A suspicious transaction report under Regulation (EU) 2024/1624 has no fixed filing period, and that surprises people looking for a number. Article 69 requires reporting “promptly” and on the entity’s own initiative. The deadlines that do exist attach to different things: responding to a request from the Financial Intelligence Unit, and the three working days that govern whether a held transaction may proceed.
This sets out what actually triggers a suspicious transaction report, which clocks run, and the two categories that are expressly reportable and routinely missed.
What this guide covers
- When a suspicious transaction report is required
- Two categories of suspicious transaction report that get missed
- The clocks that actually run on a suspicious transaction report
- The three working days in Article 71
- What must be recorded whether or not you file a suspicious transaction report
- What you may not say while a suspicious transaction report is in play
- Building an internal route that produces a suspicious transaction report on time
- Frequently asked questions
- Documenting the reporting route

When a suspicious transaction report is required
Article 69(1)(a) engages where the obliged entity knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing or criminal activity.
Three alternative thresholds, and the third is objective. The question for staff is not “am I sure” but “are there grounds”. And “regardless of the amount involved” removes any de minimis: there is no floor below which a suspicious transaction report is unnecessary.
Note also that the Article covers funds or activities. A pattern of behaviour with no transaction attached is inside the duty.
Two categories of suspicious transaction report that get missed
The second subparagraph of Article 69(1) is explicit that all suspicious transactions must be reported, including attempted transactions and suspicions arising from the inability to conduct customer due diligence.
Attempted transactions are the harder of the two operationally. A transaction rejected at the front end frequently never persists to a system of record, so there is nothing for monitoring to alert on and nothing to report from. Whether your systems can produce an abandoned or rejected transaction is worth testing rather than assuming.
The second category connects to Article 21. Where an entity cannot complete the customer due diligence measures in Article 20(1), it must refrain, terminate the relationship and consider reporting. A file closed administratively as “onboarding failed” with no suspicion assessment behind it is the commonest way this obligation goes unmet.
The clocks that actually run on a suspicious transaction report
A suspicious transaction report sits inside several clocks, and they start at different events. Presenting them as one countdown is the mistake to avoid.
| Clock | Starts at | Period | Article |
|---|---|---|---|
| Making the report | Suspicion formed | “Promptly” — no fixed period in the text | 69(1)(a) |
| Responding to an FIU request | The request | Within the deadlines imposed by the FIU | 69(1)(b) |
| Proceeding with a held transaction | Submission of the report | 3 working days without contrary instructions | 71(1) |
| Threshold reports for high-value goods | The transaction | Within the deadlines imposed by the FIU | 74(3) |
| Retention of the assessment record | End of relationship, transaction, or refusal | 5 years, then deletion | 77(3) |
Because “promptly” is not defined for a suspicious transaction report, the entity sets its own internal standard and monitors against it. That standard is what a supervisor will test, so it needs to exist in the procedure rather than in practice alone.
The three working days in Article 71
Article 71(1) requires the entity to refrain from carrying out transactions it knows or suspects to be related to proceeds of criminal activity or to terrorist financing until it has submitted the report and complied with any further specific instructions from the FIU or another competent authority. Both conditions — submitting the report does not release the transaction if instructions have been given.
The Article then permits the entity to carry out the transaction after having assessed the risks of proceeding if it has not received contrary instructions from the FIU within three working days of submitting the report.
Three points decide whether this is operated correctly. It is permissive, not automatic — the entity may proceed, it is not obliged to. It requires a recorded risk assessment before proceeding, so releasing a payment because a timer expired does not meet the Article. And the clock runs in working days from submission, so the convention used needs to be written down.
Article 71(2) covers the cases where refraining is not possible, or where refraining would be likely to frustrate efforts to pursue the beneficiaries of a suspected operation. Those are findings to be recorded, not conveniences.
What must be recorded whether or not you file a suspicious transaction report
This is the provision that changes record-keeping practice most. Article 77(1)(b) requires retention of a record of the assessment undertaken under Article 69(2) — including the information and circumstances considered and the results — whether or not it results in a suspicious transaction report, together with a copy of any report made.
