On September 2, the Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve System (Federal Reserve), Federal Deposit Insurance Corporation (FDIC), Financial Crimes Enforcement Network (FinCEN), and National Credit Union Administration (NCUA) issued a joint statement clarifying the confidentiality requirements related to Suspicious Activity Reports (SARs), particularly when banks communicate with customers regarding potentially fraudulent transactions, other suspicious activity, or account closures. The statement applies to all banks, including community banks.

Link to Background Background

The joint statement responds to concerns raised by industry commenters in response to a June 2025 request for information issued by the Federal Reserve, FDIC, and OCC on actions to help mitigate payments fraud, with a particular focus on check fraud. Commenters expressed uncertainty about whether and how bank personnel could communicate with customers when a SAR had been or may be filed in connection with the customer’s account activity. The statement also responds to concerns raised in Executive Order 14331, Guaranteeing Fair Banking for All Americans, regarding transparency over bank actions with respect to customer accounts.

The agencies are clear that the statement does not alter existing BSA legal or regulatory requirements or establish new supervisory expectations. It is a clarification, not a new rule.

Link to What the BSA Prohibits What the BSA Prohibits

The joint statement reviews the scope of the Bank Secrecy Act (BSA). The BSA prohibits the disclosure of a SAR or any information that would reveal the existence of a SAR, including to the customer or other person who is the subject of the SAR. Unauthorized disclosure could undermine ongoing and future law enforcement investigations by alerting potential suspects, deterring financial institutions from filing SARs, and even endangering SAR filers. The unauthorized disclosure of a SAR is a violation of federal law and there are an array of sanctions that can be imposed on a financial institution for unauthorized disclosure, including civil and criminal penalties, fines, and imprisonment.

Link to What the BSA Does Not Prohibit What the BSA Does Not Prohibit

The joint statement reaffirms that the BSA’s confidentiality requirements do not extend to the underlying facts, transactions, and documents upon which a SAR is based. Banks and credit unions may communicate with a customer, or with other financial institutions, about potentially fraudulent or suspicious transactions involving the customer’s account, including notifying the customer of an intention to close the account, so long as that communication does not reveal the existence of a SAR.

Importantly, the agencies confirm that even if a reasonable and prudent person familiar with SAR filing requirements might suspect or deduce from the underlying facts that a SAR was or may have been filed, the communication of those underlying facts alone does not constitute prohibited disclosure of a SAR’s existence.

Link to Examples of Permissible Customer Communications Examples of Permissible Customer Communications

The joint statement provides a non-exhaustive list of communications that would not typically reveal the existence of a SAR and are therefore generally permissible:

  • Requesting customer due diligence information or documentation to develop a customer risk profile;
  • Notifying a customer that a delay, limitation, restriction, or closure of an account may be related to suspected fraud or other suspicious activity;
  • Notifying a customer that a deposit has been rejected due to suspected fraud, such as in the context of altered or counterfeit checks;
  • Asking a customer about the purpose of a transaction or the source of funds;
  • Providing warnings or educational resources about fraud schemes or typologies, including information about known “money mule” schemes;
  • Requesting information on the originator or beneficiary of a funds transfer.

Link to Key Takeaways for Financial Institutions Key Takeaways for Financial Institutions

The joint statement is intended to provide clarity to banks and credit unions that have struggled to balance SAR confidentiality obligations with the practical need to communicate transparently with customers during fraud investigations. Several points deserve emphasis:

  • Case-by-case judgment is required. Banks should evaluate each customer communication individually and take precautions when discussing information that could reveal SAR existence. There is no blanket safe harbor.
  • Underlying facts may be discussed, but SAR existence may not. Banks may discuss transaction dates, amounts, parties, and related facts. They may not, directly or indirectly, confirm or suggest that a SAR has been or will be filed.
  • Account closure communications are permissible. Banks may notify customers that an account is being closed due to suspected fraud or suspicious activity without that notification alone constituting a prohibited SAR disclosure.
  • Inter-institution communications are also addressed. The statement confirms that communications with other banks or credit unions about suspicious activity, not just communications with the customer, are similarly governed by these principles.
  • Community banks are expressly covered. The agencies specifically note that the joint statement applies to all community banks, not just large institutions.

Financial institutions should review their internal SAR-related communication policies and procedures in light of this guidance and consider whether updates are warranted to enable more transparent and effective customer communications and engagement during fraud investigations, consistent with the BSA’s confidentiality requirements.