Law / United States

Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers

Joint Statement of on SAR Confidentiality; Federal Reserve SR 26-5

Guidance, not a law: the Financial Crimes Enforcement Network, the Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration and the Office of the Comptroller of the Currency's reading of Bank Secrecy Act and 31 CFR 1020.320, bank reports of suspicious transactions and their confidentiality. It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to private bodies.

Criminal exposure
No
Private right of action
No
Instrument type
guidance published by a regulator
Obligation class
Prohibition
Audit expectation
none

As of .

What the regulator expects

  • It reaches you if you operate as a bank as 31 CFR 1010.100(d) defines the term: each agent, agency, branch or office within the United States of banks, savings associations, credit unions and foreign banks (reached by declaring that you provide financial services).
  • The agencies say the Bank Secrecy Act prohibits you from disclosing a SAR, or any information that would reveal the existence of a SAR, including to a customer or other person who is the subject of the SAR, and from notifying any person involved in the transaction that the transaction has been reported (31 CFR 1020.320(e); 31 U.S.C. 5318(g)(2)).
  • The agencies say the underlying facts, transactions and documents upon which a SAR is based are not a SAR or information that would reveal its existence, so you may discuss them, including transaction dates, amounts and parties, with a customer or other person who is the subject of a SAR and with other third parties, including other banks or credit unions, provided the communication does not reveal the existence of a SAR.
  • The agencies say you may notify a customer of your intention to close an account for potentially fraudulent or other suspicious activity, so long as the communication does not reveal the existence of a SAR.
  • The agencies say you should consider customer communication on a case-by-case basis and take precautions when discussing information that could reveal the existence of a SAR.
  • The agencies give these as communications that would not typically reveal the existence of a SAR: requesting customer due diligence information or documentation; notifying a customer that a delay, limitation, restriction or closure of an account may be related to suspected fraud or other suspicious activity; notifying a customer that a deposit has been rejected because of suspected fraud; asking about the purpose of a transaction or the source of funds; providing warnings or educational resources about fraud schemes or typologies; communicating policies or decisions on account maintenance or services, such as declining a transaction or closing an account; and requesting information on the originator or beneficiary of a funds transfer.

Who enforces it

Enforcement body

FinCEN, the Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration and the Office of the Comptroller of the Currency, each under its own suspicious activity report regulation for the institutions it supervises. The statement carries no enforcement action of its own.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Five agencies issued the Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers on : the Federal Reserve Board, the Federal Deposit Insurance Corporation, the Financial Crimes Enforcement Network, the National Credit Union Administration and the Office of the Comptroller of the Currency. The Federal Reserve issued it as SR Letter 26-5.

The statement clarifies confidentiality requirements related to Suspicious Activity Reports. It addresses a bank's communications with its customers regarding potentially fraudulent transactions, other suspicious activity or account closures. The agencies state that the statement does not alter existing Bank Secrecy Act legal or regulatory requirements or establish new supervisory expectations.

The statement notes that FinCEN's regulations define the term bank in 31 CFR 1010.100(d) to include each agent, agency, branch or office within the United States of banks, savings associations, credit unions and foreign banks. It says the Bank Secrecy Act prohibits the disclosure of a SAR or information that would reveal the existence of a SAR, including to a customer or other person who is the subject of the SAR.

It notes that the Bank Secrecy Act also prohibits a financial institution from notifying any person involved in the transaction that the transaction has been reported. It cites 31 CFR 1020.320(e) as the FinCEN regulation that prohibits sharing a SAR or any information that would reveal its existence except as permitted by statute or regulation.

It says that under FinCEN's implementing regulation a SAR or any information that would reveal the existence of a SAR does not include the underlying facts, transactions and documents upon which a SAR is based.

It says the Bank Secrecy Act and its implementing regulations do not prohibit banks and credit unions from communicating with a customer or other person who is the subject of a SAR, or with other third parties including other banks or credit unions, about potentially fraudulent or other suspicious transactions involving the customer's account, or from notifying the customer of an intention to close the account for potentially fraudulent or other suspicious activity, so long as the communication does not reveal the existence of a SAR.

It says the factual information related to transactions, including transaction dates, amounts and parties, may be discussed, assuming there is no communication that would reveal the existence of a SAR to a customer or other person who is the subject of a SAR or to other third parties, including other banks or credit unions.

It says that, although a reasonable and prudent person familiar with the SAR filing requirement may suspect or be able to deduce from the underlying facts, transactions and documents that a SAR was or may have been filed, the underlying information alone would not constitute information revealing the existence of a SAR for confidentiality purposes.

It says banks and credit unions should consider customer communication on a case-by-case basis and take precautions when discussing information that could reveal the existence of a SAR. It gives a non-exhaustive list of communications that would not typically reveal the existence of a SAR. The list includes requesting customer due diligence information or documentation to understand the nature and purpose of customer relationships for the purpose of developing a customer risk profile.

The list includes notifying a customer that a delay, limitation or restriction on an account or service, or closure of an account, may be related to suspected fraud or other suspicious activity. The list includes notifying a customer that a deposit has been rejected because of suspected fraud or other suspicious activity. The list includes asking a customer about the purpose of a transaction or the source of funds.

The list includes providing warnings or educational resources to a customer about fraud schemes or typologies. The list includes communicating policies or decisions related to account maintenance or services, such as declining a transaction or closing an account. The list includes requesting information on the originator or beneficiary of a funds transfer.

The statement cites FinCEN guidance FIN-2025-G001 of , on cross-border information sharing by financial institutions and SAR confidentiality.

Back to the example  ·  Lint your app