← All articlesAll firms15 July 2026 · 6 min read

How to file an STR in Ireland: goAML and Revenue ROS dual reporting, step by step

A practical walkthrough of Ireland’s dual STR reporting: registering and filing with FIU Ireland via goAML and with Revenue via ROS, and what the AMLR changes.

Something about a transaction does not sit right. A client is evasive about the source of funds, or a payment arrives from an unexpected third party. As a designated person under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, your firm now has to file a Suspicious Transaction Report (STR) — and in Ireland, that means filing it twice.

Dual reporting catches out a lot of firms. An Irish STR goes to two separate bodies: FIU Ireland (within An Garda Síochána) and the Revenue Commissioners. Filing with one and not the other leaves your obligation only half discharged. And with Regulation (EU) 2024/1624 (AMLR) applying from 10 July 2027, reporting expectations are about to get sharper, not softer. Here is the process, step by step.

Why Ireland has two filings, not one

Irish law requires suspicious transaction reports to be made both to FIU Ireland and to the Revenue Commissioners. In practice:

  • FIU Ireland receives STRs electronically through the goAML portal, accessed via fiu-ireland.ie.
  • Revenue receives the same report through ROS, the Revenue Online Service, as an XML upload — and the XML file generated by goAML is accepted, so you do not have to re-key the report from scratch. Revenue's STR guidance is on revenue.ie.

One suspicion, one report, two submissions. Your file is not complete until both have gone in.

One point worth being clear on: Ireland has no threshold transaction reporting regime. There is no routine obligation to report every transaction above a set amount to the FIU. Reporting is suspicion-based — what triggers an STR is your assessment, not the size of the transaction on its own.

Before you ever need to file: register on both systems

The worst time to discover you are not registered is the day you have a live suspicion. Registration is a set-up task, and it needs doing on both systems:

  1. goAML registration. Your firm — normally through its MLRO — registers with FIU Ireland on the goAML portal at fiu-ireland.ie. Until this is done, you cannot submit to the FIU electronically.
  2. ROS registration for STRs. Your firm must also be set up on ROS to submit STRs to Revenue. Many practices already use ROS for tax filings, but STR submission is a separate matter to confirm — check the guidance on revenue.ie.

Treat both registrations as part of onboarding a new MLRO, and check them at each annual compliance review. Access tied to someone who has left the firm is a common, entirely avoidable failure.

Step 1: from internal concern to a reporting decision

An STR starts inside your firm, not on a portal. Whoever spots the red flag — a fee earner, a negotiator, a bookkeeper — should escalate it internally to your MLRO or compliance officer, who assesses whether the threshold of suspicion is met and decides whether to report.

Keep an internal record of that assessment either way. If you decide not to report, a documented rationale is what shows your supervisor — whether that is the PSRA, the Law Society of Ireland, your designated accountancy body (Chartered Accountants Ireland, ACCA or CPA Ireland), the AMLCU or the Central Bank of Ireland — that the decision was considered rather than missed.

Handle the matter on a need-to-know basis within the firm, and do not discuss the report or the underlying suspicion with the client.

Step 2: file with FIU Ireland through goAML

Once the decision to report is made, the MLRO logs into goAML and completes the STR. Practical points that make this go smoothly:

  • Assemble the facts first. Client identity details, the transactions concerned, dates, amounts, counterparties, and a clear narrative of why the activity is suspicious.
  • Write the narrative in plain English. Explain what you expected to see, what you actually saw, and why the gap concerns you. Assume the reader knows nothing about your client.
  • Save the acknowledgement. Record the submission date and any reference goAML provides — your evidence of filing.

Step 3: file the same report with Revenue through ROS

goAML lets you generate an XML file of the report you have just submitted. Revenue accepts that goAML-generated XML as an upload through ROS, which is the efficient route for the second leg:

  1. Export the XML from goAML.
  2. Log into ROS and upload the file as your STR submission to Revenue.
  3. Record the ROS submission date and reference alongside the goAML one.

Do both legs on the same day wherever possible. A gap between the two submissions is exactly the kind of loose end that surfaces awkwardly in a supervisory inspection.

Step 4: record, retain, and be ready for follow-up

Your obligations do not end at submission:

  • Keep a dual-submission record for every STR: goAML date and reference, ROS date and reference, and copies of the report and acknowledgements.
  • Retain records for five years. The AMLR sets a retain-five-years-then-delete standard, so your filing system needs both ends of that — secure retention and eventual deletion.
  • Be ready to respond fast. Under the AMLR, requests from the FIU must be answered within five working days, and shorter deadlines apply for some categories. If your client files are scattered across inboxes and shared drives, five working days is tight.

What the AMLR changes from 10 July 2027

Suspicion-based reporting continues, but the framework around it shifts:

AreaToday (CJA 2010)From 10 July 2027 (AMLR)
Your labelDesignated personObliged entity (Irish usage will likely keep both)
RulebookCJA 2010, as amendedRegulation (EU) 2024/1624, directly applicable
FIU requestsNational rulesAnswer within 5 working days (shorter for some categories)
Compliance rolesMLRO practiceA board-level compliance manager plus a compliance officer of sufficiently high standing; the compliance officer also takes on targeted financial sanctions from 10 July 2027
RecordsNational retention rulesRetain 5 years, then delete

Alongside the AMLR, Directive (EU) 2024/1640 (AMLD6) reshapes the institutional layer — national supervisors and FIU powers — and the new EU authority AMLA (amla.europa.eu) is driving more consistent supervision across member states. The practical message: your reporting workflow needs to be documented, fast and evidenced, not dependent on one person's memory.

What to do now

  1. Confirm your firm is registered on goAML via fiu-ireland.ie and that the access sits with your current MLRO.
  2. Confirm your ROS access covers STR submission to Revenue, per the guidance on revenue.ie.
  3. Write down your internal escalation route: who raises a concern, who assesses it, who files.
  4. Create a dual-submission log capturing both goAML and ROS dates and references for every report.
  5. Check your record-keeping can meet the AMLR's retain-five-years-then-delete standard and a five-working-day FIU response.
  6. Brief your team — the people most likely to spot a red flag are rarely the people who file the report.

How CompliDesk helps

CompliDesk Ireland includes an STR builder that generates goAML-compatible XML and tracks both the FIU Ireland and Revenue ROS legs of every submission, so your firm records and prepares each report in one place — the filing itself always stays with you. See the AMLR explainer for what else changes on 10 July 2027.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist