September 3, 2026

06 min read

News / US Regulators Clarify SAR Confidentiality Rules for Customer Communications

US Regulators Clarify SAR Confidentiality Rules for Customer Communications

Federal agencies clarify how banks and credit unions can discuss suspected fraud, account restrictions, and closures without disclosing SAR filings.

06 min read

The Federal Reserve, FDIC, FinCEN, NCUA, and OCC have issued a joint statement clarifying how banks and credit unions can communicate with customers about potentially fraudulent or suspicious activity without violating the confidentiality requirements of Suspicious Activity Reports (SARs).

Published on September 2, 2026, the statement addresses concerns raised by financial institutions following a 2025 request for information on payment fraud, particularly check fraud. Commenters had asked regulators to clarify how banks could maintain transparent customer communication when a fraud investigation may result in a SAR filing, account restrictions, or account closure.

The agencies emphasized that the statement does not create new BSA requirements or supervisory expectations. Instead, it explains how existing SAR confidentiality rules apply when financial institutions communicate with customers.

What SAR Confidentiality Requires

Under the Bank Secrecy Act, financial institutions cannot disclose a SAR or information that would reveal that a SAR has been filed to the customer or another person who is the subject of the report.

Regulators explained that this confidentiality requirement is intended to protect law enforcement investigations, prevent potential suspects from being alerted, encourage financial institutions to continue reporting suspicious activity, and protect individuals involved in SAR reporting.

However, the agencies highlighted an important distinction: the underlying facts, transactions, and documents supporting a SAR are not themselves considered confidential SAR information.

This means banks and credit unions may generally discuss relevant transaction information with customers, including transaction dates, amounts, counterparties, and other factual details, provided the communication does not reveal the existence of a SAR.

What Banks Can Discuss With Customers

The joint statement provides several examples of customer communications that would typically not violate SAR confidentiality.

Financial institutions may request customer due diligence information or documentation to understand the nature and purpose of a relationship and develop a customer risk profile. They may also ask customers about the purpose of a transaction or the source of funds.

Banks and credit unions may notify customers that an account, deposit, transaction, or service has been delayed, restricted, rejected, or terminated because of suspected fraud or other suspicious activity. This includes situations involving altered or counterfeit checks.

Institutions can also provide customers with warnings and educational resources on fraud typologies, including money mule schemes, in which individuals may knowingly or unknowingly receive or transfer illicit funds.

Similarly, banks may communicate policies or decisions regarding account maintenance and services, including the decline of transactions or the closure of accounts. They can also request information about the originator or beneficiary of a funds transfer.

The agencies stressed that customer communication should be assessed on a case-by-case basis, with appropriate precautions to ensure that information does not indirectly disclose the existence of a SAR.

Why It Matters for AML Compliance

The clarification provides financial institutions with greater certainty as they balance two important obligations: maintaining SAR confidentiality while communicating transparently with customers during fraud investigations and account decisions.

For compliance teams, the distinction between SAR information and underlying transactional facts is particularly important. Staff can discuss suspicious transactions and request supporting information without necessarily disclosing whether a SAR has been filed.

This also reinforces the importance of employee training, documented communication procedures, and coordination among fraud, AML, compliance, and customer service teams.

Compliance Takeaway

Banks and credit unions should review customer communication procedures to ensure employees understand what can be discussed during fraud investigations, account restrictions, and closures. Controls should prevent direct or indirect disclosure of the existence of SARs while allowing appropriate discussion of underlying transactions, customer information, and remediation measures.

The statement ultimately reinforces that SAR confidentiality does not prevent financial institutions from engaging with customers about suspected fraud. The key requirement is to ensure that those communications do not reveal the existence of a SAR.

CRO

Tired of False Positives? Try TruRisk.

70–80% less manual work, 95% less fatigue, TruRisk Agent makes compliance effortless.

Experience Agentic AML
Contact Us
Category

Industry

Published Date

September 3, 2026

Subscribe to our Newsletter

Our best articles, news and stories, delivered to your inbox every week.