Skip to main content
TCJ

AML Compliance

STR vs SAR in the UAE: When and How Suspicion Should Be Reported

Understand the practical difference between STR and SAR reporting in the UAE, when reasonable suspicion may arise, who must report, and how the goAML submission process typically works.

By Mandeep Masoun·Published ·10 min read
STR vs SAR in the UAE: When and How Suspicion Should Be Reported
STR vs SAR in the UAE: When and How Suspicion Should Be Reported

STR vs SAR in the UAE: When and How Suspicion Should Be Reported

Key takeaways

  • STRs generally focus on suspicious transactions, attempted transactions, funds or assets.
  • SARs generally focus on suspicious behaviour or circumstances that may exist without a completed transaction.
  • Reasonable suspicion does not require proof that a criminal offence occurred.
  • Suspicion should be escalated promptly to the MLRO or authorised compliance officer.
  • goAML registration, clear narratives and organised supporting documents improve reporting readiness.

What is the current UAE AML reporting framework?

The UAE’s current federal AML framework is principally based on Federal Decree-Law No. 10 of 2025 and its executive regulations under Cabinet Resolution No. 134 of 2025. The decree-law became effective on 14 October 2025 and repealed the earlier Federal Decree-Law No. 20 of 2018. The executive regulations became effective on 14 December 2025.

The framework requires regulated entities to identify, assess and report suspicions connected with money laundering, terrorist financing, proliferation financing and related criminal activity.

Reports and associated information are submitted to the UAE Financial Intelligence Unit. The reporting obligation applies to relevant financial institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers.

Businesses should also consider the rules, circulars and guidance issued by their own supervisory authority. A bank regulated by the Central Bank of the UAE may have different reporting procedures from a mainland real estate brokerage, accounting firm or dealer in precious metals supervised by another authority.

What is a Suspicious Transaction Report?

An STR is generally used where the concern centres on a completed, attempted or proposed transaction, funds or assets. The business does not need to prove that a crime occurred. The reporting question is whether the available information creates reasonable grounds to suspect that the transaction or funds may be linked to criminal activity.

Possible indicators include:

  • Large cash deposits that do not match the customer’s known business activity.
  • Funds moving rapidly through several accounts without an evident commercial purpose.
  • Payments to or from parties that appear unrelated to the underlying invoice or contract.
  • Transfers involving jurisdictions that create elevated sanctions or financial crime concerns.
  • Transactions divided into smaller amounts without a reasonable operational explanation.
  • Payments that materially conflict with the customer’s stated source of funds.
  • Asset transfers involving unclear beneficial ownership.
  • Transactions connected with forged, altered or inconsistent supporting documents.

The size of a transaction should not be treated as the only deciding factor. A smaller transaction can still be suspicious when it conflicts with the customer profile, appears deliberately structured or forms part of a wider pattern.

An unusual transaction is not automatically suspicious. A UAE trading company may receive a large payment because it has completed a legitimate contract. The business should review the customer profile, commercial documents, source of funds, payment route and explanation before reaching a reporting decision.

What is a Suspicious Activity Report?

An SAR is generally associated with suspicious conduct, circumstances or patterns that may exist without a completed movement of money or assets. The concern may arise during onboarding, customer due diligence, account opening, document verification or an attempt to establish a business relationship.

Examples may include:

  • Refusal to identify the ultimate beneficial owner.
  • Repeated submission of inconsistent incorporation documents.
  • Use of unexplained nominees or unusually complex ownership structures.
  • Attempts to bypass customer due diligence procedures.
  • Abandoning an application after source-of-funds questions are raised.
  • Providing conflicting information about the purpose of a company.
  • Repeated efforts to pressure employees into ignoring compliance requirements.
  • Suspected use of forged identification or authority documents.

A prospective customer does not need to complete an account opening or transaction before a reporting concern can arise. Suspicious conduct observed during onboarding may be relevant even where the proposed relationship is rejected.

How should a business choose between an STR and an SAR?

The practical starting point is to identify what created the suspicion. Where the concern is primarily connected with a particular transaction, attempted transaction or movement of funds, an STR may be appropriate. Where it concerns behaviour or circumstances without a specific transaction, an SAR may be more suitable.

Compliance teams should consider:

  1. Whether a transaction was completed, attempted or proposed.
  2. Whether particular funds or assets are central to the concern.
  3. Whether the issue arose mainly from customer behaviour or documentation.
  4. Whether several events form a suspicious pattern.
  5. Which report type is supported by current UAE FIU and supervisory guidance.
  6. Whether another specialised goAML report type applies.

