SAR confidentiality and record keeping in accountancy firms
Last updated: July 24, 2026
When an accountant identifies information that may require a suspicious activity report (SAR), the practice must preserve a clear record of the concern and the money laundering reporting officer’s (MLRO) response.
That information must remain separate from routine client papers so that staff, clients, and service providers do not discover the existence of the case through ordinary file access.
Confidentiality should therefore be supported by clear access controls, with the SAR record held outside the client file and handled only by people authorised to deal with the case.
Key takeaways
- SAR case material belongs in a confidential record outside the client’s normal working papers.
- The SAR record should show the information considered and the dated reasoning behind the MLRO’s decision.
- The case history needs to cover the internal report, submission, later communications, and closure.
- Access must be limited to people who have been specifically authorised to handle the case.
- The written retention approach should specify when reviews occur and how deletion is controlled.
- Data Subject Access Requests (DSARs) and law-enforcement enquiries must be referred to the person responsible for disclosure decisions.
Why SAR records need stricter handling than ordinary client records
A SAR file can reveal the existence and progress of an AML concern, including any report to the National Crime Agency (NCA) or contact from law enforcement. Disclosure could alert the client or another connected person.
Section 333A of the Proceeds of Crime Act 2002 creates a tipping-off offence where its statutory conditions are met, including when a disclosure is likely to prejudice an investigation.
Information can be shared only when a person’s authorised role requires access; seniority within the firm or involvement in the client work is not enough by itself.
Accidental disclosure is often the main risk, for example, through file notes, email subjects, or other routine system entries.
SAR record content for internal reports and external submissions
The SAR record should contain the internal report, identify when and by whom it was made, and explain the facts or information that caused concern. If the origin of the information affected whether an external SAR was submitted, the record should explain why.
It then needs to summarise the material considered, any proportionate follow-up enquiries, and the reporting outcome. Together, this should provide a clear record of the MLRO’s response to the internal SAR, rather than documenting only the final outcome.
The record should show the date of the MLRO’s assessment and explain why an external SAR was submitted, not submitted, or deferred. If the decision is deferred, it should identify the information or development awaited.
Any instructions issued to those handling the engagement should be retained with the SAR file. They can be limited to what staff need to manage the work safely, without giving them the full suspicion narrative.
If an external report is made, the confidential record should preserve what was included in the SAR, together with the submission date and the NCA acknowledgement or reference.
The case history should also cover any defence against money laundering (DAML) request, together with subsequent law-enforcement communications. The closure date should complete the case history.
A concise SAR register using unique internal references can help the MLRO track cases. The register remains confidential and does not replace the underlying decision record.
Secure storage and restricted access for SAR records
CCAB guidance states that SAR records do not form part of the client assignment’s working papers and should be kept in a separate, secure location.
The confidential file can refer to relevant client documents or preserve necessary extracts. No note indicating that a SAR exists belongs in ordinary working papers.
Labels such as “SAR filed” or “NCA report” should not be used in metadata or backups across communication and storage systems.
Need-to-know access and proportionate SAR record security
Access will usually be limited to the MLRO or nominated officer, and anyone specifically authorised to support or handle the case. Permissions should reflect that role, rather than a person’s seniority in the firm or involvement in the client work.
For electronic records, the firm must use secure, auditable access and recovery arrangements. Encryption is often appropriate, while paper files should be kept in a locked location.
The same arrangements should also cover handover if the MLRO is unavailable, leaves the firm, or is replaced.
Practical takeaway: Cloud providers and outsourced information technology support can create hidden access points, so supplier arrangements should limit and record any access by administrators or technicians. While these controls need to be deliberate, they do not require an enterprise system.
SAR record retention, deletion, and later disclosure requests
The familiar five-year rule applies to specified customer due diligence and business-relationship records. CCAB distinguishes SAR material and states that no official retention period is specified for SAR-related records or decisions.
Therefore, a practice needs its own written retention rule. The firm should base the retention period on its need to evidence compliance and manage any unresolved legal or professional exposure.
