goAML Luxembourg — how to file an STR with the CRF
In Luxembourg, money-laundering and terrorism-financing intelligence flows to one national agency: the Cellule de Renseignement Financier (CRF), and it arrives through one channel only — goAML. Every professional subject to the AML law — including EMIs, payment institutions and their Luxembourg branches — files its déclaration d’opération suspecte electronically, separately from any prudential dialogue with the CSSF. What most guidance misses is that Luxembourg has built a dedicated reporting track for online providers, and that a passported payments firm headquartered there routes its entire EU suspicion book through the CRF rather than through each host FIU. This is the operational walkthrough.
1. What the CRF is
The Cellule de Renseignement Financier (CRF) is Luxembourg’s financial-intelligence unit — part of the judicial system, attached to the public prosecutor’s office (Parquet), and operationally independent. Its mandate sits in the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the “AML Law”), with its institutional plumbing in the modified Law of 7 March 1980 on the organisation of the judiciary, whose Articles 74-2 to 74-6 govern its exchanges with prosecutors, supervisors and other administrations.
It is the sole authority competent to receive suspicious-operation reports under Article 5(1)(a) of the AML Law, from the professionals listed exhaustively in Article 2. Under Article 5(1)(b) it can also compel information from those professionals on its own initiative — a separate duty from spontaneous reporting. Like TRACFIN in France it is purely an intelligence unit; supervision sits with the CSSF. For calibration: 51,130 declarations in 2024, a 15% rise on 2023, with 12,210 declarants registered in goAML.
2. Who must file
Article 2 of the AML Law lists the professionnels in scope: for a fintech audience, credit institutions and their branches; EMIs and payment institutions, including Luxembourg branches of EU firms; investment firms and other CSSF-supervised professionals of the financial sector (PSF); virtual-asset and crypto-asset service providers; and fund managers. The obligation is operationalised for the financial sector by CSSF Regulation 12-02. Payments and e-money are not a marginal corner here: in 2024 the payment-institution sector filed 19,790 declarations and the e-money sector 14,397 — together roughly two-thirds of everything the CRF received.
3. The two named roles — RR and RC
Every professional designates two named functions, both notified to the CSSF and known to the CRF: the Responsable du Respect des obligations (RR), a management-body member accountable at board level for the AML/CFT framework, and the Responsable du Contrôle du respect des obligations (RC), the compliance officer who operates it and is the contact point for the CRF and the CSSF. The RC is in practice the person who ensures the déclaration reaches the CRF. For a Luxembourg branch of an EU institution both roles must be filled locally with genuine authority — a mailbox delegation to head office does not satisfy the substance expectation.
4. What triggers a declaration
Monitoring rules surface candidates; an investigator triages; the RC decides and files. Engineers must not quietly raise the alerting threshold to manage volume, because the legal test does not move with the tuning. Reportable situations include operations suspected of ML/TF links and operations whose lawful economic purpose is not apparent. A declaration is required even where the operation has not been, or cannot be, executed — which is precisely why the report-type choice matters.
5. The six report types — and why the choice is not cosmetic
goAML’s Luxembourg data model splits reports along two axes: whether there is a suspicious transaction to describe, and whether the suspicion concerns terrorist financing. That produces the taxonomy every RC must get right at the point of filing:
| Report type | Transactions? | Filer | Typical use |
|---|---|---|---|
| STR | Yes | Traditional sectors | Identified suspicious transactions |
| SAR | No | Traditional sectors | Suspicion, no identifiable transaction |
| STRe | Yes | Online providers | As STR, online-provider track |
| SARe | No | Online providers | As SAR, online-provider track |
| TFTR | Yes | All | Terrorist financing, with transactions |
| TFAR | No | All | Terrorist financing, no transactions |
The no-transaction branch is the one payments firms systematically under-use. The CRF’s own examples of SAR territory are an onboarding refusal, adverse media on a customer, a name on a sanctions list not covered by the modified Law of 19 December 2020 on restrictive financial measures, and abusive use of legal persons or opaque structures with no economic rationale. None has a transaction attached; none is optional to report. The CRF attributes the 2024 growth in SAR/SARe volume to attempted onboardings using false identity documents where no transaction ever occurred — and for payment institutions, fraud, counterfeiting and false identity documents were the three leading suspected predicate offences.
