How to File an STR in goAML UAE: A Complete Guide for Reporting Entities
Businesses in the UAE that identify potentially suspicious transactions or activities have an important AML reporting responsibility. For reporting entities registered with the UAE Financial Intelligence Unit (FIU), goAML is the electronic platform used to submit suspicious reports.
An STR (Suspicious Transaction Report) is submitted when a reporting entity suspects that a transaction or transactions may be connected to money laundering, fraud, terrorist financing, or another relevant financial crime. The UAE FIU states that an STR should be submitted through goAML when suspicious transactions are identified during the customer relationship or while conducting transactions for a customer or potential customer.
Understanding when an STR is required, what information should be prepared, and how the goAML reporting process works can help businesses maintain effective AML compliance.
What Is an STR in the UAE?
STR stands for Suspicious Transaction Report.
It is a report submitted to the UAE FIU when a reporting entity identifies a transaction or pattern of transactions that creates a suspicion of money laundering, fraud, terrorist financing, or another financial crime.
The important point is that an STR is not necessarily based on proof that a crime has occurred. A reporting entity should assess the available information and determine whether there are reasonable grounds for suspicion under its AML/CFT framework.
The UAE FIU’s goAML guidance distinguishes an STR from a SAR. An STR relates to suspicious transactions, while a Suspicious Activity Report (SAR) can be used where suspicious activity or an attempted, non-executed transaction is identified.
Who Can File an STR Through goAML?
STRs are submitted by reporting entities registered with the UAE FIU’s goAML system.
The UAE FIU states that accountable and reporting entities in the UAE are required to register on goAML in order to submit suspicious reports. The current goAML portal also explains that registered reporting entities use the system to file STRs and SARs.
Depending on the sector, reporting entities can include financial institutions and relevant Designated Non-Financial Businesses and Professions (DNFBPs).
Examples may include:
- Real estate businesses
- Dealers in precious metals and stones
- Company service providers
- Auditors and accountants
- Certain legal professionals
- Financial institutions
- Other businesses covered by UAE AML/CFT requirements
The exact obligations depend on the entity’s business activity, regulator, and applicable UAE legislation.
When Should a Business File an STR?
A business should consider an STR when its assessment identifies a transaction or pattern that gives rise to suspicion of relevant financial crime.
Potential warning signs can include:
- Transactions that do not match the customer’s known business profile
- Unusual movement of funds
- Complex transactions without a clear economic purpose
- Unexplained third-party payments
- Inconsistent information about the source of funds
- Unusual cash activity
- Transactions involving higher-risk jurisdictions
- Rapid movement of funds without an apparent commercial reason
- Attempts to conceal the beneficial owner
- Unusual use of corporate structures
- Transactions inconsistent with the customer’s expected activity
A single red flag does not automatically mean that an STR must be filed.
Businesses should consider the full circumstances, customer information, transaction history, risk profile, and other available information before reaching a reporting decision.
The UAE FIU publishes sector-specific typology and risk-indicator material to help reporting entities understand suspicious patterns. For example, its analysis of real-estate money laundering identifies risks involving third parties, legal structures, rental income, mortgage financing, early settlement, and property-price manipulation.
Step 1: Identify the Suspicious Transaction or Activity
The first stage is identifying what triggered the suspicion.
This may happen through:
- Transaction monitoring
- Customer due diligence
- Enhanced due diligence
- Internal AML reviews
- Employee escalation
- Periodic customer reviews
- Adverse information
- Sanctions or screening alerts
- Unusual transaction patterns
The compliance or MLRO function should review the available information and determine whether the matter requires escalation.
The decision should be supported by documented reasoning.
Step 2: Conduct an Internal Review
Before submitting an STR, the reporting entity should gather the relevant information needed to understand the customer’s activity.
Depending on the case, this can include:
- Customer identification information
- Beneficial ownership information
- Customer risk rating
- Account or relationship history
- Transaction details
- Source of funds information
- Source of wealth information
- Supporting documents
- Relevant communications
- Previous unusual transactions
- Information about counterparties
- Internal investigation findings
The objective is not simply to collect as much information as possible. The information should help explain why the transaction or activity is considered suspicious.
Step 3: Determine Whether an STR or SAR Is Appropriate
One important part of the goAML process is selecting the appropriate report type.
According to UAE FIU guidance:
STR: Used when a reporting entity suspects transactions related to money laundering, fraud, or terrorist financing.
SAR: Used when the entity suspects activity or an attempted transaction that has not been executed and may relate to money laundering, fraud, or terrorist financing.
The distinction matters because the report should accurately describe what happened.
If you are unsure whether the circumstances fall under STR or SAR reporting, the business should review the applicable FIU guidance and its internal AML procedures.
