How to File an STR in goAML UAE: Complete Guide for Businesses
Filing a Suspicious Transaction Report (STR) in goAML UAE is an important part of the UAE’s Anti-Money Laundering (AML) framework. For businesses that fall under the applicable reporting requirements, identifying suspicious activity is only the first step. The business must also have a proper internal process for reviewing the concern, documenting the reasons and, where required, submitting an STR to the UAE Financial Intelligence Unit (FIU). For DNFBPs, the UAE Ministry of Economy & Tourism’s March 2026 guidance states that STRs/SARs must be reported to the FIU without delay once the suspicious nature of the transaction becomes clear. This guide explains what an STR is, when a business may need to file one, who is responsible for filing, what information should be prepared and how the goAML reporting process works.
What Is an STR in the UAE?
STR stands for Suspicious Transaction Report. An STR is a report submitted to the UAE FIU when a reporting entity has the applicable suspicion or reasonable grounds to suspect that a transaction or attempted transaction may be connected to criminal activity, money laundering, terrorist financing or other relevant financial-crime risks. The purpose of an STR is not to prove that a customer has committed a crime. Instead, it allows the FIU to receive and analyse information that may indicate suspicious financial activity. The UAE Ministry identifies goAML as the electronic system used for reporting suspicious transactions and activities to the FIU.
Who Can File an STR in goAML UAE?
The reporting process applies to businesses and professions that fall within the UAE’s applicable reporting framework. For DNFBPs, this includes sectors such as: Real estate brokers and agents Dealers in precious metals and precious stones Independent accountants and auditors Corporate and trust service providers Other applicable DNFBP activities The Ministry provides sector-specific AML guidance and reporting resources for these businesses. A business should first establish whether its activities place it within the relevant reporting-entity category.
Who Is Responsible for Filing an STR?
The designated Compliance Officer plays a central role in the STR process. The March 2026 DNFBP guidance explains that the Compliance Officer is responsible for reviewing and scrutinising records and information concerning suspicious transactions and deciding whether to notify the FIU or maintain the transaction with documented reasons, while maintaining confidentiality. This means an employee does not normally make the final STR decision simply because they notice something unusual. Instead, businesses should have an internal escalation process. A typical process looks like this: Employee or manager identifies a red flag → Internal escalation → Compliance Officer/MLRO reviews → Suspicion is assessed → STR filed through goAML where required This internal process should be documented and understood by relevant employees.
When Should You File an STR?
An STR should not be filed simply because a transaction is unusual. The business should assess the circumstances and determine whether there are reasonable grounds for suspicion under the applicable AML/CFT/CPF requirements. Potential concerns can include: Transactions that do not match the customer’s known profile Unclear or inconsistent source of funds Unexplained complex transactions Unusual third-party payments Transactions involving higher-risk jurisdictions Attempts to conceal beneficial ownership Unusual cash activity Transactions with no apparent economic or legitimate purpose Customer behaviour that does not match the stated business purpose A single red flag does not automatically mean that an STR must be filed. The circumstances need to be assessed using a risk-based approach. The Ministry provides sector-specific red-flag guidance for DNFBPs, including real estate, precious metals and stones, corporate service providers, accountants and auditors.
How to File an STR in goAML UAE
Once the Compliance Officer determines that an STR should be submitted, the report is filed through the FIU’s goAML system.
Step 1: Identify the Suspicious Activity
The process begins when an employee, manager, Compliance Officer or other relevant person identifies potentially suspicious activity. The business should gather the relevant information rather than making assumptions about the customer. This may include: Customer information Transaction details Dates Amounts Payment methods Counterparties Beneficial ownership information Source of funds information Relevant communications Supporting documentation
Step 2: Escalate the Concern Internally
The business should have a documented procedure for employees to report potential suspicious activity internally. The information should be provided to the designated Compliance Officer or MLRO for review. The March 2026 guidance recommends that DNFBPs establish appropriate policies and controls covering internal reporting, investigation, confidentiality and the decision-making process for STRs.
Step 3: Conduct an Internal Review
The Compliance Officer reviews the available information. This may involve: Reviewing the customer’s KYC information Checking the customer’s risk classification Reviewing previous transactions Examining the source of funds or wealth Reviewing beneficial ownership Assessing the customer’s stated purpose Looking at related parties or transactions Considering applicable red flags The purpose is to determine whether the circumstances provide sufficient grounds for an STR.
