Suspicious Transaction Reporting to FIU-India: STR Rules for Bankers (2026)

KYCAML By Ashish Jain · IIBF STORE Editorial · 28 July 2026 · Updated 10 Sep 2026 · 9 min read · 63 views
Suspicious Transaction Reporting to FIU-India: STR Rules for Bankers (2026)

Every frontline banker eventually hits the same judgment call: a transaction pattern looks off, but there's no obvious fraud, no bounced cheque, nothing that trips a hard rule. This is exactly where suspicious transaction reporting to FIU-India comes in. Under the Prevention of Money Laundering Act (PMLA), 2002 and the PML (Maintenance of Records) Rules, 2005, every reporting entity — banks included — must escalate such transactions to the Financial Intelligence Unit-India (FIU-IND), the central national agency that receives, analyses, and disseminates information on suspicious financial activity. For JAIIB and CAIIB candidates, this is a high-yield exam area because it combines a legal obligation, a strict timeline, and a criminal-liability trap (tipping off) in one compact topic.

This article breaks down what actually triggers a Suspicious Transaction Report (STR), who inside the bank owns the filing, how fast it must reach FIU-IND, and why telling the customer about it can put you on the wrong side of the law. Bookmark the KYC, AML and CFT tag hub for the full run of related articles on this subject.

🚨 What Triggers a Suspicious Transaction Report

An STR is not limited to transactions above a fixed rupee value — that is precisely what separates it from a Cash Transaction Report (CTR). A transaction becomes reportable when it appears, in the bank's reasonable judgment, to involve proceeds of crime, has no obvious economic or lawful purpose, or is structured to avoid reporting or identification requirements. Typical triggers include rapid layering of funds across multiple accounts, transactions inconsistent with a customer's declared occupation or turnover, sudden activity in a dormant account, or a client who is visibly reluctant to provide documentation.

Alerts often surface first through the bank's transaction monitoring system, but they can equally come from a teller's observation, a law-enforcement reference, or patterns spotted during account review. Increasingly, banks also see STR triggers originate from digital channels — mule accounts used to route proceeds of phishing, OTP fraud, or investment scams. If you're revising cyber-enabled fraud typologies alongside this topic, the Prevention of Cyber Crime exam pattern guide maps well onto how these red flags feed into STR filing. Once an alert is raised, it goes to the Principal Officer's team for evaluation — not every alert converts into an STR, but every alert must be documented and reasoned through.

Red flags that trigger a suspicious transaction report at a bank
Red flags that trigger a suspicious transaction report at a bank

⏱️ STR Filing Timelines and the Principal Officer's Role

Every reporting entity is required to designate a Principal Officer (PO) — typically a senior compliance functionary — who is responsible for internal reporting and for furnishing information to FIU-IND under Section 12 of PMLA. Branch staff and the Principal Officer do not act independently of the record-keeping chain: the identification and transaction records that support an STR trace back to the same customer files covered under record keeping obligations under PMLA.

The widely tested timeline is this: once the bank's internal process arrives at a conclusion that a transaction is suspicious, the STR must be furnished to FIU-IND without delay and not later than seven working days from that conclusion. This is distinct from the earlier internal step of detecting and investigating the alert, which itself should not be allowed to drag on indefinitely — RBI's KYC Master Direction expects banks to reach a decision within a reasonable period after the transaction first comes to notice. Filing itself happens electronically through FIU-IND's FINnet 2.0 reporting portal, using the prescribed STR format.

💡 Exam Tip: Remember the anchor point for the 7-working-day clock — it starts from the date the bank concludes the transaction is suspicious, not from the date the transaction occurred.
STR filing timeline from alert to FIU-India submission
STR filing timeline from alert to FIU-India submission

🤐 Tipping Off: Why Bankers Cannot Alert the Customer

PMLA makes it a punishable offence for a bank, its officers, or its employees to disclose to the customer — or to any third party — that an STR has been filed or that an investigation is underway. This is called "tipping off," and it exists because a forewarned customer can move or destroy evidence, close accounts, or flee before enforcement agencies act. The confidentiality obligation extends to internal communication as well: only staff with a genuine need to know should have visibility into an STR, and it must never be referenced in customer-facing correspondence, account remarks the customer can view, or informal conversation.

This creates a real operational tension for branch staff. A customer may ask directly why their account is on hold or why a transaction was queried — the honest-sounding answer is often the wrong one. Banks train staff to use neutral, generic language ("this is a routine compliance review") rather than confirming or denying an STR. Getting this distinction right is one of the more commonly misunderstood areas in KYC-AML exam papers.

⚠️ Common Mistake: Candidates often assume tipping off only applies after an STR is filed. In practice, the same confidentiality discipline applies from the moment an internal suspicion review begins.
Tipping off prohibition under PMLA explained for bank staff
Tipping off prohibition under PMLA explained for bank staff

📊 STR vs Other FIU-India Reports

Banks file several distinct report types with FIU-IND, and exam questions frequently test whether candidates can tell them apart by trigger, threshold, and deadline. The table below lines up the four core report types reporting entities routinely submit.

