Issued September 2, 2026, the Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers confirms that suspicious activity report (SAR) confidentiality and customer communication are not mutually exclusive. The statement was issued by the Financial Crimes Enforcement Network (FinCEN), the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC).
Financial institutions have long had to balance two important responsibilities: protecting the confidentiality of SARs while communicating with customers when transactions raise concerns about fraud or other suspicious activity.
The statement clarifies that SAR confidentiality does not prevent banks and credit unions from communicating with customers about potentially fraudulent or suspicious transactions, account restrictions, or even potential account closures, as long as those communications do not reveal the existence of a SAR.
What Financial Institutions Can Tell Customers
The joint statement provides several examples of communications that typically do not reveal the existence of a SAR.
A financial institution may, for example, notify a customer that a deposit was rejected because of suspected fraud, ask about the source of funds, request information needed to understand the nature and purpose of the relationship, or provide educational information about fraud schemes and money mule activity.
Institutions may also communicate policies or decisions related to account maintenance, including declining transactions or closing accounts.
This distinction can be particularly important when an institution is investigating potentially fraudulent activity.
Instead of simply telling a customer that information cannot be discussed because of SAR confidentiality, institutions can focus on the underlying activity and appropriate risk-management actions without confirming or denying whether a SAR exists.
What SAR Confidentiality Protects
The Bank Secrecy Act (BSA) prohibits financial institutions from disclosing a SAR or information that would reveal that a SAR has been filed to the customer or other person who is the subject of the SAR.
That confidentiality requirement serves an important purpose. Revealing a SAR could alert potential suspects, interfere with law enforcement investigations, discourage financial institutions from reporting suspicious activity, and potentially put SAR filers at risk.
However, the regulators emphasize an important distinction: the underlying facts, transactions, and documents supporting a SAR are not themselves considered the SAR.
That means institutions can generally discuss relevant factual information with customers without disclosing that a SAR was filed or may be filed.
For example, institutions may be able to discuss:
- The date or amount of a transaction
- The parties involved in a transaction
- Questions about the purpose of a transaction
- The source of funds
- Requests for additional customer due diligence information
- Concerns about potentially fraudulent transactions
- Reasons for declining or restricting a transaction
- Potential account closures related to suspected fraud or suspicious activity
The critical consideration is how that information is communicated and whether the conversation reveals the existence of a SAR.
Saying Enough Without Saying Too Much
The joint statement specifically encourages institutions to approach customer communications on a case-by-case basis and take precautions when discussing information that could reveal the existence of a SAR.
This creates an important operational consideration for compliance teams.
Policies and procedures should help employees understand the difference between saying enough and saying too much.
Saying Enough: “We need additional information regarding the source of funds for this transaction.” (Focuses on the underlying transaction and the institution’s due diligence process.)
Saying Too Much: “We filed a SAR regarding this transaction.” (Directly discloses the existence of a SAR.)
Clear procedures and employee training can help ensure that communications remain consistent with SAR confidentiality requirements.
What This Means for AML/CFT Programs
BSA requirements have not changed existing SAR confidentiality rules. Instead, the statement provides clarity around how existing requirements apply to customer communications.
For financial institutions, this is an opportunity to review how SAR confidentiality is addressed throughout the compliance program.
Consider reviewing:
- Policies and procedures: Do your AML/CFT procedures clearly explain what employees can and cannot communicate about suspicious activity?
- Employee training: Are customer-facing employees trained to distinguish between discussing underlying transactions and disclosing SAR information?
- Case management: Are fraud, AML/CFT, and customer-service teams aligned on how suspicious activity is communicated?
- Customer due diligence: Do your procedures provide appropriate guidance for requesting additional information about transactions, source of funds, or the nature and purpose of a relationship?
- Account restrictions and closures: Do your communications explain applicable decisions without inadvertently revealing SAR information?
- Documentation: Are customer interactions and compliance decisions appropriately documented in monitoring logs?
For MSBs, these considerations are especially relevant. Suspicious transactions can involve multiple parties, agents, financial institutions, and customers, making clear communication protocols an important part of an effective AML/CFT program.
The Bottom Line
SAR confidentiality remains a critical component of the BSA framework, but confidentiality does not mean silence.
The September 2026 joint statement gives financial institutions greater clarity that they can communicate with customers about suspicious or potentially fraudulent activity, ask questions, request documentation, explain certain transaction restrictions, and communicate account decisions without violating SAR confidentiality, provided they do not disclose the existence of a SAR.
Effective AML/CFT compliance requires more than identifying suspicious activity and filing SARs. It also requires having the policies, procedures, training, and oversight necessary to manage what happens before, during, and after a SAR decision.
Capital Compliance Experts can help financial institutions evaluate their AML/CFT program, employee training, and annual compliance oversight to help keep pace with evolving regulatory expectations.
Tags: AML, AML/CFT Program, Anti Money Laundering, Bank Secrecy Act, BSA, Financial Crimes Enforcement Network, FinCEN, Money Services Business, MSB, SAR, Suspicious Activity Report