Skip to main content

Breaking the Silence: Regulators Clarify Rules on SARs and Customer Fraud Disclosures

On September 2, 2026, the Board of Governors of the Federal Reserve System (Federal Reserve), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC) (collectively, the Agencies), together with the Financial Crimes Enforcement Network (FinCEN), issued a Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers (the “Joint Statement”). The guidance addresses a long-standing tension: how banks can communicate transparently with customers about potentially fraudulent transactions, account restrictions, and closures without violating the statutory prohibition against disclosing the existence of a Suspicious Activity Report (SAR). It does not alter existing Bank Secrecy Act (BSA) legal or regulatory requirements or establish new supervisory expectations. Still, five agencies speaking with one voice carries real practical weight for compliance teams and in-house counsel.

The SAR Confidentiality Framework

SAR confidentiality is one of the BSA’s core protections. Under the Bank Secrecy Act’s suspicious activity reporting provision and its implementing regulations (including FinCEN’s SAR confidentiality rule for banks and parallel banking-agency rules), institutions may not disclose a SAR, or any information revealing its existence, to anyone, including the person the SAR concerns. The BSA separately bars notifying “any person involved in the transaction that the transaction has been reported.” Unauthorized disclosure risks tipping off suspects, compromising investigations, and chilling future SAR filings.

In practice, this has created a communications gap. Customers whose accounts were restricted, whose deposits were rejected, or whose accounts were closed over suspected fraud often received little or no explanation, even when they were the fraud victims. The issue came to a head on June 20, 2025, when the Federal Reserve, FDIC, and OCC issued a Request for Information on potential actions to mitigate payments fraud, with particular emphasis on check fraud. Commenters raised concerns about bank personnel’s ability to communicate with customers when a SAR may be (or has been) filed regarding activity affecting their account, and asked the Agencies and FinCEN to clarify how institutions could provide transparent, timely communication during a fraud investigation without violating SAR confidentiality.

The statement also connects to Executive Order 14331, “Guaranteeing Fair Banking for All Americans,” and its final rules, which bar the FDIC, OCC, and NCUA from requiring or encouraging institutions to terminate customer relationships based on political, social, cultural, or religious views, protected speech, or lawful but disfavored business activities. The Agencies and FinCEN say the added transparency around account actions should improve customer engagement and give customers more confidence that they will have fair access to financial services.

Each agency also issued the statement through its own usual channel, so institutions should refer to whichever version comes from their primary regulator: the Federal Reserve issued it as Supervisory Letter SR 26-5, the OCC issued it as Bulletin 2026-43 (which applies to all national banks, including community banks), the FDIC issued it as Financial Institution Letter FIL-55-2026 (which applies to all FDIC-insured institutions), and the NCUA published it for federally insured credit unions.

What the Joint Statement Permits – and What It Doesn’t

The Fact-vs.-Existence Distinction

The Joint Statement relies on a regulatory carve-out that has been on the books since 2010, though few institutions have leaned on it in customer communications. Under FinCEN’s SAR confidentiality rule, “a SAR or any information that would reveal the existence of a SAR” does not include “the underlying facts, transactions, and documents upon which a SAR is based.” The Joint Statement applies that carve-out to day-to-day customer interactions: banks and credit unions may discuss the underlying facts, transactions, and documents (including transaction dates, amounts, and parties) so long as the communication does not reveal that a SAR exists.

The Agencies and FinCEN acknowledge that “a reasonable and prudent person familiar with the SAR filing requirement may suspect or be able to deduce from these underlying facts...that a SAR was or may have been filed,” but that inference alone does not constitute information revealing a SAR’s existence.

Communications That Are Typically Permissible

The Joint Statement lists examples of communications with a customer typically not prohibited by the BSA, including:

  • Requesting customer due diligence information or documentation to understand the nature and purpose of customer relationships for developing a customer risk profile;
  • Notifying a customer that a delay, limitation, or restriction on an account or service, or an account closure, may be related to suspected fraud or other suspicious activity;
  • Notifying a customer that a deposit has been rejected because of suspected fraud or other suspicious activity, including in the context of altered or counterfeit checks;
  • Asking a customer about the purpose of a transaction or the source of funds;
  • Providing warnings or educational resources about fraud schemes or typologies, including where a customer may be defrauded or may knowingly or unknowingly be participating in a fraud scheme, such as “money mule” schemes;
  • Communicating policies or decisions related to account maintenance or services, such as declining a transaction or closing an account; and
  • Requesting information on the originator or beneficiary of a funds transfer.

