Regulators Clarify What Credit Unions Can Tell Members About Suspicious Activity

Regulators Clarify What Credit Unions Can Tell Members About Suspicious Activity

New federal guidance draws a clearer line between protecting a SAR and discussing the transactions behind it

Federal regulators are giving banks and credit unions new clarity on what employees can tell customers and members when fraud or suspicious activity is involved — including when that activity results in transaction restrictions or an account being closed.

The Federal Reserve, FDIC, NCUA, OCC and Financial Crimes Enforcement Network (FinCEN) issued a joint statement on Suspicious Activity Report confidentiality Wednesday clarifying that SAR confidentiality rules do not prevent financial institutions from communicating with customers about potentially fraudulent transactions, other suspicious activity or account closures.

The guidance could be particularly important for credit union employees working in collections, fraud, loss mitigation, branches and member service, where employees may know an account is undergoing suspicious-activity review but have been reluctant to discuss anything connected with that review.

The regulators are drawing an important distinction: the SAR is confidential, but the underlying transaction is not automatically confidential.

Under the Bank Secrecy Act, a financial institution cannot disclose a SAR or information that would reveal that a SAR exists. But the agencies emphasized that FinCEN’s regulations specifically exclude the “underlying facts, transactions, and documents upon which a SAR is based” from that prohibition.

That means a credit union can potentially discuss the transaction that raised concerns without telling the member whether the institution filed a SAR.

Regulators Respond to Industry Concerns

The clarification follows questions raised by financial institutions about how SAR confidentiality affects their ability to communicate with customers during fraud investigations.

According to the agencies, commenters responding to a June 2025 request for information on payments fraud asked regulators to clarify how institutions could provide “transparent and timely communication” to customers when a fraud investigation might lead to one or more SAR filings or ultimately to closure of the customer’s account.

FinCEN separately emphasized Wednesday that the guidance is intended to clarify that SAR confidentiality requirements do not prevent institutions from communicating with customers about potentially fraudulent transactions, suspicious activity and account closures.

The agencies stressed that the statement does not change existing Bank Secrecy Act requirements or create new supervisory expectations.

Instead, it explains more clearly what institutions were already permitted to do.

Credit Unions Can Ask Questions About Suspicious Transactions

The distinction could provide employees considerably more room to communicate than some may have assumed.

The agencies said credit unions may communicate with a member about the underlying facts and transactions involved in suspicious activity as long as they do not reveal the existence of a SAR.

That can include asking about the purpose of a transaction, requesting information about the source of funds, seeking additional customer-due-diligence information or asking for information concerning the originator or beneficiary of a funds transfer.

A credit union can also request documentation supporting a transaction.

For a collector, that could become relevant when unusual payment activity intersects with a delinquent loan.

A borrower might suddenly make a substantial payment from an unfamiliar account. An ACH payment could originate from an unrelated third party. A questionable check could be deposited immediately before a member attempts to cure a delinquency. Funds could move rapidly through an account before being applied to a loan.

The existence of a fraud or BSA review does not necessarily mean the collector must suddenly stop asking legitimate questions about those transactions.

What the employee cannot do is reveal that a SAR has been filed — or communicate information in a way that effectively tells the member that one exists.

Credit Unions Can Say Fraud Is Suspected

Perhaps the most significant clarification for frontline employees involves what an institution can say about why it is taking action.

According to the joint statement, a financial institution may tell a customer that a transaction was declined because of suspected fraudulent or suspicious activity. The agencies specifically use the example of rejecting a check deposit because the institution suspects the check may be altered or counterfeit.

Institutions can also communicate that a delay, hold, restriction or limitation involving an account or service may be related to suspected fraud or other suspicious activity.

That is considerably different from an employee believing that the appearance of suspicious activity requires the institution to tell the member nothing.

The regulators also said institutions may provide fraud warnings and educational information when they believe a customer could be the victim of a scam or may be knowingly or unknowingly participating in a fraudulent scheme.

That could include a member acting as a money mule.

Even Account Closures Can Be Explained

The guidance also addresses one of the more difficult member-service situations: closing an account because of suspicious activity.

A credit union may notify a member that it intends to close an account because of potentially fraudulent or other suspicious activity, according to the agencies, as long as the communication does not reveal whether a SAR has been filed.

That does not mean institutions must provide detailed explanations for every account closure.

The agencies caution that institutions should continue taking precautions when communicating information that could reveal the existence of a SAR, and other legal, investigative or security considerations may affect what an institution chooses to disclose.

But SAR confidentiality, by itself, does not require complete silence about the reason an account is being restricted or closed.

Suspicion Isn’t the Same as Disclosure

The regulators also addressed a particularly interesting gray area.

A sophisticated customer may understand enough about banking regulation to suspect that a SAR has been filed after the institution begins questioning transactions, restricting an account or discussing suspected fraud.

That does not necessarily mean the credit union has violated SAR confidentiality.

The agencies said a communication about underlying activity does not become prohibited merely because a customer could infer that the institution might file or may have filed a SAR.

The prohibition remains on actually disclosing the SAR or information that would reveal its existence.

That distinction is important because otherwise almost any meaningful discussion of suspicious activity could theoretically become a SAR disclosure simply because an informed member knows how the reporting system works.

A Collections Issue, Not Just a BSA Issue

For credit union collection managers, the guidance is worth looking at beyond the compliance department.

Collections departments increasingly encounter situations in which delinquency and suspicious financial activity overlap.

A member claiming fraud may also be delinquent. A questionable deposit may be used to make a loan payment. A collector may encounter unexplained third-party payments or unusual transfers while attempting to resolve an account.

In those situations, collections, fraud and BSA personnel may all be looking at the same member for very different reasons.

The September 2 guidance doesn’t give collectors unrestricted authority to discuss suspicious activity, and credit unions will still need policies defining what frontline employees can say and when conversations should be escalated.

But it does challenge an overly broad interpretation that has sometimes surrounded SAR confidentiality:

Once a SAR might be involved, nobody can say anything.

That isn’t what the regulation says.

In fact, FinCEN guidance has long distinguished the SAR itself from the information underlying it. Previous FinCEN guidance on SAR information sharing similarly stated that institutions may disclose underlying information about customers and transactions without permission so long as the disclosure does not explicitly reveal that a SAR was filed and isn’t otherwise legally restricted.

The new statement brings that distinction directly into the everyday customer conversation.

What Collection Managers Should Review

For collection departments, this may be a good reason to sit down with the credit union’s BSA, compliance and fraud teams and review exactly what collectors are currently instructed to say when suspicious activity intersects with a delinquent account.

Managers should look at whether scripts and procedures distinguish between discussing suspicious transactions and disclosing a SAR, rather than treating the two as interchangeable.

They should also determine who controls the conversation when collections and fraud investigations overlap, when a collector should escalate the call and what explanations employees are authorized to provide regarding rejected payments, account restrictions and suspected fraud.

This isn’t a loosening of SAR confidentiality.

Unauthorized disclosure remains serious. FinCEN has repeatedly warned that revealing a SAR or information that reveals its existence can compromise law-enforcement investigations, alert potential suspects and undermine the SAR reporting system.

What changed Wednesday is that five federal regulators made the other side of that rule much harder to overlook.

A credit union cannot tell a member that it filed a Suspicious Activity Report.

But that doesn’t mean it cannot talk to the member about the suspicious activity that caused the concern in the first place.