Skip to main content

Federal Agencies Clarify What Banks May Tell Customers and Other Third Parties About Suspected Fraud and SARs

On Sept. 2, 2026, the Federal Reserve, Federal Deposit Insurance Corporation, Financial Crimes Enforcement Network (FinCEN), National Credit Union Administration (NCUA) and Office of the Comptroller of the Currency (OCC) (collectively, the Agencies) issued a joint statement regarding Suspicious Activity Report (SAR) confidentiality. The statement clarifies that SAR confidentiality generally does not prevent banks, savings associations, foreign banks operating in the United States, and credit unions (collectively, banks) from discussing suspected fraud or other suspicious transactions with customers, including customers who may be the subject of a SAR, and other third parties. Banks may also notify customers that an account restriction or account closure is related to suspected fraud or other suspicious activity, provided the communication does not reveal that a SAR was filed or will be filed.

The Agencies issued the joint statement partly in response to concerns about bank personnel’s ability to communicate with customers when a SAR was filed in connection with suspicious activity. The statement also addresses concerns expressed in Executive Order 14331 (Guaranteeing Fair Banking for All Americans), regarding transparency, customer engagement, and fair access to financial services. According to the Agencies, the statement is intended to clarify existing requirements and does not change Bank Secrecy Act (BSA) legal or regulatory requirements, nor does it “establish new supervisory expectations.”

The joint statement’s scope appears to be directed at bank communications specifically, as it does not address its application to non-bank financial institutions that have their own SAR confidentiality obligations, such as money services businesses and casinos. Nevertheless, the clarification may reduce uncertainty for banks when communicating with customers and other third parties about suspected fraud or other suspicious activity.

What Institutions May Discuss

The BSA strictly prohibits the disclosure of a SAR or information that would reveal its existence, especially to the subject of the SAR. The BSA’s confidentiality provision was intended to ensure that SAR disclosures do not tip off potential suspects, compromise law enforcement investigations, endanger those who file reports, or discourage banks and financial institutions from reporting suspicious activity.

In the joint statement, the Agencies emphasized that SAR confidentiality does not prevent banks from discussing the underlying facts, transactions, and documents upon which a SAR is based, even if a reasonable and prudent person familiar with the SAR filing requirement may suspect or deduce that a SAR was filed. In particular, a bank may discuss relevant transaction dates, amounts and parties, so long as those communications do not disclose the SAR or otherwise reveal its existence.

The joint statement gives non-exhaustive examples of communications that would not typically reveal a SAR, including:

  • Requesting customer due diligence information or documents;
  • Asking about a transaction’s purpose or the source of funds;
  • Asking for information about a funds-transfer originator or beneficiary;
  • Notifying a customer that a deposit was rejected because of suspected fraud, such as a potentially altered or counterfeit check;
  • Notifying a customer that a delay, limitation, or restriction on an account may be related to suspicious activity;
  • Explaining that a delay, restriction, service limitation, or account closure may be related to suspected fraud or other suspicious activity; and
  • Providing fraud warnings or educational materials, including about money-mule schemes.

The Confidentiality Boundary Remains

Despite promoting open communication, the joint statement does not alter the strict liability for unauthorized disclosures of a SAR. Under the BSA, banks are still prohibited from disclosing a SAR or information that would reveal its existence. The BSA also prohibits banks from notifying a person that their involvement in a transaction was reported. Violations may trigger civil money penalties against both the bank and individual employees and may also carry criminal penalties. Accordingly, banks should consider focusing their communications on their observations, concerns, policies, or actions, and not on whether a SAR was filed, is being considered, or may be filed.

The joint statement recommends assessing customer communications on a case-by-case basis and taking precautions where the information or wording might reveal a SAR’s existence.

Practical Considerations

Banks, especially those dealing with business-to-business fraud, vendor management, or their own banking relationships, may wish to review customer-service, fraud-investigation, and account-closure procedures to confirm they do not prohibit or restrict factual customer communications but simultaneously emphasize SAR confidentiality.

Internal fraud investigators and customer-facing employees remain bound by BSA confidentiality requirements. That means limiting discussions on a need-to-know basis to transaction details, timeliness, and documents, while maintaining strict confidentiality around regulatory filings. Banks may wish to consider retraining their employees on these practices.

Banks should consider confirming that information about SAR filings remains with the appropriate personnel and departments handling SAR filings. They may also wish to train front-line employees on communicating the approved facts and reasons behind account actions — and on escalating questions to the appropriate parties beyond those parameters. Accordingly, banks should consider documenting the factual basis for account closure or restriction decisions separately from any SAR filings. This may help front-line employees communicate with customers without referencing SAR information/filings. 

The joint statement confirms that SAR confidentiality does not prevent banks from initiating direct, detailed inquiries while investigating potentially fraudulent or other suspicious activity, provided those efforts do not reveal the existence of a SAR. Such inquiries may include requests to verify vendor legitimacy or the economic purpose of sudden, large, or cross-border transactions, as well as requests to establish the operational or documentation thresholds a customer must meet to maintain account activity.

Expectations for corporate treasury teams may be affected by this increased transparency. Banks’ compliance inquiries may now discuss suspicious anomalies, including specific transaction dates, exact wire amounts, and named counterparties. As such, corporate treasury teams should consider maintaining clear documentation around high-value or unusual transactions to avoid delayed responses that could be interpreted as risk factors.

Bottom Line

The Agencies’ joint statement promotes communication with customers and other third parties about suspected fraud and related account actions. However, it does not relax the prohibition on disclosing a SAR or information that reveals its existence.