SAR Privilege: Safe Harbor, Penalties, and Authorized Disclosures

The SAR privilege is a federal confidentiality rule that forbids a financial institution from disclosing a Suspicious Activity Report, or even confirming that one exists, to anyone outside law enforcement and bank regulators. It is absolute. No subpoena, court order, discovery request, or private agreement can override it, and the institution cannot waive it. What the privilege does not do is lock away the ordinary business records that prompted the filing. Account statements, wire logs, and routine correspondence remain fair game in civil litigation, and that gap is where most of the real work gets done.

What the Privilege Covers

The core prohibition sits in 31 U.S.C. § 5318(g)(2)(A)(i), which bars financial institutions and their directors, officers, employees, and agents from notifying any person involved in a transaction that the transaction has been reported.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority The statute reaches beyond the physical report. It covers any information that would reveal whether a SAR exists: oral statements, emails, internal memos discussing the filing decision, and compliance-department notes created for the purpose of drafting the report.2eCFR. 12 CFR 21.11 – Suspicious Activity Report

The rule also blocks “negative” disclosures. A bank cannot tell you that no SAR was filed for a particular transaction, because that answer narrows the universe and could reveal filings on adjacent activity.3eCFR. 12 CFR 163.180 – Suspicious Activity Reports and Other Reports and Statements When a subpoena or other request for SAR information lands, the institution must decline to produce anything, cite the statute and the applicable regulation, and immediately notify both its primary federal regulator and FinCEN that the request was made.2eCFR. 12 CFR 21.11 – Suspicious Activity Report

The rigidity has a practical purpose. If the target of a money-laundering investigation could use a routine contract dispute or divorce to find out whether their bank flagged them, they could destroy evidence, move assets offshore, or leave the country before agents act. Courts treat the privilege as protection for the investigative pipeline, not the bank, and that is why no party has authority to waive it.

Why No Judge Can Peek

The workaround familiar from other privilege fights, in camera review, is unavailable here. FINRA’s arbitration rules explicitly instruct arbitrators not to request SAR documents for private inspection. The reason is structural: the moment a judge or arbitrator reads a SAR to decide whether it is privileged, the confidentiality the statute exists to preserve has already been breached. An arbitrator or judge can still conduct in camera review of documents that do not contain SAR information, to decide whether they qualify as discoverable underlying records.

Who Must Assert the Privilege

The privilege belongs jointly to the reporting institution and the federal government. Dual ownership matters: if a bank closes, merges, or changes management, the government’s interest in confidentiality survives. FinCEN, the OCC, the Federal Reserve, and other prudential regulators each maintain authority over the information and can enforce the confidentiality rules independently.

Any entity classified as a “financial institution” under the Bank Secrecy Act carries SAR obligations and the privilege that comes with them. The category is broader than most people expect:

  • Banks and credit unions, subject to 12 CFR 21.11 for national banks, 12 CFR 208.62 for state member banks, and parallel rules for other charters.
  • Casinos and gaming operations, governed by 31 CFR 1021.320, which must decline production and notify FinCEN just as banks do.4eCFR. 31 CFR 1021.320 – Reports by Casinos of Suspicious Transactions
  • Broker-dealers in securities, covered by both FinCEN regulations and separate FINRA confidentiality guidance.
  • Money service businesses, including check cashers, money transmitters, and currency exchanges.
  • Insurance companies, mutual funds, and dealers in precious metals or stones.

The obligation reaches individuals as well as institutions. Directors, officers, employees, and agents are each independently barred from disclosing a SAR, and the bar continues after they leave the organization.

What Stays Discoverable

This is the line litigators care about. The privilege protects the report and anything that would reveal the report’s existence. It does not protect the facts that prompted the report.

Records created in the ordinary course of business remain reachable through standard civil procedure. That includes account statements, wire transfer records, checks, deposit slips, account-opening documents, and emails discussing a customer’s activity.5Federal Register. Confidentiality of Suspicious Activity Reports The test is straightforward: if the document would exist even if no SAR had ever been filed, the privilege does not cover it. A monthly account statement showing a large cash deposit exists because banks send statements to every customer, not because someone chose to report the deposit.

Automated transaction-monitoring alerts sit in a gray zone. The raw data behind an alert, meaning the transaction amounts, dates, and counterparties, remains discoverable as ordinary business records. A compliance officer’s notes analyzing those alerts specifically to decide whether to file a SAR cross into protected territory. Courts generally draw the boundary at the moment the institution pivots from routine record-keeping to the SAR decision itself.

Banks sometimes stretch the privilege to cover everything connected to a suspicious customer, and courts push back on that. A routine internal audit report remains discoverable unless it specifically references a SAR filing. The privilege is not a blanket shield against producing inconvenient documents that have nothing to do with the reporting process.

Framing Discovery Requests

For the party seeking information, the practical move is to aim discovery at the underlying records. A request for “all account statements, wire transfer records, and internal correspondence regarding [customer name]” produces the same transactional data the bank reported to FinCEN, without ever touching the SAR. Skilled practitioners draft around the privilege by never asking for SARs and asking instead for categories of documents that exist independently of the reporting process.

