US Financial Regulators Clarify SAR Confidentiality Requirements
Alexandria, VA (September 2, 2026) The Board of Governors of the Federal Reserve System (Federal Reserve), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC) (collectively, the Agencies), and the Financial Crimes Enforcement Network (FinCEN) are issuing this statement to clarify confidentiality requirements related to Suspicious Activity Reports (SARs), particularly when banks 1 communicate with their customers regarding potentially fraudulent transactions, other suspicious activity (e.g., payment fraud, including check fraud), or account closures. This statement does not alter existing Bank Secrecy Act (BSA) legal or regulatory requirements or establish new supervisory expectations. On June 20, 2025, the Federal Reserve, FDIC, and OCC issued a request for information (RFI) on potential actions to help consumers, businesses, and financial institutions mitigate the risk of payments fraud, with a particular focus on check fraud. 2 In response, commenters raised a variety of concerns, including on bank personnel’s ability to communicate with a customer when a bank may file or has filed a SAR on potentially fraudulent activity. Specifically, commenters requested the Agencies and FinCEN clarify how banks can ensure compliance with SAR confidentiality requirements and provide customers with transparent and timely communication as part of the bank’s fraud investigation, which may result in one or more SAR filings and potential closure of a customer’s account. This joint statement also recognizes the concerns expressed in Executive Order 14331, Guaranteeing Fair Banking for All Americans. 3 By facilitating improved transparency over bank actions with respect to customer accounts, the Agencies intend for this statement to enhance customer engagement and provide customers with greater assurance that their banks and credit unions will provide them with fair access to financial services. SAR confidentiality is a statutory and regulatory requirement that helps to ensure that SAR information is disclosed only for appropriate purposes. The BSA prohibits the disclosure of a SAR or information that would reveal the existence of a SAR, including to a customer or other person who is the subject of the SAR. 4 Unauthorized disclosure of a SAR to that person, and any information that would reveal the existence of a SAR to that person, could undermine ongoing and future law enforcement investigations by alerting potential suspects, deterring financial institutions from reporting suspicious activity and filing SARs, and even endangering SAR filers. However, under FinCEN’s implementing regulation for SAR confidentiality, “a SAR or any information that would reveal the existence of a SAR” does not include “the underlying facts, transactions, and documents upon which a SAR is based.” 5 Accordingly, the BSA and its implementing regulations do not prohibit banks and credit unions from communicating with a customer or other person who is the subject of a SAR or with other third parties, including other banks or credit unions, about potentially fraudulent or other suspicious transactions involving the customer’s account or notifying the customer of the bank’s or credit union’s intention to close the account for potentially fraudulent or other suspicious activity, so long as that communication does not reveal the existence of a SAR. 6 SAR confidentiality does not, for instance, prohibit banks and credit unions from communicating with a customer or other person who may be the subject of a SAR or with third parties, including other banks or credit unions, when such communication involves the underlying facts, transactions, and documents upon which a SAR is based. Specifically, the factual information related to transactions, including, but not limited to, transaction dates, amounts, and partie
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
