Rail Governance

Bank Secrecy Act Suspicious Activity Reporting Obligations for AI-Initiated Transactions

Banks must document how AI models flag suspicious activity in ways regulators can actually evaluate.

Editorial team · · 10 min read
Cover illustration for “Bank Secrecy Act Suspicious Activity Reporting Obligations for AI-Initiated Transactions”
OCC and Fed Rulemaking · October 7, 2026 · 10 min read · 2,150 words

The Bank Secrecy Act asks something simple on paper: keep records and file reports that are useful to the people investigating crime, tax fraud, and regulatory violations. The statute itself, at 31 U.S.C. 5311, frames the goal as records and reports with "a high degree of usefulness in criminal, tax, or regulatory investigations." That phrase only works if there's a human decision sitting behind each transaction, one an investigator can trace back to a person who chose to act.

Two reporting instruments carry most of that weight. The Currency Transaction Report covers cash transactions over $10,000 in a single business day, filed within a set number of days. The Suspicious Activity Report covers conduct that crosses a specified threshold for banks, but the bar is lower for money services businesses. Both forms assume someone noticed something and decided to write it down.

The SAR comes with a clock. Once an institution detects facts that might warrant a filing, it has 30 calendar days to file. If no suspect has been identified, the institution can take an additional 30 days, but the outer limit is 60 calendar days from initial detection, full stop. That timeline assumes detection is a discrete event, something a person can point to and say: this is when we knew.

A five-pillar compliance structure underlies the SAR and CTR: internal controls, independent testing, a designated officer, training, and customer due diligence, the last one formalized by the 2016 CDD Rule. Every pillar assumes a human runs it. The controls get tested. Someone holds the title of designated officer and answers for the program. Someone trains the staff.

A recordkeeping mandate underlies all of it: a financial institution's records need to be detailed enough that transactions and account activity can be reconstructed if an investigator ever needs to go back and look. That requirement isn't new, and it isn't unique to AI. But reconstructing what a human teller did when a customer walked up to a counter is a different kind of problem than reconstructing what a model decided when it scored a transaction and moved on. That difference is where the next layer of this piece starts.

How AI-initiated transactions strain each of those baseline requirements

An AI agent that originates, routes, and executes transactions on its own doesn't violate the BSA by existing. It strains the assumptions the BSA was quietly built on, turning things that used to be automatic compliance checkpoints into open questions.

Start with authorization. Most payment regimes require a payment order traceable to an authorized instruction from an account holder or a legally recognized agent acting on their behalf. Agent-initiated payments complicate that picture because a single transaction might not map to any specific, transaction-level instruction a human gave. The authorization becomes structural, baked into a standing mandate the agent operates under rather than a one-time decision a person made in the moment. That shift raises real questions about who's traceable and who's liable when something goes wrong.

Then there's the legal personhood gap. An AI agent can't hold a bank account, can't own property, and can't sign anything in its own name. It acts on credentials a human sponsor hands it. That concentrates the entire compliance weight onto the sponsoring institution and whoever inside it granted the access, since there's no other legal actor to point to.

The detection clock runs into a similar problem. The 30-to-60-day SAR window assumes a human detected something specific at a specific time. When a model flags a transaction, escalates it, or dismisses it without anyone reviewing the output, when exactly did detection happen? Does the clock start when the model scores the transaction? When the score crosses whatever threshold triggers an alert? When a human analyst finally opens the file and reads what the model found? The statute doesn't say, because the statute was never written with this sequence in mind.

The five-pillar structure runs into the same wall from a different angle. It assumes a designated officer with real authority can attest to the program and be held responsible for it. When AI agents are executing transactions at scale, figuring out who that officer actually is, and what they can honestly attest to, stops being obvious.

Volume makes all of this harder to manage. The recordkeeping mandate requires that transactions be reconstructable, and at the volumes an AI agent can generate, reconstruction without machine-readable audit lineage becomes practically impossible. Automation doesn't shrink the compliance burden here. It scales it, transaction by transaction, in direct proportion to how fast the system runs.

What the SAR narrative requires when a model decides

FinCEN Form 111 requires a narrative: a plain-language account of the specific behaviors, transactions, or patterns that led to the filing. That requirement was written for a human investigator describing what another human did. It doesn't map cleanly onto the output of a probabilistic model.

Form 111 also calls for supporting documentation behind that narrative. In an AI-driven fraud detection setup, the natural candidate for that documentation is something like a SHAP (SHapley Additive exPlanations) feature attribution, paired with a model output audit trail. SHAP values show which inputs pushed a model's score up or down and by how much. That's useful information. But FinCEN has issued no formal guidance on how, or whether, model outputs like these should be folded into a SAR narrative.

The practical problem appears the moment a regulator asks why a specific transaction got flagged. An answer built around ensemble probability scores and feature weights is technically accurate. It's also not the kind of answer examiners are trained to evaluate, because examiners are trained to judge human reasoning, not model architecture. A narrative that says "the model weighted transaction velocity and merchant category at 0.31 and 0.24 respectively" is a true statement and an unsatisfying one.

One research framework integrating OCC guidance, SR 11-7, CFPB expectations, and FinCEN requirements treats SHAP reason codes as SAR supporting documentation and model output audit trails as the artifact examiners would review. The research framework offers a workable practitioner solution. It is not a regulatory standard, and no agency has adopted it as one.

A fair objection here is that rule-based alert systems have always had some version of this problem, so maybe this isn't new. It doesn't hold up under scrutiny. A rule-based system produces a direct logical chain: transaction X crossed threshold Y, which triggered rule Z. That chain translates into a narrative sentence almost word for word. A model's output is probabilistic and feature-weighted, built from the interaction of dozens of signals. The gap between what the model produces and what a narrative requires is a different kind of gap than the rule-based version, not merely a bigger one.