The institution on the other side bears the burden of properly asserting the privilege. It must refuse production, cite both the statute and the regulation, and notify FinCEN and its primary regulator of the request.2eCFR. 12 CFR 21.11 – Suspicious Activity Report A judge cannot resolve the dispute by taking a private look, so the fight has to be about categories of documents rather than about specific pages.

Safe Harbor for Filers

Filing a SAR usually means accusing a customer of criminal behavior, which would ordinarily expose the bank to defamation, tortious interference, or breach-of-contract claims. The safe harbor at 31 U.S.C. § 5318(g)(3) eliminates that exposure. Any financial institution that discloses a possible legal violation to the government under this section, and any employee who makes or requires the disclosure, is immune from civil liability under federal or state law, including claims arising under private contracts and arbitration agreements.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority

The scope is striking. The First Circuit has held that immunity applies even when a SAR was fabricated or filed with malice, reasoning that Congress deliberately left out a good-faith requirement. The Eleventh Circuit has gone the other way, limiting immunity to filings made in good faith. Where the case sits matters. In most jurisdictions, courts have read the safe harbor broadly enough to shut down virtually any civil claim rooted in the act of filing.

The immunity does not extend to government enforcement. Federal and state regulators can still pursue an institution for filing deficient SARs, maintaining weak anti-money-laundering programs, or other compliance failures. The statute says so directly.1Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority

Penalties for Improper Disclosure

Unauthorized SAR disclosure carries both civil and criminal exposure. FinCEN can impose civil penalties of up to $100,000 per violation. If the disclosure traces back to systemic anti-money-laundering program deficiencies like inadequate training or weak internal controls, additional penalties of up to $25,000 per day can accumulate for as long as the deficiency lasts.6Financial Crimes Enforcement Network. FinCEN Advisory FIN-2012-A002

Criminal penalties are steeper. A willful violation of the Bank Secrecy Act carries a fine of up to $250,000 and up to five years in prison.7Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties If the violation is part of a pattern of illegal activity involving more than $100,000 in a 12-month period, the ceiling doubles to $500,000 and ten years. Individual employees convicted of BSA violations must also forfeit any bonus received during the calendar year of the violation or the year after. An institution that discovers an unauthorized disclosure, or that receives a subpoena for SAR information from anyone other than an authorized government body, should contact FinCEN’s Office of Chief Counsel.

Authorized Disclosures That Don’t Break the Privilege

The confidentiality rule has narrow carve-outs for disclosures that serve the statute’s purpose.

Law Enforcement and Regulators

Financial institutions can share SARs and SAR-related information with any federal, state, or local law enforcement agency, and with federal and state regulators that examine the institution for Bank Secrecy Act compliance.3eCFR. 12 CFR 163.180 – Suspicious Activity Reports and Other Reports and Statements The FBI, IRS, DEA, and state attorneys general all fall within this category. These disclosures do not waive the privilege because they carry out the exact purpose Congress created the reporting system to serve.

Board Notification and Internal Sharing

Management must promptly notify the institution’s board of directors, or a board-designated committee, whenever a SAR is filed. If the person named in the SAR is a director or executive officer, the institution notifies all non-suspect directors but cannot alert the suspect.3eCFR. 12 CFR 163.180 – Suspicious Activity Reports and Other Reports and Statements Information can also move within the institution’s corporate structure for BSA purposes, as long as no person involved in the reported transaction learns that a report was filed.

Sharing Between Institutions

Section 314(b) of the USA PATRIOT Act lets financial institutions voluntarily share information with each other to identify potential money laundering or terrorist financing. To qualify for its safe harbor, an institution must register with FinCEN’s Secure Information Sharing System, verify the counterpart is also registered, and use the shared data only for identifying reportable activity, making account decisions, or meeting anti-money-laundering requirements.8Financial Crimes Enforcement Network. Section 314(b) Fact Sheet

The limit is critical. Section 314(b) does not authorize sharing the SAR itself or any information that would reveal whether a SAR exists. Institutions can exchange transaction details, customer information, and investigative findings, but the moment the communication crosses into confirming or implying a filing, it violates the confidentiality rules. Institutions collaborating on a joint SAR can discuss the prospective or already-filed joint report among themselves.8Financial Crimes Enforcement Network. Section 314(b) Fact Sheet

Cross-Border Sharing With Foreign Affiliates

A U.S. bank can share the underlying facts, transactions, and customer data with a foreign parent or overseas affiliate without breaching SAR confidentiality, provided the institution redacts anything that would reveal a SAR’s existence. FinCEN’s 2025 cross-border guidance identifies what qualifies: wire transfer details, account ownership records, customer due-diligence materials, transaction-monitoring alerts, and cyber-related data such as IP addresses and device identifiers.9Financial Crimes Enforcement Network. Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality The institution has to evaluate each sharing decision case by case, weighing its relationship with the foreign affiliate, privacy obligations under the Right to Financial Privacy Act and the Gramm-Leach-Bliley Act, and any restrictions imposed by the foreign jurisdiction.