Suspicious Activity Report - Branch Escalation Form

1. Section 1: Account & Customer Identification Details

This section captures essential identification details for all parties involved in the suspicious activity. Accurate and complete information is critical for effective investigation and regulatory reporting.

 

Branch Code

Staff Member ID Number

Staff Member Full Name

Staff Role

 

Specify other role:

Date of Incident Observation

Time of Incident Observation

Is the customer physically present at the branch?

 

Customer physical location in branch (e.g., counter, desk, waiting area)

 

Explain how the transaction was initiated without customer presence (e.g., phone, online, third party)

Customer Full Legal Name

Customer Primary Identification Number

Primary ID Type

Customer Date of Birth

Customer Contact Number

Customer Address on File

Account Number(s) Involved

Account Type(s)

Account Status at Time of Incident

Reporter's Relationship to Account

 

Provide Power of Attorney documentation details and verification status

 

Provide Legal Guardian documentation details and verification status

 

Was the third party attempting to gain unauthorized access?

 

Describe the third party's behavior and statements

 

Describe how the individual's identity was established or why it remains unknown

Are multiple customers or accounts involved in this incident?

 

Additional Customers and Accounts

Customer Name

Customer ID Number

Account Number

Relationship to Primary Customer

A
B
C
D
1
 
 
 
 
2
 
 
 
 
3
 
 
 
 
4
 
 
 
 
5
 
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

2. Section 2: Type of Suspicious Activity & Transaction Channel

Classify the suspicious activity and document transaction details. Precise categorization enables accurate risk assessment and appropriate investigative resource allocation.

 

Primary Suspicious Activity Category

 

Describe specific identity theft indicators (e.g., forged documents, impersonation tactics, discrepancies in personal information)

 

Explain how the account takeover was attempted or executed (e.g., compromised credentials, unauthorized password changes)

 

Provide check fraud details (e.g., forged signature, altered amount, counterfeit check numbers, payee discrepancies)

 

Describe card fraud specifics (e.g., skimming evidence, unauthorized card present transaction, card-not-present fraud)

 

Detail wire transfer fraud (e.g., beneficiary anomalies, urgent transfer requests, changes to wire instructions)

 

Explain ATM fraud method (e.g., skimming device, card trapping, shoulder surfing, PIN compromise)

 

Describe phishing or social engineering tactics used (e.g., pretexting, baiting, vishing, smishing)

 

Detail money laundering indicators (e.g., layering patterns, unusual source of funds, complex transaction chains)

 

Explain terrorist financing red flags (e.g., donations to suspicious organizations, use of shell companies, geographic concerns)

 

Describe elder exploitation signs (e.g., caregiver coercion, unusual withdrawals, changes to beneficiaries, cognitive concerns)

 

Detail insider threat indicators (e.g., policy violations, unauthorized system access, collusion with external parties)

 

Describe counterfeit instruments (e.g., poor quality printing, incorrect security features, serial number anomalies)

 

Explain loan or mortgage fraud (e.g., falsified income documents, inflated property values, straw buyer indicators)

 

Detail cybercrime specifics (e.g., malware signs, unauthorized remote access, data breach indicators)

 

Describe structuring or smurfing patterns (e.g., multiple small transactions below threshold, different branches used)

 

Provide detailed description of the suspicious activity not covered by standard categories

Transaction Channel(s) Involved

Transaction Amount

Transaction Currency

 

Specify currency:

Transaction Date

Transaction Time

Are there multiple transactions involved in this incident?

 

Additional Transaction Details

Date

Time

Amount

Channel

Status

A
B
C
D
E
1
 
 
 
 
 
2
 
 
 
 
 
3
 
 
 
 
 
4
 
 
 
 
 
5
 
 
 
 
 
6
 
 
 
 
 
7
 
 
 
 
 
8
 
 
 
 
 
9
 
 
 
 
 
10
 
 
 
 
 

Geographic Location of Transaction

Product or Service Involved

3. Section 3: Red Flags & Supporting Evidence Log

Document all observable red flags and collect supporting evidence. Thorough documentation strengthens the investigation and supports potential regulatory reporting obligations.

 

Red Flags Observed

Description of Other Red Flags

Detailed Description of Suspicious Behavior or Transaction

Types of Evidence Available

Upload Documentary Evidence (ID documents, forms, letters, etc.)

Choose a file or drop it here
 

Upload Photographic Evidence (suspicious individuals, documents, devices, etc.)

Choose a file or drop it here

Were there witnesses to the incident?

 

Witness Information

Witness Name

Witness ID Number

Contact Information

Witness Statement Summary

A
B
C
D
1
 
 
 
 
2
 
 
 
 
3
 
 
 
 
4
 
 
 
 
5
 
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

Did the customer provide an explanation for the activity?

 

Customer Explanation

 

Describe customer response when questioned (e.g., refused to answer, became hostile, left premises)

Plausibility Assessment of Customer Explanation (if provided)

Does this activity deviate from the customer's historical transaction pattern?

 

Describe Normal Transaction Pattern

 

Explain why this activity aligns with historical patterns yet remains suspicious

4. Section 4: Immediate Account Hold & System Actions Taken

Document all immediate actions taken to mitigate risk and secure assets. Prompt action can prevent further losses and preserve evidence.

 

Was an immediate account hold or restriction placed?

 

Types of Holds or Restrictions Applied

 

Explain why no hold was placed (e.g., insufficient evidence, customer not present, awaiting supervisor approval)

Systems Accessed to Take Action

Detailed Actions Taken in Systems

Was law enforcement notified immediately?

 

Law Enforcement Notification Details

Was the customer notified of the hold or restriction?

 

Customer Notification Details

 

Explain why customer was not notified (e.g., risk of flight, ongoing investigation, law enforcement request)

Was your immediate supervisor notified?

 

Supervisor Name and ID

 

Explain why supervisor was not notified and what alternative escalation path was used

5. Section 5: Compliance & Financial Crime Unit Sign-Off

Final assessment and escalation to Financial Crime Unit for investigation and regulatory reporting determination. This section must be completed by authorized compliance personnel.

 

Escalation Priority Level

Overall Risk Assessment

Recommended Next Actions

Assigned Compliance Officer

Financial Crime Unit Review Comments

Teller/Staff Member Signature

Supervisor Verification Signature

FCU Receiving Officer Signature

Form Status

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.