Skip to main content
Category: Suspicious Activity Reporting

SAR Confidentiality

Also known as: N/A, SAR Confidentiality Rule, Prohibition on SAR Disclosure, SAR Non-Disclosure
Simply put

SAR confidentiality is the US rule that a Suspicious Activity Report, and any information revealing that a SAR exists, must be kept secret and generally cannot be disclosed. This protection is intended to prevent tipping off the subject of a report or third parties, which could undermine an investigation. It applies to financial institutions and their employees and agents, with only limited exceptions permitted by law.

Formal definition

Under the US Bank Secrecy Act framework as implemented in FinCEN regulations, a SAR and any information that would reveal the existence of a SAR are confidential and may not be disclosed except as authorized or as necessary to fulfill BSA obligations and responsibilities. The confidentiality provision applicable to depository institutions appears at 31 CFR 1020.320(e), with parallel provisions for other categories of financial institutions and in the functional regulators' rules (for example, 12 CFR 163.180 for certain savings associations). The prohibition covers the SAR itself and information disclosing its existence; however, the underlying facts, transactions, and records that support a SAR are not themselves rendered confidential by the rule and may generally be disclosed so long as the disclosure does not reveal that a SAR exists or was filed. Financial institutions are expected to maintain the confidentiality of SARs across employees, agents, and other relevant parties. This is a regulatory/compliance obligation; institutions should confirm the precise scope of exceptions and the applicable citation for their entity type against the current regulation.

Why it matters

SAR confidentiality is a cornerstone of the US suspicious activity reporting regime because it protects the integrity of investigations that may follow a filing. If the subject of a report, or a third party, learns that a SAR has been filed, they may destroy evidence, move funds, or otherwise frustrate law enforcement inquiries. For this reason, the rule prohibits disclosure not only of the SAR itself but also of any information that would reveal the existence of a SAR, subject to limited exceptions permitted by law.

The obligation carries real operational weight for financial institutions and their employees and agents. FinCEN has publicly reminded institutions to remain vigilant in maintaining SAR confidentiality, including ensuring that all employees and agents understand the prohibition. A breach can expose an institution and individuals to regulatory consequences and can compromise ongoing matters, so many institutions build controls, access restrictions, and training around who may see a SAR or learn of its existence.

It is important to distinguish what the rule does and does not cover. The confidentiality protection attaches to the SAR and to information disclosing that a SAR was filed, not to the underlying facts, transactions, and records that support it. Those underlying records may generally be disclosed for other legitimate purposes, so long as the disclosure does not reveal that a SAR exists or was filed. Misunderstanding this boundary can lead either to improper tipping-off or to over-withholding of information that a business may lawfully share. Institutions should confirm the precise scope of exceptions and the citation applicable to their entity type against the current regulation.

Who it's relevant to

AML Compliance Officers and BSA Officers
Compliance and BSA officers are responsible for filing SARs and for ensuring that the report and any information revealing its existence are kept confidential. They typically design access controls, handling procedures, and training so that only authorized personnel encounter SARs, while ensuring the institution can still lawfully share underlying facts and records that do not reveal a SAR's existence.
Financial Institution Employees and Agents
FinCEN has emphasized that confidentiality obligations extend to all employees and agents. Front-line staff, relationship managers, and others who may come into contact with SAR-related information must understand that they may not disclose a SAR or the fact that one exists, and must be able to distinguish this from the underlying transactional records that may be shared for other legitimate purposes.
Legal, Risk, and Internal Audit Functions
In-house counsel and risk and audit teams assess whether the institution's handling of SARs complies with the confidentiality provisions applicable to its entity type, for example, 31 CFR 1020.320(e) for depository institutions or parallel provisions elsewhere. They also evaluate whether requests for information (such as litigation or subpoena demands) can be satisfied without improperly revealing the existence of a SAR.
Financial Intelligence and Investigations Analysts
Analysts who investigate suspicious activity and prepare SARs rely on confidentiality to prevent tipping off subjects and third parties, which could adversely affect a matter. They must handle SAR narratives and filing records within controlled channels while recognizing that the supporting facts and transactions themselves are not made confidential by the rule.

Inside N/A

SAR Confidentiality Prohibition ('No Tipping-Off')
Under the US Bank Secrecy Act framework and FinCEN's implementing rules, a financial institution, and its directors, officers, employees, and agents, are generally prohibited from disclosing that a Suspicious Activity Report has been filed or from disclosing information that would reveal the existence of a SAR. For banks, this prohibition is codified at 31 CFR 1020.320(e); parallel provisions exist for other categories of obliged entity in their respective SAR rules. This is distinct from broader anti-tipping-off concepts in other regimes (for example, the UK's tipping-off offense under the Proceeds of Crime Act), which are structured differently.
Scope of Protected Information
The confidentiality protection attaches to the SAR itself and to any information that would reveal that a SAR has been filed or the fact of its existence. Importantly, it does not automatically shield underlying facts, records, or documentation from disclosure; the underlying transaction records and facts may generally be disclosed for other lawful purposes so long as the disclosure does not reveal the existence of a SAR, consistent with 31 CFR 1020.320(e)(1)(ii)(A)(2). Practitioners should distinguish the protected filing from the discoverable underlying records.
Permitted Disclosures and Exceptions
The rules recognize certain disclosures that are not prohibited, such as sharing with FinCEN, appropriate law enforcement or supervisory agencies exercising oversight, and, in defined circumstances, within an organization or corporate group for purposes consistent with the BSA. The precise contours of permissible information sharing vary and should be confirmed against the applicable FinCEN rule and any relevant guidance, as exceptions are construed narrowly.
Terminology and Jurisdictional Variation
In the United States the report is a Suspicious Activity Report (SAR); many other jurisdictions use the term Suspicious Transaction Report (STR) or Suspicious Activity Report under their own regimes, and the associated confidentiality and tipping-off rules differ in source, scope, and penalties. The FATF Recommendations set an international standard supporting confidentiality of reporting, but they are standards rather than binding law, and each jurisdiction implements them differently.
Consequences of Unauthorized Disclosure
Unauthorized disclosure of a SAR or its existence may expose the institution and individuals to regulatory and, potentially, criminal exposure under the applicable regime. This is a compliance and legal-risk consideration; the existence of a SAR filing does not itself establish that any underlying wrongdoing occurred.