Step 4: Prepare the STR Information
A strong STR should give the FIU a clear understanding of the case.
The report should contain relevant information about:
The Customer
Include available identification and customer-profile information.
The Transaction
Explain:
- What happened
- When it happened
- Amount involved
- Currency
- Transaction type
- Sender
- Recipient
- Relevant accounts or parties
The Suspicion
This is one of the most important parts of the report.
Explain why the activity appears suspicious.
Avoid simply writing that a transaction is “unusual.” Describe the facts that created the suspicion and connect those facts to the customer’s profile or expected activity.
Supporting Information
Include relevant information and documentation where required by the reporting process.
The goal is to provide a clear, factual narrative that allows the FIU to understand the case.
Step 5: Access the goAML System
The reporting entity must have the appropriate access to the UAE FIU’s goAML platform.
The UAE FIU’s current registration portal provides access for reporting entities and explains that the goAML service enables registered entities to file STRs and SARs.
The UAE FIU registration guide also states that reporting entities register to obtain the ability to submit suspicious reports through goAML.
Access should be handled by authorised personnel within the organisation, such as the designated Money Laundering Reporting Officer (MLRO) or another appropriately authorised user.
Step 6: Create the STR in goAML
Once the appropriate user has accessed goAML, the report can be created using the relevant report type.
The reporting process generally involves entering information about:
- Reporting entity
- Subject/customer
- Suspicious transaction
- Related parties
- Accounts
- Beneficial owners
- Transaction details
- Suspicion indicators
- Narrative
- Supporting information
The exact fields and interface can be updated by the UAE FIU. Businesses should therefore follow the latest goAML interface and official user guidance rather than relying solely on screenshots or older third-party instructions.
Step 7: Write a Clear STR Narrative
The narrative is one of the most important parts of an STR.
A useful narrative should answer five basic questions:
Who? Who is the customer or relevant party?
What? What transaction or activity occurred?
When? When did the relevant activity take place?
Where? Which accounts, countries, businesses, or parties are involved?
Why suspicious? What facts caused the reporting entity to suspect potential financial crime?
For example, instead of writing:
“The customer’s transactions are suspicious.”
A stronger approach would explain the customer’s normal activity, describe the unusual transactions, identify the relevant counterparties, and explain why the activity does not appear consistent with the customer’s stated business or financial profile.
The report should remain factual, concise, and evidence-based.
Step 8: Review the Report Before Submission
Before submitting an STR, conduct an internal quality check.
Verify:
- Customer details
- Transaction dates
- Amounts
- Currency
- Account information
- Counterparty details
- Beneficial ownership information
- Suspicion indicators
- Narrative
- Supporting documents
- Internal reference numbers
Errors or missing information can make a report less useful for financial intelligence analysis.
The person responsible for the submission should also confirm that the report is being filed under the appropriate reporting entity and authorised user account.
Step 9: Submit the STR Through goAML
Once the report has been reviewed and completed, the authorised user submits it through goAML.
The UAE FIU’s guidance explains that reporting entities use goAML to submit suspicious reports to the FIU.
After submission, the reporting entity should retain the relevant internal records in accordance with its AML/CFT record-keeping obligations and internal procedures.
What Happens After an STR Is Submitted?
Submitting an STR does not necessarily mean the reporting entity’s involvement ends.
The FIU may require additional information while reviewing the report.
The UAE FIU’s goAML reporting guide identifies several report types that may be used when additional information is required, including:
- AIF – Additional Information File without transactions
- AIFT – Additional Information File with transactions
- RFI – Request for Information without transactions
These requests are handled through the goAML system and may require the reporting entity to provide additional information to the FIU.
Businesses should therefore monitor the goAML system and ensure that authorised compliance personnel can respond to FIU requests appropriately.
STR vs SAR: What’s the Difference?
| STR | SAR |
|---|---|
| Suspicious Transaction Report | Suspicious Activity Report |
| Used for suspicious transactions | Used for suspicious activity or attempted transactions |
| May involve an executed transaction | Can involve a non-executed/attempted transaction |
| Submitted through goAML | Submitted through goAML |
The UAE FIU’s official guide should be used when determining the appropriate report type for a specific case.
Common STR Filing Mistakes
Writing a Vague Narrative
Simply saying that a transaction is “suspicious” does not explain the basis for the suspicion.
Providing Inconsistent Information
Dates, amounts, customer details, and transaction information should be consistent throughout the report.
Ignoring the Customer’s Profile
A transaction should be considered in context. The customer’s expected activity, occupation, business model, risk profile, and transaction history can all be relevant.
Filing Without Adequate Internal Review
The MLRO or authorised compliance function should ensure that the report has been properly assessed before submission.
