A payments analyst at a brokerage notices that a client funded an account from three different cards in two names, traded for four days without ever holding a position past the close, and requested a withdrawal to a bank account in a fourth name. Nothing about the trading is prohibited. Every deposit cleared. The client passed identity checks at onboarding. The analyst still has to escalate, because the pattern has no economic explanation and that is the whole test.
What follows is a suspicious activity report, called a suspicious transaction report in some jurisdictions, filed with the national financial intelligence unit. It is not an accusation and it is not a decision. It is a disclosure of facts and of the reason those facts looked wrong.
The trigger is suspicion, not proof
Reporting regimes across the FATF-aligned world set the threshold at knowledge or suspicion of money laundering or terrorist financing, and in most cases at reasonable grounds for suspicion, which is an objective test. Nobody is required to prove anything. A firm that waits until it is sure has waited too long, and the waiting itself becomes a supervisory finding.
What raises suspicion in trading firms is usually structural rather than dramatic. Funding that does not match the declared source of funds or the stated income. Deposits and withdrawals with minimal trading in between, which is the classic pass-through pattern. Third-party payment instruments. Sudden changes in behaviour after a dormant period. Reluctance to answer routine questions. A client in a jurisdiction on the FATF grey list combined with any of the above.
Trading-specific patterns matter too. Coordinated positions across multiple accounts that net out, transfers of value between related accounts through deliberately losing trades, and account activity that looks designed to move money rather than to seek a return.
The two-stage route: internal report, then the MLRO
Staff do not file with the authorities. They file internally, to the money laundering reporting officer, and the MLRO decides whether the internal report becomes an external one. That split exists for a reason: it keeps the decision with one accountable person and it protects the employee, whose duty is discharged by escalating rather than by being right.
Two things have to be documented at that stage. Every internal report, and every decision not to escalate it, with the reasoning. A compliance function with no record of the reports it declined to file looks identical, on inspection, to one that never received any. The negative decisions are usually what a regulator reads first, because they show whether judgement is being exercised or avoided.
Deadlines vary. Some regimes require filing promptly or without delay, others set a specific window from the moment suspicion arose. The date suspicion arose therefore needs to be recorded, not reconstructed later.
Filing a report does not authorise closing the account, freezing the balance or refusing a withdrawal on its own. Some jurisdictions offer a consent regime for transactions the firm wants to complete while a report is pending. Local legal advice is required here, and this article is not it.
Tipping off
Telling the client that a report has been made, or that one is being considered, is a criminal offence in most AML regimes. So is any disclosure likely to prejudice an investigation. This is the part that catches operational teams, because the natural instinct of a support agent facing an angry client is to explain.
The practical consequences run through the whole firm. Support scripts must give a neutral reason for a delay without inventing a false one. Withdrawal screens must not display an internal status that hints at a report. Access to the SAR record has to be restricted to the compliance function, not visible to every agent who opens the client profile. A CRM that exposes an AML flag in a general note field is a tipping-off risk built into the software, and it is the reason our Broker CRM keeps compliance case notes on a separately permissioned record rather than in the ticket thread.
Training has to cover this explicitly, with the wording staff are allowed to use. Most tipping-off breaches are not deliberate. They are an agent being helpful.
What goes in the report
Identification of the subject, the accounts and the transactions. A clear narrative of what happened and why it looked suspicious, in chronological order. The supporting documents the firm holds. Financial intelligence units generally publish their own format, and many now require electronic submission through a portal with a defined schema.
The narrative is the part that determines whether the report is useful. A filing that says the activity appeared unusual gives an analyst nothing. One that says the client declared employment income of a stated range, deposited a much larger sum within eleven days across instruments in two other names, and withdrew to an unrelated account, gives them a case. Write for a reader who has never seen your platform.
Building the duty into the operation
Firms that handle this well have three things. Automated detection that surfaces patterns a human would not spot across thousands of accounts, tuned so the alert volume stays reviewable. An escalation path any employee can use in one step, without asking their manager first. And an audit trail that timestamps who saw what and when, which is the only evidence a firm has when a supervisor asks why a pattern ran for six weeks before anyone reported it.
None of that is optional once a licence is held. Reporting failures are among the most commonly cited deficiencies in supervisory examinations of regulated brokers, and they are cited because they are easy to evidence: the transactions are in the records, and either a report exists or it does not.
"The report itself is the easy bit. What separates a working compliance function from a paper one is whether the analyst who noticed something odd on a Tuesday felt able to say so."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- The threshold for reporting is suspicion or reasonable grounds for suspicion, never proof, and waiting for certainty is itself a finding.
- Staff report internally to the MLRO, who decides on external filing. Decisions not to file must be documented with reasons.
- Tipping off is a criminal offence in most regimes, so support scripts, withdrawal screens and CRM permissions all have to be designed around it.
- A useful report has a chronological narrative written for someone who has never seen your platform, not a note saying the activity looked unusual.
Frequently Asked Questions
Who files a suspicious activity report at a brokerage?
Employees file internally to the money laundering reporting officer. The MLRO assesses the internal report and decides whether to file externally with the national financial intelligence unit.
Can we tell a client that we filed a report about them?
No. Disclosing that a report has been made or considered, or anything likely to prejudice an investigation, is a criminal offence in most AML regimes and is known as tipping off.
Does filing a report mean we must close the account?
Not automatically. Whether the relationship continues, and whether a pending transaction may proceed, depends on the local regime and often on a consent process. Take local legal advice.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.