SAR Confidentiality: The Line Between the Filing and the Facts Underneath It
Download MP3Speaker: Hey, everyone.
Welcome back to another
episode of With Flying Colors.
I'm Mark Trakel, former NCUA executive
director, and I spent over three
decades on the regulator side before
I changed teams to start helping
credit unions with all things NCUA.
Today's a short update.
We're breaking down a joint statement
that NCUA and other banking regulators
and FinCEN put out just a few days ago.
It's one of those rare pieces
of guidance that gives you
more room to operate, not less.
So let's get specific.
On September 2nd, five agencies
signed this, the Federal Reserve,
FDIC, OCC, NCUA, and FinCEN.
That's every prudential regulator plus
the BSA rule maker all putting their
name on the same page, which tells you
this wasn't one agency freelancing.
It's a coordinated interagency position.
The subject, suspicious
activity report confidentiality.
Specifically, what you can say to a
member when you've filed or are consider
filing a SAR involving their account.
The headline's simple, SAR confidentiality
rules do not prevent a credit union
from communicating with a member about
a potentially fraudulent transaction or
about an action you've taken on their
account, like a closure or a hold.
What stays confidential, what you
legally cannot disclose, is the existence
of the SAR itself and its contents.
Those are two different things,
and for years a lot of compliance
programs have treated them as
if they were the same thing.
Here's where I wanna get precise,
because the statement itself gets
precise, and that precision is what
you're going to lean on in an exam.
The underlying confidentiality rule comes
straight out of the Bank Secrecy Act,
and NCUA has its own version of that same
rule for federally insured credit unions.
Both say the same thing: you cannot
disclose a SAR or any information
that would reveal that a SAR exists.
But here's the operative sentence
from the joint statement, and I'd
have your BSA officer put this exact
language in the procedures manual.
A SAR or information that would reveal
a SAR exists does not include the
underlying facts, transactions, and
documents that the SAR is based on.
That's the legal test, not how
cautious do we feel, not what's
our institutional risk tolerance.
The test is whether you're
disclosing the SAR itself or
disclosing the facts underneath it.
Telling a member, "We identified unusual
activity and placed a hold while we
investigate," or, "We're closing this
account due to activity that violates
our risk policies," those are statements
about facts and about actions taken.
They are not disclosure of a SAR's
existence or content, and the agencies
are now saying that explicitly, because
enough institutions were conflating the
two and leaving members in the dark,
sometimes for weeks, out of the caution
the rule never actually required.
Now, why does this belong on a CEO
or board member's desk and not just
the BSA officer's file cabinet?
Two reasons, both regulatory.
One, this is an exam finding waiting
to happen in either direction.
If your BSA program's internal guidance is
written more restrictively than the actual
rule requires, that's not a safe harbor.
That's your own policy manufacturing
member service and complaint handling
exposure that examiners may ask
about under the consumer compliance
side of the exam, separate and
apart from your BSA AML module.
Examiners are going to ask how you
communicate with your members during a
fraud hold, and we say nothing ever out of
caution is now a harder position to defend
than it was a week ago, because there's an
interagency statement on the books saying
that caution wasn't required by the rule.
Two, there's a safe harbor
angle worth knowing here, too.
Separate from the confidentiality piece,
the Bank Secrecy Act also gives you a
liability protection for good faith SAR
filings and related actions, including
account closure tied to that filing.
So you're actually protected on both
ends, protected from liability for the
action you took, and now expressly told
you can explain the action itself to
the member, so long as you don't cross
into confirming or describing the SAR.
So here's what I'd actually put in
front of my BSA officer this week
if it were me, and I'd frame it as a
gap analysis, not a policy overhaul.
First, pull the current SAR
confidentiality training materials
and fraud hold call scripts and check
them against the joint statements.
Underlying facts test.
If your materials say anything broader
than don't confirm or describe a SAR,
you're potentially more restrictive than
the regulation requires, and I'd want
to document that before the exam starts.
Second, get a one-page reference
in front of the frontline and fraud
staff that states the actual line,
"Discuss facts and actions taken.
Never confirm or describe a SAR,"
with sample scripted language, because
know the difference isn't a control.
It's a hope.
Third, have counsel sign off
before you finalize anything.
Remember, this is a joint statement, an
interpretive position from five agencies.
It's not a change to the
underlying regulation itself.
I'd want counsel confirming how far your
specific pre- procedures can move on the
strength of guidance versus a rule change.
The rel- regulatory theme here
is one worth sitting with.
This wasn't a new obligation
being layered on you.
It was five agencies telling
the industry that a common
practice was more conservative
than the rule actually requires.
That's worth an audit of where else your
BSA program, the safe answer, became
the house rule without any rechecking
it against what the rule actually says.
That's all I've got for you today.
I hope you're having a
wonderful Labor Day weekend.
This is Mark Trakel, as always,
signing off with flying colors.
I hope you'll listen again soon.