Common questions

Answers to the questions practitioners most commonly ask about N/A.

Does SAR confidentiality mean I can never tell anyone that a suspicious activity report was filed?
Not exactly. In the US, the prohibition targets disclosing the existence of a SAR (or its contents) to unauthorized persons, particularly the subject of the report. However, the confidentiality rule includes permitted disclosures, for example, to FinCEN, to appropriate law enforcement and supervisory agencies, and within the institution and its affiliates for certain purposes consistent with applicable rules. The core prohibition is on tipping off the subject or revealing that a SAR exists to those not entitled to know, not an absolute bar on all communication about the underlying matter.
If a SAR is confidential, does that mean all the underlying documents and facts behind it are also protected and cannot be disclosed?
No. The confidentiality protection attaches to the SAR itself and to any information that would reveal its existence. The underlying facts, transaction records, and supporting documentation are not automatically off-limits; they may generally be disclosed in appropriate circumstances so long as the disclosure does not reveal that a SAR was filed. In other words, an institution can typically produce the underlying records without breaching confidentiality, provided it does not indicate or imply the existence of a SAR. Institutions should confirm the specifics against the applicable regulation, as these are US framework rules.
Which regulation governs SAR confidentiality for banks in the US?
For banks, the SAR confidentiality requirement is set out in the FinCEN rules under the Bank Secrecy Act, at 31 CFR 1020.320(e). This provision addresses the prohibition on disclosure and the scope of permitted disclosures. Parallel provisions exist for other categories of financial institutions in their respective parts of 31 CFR Chapter X. Because these are US-specific rules, institutions operating in other jurisdictions should identify the equivalent confidentiality or tipping-off provisions under their own regimes.
Can my institution share a filed SAR with an affiliate or within a corporate group?
Under the FinCEN framework at 31 CFR 1020.320(e), certain intra-group and affiliate sharing may be permitted for specified purposes, subject to conditions and guidance issued by FinCEN. Institutions should establish internal policies defining who may access SAR information and document the legal basis for any sharing. Because the permitted scope can be nuanced and has been the subject of separate FinCEN guidance, the precise parameters should be confirmed against the current rule and guidance before sharing.
How should staff respond if a customer or a third party asks whether a SAR has been filed on them?
Staff should be trained not to confirm or deny the existence of a SAR to the subject or to any unauthorized person, as revealing that a SAR exists is what the confidentiality rule prohibits. Institutions typically establish scripted responses and escalation paths so front-line staff can handle such inquiries without breaching confidentiality. This is an operational control designed to prevent tipping off; it does not, by itself, prevent underlying facts from being addressed through legitimate channels that do not disclose the SAR.
What controls help an institution maintain SAR confidentiality in practice?
Common operational measures include restricting access to filed SARs on a need-to-know basis, segregating SAR records from general case files, applying access logging and role-based permissions, and training relevant staff on the tipping-off prohibition and on distinguishing the SAR from the underlying records. These are measures to manage and mitigate the risk of unauthorized disclosure; they support compliance but do not guarantee that no breach will occur, so institutions should periodically test and review their controls.

Common misconceptions

SAR confidentiality means all documents and records connected to the suspicious activity are secret and cannot be produced.
The prohibition protects the SAR and information revealing its existence, not the underlying facts and records themselves. Underlying transaction records and factual information may generally be disclosed for lawful purposes so long as the disclosure does not reveal that a SAR was filed, consistent with 31 CFR 1020.320(e)(1)(ii)(A)(2).
The confidentiality rule is a single global standard that applies identically everywhere.
Confidentiality and anti-tipping-off obligations are set by each jurisdiction's own instruments. In the US, the bank SAR confidentiality rule sits at 31 CFR 1020.320(e), while other regimes such as the UK use different mechanisms (for example, the tipping-off offense under the Proceeds of Crime Act). The FATF Recommendations encourage reporting confidentiality but are standards, not binding law, and exact scope and penalties vary.
Because a SAR is confidential, its filing cannot be shared with anyone at all.
The rules permit certain disclosures, such as to FinCEN and appropriate law enforcement or supervisory authorities, and, in defined circumstances, within a corporate group consistent with the BSA. These exceptions are limited and should be confirmed against the applicable FinCEN rule and guidance before relying on them.

Best practices

Distinguish between the protected SAR filing and the underlying transaction records; establish procedures that allow lawful disclosure of underlying facts and records where required, without revealing that a SAR was filed.
Maintain access controls and 'need-to-know' handling for SARs and any information indicating a SAR's existence, and document who has access and why.
Cite and rely on the correct source instrument for the entity type; for banks in the US, reference 31 CFR 1020.320(e), and confirm the parallel provision applicable to other obliged-entity categories.
Train staff to recognize the difference between the US SAR confidentiality regime and other jurisdictions' STR and tipping-off rules, so cross-border operations apply the correct standard.
Route any request for a SAR or SAR-related information through legal or compliance to assess whether a permitted exception applies before responding, rather than disclosing directly.
Confirm exact requirements, exceptions, and any applicable penalties against the current FinCEN rules and guidance for the relevant obliged entity, as scope and detail can change and vary by regime.