AMLA Has Defined the STR Format. The Compliance Question Is Whether Your Data Fits.
AMLA opened consultation on July 2 on the STR format ITS, defining data templates obliged entities must use to automate suspicious transaction reporting. This article argues the template is not a reporting convenience but a data infrastructure specification, and that management companies and TCSPs must assess now whether their compliance systems can populate it.

There is a class of regulatory document that reads like a procedural update but functions as an infrastructure mandate. On 2 July 2026, AMLA published one of them.
The document is a consultation paper on draft implementing technical standards (ITS) specifying the format to be used for the reporting of suspicions and for the provision of transaction records under Article 69(3) of Regulation (EU) 2024/1624. The headline reads: consultation on suspicious transaction reporting formats. The content is: here is the data schema your compliance system must produce.
The consultation closes 20 September 2026. A public hearing is scheduled for 9 September. But firms waiting for the final text before acting have already missed the point.
What the Draft ITS Actually Does
Under Article 69(1) of the AMLR, every obliged entity must, on its own initiative, report suspicions that funds or activities may be connected to money laundering or terrorist financing. On request from the Financial Intelligence Unit, the entity must also provide transaction records. These obligations have existed in some form under the previous AMLD framework. What the July ITS adds is specificity: a standardized machine-readable format for how those reports and records must be structured.
The draft ITS provides two categories of templates. The first covers reporting of suspicions, with templates adapted to different types of obliged entities, distinguishing between financial entities (credit institutions, investment firms, fund managers) and non-financial entities (lawyers, accountants, trust and company service providers). The second covers the provision of transaction records, applying specifically to credit and financial institutions.
The templates "shall be implemented by all FIUs and by all obliged entities wishing to internally automate the process for reporting instead of using the reporting platforms of FIUs, under the conditions set by the draft ITS."
That sentence does most of the work.
The Automation Framing Is Misleading
The drafters have presented these templates as applying to firms that choose to automate, as distinct from firms that continue to file manually through FIU portals. The implication is optionality: you can use the AMLA schema, or you can keep using your national FIU's portal.
This framing understates the practical situation for any firm operating at scale.
In Luxembourg, obliged entities currently file suspicious transaction reports with the Cellule de renseignement financier (CRF) via GoAML, the UNODC reporting platform deployed across numerous EU jurisdictions. GoAML is a portal. A compliance officer logs in, navigates to the report form, and enters data fields one by one. For a management company or TCSP managing dozens of client structures, this process is already a constraint. A single STR requires pulling client identification data, transaction history, counterparty information, and a documented suspicion rationale, then entering it across multiple screen fields without an audit trail connecting the source records to the report submission.
The AMLR does not eliminate GoAML or replace national FIU portals. But it adds a layer above them: AMLA as the coordinating authority, with a standardized cross-border data schema. Firms with clients or activities in multiple EU member states currently manage different portal interfaces per jurisdiction. The AMLA template creates a single logical schema that, once implemented internally, would support cross-border reporting from one system.
The choice between "automate with the AMLA schema" and "continue using FIU portals manually" is not a permanent binary. It is a timeline question. Any firm that expects to handle AML reporting at volume in 2027-28 under the full AMLR regime will find manual FIU portal entry increasingly inadequate. The AMLA template is not an option being offered. It is the direction the infrastructure is moving.
What the Schema Actually Requires
The substance of the template is a structured data specification, not a guidance document. The STR template for an obliged entity must capture, for each report: the identity of the reporting entity, the identity of the subject of the report (with specific identification data points corresponding to the AMLR's CDD requirements), the nature and basis of the suspicion (drawn from defined typology categories, not free narrative), the transactions or activities at issue (with amounts, dates, currencies, counterparty details, and account identifiers), and related parties connected to the reported activity.
Each of these fields maps back to data your CDD system should already be capturing. The person's full legal name, date of birth, national identification number or passport number, address, beneficial ownership structure for legal entities, the economic purpose of the relationship, the transaction pattern. The AMLA template does not invent new data requirements. It specifies the data format in which existing requirements must be expressed when filing a report.
That distinction is important. Firms that have implemented CDD processes may have captured the right information but in formats that do not map directly to the AMLA template fields. Free text rationale sections in client files, PDF copies of identification documents without structured data extraction, transaction records held in fund accounting systems that were never designed to export in a compliance data format. The template reveals whether your data capture was structured or merely present.
What This Means for Management Companies, TCSPs, and Fund Administrators
The AMLR applies from 10 July 2027. The AMLA STR format ITS will be finalized before that date, following the consultation window and public hearing in September.
For a management company or TCSP in Luxembourg, the practical question is not whether the ITS applies. It does. The question is whether the internal data environment can populate the template fields without a compliance officer manually retrieving data from disparate systems, cross-referencing documents, and transcribing information into a report interface.
That manual process is not wrong. It is the current state of affairs at most firms. But it does not scale, it produces inconsistent records, and it does not create an auditable linkage between the source compliance data (the CDD file, the transaction monitoring alert, the internal escalation record) and the STR that was filed.
The AMLA template, once finalized, will define what the linkage must look like. Firms whose compliance data environment can map directly to the template fields will have a reportable audit trail. Firms that cannot will produce reports assembled by hand, with the usual gaps in reproducibility and the usual risks at the point of supervisory review.
The September 20 consultation deadline is an opportunity to comment on the template fields before they are finalized. Whether a firm uses that opportunity is a question of resource and judgment. What is not optional is the underlying question the template asks: is your compliance data structured enough to report it in a specified format, or is it a collection of documents that require human assembly before any report can be filed?
The Position
AMLA's STR format ITS will be presented, when finalized, as an implementation detail of the AMLR's reporting obligations. It is not. It is a data specification that exposes whether compliance systems were built to produce structured output or to store documents.
The template is the conclusion. The compliance infrastructure that can or cannot populate it is the actual compliance program. Firms that treat this consultation as a forms exercise will file comments on field widths and character limits. Firms that treat it as a data architecture question will use the next twelve months to close the gap.