What Legally Counts as a Suspicious Transaction
Under AMLA (RA 9160, Section 3), a transaction is suspicious, regardless of amount, if it lacks a clear legal or trade purpose, the client isn't properly identified, the amount doesn't match the client's known capacity, it appears structured to avoid reporting thresholds, it deviates from the client's established profile, or it relates to an unlawful activity. A Suspicious Transaction Report (STR) covering such a transaction must be filed electronically through AMLC's FTRF portal by the next working day following the date the covered person determines, with finality, that the transaction is suspicious, under AMLC's GoTRACS framework.
STRs are commonly rejected or flagged as deficient for two distinct reasons: technical non-compliance (wrong file format, an outdated 11-digit institution code where an 18-digit code is now required, missing mandatory fields) and substantive quality deficiencies (no identified subject of suspicion, a reason for suspicion that doesn't match the narrative, or a narrative too vague to support investigation), a distinction AMLC's own STR quality research has documented in detail.
Most guidance on STR filing in the Philippines stops at the deadline: file within the next working day of determining suspicion, or face non-compliance. That's necessary but incomplete. AMLC's own research into STR quality, a study more candid about the state of the data than most public compliance content ever is, found that in the sample year it studied, nearly half of all STRs filed contained insufficient detail to be actionable. A technically on-time STR that AMLC can't actually use isn't a compliance success; it's a filing that satisfies the deadline and fails the purpose the deadline exists for.
If your team files what's called a SAR, a Suspicious Activity Report, elsewhere, the Philippine equivalent is the STR, and the mechanics differ in ways that matter: different filing windows, a different statutory basis, and a different quality framework AMLC applies when it reviews what you send. This guide covers both halves: getting the mechanics right, and writing a narrative that actually holds up.
Section 3 of AMLA (RA 9160, as amended) defines a suspicious transaction as one where, regardless of the amount involved, any of the following exists: there is no underlying legal or trade obligation, purpose, or economic justification; the client is not properly identified; the amount involved is not commensurate with the business or financial capacity of the client; the transaction appears structured to avoid reporting requirements; any circumstance relating to the transaction deviates from the client's profile or past transaction pattern; or the transaction is in any way related to an unlawful activity, or a money laundering offense that is about to be, is being, or has been committed.
A seventh, catch-all category, "any transaction that is similar, analogous, or identical to any of the foregoing," exists in the statute, but AMLC's own quality research flags this specific category as one of the most frequently misused fields on the form.
STR vs. CTR: Threshold and Filing Deadline
| Element | STR | CTR |
|---|---|---|
| Trigger | Determination of suspicion, any amount | Cash transaction ≥ ₱500,000 |
| Filing window | Next working day from determination | 5 working days from occurrence |
| Legal basis | AMLC RI No. 2, Series of 2024 (GoTRACS) | AMLA RA 9160, as amended |
The distinction between "occurrence" and "determination" matters more than it looks. GoTRACS defines the date of occurrence, for STR purposes, as the date when a covered person decides with finality that a transaction or series of transactions are suspicious based on its evaluation, analysis and investigation, not the date the transaction happened, and not the date an alert first fired. Submissions filed after 11:59:59 PM of the next working day following that determination date are treated as non-compliant, and may be subject to administrative sanctions.
How an STR Is Actually Filed: Format Basics
STRs are filed electronically through AMLC's Financial Transaction Reporting Facility (FTRF), using a structured CSV file format, comma-separated fields, built either by extracting data directly from the covered person's own systems or by populating a template and exporting it as CSV. Header records identify the covered person (including branch, for institutions with multiple branches); detail records carry the individual transaction data.
Two format details are worth knowing specifically because they're recent and because getting them wrong causes an outright technical rejection, not just a quality flag: as of January 2, 2026, all covered persons must use their 18-digit institution codes in GoTRACS submissions, the AMLC Portal will reject any upload using the older 11-digit code format, or an encrypted format, outright. AMLC is also running a phased transition from the existing Electronic Record Format 1.0 to a new "Format X," running from January 2, 2026 through January 2, 2028; parallel submission of both formats is allowed during the transition, and full implementation of Format X becomes mandatory from January 3, 2028.
Beyond format mechanics, GoTRACS also requires mandatory uploading of Beneficial Owner information for STRs involving account holders that are juridical persons (companies, trusts, and similar entities), a requirement introduced specifically to address a gap in earlier reporting cycles.
Why STRs Actually Get Rejected or Flagged
It's worth separating two different failure modes, because they require different fixes. A technical rejection means the file itself is invalid, wrong institution code, malformed CSV, a mandatory field left blank, and the submission simply doesn't go through. A quality deficiency is different: the file is technically valid and gets accepted, but AMLC's own analysis of the content finds it unusable for investigative purposes. Both matter, but only one shows up immediately as an error message. The second is the one that actually damages an institution's credibility over time, because it accumulates silently until an examiner pulls the pattern.