That gap cuts both ways in practice. A model can over-suppress, dismissing alerts a human reviewer would have filed on. It can also over-report, flagging at a volume that buries genuine suspicious activity under noise. Both outcomes are SAR quality failures, and both carry real examination consequences. Institutions are currently writing their own engineering solutions into a space where FinCEN has stayed silent, and silence from a regulator is rarely a sign that scrutiny won't follow.

Where the accountability chain breaks

If the narrative behind a SAR is incomplete or wrong, someone has to answer for it. The BSA puts that obligation on the institution and its designated officer, not on whoever built the AI system. That assignment doesn't move just because the transaction was executed by software instead of a person.

Nothing about the examination structure changes either. The OCC conducts regular examinations of national banks to check BSA compliance, and it takes enforcement action when the required controls aren't in place. An AI system sitting inside the transaction chain doesn't shift who gets examined. The bank is still the target, regardless of what's making the decisions upstream.

What's unresolved is upstream of that: when an agentic AI system makes an incorrect or fraudulent payment, current U.S. law doesn't clearly say whether the user who configured the agent, the developer who built it, the bank that enabled execution, or some other party carries primary responsibility. Until that gets clarified, the question of who answers for AML and KYC compliance on any given agent-initiated transaction stays open.

Regulation E adds another layer of ambiguity. It defines an unauthorized electronic fund transfer as one "initiated by a person other than the consumer without actual authority." Whether a consumer handing an AI agent access to their account counts as granting that authority hasn't been settled. That question has a direct bearing on which entity ends up holding the SAR obligation once an agent-initiated transfer turns suspicious.

All of this lands on the designated BSA officer in a very concrete way. That officer has to attest to the program's effectiveness. If the officer can't explain how the AI system reaches its alert and dismissal decisions, that attestation doesn't mean much, and an examiner can reach that conclusion without the bank ever having filed a single defective SAR. The weakness is structural.

Willful BSA violations carry real penalties, fines and prison time that rise as high as $500,000 and longer sentences for aggravated cases. Those numbers were calibrated with a human decision-maker in mind, someone who knew what they were doing and did it anyway. Whether "willfulness" applies to an institution that deployed an AI system it didn't fully understand remains unanswered, and enforcement action is the likeliest place an answer will come from.

Regulators' Rules for AI-Mediated SAR Obligations

Regulators haven't put out a comprehensive AI-specific BSA overhaul, and there's no sign one is imminent. What they're doing instead is issuing targeted guidance, joint statements, and supervisory supplements, piece by piece, and institutions need to be tracking each one as it lands.

The clearest recent signal came on September 2, 2026, when the OCC, the Federal Reserve, the FDIC, FinCEN, and the NCUA issued a joint statement on SAR confidentiality. It addresses when banks can communicate with customers about potentially fraudulent transactions. The statement holds that the BSA prohibits disclosing a SAR or anything that would reveal a SAR exists, but that confidentiality requirement doesn't stop a bank from discussing the underlying facts, transactions, and documents the SAR is based on. Banks are told to weigh customer communication case by case.

That line, underlying facts are discussable, the SAR's existence is not, gets harder to hold in an AI-mediated environment. If an AI agent flags a transaction and the customer sees that flagging happen through the interface itself, maintaining the separation between discussing facts and revealing a SAR's existence becomes a design problem as much as a compliance one.

A related signal followed less than a week later. The OCC issued an FAQ on September 8, 2026, addressing how verifiable digital credentials should be treated under the Customer Identification Program Rule. Taken together with the SAR confidentiality statement, it points to the same thing: identity verification in AI-mediated and digital-credential-based transactions is an active examination concern right now, not a future one.

The five agencies have also said directly that they want banks taking innovative approaches to meet BSA and AML obligations. That's a permissive stance, so read it carefully. Permission without specific guidance doesn't remove risk. It shifts the interpretive risk onto the institution making the call. The bank, not the regulator, absorbs the consequences if its interpretation turns out wrong at examination time.

What an AI-governed SAR process needs

None of this requires waiting on new AI-specific BSA rules. The existing framework, read closely, already tells institutions what an AI-driven SAR process has to do to hold up under examination.

Audit lineage comes first, and it isn't optional. The recordkeeping mandate requires that transactions and account activity be reconstructable. For an AI-driven process, that means logging the model's scoring, its alert generation, its escalation decisions, and its dismissal rationale, all at a level of detail that lets someone reconstruct, after the fact, why a specific transaction was flagged or why it wasn't. A log that captures the transaction but not the model's state at the moment of decision doesn't meet that bar.

Human review needs to sit at defined points in that process, specifically at the moment a transaction crosses into SAR-filing territory. The decision that a transaction meets the reporting threshold shouldn't run on full automation. A defined human review step, with documented rationale behind it, keeps the accountability chain the BSA assumes intact, and it gives the designated officer something real to point to when attesting that the program works.

Together, those two pieces give the institution a process that answers the law's original question in a new context, closing the gap this piece has been mapping: who decided, and can it be reconstructed. That question was always the heart of the BSA. AI hasn't changed what it's asking. It's changed how hard the answer is to produce.

Sources

  1. A Regulatory Governance Framework for AI-Driven Financial Fraud Detection in U.S. Banking: Integrating OCC, SR 11-7, CFPB, and FinCEN Compliance Requirements for Model Development, Validation, and Monitoring Lifecycles
  2. Suspicious Activity Reporting: Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers
  3. Bank Secrecy Act (BSA)
  4. BANK SECRECY ACT, ANTI-MONEY LAUNDERING, AND OFFICE OF FOREIGN ASSETS CONTROL

More in OCC and Fed Rulemaking