FinCEN and four federal regulators clarified SAR confidentiality on 2 September 2026. What banks may now tell customers about fraud and account closures.
Table of contents
On 2 September 2026, FinCEN and four federal regulators confirmed that SAR confidentiality does not stop a bank telling a customer that an account may be closing because of suspected fraud or other suspicious activity. The statement changes no law. It answers commenters who asked how to reconcile SAR compliance with timely customer communication during a fraud investigation.
- FinCEN issued the statement on 2 September 2026 with the Federal Reserve, FDIC, NCUA and OCC, and it creates no new rule and no new supervisory expectation.
- The pivot is an existing carve-out: SAR confidentiality does not cover the underlying facts, transactions and documents on which a report is based.
- Banks may discuss transaction dates, amounts and parties, and may say a closure may relate to suspected fraud or other suspicious activity.
- The same permission covers third parties, including other banks and credit unions, which matters most for check fraud recovery.
- It covers only "banks" as defined at 31 CFR 1010.100(d). MSBs, broker-dealers, casinos and crypto filers report under separate rules and are not addressed.
What did the agencies say about SAR confidentiality?
The Board of Governors of the Federal Reserve System, the FDIC, the NCUA and the OCC, together with FinCEN, published a joint statement on 2 September 2026 clarifying how SAR confidentiality applies when a bank talks to its own customer. The document is guidance, not a rule. It says plainly that it "does not alter existing Bank Secrecy Act (BSA) legal or regulatory requirements or establish new supervisory expectations."
Read the operative sentence exactly. Banks may communicate with the subject of a report, and with third parties including other banks and credit unions, about suspicious transactions, and may give notice of an intended closure, "so long as that communication does not reveal the existence of a SAR." SAR confidentiality attaches to the disclosure, not to the subject matter. The third-party limb is easy to miss and matters most for check fraud recovery.
The statement then lists communications, expressly non-exhaustive, that would not typically reveal a report exists.
| Communication the agencies list as typically permitted | What it touches |
|---|---|
| Requesting due diligence information to build a customer risk profile | [Customer due diligence](/resources/glossary/customer-due-diligence-cdd) |
| Notifying a customer that a delay, limitation, restriction or closure may relate to suspected fraud or other suspicious activity | Account actions |
| Notifying a customer that a deposit was rejected for suspected fraud or other suspicious activity, such as an altered or counterfeit check | Payments operations |
| Asking a customer the purpose of a transaction or the source of funds | Investigation |
| Providing fraud warnings or education, including on money mule typologies | Customer protection |
| Communicating policies or decisions on account maintenance, services or closure | Service decisions |
| Requesting information on the originator or beneficiary of a funds transfer | Wire operations |
The trigger was a request for information the Federal Reserve, OCC and FDIC published on 20 June 2025 at 90 FR 26293, aimed at payments and check fraud. Commenters asked the agencies to clarify how a bank can meet SAR confidentiality duties and still communicate with a customer during a fraud investigation. The agencies also tie the statement to Executive Order 14331, Guaranteeing Fair Banking for All Americans, published at 90 FR 38925 on 12 August 2025.
One limit sits only in a footnote. The statement addresses "banks" as defined at 31 CFR 1010.100(d). Money services businesses, broker-dealers and casinos file under 31 CFR 1022.320, 1023.320 and 1021.320, which carry parallel wording but were not covered here. Crypto firms registered as MSBs sit in that excluded group as well.
Why did banks go quiet in the first place?
Over-correction, and a SAR confidentiality statute with no safety valve. The Bank Secrecy Act at 31 U.S.C. 5318(g)(2)(A)(i) bars a filer from notifying "any person involved in the transaction that the transaction has been reported." No test of harm is attached. Because the prohibition bites regardless of consequence, many institutions defaulted to silence.
The scale explains the caution. Depository institutions filed 2,037,214 reports in 2024, per FinCEN's SAR Stats, against 839,314 in 2014. Silence as a default therefore touches millions of customer relationships a year, many of them victims rather than suspects.
The way out was already in the regulation. Under 31 CFR 1020.320(e)(1)(ii)(A)(2), the protected category excludes "the underlying facts, transactions, and documents upon which a SAR is based." That carve-out has been in force since FinCEN's 2010 confidentiality final rule at 75 FR 75593.