An attempted transfer should not automatically be classified as an SAR simply because no funds moved. UAE supervisory guidance recognises that a suspicious transaction can include an attempted transaction, regardless of its amount or timing.

The quality of a suspicious report depends less on the label chosen and more on whether the facts, red flags, timeline and reasons for suspicion are clearly documented. — KPM Global Services UAE consultant observation

Where the classification remains uncertain, the Money Laundering Reporting Officer should refer to current goAML guidance and the relevant supervisory authority’s instructions rather than relying only on internal terminology.

When should suspicion be reported?

Reporting should generally take place promptly once reasonable grounds for suspicion have been established. A business should perform an appropriate internal assessment, but it should not delay submission while trying to prove the suspected offence or conduct an investigation that belongs to the competent authorities.

Suspicion may arise through:

  • Customer due diligence and enhanced due diligence.
  • Transaction monitoring alerts.
  • Sanctions and name screening.
  • Adverse information reviews.
  • Employee observations.
  • Internal whistleblowing.
  • Document verification.
  • Changes in ownership, control or transaction behaviour.
  • Requests that conflict with the customer’s normal commercial activity.

Licensed financial institutions are expected to report suspicious transactions and activities directly to the UAE FIU through goAML. Official guidance also refers to reporting without delay or as soon as reasonably possible after suspicion develops.

Employees should escalate concerns through the organisation’s approved internal reporting process. The MLRO or authorised compliance officer should assess the information, record the decision and submit the appropriate report where required.

Who may have STR and SAR reporting obligations?

Reporting obligations extend beyond banks. Depending on the activity, licence, regulator and transaction, they may apply to financial institutions, DNFBPs and VASPs.

Relevant sectors typically include:

  • Banks, finance companies and exchange houses.
  • Insurance providers and intermediaries.
  • Investment firms, brokers and other regulated financial businesses.
  • Real estate brokers and agents.
  • Dealers in precious metals and precious stones.
  • Auditors, accountants and certain corporate service providers.
  • Trust and company service providers.
  • Legal professionals when undertaking activities covered by UAE AML requirements.
  • Virtual Asset Service Providers.
  • Other businesses designated by applicable legislation or supervisory rules.

The Ministry of Economy and Tourism identifies a range of non-financial sectors as DNFBPs and provides goAML registration and AML compliance information for businesses under its supervision.

A mainland or free zone licence does not, by itself, determine whether the business is outside AML reporting requirements. The actual activity performed, the relevant supervisory authority and the nature of transactions should be assessed.

How are STRs and SARs submitted through goAML?

The goAML portal is the UAE’s electronic platform for filing STRs, SARs and other prescribed report types with the UAE FIU. Reporting entities should register the organisation and authorised users before an urgent reporting need arises.

A practical internal process typically includes:

  1. Detect the concern: An employee or monitoring system identifies unusual activity, behaviour or documentation.
  2. Escalate internally: The matter is referred promptly to the MLRO or authorised compliance function.
  3. Assess the information: Compliance reviews the customer profile, transaction history, documents, explanations and relevant red flags.
  4. Select the report type: The MLRO chooses the appropriate goAML report based on the facts and current guidance.
  5. Prepare the narrative: The report explains who was involved, what happened, when it occurred, why it is suspicious and which documents support the concern.
  6. Submit and retain records: The report is filed through goAML, with internal records retained in line with applicable legal and regulatory requirements.

The report narrative should be factual and chronological. Unsupported conclusions, vague allegations and copied alert descriptions can make the report difficult to assess.

Information relating to a filing should remain confidential. Employees must not tell the customer that a report has been submitted or that a reporting decision is under consideration. Internal access should be limited to authorised personnel.

What do STR and SAR situations look like in practice?

Example 1: Suspicious transaction involving a UAE trading company

A Dubai trading company normally receives payments from a small group of established commercial customers. It suddenly receives several large cash deposits through different locations, followed by an instruction to transfer most of the funds to an unrelated overseas entity.

The customer provides invoices, but the goods, counterparties and payment descriptions do not align. The transaction pattern, cash activity and unexplained third-party transfer may provide grounds for considering an STR.

The compliance team should document the customer’s expected activity, the actual transaction pattern, explanations obtained, documents reviewed and reasons those explanations did not resolve the concern.

Example 2: Suspicious activity during company onboarding

A corporate service provider is asked to establish a UAE company with several layers of overseas shareholders. The applicant repeatedly changes the proposed owner, refuses to identify the ultimate beneficial owner and provides inconsistent passport and address documents.

No company is incorporated and no payment is completed because the applicant withdraws after additional questions are raised. The behaviour and documentation may nevertheless justify consideration of an SAR.

