goAML Luxembourg: The CRF Reporting Workflow Explained

goAML is Luxembourg’s electronic channel for suspicious-operation reporting and communication with the CRF; for lawyers, the platform integrates the Article 7 Bâtonnier filter before qualifying reports are forwarded to the CRF. In 2024 the CRF received significantly more suspicious reports than the prior year, according to its 2024 annual report. That same report covers the CRF’s use of blocking orders and the predicate breakdown of reports received. The legal trigger for each of those reports sits in Article 5 of the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing: a professional that knows, suspects or has reasonable grounds to suspect money laundering, an associated predicate offence or terrorist financing must inform the CRF, on its own initiative and without delay.

The duty that catches reporting teams is what Article 5 attaches to that filing. The same article requires the professional to refrain from executing the transaction until it has informed the CRF and complied with any instruction the CRF issues, forbids it from telling the customer, and obliges it to answer the CRF’s follow-up questions. A goAML filing in Luxembourg therefore has a before and an after. The upload sits in the middle of that workflow.

For filing entities the sequence runs in a fixed order: enrol on goAML, select the correct report type, assemble a report the CRF can act on, then manage the obligations that survive the upload. Each step carries its own trap, and the traps cluster after the upload, once the detection work is done.

Related reading: our guide to STR obligations and reporting triggers in Luxembourg.

The clocks that run on a goAML file

Suspicious-transaction reporting in Luxembourg is governed by a standard of promptness. There is no single fixed filing deadline, but several concrete time limits do run. Keeping them visible is the difference between a clean file and a procedural breach.

  • Filing an STR: without delay and on the professional’s own initiative, as soon as knowledge, suspicion or reasonable grounds to suspect arise (Article 5(1)(a)).
  • Refraining from execution: until the CRF has been informed and any specific instruction has been complied with (Article 5(3)). Where refraining is impossible or would frustrate efforts to pursue the beneficiaries, the professional informs the CRF immediately afterwards.
  • Oral CRF instruction: it must be confirmed in writing within three business days, otherwise its effects cease at midnight on the third business day (Article 5(3)).
  • Scope of what must be reported: all suspicious transactions, including attempted transactions, regardless of amount and without the reporter having to qualify the predicate offence (Article 5(1), as amended by the Law of 10 August 2018).
  • Five-year lookback readiness: systems must be able to answer, rapidly and fully, whether the entity has or has had a business relationship with a given person over the preceding five years (Article 4(3)).
  • Annual compliance reporting for professionals within CSSF Regulation No 12-02: the person responsible for compliance submits the compliance officer’s annual summary report to the CSSF within five months after the financial year-end. Article 42(7) does not apply to a Luxembourg investment fund that has designated a Luxembourg management company which submits that annual report.

Luxembourg’s financial intelligence unit: the CRF and the goAML portal

The CRF is Luxembourg’s sole financial intelligence unit. It receives suspicious reports, analyses them, and disseminates intelligence to the public prosecutor and other competent authorities. It is operationally separate from the prudential supervisor: the CSSF authorises and supervises banks, investment firms, funds and their managers and sets AML/CFT organisational rules, while the CRF is the recipient of the reports those obligations produce. Sending an STR to the CRF does not discharge any CSSF reporting or notification, and a CSSF filing is never a substitute for a report to the CRF.

goAML itself is the reporting application developed by the United Nations Office on Drugs and Crime for financial intelligence units, adopted by the CRF as the single channel for suspicious reporting. The current entry point is the CRF’s own site at crf.lu, which routes reporters into the goAML environment. The older justice ministry page describing the reporting process now points professionals to that new site and to a training environment where staff can rehearse a submission before filing anything real.

The legal architecture behind the portal has three layers a reporting officer should be able to name. The Law of 12 November 2004 sets the reporting duty and the cooperation obligations in Article 5. CSSF Regulation No 12-02 of 14 December 2012 sets the internal organisation that produces a report, including the governance roles. The CRF’s current suspicious-operations reporting guideline, which governs the filing workflow, and its separate guideline on freezing suspicious transactions remain applicable from 1 April 2021. A defensible filing should use the current version of each.

