Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Should You Discuss SARs With Customers?Regulatory Compliance
5 min readFor Compliance Officers

Should You Discuss SARs With Customers?

The federal Bank Secrecy Act doesn't prohibit you from discussing Suspicious Activity Reports (SARs) with the customers named in those reports. U.S. financial regulators have clarified this, prompting compliance departments to reconsider their long-held practice of absolute silence.

For years, most institutions treated SAR confidentiality as a blanket prohibition on any customer communication. Now you're facing a choice: maintain that silence, open selective dialogue, or build a structured disclosure protocol. Each path carries distinct compliance, operational, and relationship consequences.

The Decision You're Facing

You've filed a SAR. The customer knows something's wrong, frozen transactions, account restrictions, delayed wire transfers. Do you:

  • Continue saying nothing and point to "regulatory requirements"
  • Acknowledge the SAR filing without disclosing specifics
  • Provide limited context about why the activity triggered suspicion

This isn't theoretical. Your BSA officer, customer service team, and relationship managers need clear guidance before the next customer calls demanding answers.

Key Factors That Affect Your Choice

Your institution's risk tolerance for litigation. Discussing a SAR, even when legally permitted, creates documentation that plaintiffs' attorneys will request in discovery. If you tell a customer you filed a SAR because their wire pattern resembled structuring, you've created a record of your suspicion rationale.

The sophistication of your customer base. A commercial banking client with in-house counsel will interpret SAR discussions differently than a retail customer who's never heard of the Bank Secrecy Act. Your communication strategy should account for this variance.

Your existing SAR volume and false positive rate. If you're filing 50 SARs monthly and 40 result from overly sensitive transaction monitoring rules, discussing each one becomes operationally unsustainable. High false positive rates also increase reputational risk when customers learn they were reported for ultimately benign activity.

The strength of your compliance training program. Opening SAR discussions requires front-line staff who understand 31 CFR 1020.320, can explain regulatory obligations without sounding defensive, and know when to escalate to the BSA officer. If your team isn't trained to this standard, premature disclosure creates more risk than silence.

Your relationship banking model. Institutions that compete on service and personal relationships face different pressures than transaction-focused banks. A wealth management client expecting white-glove service will react more negatively to unexplained account restrictions than a checking account holder.

Path A: Maintain Confidentiality (When to Choose This)

Choose continued silence when:

You operate in a high-litigation environment. If your institution faces frequent customer lawsuits or serves industries with aggressive legal representation, every SAR discussion becomes potential evidence. The regulatory clarification permits disclosure; it doesn't require it.

Your SAR involved ongoing criminal investigation. While the Bank Secrecy Act allows customer discussions, coordination with law enforcement matters. If federal agents have requested you not alert the subject, that supersedes any transparency consideration.

The customer relationship has already terminated. If you've closed the account and ended the relationship, there's no service recovery benefit to disclosure. You've filed the SAR, met your regulatory obligation, and moved on.

Your compliance team lacks capacity for nuanced communication. Discussing SARs well requires judgment, training, and time. If your BSA officer is already managing 200 alerts monthly with minimal support, adding customer communication protocols will compromise quality across all functions.

Implementation: Document your decision to maintain confidentiality as deliberate policy, not default practice. Train customer service to respond to SAR inquiries with: "We can't discuss specific regulatory filings, but I can explain why your transaction was restricted and what documentation would help us process it." This acknowledges the customer's concern without confirming a SAR exists.

Path B: Selective Acknowledgment (When to Choose This)

Choose limited disclosure when:

The SAR resulted from obvious transaction monitoring triggers. If your system flagged six same-day deposits just below $10,000 and any reasonable person would recognize that as suspicious, acknowledging the filing reduces customer frustration without revealing investigative details.

You're trying to preserve a valuable relationship. A long-term commercial client with legitimate business reasons for unusual activity deserves more transparency than a form letter about "regulatory requirements." Selective disclosure here means: "We filed a required report about this transaction pattern. Here's what documentation would help us understand the business purpose."

The customer has already hired counsel. Once attorneys are involved, they'll request SAR confirmation through legal channels anyway. Proactive acknowledgment can de-escalate the situation and demonstrate good faith.

You need the customer's cooperation for investigation. Sometimes understanding whether activity is suspicious requires asking questions. If you need to know whether a wire transfer was authorized or fraudulent, saying "we're reviewing this under our Bank Secrecy Act obligations" provides context for your questions.

Implementation: Create a three-tier disclosure framework. Tier 1: Acknowledge a SAR was filed, no details. Tier 2: Confirm the general category of suspicious activity (unusual transaction pattern, geographic risk, negative news). Tier 3: BSA officer discussion with full context (reserved for relationship banking clients with complex legitimate business). Require BSA officer approval for Tier 2 or 3 disclosures.

Path C: Structured Transparency Protocol

Choose proactive disclosure when:

You're differentiating on customer experience. If your competitive advantage is service quality and relationship banking, treating SAR filings as opportunities for education rather than enforcement actions aligns with your brand. This works when you have the compliance sophistication to do it well.

Your false positive rate is documented and improving. If you can tell customers "our monitoring system flagged this transaction, we filed a required report, and after review we've determined your activity is consistent with your business profile," you're demonstrating both regulatory diligence and customer advocacy.

You serve a regulated customer base that understands compliance obligations. Healthcare organizations, government contractors, and other heavily regulated entities recognize that compliance sometimes requires uncomfortable conversations. They'll appreciate transparency over evasion.

Implementation: Build a SAR communication playbook that includes scripts for common scenarios, escalation paths, and documentation requirements. Every SAR discussion should be logged with: date, customer name, disclosure tier used, customer response, and any follow-up commitments. Review these logs quarterly to identify patterns and refine your approach.

Summary Matrix

Factor Maintain Silence Selective Acknowledgment Structured Transparency
Best for High-litigation risk, ongoing investigations Relationship preservation, obvious triggers Service differentiation, sophisticated customers
Training requirement Minimal (deflection scripts) Moderate (BSA officer consultation) Extensive (tiered disclosure protocols)
Documentation burden Low Medium High
Litigation exposure Baseline Moderate increase Highest (but defensible)
Customer satisfaction impact Negative but expected Mixed (depends on execution) Positive if done well
Operational complexity Low Medium High

The regulatory clarification doesn't mandate a single approach. It removes a legal barrier and forces you to make a strategic choice based on your institution's risk profile, customer base, and operational capacity. Whichever path you choose, document the rationale and train your team consistently. The worst outcome isn't choosing transparency or silence. It's having different employees make different choices for similar situations because you never decided which path to take.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like