How to Explain Suspected Fraud to Customers Without Crossing SAR Confidentiality Lines
Read Time 4 mins | Written by: Karly Field
When a financial institution identifies suspicious activity in a customer’s account, one of the hardest operational questions can be surprisingly simple:
What can we actually tell the customer?
For years, the confidentiality surrounding Suspicious Activity Reports, or SARs, has sometimes made financial institutions cautious about discussing suspicious transactions, fraud investigations or account restrictions with customers.
New joint guidance from federal regulators provides useful clarification.
On September 2, 2026, the Financial Crimes Enforcement Network (FinCEN), Federal Reserve, Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA) and Office of the Comptroller of the Currency (OCC) issued a joint statement addressing SAR confidentiality and customer communications.
The central message is straightforward: SAR confidentiality does not prevent a bank or credit union from discussing the underlying transactions, facts and concerns with a customer, as long as the institution does not disclose the existence of a SAR.
That distinction can be particularly important when financial institutions are responding to payment fraud, including check fraud, suspected money mule activity, transaction restrictions or account closures.
What Has Not Changed
The agencies were explicit that the joint statement does not alter existing Bank Secrecy Act requirements or establish new supervisory expectations.
SAR confidentiality remains mandatory.
The BSA prohibits disclosure of a SAR or information that would reveal the existence of a SAR, including to a customer or another person who is the subject of the report.
What the guidance does is clarify where that confidentiality boundary ends.
Under FinCEN’s regulations, the confidential information protected by the SAR rules does not include the underlying facts, transactions and documents upon which a SAR is based.
That gives financial institutions more room to communicate about the underlying activity than some institutions may have assumed.
What Financial Institutions Can Discuss
According to the joint statement, financial institutions may discuss factual information associated with the transaction, including transaction dates, amounts and parties, provided the communication does not reveal the existence of a SAR.
The agencies also provided examples of customer communications that would generally not violate SAR confidentiality. These include:
- Requesting information or documentation needed for customer due diligence and development of a customer risk profile.
- Telling a customer that a delay, limitation or restriction on an account or service, or an account closure, may be related to suspected fraud or other suspicious activity.
- Telling a customer that a deposit was rejected because of suspected fraud or suspicious activity, including situations involving altered or counterfeit checks.
- Asking about the purpose of a transaction or the source of funds.
- Providing warnings or educational information about fraud schemes, including situations in which a customer may be knowingly or unknowingly participating in a money mule scheme.
- Communicating account or service decisions, such as declining a transaction or closing an account.
- Requesting information about the originator or beneficiary of a funds transfer.
For community financial institutions, those examples provide something operational teams have often needed: clearer separation between discussing the suspicious activity and discussing the SAR.
The first may be appropriate. The second remains confidential.
Consider Customer Communications Case by Case
The guidance should not be interpreted as a mandate to disclose every detail of an investigation.
The agencies specifically advise banks and credit unions to evaluate customer communications case by case and take precautions when discussing information that could reveal the existence of a SAR.
That makes internal consistency important.
Fraud teams, BSA officers, frontline employees, operations personnel and customer-service teams should understand the same basic distinction:
The institution can discuss the transaction and its concerns. It cannot disclose that a SAR exists.
For example, the agencies specifically identify altered and counterfeit checks as situations in which a bank may tell a customer that a deposit was rejected because of suspected fraud or other suspicious activity.
They also specifically allow institutions to provide education about money mule schemes when a customer may be participating knowingly or unknowingly.
Those conversations can help an institution gather information, explain an operational decision and, in some cases, help protect the customer from further fraud without compromising SAR confidentiality.
Why This Matters for Check Fraud
The guidance has particular relevance to check fraud.
In explaining why the clarification was issued, the agencies pointed to a 2025 regulatory request for information focused on payment fraud, with particular emphasis on check fraud. Commenters had asked regulators to clarify how institutions could communicate transparently with customers during fraud investigations that might ultimately result in a SAR filing or an account closure.
The resulting guidance confirms that institutions are not required to remain silent about the underlying transaction simply because suspicious activity may also create a SAR obligation.
A bank investigating an altered or counterfeit check, for example, can communicate about the check and the institution’s concerns without telling the customer whether a SAR was filed.
That distinction can make fraud response more understandable for customers while preserving the confidentiality required by the BSA.
Documentation Still Matters
Clearer customer communication does not make the underlying BSA and fraud-management processes less important.
Institutions still need disciplined procedures for reviewing suspicious activity, documenting investigations, maintaining appropriate customer risk information and managing SAR-related activity.
Finovifi’s BSA Guardian supports these operational processes through AML monitoring, customer risk ratings, enhanced due diligence, sanctions screening, SAR support and case management.
The platform also allows institutions to maintain investigative information, customers and suspects, supporting documentation, remarks and SAR-related information within case-management workflows.
The regulatory clarification does not replace those controls. It provides institutions with a clearer framework for communicating with customers while those controls remain in place.
The Bottom Line
SAR confidentiality is still a bright line: do not disclose the SAR or information that reveals its existence.
But SAR confidentiality does not mean an institution must refuse to discuss the underlying suspicious transaction.
Financial institutions may discuss transaction facts, ask questions, explain certain restrictions or account decisions, warn customers about fraud schemes and communicate concerns about suspected fraud, provided those communications do not reveal the existence of a SAR.
For community banks and credit unions, that clarification creates an opportunity to review customer-facing procedures alongside fraud and BSA processes.
The goal is not simply more communication. It is better-controlled communication: enough transparency to explain what is happening while preserving the confidentiality the SAR process requires.
Source
Joint Statement on Suspicious Activity Report Confidentiality Considerations Regarding Communications with Customers, issued September 2, 2026, by FinCEN, the Federal Reserve, FDIC, NCUA and OCC.