Getting onto goAML: enrolment and the person who files

Access to goAML is not automatic on the day a firm is licensed. The entity registers as a reporting organisation, nominates the individuals who will act inside the system, and authenticates through LuxTrust, the national electronic identity and signature provider. Registration is validated by the CRF before the entity can transmit a live report, which is one reason enrolment belongs in a firm’s onboarding of its own AML function, well before the panic of a first suspicion.

Article 5(2) of the Law says the communication to the CRF is normally carried out by the person or persons the professional has designated under its internal procedures. In practice that person is the AML function. CSSF Regulation No 12-02 splits the function into two named roles that reporting teams should not blur. The person responsible for compliance with the professional obligations, the responsable du respect des obligations, is a member of the authorised management or the board who carries ultimate responsibility. The compliance officer in charge of the control of compliance, the responsable du contrôle, is the operational officer who runs the day-to-day AML programme. My reading of the split is that it exists precisely so that the decision to file and the act of filing are traceable to identifiable people, which matters when the CRF or an auditor later reconstructs a case.

Confidentiality of the filer is protected. Article 5(1) provides that the identity of the professionals, directors and employees who supplied information is kept confidential by the authorities, unless disclosure is indispensable to the regularity of legal proceedings. That protection is a reason to keep the internal escalation trail tight and documented.

STR, SAR and the difference filers keep getting wrong

goAML supports more than one report object, and choosing the correct type matters for CRF analysis. A suspicious transaction report, the déclaration d’opération suspecte, is anchored to one or more transactions. A suspicious activity report (SAR) is a report that does not contain suspicious transactions; an STR contains suspicious transactions. An attempted suspicious transaction is still a suspicious transaction for Article 5 purposes and must be reported as such, rather than treated as an SAR merely because it was not completed. The CRF publishes separate goAML material for suspicious-activity reporting and for the financial sector, which signals that it expects reporters to distinguish the two, and to resist forcing every concern into a transaction report.

The distinction is not cosmetic. An attempted transaction that a firm declined still has to be reported, because Article 5 covers attempts explicitly and removes any amount threshold. A firm that files nothing because the money never moved has misread the obligation. Equally, dressing up a pure behavioural concern as a transaction report, with a transaction invented to fit the form, produces an analysis file the CRF cannot use. The report type follows the suspicion, and the suspicion is sometimes about the actor rather than a payment.

What a usable report contains

Article 5(1)(a) requires the report to be accompanied by all the information and documents that prompted it. That is the operative content standard, and it is more demanding than a tick-box. If the CRF requires further material, Article 5(1)(b) allows it to request information and supporting documents without delay. Filing an STR or SAR does not, by itself, impose a CRF freezing order; a blocking instruction is a separate step under Article 5(3).

Two content rules trip up newer reporters. First, the obligation applies regardless of whether the reporter can determine the predicate offence. A firm does not need to conclude that the funds derive from fraud, tax crime or trafficking before it files; reasonable grounds to suspect are enough, and second-guessing the predicate is a way of talking yourself out of a report you should send. Second, terrorist financing has its own limb. Article 5(1a) extends the reporting duty to funds there are reasonable grounds to suspect are linked to terrorism, terrorist acts or those who finance it, which is a suspicion tied to where funds are going and why, even where their origin looks clean.

Luxembourg made tax offences a live predicate for money laundering, and the CRF issued a dedicated guideline on primary tax offences that has applied since 1 April 2017. For a fund administrator or a private bank, that means a structuring pattern is reportable where it gives rise to knowledge, suspicion or reasonable grounds to suspect money laundering involving a criminal tax offence, applying the same Article 5 threshold as other suspected predicate offences, a point that connects to the CRF’s handling of fraud-related signalements.

After you file: the CRF can tell you to stop

This is the part of the workflow that distinguishes Luxembourg practice from a jurisdiction where reporting and execution run on separate tracks. Article 5(3) requires the professional to refrain from carrying out a transaction it knows, suspects or has reasonable grounds to suspect is linked to money laundering or terrorist financing until it has informed the CRF and complied with any specific instruction. The CRF may instruct the professional not to carry out the operations relating to the transaction or the customer. In effect, the filing can convert into a blocking order.

