Skip to content

goAML explained: how reports reach financial intelligence units

goAML is software built by the UN Office on Drugs and Crime for financial intelligence units. Reporting entities register on their FIU's goAML portal and submit reports by web form or as XML files that follow the goAML schema, using the FIU's own codes.

Charles Archibong

, Co-founder

· 5 min read

Headline "goAML, explained" beside an illustration of a path of connected steps, on a warm cream gradient.

Key takeaways

  • goAML is UNODC software that FIUs run; each FIU operates its own portal and sets its own report codes.
  • Reporting entities register first, then submit by web form or by uploading XML that follows the goAML schema.
  • One XML report covers one report type and one reporting entity, and can hold many transactions.
  • Validate files against your FIU's current schema and lookup lists before upload, not after rejection.

goAML is a software application built by the United Nations Office on Drugs and Crime (UNODC) for financial intelligence units (FIUs). An FIU runs it to receive, store and analyse reports from banks, payment firms and other reporting entities. Those entities do not run goAML themselves: they register on their FIU's goAML portal and submit reports either by typing them into web forms or by uploading XML files that follow the goAML schema.

Preparing reports for goAML is therefore mostly a data problem. Each report must fit the schema, use the FIU's own code lists, and pass validation. A firm that files often usually builds an XML export from its case records; a firm that files rarely can use the web forms. Either way, clean customer and transaction data is what decides how long a report takes.

This article uses Nigeria's FIU as the worked example because it publishes its goAML documents openly. Requirements differ by jurisdiction, and this is general information rather than legal advice.

What is goAML, and who uses it?

UNODC's goAML page (opens in a new tab) describes it as "a fully integrated software solution developed specifically for use by Financial Intelligence Units", designed to meet their "data collection, management, analytical, document management, workflow and statistical needs". The goAML site (opens in a new tab) states that "over 70 Member States now use goAML, with many others preparing to join" (as of September 2026).

Two consequences follow for reporting entities:

  • Each FIU runs its own instance. You register with, and submit to, your FIU's portal, not a central UN system.

  • Each FIU configures its own codes and forms. The schema is shared, but report types, indicator codes and some field rules are set locally. A report valid for one FIU may not be valid for another.

How does a report reach the FIU?

The path has three stages.

1. Register as a reporting entity. Nigeria's NFIU goAML portal (opens in a new tab) says that "in order to get access to the system, you first need to register as a reporting entity under 'Register as an Organisation'". The schema expects a reporting entity number defined by the FIU in every report, as rentity_id.

2. Prepare the report. There are two routes, both described in the goAML web application manual the NFIU publishes:

Route

How it works

Suits

Web report forms

Fill in the report in the portal, section by section, with field-level validation

Occasional filers and complex one-off reports

XML or ZIP upload

Upload an XML report (or a ZIP of reports and attachments) generated by your own systems

Regular filers and high volumes

The manual also allows a hybrid: upload a partial or full XML file to create a web report, then edit and submit it in the portal.

3. Validate and submit. UNODC's goAML overview (opens in a new tab) describes "step-by-step report submission" with "inline validation" that "prevents incomplete or invalid reports". The web manual adds an XML Report Validator for checking a file against the schema before upload, and requires XML files to be UTF-8 encoded.

The NFIU website also links to filing on a second service, RapidAML, alongside goAML. Check with the NFIU which channel applies to your institution and report type.

What does a goAML XML report contain?

The NFIU's goAML schema guide (opens in a new tab) (schema 5.0.2, dated 28 October 2022) sets out the structure. A few rules shape everything else:

  • An XML report is linked to one reporting entity but may contain multiple transactions.

  • An uploaded report can be of one report type only.

  • A report can list transactions, or describe an activity without reporting any transaction.

The top-level report node carries the fields you will map most often:

Field

What it holds

rentity_id

Your reporting entity number, assigned by the FIU

submission_code

The type of submission

report_code

The report type, for example STR

entity_reference

Your own reference for the report

fiu_ref_number

A reference used for follow-up reports on an original report

reason

Why the report was made, up to 4,000 characters

action

Action taken, up to 4,000 characters

report_indicators

Classification codes from the FIU's predefined list

Below that sit the transactions, each describing where money came from and went to, with nodes for the reporter's own client on either side and for other parties.

