Regulators Clarify SAR Confidentiality in Customer Communications
New joint guidance from FinCEN and federal banking agencies confirms that financial institutions may discuss the facts underlying suspicious activity with customers, provided they do not disclose the existence of a SAR.
On September 2, 2026, the Financial Crimes Enforcement Network (FinCEN) and federal banking agencies including the Fed, FDIC, and OCC issued a joint statement clarifying the application of Suspicious Activity Report (SAR) confidentiality to customer communications. The guidance affirms that the Bank Secrecy Act does not prohibit banks from discussing underlying facts, transactions, or documents with customers, even if those details form the basis of a SAR.
The statement addresses a persistent challenge for financial institutions: how to manage accounts and communicate with customers about potential fraud without illegally disclosing that a SAR has been filed. Violating SAR confidentiality can lead to civil penalties and other risks. The guidance provides a non-exhaustive list of permissible communications, such as asking about a transaction's purpose, notifying a customer of an account closure due to suspicious activity, or requesting due diligence information. Sophisticated counsel should advise clients to review and update their internal policies, procedures, and training materials to ensure customer-facing personnel can effectively communicate about fraud risks while carefully avoiding any disclosure of a SAR itself.