Federal Agencies Clarify What Banks Can Tell Customers When Fraud Is Suspected

Five federal financial regulators issued a joint statement on September 2, 2026, providing long-awaited clarity on what banks can communicate to customers when suspicious activity is involved.

The agencies involved include the Federal Reserve, the FDIC, the NCUA, the OCC, and the Financial Crimes Enforcement Network, known as FinCEN.

The statement directly addresses one of the most persistently confusing questions in bank compliance: what can institutions say to customers when a Suspicious Activity Report, or SAR, has been filed.

Under the Bank Secrecy Act, financial institutions are prohibited from disclosing the existence of a SAR to the person who is the subject of that report.

However, the joint statement makes clear that banks and credit unions can discuss the underlying facts, transactions, and documents upon which a SAR is based without violating confidentiality rules.

The key regulatory distinction, as clarified by the agencies, is that communicating underlying facts does not constitute revealing the existence of a SAR itself.

The statement acknowledges that a reasonable and prudent person familiar with SAR filing requirements might suspect a SAR was filed, but underlying information alone does not constitute impermissible disclosure.

The genesis of the statement traces to a June 2025 Request for Information issued by the Federal Reserve, FDIC, and OCC seeking input on actions to mitigate payments fraud, with a particular focus on check fraud.

Commenters raised pointed concerns about bank personnel’s ability to communicate transparently with customers when a SAR had been filed regarding potentially fraudulent activity.

The joint statement also recognises concerns expressed in Executive Order 14331, Guaranteeing Fair Banking for All Americans, which prohibits agencies from directing institutions to terminate customer relationships based on political views or lawful activities.

The agencies provided a non-exhaustive list of permitted communications, including notifying customers that an account delay or closure may be related to suspected fraud or suspicious activity.

Banks may also notify customers that a deposit has been rejected due to suspected fraud, such as when checks are found to be altered or counterfeit.

Institutions are additionally permitted to warn customers about fraud schemes and typologies, including situations where a customer may unknowingly be participating in a money mule scheme.

Compliance officers and BSA and AML teams should review current customer communication policies immediately to ensure they reflect the clarification provided by the joint statement.

Frontline staff, branch managers, and fraud investigation teams should all receive updated training on the distinction between permissible discussion of underlying facts and impermissible SAR disclosure.

Critically, the joint statement does not alter an institution’s independent, risk-based authority to close or restrict customer accounts based on its own assessment.

Banks retain full authority to close accounts, decline transactions, and restrict services based on internal risk tolerances, suspicious activity patterns, or other legitimate risk-based criteria.

The joint statement arrives alongside FinCEN’s sweeping Notice of Proposed Rulemaking, issued on April 7, 2026, proposing the most significant overhaul of BSA and AML program requirements in over two decades.

That proposed rule shifts the regulatory focus from process-driven, check-the-box compliance toward an outcomes-based, risk-focused framework for evaluating AML and CFT programmes.

Together, the SAR confidentiality statement and the reform proposals signal a regulatory environment that rewards proactive, risk-based compliance programmes and transparent customer engagement above rigid procedural adherence.