Nestack Agent Care
Industries / Banking / SAR filing agent

Banking AI agent · SAR filing

Suspicious-Activity Reporting AI Agent

Assemble the case behind an escalation, draft the Part V narrative and run the filing clock from a date a BSA officer entered — who alone determines that suspicion exists.

4–6 weeksTypical delivery
Your stackDeployment
Pre-filingOfficer decides
Agent CareAfter launch

What this agent does

Builds the file the determination rests on

In
01

An alert is escalated, and the transactions, the customer file and any prior filing are pulled in behind it.

02

A case is normalised across the monitoring, payment and customer systems, each fact carried with its source.

Reason
03

A review concludes, and the officer's determination and initial-detection date are entered, never inferred.

04

A case is tiered under 12 CFR 21.11, whose amounts and the 30- and 60-day clocks did not move in 2025-26.

05

A narrative is drafted to stand alone — who, what, when, where and why, with method of operation noted.

Decide
06

A clock runs forward from the entered date toward the 60-day ceiling, which no investigation may extend.

07

A case reaches the named BSA officer, who determines whether the bank suspects and whether it files.

Out
08

A decision is retained with the case for five years — including a no-file record where your own rule wants one.

09

Writes run only inside the approval boundaries agreed at implementation, and never outside the perimeter.

Product statement

The agent assembles and drafts; the named BSA officer determines, signs the filing, and personally carries that exposure.

Example workflow

One case, escalation to filing

AgentHuman
1Escalation receivedFraud-alert triage, KYC review, branch referral or monitoring system
2Case assembledTransactions, counterparties, account history and prior filings, each with its source system
3Narrative draftedPart V draft, Field 2 key terms, open questions and confidence
4Controls appliedCompleteness checks, 12 CFR 21.11 tier checks, key-term currency and confidence threshold
No human action required

Stages 1 to 4 run unaided, and nothing is determined at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the BSA officer to determine.

Low confidence

Adds a second investigator read first.

Officer determination

The case is held with its evidence, its open questions and the confidence.

Approve · Amend · Send to second review
Determined — filing authorised
6Case system updatedOnly where write access and approval policy allow it
7Outcome evaluatedNarrative completeness, amendment rate, days to file and examiner findings
Amendments

A filing is amended, a closure reopened — both land on the officer's record.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Determining that the bank knows, suspects or has reason to suspect.
Setting the initial-detection date the clock runs from.
Signing and submitting the report to FinCEN.
Deciding not to file — the safe harbour does not cover that.
Automation boundaryAgent acts unaided
Assemble the case from the transaction, customer.
Draft a Part V narrative that reads without the attachments.
Run the filing clock forward from the date the officer entered.
Check the draft for completeness and hold it for the BSA officer.
Writes stay inside the boundaries set at implementation, and inside the confidentiality perimeter.
Notifying the board or its designated committee.
Answering a subpoena or any external request for a filing.
Opening or answering a 314(b) exchange.
Changes to review, documentation or escalation rules.

Example output

One case, annotated

Everything the agent assembles is attached to the case it was drawn from.

SAR assembly output · single caseIllustrative example
Case
Drafted line
Tier cited
Source of date
Confidence
Clock
Cash structuring referral
Deposits sit below the cash reporting threshold across several branches
12 CFR 21.11(c)(2)
Officer-entered
89%
Runs from the entered date
As receivedTaken from the case, payment and customer systems — nothing on this side is written by the agent.
Evidence used Branch deposit history Prior filing on subject Customer risk record
Why this tierIt is the tier the banking-agency rule sets and a person still decides.
ActionApproveAmendSend to second review
What the score decidesBelow the configured threshold the case picks up a second investigator read before it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every escalationFrom the case record
03Assembly

Take what the other agents defer

Pick up the escalations the fraud-triage and KYC agents hand over, and build the file a determination needs.

01Approved path

Detection is not determination

The clock starts when a review concludes, not when a flag fires. That rule has not moved.

02Human review

Documented to your rule

FinCEN's October 2025 FAQs require no no-file record; the FFIEC manual still asks for one; an order can compel it.

04Build an evidence trail

The activity, the review it went through and the officer who determined stay on the filing.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Monitoring systemsActimize · Verafin
SAS · Oracle FCCM
Case managementUnit21 · Hummingbird
Sardine · Alloy
Core bankingFIS · Fiserv · Jack Henry
Temenos · Finastra

Agent

Suspicious-activity reporting

Reads the case
Drafts the narrative
Holds for determination

Filing and recordsBSA E-Filing portal
Records archive · retention
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the filing

Six controls, outermost first. What the whole set lets past is written into the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeHold assembly at draft-only when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, key-term-list and review-rule changes.Track
L4Case traceabilityRecord the sources, the draft, the edits and the determination — inside the perimeter.Record
L3Officer determinationHold cases for the named BSA officer; the gate governs release, not whether the determination is sound.Gate
L2Policy guardrailsTest drafts against completeness, tier and key-term rules, and refuse disclosure the confidentiality rule bars.Restrict
L1Confidence thresholdsRoute low-confidence cases to a second investigator read before the officer sees them.Require review
Model coreCase assembled — narrative draft, key terms, open questions and confidence
L1 – L2Test whether a draft may stand
L3Puts the determination in the officer's hands
L4 – L5Keep the activity and the review behind it
L6Holds the filing at undecided when signals degrade

