Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who is responsible for reporting suspicious transactions and…
Governance, Ownership & Risk

Who is responsible for reporting suspicious transactions and cash movements to the UAF in Chile?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

The obliged institution is responsible for reporting, not the customer and not a third party. The article shows that regulated entities must file suspicious activity reports, report cash operations above the threshold, and maintain records for at least five years. Operational ownership typically sits across compliance, AML operations, and senior management, but the legal duty remains with the regulated entity.

Who actually carries the reporting duty to the UAF?

The reporting duty sits with the obliged or regulated institution, not with the customer and not with a third party acting on its behalf. In practice, that means the organisation that holds the legal AML obligation must make the filing decision, own the evidence, and ensure the report is submitted on time when the activity meets the statutory threshold or suspicion test.

How suspicious transaction reporting differs from cash movement reporting

Suspicious transaction reporting and cash movement reporting are related but not identical obligations. Suspicious reports are triggered by indicators of unusual, unexplained, or potentially illicit activity, while cash movement reporting is threshold-based and can apply even when no specific suspicion has been formed. That distinction matters because one control is judgement-driven and the other is rule-driven.

For practitioners, the common failure is assuming that only the front-line relationship owner needs to know. In reality, the legal duty depends on the regulated entity’s monitoring, escalation, and filing process, so both transaction monitoring and cash threshold handling need clear ownership and auditable workflow.

What the reporting obligation means for recordkeeping and accountability

The filing duty is only one part of the control. The institution also has to retain records long enough to reconstruct the case, support an audit trail, and respond to follow-up requests. A five-year retention period is typical in these regimes, which makes evidence management part of the compliance control rather than a separate archive function.

That creates an important operational point: if the report cannot be evidenced later, the control is incomplete even if the filing was submitted. Teams should preserve the alert rationale, supporting transaction data, escalation notes, and the final disposition so the institution can prove why a report was, or was not, filed.

Risk and Threat Considerations

Reporting failures usually arise from weak escalation paths, unclear role ownership, or fragmented transaction visibility across systems. The risk is not limited to missed filings, because delayed or inconsistent reporting can also conceal money laundering patterns, reduce the quality of the institution’s audit trail, and create supervisory exposure.

Failure mechanism: Alerts are generated but not converted into a timely filing decision because the monitoring team, AML function, and management chain do not share a single accountable process. High-volume cash activity can also be normalised operationally, causing threshold events to be missed or misclassified.

Impact: The regulated entity can fail its legal reporting obligation, lose traceability over suspicious activity, and face enforcement, remediation, or reputational consequences if the UAF later expects a filing that never happened.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-3 — Content of Audit RecordsSuspicious and cash reports depend on complete evidence trails.
AU-6 — Audit Review, Analysis, and ReportingThe workflow needs timely review of alerts and escalation outcomes.
AC-6 — Least PrivilegeReporting workflows should restrict filing and case-edit rights to accountable roles.
Recommendation — Record alert rationale, filing decisions, and supporting transaction details. Review monitoring outputs and escalate cases that meet reporting thresholds. Limit report submission and case alteration to approved AML roles.
ISO/IEC 27001:2022A.5.15 — Access controlAccess to case data and reporting actions must be governed.
A.5.28 — Collection of evidenceThe duty includes preserving evidence that supports the filing decision.
Recommendation — Define and enforce role-based access for reporting and case handling. Preserve case records and supporting evidence for the required retention period.
CIS Controls v8CIS-5 — Account ManagementOperational ownership and access to reporting functions must be assigned and reviewed.
Recommendation — Assign and periodically review access for AML reporting roles.

Practitioner Guidance

What to verify: Confirm that your filing workflow distinguishes between suspicion-based reports and threshold-based cash reports, because they often have different triggers, review paths, and evidence requirements. The legal accountable entity should be obvious in policy, case management, and escalation templates.

What good looks like: The institution can show a complete chain from alert generation to decision, filing, and retention, with timestamps and ownership at each step. That is the standard that matters when regulators or auditors ask who knew what, when, and why a report was or was not sent.

Practitioner takeaway: Treat reporting as an institutional control, not an individual judgement, and make sure compliance, AML operations, and management can each prove their part in the same recorded process.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org