William Wille, Managing Editor, The Credit Union Connection
As the nation commemorates the 25th anniversary of Sept. 11, 2001, the credit union movement has its own story of how the world changed.
The regulatory response fundamentally reshaped the operational landscape for financial institutions.
Twenty-five years is a long time. Long enough for an entire generation to grow up without remembering 9/11. That matters for credit unions, because today’s financial institutions were shaped by a world that looked very different in 2001, and many of today’s members have grown up with those safeguards as part of everyday financial life. To them, a fraud alert isn’t a sign of the times. It’s just another day.
The Regulatory Pivot
In the shadow of 9/11, national security priorities quickly rippled through the financial world. The most visible was the USA PATRIOT Act of 2001, which significantly expanded anti-money laundering obligations and established new requirements around customer identification, information sharing and cooperation with law enforcement because of the ties to terrorist financing.
Verifying member identities, monitoring transactions, filing Suspicious Activity Reports (SARs) and responding to Section 314 information-sharing requirements became another cost of doing business for credit union operations.
The PATRIOT Act built upon the Bank Secrecy Act (BSA) framework, expanding existing requirements and prompting greater investment in technology, personnel, training and risk management. Over time, BSA compliance stopped living in a back office; it became part of how the institution operated and part of the member experience.
When Compliance Meets the Member
One challenge over the past 25 years has been the tension between regulatory confidentiality and transparent member communication.
SAR confidentiality is a critical part of BSA. Financial institutions cannot disclose that a SAR has been filed or provide information that would reveal its existence, particularly when disclosure could compromise an investigation or alert someone involved in suspicious activity.
When a member experienced a delayed transaction, rejected deposit, account restriction or a closure, frontline employees could find themselves walking a very narrow line. They needed to protect confidential information and follow policy, all while answering the one question every member inevitably asks:
Why?
That’s where things could get awkward. A member could walk away feeling like the credit union was hiding something. An employee could feel the safest answer was also the least useful.
As financial services became faster and more digital post 9/11, that communication challenge only grew. Nobody particularly enjoys discovering that a perfectly legitimate transaction has been caught in the digital equivalent of airport security: shoes off, laptop out.
The Member Changed, Too
Here’s the part that can get lost in a 25-year regulatory retrospective: the membership changed during those 25 years, too.
Filene Research Institute puts the average credit union member in their mid-50s and reports that fewer than 20% of Americans under 40 currently use a credit union.
That average is a moving target. Today’s membership includes people who remember Sept. 11 vividly, people who were children when it happened, those with only a vague memory of it and others who weren’t born yet, for whom 9/11 is less a memory than a chapter in a history textbook, filed somewhere between the moon landing and dial-up internet.
Identity verification? Of course. Multifactor authentication? Sure. A fraud alert popping up mid-purchase? Expected. A transaction getting flagged and held for review? Annoying, but hardly unfamiliar.
The member’s immediate question is usually much simpler than any of that history: What happened to my money, and what happens next?
Today’s members increasingly experience financial services through systems that operate behind the scenes. They see the result, and they want to know why before they finish their coffee.
The Line Gets Clearer
That’s what makes the regulatory development of Sept. 2, 2026, interesting.
That’s when the Federal Reserve, FDIC, NCUA, OCC and FinCEN issued a joint statement clarifying how SAR confidentiality applies when financial institutions communicate with customers and members about potentially fraudulent transactions, suspicious activity or account closures.
The agencies’ message was important and, for anyone who has ever tried to explain a compliance requirement to a frontline employee at 8:59 on a Monday morning, refreshingly practical.
A credit union still cannot tell a member that a SAR has been filed or provide information that reveals its existence. Employees can discuss the underlying facts, transactions and documents supporting a SAR, as long as the conversation doesn’t reveal the SAR itself.
The statement doesn’t change underlying BSA requirements or establish new supervisory expectations. It clarifies existing ones, which is basically a plot twist nobody saw coming.
That clarity gives employees more room to explain what’s happening when a transaction is delayed, or a member encounters suspected fraud.
The Next 25 Years
The regulatory environment will keep evolving for many geopolitical and other reasons. So will the credit union membership.
In April 2026, the NCUA, FDIC and OCC proposed changes to their requirements for risk-based anti-money laundering and countering terrorist financing, aligning their rules with proposed changes from FinCEN. The proposals emphasize directing greater attention and resources toward higher-risk customers and activities, with a focus on effective, risk-based programs.
Credit unions are operating with increasingly sophisticated systems as members grow accustomed to financial services that are immediate, digital and personalized. That creates an interesting challenge for an industry whose competitive advantage has always included something decidedly human: the relationship.
A member doesn’t experience the BSA department. They experience the credit union.
When a transaction is flagged, or fraud occurs, the member cares whether someone can help them understand and navigate what’s happening. Employees need enough understanding of the rules to make that conversation possible.
The industry spent the past quarter-century building stronger systems to identify risk and protect members. The next challenge is making sure all that sophistication still works when it reaches an actual human being, quite possibly one with no memory of the event that helped set this whole journey in motion.
Twenty-five years ago, the world changed after 9/11, and credit unions adapted. For the next 25 years, credit unions will keep adapting.
The question is what they will carry forward.
The safeguards and compliance work will continue to matter. So will the conversation with the member standing on the other side of it, because that member experiences the scenario as one thing: the credit union.
The challenge for the next 25 years just might be making sure the institution built to protect the modern member still feels like an institution built for the member.