Heard it Through the FI Portal: FinCEN Clarifies Fraud Information Sharing Under Section 314(b)
I’m going to say something that may shock you. Fraudsters historically have not held many scruples. And fraud, in general, has never had much respect for boundaries – including institutional boundaries.
Downright impolite, if you ask me. But it’s also a significant operational, customer-protection, and risk-management problem.
Let me demonstrate – one institution sees the account opening, another sees the login, yet another sees the transfer, and yet even another sees the cash-out. And, by the time everyone realizes they may have been looking at the same scheme, (if they’re even so lucky to all come to that collective conclusion), the money is often long gone.
Which is where Section 314(b) has always had obvious promise.
On June 12th, FinCEN issued updated guidance clarifying how financial institutions can use Section 314(b) of the USA PATRIOT Act to share information with one another about suspected fraud. In plain English, the agency is “reminding” banks and other covered financial institutions that 314(b) is not limited to traditional money laundering or terrorist financing cases. Fraud can also fit within the framework, particularly where the activity may involve fraud proceeds, money laundering, terrorist financing, or another specified unlawful activity.
Under 314(b), eligible financial institutions that register with FinCEN and follow the rule’s requirements receive a safe harbor for sharing information with one another for permitted purposes. Participation (via FinCEN’s FI Portal) remains voluntary, but FinCEN is clearly encouraging institutions to use the tool more actively – and more quickly – to connect dots across institutions.
The updated fact sheet even gives examples of the kinds of fraud indicators that may warrant information sharing: newly added payees followed by large transfers, unusual changes in customer behavior, multiple accounts receiving or sending funds in a coordinated way, device or IP address overlaps, suspicious account-opening patterns, and other activity that may suggest fraud proceeds or a broader scheme. In other words, FinCEN is talking about the messy, modern, institution-hopping fraud patterns banks see every day.
But the fact sheet also makes pointedly clear that the information shared can be broad (more on this in just a bit.) Depending on the facts, institutions may share transaction details, customer information, account-opening or account-closure information, monitoring alerts, suspicious indicators, cyber-related data, device identifiers, IP addresses / geolocations, and even video surveillance footage. FinCEN also says the BSA does not impose a separate limitation on sharing personally identifiable information under 314(b), assuming the sharing otherwise complies with the rule.
Arguably, that makes the guidance significant for two reasons – not only is it overdue for clarity, but it is clarity that may carry with it potential consequences.
For years, the industry has had to read between the lines, footnotes, and cross-references to get to what many BSA and BSA-adjacent professionals considered the obvious point – yes, fraud-related information can be shared through 314(b) when the activity fits within the rule’s permitted purposes. Prior FinCEN materials and the FFIEC manual dropped a few breadcrumbs, but stopped short of giving banks a clean, well-lit path to safely use 314(b) for fraud investigations without wondering whether their examiner would agree.
So, of course, the clarity is welcomed.
But, for better or for worse, clarity tends to have a way of expanding what people feel comfortable doing with it.
The obvious concern is that broader, faster information sharing can become broader, faster sharing of customer information – and “customer information” can be a very large bucket. Remember, FinCEN isn’t just talking about one institution telling another, “We think these transactions may be connected.” I’ll reiterate from earlier: depending on the facts, the information shared could include customer details, transaction activity, device identifiers, IP addresses, monitoring alerts, account-opening or account-closure decisions, and even video surveillance footage.
Now, that can be very useful in the right case. But it’s also fairly easy to see the danger, and raises a pretty obvious privacy question: if that is what can be shared, what else might start traveling under the banner of fraud prevention?
Also worth musing on – once that information arrives, how much weight does the receiving institution give it? After all, a monitoring alert is still just an alert. A device match still needs context. A video clip may show something, but certainly not everything. And an account closure decision at one bank shouldn’t automatically become a de facto denial reason at another.
Making a bank’s discretion and internal controls / governance particularly important here. Banks should know who can share information, what can be shared, why it is being shared, how much is actually necessary, how it is documented, how long it is retained, and how incoming information is evaluated. Section 314(b) may be a safe harbor, but it shouldn’t become a privacy-sensitive “free-for-all” – or a shortcut for outsourcing judgment to another institution’s suspicion.
