A Suspicious Activity Report (SAR) is a report to the Isle of Man Financial Intelligence Unit (FIU) that an activity causes knowledge or suspicion of money laundering, or belief or suspicion of terrorist financing. It is the end of an internal chain, not the start: a staff member's suspicion becomes an internal disclosure to the MLRO, the MLRO assesses it, and — where there are reasonable grounds — makes the external disclosure to the FIU as soon as practicable. Getting that chain short, documented and undelayed is what the Code and the FIU actually measure.
Two things make SARs harder than they look. The mechanics are specific to the Island — the Themis system, the consent regime, the moratorium — and the quality of the narrative decides whether a report is usable.
The internal reporting chain: staff to MLRO
Every firm must operate internal reporting procedures, and Code para 25 spells out what they have to achieve: they must enable staff to know to whom suspicious activity is disclosed, ensure a clear reporting chain to the MLRO, and require an internal disclosure to the MLRO of anything the person considers suspicious. That third element is the trigger for everything downstream — the moment a staff member forms a suspicion, an internal disclosure is owed.
What happens next is set by Code para 26. On identifying suspicious activity, the firm must conduct enhanced customer due diligence — unless it reasonably believes doing so would tip off the customer — and make an internal disclosure. The two run together: the enhanced due diligence sharpens the picture the disclosure will carry, but it stops the instant it risks alerting the subject.
The Handbook is unusually direct about how that internal disclosure should travel. Under §5.4, reporting lines "should be as short as possible with a minimum number of people between the employee with suspicion and the MLRO", and internal disclosures "must reach the MLRO without any undue delay" — and must not be intercepted by supervisors or managers. A well-meaning middle layer that reviews and filters suspicions before they reach the MLRO is not a control; it is an obstruction the Handbook expressly rules out.

All suspicions should be documented. In urgent cases an initial disclosure may be made by phone and then followed up in writing, but the written record is expected, carrying full customer details and as full a statement as possible of the grounds. When the MLRO receives it, they should acknowledge receipt and remind the reporter about the prohibitions on prejudicing an investigation and on tipping off — the audit trail that later shows the chain worked.
If your internal disclosure procedures have never been tested against these requirements, that is worth a conversation.
The MLRO's decision and the external disclosure
The internal disclosure lands with the MLRO, and here the standard changes. Code para 27 requires the MLRO to assess the internal disclosure to determine whether there are reasonable grounds for knowing or suspecting money laundering or terrorist financing. Staff report what they consider suspicious; the MLRO applies judgement to decide whether that suspicion meets the threshold for an external report. Not every internal disclosure becomes a SAR — but the decision either way must be a reasoned, recorded assessment.
Where the MLRO knows or suspects, or has reasonable grounds to, para 27 requires an external disclosure to the FIU as soon as practicable. The same paragraph settles confidentiality: making the disclosure does not breach any obligation of confidence. An MLRO who hesitates over client confidentiality is hesitating over an obstacle the Code has already removed.
This is where the "report everything to be safe" instinct meets reality. The Code does not ask for volume; it asks for a genuine, well-evidenced suspicion assessed against reasonable grounds. Defensive over-reporting — a SAR on every marginal transaction to avoid a judgement call — degrades the FIU's ability to act on the reports that matter and does not discharge the firm's obligation to think. A single well-evidenced SAR is worth more than a stack of reflexive ones.
The MLRO's independence protects that judgement. SAR Guidance (p.6) is explicit that the MLRO must be able to report directly to the FIU without interference from management. Read alongside the Handbook's rule against interception, no one between the suspicion and the FIU may soften, delay or veto the report — including the board.
What the FIU is, and how a SAR reaches it
The FIU is the Isle of Man Financial Intelligence Unit, and its functions are set out in section 5 of the FIU Act 2016. A SAR is the vehicle that carries a firm's knowledge or suspicion to it, as defined in SAR Guidance §1.2. The FIU is the recipient and the analyst — not the regulator; the Authority (the Isle of Man Financial Services Authority) supervises whether your framework produces good SARs, while the FIU receives and acts on them. Regulated-sector businesses submit SARs — and consent requests — through the FIU's secure online reporting system, Themis, at https://disclosures.gov.im/, as directed by SAR Guidance §2.1 and Chapter 5 of the Handbook. Your MLRO and deputy should be registered before the system is needed under pressure; an urgent disclosure is the wrong moment to discover no one can log in.

