goAML STR Rejected: Common Reasons & What to Do
Submitting a Suspicious Transaction Report (STR) through goAML is an important part of AML compliance in the UAE. But what happens when your STR is rejected?
A rejected STR does not necessarily mean that your suspicion was wrong or that your business has failed its AML obligations. In many cases, the report may have been rejected because information was incomplete, the wrong reporting details were selected, or the report did not meet the requirements of the goAML system.
The important thing is not to simply submit the same report again.
You should first understand the rejection reason, correct the report and then resubmit it within the permitted timeframe.
In this guide, we explain the common reasons why a goAML STR may be rejected, what you should do after receiving a rejection and how to reduce the chances of the same problem happening again.
What Does “STR Rejected” Mean on goAML?
When an STR is submitted through goAML, it goes through the FIU’s reporting process. The goAML system’s Message Board can be used to notify reporting entities about the acceptance or rejection of submitted reports and to request additional information where necessary.
A rejection generally means that the submitted report needs correction or additional information before it can be properly processed.
It does not automatically mean that the underlying suspicious activity is no longer relevant.
This distinction is important.
If your business still has reasonable grounds to suspect that a transaction or activity is connected with money laundering, a predicate offence, terrorist financing or another relevant financial crime concern, the reporting obligation should not simply be ignored because the first submission was rejected. For financial institutions under CBUAE supervision, STR/SAR reporting is required where the applicable suspicion threshold is met, regardless of the transaction amount.
What Should You Do When Your goAML STR Is Rejected?
The first step is simple:
Read the rejection reason carefully.
According to the UAE goAML FAQ, rejected reports remain available for 5 calendar days, during which the report can be reverted, edited and resubmitted. The FAQ also refers to a 10-day grace period for resubmission.
A practical process is:
Rejected STR → Check rejection message → Revert report → Correct information → Review → Resubmit
Do not create a completely new report without first understanding why the original submission was rejected.
Common Reasons Why a goAML STR May Be Rejected
1. Mandatory Information Is Missing
One of the most straightforward reasons for rejection is incomplete information.
The CBUAE’s goAML reporting guidance identifies several mandatory fields, including:
- Report type
- Internal STR/SAR number
- Description or summary of the report
- Action taken by the reporting entity
- Location of the incident
- Reason for reporting
The exact requirements can depend on the report type and the reporting entity.
Before submitting an STR, the Compliance Officer or MLRO should check every mandatory field rather than assuming that the portal will identify every substantive problem.
2. The “Description of the Report” Is Too Weak
The description of the suspicion is one of the most important parts of an STR.
The CBUAE guidance states that the report description should provide a brief overview of the suspicion or reason for submitting the report.
A vague statement such as:
“The transaction appears suspicious.”
does not provide much useful context.
A stronger report should explain the relevant facts, why the activity is inconsistent or unusual, what triggered the concern and why the reporting entity considers the activity suspicious.
The objective is not to write a long story.
The objective is to give the FIU a clear and understandable explanation of the suspicion.
3. The Wrong Report Type Was Selected
goAML supports several reporting types, and selecting the correct one matters.
For example, the CBUAE distinguishes between STRs and SARs, while other reporting types can be used for specific purposes. STRs and SARs are generally the primary reports for a new suspicion, while AIF/AIFT reports can provide additional information relating to a previously submitted report.
Choosing the wrong report type can create problems during submission or review.
Before filing, the Compliance Officer should ask:
What exactly am I reporting, and which report type is appropriate for this situation?
For financial institutions, the CBUAE guidance also distinguishes suspicious activity involving transactions from suspicious activity without transactions when determining whether an STR or SAR should be used.
4. No Appropriate Reason for Reporting Was Selected
The reason for reporting is another important part of an STR.
The CBUAE guidance states that the reporting entity should select the most appropriate reason for reporting from the available options, and that at least one applicable reason should be selected to avoid rejection by the goAML system.
Don’t select an indicator simply because it sounds similar.
The selected reason should actually relate to the facts described in the report.
For example, if the concern relates to unusual activity involving a customer’s business profile, the report should identify the relevant indicator and then explain how the customer’s actual behaviour connects to that concern.
5. Transaction Details Do Not Match the Supporting Information
Another common problem is inconsistency between the information entered into goAML and the supporting documents.
