What Happens After Filing an STR Through goAML?
Filing a Suspicious Transaction Report (STR) through goAML is an important step in meeting AML/CFT reporting obligations in the UAE. But submitting the report is not necessarily the end of the process.
Once an STR reaches the UAE Financial Intelligence Unit (UAE FIU), the information may be reviewed, analysed and, where necessary, followed up with the reporting entity. The FIU may request additional information, provide further instructions, or take no further action that requires communication with the reporting entity.
Understanding what happens after an STR is submitted can help businesses, compliance officers and MLROs manage their responsibilities more effectively.
What Is an STR in the UAE?
A Suspicious Transaction Report, commonly called an STR, is submitted when a reporting entity suspects that a transaction may be connected to money laundering, fraud, terrorist financing or another relevant financial crime.
The UAE FIU’s goAML guidance explains that an STR should be submitted when a reporting entity suspects transactions related to money laundering, fraud or terrorist financing. The report is submitted electronically through the goAML system.
For applicable DNFBPs and financial institutions, STR reporting forms part of their wider AML/CFT obligations.
What Happens Immediately After an STR Is Submitted?
Once the STR has been completed and successfully submitted through goAML, it is made available to the FIU for review.
The reporting entity should not assume that receiving no immediate response means the report has been rejected or ignored.
The UAE FIU specifically states in its reports FAQ that there is no expectation that the FIU will respond to every STR or SAR. The FIU may contact the reporting entity if a report requires further due diligence or additional information.
This means the post-submission process can vary depending on the circumstances and information contained in the report.
Does the FIU Review Every STR?
STRs submitted through goAML are provided to the FIU for analysis. However, reporting entities should not expect a standard individual response to every report.
The FIU may determine that additional information is necessary to understand the reported activity. If so, the reporting entity may receive a request through the goAML Message Board.
The UAE FIU’s reporting guide identifies specific supplementary report types that can be used when additional information is requested.
What If the FIU Requests More Information?
This is one of the most important things to understand after submitting an STR.
If the FIU needs more information, the reporting entity may receive a request through the goAML Message Board.
Depending on what is required, this can involve different report types.
AIF – Additional Information File
An AIF is used when the FIU requires additional information that does not include transactions.
For example, the FIU may need clarification about a customer, business relationship, source of funds or other information connected to the original STR.
The reporting entity should provide the requested information accurately and reference the original report where required.
AIFT – Additional Information File With Transactions
An AIFT is used when the FIU requests additional information that includes transaction details.
This allows the reporting entity to provide the additional transactional information requested by the FIU through goAML.
RFI – Request for Information
The FIU may also send a Request for Information (RFI) through the goAML Message Board when additional information is required from reporting entities.
DNFBPs may therefore need to monitor their goAML Message Board regularly rather than treating STR submission as a one-time task.
Can You Edit an STR After Submission?
You should take care when reviewing an STR before submitting it.
For licensed financial institutions, the CBUAE guidance states that once a report has been submitted and accepted in goAML, changes cannot be made to correct missing or incorrect information through an amendment to the original report. Instead, the reporting entity may use an appropriate supplementary report such as an AIF, AIFT, RFI or RFIT where applicable.
This is why the MLRO or compliance officer should review the report carefully before submission.
Check the:
- Customer information
- Transaction details
- Reason for suspicion
- Reporting narrative
- Source and destination of funds
- Supporting documentation
- Internal reference number
- Actions already taken by the reporting entity
A properly prepared STR can make any subsequent FIU review more straightforward.
Does the FIU Tell You What Happened to the STR?
Not necessarily.
An STR is a confidential report submitted to the FIU. The FIU does not have to provide the reporting entity with an outcome or detailed explanation of how the intelligence is used.
The UAE FIU’s 2024 Reports FAQ states that there is no expected response time for STRs/SARs because the FIU does not necessarily respond to each report. However, it may send questions or requirements when a report merits further due diligence.
The FIU also provides quarterly feedback reports through the goAML Message Board to reporting entities and their respective supervisory bodies.
Should You Continue Monitoring the Customer?
Yes.
Filing an STR does not automatically mean that all monitoring of the customer or business relationship should stop.
The appropriate approach depends on the nature of the risk, the entity’s internal AML policies, applicable regulations and any instructions received from the FIU or relevant supervisory authority.
For licensed financial institutions, CBUAE guidance explains that following an STR/SAR filing, the institution should continue managing the customer relationship based on its internal policies, risk appetite and relevant risk factors.
For certain regulated sectors, additional sector-specific requirements may also apply.
Can You Close the Customer’s Account After Filing an STR?
Not automatically.
Submitting an STR does not by itself mean that the customer must immediately have their account or business relationship terminated.
The appropriate action depends on the circumstances and the organisation’s AML/CFT framework.
A reporting entity may need to consider options such as:
- Continuing the relationship with enhanced monitoring
- Restricting certain activities
- Conducting additional due diligence
- Reviewing the customer’s risk classification
- Exiting the relationship where appropriate
Any decision should be made in accordance with applicable laws, regulatory requirements and internal policies.
