Understanding the Joint Statement on SAR Confidentiality
Since September 2, 2026, when the Federal Reserve, FDIC, NCUA, OCC, and FinCEN issued their Joint Statement on SAR confidentiality and customer communication, BSA officers have been grappling with practical questions: what changed, what didn't, and how to implement this guidance effectively?
These questions aren't theoretical. They're what your fraud investigators ask when a customer demands to know why their wire was rejected. They're what your branch managers need to explain account closures without missteps. They're what your legal team considers when reviewing scripts for the contact center.
Here's what the field is asking, and what the guidance actually says.
Can We Tell Customers We Filed a SAR?
No, you cannot.
The Joint Statement doesn't change the core prohibition. You still can't disclose that a SAR has been filed or reveal information indicating a SAR's existence. That's 31 CFR 1020.320(e), and it remains unchanged.
What has changed is the clarification on what you can discuss: the underlying facts, transactions, and documents on which a SAR is based. You can talk about the wire transfer that raised concerns or explain why a pattern of deposits looks unusual. You can tell a customer their account activity triggered internal fraud controls.
However, you can't say "we filed a Suspicious Activity Report" or imply it. The line is between discussing the activity and disclosing the filing.
What if the Customer Figures It Out?
The guidance addresses this directly.
Even if a customer suspects or deduces from your conversation that a SAR was filed, that alone doesn't violate SAR confidentiality. The standard isn't whether a sophisticated customer could guess, but whether your communication reveals it.
This clarification removes the paralysis many institutions have felt. You don't need to avoid every conversation that might make someone wonder. You need to avoid conversations that disclose the SAR itself.
Document your approach. If a customer asks directly whether you filed a SAR, respond without confirming or denying. "We can't discuss internal compliance filings, but I can walk you through the transactions that raised concerns" keeps you compliant.
Can We Explain Why We're Closing an Account?
Yes. The statement confirms you can inform customers about account restrictions or closures.
This has been a major issue. Many institutions used vague scripts to avoid revealing a SAR, which created friction, especially when the customer wasn't the bad actor but was targeted by fraud.
You can now explain that the account was used in a way that violated your terms, that transaction patterns raised fraud concerns, or that the account was involved in activity inconsistent with its stated purpose. Offer to help the customer understand what happened and how to protect themselves.
What you can't do is say "we filed a SAR and therefore we're closing your account." Explain the closure in terms of the underlying facts and your institution's risk tolerance, not the filing.
Can We Talk to Other Banks?
Yes, and this ties into the updated Section 314(b) guidance FinCEN issued on June 12, 2026.
SAR confidentiality doesn't prevent you from sharing underlying facts with other financial institutions. If you see a pattern of suspicious wire activity involving accounts at another bank, you can share transaction details, dates, amounts, and parties involved without disclosing that you filed or plan to file a SAR.
This is crucial for fraud rings operating across multiple institutions. The constraint has never been "you can't share information." It's been "you can't reveal the SAR." The Joint Statement reaffirms that distinction and encourages information sharing about underlying facts.
How Do We Train Front-Line Staff?
Update your scripts and procedures to reflect what's actually prohibited versus what's been institutional caution.
Your fraud investigators need clear examples of compliant language. "We've identified transactions that don't match your account profile and need to understand the source of these funds" is compliant. "We're required to file a government report about this activity" is not.
Your branch managers need to know they can discuss account closures in terms of the underlying activity without resorting to vague corporate-speak. Your contact center needs scripts that explain fraud holds and rejected deposits without creating confidentiality exposure.
Role-play challenging scenarios. What does an investigator say when a customer asks, "Are you reporting me?" What does a branch manager say when someone demands to know why their business account was closed after large cash deposits? Practice the distinction between discussing facts and revealing filings.
Do We Need to Document Every Customer Conversation?
You should already be documenting decisions around SARs, including communications with customers about the underlying activity. That's not new.
The Joint Statement reinforces that customer communication during a fraud investigation isn't evidence of a confidentiality breach. It's part of managing the relationship and the risk. Your documentation should show that you discussed the underlying facts without revealing the SAR, provided appropriate fraud education, and made decisions based on the activity itself.
If you're closing an account and having a conversation about it, document what you said and why. If you're rejecting a deposit due to suspected fraud, document the explanation you provided. That record protects you if the customer later claims they weren't informed or if regulators ask how you balanced transparency with confidentiality.
Can We Educate Customers on Fraud Typologies?
The statement specifically calls out "money mule" schemes as an example of appropriate educational communication. If your investigation suggests a customer may be unknowingly involved in a scam, you can and should explain the typology.
"We're seeing a pattern consistent with a money mule scheme, where someone is asked to receive and forward funds as part of what they believe is a legitimate job" is both compliant and helpful. You're not disclosing a SAR. You're providing context that might prevent further victimization.
This applies to romance scams, business email compromise, and other fraud types where the customer may not realize they're being used. The guidance allows you to have those conversations without worrying that education equals disclosure.
Does This Change What We Put in the SAR Narrative?
No. The Joint Statement clarifies external communication boundaries, not SAR content requirements. Your narrative should still be complete, specific, and include all relevant facts about the suspicious activity.
What it does change is your ability to discuss those same facts outside the SAR context. The underlying transaction details you include in the SAR can also be discussed with the customer, with other institutions, or with law enforcement without violating confidentiality, as long as you don't reveal the SAR itself.
Next Steps
The Joint Statement is short and readable. If you haven't read it yet, start there. It's clarification, not new regulation, but the distinction it draws between the SAR and the underlying facts is the operational guidance many institutions have needed for years.
Pair it with the June 12, 2026, Section 314(b) guidance on information sharing. Together, they provide a framework for transparent customer communication and cross-institution collaboration that aligns with how fraud investigations actually work.
Update your procedures now. Your fraud team needs clarity today, and your customers deserve better communication than they've been getting under overly cautious interpretations of SAR confidentiality.




