Link to Key Takeaway Key Takeaway

On September 2, 2026, the Federal Reserve, FDIC, NCUA, OCC, and FinCEN confirmed that a bank may tell a customer that an account restriction or closure, or a rejected deposit, may be related to suspected fraud or other suspicious activity, so long as the communication does not reveal that a SAR was or will be filed.

Link to What Happened What Happened

On September 2, 2026, the Federal Reserve, the FDIC, the NCUA, the OCC, and FinCEN issued a joint statement on the application of SAR confidentiality to banks’ communications with their customers (Joint Statement). The Bank Secrecy Act prohibits a bank from disclosing a suspicious activity report or any information that would reveal that one exists, and in particular from notifying any person involved in a transaction that the transaction has been reported. In practice, those prohibitions have led many banks to say nothing at all when a payment is held, a deposit is rejected, or an account is closed and the customer asks why. The Joint Statement confirms that the SAR confidentiality prohibitions are narrower than that practice: the regulators confirmed that a bank may communicate with a customer about potentially fraudulent transactions, other suspicious activity, or account closures, provided the communication does not reveal the existence of a SAR. The Joint Statement responds to comments on the agencies’ payments fraud initiative and invokes Executive Order 14331 on fair banking.

Link to What the Agencies Confirmed What the Agencies Confirmed

The Joint Statement rests on a distinction FinCEN’s confidentiality rule has drawn since 2010: a SAR, and any information that would reveal its existence, is confidential, but “the underlying facts, transactions, and documents upon which a SAR is based” are not. The significance of the Joint Statement lies in its authorship. Each of the federal banking agencies, together with FinCEN, has now stated that the BSA and its implementing regulations “do not prohibit banks and credit unions from communicating with a customer or other person who is the subject of a SAR . . . about potentially fraudulent or other suspicious transactions involving the customer’s account,” so long as that communication “does not reveal the existence of a SAR.” The agencies note that it “would not typically reveal the existence of a SAR” for a bank to notify a customer that a delay, limitation, or restriction on an account or service, or the closure of an account, may be related to suspected fraud or other suspicious activity. The same is true for notifying a customer that a deposit was rejected because of suspected fraud or other suspicious activity, an altered or counterfeit check, for example. A non-exhaustive list of examples in the Joint Statement also covers asking about the purpose of a transaction or the source of funds, requesting due diligence information, requesting information on the originator or beneficiary of a funds transfer, warning customers about fraud typologies, and communicating account maintenance policies and decisions. The principle is not limited to the customer, as the Joint Statement confirms that the same underlying facts may be discussed with third parties, including other banks and credit unions, which is cooperation that payments fraud and funds transfer inquiries routinely require.

The Joint Statement also explicitly addresses the logical deduction problem as applied to a customer or other third party. “A reasonable and prudent person familiar with the SAR filing requirement may” suspect, or be able to deduce from the underlying facts, that “a SAR was or may have been filed.” That possibility alone, the agencies confirm, does not make the communication about underlying facts, transactions, and documents an impermissible disclosure of the existence of a SAR, a point FinCEN made in guidance last September.

What Has Not Changed

Considerations for Financial Institutions in Light of the Joint Statement

Banks may wish to begin with an inventory. Customer communications about suspicious activity are typically addressed in some combination of BSA or fraud policies, notice and rejection templates, and call center scripts, and much of that language was drafted to say as little as possible or to prohibit the discussion outright. Each should be reviewed against what the Joint Statement now permits, beginning with the clearest cases the Joint Statement identifies, such as deposits rejected for altered or counterfeit checks, with potentially different scripts for different audiences. Institutions can reasonably differ on who is authorized to say more: some will incorporate the permitted disclosure into front-line scripts with a defined end point, while others will route these conversations directly to fraud or BSA personnel trained to discuss the underlying facts without confirming or denying a filing. Either approach is defensible provided it does not disclose a SAR or the existence of a SAR. Whichever is chosen, each determination, including a decision to leave existing language unchanged, should be made at the level of policies and templates and should be documented so that the record reflects what the bank considered and why. One thing to consider is that, as banks move closer in their scripts to facts about fraud or suspicious activity, it becomes easier for mistakes to cross the line and reveal or suggest the existence of a SAR. The threshold questions are what the bank’s policies and notices say today, what more can prudently be said in certain circumstances, and where the determinations will be documented.

Photo of Carlton Greene Carlton Greene

Carlton Greene is a partner in Crowell & Moring’s Washington, D.C. office and a member of the firm’s International Trade and White Collar & Regulatory Enforcement groups. He provides strategic advice to clients on U.S. economic sanctions, Bank Secrecy Act and anti-money laundering…

Carlton Greene is a partner in Crowell & Moring’s Washington, D.C. office and a member of the firm’s International Trade and White Collar & Regulatory Enforcement groups. He provides strategic advice to clients on U.S. economic sanctions, Bank Secrecy Act and anti-money laundering (AML) laws and regulations, export controls, and anti-corruption/anti-bribery laws and regulations. Carlton is the former chief counsel at FinCEN (the Financial Crimes Enforcement Network), the U.S. AML regulator responsible for administering the Bank Secrecy Act.

Photo of Anand Sithian Anand Sithian

For high-stakes internal and government investigations and complex regulatory and compliance matters, companies and individuals look to Anand to provide strategic advice and counseling, particularly on issues relating to the Bank Secrecy Act and Anti-Money Laundering (“BSA/AML”), economic sanctions, and digital assets. Anand

…

For high-stakes internal and government investigations and complex regulatory and compliance matters, companies and individuals look to Anand to provide strategic advice and counseling, particularly on issues relating to the Bank Secrecy Act and Anti-Money Laundering (“BSA/AML”), economic sanctions, and digital assets. Anand is resident in the firm’s New York office and a member of the firm’s International Trade, White Collar and Regulatory Enforcement, and Financial Services groups.

A former federal prosecutor, Anand leverages his government experience to guide clients through complex white-collar matters, including grand jury and regulatory investigations, enforcement proceedings, and internal investigations. Anand has deep experience in parallel criminal and civil investigations and proceedings, and often represents clients in defending against civil lawsuits related to government investigations.

Representing some of the world’s largest banks and technology companies, Anand has addressed a wide range of issues, including economic sanctions, BSA/AML; economic sanctions and national security; payments and cryptocurrency; securities laws; and cybersecurity enforcement. In the regulatory space, Anand prides himself on providing commercial and actionable advice, including in the developing areas of digital assets, FinTech, and payments.

Photo of Cristina Diaz Cristina Diaz

Cristina Diaz is a senior counsel in the firm’s Financial Services Group and is based in the New York office. With more than 20 years of banking law experience, Cristina brings a unique combination of in-house insight and private practice depth. She advises

…

Cristina Diaz is a senior counsel in the firm’s Financial Services Group and is based in the New York office. With more than 20 years of banking law experience, Cristina brings a unique combination of in-house insight and private practice depth. She advises foreign and domestic banks, fintechs, and digital assets businesses on bank regulation, compliance, and enforcement.

Cristina’s practice spans bank chartering and licensing, permissible activities, capital requirements, regulatory enforcement, M&A, and corporate governance. She advises clients navigating the intersection of traditional banking and emerging financial services, including digital assets companies seeking to acquire or establish national banks, and banks exploring partnerships with fintechs and digital assets firms. She regularly helps clients navigate complex relationships and remediation initiatives with state and federal financial regulators, including the Federal Reserve, OCC, FDIC, and the Utah Department of Financial Institutions.