Can You Question a Customer Without Tipping Them Off? FinCEN Clarifies SAR Confidentiality
A clarification of existing BSA requirements — not a new rule or new supervisory expectation.
The Scenario
An AML analyst identifies an unusual wire transfer and wants to ask the customer for the purpose of the transaction. A colleague immediately says: “Don’t call them — that would be tipping them off.”
Is that actually correct?
In September 2026, FinCEN and the federal banking agencies — the Federal Reserve, FDIC, NCUA, and OCC — addressed this exact misunderstanding in a joint statement on SAR confidentiality and customer communications. The answer, put plainly, is that asking a customer about a suspicious transaction is not automatically the same as revealing a SAR.
1. Why This Clarification Matters
SAR confidentiality is a cornerstone of the Bank Secrecy Act. The prohibition against disclosing a SAR — or information that would reveal its existence — serves an important purpose: it protects investigations, preserves the integrity of law enforcement processes, and shields institutions and their employees from retaliation.
But overly cautious interpretations of that rule can backfire. When compliance teams or frontline staff believe that any conversation with a customer about a suspicious transaction amounts to “tipping off,” they may stop asking the very questions that would strengthen — or appropriately resolve — an investigation. The result is weaker filings, incomplete analysis, and a paradox: the rule designed to protect investigations inadvertently impairs them.
2. What FinCEN Clarified
The joint statement makes several key points:
- Banks can communicate with customers about potentially fraudulent transactions and other suspicious activity.
- Banks can discuss the underlying facts, transactions, and supporting documents that relate to those activities.
- Banks can communicate with customers in connection with account closures.
- Banks must not disclose the SAR itself or information that would reveal its existence.
Critically, the September 2026 statement does not change existing BSA legal or regulatory requirements and does not create new supervisory expectations. It is a clarification of the line that has always existed in the statute: the distinction between the underlying facts, transactions, and documents and the SAR or information revealing that a SAR has been or may be filed.
3. The Practical Difference
The distinction is easier to grasp with concrete examples. The following comparison illustrates the boundary between investigating underlying activity and disclosing a SAR:
✔ Acceptable — Investigating Underlying Activity
- “What was the purpose of this payment?”
- “Can you explain your relationship with this beneficiary?”
- “Please provide supporting documentation for this transfer.”
✘ Problematic — Could Reveal a SAR
- “We filed a SAR about you.”
- “Compliance has reported this transaction as suspicious.”
- “Your account is being reviewed because we intend to submit a SAR.”
The first group of questions focuses on the transaction itself — its purpose, the parties involved, and the supporting evidence. These inquiries are a normal part of customer due diligence and transaction monitoring. The second group explicitly references the SAR, the reporting process, or compliance actions that would reveal a SAR exists or is being contemplated. That is the disclosure the BSA prohibits.
4. Why Institutions Sometimes Get This Wrong
If the line has always been in the statute, why does the misunderstanding persist? Several operational factors — observable across the industry — likely contribute:
- Fear of breach. The penalties for violating SAR confidentiality are serious. Faced with ambiguity, staff default to the most restrictive interpretation: say nothing at all.
- Poorly worded internal policies. Some institutions’ procedures use broad prohibitions — such as “do not contact the customer once suspicious activity is identified” — without distinguishing between discussing the underlying facts and disclosing the SAR.
- Frontline confusion. Relationship managers and branch staff may not have been trained on the nuance. They hear “SAR confidentiality” and interpret it as a blanket gag order.
- Inadequate training. Annual BSA/AML training may cover SAR confidentiality in a single slide, without scenario-based examples that make the distinction concrete.
- Over-reliance on internal data. Analysts sometimes attempt to reach a conclusion using only transaction records and open-source research, when a reasonable customer inquiry could provide the missing context — such as the purpose of a transfer or the source of funds.
Note: These are practitioner-level observations, not claims made by FinCEN in the September 2026 statement.
5. Why This Matters for Investigation Quality
A well-conducted AML investigation tests suspicious activity against the best available evidence. In appropriate cases, direct customer clarification can help determine:
- The purpose of the transaction;
- The source of funds;
- The relationship between the parties involved;
- The business rationale for an otherwise unusual pattern;
- The availability of supporting documentation such as invoices, contracts, or loan agreements.
That said, a customer’s explanation is not automatically dispositive. Investigators should assess whether the explanation is credible, whether it is consistent with the transactional evidence, and whether it is supported by documentation. A plausible-sounding answer that contradicts the data may itself be a red flag.
The point is not that every investigation requires customer contact, but that SAR confidentiality should not be the reason an investigator avoids asking a legitimate question about the underlying activity.
6. A Simple Decision Framework
Before communicating with a customer about potentially suspicious activity, consider the following four questions:
- Am I discussing the underlying transaction or facts? If yes, this is generally permissible.
- Could my wording — directly or indirectly — reveal that a SAR exists or may be filed? If yes, rephrase or stop.
- Is the communication consistent with my institution’s internal policies and procedures? Follow your organization’s established protocols.
- Does this case require additional controls or senior review before customer contact? High-risk scenarios — such as those involving law enforcement requests, ongoing investigations, or sensitive subjects — may warrant escalation.
Institutions should apply this assessment case by case. The OCC’s related bulletin specifically notes that banks should take precautions when discussing information that might reveal the existence of a SAR. A blanket approach — either “always ask” or “never ask” — is unlikely to serve the institution well.
7. Training Takeaway
“Investigate the activity. Protect the SAR.”
That one line captures the entire principle. SAR confidentiality exists to protect the reporting process — the document, the filing, the fact that a report was made or is being considered. It should not be used — and was never intended — to prevent legitimate investigation of the underlying activity itself. Compliance teams, investigators, relationship managers, and frontline staff all benefit from understanding this distinction clearly.
🎬 Compliance Desk #01
“So how am I supposed to investigate it — telepathy?”
The humor reflects a real operational frustration. When SAR confidentiality is misunderstood as a prohibition on all customer contact, investigators are left trying to resolve complex cases without one of the most basic tools in their toolkit: asking a question. The September 2026 clarification confirms that the law does not require telepathy — just careful judgment about what you say and how you say it.
Conclusion: Three Takeaways
- Asking about a suspicious transaction is not automatically tipping off. Inquiries about the purpose, source, or documentation behind a transaction are part of normal due diligence and investigation — not a breach of SAR confidentiality.
- Disclosing a SAR or information revealing its existence remains prohibited. The BSA’s confidentiality provisions are unchanged. What institutions must avoid is language — whether explicit or implied — that tells a customer a SAR has been filed or is being considered.
- Clear procedures and staff training are essential to distinguish the two. Policies should be specific, training should include scenario-based examples, and institutions should empower staff to ask legitimate questions while safeguarding the reporting process.
Sources
- FinCEN, Federal Reserve, FDIC, NCUA & OCC — Joint Statement on Suspicious Activity Report Confidentiality (September 2, 2026)
- OCC — Bulletin 2026-43: SAR Confidentiality and Customer Communications
RiskSimplifier | Siorik Consultancy — simplifying financial crime compliance through practical learning, advisory and RegTech.