6. The “prestataire en ligne” track — the point that changes your architecture
The CRF created the SARe/STRe types for a defined set of filers it calls prestataires en ligne: payment institutions, e-money institutions, essentially online banks, and virtual-asset service providers. Two structural consequences follow.
First, these firms submit for every EU member state to the Luxembourg CRF. The CRF’s own account is blunt: the great majority of these declarations have no direct link to Luxembourg beyond the provider’s registered office and the suspect’s account, and instead concern other member states through the suspects’ residence or nationality or where the conduct occurred. The CRF then shares them with the relevant foreign FIUs under Article 53(1) of Directive (EU) 2015/849. A Luxembourg-authorised EMI passporting across the Union therefore does not open twenty host-FIU channels — it files once, and the CRF handles onward routing.
Second, essentially all SARe/STRe traffic arrives by XML generated from the filer’s own systems. The CRF notes the common trajectory: a new entrant starts on the manual SAR/STR forms, then migrates in bulk once the integration is built. Treat that migration as a planned engineering project, not a switch you flip.
7. goAML — the only channel
Reporting is entirely electronic through goAML, built on the UNODC system. There is no paper or email intake. The build:
- Enrolment first. The professional registers as a reporting entity before it can file; the RC and delegated users authenticate through the national electronic-identity means (LuxTrust). A prerequisite, not a same-day step.
- Structured model. The template carries blocks for natural persons, legal persons and accounts, and takes transactions in structured form — which is what makes machine generation viable.
- Two capture routes. Web-form entry, used in practice for manual SAR cases, or XML upload from the firm’s case-management system, which is how most STR and effectively all SARe/STRe volume arrives.
- Acknowledgement and feedback. goAML issues a receipt on submission, and is the channel for what comes back — the CRF disseminates typology and risk-assessment work to registered professionals.
8. Timing, abstention, and the blocking power
The declaration must be made promptly once suspicion crystallises. Critically, Article 5, paragraph 3 sets an abstention duty: before executing an operation it suspects to be linked to ML/TF, the professional must in principle refrain and inform the CRF. Where abstaining beforehand is impossible, or would frustrate the pursuit of the beneficiaries, the operation may proceed and the CRF is informed immediately afterwards.
The same Article 5(3) is the basis of the CRF’s blocking power, which it describes as operating generally in anticipation of a judicial seizure — securing funds while the file is analysed, often cross-border so foreign authorities can request seizure through mutual legal assistance. The volumes are selective: 208 blocking orders in 2024 covering roughly €162 million, of which 136 concerned suspected fraud (above €14 million aggregate) while just 3 corruption cases accounted for more than €134 million. For a payments firm the lesson is that a fraud-driven filing is statistically the most likely to attract a block, so the account must be capable of being held on short notice.
9. Tipping-off and confidentiality
Disclosing to the customer — or any third party — that a declaration has been or will be filed, or that an analysis is under way, is prohibited and criminally sanctioned. The prohibition covers customer-accessible notes and indirect signalling such as a suspiciously specific rejection reason. Group sharing for AML purposes is permitted on the law’s conditions, but the customer-facing wall is absolute — which is why a blocked payment needs a message that is true, neutral and identical across cases.
10. The CRF and the CSSF — two functions
The CRF receives and analyses declarations; the CSSF supervises whether you have the framework to detect, decide and file them. Inspections examine the SAR track record, sample alert investigations and assess governance against CSSF Regulation 12-02, and AML enforcement sits with the CSSF, where the named RR and RC can be held to account. The two bodies also exchange regularly about what online providers actually offer from Luxembourg, including firms operating without the necessary authorisation.