The mechanics have hard edges worth memorising. Where an instruction is given orally, it must be confirmed in writing within three business days, and if the written confirmation does not arrive, the instruction lapses at midnight on the third business day. The professional may not tell the customer about the instruction without the CRF’s express prior consent. The CRF can lift the order, in whole or in part, at any time and on its own motion. And under Article 5(3a), the duty to refrain from executing and the duty to provide information on request both apply even where the professional has not filed an STR, so a firm cannot escape a freeze simply by staying silent.

The CRF’s guideline on the freezing of suspicious transactions, in force since 1 April 2021, is the operational reference for how these instructions are handled. The CRF’s use of blocking orders to preserve assets is the reason the after-filing steps deserve a rehearsed internal procedure worked out in advance.

Challenging an instruction, and the limits of that right

A blocking instruction is not the end of the conversation. The Law provides a route to contest an instruction of the CRF before the courts, which sits in the title of the Law dealing with appeals against the CRF’s instruction. The practical reading is that a firm faced with an instruction it believes is disproportionate or mistaken has a legal channel open to it. What a firm cannot do is treat its own disagreement as authority to release funds; the instruction stands until it is lifted by the CRF or set aside through the proper route.

This is also where the confidentiality rule bites hardest. Because the professional cannot disclose the instruction to the customer without the CRF’s consent, the firm has to manage the customer relationship, including questions about delayed payments, without revealing why. Relationship managers who are outside the AML function need a script that neither lies nor tips off, and that script should be agreed before it is needed.

The tipping-off wall, and what it does not forbid

Article 5(5) prohibits professionals, their directors and their employees from disclosing to the customer or to third parties that information is being, will be or has been reported to the authorities, or that a CRF investigation is underway or possible. The prohibition is broad and it is the source of most anxiety on a reporting desk, so its carve-outs are worth stating precisely, because reporters often over-apply it.

Article 5(5) permits disclosure to supervisory authorities and, where appropriate, self-regulatory bodies. It also contains defined intra-group and same-person/same-transaction exceptions subject to the statutory conditions; the network exception applies only to the professionals referred to in Article 2(1)(8), (9), (11), (12) and (13). The same limited group of professionals benefits from the rule that seeking to dissuade a customer from illegal activity is not tipping-off. Separately, Article 5(6) requires information on suspicions reported to the FIU to be shared within the group unless the FIU instructs otherwise.

Safe harbour for good-faith reporting

A recurring fear inside reporting teams is civil or contractual liability for filing, or for filing on thin grounds. The Law addresses this directly. Article 5(4) provides that a good-faith disclosure to the competent Luxembourg authorities does not breach any contractual, professional-secrecy or legislative restriction on disclosure, and does not give rise to liability of any kind, even where the professional was not precisely aware of the predicate offence and regardless of whether illegal activity actually occurred. Article 5(4a) adds that reports and documents supplied under the reporting duty cannot be used against the professional in proceedings brought under Article 9 of the Law.

The same provision protects the people who report. Employees and representatives may not be threatened, retaliated against or subjected to discriminatory employment action for having reported a suspicion to the CRF, any contrary contractual clause or dismissal is null and void, and a dismissed employee can invoke the remedies in the Labour Code. Read together, these clauses mean the honest borderline call is the protected call. The exposure runs the other way, toward the firm that suspected and did not file.

Feedback, requests for information, and why silence is not a green light

A goAML filing does not itself determine whether a business relationship must be terminated or may continue. For professionals subject to CSSF Regulation No 12-02, Article 48(3) requires a reported relationship to be monitored with enhanced due diligence and, where appropriate, in line with FIU instructions. Where a CRF freezing order is withdrawn, the CRF’s freezing guideline states that no legislative provision requires termination of the relationship.

What the CRF does send is requests. Under Article 5(1)(b) the professional must provide, without delay and on request, any information the CRF asks for, including the documents on which the information is based. The CRF’s current guideline requires responses to information requests to be submitted through the goAML platform. A firm that cannot produce those records quickly has an internal problem that predates the request, which is why the five-year retrieval readiness in Article 4(3) and the record-keeping discipline behind it are part of the same workflow. Responding to the CRF is a continuation of the filing obligation.

