How to Identify, Investigate and File a Suspicious Transaction Report (STR) in Nigeria

A practical guide to identifying, investigating and filing STRs in Nigeria, including NFIU timelines, narratives, supporting evidence and goAML submission.

How to Identify, Investigate and File a Suspicious Transaction Report (STR) in Nigeria

Suspicious Transaction Reports are one of the most important tools in Nigeria’s anti-money laundering, counter-terrorist financing and counter-proliferation financing framework.

Financial institutions and other reporting entities are expected to identify transactions that may involve money laundering, terrorist financing, proliferation financing or the proceeds of other criminal activity, investigate the circumstances and report qualifying suspicious transactions to the Nigerian Financial Intelligence Unit (NFIU).

The principal legal obligations arise under the Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA) and the Terrorism (Prevention and Prohibition) Act 2022 (TPPA).

In December 2024, the NFIU also issued updated Guidelines for the Identification, Verification and Reporting of Suspicious Transactions related to ML/TF/PF for Financial Institutions, providing more detailed expectations around alert investigation, the formation of suspicion, STR narratives, supporting evidence and reporting timelines.

This guide explains how financial institutions can move from a transaction-monitoring alert to an effective STR.


What Is a Suspicious Transaction Report?

A Suspicious Transaction Report, or STR, is a report submitted to the NFIU when a reporting entity has established reasonable grounds to suspect that a transaction may be connected to money laundering, terrorist financing, proliferation financing, a predicate offence or another unlawful activity.

Under the MLPPA, transactions may be considered suspicious where, among other things, they:

  • involve an unjustifiable or unreasonable frequency;

  • are surrounded by unusual or unjustified complexity;

  • appear to have no economic justification or lawful objective;

  • are inconsistent with the known transaction pattern of the account or business relationship; or

  • are considered by the reporting entity to involve proceeds of criminal activity, an unlawful act, money laundering or terrorist financing.

There is no minimum monetary threshold for an STR.

Suspicious transactions should be reported regardless of their value, and the reporting obligation may apply whether the transaction has been completed or merely attempted.

An Alert Is Not Automatically an STR

This distinction is critical. Transaction-monitoring systems may generate hundreds or thousands of alerts based on scenarios, thresholds or behavioural indicators. However, an alert should not automatically be treated as a suspicious transaction.

The alert must first be reviewed and investigated to determine whether there are reasonable grounds for suspicion.

A good STR process therefore looks like: Alert → Investigation → Formation of Suspicion → STR Filing

This distinction helps institutions avoid both missed suspicious activity and defensive over-reporting.

Step 1: Identify Unusual or Potentially Suspicious Activity

The first stage is identifying transactions or behaviour that warrant further investigation. Common red flags may include:

  • unusually large deposits, withdrawals or transfers inconsistent with the customer’s profile;

  • repeated transactions structured below applicable reporting or review thresholds;

  • sudden activity on dormant or previously low-activity accounts;

  • rapid movement of funds through multiple accounts without an obvious economic purpose;

  • unexplained transactions with unrelated third parties;

  • transactions involving higher-risk jurisdictions;

  • activity inconsistent with the customer’s stated occupation, business or expected account behaviour;

  • unexplained use of multiple accounts or counterparties;

  • transactions involving sanctioned or otherwise high-risk parties;

  • unusual cash activity;

  • transactions involving suspected fraud proceeds;

  • activity associated with known financial-crime typologies; and

  • customer behaviour apparently designed to avoid KYC, source-of-funds or other compliance checks.

A red flag does not by itself prove that money laundering or another offence has occurred. It is a trigger for further investigation.

Step 2: Conduct an Internal Investigation

Once an alert is generated, the institution should assess whether there are reasonable grounds for suspicion. A proper investigation should consider the facts, customer context and relevant ML/TF/PF indicators before a determination is made.

Review the Alert - Understand exactly what rule, scenario, threshold or behaviour caused the transaction to be flagged.

Review the Customer Profile - Consider relevant information such as occupation or business activity; expected income or turnover; customer risk rating; source of funds;

source of wealth, where relevant; geography; products used; account history; and expected transaction behaviour.

Review Transaction History - Do not assess the individual transaction in isolation. Look for previous similar transactions; transaction frequency; related counterparties; movement of funds before and after the transaction; connected accounts; transaction descriptions; recurring patterns; and other relevant customer behaviour.

Review KYC and KYB Information - For corporate customers, the investigation may also require consideration of beneficial ownership; directors; shareholders; related entities; business activities; and whether the observed transactions make sense in the context of the customer’s business.

Consider Relevant Red Flags and Typologies - Investigators should consider relevant national and sector risk assessments, NFIU typology reports, regulatory advisories and the institution’s own risk assessments.

Document the Decision - If the alert is closed as not suspicious, the reason should still be documented.

Institutions should maintain records of alerts that were investigated but did not qualify for STR filing, together with clear reasons for the decision. These records may become relevant during future investigations or regulatory examinations.


Step 3: Decide Whether There Are Reasonable Grounds for Suspicion

How Long Does an Institution Have to Investigate and File?

This is one of the most important aspects of STR compliance.

