Scope
This guide helps you communicate with customers about account restrictions, transaction declines, and suspicious activity inquiries without violating SAR confidentiality requirements under 31 U.S.C. § 5318(g)(2) of the Bank Secrecy Act. It's for compliance officers, customer service managers, and frontline staff dealing with customers whose activities trigger monitoring alerts or filing decisions.
Recent clarification from five federal regulators confirms that you can discuss suspicious activity with customers, but only if you follow specific guidelines. This guide shows you where those lines are.
Key Concepts and Definitions
SAR Confidentiality: The Bank Secrecy Act prohibits disclosing that you've filed, or intend to file, a Suspicious Activity Report. The statute at 31 U.S.C. § 5318(g)(2) makes it unlawful to notify "any person involved in the transaction that the transaction has been reported."
Discussing vs. Disclosing: You can ask customers about transaction patterns, sources of funds, or business purposes. You cannot tell them you've filed a SAR or that their activity is "suspicious" in a way that implies reporting.
Tipping Off: Providing information that reveals, directly or indirectly, that a SAR exists or that law enforcement is investigating. This isn't just about saying "we filed a SAR", it includes circumstantial disclosure through timing, word choice, or action patterns.
Safe Harbor: 31 U.S.C. § 5318(g)(3) protects financial institutions from civil liability for filing SARs in good faith, but this protection doesn't extend to violations of SAR confidentiality.
Requirements Breakdown
What You Cannot Disclose
Under 31 U.S.C. § 5318(g)(2), you cannot:
- State that you've filed a FinCEN SAR (Form 111) on the customer.
- Indicate that you intend to file a SAR based on current activity.
- Reference the Suspicious Activity Report process, timelines, or internal review stages.
- Suggest that law enforcement has requested information about the customer.
- Use language that implies the customer is under investigation.
What You Can Discuss
Regulatory clarification permits you to:
- Ask customers to explain transaction purposes, counterparties, or fund sources.
- Request supporting documentation for unusual activity patterns.
- Decline transactions or restrict account features based on your risk appetite.
- Explain that you're conducting enhanced due diligence as part of your AML/CFT framework.
- Notify customers of account closures or service terminations.
Implementation Guidance
Customer Inquiries About Declined Transactions
When a customer asks why you declined a wire transfer or blocked a transaction:
Acceptable response: "We couldn't process this transaction based on our internal risk controls. Can you provide documentation showing the business purpose and the relationship with the recipient?"
Prohibited response: "This transaction raised red flags in our monitoring system, and we need to investigate before we can proceed."
The difference: The first focuses on your decision-making authority. The second implies ongoing suspicious activity analysis that could suggest Suspicious Activity Report.
Account Restrictions and Enhanced Due Diligence
You're permitted to place customers into enhanced due diligence or restrict account features without explaining the underlying monitoring alert. Frame restrictions as risk-based decisions:
Script for customer service: "Based on our periodic review of your account activity, we're requesting updated information about your business operations and expected transaction patterns. This is part of our ongoing due diligence process."
Don't reference specific transactions that triggered the review unless you can do so without implying SAR consideration.
Account Closures
You can close accounts for risk reasons without disclosing SAR filings. Many institutions use standard termination language:
Template: "We've decided to end our banking relationship with you. We'll provide [X days] notice as outlined in our account agreement. Your funds will be available for withdrawal during this period."
You're not required to provide a reason for closure, and doing so often creates more risk than staying silent.
Documentation Requests
When conducting enhanced due diligence after suspicious activity, your requests should focus on understanding legitimate business operations:
- "Please provide invoices for the three largest payments you received last month."
- "Can you explain the business relationship with [counterparty name]?"
- "What's the source of the $50,000 deposit on [date]?"
These questions gather information for your customer risk profile without suggesting that you've made a filing decision.
Common Pitfalls
Timing-Based Disclosure
Filing a SAR on Monday and closing the account on Tuesday creates an obvious pattern. Space out your actions when possible, or ensure your closure decision is independently documented based on risk tolerance, not Suspicious Activity Report.
Inconsistent Treatment
If you always ask for documentation after filing SARs but never ask during routine reviews, customers (and their attorneys) will notice. Build documentation requests into your periodic review process so they're not SAR-specific signals.
Over-Explaining Declines
Frontline staff often want to be helpful by explaining exactly why a transaction failed. Train them to provide minimal information: "We couldn't process this transaction. You can try a different payment method or contact our compliance team for review."
Email and Written Communications
Avoid putting anything in writing that references "suspicious," "unusual," "red flags," or "under review." Written records are discoverable and can undermine your confidentiality obligations if they imply SAR consideration.
Third-Party Disclosure
SAR confidentiality extends to your service providers, auditors, and parent companies. If you share SAR-related information with a vendor, ensure your contract includes confidentiality obligations that mirror 31 U.S.C. § 5318(g)(2).
Quick Reference Table
| Scenario | Can Discuss? | Safe Phrasing | Avoid |
|---|---|---|---|
| Transaction declined | Yes | "Our risk controls prevented this transaction" | "This transaction is suspicious" |
| Requesting documentation | Yes | "We need invoices to verify business purpose" | "We're investigating unusual activity" |
| Account closure | Yes | "We're ending the banking relationship" | "Your activity violated our AML/CFT Framework" |
| Enhanced due diligence | Yes | "We're conducting a periodic review" | "Your transactions triggered alerts" |
| Law enforcement inquiry | No | [Say nothing to customer] | "We've been asked to provide information" |
| Suspicious Activity Report decision | No | [Say nothing to customer] | "We need to file a report on this" |
| Ongoing monitoring | Yes | "We review all accounts regularly" | "You're on our watchlist" |
| Service restrictions | Yes | "We're limiting certain features based on risk" | "We can't offer this service due to compliance concerns" |
Key principle: You can manage risk, ask questions, and make business decisions. You cannot reveal the existence, consideration, or filing of a SAR.