What Is Tipping Off?
One of the most important responsibilities after filing an STR is maintaining confidentiality.
Tipping off generally refers to informing a customer or another unauthorised person that a suspicious transaction report has been filed, or that an investigation is taking place.
The CBUAE states that reporting entities and their personnel must not inform customers or other persons, directly or indirectly, that an STR/SAR has been or will be filed, or disclose information contained in the report or an investigation concerning the transaction.
This means employees should be careful about how they communicate with customers after suspicious activity has been identified.
For example, telling a customer, “We filed an STR about your transaction” could create serious compliance issues.
What Should the MLRO Do After Filing an STR?
The MLRO or Compliance Officer should continue managing the case according to the organisation’s AML procedures.
Practical steps may include:
1. Keep Internal Records
Maintain appropriate records relating to the suspicious activity, investigation, decision-making process and submitted report.
2. Monitor the goAML Message Board
The FIU may communicate requests for additional information through goAML.
3. Respond to FIU Requests
If an AIF, AIFT, RFI or another request is received, the requested information should be reviewed and submitted accurately within the applicable timeframe.
4. Continue Risk-Based Monitoring
The customer or transaction may require continued monitoring depending on the circumstances and the organisation’s internal risk assessment.
5. Maintain Confidentiality
Access to STR information should be restricted to authorised personnel who need the information for legitimate compliance purposes.
How Long Should STR Information Be Kept?
Record-keeping requirements depend on the applicable UAE legislation and the type of reporting entity.
The UAE FIU’s reports FAQ states, in relation to information connected with suspicious transactions and clients in the context addressed there, that relevant information should be maintained for a minimum of five years from the date of the transaction.
Businesses should therefore have a documented record-retention procedure that reflects the requirements applicable to their sector.
What If You Do Not Hear Back From the FIU?
This is not necessarily a problem.
A reporting entity should not assume that an STR has failed simply because it has not received a direct response.
The FIU’s own FAQ makes clear that there is no expectation that it will respond to every STR/SAR. The FIU may contact the reporting entity when further due diligence or information is required.
The best approach is to:
- Keep the STR and related records securely.
- Continue following your AML procedures.
- Monitor the goAML Message Board.
- Respond promptly if the FIU requests additional information.
- Avoid tipping off the customer.
What If You Discover an Error in the STR?
Do not simply assume that you can reopen and edit the submitted report.
For licensed financial institutions, CBUAE guidance specifically states that accepted reports cannot be amended directly. Appropriate supplementary report types may instead be used where applicable.
If you discover a material error, the MLRO or compliance officer should assess the issue and determine the appropriate reporting action under the applicable regulatory framework.
Does Filing an STR Mean the Customer Is Guilty?
No.
An STR is a report of suspicion, not a declaration that a customer has committed a crime.
The purpose of suspicious transaction reporting is to provide relevant information to the FIU so that it can conduct financial intelligence analysis and determine whether further action is appropriate.
Businesses should therefore avoid treating the filing of an STR as proof of criminal activity.
Common Mistakes After Filing an STR
Businesses can create additional compliance risks if they assume their responsibilities end once the report is submitted.
Common mistakes include:
- Ignoring the goAML Message Board
- Failing to respond to an FIU information request
- Discussing the STR with the customer
- Allowing unauthorised employees to access STR information
- Stopping all monitoring immediately after filing
- Failing to maintain supporting records
- Assuming every STR will receive an individual response
- Trying to modify an accepted report instead of using the appropriate supplementary reporting mechanism
Frequently Asked Questions
How long does the FIU take to respond to an STR?
There is no standard response time or expectation that the FIU will respond to every STR. The FIU may contact the reporting entity if additional due diligence or information is required.
What happens if the FIU needs more information?
The reporting entity may receive a request through the goAML Message Board. Depending on the information required, the entity may need to submit an AIF, AIFT, RFI or another applicable report.
Can I edit an STR after submitting it?
For licensed financial institutions, an accepted STR cannot simply be amended. The appropriate supplementary report mechanism should be used where applicable.
Should I tell the customer that an STR was filed?
No. Reporting entities must maintain confidentiality and should not disclose the filing of an STR or related investigation information to the customer where doing so would constitute tipping off.
Does filing an STR mean the customer relationship must end?
Not automatically. The appropriate action depends on the risk, applicable regulations, internal policies and any instructions received from the relevant authorities.
Does every STR receive a response?
No. The UAE FIU states that there is no expectation that the FIU will respond to every STR or SAR.
Final Thoughts
Filing an STR through goAML is an important AML reporting step, but it should not be viewed as the end of the compliance process.
After submission, the reporting entity should maintain proper records, monitor the goAML Message Board, remain prepared to provide additional information and continue managing the relevant customer or business relationship on a risk-based basis.
Most importantly, confidentiality must be maintained. Businesses should never assume that a customer can simply be told that an STR has been filed.
A strong post-STR process helps an organisation respond properly if the UAE FIU requests further information while maintaining its wider AML/CFT obligations.