11. Worked examples
Scenario 1 — a German customer, a Luxembourg licence. Facts: a Luxembourg-authorised EMI passporting into Germany detects layering on an account held by a Berlin-resident customer, with no Luxembourg nexus. What the rule says: the firm is an Article 2 professional and an online provider in the CRF’s taxonomy; it files an STRe to the CRF, which disseminates to the German FIU under Article 53(1) of Directive (EU) 2015/849. What the practitioner does: files once, in goAML, and resists opening a parallel host-FIU channel. Outcome: one filing route for the whole passported book, scaling to new markets without new FIU integrations.
Scenario 2 — a refusal with nothing to report. Facts: an applicant presents a forged identity document at onboarding; the account is never opened and no payment moves. What the rule says: suspicion has crystallised and a declaration is due even though nothing was executed — but with no transaction to describe, the correct type is SARe, not STRe. What the practitioner does: wires the onboarding-rejection queue into the filing workflow so document-fraud rejections generate SARe drafts instead of dying in a KYC decision log. Outcome: the firm reports the exact pattern the CRF flagged as driving 2024 volume.
Scenario 3 — abstain versus execute. Facts: a customer instructs an outgoing transfer that trips a strong suspicion. What the rule says: Article 5(3) requires abstention in principle. What the practitioner does: where the transfer can be held without alerting the customer, the firm abstains and files, letting the CRF decide whether to block; where holding it is impossible — an instant credit transfer already settled — it files immediately after and documents why. Outcome: a defensible record either way, and no tipping-off in the customer message.
12. FAQ
Can I email or post a declaration to the CRF?
No. Reporting is entirely electronic through goAML. There is no paper or email intake, so a professional that is not enrolled in goAML cannot file at all — enrol before you need to.
My Luxembourg EMI is passported across the EU. Do I file with each host FIU?
No. As an online provider you submit declarations for all member states to the Luxembourg CRF, which shares them with the FIUs concerned under Article 53(1) of Directive (EU) 2015/849.
What is the difference between an STR and a SAR in Luxembourg?
An STR reports identified suspicious transactions; a SAR reports suspicion where none could be identified — an onboarding refusal, adverse media, misuse of legal structures. Online providers use the STRe/SARe equivalents.
Must I stop the transaction before filing?
In principle yes — Article 5(3) of the AML Law requires the professional to abstain from executing an operation it suspects of ML/TF links and inform the CRF. Where abstaining beforehand is impossible, the operation may proceed and the CRF is informed immediately afterwards.
Does the CRF ever come to me for information?
Yes. Article 5(1)(b) of the AML Law lets the CRF request information from professionals on its own initiative, independently of any report you filed. Confidentiality still binds, and the request is answered through goAML.
13. What to do, today
- Enrol in goAML and provision LuxTrust access for the RC and backups as a go-live gate — before authorisation completes, not after.
- Map your filing decision tree onto the six report types, and check that the no-transaction branch (SAR/SARe/TFAR) is reachable from your onboarding-rejection and adverse-media queues.
- If you are passported from Luxembourg, drop host-FIU integrations from the roadmap and document the Article 53(1) routing instead.
- Plan the manual-to-XML migration with the CRF as a dated project, not an eventual optimisation.
- Wire the Article 5(3) abstention decision into the payment-release flow, and make sure a flagged account can actually be held on short notice.
Related: TRACFIN — filing in France · FIU-Nederland — filing in the Netherlands · EMI licence in Luxembourg (CSSF) · Circular CSSF 26/906 — internal governance for LU payment institutions · The EU AML package — AMLR, AMLD6 and AMLA · How to issue Luxembourg IBANs · Tipping-off · AML data returns compared · The CSSF AML/CFT data collection · CSSF Regulation 12-02 — the Luxembourg AML rulebook · CRBA — Luxembourg’s central register of bank accounts · RBE — Luxembourg


