Six Transaction Red Flags Your Frontline Staff Keep Missing — and the STR That Should Follow

Bemnet Aschalew

Six Transaction Red Flags Your Frontline Staff Keep Missing — and the STR That Should Follow

Who this is for: Compliance Officers and MLROs at Ethiopian banks, insurers and microfinance institutions — and the frontline teams they rely on.

The news hook

Ethiopia's anti-money-laundering framework does not sit still. Under the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), member states — Ethiopia included — are assessed against the Financial Action Task Force (FATF) standards through mutual evaluations and follow-up reporting. A recurring finding across the region, evaluation after evaluation, is the same: reporting entities file too few suspicious transaction reports (STRs), and the ones they do file are thin. ESAAMLG publishes its evaluation and typology work at esaamlg.org, and the FATF standards themselves sit at fatf-gafi.org.

In Ethiopia, the obligation to identify and report suspicion runs to the Financial Intelligence Service (FIS) under the money-laundering and terrorism-financing proclamation and its implementing directives. The law puts the duty on the institution. But suspicion is almost always spotted first at the counter — by a teller, a relationship manager, a branch operations officer. If they do not recognise the flag, nothing reaches the MLRO, and nothing reaches the FIS.

So the practical question is not "what does the law say?" It is "what is my frontline walking past every day?"

The six red flags that slip through

1. Structuring just under the reporting or CDD threshold

A customer who repeatedly deposits amounts that sit just below a known threshold — enough times, across enough days, that the pattern is the point. Frontline staff tend to see each transaction in isolation. The flag only appears when you look across a week or a month. Teach staff to ask themselves: would this look deliberate if I lined up the last ten transactions?

2. Transactions with no economic sense for this customer

A salaried customer with a modest, predictable inflow suddenly routing large third-party transfers. A small trader receiving round-number remittances from unrelated senders in several countries. The transaction may be perfectly legal on its face — the flag is the mismatch between the activity and everything you already know about the customer from onboarding.

3. Reluctance, evasiveness or over-explanation during CDD

When a customer bristles at a routine source-of-funds question, offers a rehearsed explanation nobody asked for, or tries to complete a transaction through a more junior staff member after a question was raised — that behaviour is data. Frontline staff often smooth it over to keep service moving. Train them to note it instead.

4. Third parties who direct the transaction

The named account holder is present, but someone else is doing the talking, holding the documents, and deciding the amounts. Possible nominee or money-mule arrangement. The flag is who controls the transaction, not whose name is on the form.

5. Sudden activity on a long-dormant account

An account that has been quiet for months or years springs to life with rapid in-and-out movement. Classic layering behaviour. Frontline staff rarely check dormancy history before processing — build the prompt into the workflow.

6. PEP or adverse-media proximity that onboarding missed

A customer, or a counterparty they transact with, who turns out to be a politically exposed person or the subject of credible adverse media. If screening happens only at onboarding and never again, exposure that develops after the relationship opens is invisible. Periodic re-screening closes the gap.

Turning a hunch into a defensible STR

A red flag is not an STR. The value your MLRO adds — and what an ESAAMLG-style assessment looks for — is a disciplined escalation path. Give your frontline a simple internal-escalation routine and give your MLRO a consistent STR standard.

Frontline escalation checklist (internal, before it reaches the MLRO):

  • What did I observe — transaction detail and behaviour — in plain, factual language?
  • Why is it inconsistent with what I know about this customer?
  • Did I avoid tipping off the customer that a concern was raised?
  • Have I logged it through the internal channel the same day, not at week's end?
  • Have I preserved the supporting records (slips, IDs, screening hits)?

MLRO STR standard (before filing to the FIS):

  • A clear, chronological narrative — who, what, when, how much, through which channels.
  • The specific ground for suspicion, stated explicitly, not implied.
  • The CDD/EDD already held, and any gaps you could not close.
  • Linked accounts, counterparties and related transactions.
  • A decision record: file, or documented rationale for not filing.
  • Confidentiality maintained end to end — no tipping-off.

The single biggest quality lift, region-wide, is the narrative. A one-line "customer behaved suspiciously" gives the FIS nothing to act on. A tight paragraph that connects the behaviour to the transaction to the customer profile is an STR an analyst can actually use.

What good looks like versus what weak looks like

A weak control environment screens at onboarding, trains once a year with a click-through module, and treats STR filing as a compliance-department chore. Flags die at the counter because nobody taught the counter to see them.

A strong environment makes red-flag recognition part of the frontline job description, runs short scenario-based refreshers on real typologies, gives staff a same-day escalation channel with no penalty for a false alarm, and closes the loop so staff learn which of their escalations became STRs. The difference is not budget — it is design.

The Ethiopian context

Ethiopia's financial sector is expanding fast — new digital payment providers, agent banking networks, growing remittance volumes, and, ahead, foreign bank entry. Every one of those channels widens the surface for money laundering and terrorist financing, and every one lands first at the frontline. As ESAAMLG follow-up continues to scrutinise the effectiveness of the system — not just whether laws exist on paper — the institutions that will stand out are the ones that can show suspicion is caught early and escalated well.

Your next step

Red-flag recognition is a trainable skill, and it decays without reinforcement. DaraCorp's AML & CFT course builds exactly this capability — typology-based, role-specific, and delivered in a way frontline staff retain — so the flags in this article stop slipping past the counter. Pair it with Risk Management & Compliance for the MLROs who own the STR decision, and you have both halves of the escalation chain covered.

This article describes practices reporting entities across the region are adopting. It is not legal advice; confirm your specific obligations against the current Ethiopian AML/CFT proclamation and FIS directives, and against your institution's own risk assessment.

DaraCorp AI assistant

How can I assist you today?

Powered by CopilotKit