Regulators Clarify: Banks May Discuss Suspicious Activity With Customers Without Compromising SAR Confidentiality
On September 2, 2026, the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), and the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) (together, the “Agencies”) issued a joint statement (the “Joint Statement”) clarifying how banks (and credit unions) can communicate with customers about suspicious or potentially fraudulent activity without violating the confidentiality rules that protect Suspicious Activity Reports (SARs) under the Bank Secrecy Act (BSA). The Joint Statement does not change any existing legal requirement or create new supervisory expectations, but it sends a clear signal that regulators want banks to be more forthcoming with customers, not less.
What the Joint Statement Contains
The Joint Statement responds to concerns raised in response to a 2025 interagency request for information on payments fraud, where commenters asked the Agencies to clarify how banks can give customers timely, transparent explanations for fraud-related account actions, including delays, restrictions, or closures, without running afoul of SAR confidentiality. The Joint Statement also frames itself as responsive to Executive Order 14331, Guaranteeing Fair Banking for All Americans, which focused on prohibiting debanking based on political, social, or religious views.
SAR confidentiality exists for a specific reason: to prevent tipping off the subject. If a subject learns that a SAR has been filed on them, they may destroy evidence, move funds, flee, or otherwise evade an ongoing or future law enforcement investigation. Disclosure of SAR information can also deter financial institutions from filing SARs in the first place.
The core message of the Joint Statement is a familiar one, restated with new emphasis: the BSA prohibits disclosing a SAR or anything that would reveal the existence of a SAR, but it does not prohibit sharing the underlying facts, transactions, and documents on which a SAR is based. Banks may discuss those underlying facts with the customer, even if a reasonable, SAR-savvy person might infer from those facts that a SAR was filed. That inference does not, by itself, constitute an unauthorized disclosure.
The Agencies offer a non-exhaustive list of communications that would not typically reveal the existence of a SAR, including requesting customer due diligence information; notifying a customer that an account restriction, delay, or closure may relate to suspected fraud; explaining that a deposit was rejected because of suspected check fraud; asking about the purpose of a transaction or source of funds; and providing fraud-awareness education, including on money mule schemes.
The Bigger Picture: A Continuation, Not a Departure
The Joint Statement is separate from—but expressly ties itself to—FinCEN’s September 2025 guidance, Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality (FIN-2025-G001) (the “Cross-Border Guidance”), which addressed a parallel question: whether U.S. financial institutions can share information with appropriate foreign financial institutions, including foreign affiliates and correspondents without disclosing SAR-protected information. The Cross-Border Guidance drew the same line—existence of a SAR is confidential; underlying facts, transactions, and documents are not—and offered its own illustrative list of shareable data (e.g., wire and transaction details, customer and account information, alerts, and investigative materials).
The Joint Statement essentially imports the Cross-Border Guidance’s reasoning into a new context: communications with the customer who is the subject of a potential SAR, rather than communications between institutions. The Joint Statement and the Cross-Border Guidance rely on the same regulatory hook (31 C.F.R. § 1020.320(e)(1)(ii)) and the same “reasonable and prudent person” standard, and both make the point that an ability to infer a SAR filing from the facts is not the same as a prohibited disclosure.
Read together, the two documents show a consistent regulatory direction: rather than treating SAR confidentiality as a reason for institutions to say as little as possible, the Agencies and FinCEN are encouraging banks to lean into the space the law already gives them, whether that means sharing information with a foreign affiliate to fight illicit finance, or explaining to a customer why their account was frozen. Neither the Joint Statement nor the Cross-Border-Guidance narrows SAR confidentiality; both simply clarify the boundaries of what falls outside it.
Next Steps for Banks
- Revisit customer-facing scripts and templates for fraud alerts, account restrictions, and closure notices to ensure they lean on permitted “underlying facts” language rather than defaulting to silence.
- Train frontline and fraud-investigation staff on the distinction between discussing facts (permitted) and confirming or denying a SAR filing (prohibited).
- Continue to make these calls on a case-by-case basis. The Joint Statement does not create a safe harbor, and documentation of the institution’s reasoning remains good practice.
- Consider whether the same underlying facts framework can support more effective cross-border and inter-institutional information sharing under the Cross-Border Guidance and the Section 314(b) safe harbor.
If you have questions about applying this guidance to your institution’s customer communications, fraud operations, or information-sharing practices, please contact any of the authors below.


