Verihubs Logo
Home Blog Suspicious Transaction Report (STR) Philippines: Filing Guide
14 min read KYC Published on July 22, 2026

Suspicious Transaction Report (STR) Philippines: Filing Guide

Suspicious Transaction Report (STR) Philippines: Filing Guide

A Suspicious Transaction Report (STR) is the report a covered person files with the AMLC when a transaction shows red flags, regardless of the amount involved. Most compliance guides still cite a five-working-day deadline. That figure is the AMLA statutory baseline and it is no longer correct for STRs.

Under AMLC Regulatory Issuance No. 2, Series of 2024 (GoTRACS), an STR must be filed by the next working day from occurrence, where “occurrence” means the moment suspicion is established, not the transaction date. Attempted transactions are reportable too, and a decision not to file must be documented.

What Is a Suspicious Transaction Report (STR)?

An STR is a confidential report submitted to the Anti-Money Laundering Council when a covered person concludes that a transaction is suspicious. It is not an accusation and it does not require proof of a crime. The threshold is suspicion, not certainty.

Two features separate the STR from every other report a Philippine covered person files. It has no minimum amount, so a PHP 3,000 transfer is as reportable as a PHP 3 million one if the red flags are there. And it covers attempts: under GoTRACS, covered persons must report suspicious transactions “including attempts thereof”, which means a transaction that was declined, abandoned, or never completed still triggers the obligation.

The receiving authority is the AMLC, which acts as the Philippines’ financial intelligence unit. STRs feed its analytical work and can become the evidentiary basis for freeze orders and money laundering prosecutions.

STR vs CTR: Key Differences

Covered persons file two report types, and confusing their rules is a common source of non-compliance.

FeatureCovered Transaction Report (CTR)Suspicious Transaction Report (STR)
TriggerAmount threshold breachedRed flags present, any amount
Minimum amountPHP 500,000 (general); PHP 1M jewelry and precious metals; PHP 5M casinos; PHP 7.5M real estateNone
Filing deadlineWithin 5 working days from occurrenceWithin the next working day from occurrence
What “occurrence” meansThe transaction itselfThe establishment of suspicion
Judgment requiredMechanical, threshold-basedAnalytical, requires internal review
Attempts reportableNoYes

The practical consequence: CTR filing can be automated end to end, because a system can detect a threshold breach and generate the report. STR filing cannot, because someone has to decide that a pattern is suspicious. That decision is what starts the one-day clock.

What Triggers an STR in the Philippines?

AMLA defines a suspicious transaction through seven circumstances. A transaction qualifies if any one of them is present.

  1. There is no underlying legal or trade obligation, purpose, or economic justification for the transaction.
  2. Identification of the client is incomplete or unreliable.
  3. Amounts involved do not match the business or financial capacity of the client.
  4. The transaction appears structured to avoid reporting requirements, which covers smurfing and structuring patterns.
  5. Any circumstance in the transaction deviates from the client’s profile or past transactions.
  6. The transaction relates to an unlawful activity that is about to be, is being, or has been committed.
  7. Any transaction similar or analogous to the above.

That seventh item is deliberately open-ended. It exists so covered persons cannot argue that a novel laundering method falls outside the list.

Red flags Philippine compliance teams see most often

The statutory list is abstract. In day-to-day operations, the patterns that most often escalate into STRs are more specific: deposits clustered just under PHP 500,000 from the same customer or a group of related customers; a salaried account suddenly receiving large third-party transfers; accounts that receive and immediately forward funds with no retained balance; customers who refuse to explain source of funds when asked; multiple accounts sharing an address, device, or phone number; and transaction volumes that contradict a customer’s declared occupation.

The last one is where weak onboarding shows up. If your eKYC never captured a reliable customer profile, you have nothing to compare the transaction against, and circumstance number five becomes impossible to detect.

The STR Deadline Under GoTRACS: Next Working Day, Not Five

This is the single most misreported rule in Philippine AML compliance content, and it is worth being precise about.

AMLA sets a general reporting period of five working days from occurrence for covered and suspicious transactions. On 11 December 2024 the AMLC issued Regulatory Issuance No. 2, Series of 2024, the Guidelines on Transaction Reporting and Compliance Submissions, known as GoTRACS. According to ACCRALAW’s analysis of the issuance (January 2025), GoTRACS requires covered persons to file STRs, including attempts, electronically through the AMLC File Transfer and Reporting Facility within the next working day from occurrence.

Then comes the part that changes operational planning. GoTRACS defines “occurrence” for STR purposes as the establishment of suspicion or the determination of the suspicious nature of the transaction. Your deadline does not run from the transaction date. It runs from the moment your compliance function concludes the transaction is suspicious.

Read one way, that sounds generous, because a transaction from three weeks ago can still be filed on time if suspicion was only established yesterday. Read another way, it is demanding: once the determination is made, the entire escalation and filing process has to complete inside a single working day.

The Reporting Chain: What GoTRACS Requires Internally

GoTRACS does not just set a deadline. It requires covered persons to build a documented internal process, called the reporting chain, running from the triggering event to either the filing of an STR or the documentation of a decision not to file.

Under GoTRACS, a covered person’s Money Laundering and Terrorism Financing Prevention Program must specify the procedures for the determination period, name the department or personnel responsible for each step, state the number of days allotted to each procedure, define controls for reviewing and validating suspicious transactions, and establish a decision-making policy including a Compliance Officer or review committee authorised to decide with finality whether to file.

