FinCEN Guidance FIN-2025-G001, Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality
Guidance, not a law: the Financial Crimes Enforcement Network's reading of Bank Secrecy Act and 31 CFR 1020.320, bank reports of suspicious transactions and their confidentiality. It binds nobody by itself; the law it reads does.
Guidance on an AI sector rules rule, addressed to private bodies.
- Criminal exposure
- No
- Private right of action
- No
- Instrument type
- guidance published by a regulator
- Obligation class
- Prohibition
- Audit expectation
- none
As of .
What the regulator expects
- It reaches you if you operate as a financial institution under the Bank Secrecy Act and its implementing regulations. FinCEN's page for the guidance lists depository institutions (banks), casinos, the insurance industry, money services businesses, mortgage companies and brokers, the precious metals and jewelry industry, and securities and futures firms as the financial institution types it concerns, and the SAR confidentiality rule it reads for banks is 31 CFR 1020.320(e).
- FinCEN says the Bank Secrecy Act prohibits you from disclosing a SAR, or information that would reveal the existence or non-existence of a SAR, other than in limited circumstances (31 CFR 1020.320(e); 31 U.S.C. 5318(g)(2)(A)).
- When you share underlying facts, transactions or documents with another financial institution, including a foreign one, FinCEN says you must take appropriate measures, such as redaction, to ensure that information that would reveal the existence of a SAR is not shared.
- FinCEN says the Bank Secrecy Act does not otherwise prohibit you from sharing the underlying facts, transactions and documents upon which a SAR is based, including with financial institutions in the United States and foreign financial institutions, and that the underlying information alone would not constitute information revealing the existence of a SAR.
- FinCEN says you should consider whether to share and what to share on a case-by-case basis, taking into account your risk profile, your relationship with the foreign financial institution and other relevant information available to you.
- FinCEN reminds you of your obligation to notify FinCEN, and as applicable your other federal regulators, if you receive a subpoena or other request to disclose a SAR or information that would reveal the existence of a SAR (31 CFR 1020.320(e)(1)).
- FinCEN lists as underlying facts, transactions and documents that would not typically reveal the existence of a SAR: wire transfer and payment information, records of cash deposits, withdrawals and transfers, and transaction logs showing whether accountholders have transacted with persons in specific jurisdictions; customer and account information, including account owners, beneficial ownership, products and services, business types, occupation and sources of funds or wealth; and investigative materials, including alerts, transaction and customer information stored in an investigation file, due diligence research, analytic materials that do not bear on the SAR decision process or imply that a SAR decision has been made, and cyber-related data such as IP addresses, geolocations and device identification numbers.
Who enforces it
Enforcement body
FinCEN, which issued the guidance in consultation with the staffs of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation and the National Credit Union Administration. The guidance carries no enforcement action of its own.
What this law does
The Financial Crimes Enforcement Network issued FIN-2025-G001, Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality, on . FinCEN issued it in consultation with the staffs of the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation and the National Credit Union Administration.
The guidance says it is issued to encourage and promote appropriate, voluntary cross-border sharing of information between and among financial institutions, including appropriate foreign financial institutions. It says that voluntary sharing of information between financial institutions, including their foreign affiliates and financial institutions to which they offer correspondent banking services, can make the United States financial system and the global financial system more resilient.
It says it seeks to clarify that the Bank Secrecy Act and its implementing regulations generally do not prohibit cross-border information sharing. It also says it seeks to provide examples of information that typically would not reveal the existence of a Suspicious Activity Report (SAR) and that the Bank Secrecy Act therefore does not prohibit sharing.
The guidance states that it does not alter or amend any existing legal obligations under the Bank Secrecy Act or other statutes or regulations and does not impose any new regulatory requirements or supervisory expectations. It states that it does not replace any previous guidance. It states that it does not establish or interpret any compliance standards.
The guidance says the Bank Secrecy Act prohibits the disclosure of a SAR or information that would reveal the existence or non-existence of a SAR. It says that a SAR, and information that would reveal the existence or non-existence of a SAR, may not be shared other than in limited circumstances. It says the Bank Secrecy Act does not otherwise prohibit sharing the underlying facts, transactions and documents upon which a SAR is based.
It says this sharing may be with financial institutions in the United States and with foreign financial institutions. It says that although a reasonable and prudent person familiar with the SAR filing requirement may suspect or be able to deduce from these underlying facts, transactions and documents that a SAR was filed, the underlying information alone would not constitute information revealing the existence of a SAR for confidentiality purposes.
It gives a non-exhaustive list of exemplar underlying facts, transactions and documents that would not typically reveal the existence of a SAR, in three groups: transaction information, customer and account information, and investigative or other relevant materials. It says that when sharing such information, financial institutions must take appropriate measures, such as redaction, to ensure that information that would reveal the existence of a SAR is not shared.
It says that financial institutions should consider whether to share and what to share on a case-by-case basis. It says that in determining whether to share information, financial institutions should consider their risk profile, their relationship with the foreign financial institution, and other relevant information available to the financial institution.
It says that obligations under the Right to Financial Privacy Act, the Gramm-Leach-Bliley Act, state laws and foreign law are outside its scope. It says that nothing in it affects the availability or scope of the safe harbor from liability for information sharing under section 314(b) of the USA PATRIOT Act.
FinCEN reminds financial institutions of their obligation to notify FinCEN, and as applicable other federal regulators, if the financial institution receives a subpoena or other request to disclose a SAR or information that would reveal the existence of a SAR.
The guidance gives as examples of previous guidance the interagency guidance of on sharing Suspicious Activity Reports with head offices and controlling companies, FinCEN guidance FIN-2010-G006 of on sharing by depository institutions with certain affiliates in the United States, and the Section 314(b) Fact Sheet of .
FinCEN's page for the guidance lists casinos, depository institutions, the insurance industry, money services businesses, mortgage companies and brokers, the precious metals and jewelry industry, and securities and futures firms as the financial institution types it concerns.