Filing a suspicious transaction report (SOS) in Italy
Italy’s suspicious transaction report is not a form you fill in when something looks odd. It is the output of a documented assessment, transmitted through one portal, in a structure the UIF defines down to the domain value — and it must carry no trace of who inside your firm wrote it. This piece sets out the duty under Article 35 of Legislative Decree 231/2007, the Infostat-UIF enrolment that has to happen long before the first report, the two ways to submit, what the four sections of a SOS actually contain, and how the UIF answers.
1. The reporting duty
Article 35 of Legislative Decree 231 of 21 November 2007 requires a wide population of soggetti obbligati — banking and financial intermediaries, other financial operators, professionals, non-financial operators, gaming service providers and market infrastructures, listed at Article 3 — to inform the UIF of operations where they know, suspect or have reasonable grounds to suspect that money laundering or terrorist financing is being carried out, has been carried out or has been attempted, or that the funds, regardless of amount, derive from criminal activity.
Three features of the Italian formulation shape how a monitoring function has to be built.
- No threshold. The words “regardless of amount” are in the statute. A rule set that only escalates above a value has already narrowed the duty.
- Attempts count. Attempted operations are inside the duty, not only executed ones.
- Fragmentation is a named trigger. Suspicion may be inferred from the characteristics, size and nature of operations, from their linkage or fragmentation, or from any other circumstance known to the reporter, taking into account the economic capacity or activity of the persons concerned.
The suspicion must rest on a complete assessment of all the elements of the operations available to the reporter — objective and subjective alike. To help identify them, the decree provides two published toolkits: the models and schemes representing anomalous behaviour issued by the UIF under Article 6(7)(b), and the anomaly indicators issued and updated by the UIF under Article 6(4)(e) after presentation to the Financial Security Committee.
For credit and financial institutions the perimeter is wider still: the directly applicable EU sanctions regulations for Iran and North Korea, with the Banca d’Italia measure of 27 May 2009, extend the duty to suspected financing of weapons-of-mass-destruction proliferation programmes.
2. Timing
Article 35(1) requires the report to be made without delay. Article 35(2) adds that it should be made, where possible, before carrying out the operation.
The two limbs are not the same test. “Without delay” runs from the moment the assessment concludes in suspicion, not from the moment an alert fired — but a queue that lets alerts age converts a defensible analysis window into an indefensible delay. “Where possible, before executing” is a best-efforts obligation on sequencing, which means something only if the path from analyst conclusion to filed report is short enough to beat settlement.
Article 35(4) provides the protection that makes this workable: reports made in good faith and for the purposes envisaged do not breach any contractual, legislative, regulatory or administrative restriction on disclosing information, and give rise to no liability.
3. Registration — long before you need it
Transmission is exclusively telematic, through the Banca d’Italia’s dedicated Infostat-UIF portal. Before anything can be sent, the reporter must be entered in the UIF’s anagrafe dei segnalanti — the register of reporting entities — and enabled for the relevant surveys.
The entity designates two roles: an Amministratore, responsible for registration and keeping the entity’s data current, and a Referente, responsible for evaluating and transmitting reports. For a sole proprietorship the roles coincide; for a legal person they are distinct functions. The Administrator enrols the entity through the partner registry application, sends the resulting receipt to the UIF by certified email, then requests authorisation for the surveys needed. Credentials are strictly personal, and access requires a one-time password sent to the registered mobile number.
4. What a SOS contains
The content of a suspicious transaction report is defined by the UIF itself under Article 6(4)(d), through its Istruzioni per la rilevazione e la segnalazione delle operazioni sospette, most recently issued by the measure of 18 December 2025. Detailed operational guidance sits in the user manual and operating guide made available to reporters inside the Infostat-UIF portal.
The report is organised in four sections:
| Section | What goes in it |
|---|---|
| Identifying data | Information classifying the report and identifying its recipient |
| Structured elements | Operations, subjects, accounts and relationships, and the links between them — plus structured information on any measures taken, linked reports, and the phenomena detected |
| Free-text description | The activity reported and the reasons for the suspicion |
| Attachments | Optional, and where included must be strictly functional to making the elements of suspicion clear |
The effort splits the opposite way from what teams expect. The structured sections are largely mechanical if the data model is right; the free-text section is where the report succeeds or fails, because it is the only place the reasoning appears. The attachment rule is a real constraint — a general document dump is not neutral, it dilutes the elements of suspicion.
5. The two submission methods
Compilation and transmission happen either through the data entry available on the Infostat-UIF portal, or by uploading files produced with the reporter’s own applications, built to the standards prescribed in annexes 3a and 3b of the UIF measure of 4 May 2011. The UIF additionally publishes documentation on automatic loading of reports from CSV files, and a workbook of the permitted domain values.
The choice is a volume question with a quality dimension. Data entry is fine at low volume and forces the reporter through the field structure. Programmatic upload is the only sustainable route at volume, but it moves correctness upstream: the domain-value workbook and the annex standards become part of the build specification, and the UIF periodically publishes new domain values and controls to be picked up.
The content is then subject to two levels of automatic control: a diagnostic available on the portal, run by the reporter before sending, and the UIF’s own systems on acquisition. The UIF is explicit that these controls are designed to ensure the integrity and compatibility of the information supplied — and that they cannot guarantee the completeness of the report. A SOS that passes both control layers can still be substantively inadequate, and nothing in the channel will say so.
