US Agencies Clarify Banks Can Discuss Suspicious Transactions Without Revealing SAR Filings

FinCEN, the Federal Reserve, FDIC, NCUA and Office of the Comptroller of the Currency on September 2, 2026 issued a joint statement clarifying how banks may communicate with customers about potentially fraudulent or otherwise suspicious activity without violating Suspicious Activity Report confidentiality rules.
The agencies stressed that the statement does not change existing Bank Secrecy Act requirements and does not create new supervisory expectations. Instead, it addresses a practical compliance concern raised by banks: whether SAR confidentiality prevents them from explaining suspicious transactions, fraud investigations or account closures to customers.
Under the BSA, a bank may not disclose a SAR or information that would reveal the existence of a SAR. However, the agencies clarified that this restriction does not generally prevent a bank from discussing the underlying facts, transactions and documents on which a SAR may be based.
Banks may therefore communicate with customers about potentially fraudulent or suspicious transactions involving their accounts, including payment or check fraud, and may notify customers that an account is being restricted or closed because of suspicious or potentially fraudulent activity. The key boundary is that the communication must not reveal whether a SAR has been filed, is being considered, or otherwise exists.
The agencies said banks should assess customer communications on a case-by-case basis and take precautions when discussing information that could indirectly expose a SAR filing. The joint statement also provides a non-exhaustive set of communications that would not typically reveal the existence of a SAR.
The clarification follows industry feedback to a June 2025 interagency request for information on potential actions to address payments fraud. Commenters had asked regulators to clarify how banks could give customers more timely and transparent explanations during fraud investigations while remaining compliant with SAR confidentiality requirements.
The guidance applies across institutions supervised by the participating agencies, including community banks. For compliance teams, the statement draws a clearer operational distinction between protected SAR information and the underlying customer or transaction facts that banks may need to discuss during investigations, fraud prevention and account-management decisions.



