When your credit union spots suspicious activity in your account, they’re actually allowed to talk to you about it.
Revolutionary, right?
A coalition of federal banking regulators just issued a joint statement clarifying something that’s apparently been confusing banks for years—you can discuss fraud with your customers without violating confidentiality rules. It’s like finally getting permission to do the thing you thought was already okay.
Why This Statement Exists
The Federal Reserve, FDIC, NCUA, OCC, and FinCEN came together to clear up a common misunderstanding about Suspicious Activity Reports, or SARs. Think of SARs as the official paperwork banks file when something fishy happens—fraud, money laundering, that kind of thing.
The confusion started bubbling up after regulators asked for feedback on how to combat payment fraud, especially check fraud. Banks responded with a chorus of “Wait, can we actually tell customers what’s going on?” Turns out, many institutions were treating SAR confidentiality like Fight Club rules—don’t talk about it, ever, to anyone.
But that’s not quite how it works.
The Confidentiality Rules, Explained
Here’s the deal: the Bank Secrecy Act does require SAR confidentiality. You can’t tell someone “Hey, we filed a SAR about you” or share anything that would obviously reveal a SAR exists. That makes sense—if criminals knew exactly when banks were reporting them, they’d just get better at covering their tracks. It would be like texting the burglar your security system’s blind spots.
But here’s the key distinction that everyone seems to have missed: you can absolutely discuss the underlying facts, transactions, and documents that a SAR is based on. You just can’t say “…and we filed a SAR about this.”
In other words, you can talk about the what, when, where, and how much of suspicious transactions. You can discuss specific dates, dollar amounts, and parties involved. What you can’t do is explicitly mention the SAR itself.
Sure, a reasonably savvy person might figure out that weird transactions plus bank questions probably equals a filed report. But that’s different from the bank actually confirming it. Think of it like plausible deniability, but for regulatory compliance.
What Banks Can Say to You
The regulators helpfully provided a list of conversations that won’t get banks in trouble. These examples show just how much communication is actually allowed:
- Asking for more information about your account activity to understand what you’re up to and assess risk
- Telling you they’re delaying, limiting, or closing your account because of suspected fraud or suspicious activity
- Rejecting a deposit because it looks fraudulent—like when someone tries to deposit an obviously altered or counterfeit check
- Asking about specific transactions—where’d that money come from, what’s it for, the usual questions
- Warning you about fraud schemes, including letting you know if you might be an unwitting “money mule” (someone who unknowingly helps transfer stolen money)
- Explaining account decisions like why they declined a transaction or decided to close your account
- Requesting details about who’s sending or receiving money in wire transfers
Notice a pattern? Banks can have actual, useful conversations about fraud without tap-dancing around the elephant in the room.
Why This Matters
This clarification addresses concerns raised in an executive order about fair banking practices. The goal is better transparency—customers deserve to know what’s happening with their accounts and why their bank is making certain decisions.
For years, some banks have been overly cautious, staying silent when they could have been helpful. That silence probably felt pretty frustrating if you were the customer dealing with a frozen account or rejected transaction without explanation. “Computer says no” isn’t exactly world-class customer service.
Now there’s official confirmation that banks can—and should—communicate clearly with customers during fraud investigations. They can walk you through what they’re seeing, explain their concerns, and discuss next steps. All without violating confidentiality rules.
The Bottom Line
This joint statement doesn’t create new rules or change existing Bank Secrecy Act requirements. It’s more like a friendly reminder of what’s always been allowed—with helpful examples for the folks in the back who weren’t sure.
Banks and credit unions should handle these conversations on a case-by-case basis, of course. But the key takeaway is simple: you can discuss potentially fraudulent transactions, explain account closures, and provide customers with the transparency they deserve. You just can’t explicitly reveal that you filed (or plan to file) a SAR.
It’s about finding the balance between protecting investigation integrity and treating customers like actual human beings who deserve to understand what’s happening with their money. Apparently, you can do both. Who knew?
Well, now everyone does.