SAR confidentiality creates a difficult communication challenge for banks. When suspicious or potentially fraudulent activity leads to an account restriction or closure, institutions must protect the confidentiality of any suspicious activity report. At the same time, they must communicate appropriately with their customers.
On 2 September 2026, FinCEN, the Federal Reserve, FDIC, OCC and NCUA issued a joint statement on SAR confidentiality and customer communication. As a result, banks and credit unions now have clearer guidance on where the line falls. SAR confidentiality requirements do not prohibit banks from communicating with customers about potentially fraudulent transactions or account closures. However, the communication must not reveal the existence of a SAR.
This distinction matters for every compliance officer, BSA analyst and frontline banker. In practice, concerns about SAR confidentiality and “tipping off” have contributed to cautious communication practices. Consequently, customers often receive limited information about account restrictions and closures.
Importantly, the clarification does not change the law. It also does not create new supervisory expectations. Instead, it addresses a practical question that has challenged banks for years. How much can an institution tell a customer without crossing the line into prohibited SAR disclosure? This article unpacks what the guidance says, where the boundaries remain and what your team should do now.
| Compliance area | Key clarification | Practical consideration |
|---|---|---|
| SAR confidentiality | Banks may not disclose a SAR or information that would reveal its existence | Customer communication must focus on underlying facts and circumstances |
| Customer communication | SAR confidentiality does not prohibit discussion of potentially fraudulent or suspicious activity | Assess each communication based on the facts and circumstances |
| Account restrictions and closures | Banks may communicate about restrictions or closures involving suspicious or fraudulent activity | Explanations must not reveal that a SAR was filed |
| Customer due diligence | Banks may seek information about transactions, purpose and source of funds | Customer outreach can support investigation and due diligence |
| Operational controls | The statement creates no new supervisory expectations | Institutions may review scripts, training and escalation processes |
The core dilemma: silence vs. transparency
For years, compliance teams have faced the same tension. When a bank identifies suspicious activity and files a SAR, the law prohibits disclosing that fact. Under 31 U.S.C. § 5318(g)(2), unauthorized disclosure may lead to regulatory, civil or criminal consequences. The severity depends on the circumstances and applicable law.
This rule exists for good reason. Telling a customer that a report was filed could compromise a law enforcement investigation. It could also encourage the destruction of evidence or put bank staff at risk.
However, this protection created an unintended side effect. Concerns about SAR confidentiality contributed to highly cautious communication practices at some institutions. As a result, when they froze an account or closed a relationship, they offered customers limited or no explanation. The assumption was simple: saying anything might cross the line into “tipping off.”
In turn, these cautious practices left customers with limited information about restrictions or closures. In some situations, suspicious activity may involve third-party fraud or compromised accounts. It may also involve transactions initiated without the customer’s knowledge.
What the guidance actually says about SAR confidentiality
The joint statement draws one core distinction. Banks cannot disclose a SAR or information that would reveal its existence. However, the facts, transactions and documents underlying a SAR are not SAR information solely because they formed the basis for the filing.
This distinction comes directly from FinCEN’s regulation at 31 C.F.R. § 1020.320(e)(1)(ii)(A)(2). Specifically, the regulation carves out “the facts, transactions and documents upon which a SAR is based” from the scope of SAR confidentiality. Therefore, the joint statement reinforces what the regulation has always permitted.
The statement then provides examples of communications that would not typically reveal a SAR’s existence. These depend on the facts and circumstances. For instance, banks may request customer due diligence information. They may notify a customer that a delay or closure relates to suspected fraud. They may also tell a customer that a deposit was rejected because it appears altered or counterfeit.
Furthermore, banks may ask about the purpose of a transaction or the source of funds. They may share warnings about fraud schemes. This includes situations where a customer may unknowingly act as a money mule. They may also explain policies related to account maintenance.
A customer might independently infer that suspicious activity could result in a SAR. That inference alone does not mean that discussing the underlying facts constitutes prohibited disclosure. Nevertheless, the institution must ensure that its communication does not reveal an actual SAR.
The agencies also emphasize that the joint statement does not create new legal requirements. It creates no new supervisory expectations either. It is guidance, not rulemaking. For institutions that already communicate transparently, nothing changes. For those that adopted cautious policies, this statement provides additional regulatory clarity.
Practical dos and don’ts for SAR confidentiality and customer communication
What compliance teams can do
The guidance clarifies that banks and credit unions may communicate about underlying facts, transactions and circumstances without automatically disclosing a SAR. For example, banks may communicate with customers about specific held or declined transactions through appropriate customer-facing personnel and processes. They may explain that a transaction is being reviewed because additional information or verification is required. Similarly, they can ask for source-of-funds documentation when a deposit raises questions.
Banks may also provide plain-language information about account restrictions or closures. This depends on the facts and circumstances. Crucially, the communication must not reveal the existence of a SAR. Institutions should ensure that specific explanations are consistent with the case and their legal, risk and communication policies.
In addition, compliance teams can use these interactions as part of ongoing customer due diligence. For instance, asking a customer to verify a wire transfer’s purpose is routine CDD. The joint statement confirms that SAR confidentiality requirements do not, by themselves, prevent banks from contacting customers. The key condition is that the communication does not reveal a SAR. Where appropriate, customer outreach may help the institution better understand the activity. It may also help document the customer’s explanation.
What remains strictly off-limits
The core prohibition has not changed. Absent an applicable statutory or regulatory exception, no employee may disclose that a SAR was filed or communicate information that would reveal its existence. Staff must also avoid language that directly or indirectly reveals a regulatory report. For example, phrases such as “we had to report this” or “this triggered a filing” could reveal that a report was submitted. Therefore, staff should avoid these phrases entirely.
