AML & Financial CrimeAugust 7, 20266 min read

Six Transaction Red Flags Your Frontline Staff Keep Missing — and the STR That Should Follow

ESAAMLG's mutual-evaluation cycle keeps pressure on Ethiopian reporting entities to file quality STRs. Six red flags tellers and relationship managers routinely miss, and how to turn a hunch into a defensible STR.

D
Daracorp Team

Six Transaction Red Flags Your Frontline Staff Keep Missing — and the STR That Should Follow

Who this is for: Compliance Officers and MLROs at Ethiopian banks, insurers and microfinance institutions, and the frontline teams they rely on.

Ethiopia's anti-money-laundering framework does not sit still. Under the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), member states including Ethiopia are assessed against the Financial Action Task Force (FATF) standards through mutual evaluations and follow-up reporting. A recurring finding across the region, evaluation after evaluation, is the same: reporting entities file too few suspicious transaction reports (STRs), and the ones they do file are thin. In Ethiopia the obligation to identify and report suspicion runs to the Financial Intelligence Service (FIS) under the money-laundering and terrorism-financing proclamation and its implementing directives. The law puts the duty on the institution, but suspicion is almost always spotted first at the counter, by a teller, a relationship manager or a branch operations officer. If they do not recognise the flag, nothing reaches the MLRO, and nothing reaches the FIS. So the practical question is not what the law says. It is what your frontline is walking past every day.

The six red flags that slip through

1. Structuring just under the reporting or CDD threshold

A customer who repeatedly deposits amounts that sit just below a known threshold, enough times across enough days that the pattern is the point. Frontline staff tend to see each transaction in isolation. The flag only appears when you look across a week or a month. Teach staff to ask themselves whether this would look deliberate if they lined up the last ten transactions.

2. Transactions with no economic sense for this customer

A salaried customer with a modest, predictable inflow suddenly routing large third-party transfers. A small trader receiving round-number remittances from unrelated senders in several countries. The transaction may be perfectly legal on its face. The flag is the mismatch between the activity and everything you already know about the customer from onboarding.

3. Reluctance, evasiveness or over-explanation during CDD

When a customer bristles at a routine source-of-funds question, offers a rehearsed explanation nobody asked for, or tries to complete a transaction through a more junior staff member after a question was raised, that behaviour is data. Frontline staff often smooth it over to keep service moving. Train them to note it instead.

4. Third parties who direct the transaction

The named account holder is present, but someone else is doing the talking, holding the documents, and deciding the amounts. This can signal a nominee or money-mule arrangement. The flag is who controls the transaction, not whose name is on the form.

5. Sudden activity on a long-dormant account

An account that has been quiet for months or years springs to life with rapid in-and-out movement. This is classic layering behaviour. Frontline staff rarely check dormancy history before processing, so build the prompt into the workflow.

6. PEP or adverse-media proximity that onboarding missed

A customer, or a counterparty they transact with, who turns out to be a politically exposed person or the subject of credible adverse media. If screening happens only at onboarding and never again, exposure that develops after the relationship opens is invisible. Periodic re-screening closes the gap.

Turning a hunch into a defensible STR

A red flag is not an STR. The value your MLRO adds, and what an ESAAMLG-style assessment looks for, is a disciplined escalation path. Give your frontline a simple internal-escalation routine and give your MLRO a consistent STR standard.

Frontline escalation checklist (internal, before it reaches the MLRO):

  • What did I observe, in transaction detail and behaviour, in plain factual language?
  • Why is it inconsistent with what I know about this customer?
  • Did I avoid tipping off the customer that a concern was raised?
  • Have I logged it through the internal channel the same day, not at week's end?
  • Have I preserved the supporting records (slips, IDs, screening hits)?

MLRO STR standard (before filing to the FIS):

  • A clear, chronological narrative: who, what, when, how much, through which channels.
  • The specific ground for suspicion, stated explicitly, not implied.
  • The CDD/EDD already held, and any gaps you could not close.
  • Linked accounts, counterparties and related transactions.
  • A decision record: file, or a documented rationale for not filing.
  • Confidentiality maintained end to end, with no tipping-off.

The single biggest quality lift, region-wide, is the narrative. A one-line "customer behaved suspiciously" gives the FIS nothing to act on. A tight paragraph connecting the behaviour to the transaction to the customer profile is an STR an analyst can actually use. That move from raw signal to documented, defensible record is the same discipline an ethics team applies when handling the first whistleblowing report.

Strong vs weak: what actually differs

A weak control environment screens at onboarding, trains once a year with a click-through module, and treats STR filing as a compliance-department chore. Flags die at the counter because nobody taught the counter to see them.

A strong environment makes red-flag recognition part of the frontline job description, runs short scenario-based refreshers on real typologies, gives staff a same-day escalation channel with no penalty for a false alarm, and closes the loop so staff learn which of their escalations became STRs. The difference is not budget. It is design.

Why this bites harder in Ethiopia's fast-growing sector

Ethiopia's financial sector is expanding fast, with new digital payment providers, agent banking networks, growing remittance volumes and, ahead, foreign bank entry. Every one of those channels widens the surface for money laundering and terrorist financing, and every one lands first at the frontline. As ESAAMLG follow-up continues to scrutinise the effectiveness of the system, not just whether laws exist on paper, the institutions that stand out will be the ones that can show suspicion is caught early and escalated well. That pressure only intensifies as foreign banks raise the correspondent-banking bar.

Red-flag recognition is a trainable skill, and it decays without reinforcement. DaraCorp's AML & CFT course builds exactly this capability, typology-based, role-specific, and delivered in a way frontline staff retain, so the flags in this article stop slipping past the counter. It pairs well with Risk Management & Compliance for the MLROs who own the STR decision.

This article describes practices reporting entities across the region are adopting. It is not legal advice; confirm your specific obligations against the current Ethiopian AML/CFT proclamation and FIS directives, and against your institution's own risk assessment.

Filed under
AMLCFTSTRred flagsFISESAAMLGfrontline training
DaraCorp AI assistant

How can I assist you today?

Powered by CopilotKit