How Nestack evaluates it

Evaluate the assembly workflow — not only the finished narrative.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the narrative the officer signs
Depth of coverage ▼
E1Final-output evaluationDid the narrative carry who, what, when, where and why?
E2Step-level evaluationDid the agent use the right case, the right tier rule and the current key-term list?
E3Tool evaluationDid it read and write the correct case and the correct field?
E4Confidence calibrationDo low-confidence cases actually attract more officer amendments?
E5Slice evaluationHow does performance change across specific typologies?
E6Business outcomeHow many filings were amended, and how many closed cases were reopened?
Floor — the outcome the bank answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
ES-03

Stale key-term list

The advisory key-term list was never refreshed.

Stage gathersCase evidence, prior filings and the key-term list
02 · Reasoning2 modes
ES-04

Detection date inferred

The alert timestamp is read as initial detection.

ES-06

Narrative not standalone

Part V leans on documents FinCEN never receives.

Stage proposesThe draft, the tier, the clock and the confidence
03 · Tool / write2 modes
ES-02

Disposition by throughput

Review capacity is sized to what the agent emits.

ES-05

Continuation filed early

Built on a filing rule instead of a review period.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
ES-01

Wrong subject reported

The narrative names a subject the resolution got wrong.

Stage returnsThe narrative the officer signs and FinCEN reads
05 · Change / Version1 mode
ES-07

Silent review regression

A model or rule change narrows what is escalated.

Stage tracksModel, prompt, key-term list and review rules
Sev-1 · disclosed outside the perimeter Sev-2 · a wrong narrative reaches FinCEN Sev-3 · evidence degrades, case holds

Affected slices

One typology can carry most of the failures

A programme-wide filing rate can look settled while a few typologies absorb most of the amendments and late filings. Nestack reports the amendment rate by typology, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Continuing-activity filings9.7%3.8× Review
Correspondent and cross-border7.8%3.1× Review
Elder financial exploitation4.6%1.8× Watch
Structuring and cash2.0%0.8× Normal
Bar: amendment-rate lift vs. the structuring-and-cash baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

No cycle closes without a new test

A cycle closes when the late filing is a case the next release has to catch. That suite is what the next narrative drafted is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

No-file records fall short of the bank's own rule.

02Diagnose

The case nobody called suspicious for weeks is read back until the cause narrows to one.

03Improve

The fix carries a number, and the filings that forced it travel with it.

04Verify

Nothing goes out until every touched narrative case has passed again.

05Learn

It is kept for good, and the review rules are amended in the same commit.

Learn → DetectThe return edge. The next detection is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, review workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01SAR workflow discovery and boundary definition.
02Case and monitoring source assessment.
03Tier, clock and key-term rule mapping for filings.
04Case ingestion and evidence normalisation.
05Narrative drafting and source binding.
06Confidence scoring and exception routing.
07Officer determination workflow.
08Case-system and filing integration.
09Narrative and clock cases.
10Guardrails and determination controls.
11Case-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne typology, one team ProductionProduction case systems AdvancedMultiple entities / regulators
Introduced at Pilot
Assembly to your case record
Officer determination
Narrative-completeness baseline
Introduced at Production
Reporting by typology
Determination workflow in your systems
Approved write-back
Case-system integration
Introduced at Advanced
Multi-entity rule sets
Multi-stage BSA approvals
High case volume
Multi-entity filing controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your escalation path and case record structure Case ingestion and evidence mappingWeek 1
02Representative filed and closed cases Assembly baseline, narrative extraction and source bindingWeek 2
03Your review, tiering and documentation policy Review-policy mapping and automation-boundary definitionWeek 1
04Access to relevant APIs, feeds or exports Case and monitoring assessment, then integration setupWeek 2
05Filings you would not want read back Timeliness cases and failure-mode testingWeek 4
06What no narrative may leave out Confidence scoring, exception routing, guardrails and approval controlsWeek 3
07Named BSA officers to determine on cases Officer determination workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The bands are drawn over the weeks each phase genuinely needs, which is why the fifth carries two.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1SAR workflow discovery, policy mapping and the automation boundary W2Case-system integration and the assembly baseline W3Assembly workflow, confidence logic and determination controls W4Evaluation suite, guardrails and failure-mode testing W5Filing integration, pilot cases and targeted corrections W6One review cycle run under the BSA officer, then Agent Care handover
Reading the bandEach bar spans only the weeks its work is named in. The week 5 overlap is two phases running, not padding.
At the end of W6Validation closes on live cases, and Agent Care picks up monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Banking AI agent

Build a SAR agent around your bank's determination chain.

Show us your escalation path, your case system and who signs the filing. If your fraud and KYC teams already stop at reporting, this is the page that picks it up.

Nestack Agents · Suspicious-activity reportingAGT-BK-13 · Agent Care available after launch