That’s especially true on the SAR side. The FFIEC manual makes clear that a bank is not required to file a SAR solely because it receives a 314(b) information-sharing request. In other words, shared suspicion may be useful, but it is not self-executing.
And, before we go – it’d be to my chagrin if one broader irony wasn’t noted here. As was written about in April, GAO has already warned that federal anti-scam and fraud efforts remain heavily fragmented, with agencies lacking a government-wide strategy, common definitions, and complete loss data. Yet here, FinCEN is quite sensibly telling banks to share information, move faster, and connect dots across institutional lines to combat fraud.
In fact, Treasury is even touting the guidance as part of the Administration’s “whole-of-government effort to unleash every available tool to stop fraudsters from exploiting everyday Americans and businesses.”
So yes, this guidance is useful. It may even be overdue. Fraud is fast, networked, and institution-hopping, and a well-run 314(b) program can help institutions spot patterns earlier, strengthen SAR narratives, protect customers, and give law enforcement a more complete picture.
But banks should use it like a formidable compliance tool, not a rumor mill with a safe harbor. Share only the relevant information, compare the notes, and connect the dots (just don’t mistake the dots for the whole picture).
Because fraudsters may talk to each other – so banks probably should too.
But when they do, accuracy, context, and discretion still matter.
The updated 314(b) Fact Sheet ca be found here: [Section 314(b) Fact Sheet]
Treasury’s Press Release can be found here: [FinCEN Issues Guidance to Help Financial Institutions Eliminate Fraud Through Information Sharing]

Brett Goodnack, JD, CAMS
Compliance Advisor
I Still Haven’t Found Who I’m [Not] Looking For: GAO Flags Ownership Gaps After Treasury Narrows BOI Reporting
Stop me if you’ve heard this old chestnut before: A legal entity walks into a bank.
The bank asks, “Who actually owns you?”
The entity looks around and whispers, “…Who wants to know?”
Alright, fine – not much of a joke (no one said federal regulatory humor was easy). But that, in miniature, is the problem the Corporate Transparency Act was supposed to help solve.
Instead of forcing banks – and, notably, law enforcement and investigators – to keep playing ownership detective one customer at a time, the law created a federal beneficial ownership registry at FinCEN, bringing the U.S. closer to the ownership-transparency framework already familiar across much of Europe and the world at large. It’s a simple-enough idea – anonymous shell companies are useful to criminals precisely because they are anonymous, so maybe the government should make them a little less so. After all, FinCEN’s self-described slogan is “follow the money,” and what better way to start than by making the company say who is behind it?
Then came Treasury’s 2025 reversal.
In March 2025, FinCEN issued an interim final rule that dramatically narrowed the BOI reporting program, exempting domestic companies and U.S. persons and leaving the reporting obligation largely to foreign companies registered to do business in the United States. A new U.S. Government Accountability Office (GAO) report translates that policy choice into stark numerical terms – more than 99 percent of the entities that previously would have had to report are now outside the rule.
Now, it’s no secret that Treasury’s stated rationale was burden reduction – to be sure, a valid concern. Anyone on the bank-compliance front lines knows that small businesses have spent the last few years trying to understand a rule that was delayed, challenged, revived, narrowed, and reworked enough times to make even seasoned professionals wake up in a cold sweat shouting “…substantial control!” Nobody can pretend that BOI reporting was frictionless.
But GAO’s point is that burden reduction came with a significant cost. The report notes that U.S.-based shell companies can pose significant illicit-finance risks, a fact that should likewise surprise no one in banking. Shell companies have long been used to obscure ownership, move illicit funds, evade sanctions, conceal fraud proceeds – overall, make “follow[ing] the money” a whole lot harder.
Treasury relieved millions of entities from reporting, but, of course, the ownership question didn’t disappear. It simply moved back into the slower, murkier downstream work – to law enforcement, to investigators, and, practically speaking, to banks.
