The Conventional Wisdom
At compliance conferences, the common pitch is that your Suspicious Activity Report (SAR) failures are due to outdated technology. The proposed solution? Advanced analytics, machine learning models, and AI-driven transaction monitoring. Automate your way out of the problem.
This narrative gained traction after Merrill Lynch agreed to pay a $7.5 million civil penalty to the SEC for failing to file numerous SARs from April 2020 through September 2024. Vendors quickly pointed to the case as proof that manual processes can't scale. Analysts called for a "digital transformation" of AML programs. The message was clear: technology solves compliance gaps.
It's a comforting story. It's also dangerously incomplete.
Why Technology Alone Isn't Enough
Technology doesn't file SARs. People do. The Merrill Lynch case highlights a deeper issue than just tools: failures in governance, escalation protocols, and human judgment that no algorithm can fix.
The violations spanned four and a half years. That's not a detection gap. You don't miss suspicious activity for 54 months because your transaction monitoring system needs an upgrade. You miss it because your escalation workflows broke down, your review queues went unmanaged, or your compliance team lacked the authority to act on what they found.
Consider what a SAR filing actually requires under the Bank Secrecy Act and FinCEN regulations. You must identify potentially suspicious activity, conduct a reasonable investigation, make a determination about whether the activity warrants filing, document your analysis, and submit the report within specific timeframes. The critical judgment happens between detection and filing. That's where compliance officers assess context, evaluate customer explanations, and decide whether activity crosses the threshold.
Technology can surface anomalies. It cannot make the determination that a pattern is suspicious rather than merely unusual. It cannot weigh reputational risk against regulatory obligation. It cannot navigate the judgment call when facts are ambiguous.
The Evidence
The SEC's enforcement action doesn't detail which specific controls failed at Merrill Lynch, but the duration tells you what you need to know. Systemic SAR failures lasting years point to one of three root causes:
First, inadequate governance over the SAR filing process itself. Who owns the decision to file? What happens when a front-line analyst identifies something questionable but a relationship manager pushes back? If your escalation path isn't clear, urgent, and protected from business pressure, SARs won't get filed regardless of how sophisticated your monitoring tools are.
Second, insufficient resources allocated to investigation and documentation. You can detect a thousand alerts per day, but if you have three people reviewing them, you're building a backlog that will eventually result in missed filings. The math doesn't work. Technology that increases detection without proportional investigation capacity makes the problem worse, not better.
Third, weak quality assurance over completed reviews. Someone needs to audit whether analysts are applying consistent standards, whether investigations are thorough, and whether filing decisions align with regulatory expectations. This oversight function is entirely human.
Look at what actually triggers SAR filing requirements: transactions involving potential money laundering, terrorist financing, fraud, or violations of the Bank Secrecy Act. The FATF Recommendations and USA PATRIOT Act establish the "know your customer" principle that underpins this obligation. You're not just monitoring for statistical outliers. You're evaluating whether activity is consistent with what you know about the customer's legitimate business, risk profile, and expected transaction patterns.
That evaluation requires institutional knowledge, industry context, and regulatory judgment. It's the kind of work that becomes harder, not easier, when you over-rely on algorithmic scoring.
What to Do Instead
Start with your escalation protocol. Map every handoff from initial alert to final SAR filing. Where do reviews stall? Who has veto authority? What happens when business units contest a compliance determination? If your Money Laundering Reporting Officer can't override relationship managers, your technology stack is irrelevant.
Second, audit your investigation standards. Pull a sample of closed alerts that didn't result in SAR filings. Review the documentation. Are analysts conducting genuine investigations, or are they checking boxes? Are they documenting why they concluded activity wasn't suspicious, or are they just noting that the customer provided an explanation? Weak investigation standards create regulatory exposure that automation amplifies.
Third, staff for the workload you have, not the workload you wish you had. If your monitoring system generates 500 alerts per week, you need enough investigators to review 500 alerts per week with sufficient depth to make sound filing determinations. Reducing false positives through better tuning helps, but it doesn't eliminate the need for human capacity.
Fourth, implement a quality assurance layer that reviews both filed SARs and decisions not to file. This function should report independently of the front-line compliance team and should have direct access to senior management. It's your early warning system for systematic misjudgments.
Finally, test your governance under pressure. Run a tabletop exercise where a high-value client's activity triggers SAR criteria, but the relationship manager insists it's legitimate. Who makes the final call? How quickly can they make it? What documentation do you require? If you don't know the answers, you're one difficult case away from a filing failure.
When Technology Helps
Technology absolutely matters. Transaction monitoring systems that reduce false positives let investigators focus on genuine risks. Case management platforms that track review timelines prevent SARs from falling through the cracks. Data analytics that identify emerging typologies help you stay ahead of evolving threats.
If your current tools can't ingest data from all relevant sources, if they generate so many false positives that your team is drowning, or if they lack audit trails showing who reviewed what and when, then yes, you need better technology.
But buy it with clear eyes. You're not automating judgment. You're creating the infrastructure that lets your compliance team exercise judgment effectively. The $7.5 million penalty Merrill Lynch paid didn't stem from insufficient AI. It stemmed from a compliance program that, for four and a half years, failed to convert detection into action.
Your SAR process is only as strong as the weakest handoff between alert and filing. Find that handoff. Fix the governance around it. Then buy the technology that supports the humans making the actual decisions.




