inaccurate information, and every inaccuracy in a SAR is potentially a compliance failure. The verification step is not a quality check on the AI's prose style. It is a line-by-line confirmation that every factual statement in the draft is supported by the case file. The analyst who verifies the draft must be able to answer, for each sentence that contains a factual claim, the question: where in the case file is the evidence for this claim?
In practice, efficient verification involves reviewing the AI-generated narrative against the structured case data point by point: checking each named subject against the subject information in the case file, checking each transaction amount, date, and type against the transaction records, checking each statement about the investigation against the analyst's case notes, and checking the narrative's statement of why the activity was suspicious against the analyst's own documented assessment. This is not a 30-second scan. For a complex multi-account case, thorough verification may take 20 to 40 minutes. That is still substantially faster than drafting from scratch, and the verification process is also the analyst's final read-through of the case as a whole, which often surfaces details that should be in the narrative but were not in the initial structured input.
The Auto-File Prohibition and Why It Is Absolute
No AI tool should ever auto-file a SAR. This is not a best practice. It is a regulatory bright line with legal consequences that are severe enough to make the sentence worth repeating in every discussion of AI in BSA programs: no AI tool should ever auto-file a SAR.
The prohibition exists for reasons that go beyond the accuracy concern. The SAR certification requirement (the attestation by a named compliance officer that the filing is accurate and complete) is a legal obligation that cannot be delegated to a machine. There is no mechanism in the BSA regulatory framework for an institution to designate an AI system as a compliance officer or to transfer the certification responsibility to an automated process. The SAR must be reviewed and certified by a human being who has the authority and the accountability to make that certification. An auto-filed SAR has no human certifier and therefore does not meet the statutory filing requirement, regardless of the accuracy of its contents.
Beyond the certification requirement, the SAR filing decision itself requires human judgment that AI cannot reliably provide. The standard for SAR filing under the BSA is that the bank suspects that a transaction or pattern of transactions involves funds from illegal activity, or that the customer is attempting to evade BSA reporting requirements, or that no reasonable lawful explanation exists for the activity after investigation. That suspicion determination requires the analyst to weigh the specific facts of the case against their knowledge of the customer, the institution's community, and the applicable typologies. It requires weighing explanations the customer provided against the totality of the evidence. It requires a professional judgment about whether the evidence crosses the threshold for required filing versus whether it warrants continuing enhanced monitoring without a SAR.
AI can inform that judgment. AI cannot make it. A model that auto-files SARs is making the suspicion determination without human review, and the institution has lost control of the regulatory filing process. The consequences of that loss of control run in both directions. False positive SARs filed without proper human review expose innocent customers to law enforcement attention, damage the institution's relationship with legitimate customers, and waste law enforcement resources on non-suspicious activity. False negative SARs that should have been filed but were not because the AI model did not score them above an auto-file threshold represent program failures that create examination exposure and, in serious cases, potential civil money penalties.
The human investigator who reviews the AI-drafted narrative and makes the filing determination is not a rubber stamp. They are the control that the regulatory framework requires and that protects the institution from both over-filing and under-filing. The AI drafting capability is valuable precisely because it frees the analyst from the mechanical writing task so they can focus on the judgment task that cannot be automated: is this activity suspicious enough to file?
Constructing a Complete SAR Narrative: Walked Through
To make the AI-assisted drafting workflow concrete, consider a worked example. The scenario is a structuring investigation involving a sole proprietor who operates a cash-intensive landscaping business. The rule-based monitoring system generated alerts on three consecutive months of transactions in which the business owner made multiple cash deposits per week, each below $10,000, totaling between $45,000 and $55,000 per month. The analyst investigated, found no invoices or other business records on file to support the claimed business volume, and noted that the deposit pattern is inconsistent with the seasonal nature of landscaping work in the institution's northern market (the deposits continued through winter months at the same rate as summer months).
The structured case data the analyst provides to the AI drafting tool includes: subject name and account number, the monthly totals and transaction-level details for the three months under investigation, the alert types that triggered the investigation (cash structuring alerts), the analyst's notes about the absence of business records and the seasonal anomaly, the subject's explanation (provided verbally in a customer interview: "I collect from clients as the work is done"), the analyst's assessment of why the explanation was insufficient (seasonal work pattern does not support winter volumes), and the conclusion (SAR filing recommended, activity type: structuring).
The AI drafts a narrative that opens by identifying the subject and account, describes the cash deposit pattern with specific monthly totals and transaction frequency, notes the investigation triggered by transaction monitoring alerts, documents the customer interview and the explanation provided, explains why the explanation was not sufficient to address the suspicion (seasonal business with winter deposit volumes inconsistent with the service offered), and concludes with the recommendation that the activity category is "structuring" under the SAR form classifications.
The analyst's verification pass confirms: each monthly total matches the transaction records, the transaction frequency description is accurate, the customer interview notes are accurately reflected, the seasonal anomaly is stated correctly (the analyst checks the state's average frost dates to confirm the winter seasonality claim is grounded), and the activity category selection is appropriate. The analyst revises two sentences where the AI description was slightly imprecise: the AI described deposits as "daily" when the actual pattern was four to five times per week, and it characterized the customer interview as occurring "at the branch" when the analyst's notes indicate it was a phone call. Both corrections are substantive, not stylistic. They matter because a SAR that states the interview was at the branch when it was a phone call is inaccurate, and if that SAR becomes part of a law enforcement investigation, the discrepancy is a credibility issue.
After verification, the analyst certifies the accuracy of the narrative and the compliance officer reviews and certifies the full SAR before filing. The total time from structured data to filed SAR: approximately 45 minutes. Without AI drafting, the analyst estimated the narrative alone would have taken 75 to 90 minutes. The time saving is real. The verification step is what makes it defensible.
