Search results calling this a “SAR report” describe a U.S. filing. Institutions regulated by the BSP, OJK, BNM, or SBV do not file a SAR: they file an STR, a Suspicious Transaction Report, under their own national law. The name, the filing deadline, and the receiving regulator all differ from the American version.
That distinction is not academic. A compliance manual that still says “SAR” is quoting the wrong statute, the wrong deadline, and in an examination, the wrong evidence of whether the institution understands its own obligations.
What's the difference between a SAR and an STR?
A Suspicious Activity Report is the term used under the U.S. Bank Secrecy Act, filed with FinCEN. A Suspicious Transaction Report is the equivalent obligation under most non-U.S. AML regimes, including the ones that govern financial institutions across the Philippines, Malaysia, Vietnam, and (in its English rendering) Indonesia.
Both exist for the same reason: to tell a financial intelligence unit that a transaction, or a pattern of transactions, looks like it could involve money laundering or terrorism financing. But the form, the statutory basis, the filing portal, and the deadline are jurisdiction-specific. In the Philippines, the obligation sits under Republic Act 9160 (the Anti-Money Laundering Act, as amended) and is filed with the Anti-Money Laundering Council, not with FinCEN, and not as a “SAR.”
Vendor content and generic compliance guides frequently use “SAR” as a catch-all label for any suspicious-transaction obligation, which is why the search term surfaces results from institutions that have never operated under U.S. law. An examiner reviewing your STR program will not be looking for that label.
Which regulators use STR instead of SAR?
Malaysia's central bank publishes STR forms and a dedicated STR FAQ page under that exact terminology. Vietnam's State Bank uses “Suspicious Transaction Reports (STRs)” as its official English term under the 2022 AML Law. Indonesia's financial intelligence unit, PPATK, and its banking regulator, OJK, are consistently described in English-language regulatory summaries as requiring a “Suspicious Transaction Report,” we have not independently verified the native Bahasa Indonesia term used in PPATK's own filings, so treat that specific rendering as unconfirmed rather than exact.
| Jurisdiction | Regulator | Term used | Primary legal basis |
|---|---|---|---|
| Philippines | BSP / AMLC | STR | RA 9160, as amended (AMLA), AMLC GoTRACS |
| Malaysia | BNM | STR | Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 |
| Vietnam | SBV | STR | Law on Anti-Money Laundering 2022 |
| Indonesia | PPATK / OJK | “Suspicious Transaction Report” (English-language usage) | Law No. 8 of 2010 |
| United States, for contrast | FinCEN | SAR | Bank Secrecy Act |
What triggers an STR filing?
There is no minimum transaction size. The trigger is suspicion, not value: any transaction, or attempted transaction, that gives reasonable grounds to suspect it involves proceeds of an unlawful activity, is structured to avoid reporting, has no clear economic or lawful purpose, or otherwise deviates from the customer's known profile. That is a meaningfully different test from the fixed-threshold reporting covered next.
STR vs. CTR: what's the difference?
The two obligations get conflated constantly, and the confusion has a real compliance cost.
| STR | CTR | |
|---|---|---|
| Trigger | Suspicion, regardless of amount | Single transaction, or aggregated same-day transactions, of ₱500,000 or more |
| Filing deadline | Next working day from the point of occurrence | 5 working days from the point of occurrence |
| What “occurrence” means | The point suspicion is established, not the transaction date | The transaction date itself |
| Filed under | AMLC GoTRACS | AMLC GoTRACS |
The ₱500,000 figure is a reporting threshold that defines when a covered transaction must be reported at all. It is not a penalty amount, and pieces that use it as a fine figure are misquoting the rule.
How fast do you have to file an STR?
Next working day from occurrence, where occurrence is the point your institution establishes suspicion, not the date the underlying transaction took place. That timeline runs under AMLC's GoTRACS framework, formalized by AMLC Regulatory Issuance No. 2, Series of 2024, effective from its publication on 11 December 2024, with specific provisions phased in through 2025 and beyond.
The most common version of this mistake is an institution's own SLA quoting a five-working-day window for STRs, which is the CTR deadline, not the STR one. We've written a full breakdown of exactly where that error creeps into policy documents, and how to catch it before an examiner does, in The STR Filing Window Trap.
What goes into an STR narrative?
A narrative that says a transaction “appears suspicious” without a specific typology, a customer-behavior comparison, and a clear articulation of why the pattern deviates from expected activity is not an actionable filing; AMLC's own review of a sample year found that close to half of submitted STRs weren't. The standard structure examiners expect covers who, what, when, where, why, and how, tied to a named red flag rather than a general statement of concern.
We cover that narrative framework in full, including the specific phrasing patterns that get filings rejected, in How to Write a BSP-Ready STR in 2026.
What happens if you file late, or don't file at all?
Under the MORNBFI's Appendix Q-26, AMLC-supervised institutions face penalties of up to ₱1,000,000 per violation, or ₱100,000 per day for a continuing violation. That is separate from, and larger than, the ₱500,000 CTR reporting threshold, and the two figures should never be quoted interchangeably.
The supervisory stakes have also shifted since the Philippines exited the FATF grey list on 21 February 2025. Grey-list exit was a country-level result; the next mutual evaluation cycle, in 2027, is decided by what individual institutions can demonstrate, and a pattern of late or boilerplate STRs is exactly the kind of institution-level evidence examiners will be looking for. We cover what that exit does and doesn't change in The Philippines Has Cleared 18 of the FATF's Action Items.
Where does STR filing fit inside a broader compliance program?
STR and CTR filing are one module of a wider AML obligation that starts with name screening and transaction monitoring and ends in case management and reporting.
FyscalTech's Regulatory Reporting module drafts STR narratives directly from case investigation data using its AI layer, and exports in AMLC's native GoTRACS format, so the narrative-quality problem above is addressed at the point of filing rather than caught after the fact.
For a broader view of what a modernized reporting workflow looks like, see our regulatory reporting playbook for mid-size fintechs.

