Filing an STR through goAML in the UAE
A working reference for MLROs and analysts at firms licensed by the Central Bank of the UAE: who files, which report type to choose, how long you have, what the narrative must answer and what you may not tell the customer. Each point links to the CBUAE Rulebook text it comes from.
Reviewed · Educational material, not legal advice.
Who must file
The CBUAE's Guidance for Licensed Financial Institutions on Suspicious Transaction Reporting applies to the financial institutions the CBUAE licenses and supervises (LFIs). Section 3.4 requires them to submit suspicious transaction and activity reports directly to the UAE Financial Intelligence Unit through goAML, and makes goAML registration mandatory for every entity under CBUAE supervision. A newly licensed firm should register immediately after receiving its licence; the Compliance Officer or MLRO can be the registered user.
The duty to report comes from Federal Decree-Law No. (20) of 2018 and its implementing regulation, Cabinet Decision No. (10) of 2019. Firms supervised by the DFSA, the FSRA, VARA or the Capital Market Authority (formerly the SCA) also report to the FIU through goAML, under their own regulator's rules. This guide follows the CBUAE text; check your regulator's rulebook for differences.
The guidance states that failing to register on goAML may be treated as a breach of the firm's AML/CFT obligations.
Report types
goAML offers several report types. The CBUAE guidance refers to these:
| Type | Use |
|---|---|
| STR | Suspicious Transaction Report: transactions suspected to be related to money laundering, a predicate offence, or the financing of terrorism or illegal organisations. |
| SAR | Suspicious Activity Report: suspicious activity, or an attempted transaction that was not executed. |
| AIF / AIFT | Additional Information File, without or with transactions: further information on a case already reported. |
| RFI / RFIT | Request for Information, without or with transactions: the report type used to answer an FIU request. |
| HRC / HRCA | High Risk Country transaction or activity report. |
On the report cover, the description of the report is mandatory for STR and SAR types and the action taken by the reporting entity is mandatory for all. The FIU reference field applies only to AIF, AIFT, RFI and RFIT reports, where you quote the case number from the FIU's Message Board.
Choose the Reason for Reporting (RFR) that matches the actual suspicion. The FIU has noted reports filed under terrorist-financing reasons with no evidence of terrorist financing; a wrong RFR leads to requests for clarification.
How long you have
The CBUAE expects suspicious activity to be reported without delay and asks firms to file ahead of the maximum timelines in section 4.6. The maximums are:
| Situation | Maximum timeline |
|---|---|
| Standard alert | STR or SAR filed within 35 business days from the date the automated alert was generated. This covers dispositioning the alert, the recommendation and the decision to file. |
| Complex investigation | Initial STR within 15 business days of the alert, labelled "Complex investigation"; follow-up STR or SAR within 30 business days of filing the initial report. |
| Continuing activity | After filing, enhanced monitoring of the account holder; if the activity continues, file again expeditiously. |
The guidance sets a separate, faster path for activity that needs immediate attention, such as ongoing violations or suspected terrorist financing, and for alerts escalated for expedited review (sections 4.4 and 4.7). If your procedure has an escalation route, read those sections alongside the table.
The 35 days count from alert generation, not from the day an analyst opened the alert. The STR deadline calculator counts them for a given date, with UAE public holidays.
The 35 business days are a ceiling. An alert left untouched until day 30 will be hard to defend at inspection even if the report goes in on time.
What the narrative must answer
Section 3.3 asks every narrative to answer who, what, when, where and why, and to describe how the activity was carried out. In practice:
- Who: the subjects, including the conductor, beneficiary and account holders; identifiers such as passport numbers and addresses; for entities, beneficial owners, directors and signatories; each party's role; and how the parties are related, if known.
- What: the instruments used (wire transfers, cards, foreign currency and so on), how the funds were moved, the source or use of the funds, and every affected account number, including accounts at other institutions where known.
- When: the date the activity was first observed and how long it lasted, with transactions listed one by one in date order rather than as a total, and whether each was completed or only attempted.
- Where: the offices involved and any foreign jurisdiction, institution and account in the chain, as far as the ultimate originator and beneficiary where this can be established.
- Why: why the activity is unusual for this customer, given the products, the accounts, the expected activity and the stated purpose; and, if an automated alert started the review, the scenario or rule that fired.
- How: the method. The guidance's own example: where cheque deposits are matched by outgoing wires, describe both legs with dates, destinations, amounts, accounts, frequency and beneficiaries.