AMLC's own STR quality research quantified the second category directly. In its review of a full year of STR submissions, only 53.09% of filed STRs were deemed actionable, 46.91% had insufficient detail to warrant further investigation.
| Deficiency | Share studied | What it looks like |
|---|---|---|
| No subject of suspicion identified | ~31% | The name/entity suspected of the unlawful activity was missing entirely. |
| Missing accountholder details | ~7% | Basic identifying information for the account holder wasn't provided. |
| Reason for suspicion inconsistent with narrative | ~35% | The predicate crime selected didn't match what the narrative actually described. |
| Low quality or insufficient narrative | ~32% | The narrative was vague, too short, or based only on subjective client behavior with no transactional substance. |
| ZSTR code misuse | ~11% | Used to report account details of a suspect with no actual suspicious transaction described. |
Some of these overlap, a single deficient STR can be missing a subject of suspicion and have an inconsistent reason for suspicion at the same time, which is part of why the overall actionable rate landed just above 53% rather than being close to 100% minus any single deficiency's share.
The 5Ws and 1H: AMLC's Own Framework for a Usable Narrative
In response to its own findings, AMLC's guidance to covered persons is to structure every STR narrative around six questions, the same 5Ws and 1H framework used in investigative writing generally, applied specifically to what an STR needs to establish.
- WHO — Subject profile: Name, address, date of birth of the subject of suspicion, and of the account holder, if different.
- WHAT — Transaction detail: The correct transaction code, amount, and currency, filled in accurately, not defaulted or approximated.
- WHERE — Place of transaction: The branch of the covered person where the transaction occurred, reported at branch level even when the head office files the report.
- WHEN — Transaction date: The actual date(s) of the transaction(s) under review.
- WHY — Suspicious indicator: The specific suspicious circumstance or predicate crime from AMLA's list, chosen to genuinely match what the narrative describes, not chosen by default.
- HOW — The narrative itself: The pattern of transactions, nature of business, source of income, affiliations, internal alerts, and open-source information that together explain why the activity looks like money laundering or terrorism financing.
What a High-Quality STR Actually Contains
AMLC's own characterization of a high-quality STR comes down to four things: a complete subject/accountholder profile; a substantial narrative that covers the subject's profile, their transaction pattern, nature of business, source of income, known affiliations, internal database alerts, and any open-source information available; disclosure of all mandatory transaction parties (beneficiaries, counterparties) required for that transaction type; and a stated reason for suspicion that's actually consistent with what the narrative describes.
The examples AMLC cites as high-quality in its own research follow a consistent pattern worth internalizing: they establish the subject's stated occupation, income, and account history as a baseline; they show a specific transaction pattern that deviates from that baseline, quantified in amounts and counts, not described impressionistically; they cross-reference watchlist or internal-database screening results where relevant; and they explain, where available, what an account officer or branch manager's own inquiry revealed. None of that requires elaborate prose. It requires the narrative to do the analytical work of connecting a specific pattern to a specific concern, rather than asserting a conclusion and leaving the reader to take it on faith.
Mistakes That Reliably Produce Low-Value STRs
A few specific patterns account for a disproportionate share of the deficiencies AMLC has documented.
- Filing based on subjective client behavior alone: "Client seemed nervous," "wouldn't make eye contact," "wanted the transaction done immediately", with no transactional pattern to support it. AMLC's own guidance treats these as insufficient on their own, though they can support a filing when combined with an actual transactional red flag.
- Choosing the closest-sounding predicate crime rather than the one the narrative actually supports: The recurring example is filing under "Forgeries and Counterfeiting" for what the narrative describes as card fraud or a disputed transaction, which is legally closer to swindling.
- Overusing the catch-all "similar, analogous, or identical" category: Instead of selecting the specific, correct suspicious indicator, or worse, using it to describe two different suspicious indicators at once instead of choosing the more accurate one.
- Filing low-substance STRs for routine disputes: Disputed card transactions, counterfeit card use, card skimming, and checks returned for insufficient funds or closed accounts, where the perpetrator is unknown and no further investigative detail is available. These accounted for over 40% of all STRs in AMLC's sample year.
- Misusing the ZSTR transaction code: To report a suspect's account details without an actual suspicious transaction attached to it. AMLC's guidance is explicit that this code should only be used when no transaction was made by the subject.
Closing the Gap
Several of AMLC's most common deficiencies, missing subject details, an unsupported narrative, a reason for suspicion chosen without reference to the underlying case record, share a root cause: the analyst writing the STR is working from memory and a partial case view rather than a complete one. FT AML Solution's Regulatory Reporting module pre-populates STR forms directly from case data, which means the subject profile, transaction history, and screening results AMLC's own quality framework asks for are already in the form the analyst is reviewing, rather than something they have to reconstruct from separate systems under a next-working-day deadline.
Frequently Asked Questions
What legally counts as a suspicious transaction in the Philippines?
Under AMLA Section 3, a transaction is suspicious regardless of amount if it lacks legal or economic justification, the client isn't properly identified, the amount doesn't match the client's capacity, it appears structured to avoid reporting, it deviates from the client's profile, or it relates to unlawful activity.
What is the STR filing deadline?
The next working day following the date a covered person determines, with finality, that a transaction is suspicious, under AMLC's GoTRACS framework.
Why do STRs get technically rejected?
Common causes include using an outdated 11-digit institution code instead of the 18-digit code required since January 2026, an unsupported file format, or missing mandatory fields.
What makes an STR narrative low quality?
A missing subject of suspicion, a stated reason for suspicion inconsistent with the narrative, and a narrative too vague or brief to support further investigation.
What framework does AMLC recommend for writing an STR narrative?
A 5Ws and 1H structure: Who, What, Where, When, Why, and How.