The business should preserve the application, communications, submitted documents, screening results and internal assessment.

What common reporting mistakes should businesses avoid?

Common weaknesses include:

  • Waiting for proof of criminal activity before escalating a concern.
  • Assuming that rejected customers or failed transactions cannot be reported.
  • Automatically treating every unusual transaction as suspicious.
  • Selecting a report type without considering the underlying facts.
  • Writing a vague report narrative with no clear chronology.
  • Failing to explain why the activity conflicts with the customer profile.
  • Omitting relevant counterparties, accounts or supporting documents.
  • Allowing commercial pressure to influence the reporting decision.
  • Delaying escalation to the MLRO.
  • Keeping no record of a decision not to report.
  • Sharing confidential reporting information with unauthorised employees.
  • Informing or indirectly alerting the customer.

A decision not to file may also require a clear internal record. The file should show which facts were reviewed, how the red flags were resolved and who approved the decision.

What documents should be prepared for an internal assessment?

The exact documents depend on the customer and activity, but a useful preparation checklist includes:

  • Customer identification and verification records.
  • Trade licence and incorporation documents.
  • Ultimate beneficial ownership information.
  • Customer risk assessment.
  • Source-of-funds and source-of-wealth evidence where relevant.
  • Transaction history and account statements.
  • Contracts, invoices, purchase orders and shipping records.
  • Payment instructions and counterparty details.
  • Sanctions, PEP and adverse information screening results.
  • Email correspondence and customer explanations.
  • Monitoring alerts and investigation notes.
  • A chronological summary of relevant events.
  • Internal escalation records.
  • The MLRO’s assessment and reporting decision.
  • Copies or references for documents submitted through goAML.

Documents should be organised before the narrative is finalised. A clear timeline often reveals connections that are difficult to identify when records are reviewed separately.

How can KPM Global Services UAE assist?

KPM Global Services UAE can support businesses in Dubai and across the UAE with practical AML compliance procedures, reporting workflows and documentation controls. The objective is to help management and compliance teams understand their obligations and build a process that can be followed consistently.

Support may include:

  • Reviewing AML policies and internal escalation procedures.
  • Assessing whether business activities fall within relevant DNFBP requirements.
  • Developing STR and SAR internal reporting templates.
  • Reviewing customer due diligence and beneficial ownership files.
  • Supporting goAML registration readiness.
  • Training employees to identify and escalate red flags.
  • Reviewing the quality of internal investigation records.
  • Conducting AML risk assessments and compliance health checks.
  • Strengthening recordkeeping and management oversight.

KPM Global Services UAE does not guarantee acceptance of a report, closure of a regulatory review or any particular authority outcome. Reporting decisions should be made by the authorised MLRO or responsible compliance officer based on the facts and applicable requirements.

What should businesses take away from STR and SAR reporting?

The difference between an STR and an SAR is practical rather than purely linguistic. STRs generally concern suspicious transactions, attempted transactions, funds or assets. SARs generally address suspicious behaviour or circumstances where a specific transaction may not be central.

The reporting entity should focus on the underlying facts, document its reasoning and act promptly once reasonable grounds for suspicion exist. A clear internal process helps employees escalate concerns without conducting excessive investigations or exposing confidential reporting decisions.

Businesses should periodically review their goAML access, MLRO responsibilities, escalation procedures, reporting templates and staff training. These controls are most effective when established before a suspicious event occurs.

This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.

Questions and answers

Q: Is an STR the same as an SAR in the UAE?

A: No. An STR generally concerns a suspicious transaction, attempted transaction or funds, while an SAR generally concerns suspicious conduct or circumstances. The appropriate report should be selected according to the facts and current UAE FIU or supervisory guidance.

Q: Can an attempted transaction require an STR?

A: Yes. A transaction does not necessarily need to be completed before it becomes reportable. An attempted transaction may support an STR where the attempted movement of funds or assets is central to the suspicion.

Q: Does a business need proof before filing a suspicious report?

A: No. Reporting is generally based on reasonable grounds for suspicion rather than conclusive proof of criminal activity. The business should still conduct an appropriate internal review and document the reasons supporting its decision.

Q: Who normally submits an STR or SAR through goAML?

A: The report is typically submitted by the organisation’s MLRO, compliance officer or another specifically authorised person. Other employees should follow the internal escalation procedure rather than filing independently unless the organisation’s approved process states otherwise.

Q: Can a customer be told that an STR or SAR was filed?

A: No. Reporting information should be treated as confidential, and employees should not inform or indirectly alert the customer. Access to the report and related internal records should be restricted to authorised personnel.