What report types does Nigeria's FIU accept?

The NFIU's lookup master (opens in a new tab) lists the report codes its goAML instance accepts. They include:

Code

Report

STR

Suspicious transaction report

SAR

Suspicious activity report

CTR

Currency transaction report

FTR

Foreign transaction report

PEP

PEP transaction reports

FSTR, CSTR, DTSTR, KSTR, TFSTR

STRs for fraud, corruption, drug trafficking, kidnapping for ransom and terrorism financing

IPG-S, IPG-c

STR and CTR for internet payment gateways

AIF

Additional information file

BVN, BVNP

BVN complete and partial name change requests

The last row is a reminder that goAML in Nigeria carries more than suspicion reports. Choosing the specific STR code (fraud rather than general STR, for example) gives the FIU a classification it can route on, so map your case outcomes to the right code rather than defaulting to STR.

How should you prepare your data for goAML?

Preparation is mostly about data. A checklist:

  1. Get the current documents. Download the schema guide, lookup master, web guide and validator from your FIU. The NFIU publishes all four on its XML Reporting Format (opens in a new tab) page. Note the schema version you build against.

  2. Map your data to the schema once. Customer, account, transaction and counterparty fields in your systems should each map to a goAML node. Write the mapping down and keep it with the schema version.

  3. Map your codes to the FIU's lookups. Transaction types, identification types, country codes and indicators must use the FIU's exact values, not your internal labels.

  4. Hold counterparty detail. goAML reports describe both sides of a transaction. If your records hold only your own customer's side, reports will be thin or fail validation.

  5. Validate before upload. Run every generated file through the validator, and fix the generator rather than hand-editing XML.

  6. Keep references. Record your entity_reference and any FIU reference against the case, so follow-ups and amendments can point to the original.

  7. Re-check when the FIU updates. A schema or lookup change can invalidate an export that worked last month.

Where does Myaza fit?

Myaza Cases & SAR Filing covers the preparation side. From an investigation, an analyst drafts a SAR or STR and supplies the reason; the report is generated in goAML format, can be reviewed on the report's detail view, and is exported as XML for you to submit to your FIU. When it has been filed, you record the external reference and the report moves to filed. The drafter cannot file their own report, and an amended report links to the one it amends. The investigations and reporting documentation describes the lifecycle.

Myaza does not submit reports to an FIU on your behalf. Registration, the portal account and the act of filing stay with your organisation, as does checking the export against your FIU's current schema and codes.

What to do next

  • Confirm your organisation is registered on your FIU's goAML portal and who holds the accounts.

  • Download the current schema guide and lookup lists, and record the versions.

  • Decide between web forms and XML upload based on how often you file.

  • Map your case outcomes to the FIU's specific report codes.

  • Run a test report through the validator before you need to file a real one.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

  • Headline "A SAR an FIU can act on" beside an illustration of an identity document with a portrait and machine-readable zone, on a warm cream gradient.

    Risk & Compliance

    Writing a suspicious activity report an FIU can act on

    A useful SAR or STR narrative answers who, what, when, where, why and how in one chronological account, explains why the activity is unusual for this customer, and gives facts an analyst can follow without opening your systems.

  • Headline "From alert to decision" beside an illustration of a stack of case cards, on a warm cream gradient.

    Risk & Compliance

    From alert to decision: running an investigation queue that keeps up

    Keep two queues with two jobs. Triage alerts quickly and label every one; open an investigation only when the evidence needs an owner, group it by customer, prioritise by risk and deadline, and close it with a recorded outcome and rationale.

  • Headline "CBN automated AML standards" beside an illustration of stacked verification cards, on a warm cream gradient.

    Risk & Compliance

    CBN's baseline standards for automated AML: preparing your stack

    The CBN's baseline standards, issued on 10 March 2026, set mandatory minimum requirements for automated systems that detect, analyse and report suspicious activity in real time. The CBN has said compliance is assessed at the level of the institution, so buying a tool is a start, not an answer.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.

goAML explained: preparing reports for your FIU · Myaza Trust