
Permission to Speak (and a Reason To): FinCEN and Banking Agencies Clarify SAR Confidentiality Rules for Customer Communications About Fraud and Account Closures

On September 2, 2026, the Financial Crimes Enforcement Network (FinCEN), together with the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC) (collectively, the Agencies), issued a joint statement (the Statement) clarifying that Suspicious Activity Report (SAR) confidentiality rules do not prevent banks and credit unions from discussing the underlying facts of potentially fraudulent or other suspicious transactions with the customer involved — and with third parties, including other banks and credit unions — so long as the communication does not reveal the existence of a SAR itself.
Background Behind the Statement
The Statement comes in response to two recent developments in the regulatory landscape for supervised financial institutions.
First, in June 2025, the Federal Reserve, FDIC, and OCC issued a request for information seeking input on potential measures to address payments fraud, with a particular focus on check fraud.[1] Commenters raised concerns about whether SAR confidentiality rules restricted bank personnel’s ability to communicate with customers during fraud investigations and requested clarification from the agencies and FinCEN on how to ensure compliance with SAR confidentiality requirements.
Second, the Statement recognizes the concerns expressed in Executive Order 14331, Guaranteeing Fair Banking for All Americans, issued by President Trump in August 2025 (the Fair Access EO), which directs regulators to review and, where warranted, penalize institutions that have engaged in “politicized debanking.”[2] In the Statement, the Agencies noted that by “improv[ing] transparency over bank actions with respect to customer accounts” they hoped to “provide customers with greater assurance that their banks and credit unions will provide them with fair access to financial services.”
The Core Distinction: SAR Information Versus Underlying Facts
Generally, the disclosure of a SAR or information that would reveal the existence of a SAR, including to a customer or the subject of the SAR is a violation of the Bank Secrecy Act (BSA) that carries with it an array of potential sanctions. The BSA separately prohibits a financial institution from notifying any person involved in the transaction that the transaction has been reported.
The Statement, however, underscores a distinction already present in the BSA’s implementing regulations: “the underlying facts, transactions, and documents upon which a SAR is based” fall outside the SAR disclosure restrictions.[3] The Statement clarifies this distinction and makes clear that the disclosure of a SAR’s underlying facts does not constitute disclosure of a SAR for confidentiality purposes:
[T]he BSA and its implementing regulations do not prohibit banks and credit unions from communicating with a customer or other person who is the subject of a SAR or with other third parties, including other banks or credit unions, about potentially fraudulent or other suspicious transactions involving the customer’s account or notifying the customer of the bank’s or credit union’s intention to close the account for potentially fraudulent or other suspicious activity, so long as that communication does not reveal the existence of a SAR.
Critically, the Statement goes on to address the obvious practical objection. Even where a reasonable and prudent person familiar with the SAR filing requirement may suspect, or be able to deduce from the underlying facts, transactions, and documents, that a SAR was or may have been filed, “the underlying information alone would not constitute information revealing the existence of a SAR for confidentiality purposes.” That the customer may connect the dots, in other words, does not itself convert a permissible discussion of facts into a prohibited disclosure.
The Statement provides a non-exhaustive list of communications that “would not typically reveal the existence of a SAR,” such as:
- Requesting customer due diligence information or documentation needed to understand the nature and purpose of the customer relationship for developing a customer risk profile;
- Asking about the purpose of a transaction, the source of funds, or the originator or beneficiary of a funds transfer;
- Notifying a customer that a delay, limitation, restriction, or closure of an account may be related to suspected fraud or other suspicious activity;
- Notifying a customer that a deposit was rejected because of suspected fraud, such as when a check may have been altered or counterfeited;
- Providing warnings or educational resources about fraud schemes and typologies, including where a customer may be defrauded or may be participating in a fraud scheme knowingly or unknowingly, such as information about known “money mule” schemes; and
- Communicating account-maintenance or service decisions, such as declining a transaction or closing an account.
More broadly, institutions may also discuss the transaction at issue, their remediation efforts, and potential mitigation measures available to the customer.
What the Statement Does Not Change
Equally important is what the Statement does not do.
The Statement does not create a blanket safe harbor for customer communications. Rather, banks and credit unions must “consider customer communication on a case-by-case basis and take precautions when discussing information that could reveal the existence of a SAR.” And, in any event, the baseline prohibition on disclosure that a SAR has been filed or exists remains unchanged. The Agencies were also explicit that the Statement “does not alter existing Bank Secrecy Act (BSA) legal or regulatory requirements or establish new supervisory expectations.”
The Statement also does not require banks or credit unions to provide a particular explanation to a customer. Rather, it clarifies what the BSA’s SAR confidentiality provisions do not prohibit, leaving institutions to determine whether and how to communicate in light of the particular circumstances and applicable requirements.
Practical Considerations for Banks and Credit Unions
Although the Statement does not change the governing law, it does have particularly important implications for institutions’ fraud investigations and account-closure processes.
- Broader (But Careful) Disclosure Is Permitted. The most obvious takeaway from the Statement is that banks and credit unions can potentially broaden the scope of information they provide to customers. Institutions should review their existing practices against the Statement’s clarification, while also making sure there are adequate controls to prevent the disclosure of prohibited information.
- Beware the Double-Edged Sword. By clearly marking a wider boundary around the universe of permissible disclosures, the Agencies have given institutions welcome flexibility — and a new source of risk. The Agencies have expressly acknowledged that the Statement is meant to advance the aims of the Fair Access EO. Neither the Statement nor the Fair Access EO imposes an affirmative duty to explain a fraud investigation or an account closure. But now that the Agencies have said on the record that these conversations are permitted, SAR confidentiality is no longer available as the reason an institution said nothing — to an examiner, to a customer complaint, or to a plaintiff. Institutions should be careful not to treat the Statement as purely permissive: a bank that says too little may find its silence harder to defend.
[1] Request for Information on Potential Actions to Address Payments Fraud, 90 Fed. Reg. 26293 (June 20, 2025).
[2] Exec. Order No. 14331, Guaranteeing Fair Banking for All Americans, 90 Fed. Reg. 38925 (Aug. 12, 2025).
[3] 31 C.F.R. § 1020.320(e)(1)(ii)(A)(2)
This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.


