What problem does it solve?
When an investigation concludes that activity is suspicious, the investigator must write a report to the financial intelligence unit. The narrative is the only free text part of the report, and it has to explain who was involved, which accounts and transactions, over what period, what typology it resembles and why it is suspicious, clearly and completely. FinCEN's narrative guidance warns that incomplete, incorrect or disorganized narratives make further analysis by law enforcement difficult, if not impossible.
Writing it is slow. Investigators copy transaction tables, reconstruct timelines from statements and case notes, and write prose under deadline pressure, since reports must be filed within a fixed period after detection (in the United States, as FinCEN's guidance restates, no later than 30 calendar days after initial detection). Quality varies between investigators, and quality assurance teams send drafts back for missing facts or unclear reasoning. Time spent writing is time not spent investigating.
How does it work?
- Assemble the facts. The agent gathers the case file: alerts, customer due diligence, transactions, counterparties, previous reports, investigator notes and any external requests.
- Build the timeline. It orders the relevant transactions and events and computes totals, date ranges and counterparties, using data queries rather than the language model for numbers.
- Draft the narrative. It writes the narrative in the structure the financial intelligence unit expects, with each statement referencing the record it comes from.
- Check completeness. It checks the draft against the filing guidance (subjects, instruments, dates, amounts, locations, reason for suspicion) and flags anything missing.
- Investigator attests. The investigator verifies each fact, edits the reasoning, and files. The draft, the edits and the final version are retained.
- Audience
- Employee facing
- Autonomy
- Copilot
- Adoption
- Emerging
- Channels
- Internal tools, Agent desktop
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Employee productivity, Compliance quality, Speed and cycle time.
Indicative value
A bank filing 5,000 suspicious activity reports a year
USD 101,250 to USD 800,000
Investigator capacity released per year
How this is calculated
Formula: reports * hoursPerNarrative * timeSaved * costPerHour. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Reports filed per year reports, reports per year | 5,000 | 5,000 | The reference bank. |
| Investigator hours spent drafting each narrative today hoursPerNarrative, hours per report | 1.5 | 4 | Editorial assumption. Replace with your own time study. |
| Share of drafting time saved timeSaved, fraction of drafting time | 0.3 | 0.5 | Editorial assumption. Verification and editing time remain with the investigator, and public results so far are vendor reported and measure alert review rather than drafting alone (for example Uphold's 44% faster median alert review in a pilot); replace with results from your own pilot. |
| Fully loaded investigator cost per hour costPerHour, USD per hour | 45 | 80 | Editorial assumption. Replace with your own. |
What it leaves out: Counts drafting time only. It leaves out quality assurance rework avoided, better reports for law enforcement, and the cost of validating and running the drafting system.
Who already uses it?
4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Nexo
Europe · Payments and cards · 2026
Digital asset services company Nexo uses Unit21's transaction monitoring and case management with AI agents that automate alert narratives and dispositions. Analysts work in a supervisory role, verifying the AI generated output, investigating anomalies and applying judgment. The vendor reports that a majority of alert reviews are now automated, with further automation projected.
- Automation rate: 57%, share of alert reviews automated
"By automating alert narratives and dispositions, Unit21’s AI Agents have enabled Nexo to achieve 57% automation in alert reviews, with projections to reach up to 80% as the models continue to evolve."
Claimed by: vendor
Uphold
United States · Payments and cards · 2026
Crypto platform Uphold unified alerts, cases and regulatory filings with FinCEN and FINTRAC in Unit21, and piloted Unit21's AI agent to help analysts review alerts faster and more consistently. The vendor reports a drop in median alert review time from the pilot and predicts much faster suspicious transaction report preparation, which has not yet been measured.
- Handling time reduction: 44%, median alert review time during the pilot
"Median alert review time has dropped by 44% thanks to a pilot of Unit21’s AI Agent, which helps analysts process alerts faster and more consistently."
Claimed by: vendor
BMO and Amalgamated Bank
North America · Banking · 2026
FIS announced in May 2026 that it is building a Financial Crimes AI Agent with Anthropic that assembles evidence across a bank's core systems for anti money laundering alert and case investigations and supports suspicious activity report narratives. BMO and Amalgamated Bank are developing with the agent, and FIS plans general availability in the second half of 2026. The release states aims for investigation time and narrative quality but no measured results.
No outcome disclosed.
Finshark
Sweden · Payments and cards · 2024
Swedish open banking and instant payments company Finshark uses Lucinity's case manager with the Luci AI copilot, which adds case summaries, report writing and customer research to investigations, together with Lucinity's regulatory reporting module. The case study says the administrative manual work in case investigations has been significantly reduced but gives no figures.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Structured case files with transactions, subjects and investigator notes
- Examples of high quality narratives approved by quality assurance
- The financial intelligence unit's filing guidance and field definitions
- Access controls that match SAR confidentiality requirements
Systems to integrate
- AML case management system
- Transaction and customer data stores
- Financial intelligence unit filing system or e filing format
- Quality assurance workflow
Complexity: Medium
Drafting from a well structured case file is within reach of current models. The work is in grounding every fact, computing numbers outside the model, protecting highly sensitive data and keeping the investigator accountable for the content.