Special routes: lawyers and self-hosted crypto transfers

Lawyers have a specific Article 7 reporting route through the President of the relevant Ordre des avocats; crypto-asset service providers use the ordinary Article 5 reporting framework but also have a separate self-hosted-address risk duty. Under Article 7(1), lawyers are exempt from Article 5(1) and (1a) for information received or obtained while providing legal advice or ascertaining a client’s legal position, or while defending or representing that client in judicial proceedings and related advice. Where the reporting duty applies, Article 7(2) routes the information through the President of the relevant Ordre des avocats, and the Bar confirms that goAML integrates that Bâtonnier filter. A firm that is not a law practice should not assume this indirect channel applies to it.

Crypto-asset service providers picked up a specific obligation more recently. Following the Law of 6 February 2025, Article 7-1a requires providers to identify and assess the money-laundering and terrorist-financing risk of crypto-asset transfers to or from a self-hosted address, and to apply proportionate mitigating measures. That risk adds to the ordinary Article 5 reporting duty, which continues to apply, and it connects the goAML workflow to the wider shift toward the EU AML single rulebook and its harmonised obligations.

Where goAML filings actually fail

The recurring failure modes are procedural ones, and they are worth naming as an auditor would. A firm files the transaction report but forgets that Article 5(3) required it to refrain from executing, so the money leaves before the CRF is informed. A relationship manager, outside the AML function and unbriefed, reassures a customer in a way that breaches Article 5(5). An oral instruction is received and acted on, but the three-business-day written confirmation is never chased, leaving the firm unsure whether the block still stands. Enrolment on goAML is left until a first suspicion arises, and the validation delay collides with the without-delay standard. Each of these is avoidable with a written procedure and a rehearsed handoff between the AML function and the front office.

The CSSF tests this in supervision and has issued administrative sanctions for AML/CFT shortcomings (see CSSF enforcement decisions), and the annual CSSF AML/CFT data collection gives it a quantitative view of each entity’s reporting behaviour. A firm whose STR volume looks anomalous against its risk profile invites questions, which is another reason the whole workflow, from enrolment through to the CRF’s follow-up, is what a supervised entity should be able to defend.

Frequently Asked Questions

Does an STR to the CRF discharge any obligation toward the CSSF?

No. The CRF and the CSSF are different authorities with different roles. A report to the CRF satisfies the Article 5 cooperation duty toward the financial intelligence unit; it does not replace any CSSF notification, periodic AML/CFT data submission or prudential reporting the entity owes separately. Firms that treat the two as interchangeable end up short on one side.

If we declined a transaction and no money moved, is there anything to report?

Yes, if suspicion arose. Article 5 expressly covers attempted suspicious transactions and applies regardless of amount. If the declined or aborted transaction is the suspicious transaction, it belongs in an STR; use an SAR where the report does not contain a suspicious transaction. Declining the business does not replace the filing.

The CRF gave us an instruction by phone. When can we act on it, and how long does it last?

An oral instruction takes effect immediately but must be confirmed in writing within three business days. If no written confirmation arrives, the instruction’s effects cease at midnight on the third business day. Keep a contemporaneous note of the oral instruction and chase the written confirmation so you know whether the block still stands.

Can we tell a long-standing client why a payment is held?

Not without the CRF’s express prior consent. Article 5(3) forbids disclosing the instruction to the customer without that consent, and Article 5(5) separately prohibits revealing that a report has been or may be made. You can manage the relationship and decline to execute, but you cannot explain the regulatory reason.

Are we exposed if the suspicion turns out to be unfounded?

A good-faith report does not create liability, even where no illegal activity actually occurred and even where the reporter was not aware of the precise predicate offence. Article 5(4) provides that protection, and Article 5(4a) prevents the report from being used against the professional in Article 9 proceedings. The unfiled suspicion carries the greater risk.

We are a management company relying on delegates. Who files?

The reporting duty attaches to the obliged entity, and Article 5(2) says the designated person under the entity’s internal procedures transmits the report. Delegation of AML tasks does not move the legal obligation off the entity, so the arrangement has to make clear who holds goAML access and who decides to file, with the person responsible for compliance retaining ultimate responsibility under CSSF Regulation No 12-02.

How much detail does the CRF expect in the first report?

Article 5(1)(a) requires the report to be accompanied by all the information and documents that prompted it, so the first submission should carry the transaction detail, customer identification and the narrative reasoning behind the suspicion. If the CRF requires further material, it may request it under Article 5(1)(b); the initial submission should therefore include all supporting information and documents that prompted the report.

