Blog Image

How to Identify Suspicious Transactions Before Filing a goAML Report

Suspicious transactions are not always large, unusual-looking payments. In many cases, the warning signs are found in the customer’s behaviour, the source of funds, the business rationale, or a pattern that does not match the customer’s expected profile.

For UAE-regulated businesses, identifying these concerns early is essential. A Suspicious Transaction Report (STR) submitted through goAML should be based on a reasonable suspicion arising from known facts, transaction behaviour, documents, and customer due diligence—not on guesswork or bias.

This guide explains how businesses can identify suspicious transactions before filing a goAML report and build a stronger internal AML reporting process.

What is a suspicious transaction?

A suspicious transaction is a transaction, attempted transaction, customer activity, or business relationship that gives reasonable grounds to suspect possible money laundering, terrorist financing, financing of illegal organisations, or another financial crime.

A transaction does not need to be completed before concerns arise. An attempted transaction may also need internal review where the customer’s conduct, documentation, source of funds, or transaction structure appears unusual.

In the UAE, financial institutions and designated non-financial businesses and professions (DNFBPs) are expected to use a risk-based approach, monitor customer activity, and report suspicions to the Financial Intelligence Unit through the goAML system where appropriate.

The key principle: unusual does not always mean suspicious

Not every unusual transaction requires an STR.

For example, a customer may receive an unexpectedly large payment because they have won a genuine contract, sold an asset, received an investment, or expanded into a new market. The important question is whether the business can reasonably understand and verify the explanation.

A transaction may become suspicious when:

  • It does not fit the customer’s known profile, business activity, income level, or expected transaction pattern.
  • The customer cannot provide a credible explanation or supporting documents.
  • The transaction appears unnecessarily complex, concealed, split, or routed through unrelated parties.
  • There are inconsistencies between the customer’s statements, submitted documents, and actual activity.
  • Multiple red flags appear together.

The purpose of AML monitoring is not to accuse customers. It is to identify risks, review them objectively, and escalate concerns through the correct compliance process.

10 common red flags to review before filing a goAML report

1. Transactions inconsistent with the customer’s profile

A customer’s transaction activity should broadly match what is known about their occupation, business, income, declared source of wealth, and expected use of the service.

Examples include:

  • A newly formed company receiving or transferring high-value amounts with no clear commercial activity.
  • A low-income individual making frequent large cash deposits.
  • A small trading company suddenly receiving payments that are far above its stated business turnover.
  • Funds moving through an account without an apparent link to the customer’s business activity.

Ask: Does this activity make commercial and financial sense for this customer?

2. Unclear or unsupported source of funds

Source of funds means the immediate origin of money used in a transaction. A customer may say the money came from “business profits,” “savings,” “loan proceeds,” or “an investor,” but this should be supported where the level of risk requires it.

Red flags may include:

  • The customer is unable or unwilling to provide bank statements, agreements, invoices, payroll records, sale contracts, or loan documents.
  • Supporting documents appear incomplete, inconsistent, altered, or unrelated to the transaction.
  • A stated source of funds does not align with the customer’s known income or business profile.
  • Money is received from an unrelated third party without a clear reason.

3. Third-party payments with no clear commercial reason

Third-party payments are not automatically suspicious. However, they should be examined where the payer, beneficiary, customer, and commercial purpose do not align.

Examples include:

  • Payment for a property, goods, or professional service is made by an unrelated individual or company.
  • The customer asks for payment to be sent to a third party not named in the contract or invoice.
  • Multiple individuals fund one transaction without a documented reason.
  • A customer says they are acting for someone else but refuses to disclose the beneficial owner.

The business should understand who is ultimately involved, why the payment structure is being used, and whether the explanation is supported by documents.

4. Unusual cash activity

Cash is legitimate in many businesses, but it can create higher AML risk when it is large, frequent, unexplained, or inconsistent with the customer profile.

Review situations such as:

  • Frequent cash payments just below an internal or regulatory review threshold.
  • Large cash transactions without a clear explanation of where the cash came from.
  • Cash payments by customers whose business normally operates through bank transfers.
  • A customer who repeatedly converts cash into other assets, instruments, or payments.

