This section captures essential identification details for all parties involved in the suspicious activity. Accurate and complete information is critical for effective investigation and regulatory reporting.
Branch Code
Staff Member ID Number
Staff Member Full Name
Staff Role
Teller
Senior Teller
Branch Manager
Customer Service Representative
Loan Officer
Other Branch Staff
Specify other role:
Date of Incident Observation
Time of Incident Observation
Is the customer physically present at the branch?
Customer physical location in branch (e.g., counter, desk, waiting area)
Explain how the transaction was initiated without customer presence (e.g., phone, online, third party)
Customer Full Legal Name
Customer Primary Identification Number
Primary ID Type
Government-issued ID Card
Passport
Driver's License
Other Official Document
Customer Date of Birth
Customer Contact Number
Customer Address on File
Account Number(s) Involved
Account Type(s)
Checking Account
Savings Account
Certificate of Deposit
Loan Account
Credit Card
Investment Account
Safe Deposit Box
Other
Account Status at Time of Incident
Active - Good Standing
Active - Restricted
Dormant
Frozen
Closed
Pending Closure
Reporter's Relationship to Account
Account Owner
Authorized Signatory
Power of Attorney
Legal Guardian
Trustee
Beneficiary
Third Party with No Authorization
Unknown/Unidentified Individual
Provide Power of Attorney documentation details and verification status
Provide Legal Guardian documentation details and verification status
Was the third party attempting to gain unauthorized access?
Describe the third party's behavior and statements
Describe how the individual's identity was established or why it remains unknown
Are multiple customers or accounts involved in this incident?
Additional Customers and Accounts
Customer Name | Customer ID Number | Account Number | Relationship to Primary Customer | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Classify the suspicious activity and document transaction details. Precise categorization enables accurate risk assessment and appropriate investigative resource allocation.
Primary Suspicious Activity Category
Identity Theft
Account Takeover
Check Fraud
Credit/Debit Card Fraud
Wire Transfer Fraud
ATM Fraud
Phishing or Social Engineering
Money Laundering
Terrorist Financing
Elder Financial Exploitation
Insider Threat or Employee Misconduct
Counterfeit Currency or Instruments
Loan or Mortgage Fraud
Cybercrime or Digital Fraud
Structuring or Smurfing
Other Suspicious Activity
Describe specific identity theft indicators (e.g., forged documents, impersonation tactics, discrepancies in personal information)
Explain how the account takeover was attempted or executed (e.g., compromised credentials, unauthorized password changes)
Provide check fraud details (e.g., forged signature, altered amount, counterfeit check numbers, payee discrepancies)
Describe card fraud specifics (e.g., skimming evidence, unauthorized card present transaction, card-not-present fraud)
Detail wire transfer fraud (e.g., beneficiary anomalies, urgent transfer requests, changes to wire instructions)
Explain ATM fraud method (e.g., skimming device, card trapping, shoulder surfing, PIN compromise)
Describe phishing or social engineering tactics used (e.g., pretexting, baiting, vishing, smishing)
Detail money laundering indicators (e.g., layering patterns, unusual source of funds, complex transaction chains)
Explain terrorist financing red flags (e.g., donations to suspicious organizations, use of shell companies, geographic concerns)
Describe elder exploitation signs (e.g., caregiver coercion, unusual withdrawals, changes to beneficiaries, cognitive concerns)
Detail insider threat indicators (e.g., policy violations, unauthorized system access, collusion with external parties)
Describe counterfeit instruments (e.g., poor quality printing, incorrect security features, serial number anomalies)
Explain loan or mortgage fraud (e.g., falsified income documents, inflated property values, straw buyer indicators)
Detail cybercrime specifics (e.g., malware signs, unauthorized remote access, data breach indicators)
Describe structuring or smurfing patterns (e.g., multiple small transactions below threshold, different branches used)
Provide detailed description of the suspicious activity not covered by standard categories
Transaction Channel(s) Involved
In-Person at Branch
ATM
Online Banking
Mobile Banking App
Telephone Banking
Wire Transfer System
Check Deposit
Card Payment Terminal
Third-Party Payment Processor
Transaction Amount
Transaction Currency
USD
EUR
GBP
JPY
CHF
CAD
AUD
Other
Specify currency:
Transaction Date
Transaction Time
Are there multiple transactions involved in this incident?
Additional Transaction Details
Date | Time | Amount | Channel | Status | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | ||||||
2 | ||||||
3 | ||||||
4 | ||||||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Geographic Location of Transaction
Product or Service Involved
Personal Checking
Business Checking
Savings Account
Credit Card
Debit Card
Personal Loan
Business Loan
Mortgage
Investment Product
Safe Deposit Box
Treasury Services
Trade Finance
Other
Document all observable red flags and collect supporting evidence. Thorough documentation strengthens the investigation and supports potential regulatory reporting obligations.
Red Flags Observed
Description of Other Red Flags
Detailed Description of Suspicious Behavior or Transaction
Types of Evidence Available
Physical documents submitted
Digital documents or emails
Surveillance footage
Audio recordings
Photographs
System logs or audit trails
Witness statements
Customer correspondence
News or media reports
Public records or database checks
No evidence available at this time
Upload Documentary Evidence (ID documents, forms, letters, etc.)
Upload Photographic Evidence (suspicious individuals, documents, devices, etc.)
Were there witnesses to the incident?
Witness Information
Witness Name | Witness ID Number | Contact Information | Witness Statement Summary | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Did the customer provide an explanation for the activity?
Customer Explanation
Describe customer response when questioned (e.g., refused to answer, became hostile, left premises)
Plausibility Assessment of Customer Explanation (if provided)
Does this activity deviate from the customer's historical transaction pattern?
Describe Normal Transaction Pattern
Explain why this activity aligns with historical patterns yet remains suspicious
Document all immediate actions taken to mitigate risk and secure assets. Prompt action can prevent further losses and preserve evidence.
Was an immediate account hold or restriction placed?
Types of Holds or Restrictions Applied
Full Account Freeze
Debit Card Block
Online Banking Suspension
Wire Transfer Block
ATM Access Block
Check Writing Privilege Suspension
Mobile App Access Revocation
Specific Transaction Type Block
Temporary Hold Pending Review
Explain why no hold was placed (e.g., insufficient evidence, customer not present, awaiting supervisor approval)
Systems Accessed to Take Action
Core Banking System
Card Management System
Online Banking Platform
Wire Transfer System
Customer Relationship Management
Fraud Detection System
Document Management System
No systems accessed
Detailed Actions Taken in Systems
Was law enforcement notified immediately?
Law Enforcement Notification Details
Was the customer notified of the hold or restriction?
Customer Notification Details
Explain why customer was not notified (e.g., risk of flight, ongoing investigation, law enforcement request)
Was your immediate supervisor notified?
Supervisor Name and ID
Explain why supervisor was not notified and what alternative escalation path was used
Final assessment and escalation to Financial Crime Unit for investigation and regulatory reporting determination. This section must be completed by authorized compliance personnel.
Escalation Priority Level
Critical - Immediate FCU Review Required (within 1 hour)
High - Same Business Day Review
Medium - Review within 24 hours
Low - Review within 48 hours
Informational - No immediate action required
Overall Risk Assessment
Recommended Next Actions
Assigned Compliance Officer
Financial Crime Unit Review Comments
Teller/Staff Member Signature
Supervisor Verification Signature
FCU Receiving Officer Signature
Form Status
Submitted - Pending Review
Under Investigation
SAR Filed
No Further Action Required
Referred to Law Enforcement
Closed - Insufficient Evidence
Closed - False Positive
To configure an element, select it on the form.