Consent, the notice period and the moratorium
A SAR can do more than inform. Where a firm needs to carry out an act — completing a transaction, releasing funds — that might otherwise be a money-laundering offence, the SAR can request the FIU's consent, an "authorised disclosure" under section 154 of the Proceeds of Crime Act 2008. SAR Guidance §3 is careful about what consent is: it provides a defence for the act, but does not approve it and does not oblige you to carry it out. Consent removes a criminal risk; it does not endorse the commercial decision, which remains yours.
The mechanics are time-bound and worth knowing precisely. The statutory Notice Period is 7 working days, with the day of submission counted as Day 0. If the FIU neither grants nor refuses consent within that period, the reporter has implied consent from day 8 and may proceed. If consent is refused, a 31-calendar-day moratorium applies under POCA, during which the act must not be carried out. Under the Anti-Terrorism and Crime Act, there is no moratorium. And section 156 of POCA lets deposit-taking bodies deal with transactions of £250 or less without seeking consent at all.
So you need consent only when proceeding would otherwise be an offence — and even then, the notice period is short and implied consent exists for a reason. What you must never do is treat a granted or implied consent as the FIU telling you the client is fine. It is a defence for one act, nothing more.
Consent timing is one of the areas we see firms get wrong under pressure. If a live transaction is waiting on a SAR, get the mechanics right.
What a good SAR contains
The FIU publishes concrete quality points, and they reward firms that follow them. Drawing on SAR Guidance §4 and the Good Practice note, a good SAR is built on a full chronological narrative — who is doing what, with whom, when, how, where and why — written so that a reader with no prior knowledge of the case can follow the grounds for suspicion.
Every subject must be uniquely identified in a separate record: full name spelt correctly and in the right order, date of birth, nationality and addresses, with PEP status flagged. Never enter "unknown" — if you are unsure of a field, leave it blank rather than assert a fact you do not have. Transaction detail should be full: senders, receivers, banks and sort codes, and where a generic sort code is used, state where the funds are domiciled. Where a subject has featured in earlier reports, quote the previous SAR or Themis reference numbers so the FIU can connect the intelligence.

Two practical points close the quality gap. Supporting evidence should be attached as files — PDF, Word, Excel or image — and never as hyperlinks, because a link can change at source and leave the FIU with nothing. And where the same matter has been reported to another jurisdiction, flag that dual reporting.
Common mistakes we see
The most damaging is the intercepted disclosure — a suspicion that reaches a line manager who decides whether it is worth passing up, in direct contradiction of the Handbook's rule that reporting lines carry a minimum number of people and that supervisors must not intercept. The second is reflexive over-reporting: filing SARs to feel safe rather than because a genuine suspicion has been assessed against reasonable grounds, which buries real intelligence in noise.
The third cluster is timing. The FIU itself names the causes of reports that are not made "as soon as practicable" in SAR Guidance §1.5 — an MLRO unavailable with no deputy appointed, confusion over the requirements, an internal investigation that stalls, chronic understaffing, and internal management sign-off blocking the report. Every one of these is a control failure, not bad luck. A firm with a registered deputy, clear procedures and no management veto over the MLRO does not produce late SARs for these reasons. The fourth is the thin narrative: a report that states a conclusion without the chronological who-what-when-why that lets the FIU act, or one that enters "unknown" in identity fields the Guidance tells you to leave blank.
Frequently asked questions
If we report everything, are we safe?
No. The Code asks you to assess whether there are reasonable grounds for knowing or suspecting ML/FT and to report where that threshold is met — not to file a SAR on every marginal transaction. Defensive over-reporting degrades the FIU's intelligence and does not discharge the duty to exercise judgement.
What if we accidentally tip off the client?
Tipping off, under SAR Guidance §4.1.8, occurs when someone in the regulated sector divulges that a disclosure has been made to the FIU, or that a money-laundering investigation is underway. It is particularly relevant when taking on a new client or ending an existing relationship. This is why Code para 26 suspends enhanced due diligence where it would tip the customer off. If in doubt about a communication or an exit, seek independent legal advice before acting.
Do we need the FIU's consent before we proceed with a transaction?
Only where proceeding would otherwise be a money-laundering offence. Consent is an authorised disclosure under section 154 of POCA that provides a defence — it does not approve or oblige the act. The notice period is 7 working days (Day 0 is the submission day), with implied consent from day 8 if the FIU does not respond; a refusal triggers a 31-calendar-day moratorium under POCA. Deposit-takers may handle transactions of £250 or less without seeking consent.
How do we actually submit a SAR?
Through the FIU's secure online system, Themis, at https://disclosures.gov.im/, as directed by SAR Guidance §2.1 and Chapter 5 of the Handbook. Consent requests go through the same portal. Register your MLRO and deputy before you need it.
A SAR is only as good as the chain that produced it and the narrative that carries it — keep the line short, the judgement genuine, and the story clear enough for a stranger to follow.