The NFIU’s current guidance clarifies that the 24-hour reporting period is triggered once the institution has examined the transaction and determined that reasonable grounds for suspicion exist.

The transaction should also be subjected to the institution’s examination and screening process not later than 72 hours.

A practical way to understand the process is therefore:

Alert generated → investigation and examination → suspicion established → STR filed within 24 hours

The 72-hour period should not be treated as a routine waiting period.

Institutions should investigate alerts as promptly as the level of risk requires and maintain internal service levels that allow potentially suspicious activity to be escalated quickly.

Higher-risk matters, particularly those involving terrorism financing, sanctions, fraud in progress or rapidly moving funds, may require significantly faster action.


An STR should be based on more than a vague feeling that a transaction “looks unusual.”

The institution should be able to explain how the: Facts + Context + Relevant Red Flags or Indicators, led it to reasonable grounds for suspicion.

The reasoning should be clear enough that another appropriately trained compliance professional reviewing the same information could understand how the institution reached its conclusion.

This does not mean that the institution must prove that a crime occurred. An STR is a financial intelligence report, not a criminal conviction.

The institution needs reasonable grounds for suspicion, not proof beyond reasonable doubt.

Step 4: Prepare the STR Narrative

A high-quality STR is not simply a collection of transaction data. The narrative should enable an NFIU analyst who has never seen the customer before to understand:

  • Who is involved?
  • What happened?
  • When did it happen?
  • Where did it happen?
  • Why is it suspicious?
  • How was the activity carried out?

Who?

Identify the relevant subject or subjects. This may include customer name; account number; identification information; occupation or business; directors or beneficial owners; relevant counterparties; and related persons or entities.

What?

Explain what activity occurred.For example deposits; transfers; withdrawals; purchases; payments; movement through related accounts; or another relevant transaction pattern.

When?

Provide the relevant dates and times. Where the suspicious activity covers multiple transactions, explain the relevant period and chronology.

Where?

Identify the relevant location or channel. This may include branch; online banking; mobile application; payment platform; ATM; international transfer channel; or another relevant transaction location.

Why Is It Suspicious?

This is often the most important part of the narrative. Explain why the activity is inconsistent with what the institution knows about the customer. Avoid generic statements such as: “The transaction is suspicious because it is unusual.”

Instead, explain the actual inconsistency. For example:

“The customer operates a small domestic retail business with average monthly inflows of approximately ₦3 million. During a four-day period, the account received ₦48 million from 17 unrelated individuals, with approximately 90% of the funds transferred to three newly introduced corporate beneficiaries within 24 hours of receipt.”

The narrative should then connect those facts to the relevant red flags, typologies or suspected financial-crime risk.

How?

Explain how the suspicious activity was carried out, including any apparent structuring, layering, use of related accounts, rapid movement of funds or other relevant mechanism.

Step 5: Identify the Suspected Predicate Offence

Where possible, the reporting entity should identify the suspected predicate offence associated with the STR based on its best assessment of the available information.

Examples may include fraud; corruption; bribery; kidnapping for ransom; drug trafficking; cybercrime; terrorist financing; proliferation financing; or another relevant criminal activity.

The institution does not need to establish conclusively that the offence occurred.

However, where the facts indicate a likely predicate offence, the STR should communicate that assessment clearly.

Step 6: Include Relevant Supporting Information

A strong STR should be supported by relevant customer, transaction and investigation information. The objective is to give the NFIU sufficient context to analyse the report without having to reconstruct the institution’s entire investigation from incomplete information.


Step 7: File the STR Through the Appropriate NFIU Channel

The appropriate reporting channel depends on the type of reporting entity.

Financial Institutions

Most financial institutions file STRs through the NFIU’s goAML platform. goAML supports web-based reporting as well as structured electronic reporting.

Bureau de Change Operators

Bureaux de Change currently file STRs through the NFIU’s RapidAML platform rather than the standard goAML process.

DNFBPs

Designated Non-Financial Businesses and Professions also use RapidAML for STR filing. Reporting entities should therefore ensure that their regulatory-reporting workflows are configured for the channel applicable to their regulatory category.


Step 8: Monitor the Filing Status and Respond to NFIU Feedback

Submitting an STR is not necessarily the end of the reporting process.

Compliance teams should monitor whether the report has been successfully received and whether the NFIU has provided any validation message, feedback or request for additional information.

Where a report is rejected, the institution should investigate the cause and correct it promptly.

Compliance teams should therefore monitor:

  • whether the STR was successfully received;

  • validation or rejection messages;

  • requests for additional information;

  • supplementary reporting requirements; and

  • subsequent relevant customer activity.

Where material new information emerges after the original STR is filed, the institution may need to provide additional information to the NFIU with reference to the original report.

Important to Note

Do Not Tip Off the Customer

STRs are confidential. Employees should not tell a customer or other relevant person that:

  • an STR has been filed;

  • an STR is about to be filed;

  • the institution is conducting an STR-related investigation; or

  • information has been disclosed to the NFIU.

Tipping off can itself result in serious criminal consequences. Staff involved in alert investigation and STR filing should therefore understand the institution’s confidentiality and escalation procedures.