Data-protection storage limitation also requires records to be kept only while there is a defensible reason.
Each case can carry a review date, and the record should explain the reason for any extension, especially if a legal or investigative hold applies. Secure deletion needs to extend to all duplicate or exported copies.
When documents might be relevant to an investigation, destruction must stop; the Proceeds of Crime Act separately addresses their concealment, falsification, or destruction in specified investigation circumstances.
Disclosure controls for DSARs and law-enforcement contact
Requests for SAR-related information should be routed to the MLRO or another designated decision-maker, so any disclosure question is assessed before staff responds.
When the request is a DSAR, the firm should make the disclosure decision before any response is given. The decision-maker needs to consider whether the crime-and-taxation exemption restricts access or transparency, particularly if disclosure would be likely to prejudice the relevant purpose.
The record should then show how the request was assessed, what response was given or withheld, and the legal basis relied on.
Law-enforcement contact should be handled in the same controlled way, with the SAR case note identifying the authority for the request and what was disclosed in response.
Specialist advice is often appropriate if the request creates uncertainty, conflict, or legal dispute.
Practical takeaway:
Even sole practitioners should demonstrate a controlled, recoverable SAR process with a dated decision trail and documented lifecycle and disclosure steps.
A proper SAR process should leave the practice able to reconstruct the case while keeping the information away from anyone without an authorised need to know.
In summary
Compliant SAR record keeping ensures accountancy firms possess a coherent account of each decision while keeping sensitive information out of day-to-day systems and client files.
The case record should be complete enough to show what was known, how the MLRO responded, and what happened afterwards.
A smaller practice can meet the same standard through deliberate organisation rather than elaborate systems, provided SAR material remains separate from ordinary client work and the process can still be managed if the MLRO is unavailable.
FAQs
SAR material requires a dedicated confidential file. The client file can point to relevant source documents where needed, without revealing that a report or concern exists. The firm’s controls should also address common places where information can appear unintentionally, such as email subject lines, file names, and system notes.
Normally, access is reserved for the MLRO, with additional permission only for people expressly approved to assist with the case. A partner or manager may be informed if they are authorised to assist with the case, but access should not follow simply from seniority or involvement in the client work. Other staff should be told only what they need to know to handle the engagement safely.
There is no stated official retention period for SAR records or related decisions. The firm’s retention approach should define how long the records will be retained, considering its compliance needs and any continuing exposure arising from legal duties or professional obligations. Individual cases can be reviewed at set dates, with records kept for longer where an investigation or legal hold remains active.
The decision record needs to explain the basis for the conclusion, showing what information was reviewed and how any reasonable checks informed the dated decision. The note should also explain why the available facts did not lead to an external report. If the decision is postponed, the record should identify what further information or event is awaited before the case is reviewed again.
An appointed disclosure decision-maker should receive the request, even when the MLRO holds that responsibility. The assessment must address the circumstances of the request and whether the crime-and-taxation exemption affects the response. The record needs to set out the conclusion and the justification in law, with expert input considered if the position remains unclear or contested.
A sole practitioner should keep each SAR case in a separate confidential record, so the file shows the path from the initial concern to the decision reached and any later communications. The records should be stored safely and reviewed against the firm’s retention policy. A continuity plan needs to cover the practitioner’s unavailability or a later transfer of MLRO responsibilities.
References and Source Material
- HMRC, Risks common to accountancy service providers
- Money Laundering Regulations 2017
- CCAB, Anti-Money Laundering and Counter-Terrorist Financing Guidance for the Accountancy Sector
- Proceeds of Crime Act 2002, section 333A: Tipping off in the regulated sector
- Proceeds of Crime Act 2002, section 342: Prejudicing an investigation
- UK Financial Intelligence Unit, National Crime Agency, SARs Best Practice Guidance, Chapter 2: Submitting a SAR
- Home Office Circular 004/2021, Confidentiality and sensitivity of SARs in private civil litigation
- Information Commissioner’s Office, A guide to data security
- Information Commissioner’s Office, Sharing personal data with law-enforcement authorities

