What happened
The federal banking agencies and the Financial Crimes Enforcement Network issued a joint statement on September 2 clarifying how Bank Secrecy Act confidentiality rules apply when institutions talk to customers. The core message, reported by Compliance Week: the BSA does not prohibit banks and credit unions from speaking with a customer who may be the subject of a Suspicious Activity Report, as long as the conversation does not reveal that a SAR exists.
In practical terms, an institution can discuss potentially fraudulent or suspicious transactions involving a customer's account, and can tell the customer it intends to close the account over that activity, without automatically breaching confidentiality. The statement responds to comments on a June 2025 request for information about payments fraud, in which banks asked how they could keep customers informed during fraud investigations that might end in a SAR filing and an account closure. It also acknowledges concerns raised in an executive order on fair banking, the debanking debate that has been running alongside fraud work.
What stays off limits is unchanged: revealing that a SAR was filed, or sharing information that would let a customer infer one exists, can tip off suspects, weaken investigations, and deter future filings. The agencies stress that each situation is fact specific, and note that underlying facts alone do not count as revealing a SAR, even when a reasonable person might suspect one was filed.
Why this is a GRC story
SAR confidentiality is one of the sharpest tensions in AML compliance. The rule exists to protect law enforcement, but many banks have responded by going silent with customers altogether. That over-correction has real costs: fraud victims get no explanation when their accounts are frozen, legitimate customers are left confused when accounts are closed, and the debanking complaints that followed are part of the fallout. This statement draws a cleaner line: talk about the conduct, never about the filing.
The hard part is operational. The distinction between explaining a fraud decision and revealing a filing is subtle, and it usually lands on frontline staff in fraud units and call centers, not on attorneys. A compliance program that leaves this as a judgment call without training and approved talking points will produce exactly the inconsistency regulators worry about. Policies, scripts, and escalation paths need to reflect the clarification before examiners ask about it.
There is also a governance lesson in how this happened. The clarification came from industry feedback through a formal request for information. AML and fraud teams that surface operational friction through comment letters and RFI responses are doing real risk management work, not paperwork.
What to watch
Watch how examiners apply the statement in practice and whether the agencies issue further guidance, since fact-specific standards are only as consistent as the people applying them. Also watch whether the logic spreads beyond fraud investigations into other SAR contexts.
For compliance teams, the practical move is to review account closure communications and fraud investigation scripts now, make sure staff know the difference between explaining decisions and revealing filings, and document the training. The line between helping customers and protecting investigations just got clearer, but only for institutions that actually operationalize it.
Attribution: Analysis based on Compliance Week's reporting and related public reporting. This article is original commentary, not a repost of the source material.