Banks still have to understand customer ownership and control (see, generally: 31 CFR 1010.230). Banks still have to manage legal entity risk. And with that in mind, banks still have to investigate suspicious activity – particularly when the ownership structure looks like it was designed by someone trying very hard not to be found. So, the government may have reduced the reporting burden on businesses, but it hasn’t eliminated any of the underlying opacity – and that opacity was arguably always the real problem.
GAO recommended that Treasury identify potential actions to address the risks created by the domestic-company and U.S.-person exemptions and provide Congress and law enforcement with useful information to address those risks. And, as GAO curtly reported, “Treasury disagreed with the recommendation.”
GAO’s report can be found here: GAO-26-107967 – Corporate Transparency: Treasury Should Address Gaps in Ownership Information Resulting from Expanded Exemptions

Brett Goodnack, JD, CAMS
Compliance Advisor
FinCEN Advisory Raises Screening, Fair Banking Concerns
The White House recently issued an Executive Order titled “Restoring Integrity to America’s Financial System,” and the fear was that it would push banks toward a role they were never designed to play – immigration-adjacent screeners, asked to translate lawful-presence questions into BSA, fraud, credit, and customer-risk decisions.
On June 5th, FinCEN, joined by the FDIC, OCC, NCUA, and coordinated with the IRS, issued a new advisory on “non-work authorized populations and their employers” and the risks they allegedly pose to the integrity of the U.S. financial system. The advisory is expressly issued in response to the Executive Order, and it asks financial institutions to use the SAR keyword “FINANCIALINTEGRITY-2026-A002” when reporting activity connected to the typologies it describes.
That’s the thing about executive orders, which we’ve written about time and time again. They may begin as political documents – ones without the force or effect of law. But in many cases, someone eventually turns them into operational guidance – the kind that banks are suddenly “expected” to follow.
Just like the EO that gave it life, much of the advisory describes real financial-crime risk. It discusses identity theft, fraudulent use of Social Security numbers, off-the-books payroll, payroll tax evasion, workers’ compensation fraud, shell companies, complicit labor brokers, unregistered money services businesses, structured cash withdrawals, check cashing, P2P payments, and cash courier activity. But, as has been argued in the past, banks have been advised of – and are aware of – these patterns already. In fact, the “strongest” parts of the advisory read less like a new immigration warning and more like familiar payroll-fraud and labor-broker typologies – just wearing a new jacket.
The advisory is particularly detailed on labor broker schemes. It describes shell companies in industries like construction, agriculture, hospitality, domestic service, and staffing; checks written for supposed subcontracting services; repeated cash withdrawals or check-cashing activity; and workers paid outside ordinary payroll systems. FinCEN says financial institutions reported more than $2.5 billion in suspicious activity associated with this kind of scheme in 2025.
Then comes the even harder part.
The advisory tells banks to consider the use of an ITIN, in lieu of an SSN or valid employment authorization document, as a possible risk factor when opening accounts or extending credit. It notes that ITINs don’t establish legal status, authorize employment, or serve as identification outside the federal tax system. Now, that’s true enough, as far as it goes. But it is also true that ITINs exist so people who are not eligible for Social Security numbers can comply with federal tax obligations – a point the advisory acknowledges in almost ‘blink-and-you’ll-miss-it’ fashion.
Treating ITIN use as inherently suspicious risks doing exactly what the advisory says it is not doing – turning a lawful identifier used by many foreign nationals and immigrants into a reason for heightened scrutiny. And once that happens, the concern is not just BSA overreporting; it is fair banking and fair lending risk. A bank that treats ITIN users, immigrant-owned businesses, or customers with nontraditional documentation as categorically more suspicious may not be managing risk so much as converting immigration-adjacent assumptions into account access, credit availability, and customer-service decisions.
This may explain why the advisory includes the usual (and increasingly important) caveats: no single red flag is determinative, no red flag should be taken in isolation, institutions should consider the surrounding facts and circumstances, and no customer type presents a uniform money laundering or terrorist financing risk. Perhaps most importantly of all – the advisory explicitly states that its red flag indicators “do not convey or alter any independent regulatory obligations or supervisory expectations.”
