On September 2, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”), the Board of Governors of the Federal Reserve System (“Federal Reserve”), the Federal Deposit Insurance Corporation (“FDIC”), the National Credit Union Administration (“NCUA”), and the Office of the Comptroller of the Currency (“OCC”) issued a joint statement on a question that has long vexed financial institutions: how much can a bank tell a customer once the customer is the subject of a Suspicious Activity Report (“SAR”)? The answer: likely more than some institutions have considered permissible.
The joint statement addresses SAR confidentiality under the Bank Secrecy Act (“BSA”) as applied to bank and credit union communications with customers about potentially fraudulent transactions, other suspicious activity (including check fraud), or account closures. It does not alter existing BSA requirements or create new supervisory expectations. Rather, the joint statement follows a June 2025 request for information from the public issued by the Federal Reserve, FDIC, and OCC concerning payments fraud. In response, commenters raised concerns about the ability of bank personnel to communicate with customers when a bank may file or has filed a SAR concerning potentially fraudulent activity. It also reflects concerns raised in Executive Order 14331, Guaranteeing Fair Banking for All Americans, which directed federal banking regulators to remove from supervisory materials the use of “reputation risk” – or equivalent concepts – that could result in unlawful debanking. Instead, the Administration announced a policy that banking decisions should be based on “individualized, objective, and risk-based analyses” rather than a customer’s political or religious beliefs or lawful business activities.
The Key Distinction
Subject to limited carve-outs, the BSA and its implementing regulations prohibit disclosing a SAR, or information that would reveal the existence of a SAR, to a customer or other person who is the subject of the SAR. But FinCEN’s implementing regulations exclude from the prohibition “the underlying facts, transactions, and documents upon which a SAR is based.” That distinction is the heart of the guidance: banks and credit unions may discuss the underlying facts, transactions, and documents (including dates, amounts, and parties) with a customer or with third parties, including other banks or credit unions, and may notify a customer of an intended account closure for suspected fraud or other suspicious activity, provided the communication does not reveal the existence of a SAR. Banks and credit unions should make those determinations on a case-by-case basis and take precautions when discussing information that could reveal a SAR’s existence. This holds even if a reasonable and prudent person familiar with SAR requirements might suspect or deduce that one was filed; the underlying information alone cannot reveal the existence of a SAR.
Communications Typically Permitted
Banks and credit unions may file a SAR without taking any action on a customer account. When action is taken, communications with customers are typically minimalist. But the joint statement provides examples of communications, including due diligence questions, that would not run afoul of the confidentiality requirement. The joint statement provides a non-exhaustive list of customer communications that typically would not reveal a SAR’s existence:
- Requesting due diligence information to understand a customer relationship.
- Notifying a customer that an account or service delay, restriction or closure, or a rejected deposit, may relate to suspected fraud or other suspicious activity.
- Inquiring about the purpose of a transaction or source of funds.
- Providing fraud-related warnings or educational resources.
- Communicating policies or account decisions, such as declining a transaction or closing an account, or requesting originator or beneficiary information on a funds transfer.
Practical Takeaways
Banks may consider:
- Updating training materials and internal guardrails to reflect the agencies’ clarification that discussing underlying facts, transactions, and documents with customers does not violate SAR confidentiality.
- Revising correspondence, i.e., account-closure notices, to remove unnecessarily restrictive language driven by SAR-related concerns.
- Coordinating with fair-banking teams responsible for compliance with Executive Order 14331’s focus on prohibiting politicized or unlawful de-banking.
- Reassessing policies on inter-institutional information sharing.
- Evaluating other applicable restrictions on information sharing, including privacy and other federal or state law requirements.
Bottom Line
Financial institutions should treat the joint statement as an opportunity to reassess customer communication practices and modify, as appropriate, unnecessarily restrictive interpretations of SAR confidentiality. The joint statement gives institutions substantially more clarity on permissible communications regarding suspicious transactions and account actions without violating SAR confidentiality, while preserving the fundamental rule that neither a SAR nor information revealing its existence may be disclosed.
McGuireWoods will continue to monitor developments and publish updates as new guidance is issued. For questions about SAR confidentiality or anti-money laundering compliance generally, contact the authors of this article or another McGuireWoods attorney you work with.