Agencies clarify banks may contact customers tied to SARs

Bowman Says US Regulators Reached Consensus On Basel Plan
Al Drago/Bloomberg

Processing Content
  • Key insight: Bank regulators said that banks can contact customers who are subject to suspicious activity reports without violating SAR confidentiality, provided they do not reveal that a SAR has been issued concerning their activity.
  • Expert quote: "Although a reasonable and prudent person familiar with the SAR filing requirement may suspect or be able to deduce from these underlying facts, transactions, and documents that a SAR was or may have been filed," the statement noted, "the underlying information alone would not constitute information revealing the existence of a SAR for confidentiality purposes." —Interagency guidance 
  • Forward look: The agencies are moving to give banks more flexibility to focus resources on higher-risk customers and activities as part of the administration's anti-money-laundering compliance overhaul. 

Banking agencies on Wednesday issued a joint statement clarifying their stance that banks may communicate with customers whose accounts are involved in suspicious activity, as long as they do not inform the customer of the existence of a suspicious activity report.

The joint statement, issued collectively by the Federal Reserve, the Federal Deposit Insurance Corp., the National Credit Union Administration and the Office of the Comptroller of the Currency, responds to concerns that firms may want to contact a customer whose account is involved in fraud, even while SARs, under the Bank Secrecy Act, remain confidential.

"The BSA and its implementing regulations do not prohibit banks or credit unions from communicating with a customer or other person who may be the subject of a SAR about potentially fraudulent or other suspicious transactions involving the customer's account or notifying the customer of the bank's or credit union's intention to close the account for potentially fraudulent or other suspicious activity, so long as that communication does not reveal the existence of a SAR."

The statement, which the agencies say creates no new formal regulation, comes as banks have been confronting ever-higher levels of fraud in recent years. The agencies issued a request for information in June 2025 to ask banks what they could do more to fight check fraud. Commenters asked the regulators to allow banks some leeway to talk with customers as part of the fraud investigation. The statement also "recognizes the concerns" expressed by President Trump's debanking executive order, saying the statement increases communication channels between customers and banks. 

Fraud is a major issue for banks, whose anti-fraud tech spending has soared in recent years in response, according to American Banker research. Meanwhile, fraud rings are exploiting economic uncertainty and low entry costs, especially around checks. 

Suspicious activity reports are often one step in a bank's response and investigation of suspected fraud. However, the BSA prohibits not only disclosure of a SAR itself but also information that would reveal a SAR's existence. The BSA does, however, allow banks to discuss the "underlying facts, transactions and documents upon which a SAR is based." 

The agencies acknowledge that anyone familiar with bank anti-money-laundering regulations could readily deduce the existence of a SAR from such communications, but say that does not count as "revealing" the SAR's existence.

"Although a reasonable and prudent person familiar with the SAR filing requirement may suspect or be able to deduce from these underlying facts, transactions, and documents that a SAR was or may have been filed, the underlying information alone would not constitute information revealing the existence of a SAR for confidentiality purposes," the guidance said.

The agencies say firms should consider these instances on a fact-specific basis. Requesting documentation from consumers, notifying them of a closure or account restriction or rejected deposits, asking customers about a transaction's purpose, fraud advisories or requesting information on the originator or recipient of a transfer would be protected actions under the standard.

Agencies have been overhauling anti-money-laundering regulations under the Trump administration. The agency also proposed stripping back anti-money-laundering requirements to align with the administration's deregulatory push.

Under the proposal, banks would be allowed to narrow the focus of their resources to blatant higher-risk customers and activities, while retaining risk-based internal controls, independent testing, a U.S.-based AML officer in contact with regulators and ongoing training in the organization. The rule introduces a two-part standard: Banks are responsible for having an AML program and for implementing it.

The proposal also directs the banking agencies to coordinate directly with the executive branch before issuing actions. The FDIC would be required to notify Fincen 30 days or more before pursuing significant anti-money-laundering actions, during which banks share their side of the story with Fincen. That rule is still pending.


For reprint and licensing requests for this article, click here.
Regulation and compliance AML FDIC OCC
MORE FROM AMERICAN BANKER
Load More