
Filing an STR in the UAE: A Practical Walkthrough of goAML
Every compliance officer knows the moment. A transaction lands on your desk and something about it just doesn't add up. What happens next isn't really a judgment call you make on your own; it's a defined process, and in the UAE that process runs through one system called goAML. The platform is run by the Financial Intelligence Unit or FIU (Financial Intelligence Unit).
So let's walk through it properly. What a Suspicious Transaction Report or STR actually is. When you're required to file one and how to get a submission through goAML from start to finish. Whether you're setting up a compliance function from scratch or just want something your team can come back to, this should cover what you need.
So What Exactly Is an STR?
An STR is basically a formal report you send to the FIU whenever you have reasonable grounds to suspect that funds or an attempted transaction are tied to money laundering, terrorist financing, or some other kind of criminal activity.
And it's not optional. Under UAE AML and CFT law, licensed financial institutions and DNFBPs (think real estate brokers, dealers in precious metals and stones, auditors, company service providers, and so on) are legally required to report suspicion. That holds no matter how small the amount is, and it doesn't matter whether the transaction actually went through or not.
It is worth repeating this part, because it trips people up: an STR is about suspicion, not proof. Nobody is asking you to prove a crime happened. You just need reasonable, well-documented grounds to think one might have.
STR or SAR? Honestly, the Line Is Thinner Than You'd Think
An STR responds to one specific transaction that raised a flag, whether it went through or was only attempted. A SAR on the other hand responds to a pattern. A broader picture of suspicious behavior where no single transaction on its own tells the whole story.
Both are covered by the same FIU rules and both go through the same goAML system, so in practice the standards for what to report and how to report it line up pretty closely between the two.
What goAML Actually Is
goAML is a case management platform that was originally built by the UNODC(United Nations Office on Drugs and Crime) and is now used by the UAE's FIU, which sits under the Central Bank. It's the only channel through which STRs, SARs, Cash Transaction Reports and freeze or unfreeze notifications get submitted.
There is no workaround here. No inbox to email, no form to fax over. If your business counts as a reporting entity, goAML is where the whole process starts and ends. Getting comfortable with this platform is honestly most of what it means to stay on top of AML reporting in the UAE.
Step 1: Get Your Entity Registered
Nothing can be filed until your organisation has an active account, so this comes first. You start by heading to the official goAML registration portal through the UAE Central Bank or FIU website. From there, you register as a "Reporting Entity," which means submitting your trade license details, your regulator information and naming a compliance contact. You'll also need to appoint a Compliance Officer, since this person holds admin rights on the account and becomes the main point of contact with the FIU. Once your registration gets approved, you're issued credentials to log into the portal.
This is mostly a one-time task. That said, it's worth keeping contact details and authorised users up to date as your team changes over time.
Step 2: Work Out Whether You're Actually Looking at Something Suspicious
Before goAML even opens, there is usually an internal review that happens first. A transaction gets flagged whether by a staff member, a monitoring system, or a screening alert. That flag then goes up to the Compliance Officer or the MLRO, meaning the Money Laundering Reporting Officer. From there, the case gets reviewed, documented and weighed against the threshold for filing.
Some of the more common triggers worth knowing: activity that doesn't match a customers known business or income, structuring (where large amounts get broken into smaller transactions specifically to dodge reporting thresholds), involvement of higher-risk jurisdictions, a customer who is reluctant to hand over ID or source of funds documentation, ownership structures that are oddly complex with no clear commercial reason behind them and any hit against sanctions lists or PEP screening, where PEP means Politically Exposed Person.
Step 3: Pull the Information Together Before You Start
Before you even open the report, it helps to have everything ready. That means full identifying details on the customer, whether that is an ID or passport for an individual or a trade license for an entity. You'll also want the transaction details themselves. Date, amount, currency, channel, and who was on the other end. Then there's the narrative which explains factually why the transaction raised concern and this is genuinely the part analysts scrutinize the most. On top of that, gather your supporting paperwork, things like account statements, correspondence, and KYC records, along with your own internal case reference for your audit trail.
Take the narrative seriously. Something vague like "transaction seemed unusual" tells an analyst basically nothing. Compare that to something like: the customer, a retail trading company, received three wires from unrelated entities in a given jurisdiction totaling a specific amount within 48 hours, followed by an immediate cash withdrawal that didn't match the account's stated business activity. That level of detail is what actually moves a case forward.
Step 4: Open the Report in goAML
Once you're ready, log into the goAML portal and head to the reporting section. From there, you pick STR or SAR depending on what you're dealing with. You'll also need to decide between the standard web form and if you're a larger institution, a batch upload via XML. For most small and mid-sized reporting entities, the web form is more than enough and doesn't require any extra IT setup.
Step 5: Fill In Each Section
A typical STR submission is made up of a handful of sections. The Reporting Entity Details get pulled automatically from your registration. The Report Details cover the type of report, the date it was detected and the suspicion indicators you select from a set list. Then there is the Subject section, which is the person or entity the report concerns, followed by the transaction section, which is a line-by-line breakdown of everything relevant. The Account section covers account numbers, when they were opened, and account type. The Narrative is your factual account of what raised the suspicion, and finally there are attachments, where you include whatever documentation backs it all up.