When the Case Is Complex: Multi-Account Investigations
SAR narrative drafting for multi-account, multi-entity investigations requires more care than the straightforward structuring example above. When the suspicious activity involves multiple accounts at the same institution, related entities with common beneficial owners, counterparty accounts at other institutions, and transactions spanning months or years, the narrative must integrate a large volume of specific factual detail without becoming incomprehensible.
AI drafting tools can handle complex multi-account cases, but the quality of the output depends heavily on the quality and organization of the structured input. An analyst who provides a well-organized case summary with clearly labeled sections for each account, each subject, and each transaction cluster will get a far more coherent draft than an analyst who provides a stream-of-consciousness case note and asks the AI to turn it into a narrative. The investment in organizing the case data before drafting pays dividends in both the quality of the AI output and the efficiency of the verification step.
For complex cases, the verification step should be organized by account and by subject, not by reading the narrative from start to finish. The analyst should verify all facts about Account A before moving to Account B, rather than checking facts as they appear in the narrative order, which may interleave information from multiple accounts in ways that make verification harder to track. A verification checklist, built in the case management system or on paper, with a line for each factual claim that requires source confirmation, is a practical tool that also produces a documentation record of the verification process itself.
FinCEN has published guidance on SAR narrative quality that is worth consulting as a drafting standard. The guidance emphasizes completeness (all parties, all transactions, all relevant investigative steps), specificity (amounts and dates, not approximations), clarity (a law enforcement reader unfamiliar with the institution's systems should be able to understand the narrative), and appropriate use of the "5 Ws" structure (who was involved, what transactions occurred, when they occurred, where they occurred, and why the activity was considered suspicious). AI-drafted narratives that are evaluated against these criteria, and revised by the analyst to address any gaps, are more likely to function as useful law enforcement intelligence and more likely to withstand examination review.
Regulatory and Governance Requirements for AI SAR Drafting
Using AI tools in the SAR drafting workflow creates several governance obligations that BSA program managers need to address explicitly. OCC Bulletin 2026-13 brings generative AI tools used in regulatory filing processes within the scope of model-risk management. This means the AI drafting tool, like the transaction monitoring prioritization model, requires model-inventory documentation, use-case documentation, and a governance trail showing who approved the use of AI in the SAR drafting workflow and under what constraints.
The institution's BSA policy should address AI drafting explicitly. The policy should state that AI tools may be used to generate draft SAR narratives from structured case data, that every factual claim in the AI-generated draft must be verified against the case file before the SAR is filed, that the verification process must be documented in the case record, that the SAR must be reviewed and certified by a named compliance officer, and that no SAR may be filed directly from AI-generated output without human review and certification. Each of these policy elements corresponds to a specific regulatory requirement; together they constitute the governance framework that protects the institution if an examiner asks how AI is used in the SAR filing process.
The institution should also maintain a log or record of which SARs were drafted with AI assistance. This serves two purposes. It enables the institution to analyze the performance of the AI drafting tool over time (are AI-drafted SAR narratives being revised significantly by analysts, suggesting the tool's output quality is poor for certain case types?). It also enables the institution to respond to any examiner question about AI use in the BSA program with a specific and documented answer rather than an estimate.
When a vendor-supplied AI tool is used for SAR drafting, the institution retains full responsibility for the accuracy of the SAR. OCC 2026-13 is explicit that third-party model risk obligations do not transfer to the vendor. The institution must conduct or obtain third-party validation of the AI drafting tool's performance, document that validation, and include the tool in the institution's model-risk monitoring program. The vendor's representation that their tool is "accurate" or "compliant" is not a substitute for the institution's independent validation obligation under the bulletin.
Key Takeaways
- A SAR (Suspicious Activity Report) is a federal regulatory filing submitted to FinCEN (Financial Crimes Enforcement Network) when a bank suspects financial crime. The narrative section is the most consequential part of the SAR for law enforcement utility and examiner review, and it is the section where AI can generate the most time savings in the drafting process.
- AI drafting tools can produce a complete SAR narrative from structured case data in under two minutes. For a narrative that would take 45 to 90 minutes to write manually, this represents a substantial time saving that frees analyst time for investigation work. The drafting capability is valuable and real; it does not eliminate the verification obligation.
- Every factual claim in an AI-generated SAR narrative must be verified against the case file before the SAR is filed. The verification step is not a quality review of the AI's prose. It is a line-by-line confirmation that every statement of fact in the draft is accurate and supported by the case record. Errors introduced by AI drafting (transposed dates, incorrect amounts, inferences not grounded in the case file) must be caught at this step.
- No AI tool should ever auto-file a SAR. The BSA certification requirement mandates that a named compliance officer attest to the accuracy of the filing as a human judgment. There is no mechanism in the regulatory framework for delegating that certification to an automated process. Auto-filing a SAR is not a governance shortcut. It is a regulatory violation.
- The SAR filing decision (the determination that activity is suspicious enough to warrant a regulatory filing) requires human judgment about whether the evidence crosses the suspicion threshold after weighing all available explanations and facts. AI can inform that judgment by drafting the narrative and organizing the evidence. AI cannot make that judgment for the analyst or the compliance officer.
- Under OCC Bulletin 2026-13, AI tools used in SAR drafting are subject to model-risk governance requirements: the tool must appear in the model inventory, its use must be documented in the BSA policy, and the institution retains full responsibility for the accuracy of AI-assisted SAR filings regardless of whether the drafting tool was built internally or purchased from a vendor.
- Complex multi-account SAR narratives benefit from organized structured input before AI drafting, and from account-by-account verification rather than a linear read-through of the narrative. A verification checklist that records the source confirmation for each factual claim produces both a quality control record and a documentation artifact that demonstrates the institution's verification process to an examiner.
Skill.re