Cash activity should be assessed in context. The concern is not simply “cash”—it is cash that cannot be reasonably explained or verified.

5. Structuring or splitting transactions

Structuring occurs when a person divides a larger transaction into several smaller transactions, potentially to avoid scrutiny, documentation requirements, or reporting triggers.

Possible indicators include:

  • Multiple payments made on the same day or over several days for the same transaction.
  • Payments repeatedly made just below internal review limits.
  • Several related people making separate payments for one purchase.
  • A customer cancelling and re-entering transactions in smaller amounts.

A single split payment may have a legitimate reason. Repeated patterns without a sound explanation should be escalated.

6. Complex transactions without business logic

Unnecessary complexity can be a warning sign, particularly where it obscures the identity of the payer, beneficiary, or true purpose of funds.

Examples include:

  • Funds moving through several accounts or companies before reaching the final recipient.
  • Payments involving jurisdictions unrelated to the customer, contract, goods, or service.
  • Multiple changes to beneficiaries or payment instructions.
  • Use of companies with no clear operational role in the transaction.

Ask the customer to explain the commercial rationale. If the explanation remains unclear or unsupported, document the concern.

7. Customer reluctance or evasive behaviour

Customer behaviour matters. A customer who becomes unusually defensive, rushes a transaction, avoids questions, or refuses to provide standard documents may create an elevated risk.

Watch for customers who:

  • Insist that checks should be skipped because they are “urgent” or “confidential.”
  • Provide vague, changing, or contradictory explanations.
  • Refuse to disclose beneficial ownership or the party on whose behalf they are acting.
  • Attempt to influence staff to ignore normal compliance procedures.
  • Ask whether a transaction will be reported to authorities.

A polite but firm compliance process should apply consistently to all customers.

8. Sanctions, high-risk geography, or adverse information

Transactions involving sanctioned persons, restricted jurisdictions, or credible adverse media require immediate and careful review under the business’s AML and sanctions procedures.

Potential indicators include:

  • A customer, beneficial owner, counterparty, or connected party matches a sanctions or watchlist result.
  • Transaction routes involve high-risk or unusual jurisdictions with no commercial explanation.
  • Reliable public information links a customer or connected person to fraud, corruption, financial crime, or serious misconduct.
  • The customer’s ownership structure makes it difficult to identify the ultimate beneficial owner.

Potential matches should be reviewed carefully to avoid false positives. Do not make assumptions based only on nationality, ethnicity, religion, or country of origin.

9. Activity inconsistent with the business’s trade licence or stated purpose

A customer company should generally operate within its declared business model and licensed activities.

Examples include:

  • A consultancy receiving high-value payments for physical goods trading.
  • A newly established company conducting major international transactions without staff, contracts, suppliers, or business infrastructure.
  • Payments that do not match the company’s invoices, website, trade licence, or stated customer base.
  • A company using its account mainly to receive and transfer funds for unrelated entities.

When the activity changes, obtain an updated explanation and supporting evidence. A genuine business may have expanded, but the change should be understood and recorded.

10. Repeated concerns across the customer relationship

One isolated red flag may be explained. A pattern of concerns is more significant.

Consider the full picture:

  • Has the customer given inconsistent information more than once?
  • Have there been repeated third-party payments?
  • Are documents regularly delayed or incomplete?
  • Does the customer’s activity continue to differ from their declared profile?
  • Has the customer previously been subject to enhanced due diligence or internal escalation?

A well-documented pattern is often more meaningful than one transaction viewed in isolation.

A practical five-step review before filing an STR

Step 1: Pause and preserve the facts

Do not make assumptions or confront the customer with an accusation. Record the transaction details, dates, parties involved, payment references, documents received, communications, and why the activity raised concern.

Preserve relevant records according to your AML policy and applicable UAE record-keeping requirements.

Step 2: Compare the activity with the customer profile

Review the customer’s KYC file, beneficial ownership information, risk rating, expected transaction activity, business licence, source of funds, source of wealth where applicable, and prior transaction history.