A supervisor examining reporting quality will look hardest at the assessments that did not result in a report, because that is where under-reporting shows. An entity holding copies of its filed reports and nothing else cannot demonstrate that the cases it decided not to file were considered at all.
So the record needs to list what was considered, not just the conclusion: the customer file, the expected activity profile, transaction history, the beneficial ownership position, the risk score, sanctions status, group information and any explanation obtained. And it needs to state which of the three Article 69(1) thresholds was met, or that none was — “no suspicion” and “not enough evidence to be certain” are very different conclusions and only one is a lawful basis for not reporting.
What you may not say while a suspicious transaction report is in play
Article 73 prohibits obliged entities and their directors, employees or persons in comparable positions — including agents and distributors — from disclosing to the customer or to other third persons three things: that transactions or activities are being or have been assessed under Article 69, that information is being, will be or has been transmitted, or that a money laundering or terrorist financing analysis is being, or may be, carried out.
The third limb is the widest and the one staff most often breach. Saying “I may have to escalate this” is a disclosure even though nothing has yet happened.
Ordinary due diligence enquiries remain legitimate — you may ask a customer about a transaction. What you may not do is say why. Where a transaction is held under Article 71, the customer-facing team needs an approved form of words agreed in advance, and an exit letter drafted without Article 73 in mind is the classic breach.
Building an internal route that produces a suspicious transaction report on time
Because the Regulation does not supply a filing period, the internal route is what makes “promptly” measurable. Five steps, each with a named owner and a stated timescale, are enough.
Raising. Anyone forming a suspicion reports internally the same day. That includes suspicions arising from an alert, from a refused onboarding, and from an attempted transaction that never completed. Staff need to know the route exists and that Article 72 protects them for using it.
Acknowledging. The compliance officer records receipt. This matters evidentially: the gap between the internal report and the external one is the part the entity controls, and an unacknowledged internal report is indistinguishable from one never made.
Assessing. The Article 69(2) assessment is performed and recorded, listing what was considered. Where an enquiry of the customer would itself tip them off, the decision not to enquire is recorded too.
Deciding and filing. The compliance officer decides, files the suspicious transaction report where the threshold is met, and records the reference. Where a transaction is being held, the sequencing matters: the suspicion assessment comes before any exit or delay communication reaches the customer.
Following up. FIU requests for additional information run to deadlines the FIU imposes, and those need tracking separately from the original report. A request can also arrive about a customer you have never reported on, so the process should not assume a prior case exists.
Sampling the cases that produced no suspicious transaction report is the single most useful quality control. Two things are worth testing: that the reasoning addresses one of the three Article 69(1) thresholds explicitly, and that the record lists the information and circumstances considered rather than only the conclusion. Both are what Article 77(1)(b) actually asks for.
Frequently asked questions
Is there a fixed number of days to file a suspicious transaction report?
Not in the Regulation. Article 69 requires prompt reporting on the entity’s own initiative. Fixed periods apply to responding to FIU requests and to threshold-based reports under Articles 74 and 80, both of which run to deadlines the FIU imposes.
Who submits the report?
The compliance officer. Article 11(2) makes that role responsible for reporting suspicious transactions to the FIU in accordance with Article 69(6), so an internal route that lets a line manager close a report before it reaches them defeats the Article.
Can we outsource suspicion reporting?
Almost never. Article 18(3)(e) makes reporting to the FIU non-delegable, with one narrow exception: outsourcing to another obliged entity belonging to the same group and established in the same Member State.
Are we protected if the suspicion turns out to be wrong?
Article 72 provides that disclosure to the FIU in good faith, in accordance with Articles 69 and 70, does not constitute a breach of any restriction on disclosure imposed by contract or by law, and does not involve the entity or its staff in liability of any kind. That protection covers disclosure to the FIU — it does not permit telling anyone else.
Documenting the reporting route
The suspicious transaction report obligation is easy to state and hard to evidence, because the evidence is mostly in the cases you did not report. Our EU AMLR Toolkit includes the suspicion assessment record Article 77(1)(b) requires, a tipping-off standard with approved forms of words, and a log that keeps threshold reports separate from suspicion reports. The wider due diligence context is in CDD vs EDD, the deadline that governs the whole programme is in the AMLR 2027 timeline, and Article 69 is on EUR-Lex.