Out of all of these, the indicators and the narrative are what FIU analysts lean on most when they are triaging what comes in, so it's worth giving both real attention.
Step 6: Check It Over, Then Submit
Before you send it off, double-check the names, dates, and amounts, since mistakes here can delay analysis or force a resubmission. Read the narrative as if you were the analyst on the other end and ask yourself whether it stands on its own or would prompt a follow up call just to understand it. And make sure the customer hasn't been tipped off in any way, because tipping off is a criminal offence under UAE law.
Once you submit, goAML gives you a reference number. Hold onto that, since it's your proof of filing and might come up again if the FIU follows up later.
Step 7: What Comes After Filing
Once it's submitted, keep your supporting documents and internal escalation trail on file, generally for at least five years. Don't disclose the filing to the customer, directly or otherwise. You should also keep monitoring the relationship going forward, since filing a report doesn't mean you have to end it, but it does mean applying more scrutiny than before. And if the FIU comes back with any follow up questions, respond promptly.
Mistakes Worth Avoiding
A few things trip people up again and again. Sitting on a report too long is one of them. You should file once suspicion is reasonably formed rather than letting internal debate drag things out. Vague narratives are another, since they just slow analysts down and make the whole report less useful. Tipping off the customer, even indirectly is a serious one. Since it's a criminal offense, not a technicality. Sloppy or inconsistent data entry across sections causes confusion for no good reason. And treating the STR like an accusation is a mindset issue worth correcting, because it's not a verdict, it's a documented suspicion and the narrative should read that way.
A Quick Pre-Submission Check
Before you hit submit, just run through it one more time. Is your entity registered with active credentials? Have you verified the customer and transaction details? Does the narrative actually explain itself or is it missing something? Are the right indicators selected and are your documents attached? And of course, make sure you haven't tipped off the customer and that you've saved the reference number once it's gone through.
Why This Actually Matters
Staying on top of FIU compliance in Dubai or really anywhere in the UAE isn't just a box-ticking exercise. A well-built STR helps analysts move faster, gives your organisation a stronger audit trail and signals a compliance culture that's actually functioning rather than just documented on paper. That's increasingly what regulators like the Central Bank, the DFSA, and the FSRA are looking for when they review a firm.
If you're putting together your AML framework or just trying to tighten up the one you've already got, it's worth spending real time training your staff on what actually makes a strong STR. Sharp indicators, a narrative that's specific rather than vague, clean data across the board. That effort pays off long after any one filing is done. It's honestly what builds trust with regulators, partners, and customers over time.
One last thing, this guide is meant as general compliance information, not legal advice. If you need something specific to your license type, talk to your compliance officer or a lawyer and lean on the official FIU and Central Bank of the UAE guidance for anything official.
Frequently Asked Questions (FAQs)
1. What is an STR in the UAE?
A Suspicious Transaction Report (STR) is a report submitted to the UAE Financial Intelligence Unit (FIU) when a reporting entity has reasonable grounds to suspect that a transaction or attempted transaction may be connected to money laundering, terrorist financing, or other criminal activity. An STR can be filed even when the transaction has not been completed and does not require proof that a crime occurred.
2. Who is required to file an STR in the UAE?
Financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs) operating in the UAE are required to report suspicious transactions or attempted transactions to the FIU when reasonable grounds for suspicion exist. DNFBPs can include real estate businesses, dealers in precious metals and stones, auditors, and corporate service providers, depending on their activities and regulatory classification.
3. How do you file an STR through goAML in the UAE?
To file an STR through goAML, a reporting entity generally needs to register and maintain an active goAML account, review the suspicious activity internally, collect relevant customer and transaction information, select the appropriate report type and suspicion indicators, provide a clear narrative, attach supporting documents where appropriate, review the submission, and submit it through the goAML platform.
4. What information should be included in a UAE STR?
A strong STR should contain accurate reporting entity information, details of the subject or customer, relevant transaction and account information, the applicable suspicion indicators, and a clear factual narrative explaining why the activity is considered suspicious. Supporting documents such as KYC records, account statements, transaction records, and relevant correspondence may also be included where appropriate.
5. Does an STR require proof of money laundering in the UAE?
No. An STR is based on reasonable grounds for suspicion and does not require the reporting entity to prove that money laundering, terrorist financing, or another offence has occurred. The reporting entity should provide factual information and clearly explain the circumstances that led to the suspicion rather than making an unsupported accusation.
6. Is it legal to tell a customer that an STR has been filed?
Reporting entities should not disclose to a customer or other unauthorised person that an STR has been filed or that a suspicious transaction is being reported where such disclosure would amount to tipping off. Tipping off can have serious legal consequences under UAE AML legislation, so communication about an STR should be handled carefully and only by authorised personnel.
7. What should a business do after submitting an STR through goAML?
After submitting an STR, the business should retain the relevant records and supporting documentation, maintain an appropriate audit trail, continue monitoring the customer or business relationship based on its risk assessment, and respond promptly to any follow-up requests from the FIU or relevant regulator. The business should also keep the goAML submission reference number for its records. (akj)*