Key Takeaways

  • The reporting trigger is Article 5 of the Law of 12 November 2004: know, suspect or have reasonable grounds to suspect, then inform the CRF on your own initiative and without delay.
  • Enrol on goAML through LuxTrust before a first suspicion arises; CRF validation of the registration takes time the without-delay standard does not give you.
  • Report attempts and any amount, and do not wait until you can name the predicate offence; Article 5 removes both the threshold and the predicate-qualification requirement.
  • Refrain from executing until the CRF is informed and any instruction is met; an oral instruction lapses at midnight on the third business day if no written confirmation arrives.
  • Do not disclose that a report has been or may be made, or that an FIU investigation is or may be underway; separately, a CRF instruction may be disclosed to the customer only with the FIU’s express prior consent.
  • Article 5(4) protects good-faith disclosures from liability arising from the disclosure, while Article 5(4a) provides that reports, information and documents supplied under Article 5(1) and (1a) cannot be used against the professional in proceedings based on Article 9.
  • Answering the CRF’s Article 5(1)(b) requests for additional information is part of the filing obligation, and depends on five-year record-retrieval readiness under Article 4(3).
  • Lawyers report through the Bâtonnier under Article 7, and crypto-asset providers carry a separate self-hosted-transfer risk duty under Article 7-1a; check the routing before you file.

Sources and References

Filing is a workflow you can rehearse

The single most useful thing a Luxembourg obliged entity can do about goAML is to stop treating the upload as the event. The workflow is the sequence: enrol and validate access ahead of need, decide and record who inside the firm files, choose the correct report type, submit the supporting information and documents that prompted the suspicion, comply with Article 5(3) and any CRF instruction, preserve confidentiality, and continue any enhanced monitoring and follow-up required under the rules applicable to the professional. Write that sequence down, rehearse the front-office handoff, and confirm your team can retrieve five years of records on request. The next real suspicion will arrive without warning, and the after-filing steps are the ones that will be judged.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • DAC7 Reporting for Luxembourg Platform Operators: Who Reports, What Data, and When

    Updated July 2026In this guideWho Qualifies as a Reporting Platform OperatorReportable ActivitiesReportable Sellers and the Exclusion ThresholdsDue Diligence ProceduresWhat to ReportFiling with the ACD: Registration and Annual DeclarationPenalties for Non-ComplianceFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesIf you operate a digital platform in Luxembourg and have not yet registered with the Administration des Contributions Directes, you…

  • FINTRAC Foreign Branch Rules: Canada’s Extraterritorial AML Reach

    A Canadian bank with a branch in Singapore falls within section 9.7; a life insurance company’s foreign subsidiary is covered only if it carries out similar activities and is wholly owned or consolidated with the company; and a securities dealer’s affiliated London entity can trigger section 9.8 if the statutory affiliation test is met. Canada’s…

  • AML Reporting in Luxembourg: STRs, GoAML, and Your Obligations

    Updated July 2026In this guideIntroductionThe Legal Basis for AML Reporting in LuxembourgWho Must Report? Obliged Entities and ScopeSuspicious Transaction Reports: What Triggers Reporting?Filing Suspicious Transaction Reports: The ProcessOther AML Reporting Obligations Beyond STRsThe CRF: Luxembourg’s Financial Intelligence UnitHow AML Reporting Works in PracticeCommon AML Reporting MistakesRecent Developments: AMLA, the AMLR, and the Single RulebookComing Soon:…

  • FINMA Iran Sanctions Update: The 18 August Freeze List

    FINMA’s updated Iran sanctions notification of 18 August 2026 marks a precise moment on the clock. At 23:00 that evening, an amendment to Annexes 12, 13 and 14 of the Ordinance of 12 December 2025 on measures against the Islamic Republic of Iran (SR 946.231.143.6) took effect. The Federal Department of Economic Affairs, Education and…

  • MMF Weekly Liquid Assets: What the CSSF Consultation Means for Luxembourg Managers

    Updated July 2026In this guideWhat the CSSF published on 8 June 2026The statutory MMF weekly liquid assets minimums the guidance leaves untouchedThe notification trigger most managers will need to wire inWhat the resilience levels do not meanHow this connects to stress testing under Article 28What Luxembourg managers should review before 3 August 2026Frequently Asked QuestionsRelated…