Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

SAR confidentiality: what an MLO must not disclose

Updated 6 min read
Key takeaway

A financial institution and its directors, officers, employees and agents generally may not notify a person involved in a suspicious transaction that a Suspicious Activity Report (SAR) has been filed.

More key points
  • The rule protects the SAR and information that would reveal its existence, while allowing specified disclosures to government authorities and relevant supervisory agencies; do not confuse that prohibition with ordinary recordkeeping or customer-service duties.
On this page7 sections
  1. What is prohibited
  2. Permitted disclosures are limited
  3. Customer questions and records
  4. How to respond to a scenario
  5. Practical application and common errors
  6. Workflow checks and scenario
  7. Exam takeaway

A mortgage professional may identify suspicious activity, escalate it internally and support a filing, but cannot tip off the customer that a SAR was submitted. The confidentiality rule protects investigations and the reporting system.

What is prohibited

Under the applicable Bank Secrecy Act regulation, a financial institution and its personnel may not notify a person involved in the transaction that a SAR has been filed. The SAR and information that would reveal its existence receive special confidentiality protection. Staff should not confirm, deny or hint that a report was submitted.

Permitted disclosures are limited

Regulations permit specified disclosures to government authorities and certain supervisory agencies. Those exceptions are not a general license to share the filing with a customer, broker, unrelated employee or outside party. Follow the institution's legal and compliance channels for any request.

Customer questions and records

A customer may ask why a transaction is delayed, declined or reviewed. Staff should respond with accurate, approved explanations that do not reveal a SAR. Keep ordinary account, loan and compliance records as required, but do not place the SAR itself in a customer-accessible file or disclose protected details.

How to respond to a scenario

  1. Escalate suspicious activity through the designated internal process.
  2. Do not tell the subject that a SAR was or will be filed.
  3. Route external requests to the BSA officer or legal counsel.
  4. Disclose only under a recognized regulatory exception and through approved channels.
  5. Keep required supporting records separate and protected according to policy.

Practical application and common errors

A Suspicious Activity Report is filed with FinCEN by a financial institution when applicable reporting rules and facts require it. Federal law prohibits a financial institution and its directors, officers, employees, and agents from notifying a person involved in the transaction that the transaction has been reported. SARs and information revealing their existence are confidential, subject to statutory exceptions for authorized government use and certain communications within the institution’s permitted channels.

An MLO who notices suspected fraud should follow the institution’s escalation process. The MLO may provide facts to the designated BSA officer or other authorized personnel; that internal report is not the same as telling the borrower that a SAR was or will be filed. The institution decides whether the legal filing threshold and deadline are met. MLOs should not promise that a report will be filed or disclose a filing decision.

Avoid indirect disclosure too. Telling a customer “we reported you,” hinting that a particular document triggered a SAR, or giving a copy of the SAR can reveal protected information. A neutral explanation that the institution cannot discuss internal monitoring or reporting is safer. Ordinary requests for documents or a decision explanation should be handled under normal procedures without identifying a SAR.

The confidentiality rule does not mean an MLO can never discuss underlying facts. The institution may communicate ordinary account information or provide required notices, but communications should not reveal the existence of a SAR or information that would identify one. Follow counsel and BSA policy when responding to subpoenas, law-enforcement inquiries, litigation, or regulator requests; do not independently decide that a confidentiality exception applies.

SAR records have retention requirements and access controls. Preserve related material through approved systems, restrict access to personnel with a business or compliance need, and do not store sensitive information in personal email or casual chat. Record factual observations and source documents, not unsupported accusations. Internal escalation should be prompt because filing deadlines can run from initial detection of facts.

A customer’s request for a SAR is different from a request for a copy of a credit report, adverse-action notice, or ordinary account record. A SAR itself is not a consumer file disclosure. The institution must separately meet applicable FCRA, ECOA, and other notice duties where they apply, without revealing SAR status.

For an exam question, the essential rule is no notification to a person involved that the institution filed a SAR, and no disclosure of the SAR or information revealing its existence except as permitted by law. Internal reporting to authorized BSA personnel is appropriate. Do not confuse confidentiality with a prohibition on making the required filing.

Workflow checks and scenario

Employees should know a safe, standard response to questions such as “Did you report me?” or “Why was this transaction flagged?” Avoid confirming or denying a SAR. Direct the inquiry through normal customer-service and compliance channels and provide only the information the institution may lawfully disclose. Train employees not to mention a SAR in ordinary loan notes or borrower correspondence that could be accessible outside the BSA function.

The internal escalation record should preserve facts supporting suspicion, dates, documents, and who received the information. Do not create a separate “SAR file” in an unapproved location or copy the SAR into the loan file. Access should follow the bank’s BSA confidentiality controls. When responding to lawful process, involve the BSA officer and counsel because a court or agency request does not automatically authorize disclosure to the customer.

Current interagency guidance adds an important communication distinction for banks. In a September 2026 joint statement, FinCEN and federal banking agencies clarified that SAR confidentiality does not prevent a bank from communicating transparently and promptly with customers about potentially fraudulent transactions, suspicious activity, or account closures. The statement does not change the confidentiality rule: explain the account facts and actions as appropriate, but do not reveal whether a SAR was filed or information that would reveal its existence. Apply the guidance to covered banks and follow the institution’s BSA and legal procedures; other mortgage-related institutions should follow the SAR rule applicable to their own category.

Confidentiality applies even when a borrower guesses correctly that suspicious activity was reported. Staff should not validate the guess. If a consumer disputes an account event, investigate and respond to the underlying transaction through ordinary procedures without discussing the SAR. Training should cover contractors and agents who may see transaction data, and access controls should prevent unnecessary exposure of SAR information.

A useful training test asks an employee to respond to a customer who says, “I know you filed a report.” The employee should neither confirm nor deny, should avoid discussing internal monitoring, and should route any underlying account dispute through approved customer-service channels. Supervisors should verify that staff understand this rule before they can access BSA-sensitive systems. The institution’s counsel or BSA officer should handle exceptions and legal process.

Exam takeaway

No tipping off: do not reveal that a SAR was filed or share information that discloses its existence, except through the narrow authorized government or supervisory channels.

Common questions

Can an MLO tell the borrower that a SAR was filed if the borrower asks directly?

No. The institution and its personnel may not notify the subject that a SAR was filed.

Can a SAR be shared with a regulator?

The rule allows specified disclosures to government authorities and relevant supervisory agencies; use approved legal and compliance channels.

Does SAR confidentiality prohibit all normal communication with a customer?

No. Staff can communicate about the transaction using accurate approved explanations, while protecting the filing and its existence.