Every reporting entity in Nigeria (banks, microfinance banks, fintechs, and DNFBPs) must file Suspicious Transaction Reports with the Nigerian Financial Intelligence Unit (NFIU). The obligation sits in Section 7 of the Money Laundering (Prevention and Prohibition) Act 2022, and it comes with the shortest deadline in Nigerian compliance: 24 hours from the moment suspicion is formed.
There is no minimum amount. A ₦40,000 transfer that fits a laundering pattern is reportable; a ₦50 million transfer that is ordinary for the customer may not be. The trigger is suspicion, not size.
This guide walks through the full process: recognizing what counts as suspicious, registering on goAML, assembling the record, writing the narrative, and staying on the right side of the confidentiality rules after you file.
What counts as suspicious
Suspicion is a lower bar than proof. You are not concluding that the customer committed a crime. You are reporting that the activity does not fit what you know about the customer, or that it matches a pattern regulators have flagged. Common triggers:
- Structuring: cash deposits broken into amounts just below the ₦5 million / ₦10 million reporting thresholds, especially across branches or days.
- Profile mismatch: a student account or low-income customer suddenly moving amounts inconsistent with their declared occupation and history.
- Rapid pass-through: funds arriving and leaving within hours, with the account acting as a pipe rather than a store of value.
- Unexplained cash intensity: a business account whose cash deposits dwarf any plausible turnover for its industry.
- Sanctions proximity: names, phone numbers, or addresses that nearly match watchlist entries, or counterparties in high-risk jurisdictions.
- PEP-linked activity: unusual movement connected to a politically exposed person or their close associates.
- KYC evasion: a customer who stalls, provides inconsistent identity details, or resists update requests when asked routine questions.
If your transaction monitoring flags any of these, the clock has already started.
The clock starts at suspicion, not at proof
The most common failure mode in examinations is not a missing report. It is a late one. The 24-hour window begins when a staff member or a monitoring system forms the suspicion, not when a committee concludes it, and not when the investigation file is complete.
Practical discipline: every alert, referral, or observation that could amount to suspicion should be timestamped when received by the compliance unit. If internal review takes three days, the NFIU can still see a filing made 72 hours after the original alert. Document the timeline as carefully as the transaction.
Step 1: Register your institution on goAML
All statutory reports to the NFIU go through goAML, the FIU's reporting platform. Before you can file anything:
- Create the entity account on the goAML portal with your institution's registration details: CAC documents and your regulatory license (CBN, or the relevant regulator for your entity type).
- Register at least one user under the institution, normally the Chief Compliance Officer, as the designated goAML correspondent.
- Wait for NFIU validation. Accounts are reviewed before they become active, so do this well before you need to file your first report.
If your CCO changes, update the goAML registration promptly. Examiners treat an out-of-date correspondent as a governance finding in itself.
Step 2: Assemble the transaction record
goAML asks for structured data, and the quality of your filing depends on what you collect before you start typing. For the subject of the report, pull together:
- Full KYC snapshot: name, BVN/NIN, address, phone, occupation, and identification documents on file.
- Account numbers and the roles of every party (sender, receiver, beneficial owner where relevant).
- The complete transaction set: dates, amounts, channels (branch, mobile, POS, transfer), and counterparties, not just the single transaction that triggered the alert, but the pattern around it.
- Any prior STRs on the same subject, referenced by date.
Step 3: Write the narrative
The free-text narrative is where most weak filings fail. A reviewer at the FIU reads the structured fields for the facts and the narrative for the reasoning. A useful structure is three short paragraphs:
- Who and what: the customer's profile and the activity, in plain figures.
- Why it is suspicious: the specific mismatch or pattern. State observations, not accusations: "deposits of ₦480,000 daily for 11 days, below the reporting threshold, inconsistent with declared income as a trader" rather than "customer is laundering money."
- What you did: internal review steps taken, customer contact if any, and your basis for escalating.
Write it so that a reader with no access to your core banking system understands the concern in one pass.
Step 4: Submit and preserve the trail
Enter the report in goAML or upload the XML submission, then save the acknowledgement. Keep the complete file (alert, review notes, KYC snapshot, submission receipt) for at least five years, the retention floor under the MLPPA. Examiners routinely ask for the STR file for a specific customer by name; you should be able to produce it in minutes.
After you file: confidentiality is absolute
Disclosing to the customer, or to anyone outside the authorized chain, that an STR has been made is the offence of tipping off. It carries criminal liability for the individual, not just the institution. In practice:
- No branch staff, relationship manager, or call center agent informs the customer.
- Internal access to STR records is restricted to the compliance unit.
- System alerts that generate STRs are never surfaced in customer-facing channels.
STR, CTR, FTR: which report, when
| Report | Trigger | Deadline | Threshold |
|---|---|---|---|
| STR | Suspicion of money laundering or terrorism financing, from a transaction, attempted transaction, or account activity | Within 24 hours of suspicion | None. Any amount. |
| CTR | Cash transaction in a single day | Within 7 days of the transaction | Above ₦5m (individual) / ₦10m (corporate) |
| FTR & others | Funds transfers and other statutory reports as defined in CBN reporting guidelines | Per the applicable guideline | Per the applicable guideline |
If a cash transaction is both above the CTR threshold and suspicious, file both. One does not substitute for the other.
The mistakes examiners flag most
- Filing late. Anything past 24 hours from the first documented suspicion needs an explanation.
- Vague narratives. "Transaction deemed suspicious" is not a narrative; it is a placeholder that failed to be replaced.
- Tipping off, usually accidentally, through relationship managers who were told more than they needed to know.
- Filing a CTR where an STR was required, because the amount crossed a threshold but nobody asked why.
- Waiting for certainty. Suspicion is the standard. A wrong STR filed in good faith is compliance; a right one filed late is a finding.
Where Finhaq fits
Most of this process is data assembly under deadline pressure, which is what automation is for. Finhaq screens transactions in real time, flags the patterns on the list above, keeps an immutable audit trail of every alert and decision, and produces reports in goAML-ready formats. At Buildbank MFB, it blocked over ₦97 million in suspicious value with zero false negatives.
If you want to know where your reporting process would break under an examination, the free AML readiness assessment scores it in three minutes.
This article is general guidance for compliance professionals, not legal advice. Reporting obligations are set by the Money Laundering (Prevention and Prohibition) Act 2022, CBN AML/CFT regulations, and NFIU directives. Always check the current instruments and your regulator's circulars.
See Finhaq screen your own transactions
A 30-minute demo on your scenarios: real-time screening, explainable verdicts, and goAML-ready reporting.