Step 4: Gather the Information Required for the Report
Before submitting the STR, make sure the relevant information is complete and accurate. The report may need information concerning: The reporting entity Company details Reporting officer details Relevant registration information The customer Full name Identification information Address/contact information Customer relationship details The transaction Transaction date Amount Currency Transaction type Account or payment details where relevant Parties involved The suspicion This is one of the most important parts of the report. The explanation should clearly describe: What happened Why it appears unusual What information raised the concern Why the activity does not appear consistent with the customer’s known profile or stated purpose Any relevant red flags Supporting information available to the business
Step 5: Log in to goAML
The authorised reporting entity accesses the goAML platform using its approved credentials and authentication method. The Ministry’s current goAML instructions explain the registration and portal access process and provide sector-specific resources, including a goAML Web Submission Guide and guidance on How to Submit a Report to the FIU.
Step 6: Select the Appropriate Report Type
The reporting entity selects the appropriate report type within the goAML system based on the circumstances. Businesses should ensure they understand the difference between the following: STR — Suspicious Transaction Report SAR — Suspicious Activity Report The appropriate reporting category depends on the facts and applicable requirements.
Step 7: Enter the Report Details
Complete the required fields accurately. Avoid vague statements such as: “The transaction looks suspicious.” Instead, provide a factual explanation of the circumstances and the reasons for the suspicion. A strong narrative should allow the FIU to understand the situation without having to guess what happened.
Step 8: Upload Supporting Information Where Required
Where relevant and appropriate, provide supporting documentation and information through the reporting process. Examples may include: Transaction records Customer identification information Contracts Invoices Bank-related information Ownership documents Correspondence Other relevant records Only provide information that is relevant to the report and follow the applicable goAML requirements.
Step 9: Review the STR Before Submission
Before submitting the report, check: Customer information Transaction amount Dates Parties Transaction type Reason for suspicion Supporting information Contact details Report classification An inaccurate STR can create unnecessary compliance issues.
Step 10: Submit the STR
Once the compliance officer has reviewed the report and confirmed that reporting is required, the STR can be submitted to the FIU through goAML. The March 2026 DNFBP guidance states that applicable STRs/SARs should be reported without delay once the suspicious nature of the transaction becomes clear.
What Should You Write in an STR Narrative?
The narrative is one of the most important parts of the report. A useful narrative should be clear, factual, and specific. For example, instead of writing: “Customer made unusual payments.” A stronger explanation would identify the following: The customer’s normal activity The transaction that triggered concern The amount and date The parties involved Why the transaction was inconsistent with the customer’s known profile What explanation the customer provided, if any Why that explanation did not resolve the concern What supporting information is available The objective is to explain why the transaction is suspicious, rather than simply stating that it is suspicious.
How Long Do You Have to File an STR?
For DNFBPs, the March 2026 guidance states that STRs/SARs must be submitted to the FIU without delay. The guidance explains that once the compliance officer confirms that a transaction is suspicious, whether it is pending, in progress, or already completed, it should be reported immediately. This is why businesses should have an internal escalation procedure that allows employees to raise concerns promptly. Waiting until the end of the month or conducting an unnecessarily lengthy internal process can create compliance risks.
Can You Continue the Customer Relationship After Filing an STR?
Filing an STR does not automatically mean that every customer relationship must be terminated. The business needs to assess the situation and follow its AML policies and applicable legal requirements. The March 2026 DNFBP guidance specifically refers to procedures for follow-up actions and handling business relationships after an STR has been filed. The decision should therefore be risk-based and properly documented.
What Is Tipping Off?
Tipping off refers to improperly disclosing information that could alert a customer or another person that a suspicious transaction report has been or will be submitted. This can compromise an investigation and create legal and regulatory risks. Businesses should therefore maintain strict confidentiality around: Internal suspicious-activity reviews STR decisions Reports submitted to the FIU Requests or follow-up from competent authorities The March 2026 DNFBP guidance specifically addresses confidentiality and the prohibition against tipping off.
Common STR Filing Mistakes
Writing a Weak Narrative
A vague description makes it difficult to understand why the activity is suspicious.
Reporting Without Investigation
A business should not treat every unusual transaction as automatically suspicious.
Delaying the Report
The applicable guidance requires reporting without delay once the suspicious nature becomes clear.
Missing Important Customer Information
Incomplete KYC or transaction information can weaken the quality of the report.
