SAR Confidentiality: The Line Between the Filing and the Facts Underneath It

Download MP3

Speaker: Hey, everyone.

Welcome back to another
episode of With Flying Colors.

I'm Mark Trakel, former NCUA executive
director, and I spent over three

decades on the regulator side before
I changed teams to start helping

credit unions with all things NCUA.

Today's a short update.

We're breaking down a joint statement
that NCUA and other banking regulators

and FinCEN put out just a few days ago.

It's one of those rare pieces
of guidance that gives you

more room to operate, not less.

So let's get specific.

On September 2nd, five agencies
signed this, the Federal Reserve,

FDIC, OCC, NCUA, and FinCEN.

That's every prudential regulator plus
the BSA rule maker all putting their

name on the same page, which tells you
this wasn't one agency freelancing.

It's a coordinated interagency position.

The subject, suspicious
activity report confidentiality.

Specifically, what you can say to a
member when you've filed or are consider

filing a SAR involving their account.

The headline's simple, SAR confidentiality
rules do not prevent a credit union

from communicating with a member about
a potentially fraudulent transaction or

about an action you've taken on their
account, like a closure or a hold.

What stays confidential, what you
legally cannot disclose, is the existence

of the SAR itself and its contents.

Those are two different things,
and for years a lot of compliance

programs have treated them as
if they were the same thing.

Here's where I wanna get precise,
because the statement itself gets

precise, and that precision is what
you're going to lean on in an exam.

The underlying confidentiality rule comes
straight out of the Bank Secrecy Act,

and NCUA has its own version of that same
rule for federally insured credit unions.

Both say the same thing: you cannot
disclose a SAR or any information

that would reveal that a SAR exists.

But here's the operative sentence
from the joint statement, and I'd

have your BSA officer put this exact
language in the procedures manual.

A SAR or information that would reveal
a SAR exists does not include the

underlying facts, transactions, and
documents that the SAR is based on.

That's the legal test, not how
cautious do we feel, not what's

our institutional risk tolerance.

The test is whether you're
disclosing the SAR itself or

disclosing the facts underneath it.

Telling a member, "We identified unusual
activity and placed a hold while we

investigate," or, "We're closing this
account due to activity that violates

our risk policies," those are statements
about facts and about actions taken.

They are not disclosure of a SAR's
existence or content, and the agencies

are now saying that explicitly, because
enough institutions were conflating the

two and leaving members in the dark,
sometimes for weeks, out of the caution

the rule never actually required.

Now, why does this belong on a CEO
or board member's desk and not just

the BSA officer's file cabinet?

Two reasons, both regulatory.

One, this is an exam finding waiting
to happen in either direction.

If your BSA program's internal guidance is
written more restrictively than the actual

rule requires, that's not a safe harbor.

That's your own policy manufacturing
member service and complaint handling

exposure that examiners may ask
about under the consumer compliance

side of the exam, separate and
apart from your BSA AML module.

Examiners are going to ask how you
communicate with your members during a

fraud hold, and we say nothing ever out of
caution is now a harder position to defend

than it was a week ago, because there's an
interagency statement on the books saying

that caution wasn't required by the rule.

Two, there's a safe harbor
angle worth knowing here, too.

Separate from the confidentiality piece,
the Bank Secrecy Act also gives you a

liability protection for good faith SAR
filings and related actions, including

account closure tied to that filing.

So you're actually protected on both
ends, protected from liability for the

action you took, and now expressly told
you can explain the action itself to

the member, so long as you don't cross
into confirming or describing the SAR.

So here's what I'd actually put in
front of my BSA officer this week

if it were me, and I'd frame it as a
gap analysis, not a policy overhaul.

First, pull the current SAR
confidentiality training materials

and fraud hold call scripts and check
them against the joint statements.

Underlying facts test.

If your materials say anything broader
than don't confirm or describe a SAR,

you're potentially more restrictive than
the regulation requires, and I'd want

to document that before the exam starts.

Second, get a one-page reference
in front of the frontline and fraud

staff that states the actual line,
"Discuss facts and actions taken.

Never confirm or describe a SAR,"
with sample scripted language, because

know the difference isn't a control.

It's a hope.

Third, have counsel sign off
before you finalize anything.

Remember, this is a joint statement, an
interpretive position from five agencies.

It's not a change to the
underlying regulation itself.

I'd want counsel confirming how far your
specific pre- procedures can move on the

strength of guidance versus a rule change.

The rel- regulatory theme here
is one worth sitting with.

This wasn't a new obligation
being layered on you.

It was five agencies telling
the industry that a common

practice was more conservative
than the rule actually requires.

That's worth an audit of where else your
BSA program, the safe answer, became

the house rule without any rechecking
it against what the rule actually says.

That's all I've got for you today.

I hope you're having a
wonderful Labor Day weekend.

This is Mark Trakel, as always,
signing off with flying colors.

I hope you'll listen again soon.

SAR Confidentiality: The Line Between the Filing and the Facts Underneath It
Broadcast by