Check details such as:
- Transaction date
- Transaction amount
- Currency
- Account details
- Sender
- Beneficiary
- Customer name
- Institution information
- Supporting documents
Even a small discrepancy can make an STR harder to assess.
Before resubmitting a rejected report, compare the information in goAML against the original transaction records and supporting documents.
6. Incorrect Party or Transaction Information
An STR should clearly identify the relevant parties and transactions.
The CBUAE’s goAML guidance contains specific requirements around transaction information and the parties involved. It also requires reporting entities to follow the relevant transaction structure when entering transactions into the system.
This means businesses should take care when entering:
- Ordering parties
- Beneficiaries
- Accounts
- Financial institutions
- Transaction amounts
- Transaction dates
- Related parties
Incorrectly identifying a party can make the report difficult to understand and may lead to rejection or requests for clarification.
7. The Report Does Not Clearly Explain the Suspicion
This is more serious than simply missing a field.
A report can technically contain all the required fields but still fail to communicate why the activity is suspicious.
For example, instead of simply stating:
“Customer made a large transaction.”
explain the relevant circumstances:
- What is unusual about the transaction?
- Is it inconsistent with the customer’s known profile?
- What information raised the concern?
- Is there unusual movement of funds?
- Are there unexplained third parties?
- Is the transaction connected to other activity?
- What checks were performed?
- What did the business discover?
The FIU needs useful information, not just a transaction description.
8. The STR Was Resubmitted Without Making the Requested Changes
This is one of the biggest mistakes to avoid.
If an STR has been rejected and the FIU has provided rejection grounds, simply submitting the same report again without addressing those issues can result in another rejection.
The correct approach is to:
- Read the rejection message.
- Identify every issue raised.
- Revert the report.
- Make the necessary corrections.
- Review the entire report.
- Resubmit it.
Do not assume that fixing one field is enough if the rejection message identifies multiple issues.
9. Supporting Information Is Not Sufficient
Depending on the circumstances, the FIU may need additional information to understand the reported activity.
Supporting information can help establish the context behind the suspicion.
This might include relevant:
- Customer documents
- Transaction records
- Contracts
- Invoices
- Account information
- Correspondence
- Internal investigation findings
However, businesses should provide information that is relevant to the report rather than uploading unnecessary documents simply to make the file larger.
10. The Report Contains Internal Inconsistencies
Before resubmitting an STR, read it from beginning to end.
Check whether:
- The customer’s name is consistent throughout.
- Transaction dates match.
- Amounts match.
- The selected reason matches the narrative.
- The transaction details support the explanation.
- The action taken is accurately described.
- The supporting documents correspond to the reported activity.
Sometimes the problem is not one missing field. It is that different parts of the report tell slightly different stories.
How to Fix a Rejected STR on goAML
If your STR has been rejected, the general process is:
Step 1: Open the Rejected Report
Go to the relevant section of your goAML account and locate the rejected STR.
Step 2: Read the Rejection Message
The goAML Message Board is used for communications relating to report acceptance, rejection and requests for additional information.
Read the message carefully and identify each issue.
Step 3: Revert the Report
The UAE goAML FAQ instructs users to use Revert to return the rejected report for editing.
Step 4: Correct the Report
Fix the specific issues identified in the rejection message.
Don’t limit your review to the highlighted field. Check the entire report for related inconsistencies.
Step 5: Review the Narrative
Make sure the reason for suspicion is clear, factual and supported by the information included in the report.
Step 6: Check the Transactions
Compare the transaction details against your original records.
Step 7: Resubmit
Once the report has been reviewed and corrected, resubmit it through goAML within the applicable timeframe.
How Long Do You Have to Resubmit a Rejected STR?
The UAE goAML FAQ states that a rejected report remains available for 5 calendar days, and users can revert, edit and resubmit it before the applicable resubmission grace period expires. It identifies a 10-day grace period for resubmission.
Because timing can matter in AML reporting, businesses should not wait until the final day.
If there is uncertainty about the rejection reason, seek clarification promptly rather than allowing the report to expire.
What If You Cannot Understand the Rejection Reason?
If the rejection message is unclear, do not guess.
Review the applicable UAE FIU/goAML guidance and, where necessary, contact the appropriate goAML support channel or supervisory authority.