As a matter of prudent AML and fraud control, institutions should also consider their monitoring disclosures. Telling a customer “transactions over a certain amount get flagged” reveals the institution’s surveillance mechanics. Consequently, that kind of detail could help bad actors structure transactions to avoid detection.
Similarly, staff should not speculate about law enforcement interest in a customer’s account. Such communications may be inappropriate for reasons independent of SAR confidentiality and could compromise an investigation. Even well-intentioned transparency has limits. These restrictions help protect the confidentiality of SAR reporting and the integrity of financial crime investigations.
Frontline reference: say this, not that
The following examples illustrate the difference between communications that could reveal a SAR and fact-based alternatives. These are not regulator-approved scripts. Instead, institutions may adapt them to their own policies and circumstances.
| Scenario | Avoid saying | Example fact-based communication |
|---|---|---|
| Transaction delay or wire hold | “We filed a confidential report with FinCEN about this transaction.” | “We have placed a temporary hold on this wire transfer to verify payment instructions and confirm source-of-funds details.” |
| Rejected or altered deposit | “Our AML software triggered an automatic threshold alert on your deposit.” | “We rejected this check deposit because the item appears altered or counterfeit.” |
| Information request (CDD) | “If you do not answer these questions, we will be forced to file a SAR on you.” | “We need additional documentation to better understand the purpose of this transfer and complete our review.” |
| Account closure | “Due to compliance triggers and confidential regulatory filings, we must close your account.” | “We have decided to close this account in accordance with our account terms and applicable policies. We can explain the account closure process and next steps.” |
| Law enforcement inquiries | “Federal authorities are currently investigating your transaction history.” | “We can explain the specific transaction restriction and what information we need to review it, but we cannot discuss confidential internal processes.” |
Action items for banks and credit unions
The joint statement is clear in its scope. However, turning guidance into practice requires deliberate effort. Compliance teams may wish to use the clarification as an opportunity to review several operational areas.
Update frontline staff scripts and training
Customer communication scripts and standard notices are often used for account restrictions and closures. In some institutions, these scripts may default to vague language such as “we are unable to continue this relationship.” The clarification may give banks greater confidence to communicate more specifically about underlying facts.
Training is equally important. Branch managers, call center staff and fraud investigators need to understand the line between discussing facts and disclosing a SAR. Role-based training scenarios can help staff understand how the principles apply in realistic situations. For instance, walk staff through examples: a customer calling about a frozen account, a business owner asking why a wire was held or a client questioning an account closure letter. Institutions may consider using a clear ‘say this, not that‘ framework to help staff apply these principles consistently.
Revise AML and fraud escalation protocols
Some institutions route customer inquiries about account restrictions to compliance or specialist teams. Depending on the escalation model, this approach may create bottlenecks or delay responses. The clarification may give institutions greater confidence when designing customer communication processes, including determining which communications may be handled by trained frontline personnel and which require escalation.
As a first step, review your escalation protocols. Identify which communications trained frontline staff can handle. Routine source-of-funds requests and standard transaction explanations may move through established frontline processes. On the other hand, more sensitive matters should follow the institution’s escalation procedures. This is particularly true for matters involving SAR confidentiality, law enforcement activity or legal restrictions.
Align customer due diligence outreach workflows
Customer due diligence does not stop at onboarding. Ongoing monitoring often generates questions that require customer contact. The joint statement confirms that SAR confidentiality requirements do not, by themselves, prevent this outreach.
When your monitoring system flags unusual activity, consider maintaining a documented process for customer contact. This serves two purposes. First, it strengthens your institution’s understanding of the customer’s activity profile. Second, a documented outreach process may help demonstrate how the institution gathers additional information as part of its risk-based compliance framework.
Frequently asked questions (FAQ)
Can a bank or credit union tell a customer that a SAR was filed?
No. Under the Bank Secrecy Act, disclosing a SAR or any information that would reveal a SAR is prohibited. This prohibition generally extends to the subject of the report and to other unauthorized persons. However, limited statutory and regulatory exceptions exist. Unauthorized disclosure may result in civil or criminal penalties.
What can a bank or credit union tell a customer about suspicious activity on their account?
Banks may communicate about the underlying facts, transactions and documents related to the suspicious activity. For example, they can explain that a transaction was held because it appeared inconsistent with normal activity. They can also explain that a deposit was rejected due to suspected fraud. However, they cannot reveal that a SAR was filed.
Does the September 2026 joint statement change the law?
No. The joint statement does not alter existing BSA legal or regulatory requirements. It also does not establish new supervisory expectations. Instead, it clarifies how existing SAR confidentiality requirements apply to certain customer communications about underlying facts and circumstances.
Can a bank or credit union explain why it is closing a customer’s account?
The joint statement clarifies that banks may communicate about account closures involving potentially fraudulent or suspicious activity. The key condition is that the communication does not reveal a SAR. The appropriateness of any specific explanation depends on the circumstances.
What this means for banks and credit unions
The September 2026 joint statement provides an important reminder. SAR confidentiality does not require institutions to remain silent about the underlying activity that affects a customer.
Banks may wish to use the clarification to review whether their communication practices are more restrictive than necessary. Customer-facing teams should understand the difference between discussing facts and disclosing a SAR. Meanwhile, compliance and legal teams should maintain appropriate controls for sensitive cases.
The objective is not unlimited transparency. Rather, it is better judgment. Banks and credit unions should provide customers with meaningful information where appropriate. At the same time, they must protect SAR confidentiality and the integrity of financial crime investigations. Ensure that policies, scripts and escalation processes provide appropriate guidance on what to communicate and when to escalate.
If your institution needs support reviewing its AML controls and customer communication processes in light of the latest regulatory guidance, Compliance7 offers a free initial consultation to help you get started.
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance or legal professional.



