U.S. financial regulators recently clarified that the Bank Secrecy Act doesn't stop financial institutions from discussing Suspicious Activity Reports (SARs) with the customers involved. This shifts a long-standing practice where compliance teams avoided any contact with SAR subjects, leaving them in the dark about account closures or transaction blocks.
The statement doesn't introduce new permissions; it corrects a misunderstanding that's influenced compliance operations for years.
What the Clarification Actually Says
Federal agencies confirmed that SAR Confidentiality rules under 31 U.S.C. § 5318(g)(2) prohibit disclosing that a SAR has been filed. However, they don't stop you from discussing the suspicious activity itself with your customer.
You can't say: "We filed a Suspicious Activity Report on your wire transfer last Tuesday."
You can say: "We're reviewing unusual patterns in your account activity and need additional documentation about the source of these funds."
This distinction is crucial because it separates two compliance obligations that many institutions have confused: the duty to report suspicious activity to FinCEN, and the duty to conduct effective Customer Due Diligence.
Key Findings for Your SAR Workflow
Finding 1: Your account closure scripts can now include substance.
Most institutions close high-risk accounts with vague language: "We've decided to end our business relationship." Now, you can explain the compliance concerns behind that decision, as long as you don't mention the Suspicious Activity Report itself. Describe transaction patterns, documentation gaps, or risk thresholds without breaching confidentiality rules.
Finding 2: Enhanced Due Diligence conversations don't constitute Tipping Off.
When you spot suspicious activity during Ongoing Due Diligence, you can request source of funds documentation, beneficial ownership updates, or transaction purpose explanations without worrying about a Tipping Off violation. The clarification confirms that seeking information about suspicious activity is part of your BSA obligations, not a breach.
Finding 3: Your legal and compliance teams have been over-rotating on confidentiality.
If your policy bans any communication with SAR subjects beyond form letters, it's not required by the BSA. It's a risk management choice. The clarification lets you reconsider whether strict information quarantine helps your compliance program or just creates customer friction without reducing risk.
Finding 4: The Safe Harbor provision still applies to good-faith disclosures.
The BSA's Safe Harbor under 31 U.S.C. § 5318(g)(3) protects institutions from civil liability when they file SARs in good faith. This protection extends to communications with customers about the underlying activity, as long as you're acting within your compliance obligations and not maliciously disclosing confidential law enforcement information.
Finding 5: State privacy laws and contractual obligations still apply.
The clarification addresses federal BSA requirements. It doesn't override state consumer privacy statutes, data protection regulations, or contractual confidentiality terms in your customer agreements. Before changing communication protocols, your legal team needs to map federal permissions against state-level constraints.
What This Means for Your Compliance Program
You now have three operational choices where you previously had one:
Option 1: Maintain current practice.
Continue treating SAR subjects as off-limits for substantive communication. This minimizes Tipping Off risk and simplifies staff training, but it also perpetuates customer complaints about arbitrary account closures and limits your ability to gather information that might resolve suspicious activity without a Suspicious Activity Report.
Option 2: Adopt selective engagement.
Develop protocols for when your team will discuss suspicious activity with customers and when you won't. For example, engage with established business customers showing unusual transaction patterns but maintain silence with new accounts exhibiting structuring behavior. This requires more sophisticated staff judgment and documented decision criteria.
Option 3: Default to transparency.
Shift institutional culture toward explaining compliance concerns to customers whenever the BSA doesn't explicitly prohibit it. This could improve customer retention and relationship management, but it requires extensive staff retraining and introduces new litigation risk if customers perceive discrimination or inconsistent policy application.
Most institutions will likely choose a path between Options 1 and 2. The clarification doesn't force you to change anything, but it removes the regulatory excuse for overly conservative policies.
Action Items by Priority
Immediate (this quarter):
Review your current SAR confidentiality policy with legal counsel. Identify which restrictions are legally required versus institutionally chosen. Document the distinction in your BSA/AML Policy Manual so examiners understand your reasoning.
Update staff training materials to reflect the clarification. Your investigators and customer-facing teams need to understand they can discuss suspicious activity patterns without violating confidentiality rules, but they must never reference the Suspicious Activity Report itself.
Short-term (next two quarters):
Draft communication templates for common scenarios: account closures following SAR filings, Enhanced Due Diligence requests triggered by suspicious activity, and transaction blocks pending compliance review. Have legal and compliance jointly approve language that explains concerns without Tipping Off.
Revise your Escalation to MLRO procedures to include decision criteria for when investigators should engage with SAR subjects versus when they should maintain information barriers. Document those criteria so your approach is consistent and defensible during examinations.
Medium-term (next year):
Analyze whether increased transparency with customers reduces repeat suspicious activity or improves information gathering during investigations. Track metrics: SAR subject response rates to information requests, account closure appeal rates, and regulatory examination findings related to customer communication.
Consider whether this clarification changes your risk appetite for certain customer segments. If you've been automatically exiting customers after a single SAR to avoid communication complexity, you might now retain relationships where additional due diligence could resolve concerns.