- 1
Start from the filing guidance
Turn the financial intelligence unit's guidance and your quality assurance checklist into a structure and a completeness check the draft must satisfy.
- 2
Compute, then write
Calculate totals, date ranges and counts with queries, and give them to the model as facts. Never let the model do arithmetic in the narrative.
- 3
Require citations
Make every statement in the draft reference a record in the case file, and show the references to the investigator in the editing view.
- 4
Measure against quality assurance
Compare drafts, edited versions and quality assurance outcomes on a sample of cases before rolling out, and track edit distance and rework rates afterwards.
- 5
Lock down confidentiality
Run the model in an environment approved for SAR data, with no retention by third parties and access limited to the investigation team.
Guardrails
- The investigator verifies every fact and is the named author of the filed report
- Numbers come from data queries, not from the language model
- Every statement references a source record; unsupported statements are flagged
- SAR confidentiality, with access limited to the investigation team and no data retained by model providers
- Draft, edits and final version retained for audit
KPIs to instrument
- Drafting time per report, before and after
- Quality assurance rework rate and reasons
- Share of draft statements changed or removed by investigators
- Completeness check failures per draft
- Time from case conclusion to filing
Human in the loop
The system drafts; the investigator decides whether to file, verifies the facts, rewrites the reasoning where needed and attests. Quality assurance reviews a sample as today, and the money laundering reporting officer owns the use of the tool.
Common failure modes
- Confident errors in facts
- A wrong amount or date in a filed report undermines the bank and the investigation. Compute numbers outside the model and require citations.
- Boilerplate reasoning
- Drafts converge on generic typology language that tells law enforcement little. Measure how much investigators rewrite the reasoning section and coach the prompts on good examples.
- Automation of the decision
- The draft makes filing look like the default. Keep the decision to file separate from the drafting step and record it explicitly.
What are the risks and rules?
EU AI Act
Minimal risk
Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.
Rules that apply
Guidance
- Guidance on Preparing a Complete and Sufficient Suspicious Activity Report Narrative (Financial Crimes Enforcement Network (FinCEN), North America). Guidance of November 2003 that explains the five essential elements a narrative must cover (who, what, when, where and why, plus how) and the 30 day filing deadline, with examples of sufficient and insufficient narratives; a useful completeness checklist for any drafting tool.
- Supporting Artificial Intelligence Adoption in AML/CFT (Hong Kong Monetary Authority, Asia Pacific). Circular of 19 November 2025. It reports that more than 30% of authorized institutions already use AI in transaction monitoring and announces supervisory workshops that include the use of generative AI to compile suspicious transaction reports.
- Joint Statement Encouraging Innovative Industry Approaches to AML Compliance (FinCEN and the US federal banking agencies, North America). Statement of 3 December 2018. Innovative pilot programs should not in themselves subject banks to supervisory criticism, even if they ultimately prove unsuccessful.
Controls to put in place
- Named investigator attests every filed report
- Environment and model provider terms approved for SAR confidentiality
- Citation and completeness checks on every draft
- Retention of draft, edits and final version
- Inventory entry with owner, prompts under change control and periodic quality review
Frequently asked questions
- Can generative AI write a suspicious activity report?
- It can draft the narrative from the case file, but the investigator remains responsible for the decision to file and for every fact in it. Treat it as a drafting copilot with citations, not as an adjudicator.
- Do regulators allow AI drafted SAR narratives?
- No rule we know of forbids them, and none removes the filer's accountability. In November 2025 the Hong Kong Monetary Authority announced workshops on using generative AI to compile suspicious transaction reports, and in 2018 FinCEN and the US federal banking agencies encouraged innovative approaches to AML compliance, including pilot programs.
- Who is already using AI to write investigation narratives?
- Mostly fintech, crypto and payment firms so far, through vendor platforms. Unit21 reports that by automating alert narratives and dispositions its AI agents automate 57% of alert reviews at Nexo, and FIS announced in May 2026 that BMO and Amalgamated Bank are developing with its Financial Crimes AI Agent. Public results from large banks are still scarce.
- How do you stop the model inventing facts?
- Compute every number with data queries, require a source reference for every statement, flag anything unsupported, and have the investigator verify the facts before filing.
How to cite this page
Blits.ai AI Use Case Library, "AI copilot for SAR and STR narrative drafting", last verified 26 September 2026, https://www.blits.ai/ai-use-cases/suspicious-activity-report-drafting. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published