Annex 1 gives nine examples of narratives that fall short. The same gaps recur: no identifying details for the subject, no explanation of why the activity is suspicious, totals without dates and amounts, and nothing on where the money went.
For a broker, that means
A wash-trading STR should name both accounts and what links them (a shared passport, device or funding account), list the matched deals with tickets and times, state the profit and loss moved between the accounts and any rebate the introducing broker earned on the volume, and say what the firm has done, for example holding a pending withdrawal.
STR narrative template (PDF)
The template follows the structure above: who, what, when, where, why and how, then evidence references, red flags observed, actions taken and the review. The last page is a filled example on synthetic data: a wash-trading case between two MT5 accounts. Free to download, no form.
Attachments and the rest of the form
Supporting documents are mandatory: KYC documentation, copies of identification, account-opening forms, transaction receipts, financial statements and other documents relevant to the investigation, together with the records of any due diligence or internal investigation the firm carried out.
Suspected amounts are entered in AED. Each party is entered as a person, an account or an entity, with the fields goAML requires for each; for accounts classed as "My Client", every signatory is captured. goAML also has an XML schema for filing batches of reports.
Keep the MLRO's contact details current in goAML. The FIU has reported receiving reports where they were out of date, which slows its follow-up.
Tipping-off and confidentiality
Under Article 18 of the AML-CFT Decision, the firm must keep both the information reported and the fact of reporting confidential. Section 5 of the guidance adds that informing a customer or any other person, directly or indirectly, that a report has been or will be filed, what it contains, or that an investigation is under way is a federal crime, punishable by a fine of AED 100,000 to AED 500,000 and imprisonment.
Confidentiality does not prevent sharing within the firm or its group for the purpose of identifying, preventing or reporting suspicious transactions (Article 39.1 of the AML-CFT Decision).
In practice: hold and decline messages to the client should be neutral and agreed with compliance in advance, and front-office staff should see that an account is restricted, not why.
After filing
Section 6 of the guidance (full text, PDF) asks the firm to follow any FIU instructions on the transaction and the relationship, review the reported customer's related accounts, and treat the customer as high risk with enhanced due diligence and monitoring. Unless the FIU instructs otherwise, the firm is not obliged to carry out a transaction it suspects. If it keeps the relationship, the decision and the controls around it are documented and approved by senior management.
Record keeping
The guidance asks firms to keep all information relating to transaction monitoring and suspicious activity reporting for at least five years, as Article 24 of the AML-CFT Decision provides. That includes alerts closed without a report.
A decision not to file needs the same care as a filing: which facts were checked, why they explained the activity, and who decided.
Where Marqib fits
Marqib prepares the case file this guide describes. Deterministic rules raise the alert; the case shows the evidence rows, a draft narrative in which every sentence cites one of them, the CBUAE clock from the alert date, and a goAML XML draft for the reviewer to check. An analyst proposes, a different person approves with a reason code, and both are written to a hash-chained audit log.
Sources
- CBUAE Rulebook, STR guidance 3.3: Best practices for drafting an STR or SAR
- CBUAE Rulebook, STR guidance 3.4: How to submit an STR and other report types
- CBUAE Rulebook, STR guidance 4.6: Summary of review, investigation and reporting timelines
- CBUAE Rulebook, STR guidance Annex 1: Examples of insufficient STR and SAR narratives
- CBUAE Rulebook, STR guidance 5: Confidentiality and prohibition against tipping off
- CBUAE, Guidance for LFIs on Suspicious Transaction Reporting (full text, PDF)
Questions
Is 35 business days the deadline to file an STR in the UAE?
It is the maximum under the CBUAE guidance, counted from the date the automated alert was generated. The CBUAE expects suspicious activity to be reported without delay and asks firms to file ahead of that limit.
When is an investigation "complex"?
The firm designates it. It then files an initial STR within 15 business days of the alert, labelled "Complex investigation", and a follow-up within 30 business days of the initial filing.
What is the difference between an STR and a SAR in goAML?
An STR reports transactions. A SAR reports activity, or an attempted transaction that was not executed.
Can we tell a client why a withdrawal is on hold?
Not that a report has been or will be filed, or that an investigation is under way. That is tipping-off, a federal crime in the UAE. Use neutral wording agreed with compliance.
Does this guidance apply to DFSA- or FSRA-regulated firms?
The CBUAE guidance applies to firms the CBUAE licenses and supervises. Firms in the DIFC and ADGM report to the same FIU through goAML but follow their own regulator's rules, which may differ in detail.