All developments
OCCBSA / AMLSeptember 2, 2026

Regulators Clarify What Banks Can (and Can't) Tell Customers About SARs

Five federal regulators — OCC, Federal Reserve, FDIC, FinCEN, and NCUA — jointly clarified the rules around SAR confidentiality when institutions communicate with customers about potentially fraudulent transactions. The statement addresses a persistent compliance tension: institutions must protect SAR confidentiality (including not 'tipping off' subjects) while still being able to warn or question customers about suspicious activity without inadvertently disclosing a SAR has been filed. Compliance officers should review customer-facing fraud communication workflows to ensure staff are not crossing the tipping-off line.

What to do

  • Review and update internal SAR confidentiality policies and customer communication scripts — particularly those used in fraud outreach or account review conversations — to ensure alignment with the joint statement's clarified guidance.

Who this affects

Bank / Credit UnionMoney Services BusinessCrypto ExchangeFintech / NeobankTrust CompanyCrypto Custodian

Does this affect your program?

Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.

Source

Read the official publication

This radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.

Related developments

FinCEN

FinCEN GTO: Southwest Border MSBs Must Report Cash Transactions $1K–$10K

FinCEN has issued a Geographic Targeting Order (GTO) requiring certain money services businesses operating along the U.S. southwest border to report and retain records of cash transactions between $1,000 and $10,000 — well below the standard $10,000 CTR threshold — and to verify the identity of customers presenting such transactions. This is a significant AML/BSA escalation for covered MSBs in the targeted geography, effectively lowering the transaction monitoring and KYC trigger point for cash dealings. Non-compliance with a GTO carries the same penalties as violations of the Bank Secrecy Act.

FinCEN

FinCEN Proposes Cutting Off UAE Branches of Banque Misr Over Money Laundering Risk

FinCEN is proposing to designate the UAE-based branches of Banque Misr as a primary money laundering concern under Section 311 of the USA PATRIOT Act. If finalized, U.S. financial institutions would be prohibited from opening or maintaining correspondent accounts for Banque Misr UAE, required to take reasonable steps to block transactions involving Banque Misr UAE flowing through foreign correspondent accounts, and required to apply enhanced due diligence to foreign correspondent accounts to prevent their use for such transactions. Any firm that maintains foreign correspondent banking relationships — including crypto exchanges and fintechs with banking partners — must ensure Banque Misr UAE exposure is identified and addressed.

OCC

OCC Proposes Two-Tier Framework for Violations: Substantive vs. Technical

The OCC is proposing to split regulatory violations into 'substantive' and 'technical' categories to better calibrate supervisory responses, including when Matters Requiring Attention (MRAs) are issued. For banks and trust companies engaged in crypto or fintech activities, this could affect how examiners escalate findings related to BSA/AML, KYC, or digital asset compliance gaps. Comment period is open, giving institutions an opportunity to shape the final framework.

OCC

OCC Revises Enforcement Action and MRA Policies and Procedures

The OCC has released updated internal policy manuals governing how bank enforcement actions and Matters Requiring Attention (MRAs) are issued and managed. These revisions signal a shift toward greater consistency and transparency in how the OCC responds to supervisory findings, which is directly relevant to banks and trust companies navigating crypto, BSA/AML, and fintech-related examination findings. Compliance officers should review the updated PPMs to anticipate examiner expectations.

Stay ahead of every rule change

PliOS monitors FinCEN, OCC, OFAC, the SEC and CFTC and tells you which of your policies each new rule affects — with the edit already drafted. Start free.

Run My Free Assessment