This is also the second time in a year FinCEN has leaned on it. Guidance FIN-2025-G001, issued on 5 September 2025, applied the same reasoning to cross-border sharing between institutions. Restating one carve-out twice in twelve months shows how firmly the silence had set.
| Milestone | Date | Effect on SAR confidentiality |
|---|---|---|
| BSA notification prohibition, 31 U.S.C. 5318(g)(2) | In force | Bars telling anyone involved that a transaction was reported |
| FinCEN confidentiality final rule, 75 FR 75593 | 3 December 2010 | Adds the underlying-facts carve-out at 31 CFR 1020.320(e) |
| Payments fraud request for information, 90 FR 26293 | 20 June 2025 | Commenters ask the agencies to clarify customer communication |
| Executive Order 14331, 90 FR 38925 | 12 August 2025 | Raises fair access and transparency in account terminations |
| Guidance FIN-2025-G001 | 5 September 2025 | Applies the carve-out to cross-border information sharing |
| Reputation risk rules, 91 FR 18279 and 91 FR 38270 | 10 April and 25 June 2026 | Constrain supervisory pressure to terminate relationships |
| Joint statement on SAR confidentiality | 2 September 2026 | Confirms the carve-out permits customer communication |
Note what the statement concedes. A reasonable and prudent person familiar with the filing requirement may deduce from the underlying facts that a report was made, and that deduction alone is not a disclosure. It does not touch the filing duty, the deadlines, or the transaction monitoring behind the report.
What changes for your BSA obligations?
Nothing in the filing regime moves. SAR confidentiality governs what leaves your building, not what you detect or report. That distinction decides which controls you rewrite.
Customer due diligence gains room. The agencies list requesting due diligence information to understand a relationship's nature and purpose as typically permitted. Teams that stopped asking follow-up questions once an alert escalated, fearing a breach of SAR confidentiality, can restore that step and evidence the risk profile under the Bank Secrecy Act.
Filing duties are untouched. The 5,000 dollar threshold at 31 CFR 1020.320(a)(2), the 30 calendar day clock from initial detection, its extension to no later than 60 days where no suspect is identified, and narrative quality all sit where they were, as does the scrutiny visible in the Merrill transaction monitoring penalty.
Bank-to-bank contact is the operational prize. Because the permission extends to other institutions, a receiving and an originating bank can compare transaction facts during check fraud recovery. Section 314(b) remains the separate route for sharing that goes further.
Account closure changes most. A notice saying a closure may relate to suspected fraud or other suspicious activity is not by itself a prohibited disclosure. Closure letters, exit scripts and holding statements need review; most were drafted to say nothing.
Record-keeping gains an artefact, and it inherits a known retention period. Under 31 CFR 1020.320(d) a bank keeps the report and its supporting documentation for five years from filing. A log of who approved customer wording, and why, belongs with it. Your regulator's own SAR rule sits alongside FinCEN's: 12 CFR 208.62(j) for the Federal Reserve, 12 CFR 353 for the FDIC, 12 CFR 748.1(d) for the NCUA, and 12 CFR 21.11(k) and 163.180(d) for the OCC.
Sanctions work does not move with it. A blocking or rejection notice under an OFAC programme sits in a different regime with its own duties. Reading SAR confidentiality across into sanctions screening messaging would be an error.
What is still uncertain about SAR confidentiality?
Start with the case for the prohibition, which the agencies restate. Unauthorised disclosure can undermine investigations, deter filing, and even endanger SAR filers. Those are real costs any argument for talking more must clear.
The largest practical risk is that operators read the headline and miss the condition. The rule of construction opens with a proviso: it applies "Provided that no person involved in any reported suspicious transaction is notified that the transaction has been reported." A script that says "we have filed a report" fails, whatever else it discusses.
One script cannot serve two populations. The agencies' own money mule bullet concedes that a customer may be participating in a fraud scheme knowingly or unknowingly. The same disclosure that gives a victim an explanation hands a witting mule the dates, amounts and counterparties under examination. The statement offers no way to tell them apart, so segmentation by suspicion posture has to happen before the call, not during it.
Guidance on SAR confidentiality is not a rule. This went out without notice and comment, so it confers no safe harbour, and it can be withdrawn as easily as it was issued.
Civil exposure needs naming rather than assuming. The limitation on liability at 31 U.S.C. 5318(g)(3), carried into 31 CFR 1020.320(f), protects an institution for making a disclosure to government and for failing to notify the subject of it. It attaches to the report, not to what a bank volunteers to a customer instead. A closure letter that names suspected fraud therefore carries defamation and contract exposure the BSA does not answer.
