When your team closes a customer's account and your call center tells them "we filed a suspicious activity report," you've just violated 31 U.S.C. § 5318(g)(2). This isn't a hypothetical situation. It's recorded and creates liability for both the institution and the employee who disclosed it.
The Federal Reserve, FDIC, FinCEN, NCUA, and OCC issued a joint statement on September 2, 2026, clarifying how financial institutions can communicate with customers about suspicious activity without breaching SAR Confidentiality. The statement doesn't introduce new requirements. It explains what existing rules permit because compliance teams keep making the same preventable mistakes.
Why These Mistakes Keep Happening
SAR Confidentiality violations often stem from a misunderstanding: teams think the entire fraud investigation is confidential, so they either say nothing or over-explain and accidentally disclose the Suspicious Activity Report itself.
The reality is more nuanced. The SAR document and any information revealing its existence are confidential. The underlying facts, transactions, dates, amounts, and counterparties are not. You can discuss the suspicious wire transfer, but you cannot tell the customer you reported it to FinCEN.
Most violations occur because institutions don't train staff on this distinction. Customer service representatives, branch managers, and fraud analysts handle account restrictions daily but receive no guidance on what language crosses the line. Without clear procedures, well-meaning employees either freeze up or say too much.
Mistake 1: Refusing to Explain Account Closures
Why it happens: Compliance teams often interpret SAR Confidentiality as a blanket prohibition on discussing any aspect of a suspicious activity investigation. When a customer asks why their account was closed, staff say "we can't discuss it" and hang up.
The consequence: This approach damages customer relationships unnecessarily and doesn't actually protect SAR Confidentiality. Customers escalate to regulators, social media, or legal counsel. You've created a reputational problem while misapplying the rule.
The fix: Train staff to discuss the underlying facts without referencing the SAR. You can say: "We closed your account because we identified transactions that raised concerns about possible fraud or unauthorized activity." You can reference specific transaction dates, amounts, and patterns. You cannot say: "We filed a Suspicious Activity Report" or "This triggered our Suspicious Activity Report threshold."
The joint statement explicitly permits institutions to notify customers that an account has been restricted or terminated because of suspected fraud or other suspicious activity. Use that language.
Mistake 2: Letting Untrained Staff Handle SAR-Related Customer Calls
Why it happens: Institutions route customer inquiries about account restrictions to general call centers or branch staff who haven't received SAR Confidentiality training. The assumption is that fraud or AML teams will handle the investigation, and customer-facing staff just need to deflect questions.
The consequence: Untrained employees make two types of errors. Some disclose the Suspicious Activity Report directly: "Your account was flagged and we had to file a report with the government." Others invent explanations that contradict the actual facts, creating inconsistent records that complicate investigations.
The fix: Implement a tiered response protocol. General staff should use pre-approved language: "I'll connect you with our fraud resolution team, who can discuss the specific transactions and next steps." Route SAR-related inquiries to trained specialists who understand the distinction between underlying facts and SAR information.
Your training program should include scenario-based exercises. Present staff with realistic customer questions and require them to draft compliant responses. Review call recordings quarterly to identify language patterns that risk disclosure.
Mistake 3: Putting SAR References in Customer-Facing Documents
Why it happens: Internal workflows blur the line between operational records and customer communications. A fraud analyst notes "SAR filed 03/15" in the account management system, and that notation appears on a letter the customer receives about their account closure.
The consequence: You've created a written record of SAR disclosure. Unlike a verbal slip that's hard to prove, this documentation establishes the violation. It also signals to the customer that they're under investigation, potentially compromising law enforcement efforts.
The fix: Separate your internal SAR tracking systems from customer communication templates entirely. Use distinct databases or fields that cannot populate customer-facing letters, emails, or portal messages.
When documenting account decisions, use neutral language in any system that generates customer correspondence: "Account closed due to activity inconsistent with expected use" rather than "Account closed pending SAR review." Implement approval workflows that require compliance review before any communication referencing suspicious activity goes to a customer.
Mistake 4: Failing to Coordinate Across Fraud and AML Teams
Why it happens: Fraud teams focus on preventing losses and recovering funds. AML teams focus on regulatory reporting. They operate in separate systems with different timelines, and neither team knows what the other has told the customer.
The consequence: The fraud team tells a customer their wire transfer was blocked because "we're investigating potential money laundering." The AML team later files a Continuing Activity SAR. The customer now knows a report exists because the fraud team used language that directly implies regulatory filing.
The fix: Establish a communication protocol that requires fraud and AML teams to log all customer interactions in a shared case management system before taking action. When fraud blocks a transaction, AML should review the proposed customer notification language before it's sent.
Create standard phrases that both teams use consistently: "suspected unauthorized activity," "potential fraud," "activity that violates our account terms." Avoid "money laundering," "terrorist financing," or "suspicious activity reporting" in customer communications. These terms signal regulatory processes, not just fraud prevention.
Mistake 5: Assuming "Suspicious Activity" Language Is Always Safe
Why it happens: Compliance teams know they can discuss suspicious activity with customers, so they use the phrase liberally, thinking it's a safe substitute for mentioning the SAR itself.
The consequence: Context matters. Telling a customer "we identified suspicious activity and restricted your account" is permissible. Telling them "we're required to report suspicious activity to federal authorities within 30 days" reveals the Suspicious Activity Report timeline and process, which discloses the existence of a SAR.
The fix: Train staff to describe the behavior or transaction pattern, not the regulatory classification. Instead of "your transactions met the threshold for suspicious activity reporting," say "we identified multiple wire transfers to high-risk jurisdictions that didn't match your stated business purpose."
When customers ask directly whether you filed a SAR, use the approved response: "We can't discuss whether we've filed regulatory reports, but we can explain the transaction concerns that led to this account decision." Then pivot back to the underlying facts.
Prevention Checklist
Before you communicate with a customer about fraud, account restrictions, or closures related to potentially suspicious activity:
- Confirm the employee has completed SAR Confidentiality training within the past 12 months
- Review the communication for any language that references "filing," "reporting to authorities," "SAR," or "FinCEN"
- Verify that the explanation focuses on transaction facts (dates, amounts, counterparties, patterns) rather than regulatory processes
- Check that internal SAR tracking codes or references cannot appear in customer-facing systems
- Log the planned communication in your case management system so fraud and AML teams can coordinate messaging
- Prepare a response to "Did you file a SAR?" that acknowledges the question without confirming or denying
- Document the communication method, content, and customer response in case of future regulatory examination
The joint statement clarifies that SAR Confidentiality doesn't prevent you from talking to customers about fraud. It prevents you from telling them you filed a report. Master that distinction, and you'll avoid the mistakes that create unnecessary violations.



