What makes a transaction suspicious?
Why suspicion is judged mainly against what a firm knows about its customer, what a red flag is, and how staff are expected to spot and escalate unusual activity.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 1 of 4 · all topics in this chapter
Short answer
A transaction is usually suspicious because it does not fit what the firm knows about the customer: their legitimate business or personal activities, the normal use of the account, or their economic profile. Amount alone neither triggers a report nor rules one out, although unusually large or complex transactions must be examined closely. Red flags are warning signs that call for questions about the source of funds and the purpose. Staff with even a slight suspicion report it without delay to the AML compliance officer, who decides whether to report to MOKAS.
Suspicion at a glance
| Point | Rule |
|---|---|
| Benchmark for suspicion | The customer's known legitimate activities, the account's normal business and the customer's economic profile |
| Amount | No minimum; reporting applies whatever the amount, and attempted transactions are included |
| Red flag | A risk indicator that prompts further investigation and a request for explanations about source of funds and purpose |
| Firm's duty | Hold enough information about each customer to notice promptly when one transaction, or a pattern of them, is out of the ordinary |
| Staff duty | All employees are trained to detect suspicious activity and report even a slight suspicion to the AML compliance officer without delay |
| Who decides on a report to MOKAS | The AML compliance officer, after a documented evaluation |
Source: Law 188(I)/2007, Articles 58, 60 and 69, as amended up to 2026; CySEC AML Directive, paragraphs 9, 26, 28 and 34 and the Third Appendix.
Why is suspicion measured against the customer's profile?
There is no closed list of suspicious transactions; the ways money can be laundered or used to finance terrorism are almost unlimited. What the rules offer instead is a benchmark. A suspicious transaction is often one that clashes with what the firm knows of the customer's lawful business or private activity, with how the account is normally used, or with the economic profile drawn up at onboarding.
That is why CDD and suspicion are linked. A firm can only notice that something is out of line if it knows what normal looks like for that customer. A €200,000 transfer may be routine for one client and alarming for another; a series of small payments may be unremarkable for a retail customer and strange for a dormant corporate account. Size does not settle the question on its own, although unusually large or complex transactions, and transactions with no apparent economic or lawful purpose, must always be examined closely.
Knowing what normal looks like is the job of ongoing monitoring, covered in the KYC & Customer Due Diligence notes.
Terms used in this note
- Economic profile
- The picture a firm builds of a customer at onboarding and keeps up to date, covering expected activity, source of funds and the purpose of the relationship, against which later transactions are measured.
- Red flag
- A warning sign that a transaction or activity may be linked to money laundering or terrorist financing and should be looked at more closely.
- Unusual transaction
- A transaction that departs from a customer's normal pattern or expected activity, or has no apparent economic or lawful purpose. It must be examined, and it is reported internally as soon as it gives rise to suspicion.
What is a red flag and what should happen when one appears?
A red flag is a risk indicator: a fact or pattern that suggests a transaction or activity might be linked to money laundering or terrorist financing. CySEC's AML Directive attaches a list of examples, described in What are the red flags?. The list is not exhaustive, but spotting any item on it is a valid reason to investigate further.
Investigating means gathering information before concluding. The firm asks for explanations about the source and origin of the funds, the nature and economic purpose of the transaction and the circumstances around it, and checks the answers against what it already knows. A red flag that is investigated and satisfactorily explained, with the findings recorded on the customer's file, may need no report. If it is not explained, or leaves even a slight suspicion, it is reported to the AML compliance officer without delay.
Who in the firm spots and escalates suspicion?
Every obliged entity needs a process to identify and report suspicious transactions, and all employees must be trained to recognise them. The process has four parts: staff report internally, without delay, to the AML compliance officer; the compliance officer formally evaluates each report and documents the decision; the compliance officer either reports to MOKAS and then watches the customer's activity closely, or records why no report was made; and senior management or the board is told periodically about suspicious transaction filings.
Employees report to the compliance officer, not straight to MOKAS or to anyone else in the firm. The internal route protects them and lets one person with access to all the firm's information make the decision. The steps and documents are covered in How are suspicious transactions reported?
How to think about it
Ask one question: does this fit the customer? Compare the transaction with the economic profile and the account's usual activity, not with a fixed amount. If it does not fit, look into it by asking about the source of the funds and the purpose. Anyone with even a slight suspicion reports it to the AML compliance officer without delay, rather than waiting to be sure; the compliance officer evaluates and decides about MOKAS. Being a PEP or a high-risk client is a reason for closer monitoring, not a suspicion in itself.
Common mistakes
Judging suspicion by size alone. A large transaction that fits the profile may be normal; a small one that does not fit may be suspicious.
Reporting straight to MOKAS as an employee. Staff report internally to the AML compliance officer, who decides on the report to MOKAS.
Treating a risk factor as a suspicion. PEP status or a high-risk country raises the level of due diligence; suspicion depends on what actually happens in the relationship, although transfers to or from countries that apply FATF standards poorly are themselves on the list of red flags.
Waiting for a threshold before reporting. CDD thresholds such as €15,000 decide when checks apply to occasional transactions, and a suspicion triggers CDD at any amount; suspicion is reported whatever the amount.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Article 58: internal reporting and staff training among the required procedures · Article 60(c): due diligence whenever there is a suspicion · Article 69: internal reporting and reporting to MOKAS
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
Paragraph 9: compliance officer's duties · Paragraph 26: ongoing monitoring · Paragraph 28 and Third Appendix: suspicious transactions and examples · Paragraph 34: employees report without delay
Practise this topic
Test what you just read
The Chapter 7 pack has 53 exam-style questions, 5 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 15 free Chapter 7 flashcards →