Finally, the policy pull runs both ways at once. Executive Order 14331 and the reputation risk rules push toward explaining terminations, while the notification prohibition still pushes toward silence. Supervisors ask for transparency in the same period they tighten how BSA findings get cited, a shift covered in the new matters requiring attention rule and the risk-based AML program rule.
How does the US rule compare with the UK tipping off offence?
The UK tipping off offence is strictly narrower, because it stacks a harm filter on top of the US test. Section 333A(1) of the Proceeds of Crime Act 2002 requires both that the person discloses that a report was made and that the disclosure "is likely to prejudice any investigation" which might follow. The US prohibition has only the first limb, which is why a clarification of SAR confidentiality was needed at all.
| Feature | United States | United Kingdom |
|---|---|---|
| Instrument | 31 U.S.C. 5318(g)(2); 31 CFR 1020.320(e) | Proceeds of Crime Act 2002, s.333A |
| Test | Reveals the existence of a report | Reveals a report was made and is likely to prejudice an investigation |
| Harm element | None | Required |
| Separate offence | None equivalent | s.333A(3), prejudicial disclosure that a Part 7 investigation is contemplated or under way |
| Stated penalty | Not set out in the confidentiality rule | Up to two years on indictment, or three months summarily |
| Route for facts | Underlying facts carve-out at 1020.320(e)(1)(ii)(A)(2) | Facts fall outside s.333A(2) entirely; s.333B to s.333D add entity-scoped gateways |
Note the trap for a group harmonising scripts. Section 333A(3) separately criminalises disclosing that a Part 7 investigation is contemplated or under way, where that is likely to prejudice it, so the reassuring line "this is now with the authorities" risks the UK offence and breaches the US proviso at once. Harmonise to the stricter reading.
How should compliance teams respond?
Compliance teams should re-audit outbound customer language first, starting with closure letters, rejection notices, hold messages and exit scripts. Sort each sentence into two buckets: transaction facts, which are permitted, and anything signalling a filing, which is not. Delete the second rather than softening it.
Then build the phrase bank the statement actually authorises. It says staff could discuss the transactions in question, the bank's "remediation efforts, and what potential mitigation steps are available to the customer." Give the front line that wording rather than open discretion, but note the agencies still want case-by-case judgement and precautions. Define who escalates a non-standard request, and log the outcome. Train fraud operations and the BSA team together, since that split breeds inconsistent language, and re-test vendor templates, which often ship with empty closure reasons.
Zyphe sits upstream of this problem. Our AML software keeps an exportable audit trail of what was verified and when, exactly the artefact a wording-approval log points at, so an officer can evidence the factual basis of a conversation without reaching into filing records. As our primer on decentralised KYC explains, personal data is sharded across more than 60,000 nodes under a 29-of-100 threshold scheme with a customer-held key, so that record never becomes another store of identity documents. Book a demo to see the audit trail.
The bottom line
This is a clarification, not a liberalisation, and the difference matters when you brief the front line. Five agencies have removed SAR confidentiality as an excuse for saying nothing, moving the burden from silence to precision. Teams must now say the right amount, in writing, to customers who are often victims rather than suspects, and sometimes neither. That is harder than a blanket no comment, and it will be judged on individual sentences. Rewrite the scripts, log the judgement calls, and keep the two buckets of language apart.
Cited sources
- Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers, 2 September 2026
- FinCEN news release announcing the joint statement
- 31 CFR 1020.320, including the confidentiality carve-out at paragraph (e)(1)(ii)(A)(2)
- 31 U.S.C. 5318, including the notification prohibition at (g)(2) and the limitation on liability at (g)(3)
- FinCEN guidance FIN-2025-G001, Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality, 5 September 2025
- Confidentiality of Suspicious Activity Reports final rule, 75 FR 75593
- FinCEN SAR Stats, SAR filings by industry filing trend data
- Request for Information on Potential Actions To Address Payments Fraud, 90 FR 26293
- Executive Order 14331, Guaranteeing Fair Banking for All Americans, 90 FR 38925
- Prohibition on the Use of Reputation Risk by Regulators, 91 FR 18279
- Prohibition on the Use of Reputation Risk, 91 FR 38270
- Proceeds of Crime Act 2002, section 333A, tipping off in the regulated sector
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.