Can You Tell a Member Their Account Was Flagged for Suspicious Activity?

A member’s deposit has been rejected. Their transaction is delayed. Their account has been restricted or closed.
Naturally, they want to know why.
For credit union employees, that can create an uncomfortable question: How much can you tell the member without violating Suspicious Activity Report (SAR) confidentiality requirements?
Recent guidance from federal banking regulators provides some helpful clarification. On September 2, 2026, the National Credit Union Administration (NCUA), Financial Crimes Enforcement Network (FinCEN), and other federal banking agencies issued a joint statement addressing what financial institutions can communicate about potentially fraudulent transactions, suspicious activity, and account closures.
The takeaway is important: SAR confidentiality does not mean credit unions have to remain silent about the underling activity.
The statement does not change existing Bank Secrecy Act (BSA) requirements or establish new supervisory expectations. Instead, it helps clarify where the line falls between communicating with a member and revealing information that must remain confidential.
What Employees Can—And Can’t—Say
The BSA prohibits a credit union from disclosing a SAR or information that would reveal that a SAR exists.
But there is an important distinction: the underlying facts, transactions, and documents that may have led to a SAR are not themselves considered a SAR.
In other words, employees may be able to discuss the activity that caused concern without discussing or revealing the existence of the SAR itself.
The agencies provided several examples of communications that generally would not reveal the existence of a SAR. These include:
Ask a member about the purpose of a transaction or source of funds.
Request customer due diligence information or documentation.
Explain that a transaction delay, account restriction, or closure may be related to suspected fraud or other suspicious activity.
Tell a member that a deposit was rejected because of suspected fraud, such as an altered or counterfeit check.
Request information about the originator or beneficiary of a funds transfer.
Provide warnings or educational information about fraud schemes, including when a member may knowingly or unknowingly be participating in one.
Communicate decisions about account services, including declining a transaction or closing an account.
Credit unions may also communicate with third parties, including other financial institutions, about underlying facts, transactions, and documents when appropriate, provided the communication does not reveal the existence of SAR.
The key distinction is this: employees can discuss the activity. They cannot disclose the SAR.
Why This Matters at the Front Line
The distinction may sound straightforward in policy. Applying it during an actual member conversation can be much more difficult.
Imagine a member standing at the teller line asking why a check was rejected. Or calling repeatedly because access to an account has been restricted. An employee who knows SARs are confidential may be so cautious that they are unsure whether they can explain anything at all.
On the other hand, an employee trying to be helpful could inadvertently say too much.
BSA and fraud personnel face similar situations when they need additional information from a member while reviewing suspicious activity. Management may also become involved when the credit union decides to restrict services or close an account.
That is why the agencies’ clarification is particularly useful from a training perspective. Employees need more than a general instruction to “maintain SAR confidentiality”. They need to understand what that means in the conversations they actually have with members.
Would Your Employees Know What to Say?
The joint statement creates a good opportunity to look at your existing BSA procedures and training through a practical lens.
Consider some of the situations your employees may encounter:
A member asks why their transaction is being delayed. What should the employee say?
A member wants to know why their deposit was rejected. How much information can be provided?
BSA personnel need additional information about the source of funds. How should they frame the request? The credit union has decided to close an account because of suspicious activity. How should that decision be communication.
Your written policy may address SAR confidentiality—but does it give employees enough guidance to confidently handle those conversations? Turn Guidance into Practice
The September 2 joint statement does not create a new compliance requirement. But it does create an opportunity to make sure your existing procedures and training reflect how SAR confidentiality works in practice.
Credit unions may want to review whether employees understand the distinction between a SAR and the underlying activity, whether procedures address common member-facing scenarios, and whether frontline, BSA, fraud, and management personnel know when a conversation should be escalated.
At Griffin & Furman, we work closely with credit unions to evaluate the procedures and controls supporting their BSA compliance program. Our team can assist with reviewing SAR confidentiality procedures and member communication practices, identifying areas where additional guidance or training may be appropriate, and considering how the agencies’ clarification applies to everyday situations.
We can also incorporate these considerations into your BSA audit to evaluate whether current practices and controls appropriately address SAR confidentiality and member communications.
Contact us to discuss your BSA compliance needs or how these considerations can be incorporated into your next BSA audit.
.png)

_edited.png)



Comments