Failing to Monitor FIU Requests
An STR may lead to requests for additional information. Businesses should monitor their goAML communications and respond appropriately.
Treating STR Reporting as a One-Time AML Task
Effective AML compliance requires ongoing monitoring, risk assessment, customer due diligence, record keeping, and escalation—not simply filing reports when an issue appears.
How Businesses Can Improve STR Reporting
A strong STR reporting framework should be supported by:
Clear AML Policies
Employees should understand how suspicious transactions are identified and escalated.
Employee Training
Staff who interact with customers or transactions should understand relevant red flags.
Effective Transaction Monitoring
Businesses should have appropriate processes for identifying unusual activity.
Strong Customer Due Diligence
Accurate customer and beneficial-owner information makes unusual activity easier to identify.
Documented Escalation Procedures
Employees should know who to contact when they identify a potential AML concern.
Regular AML Risk Assessments
The business should periodically reassess its exposure to money laundering and terrorist-financing risks.
Does Every Unusual Transaction Require an STR?
No.
An unusual transaction is not automatically a suspicious transaction.
A business should assess the circumstances using a risk-based approach and consider all relevant information.
For example, a large transaction may have a legitimate explanation if it is consistent with the customer’s business activity and supported by appropriate documentation.
Conversely, a relatively small transaction may raise concerns when it forms part of a broader pattern of suspicious activity.
The quality of the assessment is therefore important.
Why Accurate STR Reporting Matters
STRs form an important part of the UAE’s financial-intelligence framework.
The UAE FIU analyses suspicious reports and other financial intelligence to identify potential financial-crime patterns and support relevant authorities.
The FIU’s recent publications continue to highlight emerging risks, including fraud, trade-based money laundering, real-estate money laundering, and misuse of virtual assets.
For reporting entities, this means STR reporting should be treated as part of a broader AML/CFT control framework rather than simply an administrative requirement.
Final Thoughts
Filing an STR in goAML UAE is an important responsibility for reporting entities that identify suspicious transactions or activities.
The process starts with identifying unusual or suspicious activity, conducting an appropriate internal assessment, selecting the correct report type, preparing accurate information, and submitting the report through the goAML platform.
A good STR should clearly explain what happened, who was involved, when it happened, and why the activity created suspicion. It should be factual, supported by relevant information, and consistent with the reporting entity’s AML/CFT procedures.
Businesses should also remember that STR reporting is only one part of AML compliance. Effective compliance requires ongoing customer due diligence, risk assessment, transaction monitoring, employee training, record keeping, and appropriate escalation procedures.
Because UAE FIU guidance and goAML procedures can be updated, reporting entities should always refer to the latest official FIU guidance and platform requirements when preparing an actual submission.
Frequently Asked Questions
What is an STR in goAML UAE?
An STR is a Suspicious Transaction Report submitted through the UAE FIU’s goAML platform when a reporting entity suspects that transactions may be connected to money laundering, fraud, terrorist financing, or related financial crime.
Who can file an STR in the UAE?
Registered reporting entities use the UAE FIU’s goAML platform to submit STRs and other suspicious reports. Access is provided through the FIU’s registration and launch-portal process.
How do I file an STR in goAML?
The general process involves identifying and assessing suspicious activity, gathering relevant customer and transaction information, selecting the appropriate report type, entering the required information in goAML, reviewing the report, and submitting it through the authorised reporting entity account.
What is the difference between an STR and SAR?
An STR relates to suspicious transactions, while a SAR can be used for suspicious activity or an attempted transaction that has not been executed. The UAE FIU’s official goAML guide provides the relevant distinction.
What information should an STR contain?
An STR should provide relevant information about the customer, transaction, involved parties, accounts, beneficial ownership where applicable, and the reasons for the suspicion. The narrative should clearly explain the facts that led to the reporting decision.
Can an STR be filed for an attempted transaction?
Where the suspicious matter concerns an attempted or non-executed transaction, the UAE FIU’s goAML guidance identifies SAR as the applicable report type in that circumstance.
What happens after filing an STR?
The FIU may review the report and request additional information. The goAML reporting guide identifies AIF, AIFT, and RFI report types for situations where further information may be requested.
Does every unusual transaction require an STR?
Not necessarily. Reporting entities should assess transactions in context using their AML/CFT framework and a risk-based approach. An unusual transaction may have a legitimate explanation, while suspicious activity can also become apparent through a pattern of transactions.
Who is responsible for STR reporting within a company?
The reporting entity should have an appropriately authorised compliance function, typically involving its MLRO or designated AML/CFT personnel, responsible for assessing and submitting suspicious reports in accordance with applicable requirements.