Filing an STR Does Not Automatically Mean Freezing the Account

Filing an STR does not, by itself, automatically mean that the institution should freeze the customer’s account.

Under the applicable AML framework, the NFIU or another competent authority may issue an appropriate stop instruction, and a court may subsequently make relevant orders where the statutory conditions are satisfied.

Separate immediate-freezing obligations may also apply under targeted financial-sanctions requirements.

Institutions should therefore distinguish between:

  • filing an STR;

  • taking appropriate internal risk-management measures permitted by law and contract;

  • complying with sanctions-freezing obligations;

  • responding to an NFIU or competent-authority instruction; and

  • acting pursuant to a court order.

An STR should not be treated as an automatic instruction to freeze every reported customer.

Penalties for Failing to Report an STR

Failure to comply with STR reporting obligations can result in significant legal and regulatory consequences.

Under the Money Laundering (Prevention and Prohibition) Act 2022, a financial institution or DNFBP that fails to comply with applicable suspicious-transaction reporting requirements may be liable, on conviction, to a fine of:

₦1 million for each day the offence continues.

Regulatory and supervisory authorities may also impose administrative sanctions where reporting failures arise from weaknesses in the institution’s AML/CFT/CPF framework or internal controls.

Separate consequences can arise where the suspicious activity relates to terrorism, terrorist financing or proliferation financing.

The consequences of weak STR processes can therefore extend well beyond a simple late-reporting penalty.

What Does a Good STR Process Look Like?

A mature STR process should enable an institution to answer questions such as:

  • Are potentially suspicious transactions being identified consistently?

  • Do transaction-monitoring alerts contain enough customer context to support investigation?

  • Are alerts investigated promptly?

  • Can investigators distinguish unusual activity from genuinely suspicious activity?

  • Are reasons for closing non-suspicious alerts documented?

  • Can investigators see the customer’s KYC, risk rating and transaction history in one place?

  • Are previous alerts and STRs visible during investigations?

  • Is the STR narrative clear enough for an external analyst to understand?

  • Are relevant supporting documents readily available?

  • Is the 24-hour filing deadline monitored once suspicion is established?

  • Can STRs be submitted through the appropriate NFIU reporting channel?

  • Are rejected reports and NFIU requests followed up?

  • Is there a complete audit trail from alert generation through final filing?

  • Are staff appropriately trained on confidentiality and tipping-off requirements?

Where several of these activities depend on spreadsheets, email, manual data gathering and disconnected systems, both the operational burden and the risk of error increase.

How Regfyl Can Support STR Identification, Investigation and Filing

Regfyl is designed to connect the different stages of the AML investigation and regulatory-reporting lifecycle.

Automated Transaction Monitoring

Regfyl can monitor transaction activity using configurable rules, scenarios, customer segments and financial-crime typologies to identify activity requiring further review.

An alert does not automatically become an STR. It is routed into an investigation process where compliance teams can assess the relevant facts and context.

Consolidated Customer Risk View

Investigators can review relevant customer information alongside the alert, including:

  • KYC and KYB information;

  • customer risk profile;

  • transaction history;

  • previous alerts;

  • case outcomes; and

  • other relevant risk indicators.

This helps reduce the time spent gathering information from multiple systems before deciding whether reasonable grounds for suspicion exist.

Investigation and Case Management

Alerts can be managed through structured case workflows incorporating investigation notes; supporting documents; attachments; escalation; review and approval; case status; decision history; and audit trails.

This creates evidence of both STR decisions and decisions to close alerts as non-suspicious.

STR Preparation

Where an investigation results in reasonable grounds for suspicion, Regfyl can use information already captured during the investigation to support preparation of the STR.

This reduces the need for compliance teams to manually reconstruct customer, transaction and investigation information at the reporting stage.

Direct goAML Submission

For supported financial-institution reporting workflows, Regfyl integrates directly with the NFIU goAML platform.

This enables institutions to connect:

Detection → Investigation → STR Preparation → Review and Approval → NFIU Submission → Audit Trail

within a more integrated regulatory-reporting process.

Governance and Reporting

Regfyl also provides visibility into matters such as:

  • alert volumes;

  • investigation ageing;

  • escalation;

  • case outcomes;

  • regulatory reports;

  • turnaround times; and

  • audit history.

This can help Compliance leadership monitor both operational performance and the effectiveness of the institution’s STR framework.

Is Your STR Process Still Too Manual?

An effective STR programme needs more than a transaction-monitoring rule.

It requires the institution to identify unusual activity, investigate it quickly, understand the customer context, document its reasoning, prepare a clear narrative, file within the required timeframe and maintain evidence of every decision.

Where each of those steps takes place in a different system, the compliance team spends valuable time moving information rather than investigating financial crime.

See how Regfyl can connect transaction monitoring, investigations and direct goAML regulatory reporting within one AML workflow.

See Regfyl STR Reporting in Action


Tags: #Suspicious Transaction Reports #STR #NFIU #goAML #Transaction Monitoring #AML/CFT/CPF #Regulatory Reporting #Financial Crime Compliance #Money Laundering #Nigeria
← Back to Insights