SAR redaction is the removal of personal data from a Suspicious Activity Report. POCA 2002 s.330 makes it an offence in the regulated sector to fail to disclose knowledge or suspicion of money laundering to the National Crime Agency (NCA), and s.333A separately criminalises tipping off a person that a disclosure has been, or is being, considered. anonym.plus strips names and account IDs on your device, the activity narrative left whole.
When this applies
An anti-money-laundering team must share a SAR internally for review or training. The file names the customer, the account, and the reporter, all of which can be cleared — without breaching the s.333A duty on who else may see it.
How anonym.plus handles it
- Open the report in anonym.plus on your device.
- The tool flags customer, reporter, and beneficiary names.
- Account and transaction IDs get flagged too.
- Swap each confirmed item for a steady label.
- Save the protected copy with no network call.
What you need to provide
- The SAR (PDF, DOCX, or e-filing export).
- An operator: Mask keeps part of an account number visible.
- Optional label map to keep one customer steady.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | subject customer → [CUSTOMER] |
| Names | PERSON | nominated officer → [REPORTER] |
| Financial | UK_BANK_NUMBER | 20-00-00 44718820 → [ACCOUNT] |
| Identifiers | UK_NINO | QQ 12 34 56 C → [NINO] |
| Dates | DATE_TIME | activity 02 Feb → [DATE] |
| Financial | IBAN_CODE | wire IBAN → [IBAN] |
Compliance achieved
- Supports handling the SAR to the NCA under POCA 2002 s.330 (the regulated-sector failure-to-disclose offence).
- The POCA 2002 s.333A tipping-off offence still limits who else may lawfully see the disclosure once it is shared.
- Local work keeps the disclosure off any cloud service.
- On-device AES-256-GCM guards the working files.
- Masks part of an account number when full removal is not needed.
Anonymise suspicious activity reports offline — see plans & start free →
Limitations & cautions
The <strong>s.333A tipping-off offence</strong> limits who may see a disclosure, separately from redaction. Confirm the reader is allowed access first. The tool removes named IDs; it does not itself clear who is a permitted recipient.
Frequently asked questions
Can I share a SAR freely after this?
No. POCA 2002 s.333A makes it an offence to tip off a person that a disclosure has been or is being considered, even once the file is cleaned. Confirm the reader is a permitted recipient before you share any version.
Why process the disclosure offline?
A SAR is highly sensitive under s.330. Local work keeps the customer and account data off any cloud service, which lowers leak and breach risk on top of the statutory duty.
Can I keep part of an account number?
Yes. The Mask operator hides most digits and leaves a few, so reviewers can still match records without seeing the full number.