U.S. financial regulators recently clarified that the Bank Secrecy Act doesn't prevent you from discussing Suspicious Activity Reports (SARs) with the customers named in them. This clarification is important because it corrects a widespread misunderstanding that has affected how compliance teams handle customer conversations for years.
The confusion is understandable. SARs involve potential criminal activity and regulatory scrutiny. When something feels that sensitive, the safest path seems to be saying nothing at all. But that instinct, while understandable, has led to operational mistakes that undermine both compliance effectiveness and customer relationships.
Why These Mistakes Keep Happening
The root cause isn't ignorance. It's overcorrection.
Most compliance professionals know that SAR confidentiality is serious. The regulations prohibit you from disclosing that you've filed a SAR or that you're considering filing one. That's clear. But in practice, teams often extend that prohibition beyond its actual scope, treating any conversation about suspicious activity as forbidden territory.
This happens because the stakes feel enormous. A confidentiality breach can trigger regulatory penalties. So teams err on the side of silence, even when silence creates its own problems. The regulatory clarification addresses this gap between what the law requires and what institutions have been doing in practice.
Mistake 1: Treating All Suspicious Activity Discussions as Prohibited
Your team freezes when a customer asks why their transaction was delayed or their account flagged. They deflect, offer vague responses, or simply refuse to engage. They believe any discussion of the underlying facts violates SAR confidentiality.
Why it happens: The prohibition on disclosing SAR filings gets conflated with discussing the suspicious activity itself. Teams assume that if they can't mention the SAR, they can't talk about what triggered it.
The consequence: Customers escalate complaints and file regulatory grievances about poor service. Your institution loses business relationships that could have been preserved with straightforward communication. Meanwhile, you gain no additional compliance protection, because you were never prohibited from discussing the facts in the first place.
The fix: Train your team on the distinction. You cannot say "We filed a SAR about your transaction" or "We're considering filing a SAR." But you can explain the specific transaction patterns, regulatory requirements, or risk factors that prompted your review. Focus on what you observed and why it matters under your compliance obligations, without referencing the SAR process itself.
Mistake 2: Failing to Document What You Can and Cannot Say
Your compliance team operates without clear guidance on customer communication boundaries. Each staff member makes individual judgment calls about what's permissible. Some share detailed explanations; others refuse to acknowledge that a review occurred.
Why it happens: The regulatory clarification is recent, and many institutions haven't translated it into operational procedures. Without documented protocols, staff default to their personal risk tolerance, which varies widely.
The consequence: Inconsistent customer experiences damage your reputation. More seriously, inconsistent documentation creates regulatory risk. If examiners review your SAR-related communications and find wildly different approaches, they'll question whether you have effective controls at all.
The fix: Develop communication protocols that specify what information your team can share, what language to use, and what requires escalation to legal counsel. Include example scenarios and sample language. This isn't about scripts, it's about boundaries. Your frontline staff need to know where the line is before they're standing on it during a difficult customer call.
Mistake 3: Assuming Silence Protects You From Liability
Your institution adopts a "say nothing" policy, believing that minimal communication minimizes legal exposure. When customers press for explanations, your team offers only that they're "following procedures" or "complying with regulations."
Why it happens: Legal departments, concerned about any potential confidentiality breach, recommend maximum caution. Silence feels like the safest legal position.
The consequence: This approach creates different liability. Customers who receive no explanation for adverse actions may claim discrimination, arbitrary treatment, or denial of due process. You end up defending against customer complaints and regulatory inquiries about fair treatment, all while having avoided a risk that didn't actually exist.
The fix: Shift from "say nothing" to "say what's permissible." Work with legal counsel to identify the information you can share about your compliance processes, regulatory obligations, and the specific factors that triggered review. Transparency about your reasoning, separate from SAR filing status, often resolves customer concerns and demonstrates that your decisions follow consistent, documented criteria.
Mistake 4: Neglecting to Update Investigation and Case Management Practices
Your investigation team continues operating under old assumptions. They avoid documenting certain customer conversations, skip creating records of explanations provided, or maintain separate informal notes that don't enter your official case files.
Why it happens: When teams believed they couldn't discuss suspicious activity, they developed workarounds. Those habits persist even after the regulatory environment changes.
The consequence: Your investigation files become incomplete. When regulators review your SAR program, they see gaps in your documentation of customer interactions. Worse, if a customer dispute escalates to litigation, you lack records showing what you communicated and when. The informal notes your team kept separately may be discoverable but won't support your position because they weren't part of your formal compliance process.
The fix: Revise your investigation case management procedures to include customer communications as standard documentation. Train investigators to record what they explained to customers, what questions they answered, and what information they appropriately withheld. This creates a complete record that demonstrates both your compliance with confidentiality requirements and your commitment to fair customer treatment.
Mistake 5: Missing the Training Moment
Your compliance team receives the regulatory clarification but doesn't cascade it to customer-facing staff. Branch employees, call center representatives, and account managers continue operating under the old understanding.
Why it happens: Compliance departments focus on updating their own procedures and assume the clarification primarily affects investigation teams. They underestimate how many staff members field customer questions about flagged transactions or delayed services.
The consequence: Your frontline staff continue giving customers the runaround. They escalate questions they could answer themselves. They create friction in customer relationships over issues that don't require it. Meanwhile, your compliance team wonders why customer complaints about transparency haven't decreased.
The fix: Treat this regulatory clarification as a cross-functional training priority. Develop role-specific guidance for every team that interacts with customers about account activity. Focus on what each role can say, what requires escalation, and how to explain compliance obligations without referencing SAR processes. Include this content in onboarding for new hires and refresher training for existing staff.
Prevention Checklist
Use this checklist to audit your current SAR communication practices:
- Written protocols distinguish between prohibited SAR disclosures and permissible discussions of suspicious activity
- Customer-facing staff can explain transaction reviews without referencing SAR filings
- Investigation case files document all customer communications about flagged activity
- Legal counsel has reviewed and approved your communication boundaries
- Training materials for all customer-facing roles address the confidentiality clarification
- Quality assurance processes review customer communications for both compliance and consistency
- Escalation procedures specify when staff should involve compliance or legal teams
- Your complaint resolution process addresses transparency concerns separately from SAR confidentiality
- Annual compliance training includes updated guidance on customer communication rights
- Management monitors customer feedback for signs that communication gaps persist
The regulatory clarification doesn't eliminate SAR confidentiality requirements. It corrects a misunderstanding that made compliance harder than it needed to be. Your job now is to translate that clarification into operational reality, so your team can maintain both regulatory compliance and productive customer relationships.



