It’s a simple question with genuinely high stakes. On one side is the Bank Secrecy Act’s (BSA) strict prohibition on disclosing a Suspicious Activity Report (SAR), or any information that would reveal that a SAR exists to the subject of that report. On the other side is a very real operational tension: financial crimes investigators need to communicate with customers about potentially fraudulent transactions or other suspicious activity, about account closures, and about the steps being taken to protect them. For many institutions, uncertainty about where those boundaries lie has often led to a more cautious approach to customer communication.

On September 2, 2026, the Federal Reserve, FDIC, NCUA, OCC, and FinCEN issued a Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers, providing a clear, coordinated answer. The Agencies and FinCEN stated that the BSA does not prohibit banks and credit unions from communicating with a customer, or other third parties, including other institutions, about potentially fraudulent or suspicious transactions, or about the intention to close an account, so long as that communication does not reveal the existence of a SAR.

That single sentence resolves a question the industry has been asking for years.

Why FinCEN and the Banking Agencies Issued This Statement

This statement responds directly to industry feedback received through the Request for Information (RFI) on Potential Actions to Address Payments Fraud issued by the Board, FDIC, and OCC in June 2025. Commenters specifically asked for clarification on how banks can ensure compliance with SAR confidentiality requirements while still providing customers with transparent and timely communication as part of a fraud investigation — one that may result in SAR filings and a potential account closure.

Institutions told the regulators what those of us in the field already knew: the tension between SAR confidentiality and customer communication is a genuine operational problem, especially in the middle of an active fraud investigation when customers are demanding answers. The regulators listened.
Importantly, the statement does not alter existing BSA legal or regulatory requirements, nor does it establish new supervisory expectations. It’s clarification, not new law. But that clarification matters a great deal.

The Key Distinction: The SAR vs. the Underlying Facts

At the heart of the statement is a distinction that experienced BSA officers have long understood but that has been hard to operationalize consistently: the difference between the SAR itself and the underlying facts, transactions, and documents on which a SAR is based.

The BSA prohibits disclosure of a SAR or information that would reveal the existence of a SAR. That prohibition exists for good reason — unauthorized disclosure can undermine ongoing and future law enforcement investigations, deter institutions from reporting suspicious activity, and even endanger filers.

However, SAR confidentiality does not prevent an institution from discussing the underlying facts with a customer who may be the subject of a SAR or with third parties, including other banks and credit unions. Institutions may discuss transaction details, such as dates, amounts, and parties, provided the communication does not reveal that a SAR exists.

The statement even addresses the reasonable follow-up concern: even if a “reasonable and prudent person familiar with the SAR filing requirement may suspect or be able to deduce” from those underlying facts that a SAR was or may have been filed, the underlying information alone does not constitute information revealing the existence of a SAR for confidentiality purposes. That’s an important guardrail. The standard isn’t whether a sophisticated observer could guess that a SAR might exist — it’s whether your communication reveals it.

What Can Banks Say to Customers?

The statement offers a non-exhaustive list of communications that would not typically reveal the existence of a SAR. Institutions can:

  • Discuss the transaction(s) in question and the concerns raised by them
  • Discuss the institution’s remediation efforts
  • Discuss potential mitigation steps available to the customer
  • Provide warnings or educational resources to a customer about fraud schemes or typologies (the guidance specifically cites “money mule” schemes as an example)
  • Inform customers about account restrictions or closures, and tell them when a deposit has been rejected because of suspected fraud
  • Request customer due diligence-related information to understand customer relationships, and ask a customer about the purpose of a transaction or the source of funds

What you cannot do is disclose that a SAR has been filed, or phrase communications in a way that leads the customer to infer it. The guidance is explicit that communications should be considered on a case-by-case basis, with precautions taken when discussing information that could reveal the existence of a SAR.

Why Does SAR Confidentiality and Customer Communication Matter?

The statement comes at a critical time. Payments fraud, particularly check fraud, remains a persistent and growing challenge, while increasingly sophisticated schemes make customer communication during investigations more difficult. Fraud victims need clear, timely information. When customers may be knowingly or unknowingly involved in a scheme, institutions must still manage the relationship and account carefully and lawfully.

The statement makes clear that transparent and timely communication with customers during a fraud investigation is not just permissible, it’s part of doing the job well. The constraint is that the SAR itself stays confidential.

From Guidance to Practice: Operationalizing SAR Confidentiality

I previously wrote about the SAR FAQs, outlining that guidance only creates value when it’s translated into practice. So what does operationalizing this statement actually look like?

  1. Update your procedures
    If your fraud and investigation workflows default to “don’t communicate,” that default needs to be revisited against this new clarity. Customer-facing teams — especially those handling fraud claims and account closures — need clear, documented guidance on what they can discuss and how to phrase it.
  2. Maintain a strong audit trail
    Every decision around a SAR, including the decision not to file and the communications surrounding it should be documented. That’s not new; it’s good practice the regulators have consistently reinforced.
  3. Equip teams to recognize fraud typologies
    The guidance specifically calls out “money mule” schemes as an example of an appropriate educational communication. Investigators need to be able to identify those patterns, and systems need to identify them, before anyone can have a meaningful, compliant conversation with the customer.
  4. Lean into information sharing
    The statement reaffirms that SAR confidentiality doesn’t bar communication with other banks and credit unions about underlying facts.

“… under FinCEN’s implementing regulation for SAR confidentiality, “a SAR or any information that would reveal the existence of a SAR” does not include “the underlying facts, transactions, and documents upon which a SAR is based.”

That sits squarely alongside the updated 314(b) guidance FinCEN issued on June 12, 2026, which reframed the question from whether institutions can share information to whether they are equipped to do so at the speed and scale today’s threat environment demands.

The Bottom Line

For years, the SAR confidentiality rule has shaped how many institutions communicate with customers about suspicious activity. This statement corrects that position. Investigators can talk to customers about fraud, walk them through what financial institutions are seeing, explain concerns, and discuss next steps. You can close accounts and explain why but you cannot inform them about the SAR.

That distinction is now on the record, jointly, from the Federal Reserve, FDIC, NCUA, OCC, and FinCEN. For those of us who’ve been navigating this tension for years, it’s a welcome and long-overdue clarification and an opportunity to bring our customer communication in line with how fraud investigations work in practice.


Source link


administrator