I’m going to say something that may shock you. Fraudsters historically have not held many scruples. And fraud, in general, has never had much respect for boundaries – including institutional boundaries.
Downright impolite, if you ask me. But it’s also a significant operational, customer-protection, and risk-management problem.
Let me demonstrate – one institution sees the account opening, another sees the login, yet another sees the transfer, and yet even another sees the cash-out. And, by the time everyone realizes they may have been looking at the same scheme, (if they’re even so lucky to all come to that collective conclusion), the money is often long gone.
Which is where Section 314(b) has always had obvious promise.
On June 12th, FinCEN issued updated guidance clarifying how financial institutions can use Section 314(b) of the USA PATRIOT Act to share information with one another about suspected fraud. In plain English, the agency is “reminding” banks and other covered financial institutions that 314(b) is not limited to traditional money laundering or terrorist financing cases. Fraud can also fit within the framework, particularly where the activity may involve fraud proceeds, money laundering, terrorist financing, or another specified unlawful activity.
Under 314(b), eligible financial institutions that register with FinCEN and follow the rule’s requirements receive a safe harbor for sharing information with one another for permitted purposes. Participation (via FinCEN’s FI Portal) remains voluntary, but FinCEN is clearly encouraging institutions to use the tool more actively – and more quickly – to connect dots across institutions.
The updated fact sheet even gives examples of the kinds of fraud indicators that may warrant information sharing: newly added payees followed by large transfers, unusual changes in customer behavior, multiple accounts receiving or sending funds in a coordinated way, device or IP address overlaps, suspicious account-opening patterns, and other activity that may suggest fraud proceeds or a broader scheme. In other words, FinCEN is talking about the messy, modern, institution-hopping fraud patterns banks see every day.
But the fact sheet also makes pointedly clear that the information shared can be broad (more on this in just a bit.) Depending on the facts, institutions may share transaction details, customer information, account-opening or account-closure information, monitoring alerts, suspicious indicators, cyber-related data, device identifiers, IP addresses / geolocations, and even video surveillance footage. FinCEN also says the BSA does not impose a separate limitation on sharing personally identifiable information under 314(b), assuming the sharing otherwise complies with the rule.
Arguably, that makes the guidance significant for two reasons – not only is it overdue for clarity, but it is clarity that may carry with it potential consequences.
For years, the industry has had to read between the lines, footnotes, and cross-references to get to what many BSA and BSA-adjacent professionals considered the obvious point – yes, fraud-related information can be shared through 314(b) when the activity fits within the rule’s permitted purposes. Prior FinCEN materials and the FFIEC manual dropped a few breadcrumbs, but stopped short of giving banks a clean, well-lit path to safely use 314(b) for fraud investigations without wondering whether their examiner would agree.
So, of course, the clarity is welcomed.
But, for better or for worse, clarity tends to have a way of expanding what people feel comfortable doing with it.
The obvious concern is that broader, faster information sharing can become broader, faster sharing of customer information – and “customer information” can be a very large bucket. Remember, FinCEN isn’t just talking about one institution telling another, “We think these transactions may be connected.” I’ll reiterate from earlier: depending on the facts, the information shared could include customer details, transaction activity, device identifiers, IP addresses, monitoring alerts, account-opening or account-closure decisions, and even video surveillance footage.
Now, that can be very useful in the right case. But it’s also fairly easy to see the danger, and raises a pretty obvious privacy question: if that is what can be shared, what else might start traveling under the banner of fraud prevention?
Also worth musing on – once that information arrives, how much weight does the receiving institution give it? After all, a monitoring alert is still just an alert. A device match still needs context. A video clip may show something, but certainly not everything. And an account closure decision at one bank shouldn’t automatically become a de facto denial reason at another.
Making a bank’s discretion and internal controls / governance particularly important here. Banks should know who can share information, what can be shared, why it is being shared, how much is actually necessary, how it is documented, how long it is retained, and how incoming information is evaluated. Section 314(b) may be a safe harbor, but it shouldn’t become a privacy-sensitive “free-for-all” – or a shortcut for outsourcing judgment to another institution’s suspicion.
That’s especially true on the SAR side. The FFIEC manual makes clear that a bank is not required to file a SAR solely because it receives a 314(b) information-sharing request. In other words, shared suspicion may be useful, but it is not self-executing.
And, before we go – it’d be to my chagrin if one broader irony wasn’t noted here. As was written about in April, GAO has already warned that federal anti-scam and fraud efforts remain heavily fragmented, with agencies lacking a government-wide strategy, common definitions, and complete loss data. Yet here, FinCEN is quite sensibly telling banks to share information, move faster, and connect dots across institutional lines to combat fraud.
In fact, Treasury is even touting the guidance as part of the Administration’s “whole-of-government effort to unleash every available tool to stop fraudsters from exploiting everyday Americans and businesses.”
So yes, this guidance is useful. It may even be overdue. Fraud is fast, networked, and institution-hopping, and a well-run 314(b) program can help institutions spot patterns earlier, strengthen SAR narratives, protect customers, and give law enforcement a more complete picture.
But banks should use it like a formidable compliance tool, not a rumor mill with a safe harbor. Share only the relevant information, compare the notes, and connect the dots (just don’t mistake the dots for the whole picture).
Because fraudsters may talk to each other – so banks probably should too.
But when they do, accuracy, context, and discretion still matter.
The updated 314(b) Fact Sheet ca be found here: [Section 314(b) Fact Sheet]
Treasury’s Press Release can be found here: [FinCEN Issues Guidance to Help Financial Institutions Eliminate Fraud Through Information Sharing]

Brett Goodnack, JD, CAMS
Compliance Advisor