Two implications are easy to miss. First, a decision not to file still has to be documented, so an examiner can reconstruct why your team cleared a flagged transaction. Second, because you must state how many days each step takes, an internal process that allots three days to review and two days to escalate is self-evidently non-compliant with a next-working-day deadline. Your written program can contradict your obligation on paper.

How to File an STR: Practical Steps

The mechanics follow the reporting chain rather than a single form submission.

Detect and escalate. Transaction monitoring, a branch employee, or a periodic review flags an unusual transaction. It moves to the compliance unit through the defined escalation path.

Review and validate. Compliance assesses the transaction against the customer profile, source of funds documentation, and the seven statutory circumstances. Compliance may run additional due diligence at this stage.

Decide. The Compliance Officer or review committee determines whether suspicion is established. This moment is the “occurrence” that starts the next-working-day clock. Whichever way the decision goes, the team records it.

File electronically. If the decision is to file, the STR goes to the AMLC through the File Transfer and Reporting Facility in the prescribed electronic format, complete and accurate, by the next working day.

Preserve confidentiality. The filing is never disclosed to the customer or to anyone outside the authorised chain.

Tipping Off: The Rule That Carries the Heaviest Penalty

Telling a customer that an STR has been filed, or hinting at it, is a criminal offence in the Philippines. The prohibition covers communication by any means, to any person, entity, or media, about the fact of the report, its contents, or any related information.

According to the Implementing Rules of RA 9160, breach of confidentiality under Section 14(d) of AMLA carries imprisonment of three to eight years and a fine of PHP 500,000 to PHP 1 million. That is a heavier custodial penalty than the one for failing to file the report at all, which tells you how seriously the framework treats confidentiality.

This has design consequences. Front-line staff should not be able to see STR status in the customer record. Account closures or restrictions that follow an STR need a defensible commercial rationale that does not reveal the filing.

Consequences of Failing to File an STR

Failure to report is not treated as a paperwork lapse. Under AMLA, a covered person who knows a transaction must be reported and fails to report it commits an offence in its own right.

OffenceImprisonmentFine
Failure to disclose and file a required report (AMLA Sec. 4(c))6 months to 4 yearsPHP 100,000 to PHP 500,000, or imprisonment, or both
Breach of confidentiality / tipping off (AMLA Sec. 14(d))3 to 8 yearsPHP 500,000 to PHP 1 million
Malicious or bad-faith reporting6 months to 4 yearsPHP 100,000 to PHP 500,000

Beyond the criminal exposure, GoTRACS states that submissions filed beyond the prescribed periods count as non-compliance and may result in administrative sanctions from the AMLC. Those sanctions scale with the size of the institution and the gravity of the violation, and they sit alongside whatever action your primary supervisor, whether BSP, SEC, or the Insurance Commission, decides to take.

One protection is worth knowing. A report filed in good faith in the regular performance of duties does not expose the filer to administrative, criminal, or civil proceedings, whether or not it leads to a prosecution. The framework deliberately protects over-reporting and penalises silence.

Frequently Asked Questions About STRs in the Philippines

What is the STR filing deadline in the Philippines?

Under AMLC Regulatory Issuance No. 2, Series of 2024 (GoTRACS), an STR must be filed electronically through the AMLC File Transfer and Reporting Facility within the next working day from occurrence. “Occurrence” means the establishment of suspicion or the determination that a transaction is suspicious, not the date of the transaction. The five-working-day figure often quoted online is the AMLA statutory baseline and the CTR deadline, not the current STR deadline.

Is there a minimum amount for filing an STR?

No. Unlike Covered Transaction Reports, which are triggered by amount thresholds such as PHP 500,000 for most covered persons, STRs have no minimum. Any transaction of any size must be reported if it meets one of the seven suspicious circumstances under AMLA.

Do I need to report a transaction that was never completed?

Yes. GoTRACS requires covered persons to report suspicious transactions including attempts. A transaction that was declined, abandoned, or blocked still triggers the STR obligation if suspicion was established.

What happens if we decide not to file after reviewing a flagged transaction?

The decision must be documented. GoTRACS requires the reporting chain to run from the triggering event to either the filing of an STR or the documentation of a decision not to file. An undocumented decision to clear a flagged transaction is a compliance gap that an AMLC examination can surface.

Can we tell the customer that we filed an STR?

No. Tipping off is a criminal offence. Under Section 14(d) of AMLA, breach of confidentiality carries imprisonment of three to eight years and a fine of PHP 500,000 to PHP 1 million. The prohibition covers any communication about the fact of the report, its contents, or related information, to any person, entity, or media.

Who decides whether to file an STR?

Under GoTRACS, the covered person’s Money Laundering and Terrorism Financing Prevention Program must designate a Compliance Officer or a review committee authorised to decide with finality whether to file an STR or to document the non-filing. The program must also name the personnel responsible for each step in the reporting chain.

A One-Day Deadline Is Really an Onboarding Problem

Compliance teams that miss STR deadlines usually are not slow. They are stuck reconstructing who the customer is after the alert fires: pulling documents, chasing source of funds, verifying identity details that onboarding should have settled. A next-working-day window does not leave room for that.

What makes the deadline achievable is a verified customer profile that already exists when the alert arrives. Verihubs eKYC API builds that profile at onboarding, with government ID verification across 15+ Philippine document types, biometric liveness detection, and deepfake detection. When your compliance officer opens a flagged transaction and the identity underneath it is already confirmed, the review that GoTRACS expects inside one working day becomes realistic.

Talk to the Verihubs team about building an eKYC foundation that makes AMLC reporting deadlines achievable.

View Blog