Joint Agency Statement: Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers

NASCUS Summary: Joint Agency Statement Summary on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers
September 2026

On September 2, 2026, the Federal Reserve, FinCEN, FDIC, OCC, and NCUA issued the Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers.

The joint statement clarifies confidentiality requirements around Suspicious Activity Reports (SARS) and what financial institutions (FIs) may communicate to members regarding suspicious activity without violating SAR confidentiality requirements.

The statement also recognizes concerns relating to Executive order 14331, Guaranteeing Fair Banking for All Americans and is intended to facilitate improved transparency, enhance member engagement, and provide greater assurance of fair access to financial services.


Summary

On June 20, 2025, a Request for Information (RFI) issued by the Federal Reserve, FDIC, and OCC was published relating to actions that could occur to help mitigate the risk of payments fraud (with a particular focus on check fraud).

From that RFI, FIs raised concerns about how their team members are able to communicate information without violating SAR confidentiality requirements, specifically not disclosing the fact that a SAR has been, or may be, filed. 

 SAR Confidentiality:

  • The BSA prohibits the disclosure of a SAR, or information that would reveal the existence of a SAR, to a member or others who may be a subject of the SAR.  The reason for this being that making the subjects of a SAR aware of its existence could alert potential suspects and undermine any investigations by law enforcement that are occurring, or that may occur in the future.[1]
  • However, what the joint statement is trying to instill in FIs is the fact that they are allowed to discuss with members, other subjects of a SAR, other third parties, as well as other banks and credit unions the underlying facts and activities upon which SARs are based, provided the communication does not reveal the existence of a SAR.

Examples of Communication Typically Not Prohibited by the BSA

  • Due diligence information or documentation obtained to understand nature and purpose of member relationships.
  • Notification to members around delays, limitations, or restrictions on an account, or closure to an account, related to suspected fraud or suspicious activity.
  • Notification of rejected deposits due to suspected fraud or suspicious activity.
  • Asking a member the purpose of transaction or source of funds.
  • Providing warnings or education resources to members related to fraud schemes or typologies.
  • Communication policies or decisions related to account maintenance or services.
  • Requesting information on the originator or beneficiary of a funds transfer.

Key Considerations:

  • The joint statement notes something that should instill confidence in FIs when they are having conversations.  It states: although a reasonable and prudent person familiar with the SAR filing requirements may suspect or be able to deduce from these underlying facts, transactions, and documents that a SAR was or may be filed, the underlying information alone would not constitute information revealing the existence of a SAR for confidentiality purposes.
  • This joint statement provides another example of the agencies continuing to educate and empower FIs in their efforts to combat fraud to the best degree possible.  Fraud losses continue to rise each year across all channels. 
  • Other educational resources and process improvements we have recently seen include:
    • Multiple alerts and press releases urging FIs to remain vigilant and report suspicious activity, spotlighting various fraud schemes, such as digital asset scams (Pig Butchering), student aid fraud.

[1] 31 U.S.C. § 5318(g)(2)(A)