On September 2, 2026, the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Financial Crimes Enforcement Network (FinCEN), and the National Credit Union Administration issued a joint statement clarifying confidentiality requirements related to Suspicious Activity Reports, particularly when banks communicate with their customers regarding potentially fraudulent transactions. The statement matters because SAR confidentiality rules have long created operational tension for financial institutions: banks must file SARs without disclosing their existence, yet they also need to communicate with customers to resolve fraud concerns. The joint statement is directed at all community banks, according to the OCC bulletin announcing it.

The joint statement highlights confidentiality considerations that arise in customer communications. It provides a non-exhaustive list of communications that would not typically reveal the existence of a SAR. The OCC bulletin does not reproduce the full list, but the framing indicates that regulators are attempting to give banks clearer guardrails for routine fraud-related conversations without crossing into prohibited disclosure. The statement was issued through OCC Bulletin 2026-43 and applies to national banks, federal savings associations, and federal branches and agencies, as well as institutions supervised by the other four agencies.

The primary source is the OCC bulletin published on September 2, 2026, which summarizes the joint statement and identifies the five issuing agencies. The bulletin was signed by James M. Gallagher, Senior Deputy Comptroller and Chief National Bank Examiner. The source is a primary regulatory communication, but the dossier contains only the bulletin's summary text, not the full joint statement itself. As a result, the specific examples of permissible communications and any detailed legal analysis are not available in the evidence reviewed. The bulletin directs questions to the Compliance and Operational Risk Division, Office of the Chief National Bank Examiner, at (202) 649-6550.

For community banks, the practical implication is a potentially clearer compliance path when handling fraud-related customer interactions. The statement appears designed to reduce uncertainty about whether routine communications—such as asking a customer about a suspicious transaction or explaining a fraud hold—could be construed as revealing a SAR. Because the statement applies to all community banks, it may standardize expectations across federal banking regulators and FinCEN, reducing the risk of inconsistent supervisory treatment. The involvement of FinCEN is notable because FinCEN administers SAR regulations under the Bank Secrecy Act, while the banking agencies examine for compliance.

The evidence reviewed is limited to a single OCC bulletin summary, and the full joint statement was not included in the dossier. Key details remain unknown, including the specific communications listed as not typically revealing a SAR, any examples of prohibited disclosures, and whether the statement changes existing legal obligations or merely clarifies them. The bulletin's summary text contains an incomplete sentence—"The joint statement highlights that"—suggesting the original document contains additional substantive points not captured in the source. Market participants should monitor whether the full joint statement introduces new expectations or simply consolidates existing guidance, and whether subsequent examination manuals or FAQs incorporate the clarified confidentiality framework.