Ignoring Beneficial Ownership
Complex or unclear ownership structures can be important to the overall risk assessment.
Poor Internal Escalation
Employees should know exactly who to contact when they identify a potential AML concern.
Discussing the STR With the Customer
Businesses need to maintain confidentiality and avoid prohibited tipping-off.
STR vs SAR in UAE goAML
STR SAR Suspicious Transaction Report Suspicious Activity Report Focuses on suspicious transactions Focuses on suspicious activity or applicable attempted activity Submitted through the applicable FIU reporting system Submitted through the applicable FIU reporting system Requires a clear explanation of the suspicion Requires a clear explanation of the suspicious activity Subject to applicable UAE AML reporting requirements Subject to applicable UAE AML reporting requirements
The FIU’s goAML framework supports the reporting of STRs and SARs, while the precise report type should be selected based on the facts and applicable requirements.
Why Your AML Process Matters Before an STR Is Filed
A good STR process starts long before someone opens go-AML. Your business should already have: A documented AML/CFT/CPF risk assessment KYC and CDD procedures UBO identification procedures Customer risk classification Transaction monitoring Internal escalation procedures A designated Compliance Officer AML record-keeping procedures Staff AML training Sanctions and targeted financial sanctions controls where applicable The Ministry’s current AML resources provide sector-specific compliance guidance and reporting materials for DNFBPs.
2026 STR Compliance Checklist
Before submitting an STR, the compliance officer should check the following: Customer has been correctly identified Relevant KYC information has been reviewed Beneficial ownership has been assessed Transaction details are accurate The customer risk profile has been reviewed Relevant red flags have been considered Source of funds/wealth information has been reviewed where relevant An internal investigation has been documented The reason for suspicion is clearly explained Supporting information has been identified Appropriate report type has been selected Confidentiality controls are in place The report is submitted without delay where required
Final Thoughts
Filing an STR in goAML UAE is not simply a matter of filling out an online form. The quality of the report depends on the entire AML process behind it — from customer due diligence and transaction monitoring to internal escalation, Compliance Officer review and accurate reporting. For DNFBPs, the March 2026 guidance makes the timing requirement particularly important: once the suspicious nature of a transaction becomes clear, the applicable STR/SAR should be submitted to the FIU without delay. Businesses should therefore make sure their employees understand how to escalate concerns and that their Compliance Officer or MLRO has a clear, documented process for investigating and reporting suspicious activity. If your business is unsure whether its current goAML reporting process meets UAE AML requirements, a professional AML compliance review can help identify gaps before they become a regulatory problem.
Frequently Asked Questions
What is an STR in goAML UAE?
An STR is a Suspicious Transaction Report submitted to the UAE Financial Intelligence Unit through the applicable goAML reporting system when the relevant suspicion or reasonable grounds for suspicion exist.
Who can submit an STR?
For DNFBPs, the designated Compliance Officer has a central role in reviewing suspicious transactions and deciding whether to notify the FIU.
When should an STR be filed in the UAE?
Applicable STRs/SARs should be reported to the FIU without delay once the suspicious nature of the transaction becomes clear.
Can I file an STR without goAML registration?
DNFBPs subject to the applicable reporting requirements need to use the FIU’s approved reporting system. The Ministry identifies goAML as the electronic system used for STR/SAR reporting.
What information should an STR contain?
The report should contain accurate information about the reporting entity, customer, transaction, parties involved and the reasons for the suspicion, together with relevant supporting information where required.
What makes a good STR narrative?
A good narrative explains the facts clearly and logically. It should show what happened, why the activity is inconsistent or concerning, and what information led the compliance officer to form the suspicion.
Can a business tell the customer that an STR was filed?
Businesses must observe applicable confidentiality requirements and tipping-off restrictions. Information about an STR should not be improperly disclosed to the customer or other unauthorised persons.
Is every unusual transaction an STR?
No. An unusual transaction is a potential red flag, but the business should assess the circumstances and determine whether the applicable threshold for suspicion and reporting has been met.
What happens after an STR is filed?
The FIU receives and analyses reports. The reporting entity may also need to maintain records and respond to lawful requests or follow-up requirements from competent authorities.
Do UAE businesses need AML procedures before filing an STR?
Yes. An effective STR process should be part of a broader AML/CFT/CPF framework that covers customer due diligence, risk assessment, transaction monitoring, internal reporting, and compliance officer oversight.