goAML explained: how reports reach financial intelligence units
goAML is software built by the UN Office on Drugs and Crime for financial intelligence units. Reporting entities register on their FIU's goAML portal and submit reports by web form or as XML files that follow the goAML schema, using the FIU's own codes.

Charles Archibong, Co-founder
· 5 min read

Key takeaways
- goAML is UNODC software that FIUs run; each FIU operates its own portal and sets its own report codes.
- Reporting entities register first, then submit by web form or by uploading XML that follows the goAML schema.
- One XML report covers one report type and one reporting entity, and can hold many transactions.
- Validate files against your FIU's current schema and lookup lists before upload, not after rejection.
goAML is a software application built by the United Nations Office on Drugs and Crime (UNODC) for financial intelligence units (FIUs). An FIU runs it to receive, store and analyse reports from banks, payment firms and other reporting entities. Those entities do not run goAML themselves: they register on their FIU's goAML portal and submit reports either by typing them into web forms or by uploading XML files that follow the goAML schema.
Preparing reports for goAML is therefore mostly a data problem. Each report must fit the schema, use the FIU's own code lists, and pass validation. A firm that files often usually builds an XML export from its case records; a firm that files rarely can use the web forms. Either way, clean customer and transaction data is what decides how long a report takes.
This article uses Nigeria's FIU as the worked example because it publishes its goAML documents openly. Requirements differ by jurisdiction, and this is general information rather than legal advice.
What is goAML, and who uses it?
UNODC's goAML page (opens in a new tab) describes it as "a fully integrated software solution developed specifically for use by Financial Intelligence Units", designed to meet their "data collection, management, analytical, document management, workflow and statistical needs". The goAML site (opens in a new tab) states that "over 70 Member States now use goAML, with many others preparing to join" (as of September 2026).
Two consequences follow for reporting entities:
Each FIU runs its own instance. You register with, and submit to, your FIU's portal, not a central UN system.
Each FIU configures its own codes and forms. The schema is shared, but report types, indicator codes and some field rules are set locally. A report valid for one FIU may not be valid for another.
How does a report reach the FIU?
The path has three stages.
1. Register as a reporting entity. Nigeria's NFIU goAML portal (opens in a new tab) says that "in order to get access to the system, you first need to register as a reporting entity under 'Register as an Organisation'". The schema expects a reporting entity number defined by the FIU in every report, as rentity_id.
2. Prepare the report. There are two routes, both described in the goAML web application manual the NFIU publishes:
Route | How it works | Suits |
|---|---|---|
Web report forms | Fill in the report in the portal, section by section, with field-level validation | Occasional filers and complex one-off reports |
XML or ZIP upload | Upload an XML report (or a ZIP of reports and attachments) generated by your own systems | Regular filers and high volumes |
The manual also allows a hybrid: upload a partial or full XML file to create a web report, then edit and submit it in the portal.
3. Validate and submit. UNODC's goAML overview (opens in a new tab) describes "step-by-step report submission" with "inline validation" that "prevents incomplete or invalid reports". The web manual adds an XML Report Validator for checking a file against the schema before upload, and requires XML files to be UTF-8 encoded.
The NFIU website also links to filing on a second service, RapidAML, alongside goAML. Check with the NFIU which channel applies to your institution and report type.
What does a goAML XML report contain?
The NFIU's goAML schema guide (opens in a new tab) (schema 5.0.2, dated 28 October 2022) sets out the structure. A few rules shape everything else:
An XML report is linked to one reporting entity but may contain multiple transactions.
An uploaded report can be of one report type only.
A report can list transactions, or describe an activity without reporting any transaction.
The top-level report node carries the fields you will map most often:
Field | What it holds |
|---|---|
| Your reporting entity number, assigned by the FIU |
| The type of submission |
| The report type, for example STR |
| Your own reference for the report |
| A reference used for follow-up reports on an original report |
| Why the report was made, up to 4,000 characters |
| Action taken, up to 4,000 characters |
| Classification codes from the FIU's predefined list |
Below that sit the transactions, each describing where money came from and went to, with nodes for the reporter's own client on either side and for other parties.
What report types does Nigeria's FIU accept?
The NFIU's lookup master (opens in a new tab) lists the report codes its goAML instance accepts. They include:
Code | Report |
|---|---|
STR | Suspicious transaction report |
SAR | Suspicious activity report |
CTR | Currency transaction report |
FTR | Foreign transaction report |
PEP | PEP transaction reports |
FSTR, CSTR, DTSTR, KSTR, TFSTR | STRs for fraud, corruption, drug trafficking, kidnapping for ransom and terrorism financing |
IPG-S, IPG-c | STR and CTR for internet payment gateways |
AIF | Additional information file |
BVN, BVNP | BVN complete and partial name change requests |
The last row is a reminder that goAML in Nigeria carries more than suspicion reports. Choosing the specific STR code (fraud rather than general STR, for example) gives the FIU a classification it can route on, so map your case outcomes to the right code rather than defaulting to STR.
How should you prepare your data for goAML?
Preparation is mostly about data. A checklist:
Get the current documents. Download the schema guide, lookup master, web guide and validator from your FIU. The NFIU publishes all four on its XML Reporting Format (opens in a new tab) page. Note the schema version you build against.
Map your data to the schema once. Customer, account, transaction and counterparty fields in your systems should each map to a goAML node. Write the mapping down and keep it with the schema version.
Map your codes to the FIU's lookups. Transaction types, identification types, country codes and indicators must use the FIU's exact values, not your internal labels.
Hold counterparty detail. goAML reports describe both sides of a transaction. If your records hold only your own customer's side, reports will be thin or fail validation.
Validate before upload. Run every generated file through the validator, and fix the generator rather than hand-editing XML.
Keep references. Record your
entity_referenceand any FIU reference against the case, so follow-ups and amendments can point to the original.Re-check when the FIU updates. A schema or lookup change can invalidate an export that worked last month.
Where does Myaza fit?
Myaza Cases & SAR Filing covers the preparation side. From an investigation, an analyst drafts a SAR or STR and supplies the reason; the report is generated in goAML format, can be reviewed on the report's detail view, and is exported as XML for you to submit to your FIU. When it has been filed, you record the external reference and the report moves to filed. The drafter cannot file their own report, and an amended report links to the one it amends. The investigations and reporting documentation describes the lifecycle.
Myaza does not submit reports to an FIU on your behalf. Registration, the portal account and the act of filing stay with your organisation, as does checking the export against your FIU's current schema and codes.
What to do next
Confirm your organisation is registered on your FIU's goAML portal and who holds the accounts.
Download the current schema guide and lookup lists, and record the versions.
Decide between web forms and XML upload based on how often you file.
Map your case outcomes to the FIU's specific report codes.
Run a test report through the validator before you need to file a real one.
Sources
goAML (Anti-Money-Laundering System), UNODC (opens in a new tab)
goAML software solution, UNODC goAML site (opens in a new tab)
NFIU goAML portal home, Nigerian Financial Intelligence Unit (opens in a new tab)
XML Reporting Format, Nigerian Financial Intelligence Unit (opens in a new tab)
goAML Schema Enumeration Reference (Lookup Master), NFIU (opens in a new tab)

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