Make sure to highlight that sentence. Because without it, this advisory could be read much too broadly. A customer using an ITIN is not automatically suspicious. A foreign passport is not a SAR. A remittance is not, by itself, a typology. And an immigrant-owned business in a cash-heavy industry is not presumptively a front for payroll fraud. Not to mention, Regulation B’s prohibited bases still exist – including race and national origin – as do the broader concepts tied to UDAP/UDAAP that arise when a “risk-based” process becomes unfair, inconsistent, or needlessly (and unjustifiably) exclusionary.
If banks use this advisory to sharpen monitoring for payroll fraud, identity theft, shell companies, structuring, unregistered MSB activity, and labor exploitation – fair enough; that’s at least the part rooted in actual financial-crime risk. But if banks internalize the broader message as “ITIN customers equal higher risk,” the advisory becomes something else entirely – a door to categorical financial exclusion, opened with a SAR keyword.
The FinCEN Advisory can be found here: [FIN-2026-A002]
Its genesis, Executive Order 14406, can be found here: [91 FR 30479]

Brett Goodnack, JD, CAMS
Compliance Advisor
Fair Lending Groups Sue CFPB Over ECOA Final Rule
A little over a month after the CFPB finalized its Regulation B rewrite – the one that indicates that ECOA never really authorized disparate-impact liability after all – fair lending advocates have taken the Bureau to court. On May 27th, the National Fair Housing Alliance, Rise Economy, BLDS, and SolasAI filed suit in federal court in Washington, D.C., seeking to block the CFPB’s final rule before it takes effect on July 21st.
The plaintiffs argue that the CFPB’s final rule dismantles core fair-lending protections that have existed, in one form or another, for decades. As we discussed last month, the challenged rule essentially aims to do three big things – it removes disparate-impact liability from Regulation B, narrows what counts as unlawful discouragement of applicants or prospective applicants, and tightens the conditions around Special Purpose Credit Programs. Now, according to this iteration of the CFPB, this is “clarifying” ECOA. But, according to the plaintiffs, it is an about-face so sharp it could slice right through 50 years of history.
And, to that end, the heart of the challenge is simple enough – the plaintiffs say the CFPB cannot just wave away half of a century of regulatory, congressional, and judicial understanding simply because the agency has suddenly discovered a new “best reading” of the statute.
And the complaint does more than simply accuse the CFPB of changing its mind. It argues that the Bureau changed its mind without identifying a concrete problem with the existing framework, without meaningfully grappling with contrary evidence, without adequately weighing costs and benefits, without giving small entities the required procedural protections, and without responding in any serious way to significant comments.
On that latter procedural point, the complaint argues that when an agency proposes one of the most sweeping fair-lending rewrites in decades, gives the public 32 days over Thanksgiving to respond, receives roughly 64,000 comments, and then changes essentially nothing, “reasoned decision-making” starts to look less like the standard.
More plainly, their complaint argues that the rule is arbitrary and capricious, contrary to ECOA, procedurally defective, and unsupported by meaningful evidence. They also challenge Acting Director Russell Vought’s authority to issue the rule (arguing that the administration could not simply fire the confirmed CFPB Director, plug in an acting replacement, and call that a lawful vacancy).
But beneath the many plausible legal claims is the more practical concern – this rule doesn’t merely change how lawyers argue fair-lending cases. No – it changes what kinds of discrimination the law itself is built to see.
If it’s been said once, it should be said a thousand times – the final rule may reduce one federal theory of liability, but it does not erase fair-lending risk. Nor does it repeal the Fair Housing Act. Nor does it preempt state law. Nor does it eliminate redlining risk, marketing risk, model risk, reputational risk, or – starkly – the possibility that a future CFPB – perhaps one less eager to mistake political errands for legal clarity – tries to swing the pendulum back with interest.
The Plaintiffs have issued a joint statement / Press Release, and it can be found here: [Fair Housing and Lending Advocates Sue CFPB Over New Rule Gutting Key Anti-Discrimination Protections]
The complaint itself can be found here: [COMPLAINT FOR DECLARATORY AND INJUNCTIVE RELIEF]

Brett Goodnack, JD, CAMS
Compliance Advisor