The question is simple: Is the transaction consistent with what we know about this customer?

Step 3: Seek proportionate clarification

Where appropriate, request further information or documents through normal business communication. Examples include invoices, contracts, proof of delivery, bank statements, loan agreements, asset sale documents, or an explanation of third-party involvement.

Do not tell the customer that an STR is being considered or that a report may be filed.

Step 4: Escalate internally to the compliance officer or MLRO

Frontline staff should not decide alone whether to file a goAML report. They should submit an internal suspicious activity referral to the designated compliance officer or Money Laundering Reporting Officer (MLRO).

The MLRO should assess the information objectively, decide whether suspicion exists, and determine the appropriate action under the organisation’s policies and UAE obligations.

Step 5: File a clear, factual goAML report where required

If the MLRO concludes that there are reasonable grounds for suspicion, the report should be filed through goAML without delay in line with the organisation’s procedures.

A good report should be factual and easy to follow. It should explain:

  • Who is involved, including beneficial owners and connected parties.
  • What happened, including transaction values, dates, payment routes, and account details where relevant.
  • When and where the activity occurred.
  • Why the activity is suspicious.
  • What documents, transaction records, and customer explanations support the concern.
  • What actions the business has taken, such as enhanced due diligence or internal escalation.

Avoid emotional language, unsupported conclusions, or vague statements such as “the customer looks suspicious.” Explain the specific facts and red flags.

Do not tip off the customer

“Tipping off” means disclosing, directly or indirectly, that a suspicious transaction report has been filed or that an investigation may be taking place.

Staff should continue to communicate professionally and follow normal procedures. If a transaction needs to be delayed, declined, or escalated, this should be handled through the organisation’s approved compliance process.

Regular staff training is essential because an accidental comment, email, or message can create significant compliance risk.

Build a stronger AML monitoring process

A reliable AML process is not based on checking transactions only when something goes wrong. It should include:

  • Customer risk assessment at onboarding.
  • Clear expected-activity profiles.
  • Regular KYC and beneficial ownership updates.
  • Transaction monitoring appropriate to the business’s risk level.
  • Enhanced due diligence for higher-risk customers and transactions.
  • A documented internal escalation process.
  • MLRO review and decision records.
  • Staff training with sector-specific examples.
  • Secure retention of KYC, transaction, and review records.

For real estate brokers, accountants, auditors, company service providers, precious-metal dealers, and other DNFBPs, the red flags will differ by sector. Your AML policy should therefore reflect your actual services, customer base, payment methods, and risk exposure.

Final thought

A goAML report is not filed because a customer is “different” or because a transaction is merely large. It is filed when the facts create reasonable grounds for suspicion and the concern cannot be satisfactorily resolved through normal due diligence.

The strongest compliance decisions are evidence-based, documented, and made through a consistent internal process. If your business is unsure how to assess red flags, manage enhanced due diligence, or prepare an internal STR workflow, professional AML support can help strengthen your controls before a high-risk situation arises.

This article is for general information only and does not constitute legal advice. UAE AML obligations should be reviewed against the latest applicable laws, guidance, and your business’s specific regulatory status.

Frequently Asked Questions

1. Does every unusual transaction need to be reported through goAML?

No. An unusual transaction should be reviewed, but an STR is generally considered when there are reasonable grounds for suspicion after assessing the facts, customer profile, explanations, and available documents.

2. Can an attempted transaction be suspicious?

Yes. A transaction does not need to be completed before concerns arise. An attempted transaction may require internal escalation if there are indicators of possible financial crime.

3. What documents should be reviewed when a transaction appears suspicious?

Depending on the transaction, review KYC documents, beneficial ownership records, invoices, contracts, bank statements, proof of source of funds, business licences, correspondence, and previous transaction history.

4. Can we ask the customer why a transaction is unusual?

Yes. You may request reasonable clarification and supporting documents through normal business communication. However, do not disclose that an STR is being considered or filed.

5. Who should decide whether to file a goAML report?

Staff should escalate concerns internally. The designated compliance officer or MLRO should assess the information and decide whether a report is required under the organisation’s AML procedures and UAE obligations.