The deposit-rejection example is particularly significant. In the check-fraud context that prompted the RFI, institutions and customers have long felt the absence of any explanation. The explicit blessing for money-mule education (where a person’s account is used, knowingly or not, to move illegally obtained funds for someone else) is also notable; many compliance teams had steered clear of that outreach out of an abundance of caution.

The Bright Line That Remains

The core prohibition remains that institutions cannot tell a customer that a SAR has been, is being, or will be filed, nor can they hand over the SAR itself. The Agencies and FinCEN advise evaluating customer communications case by case and taking precautions where a communication could reveal a SAR’s existence. This is interpretive guidance, not a safe harbor or regulatory exemption.

Account Closure Authority Is Unchanged

A financial institution’s independent, risk-based authority to close or restrict accounts remains intact. The fair-banking rules under Executive Order 14331 restrict only regulators—barring them from directing account termination based on protected political, social, or religious views or lawful but disfavored business activities—not a bank’s own risk-based decisions. In practical terms, the Joint Statement gives institutions room to tell a customer that a closure relates to suspected fraud, without that disclosure being treated as an impermissible SAR revelation.

What Compliance Teams Should Do Now

The most immediate action item is updating customer-facing scripts and templates. Compliance teams should replace vague language (“we are unable to process your transaction”) with references to suspected fraud where appropriate, taking care to omit any mention of a SAR filing. Frontline and fraud-investigation staff will also need training on where the fact-vs.-existence line falls, with concrete examples of what can and cannot be said. Legal or compliance personnel should remain available for the harder judgment calls. Finally, because this is interpretive guidance and not a safe harbor, institutions should document their reasoning contemporaneously. If a disclosure’s appropriateness is later questioned, that record will matter.

Litigation Considerations

SAR confidentiality has long been a thorny issue for banks to consider when responding to discovery requests in litigation or to third-party subpoenas. This often comes into play in actions by customers alleging that the bank aided and abetted a fraud, or was negligent in not uncovering a fraud. Banks of course are still not permitted to produce the SAR itself, or reveal the filing of the SAR in the course of responding to interrogatories. However, a bank would still have to identify the date on which it became aware of the activity subject to the SAR, and other facts that underly the SAR filing. This includes any internal investigation that may have been conducted as a result of the SAR. The Joint Statement underscores the fact that a litigant cannot use the existence of a SAR to shield uncomfortable facts from discovery

Conclusion

For compliance teams, the takeaway is straightforward: the facts that prompted the SAR are not themselves confidential, and the five-agency consensus gives institutions considerably more room to explain account restrictions, rejected deposits, and closures to customers. Institutions that have defaulted to silence should take the opportunity to revisit that posture, update their scripts, and train staff on the distinction. The regulatory text has supported this since 2010; what has changed is that regulators are now saying so explicitly, together.

Subscribe To Viewpoints

Authors

Pete S. Michaels

Pete S. Michaels

Member / Co-Chair, Financial Services Practice

Pete S. Michaels is a Member at Mintz who focuses his practice on securities litigation, regulatory proceedings involving financial service companies and products, and compliance matters. He represents financial services firms and insurance companies and their employees, directors, and officers.
Edmund P. Daley is a Member in Mintz's Litigation Practice, focusing on white collar defense and financial services litigation. He represents public and private companies, investors and individuals in all manner of government investigations, enforcement actions and compliance related to financial laws. He is an active member of the firm’s Appellate Practice Group and has experience preparing motions for state and federal court cases, legal opinions, and appellate briefs.
Molly Connolly is an Associate in Mintz’s Litigation Practice, focusing on complex commercial litigation, government enforcement matters, and sensitive investigations. She represents clients across a number of industries, including financial services.
Michael E. Pastore

Michael E. Pastore

Special Counsel

Michael E. Pastore is a Special Counsel at Mintz who represents banks, financial services, and other companies in litigation and government proceedings involving consumer protection and other laws. He also handles arbitrations and guides clients through government and internal investigations.