Regulators Clarify What Banks Can (and Can't) Tell Customers About SARs
Five federal regulators — OCC, Federal Reserve, FDIC, FinCEN, and NCUA — jointly clarified the rules around SAR confidentiality when institutions communicate with customers about potentially fraudulent transactions. The statement addresses a persistent compliance tension: institutions must protect SAR confidentiality (including not 'tipping off' subjects) while still being able to warn or question customers about suspicious activity without inadvertently disclosing a SAR has been filed. Compliance officers should review customer-facing fraud communication workflows to ensure staff are not crossing the tipping-off line.
What to do
- Review and update internal SAR confidentiality policies and customer communication scripts — particularly those used in fraud outreach or account review conversations — to ensure alignment with the joint statement's clarified guidance.
Who this affects
Does this affect your program?
Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.
Source
Read the official publicationThis radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.