The Ministry of Economy & Tourism currently directs users to goAML@uaefiu.gov.ae for technical goAML issues.
For substantive AML reporting questions, businesses should also consider whether guidance from their relevant Supervisory Authority or qualified AML professional is appropriate.
Does a Rejected STR Mean You Do Not Need to Report?
No.
A rejection should not automatically be interpreted as a decision that the underlying activity is not suspicious.
If your business still has the applicable grounds for suspicion, the reporting obligation should be assessed independently of the technical or content issues that caused the first submission to be rejected.
For CBUAE-supervised financial institutions, the rule is particularly clear: an STR or SAR must be filed when there are reasonable grounds to suspect that a transaction, attempted transaction or funds are connected to criminal proceeds, a crime or intended criminal use, regardless of the amount.
What Should the Compliance Officer Check Before Resubmitting?
A short internal checklist can prevent another rejection.
STR Resubmission Checklist
- [ ] Read the rejection reason completely
- [ ] Revert the rejected report
- [ ] Confirm the correct report type
- [ ] Check the internal STR/SAR number
- [ ] Review the description of the suspicion
- [ ] Select the appropriate reporting reason
- [ ] Verify the location of the incident
- [ ] Check all customer and party details
- [ ] Verify transaction dates and amounts
- [ ] Check supporting documents
- [ ] Confirm the action taken by the business
- [ ] Remove inconsistencies
- [ ] Review the complete report
- [ ] Resubmit within the applicable timeframe
How to Reduce goAML STR Rejections
The easiest way to deal with rejected STRs is to prevent avoidable mistakes before submission.
Use an Internal STR Review Process
Don’t let one person prepare and submit every report without review where your organisation’s size and controls allow for a second-level check.
A simple review can catch:
- Missing information
- Incorrect dates
- Incorrect amounts
- Weak narratives
- Wrong reporting indicators
- Missing supporting information
Maintain a Clear Internal STR File
Keep the investigation records, supporting documents and decision-making notes together.
This makes it easier to prepare a complete STR and explain the reasoning behind the report.
Train Your Compliance Team
goAML reporting is not simply a matter of filling in an online form.
Compliance Officers and relevant employees should understand the difference between report types, reporting indicators, transaction information and the information expected in the narrative.
Don’t Rush the Narrative
The reason for suspicion deserves careful attention.
A clear narrative should allow someone who was not involved in the original investigation to understand:
Who was involved → What happened → When it happened → Why it is unusual/suspicious → What checks were performed → What action the business took.
Frequently Asked Questions
Why was my goAML STR rejected?
There can be several reasons, including missing mandatory information, an incorrect report type, inappropriate reporting indicators, insufficient explanation of the suspicion, inaccurate transaction details or inconsistencies within the report.
Can I edit a rejected STR?
Yes. The UAE goAML FAQ states that a rejected report can be reverted, edited and resubmitted within the applicable period.
Should I create a new STR after rejection?
Not automatically. First review the rejection notice and use the available revert/edit process where applicable. The objective is to correct the rejected report rather than simply duplicate it.
How long does a rejected STR stay on goAML?
The UAE goAML FAQ states that rejected reports remain for 5 calendar days. It also refers to a 10-day grace period for resubmission.
Can a rejected STR be submitted again?
Yes. The report can generally be corrected and resubmitted within the applicable timeframe. Make sure the issues identified in the rejection notice have been addressed before resubmission.
What if my STR is rejected again?
Review the latest rejection reason carefully and determine what remains unresolved. If the reason is unclear, contact the appropriate goAML support or supervisory channel rather than repeatedly submitting the same information.
Final Thoughts
A rejected goAML STR can be frustrating, especially when you have already spent time preparing the report. But the rejection itself is not the end of the process.
The most important thing is to understand why the report was rejected and correct the underlying issue before resubmitting.
Pay particular attention to the report type, mandatory fields, reporting reasons, transaction details and—most importantly—the explanation of why the activity is considered suspicious.
Remember that goAML reporting is part of a wider AML compliance process. A strong internal investigation, clear documentation and careful review before submission can significantly reduce avoidable reporting errors.
If your STR is rejected, don’t simply resubmit the same report. Read the rejection reason, correct the report, review it carefully and resubmit within the applicable timeframe.