6. The anonymity rules
Italian law protects the individual who files, and the protection imposes drafting obligations rather than merely granting rights.
- Obliged entities, and the professional bodies that receive reports from their members, must adopt measures ensuring the maximum confidentiality of the identity of the persons making the report (Article 38(1) and (2)).
- The report as transmitted must be free of any reference to the name of the natural person reporting (Article 36(6); Article 37(2) and (3)).
- Investigative bodies must omit the identity of the natural persons and obliged entities that sent a report from any denunciation transmitted to the judicial authority (Article 38(4)).
- The judicial authority may obtain the reporter’s identity only by reasoned decree, where it considers it indispensable for establishing the offences being prosecuted (Article 38(3)).
The consequence sits in the free-text section and the attachments: internal case notes, alert screenshots and email chains routinely carry analyst names, and pasting them into a SOS breaches the rule.
7. What happens next
The UIF performs financial analysis of the reports it receives under Article 40(1)(a), drawing on its own studies, inspection findings and archives. It may request further information from the reporting entity, from other obliged entities and from public administrations, and exchange information with foreign FIUs.
Distribution is prescribed. The UIF transmits data on reports received to the National Anti-Mafia and Counter-Terrorism Directorate for checking against ongoing proceedings (Article 40(1)(c)); it transmits without delay to the Anti-Mafia Investigation Directorate and the Guardia di Finanza’s Special Currency Police Unit those reports presenting ML or TF risks, with its analysis (Article 40(1)(d)); and it retains evidence of reports not transmitted for ten years, consultable by investigative bodies (Article 40(1)(f)).
Reporters are not left in silence. Under Article 41(2) the UIF communicates outcomes back through a flusso di ritorno — a return flow sent periodically by certified email. It is the only structured signal a firm gets about whether its reports are useful, and it arrives at a PEC address somebody has to be reading.
8. Three scenarios
Scenario 1 — the passporting firm with no portal access. An EU payment institution begins serving Italian customers and its monitoring team produces its first Italian suspicion in month two. Facts to rule: transmission is exclusively telematic through Infostat-UIF, and requires prior entry in the anagrafe dei segnalanti with an Administrator and a Referente, PEC correspondence and per-survey authorisation. What the MLRO does: start enrolment at market entry, name a Referente and a deputy, and confirm the PEC address is monitored. The failure mode is a completed analysis and no lawful way to transmit it.
Scenario 2 — the threshold that was not in the law. A firm’s escalation rules route only transactions above a value to the SOS queue, on the reasoning that small amounts are immaterial. Facts to rule: Article 35 catches funds deriving from criminal activity regardless of amount, expressly covers attempted operations, and names fragmentation as a basis for suspicion. What the compliance officer does: remove the value floor, add attempted and declined operations to the reviewable population, and add an aggregation view so fragmentation is visible rather than filtered out. The failure mode is a smurfing pattern invisible precisely because each leg is small.
Scenario 3 — the report that named the analyst. A team pastes its internal investigation note into the free-text section and attaches the alert export, both of which carry the analyst’s name in headers and footers. Facts to rule: the report must be free of any reference to the name of the natural person reporting, and attachments must be strictly functional to clarifying the suspicion. What the team does: draft the free-text narrative as a purpose-written account rather than a copy of the case file, and scrub or re-export attachments. The failure mode is a confidentiality protection the firm has waived on its own behalf.
9. FAQ
Is there a monetary threshold for a SOS?
No. Article 35 of Legislative Decree 231/2007 covers funds deriving from criminal activity regardless of amount, and extends to operations that were attempted as well as carried out. Threshold-driven filings are a separate obligation — the comunicazioni oggettive.
Can a SOS be filed on paper or by email?
No. Transmission is exclusively telematic through the Infostat-UIF portal, after registration in the UIF’s register of reporting entities and authorisation for the relevant survey.
Must we key the report, or can we upload it?
Either. Reports can be compiled through the portal’s data entry, or uploaded as files produced with the reporter’s own applications following the standards in annexes 3a and 3b of the UIF measure of 4 May 2011. The UIF also publishes documentation on automatic loading from CSV and a workbook of permitted domain values.
Does passing the diagnostic mean the report is adequate?
No. The UIF states that the two levels of automatic control ensure the integrity and compatibility of the information supplied but cannot guarantee the completeness of the report. Substantive quality is assured by internal review, not by the portal.
Do we learn what happened to a report?
Partly. Under Article 41(2) the UIF sends outcomes back to the reporting entity through a periodic return flow delivered by certified email, informed also by feedback from the investigative bodies.
10. What to do, today
- Start Infostat-UIF enrolment at market entry — Administrator, Referente, a deputy, and a PEC address somebody monitors.
- Remove any monetary floor from the SOS escalation path, and bring attempted and declined operations into the reviewable population.
- Build an aggregation view so fragmentation is visible; the statute names it as a basis for suspicion.
- Map the UIF anomaly indicators and behavioural schemes to your own scenarios, and re-map when the UIF updates them.
- Write the narrative as a purpose-built account, not a paste of the case file — and scrub analyst names from attachments.
- If you will file at volume, treat the domain-value workbook and the annex standards as a build specification, with a watch on new domain values and controls.
- Put the PEC return flow into a monitored process and feed its findings back into scenario tuning.
Related: UIF anomaly indicators and red-flag schemes · INFOSTAT — the Banca d’Italia reporting channel · The Italian AML framework beyond the UIF · Comunicazioni oggettive · SARA aggregate AML reporting


