Industry

There is no seven-day STR deadline. It was amended out of the Act.

Ask a compliance team in Pakistan how long they have to file a Suspicious Transaction Report and a good number will say seven working days. It is an understandable answer. It was also true, once.

The current text of section 7(1) of the Anti-Money Laundering Act, 2010 ends with a short proviso:

“Provided that STR shall be filed by the reporting entity with the FMU promptly.”

The footnote attached to that word is the interesting part. It records that the words “immediately, but not later than seven working days after forming that suspicion” were substituted — removed by amendment, gazetted under notification F.22(8)/2019-Legis.

So the deadline people remember is not merely being missed. It was taken out of the Act, and what replaced it is harder.

Where the seven days went

They did not disappear entirely, which is why the confusion persists. Section 7(3) of the same Act still says:

“All CTRs shall, to the extent and in the manner prescribed by the FMU, be filed by the reporting entities with the FMU immediately, but not later than seven working days, after the respective currency transaction.”

Currency Transaction Reports keep the seven working days. Suspicious Transaction Reports do not. One sentence in the same section carries a number and the other does not, and a team that learned the rule as “seven working days for reporting” has no particular reason to notice which one it attached to.

FMU’s own guidance leaves no room for the older reading. Its FAQ on STRs puts it directly: reporting entities “are required to promptly report a STR i.e. without any delay”, and “when the suspicion is formed by the reporting entity after analysis of the related transactions or activities, the STR should be filed immediately to FMU”.

Why “promptly” is harder than a date

A deadline is a generous thing to be given. It is unambiguous, it is the same for everybody, and it can be proved with a timestamp. “Promptly” has none of those properties, and three consequences follow.

The clock starts at an event only you can see. Seven working days ran from forming suspicion; so does “promptly”, but without an outer bound the only question that matters is when suspicion was formed and what happened next. That is an internal moment — an analyst reaching a conclusion — and if your process cannot date it, you cannot evidence anything about the interval that followed.

The standard is relative, not absolute. Four days is prompt if the case needed four days of analysis and the record shows it moving. Four days is not prompt if the file sat in a queue for three of them. The same elapsed time is either fine or not depending on evidence you either kept or did not.

Speed now argues with accuracy. Once a report is accepted on goAML there is no self-service way to correct it. FMU’s guidance is explicit that reporting entities should “authenticate and verify the information prior to submitting the report”, and that amending an accepted report means approaching FMU in writing, preferably through the goAML Message Board. You are being asked to file immediately and to get it right first time, and those two instructions pull against each other every time a case is marginal.

What this actually asks you to build

If the obligation is an interval rather than a date, the deliverable is a record of that interval. In practice that means four things, none of which are exotic.

A dated suspicion event. Whatever triggers review — an alert, an analyst’s judgement, adverse media — needs a timestamp at the moment the institution decides suspicion exists, distinct from when the underlying transaction happened and from when the report was filed. Without that field there is no interval to report on.

A trail between the two ends. Alert raised, assigned, reviewed, escalated, decided, submitted, acknowledged. Not for its own sake: it is the only way to show that four days was analysis rather than backlog.

Acknowledgements captured, not just received. FMU returns a system-generated acknowledgement through the goAML Message Board against every report, and notifies the registered users by email. An acknowledgement sitting in one person’s inbox is not an institutional record. It belongs against the case.

A rejection loop that closes. Rejected reports can be reverted and resubmitted through the web form, or corrected and resubmitted where the report was filed as XML. Either way the clock has not stopped. The rejection reason, the correction and the resubmission all belong in the same trail as the original.

Three things worth checking while you are here

The same FMU guidance settles a few questions that come up repeatedly, and getting them wrong is more common than getting the timeframe wrong.

There is no threshold. STRs are filed against suspicious transactions or activity, executed or attempted, irrespective of amount. A rule that suppresses reports below a figure is not a risk appetite; it is a gap.

There is no minimum number of transactions. A report can carry many related transactions, and an activity-based STR can carry none at all.

When suspicion is mixed, file the STR-F. goAML takes activity-based reports (STR-A) and transaction-based reports (STR-F). Where a case raises both, FMU’s guidance is that STR-F is the one to use.

What it costs to get wrong

Section 33 makes wilful failure to comply with the STR reporting requirement punishable by up to five years’ imprisonment, a fine up to PKR 500,000, or both, with the relevant regulator able to revoke a licence or registration on top. Section 34 attaches the same five years, and a fine up to PKR 2,000,000, to unauthorised disclosure of STR data.

Set against that, section 12 is worth reading too: no civil, criminal or disciplinary proceedings lie against a reporting entity or its officers for filing. The asymmetry is deliberate. The Act protects you for reporting and penalises you for not reporting, which tells you which error it expects institutions to make.

The part worth saying plainly

Nothing above requires new software to understand. But the obligation moved from something a calendar can satisfy to something only a record can, and a process built around “we have a week” will not produce that record — not because anyone is careless, but because it was never asked to.

If your STR process cannot currently answer “when was suspicion formed, and what happened between then and submission” for a case picked at random from last quarter, that is the gap. It is worth finding before someone else asks the question.

We have written separately about the second phase of STR-F automation, which moves inter-bank transactions to goAML XML and has no announced date yet.

This is a description of published requirements, not legal advice. The Anti-Money Laundering Act, 2010 and FMU’s guidance are the authority; both are public, and worth reading rather than relying on a summary.

Building something that has to hold up?

Bring the process, not a specification. We will tell you honestly whether an agent is the right answer.