US Regulators Clarify SAR Confidentiality Rules for Customer Communications
Five federal financial agencies have jointly clarified the application of Suspicious Activity Report confidentiality rules to customer communications, addressing a key area of compliance uncertainty.
On September 2, 2026, five U.S. financial regulators—the Federal Reserve, FDIC, NCUA, OCC, and FinCEN—issued a joint statement clarifying the confidentiality rules surrounding Suspicious Activity Reports (SARs). The guidance focuses on how financial institutions can communicate with customers about accounts or transactions that may be the subject of a SAR filing without unlawfully disclosing confidential information.
Violating SAR confidentiality can result in severe civil and criminal penalties for both institutions and individuals. This creates a difficult challenge for banks, which must manage customer relationships—including account closures or restrictions—while adhering to the strict prohibition on tipping off customers about SAR filings. The new interagency guidance provides a clearer framework for navigating these sensitive communications, aiming to reduce compliance risk and uncertainty.
Financial institutions and their counsel should immediately review the clarification and assess its impact on their existing policies, procedures, and employee training for handling customer inquiries or account terminations related to suspicious activity. The guidance will likely become the standard by which examiners and enforcement agencies judge a firm's conduct in this area.