On AML and crypto exchanges — when is a 'SAR' triggered?
I'm trying to get my head around the various AML obligations for crypto exchanges, particularly when dealing with international clients. We're a small operation, just getting licensed in a couple of jurisdictions, and the nuances are proving trickier than anticipated. Specifically, when do you guys typically trigger a Suspicious Activity Report (SAR) in a cross-border scenario? Is it purely based on the transaction amount exceeding a certain threshold, or are there other common red flags you've seen that warrant filing one, even if the amount is relatively small? Just trying to understand the practical implementation beyond the legal text.