Report TypeWhat Triggers ItMonetary Threshold?Typical Timeline to FIU-IND
Suspicious Transaction Report (STR)Reasonable suspicion of proceeds of crime or no lawful purpose❌ No thresholdWithin 7 working days of conclusion
Cash Transaction Report (CTR)Aggregate cash transactions in a month by an account/customer✅ Yes, prescribed aggregate valueBy the 15th of the succeeding month
Counterfeit Currency Report (CCR)Detection of forged or counterfeit currency notes❌ No thresholdBy the 15th of the succeeding month
Non-Profit Organisation Transaction Report (NTR)Transactions in accounts of non-profit organisations above the prescribed value✅ Yes, prescribed aggregate valueBy the 15th of the succeeding month

The absence of a threshold is what makes STR unique — a ₹5,000 transfer can be just as reportable as a ₹5 crore one if the surrounding facts are suspicious. This is also why STR relies heavily on judgment and pattern recognition rather than a simple rupee-value trigger.

🏛️ Inside FIU-India's Reporting Ecosystem

FIU-IND functions as the national nodal agency for receiving and analysing reports from banks, NBFCs, insurers, and other reporting entities, and for sharing actionable intelligence with law enforcement and regulators. Understanding where it sits in the broader institutional structure — alongside enforcement agencies, RBI, and sector regulators — is covered in depth under Organization Structure in India, which every candidate should read alongside this topic.

The underlying legal mandate for all of this — PMLA itself, its rules, and the reporting obligations placed on banks — is set out in Legislation at National Level. India's STR framework also reflects global standards; for the international benchmarks that shaped these obligations, see International Guidelines & Standards. Because monitoring quality depends directly on how current customer data is, ongoing re-verification cycles described in periodic KYC updation rules feed the same alert pipeline that produces STR triggers, and identity data drawn from the Central KYC Records Registry often supports the customer-profile checks a Principal Officer runs before deciding to file.

📌 Remember: FIU-IND does not investigate crimes itself — it analyses reports and routes actionable intelligence to enforcement agencies, RBI, and other regulators.

For the current reporting formats, FAQs, and compliance clarifications, banks and candidates can refer to the Reserve Bank of India's published guidance at rbi.org.in.

🎯 Exam Takeaways and What to Revise Next

For KYC-AML papers, lock in three things: STR has no monetary threshold, the 7-working-day clock starts from the bank's conclusion of suspicion (not the transaction date), and tipping off is a standalone offence independent of whether the STR was ultimately accepted or acted upon by FIU-IND. Questions often combine two of these in a single scenario-based MCQ, so practise reading the fact pattern carefully before picking the trigger.

Ready to test yourself under exam conditions? Attempt a full mock set on iibf.store/tests or continue your structured prep through the CAIIB course track.

🧠 Practice MCQs: Suspicious Transaction Reporting to FIU-India

Q1. Within how many working days must a bank furnish an STR to FIU-IND after concluding that a transaction is suspicious? (a) 24 hours (b) 3 working days (c) 7 working days (d) 30 calendar days

Answer: (c) — The STR must reach FIU-IND without delay and not later than 7 working days from the date the bank concludes the transaction is suspicious.

Q2. Who is primarily responsible for filing STRs on behalf of a bank? (a) Branch Manager (b) Principal Officer (c) Compliance intern (d) External auditor

Answer: (b) — The Principal Officer, designated under PMLA, is responsible for internal reporting and furnishing information to FIU-IND.

Q3. Under PMLA, informing a customer that an STR has been filed against their account is known as: (a) Disclosure (b) Whistleblowing (c) Tipping off (d) Escalation

Answer: (c) — Tipping off is a punishable offence under PMLA that prohibits alerting the customer or third parties about an STR.

Q4. Which of the following is TRUE about the monetary threshold for filing an STR? (a) STR applies only above ₹10 lakh (b) STR applies only above ₹50,000 (c) STR has no minimum monetary threshold (d) STR threshold matches the CTR threshold

Answer: (c) — Unlike CTR, an STR can be filed regardless of transaction value if the activity appears suspicious.

Q5. FIU-IND functions under which government body? (a) RBI (b) SEBI (c) Department of Revenue, Ministry of Finance (d) Ministry of Home Affairs

Answer: (c) — FIU-IND operates as an independent body reporting to the Department of Revenue, Ministry of Finance.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

What does STR stand for in banking compliance?

STR stands for Suspicious Transaction Report, a report banks and other reporting entities must file with FIU-India when a transaction appears to involve proceeds of crime or has no apparent lawful purpose.

Is there a minimum transaction amount for filing an STR?

No. Unlike the Cash Transaction Report, an STR has no monetary threshold — any transaction, regardless of value, can be reportable if it is genuinely suspicious.

What happens if a bank delays or fails to file an STR?

Delayed or missed STR filings expose the bank to regulatory action and penalties under PMLA, along with supervisory scrutiny from RBI during compliance inspections.

Can a bank simply close a suspicious account instead of filing an STR?

No. Closing or restricting an account is a separate risk decision from the statutory obligation to file an STR — the reporting requirement stands regardless of what account-level action the bank takes.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. A proprietor deposits cash of ₹4 lakh, ₹3.5 lakh and ₹4 lakh on three different dates of the same calendar month into his proprietorship account, all as receipts. No single deposit crosses ₹10 lakh. What is the bank's primary obligation under PMLR?
Q2. Which of the following is a mandatory element that every transaction record must contain under the record-keeping requirements described in the chapter?
Q3. An auditor asks why STR cannot be generated centrally by software the way CTR, NTR and CBTR are. Which explanation is most accurate as per the chapter?
Q4. A customer closes his current account on 1 April 2024. Under PMLA/PMLR, until when must the bank retain his KYC identity documents (assume no legal proceeding is pending)?
Q5. A large bank with straight-through processing and millions of customer-initiated transactions wants to justify investing in AML software rather than relying on manual scrutiny. Which benefit set best supports this, per the chapter?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading