Your securities broker-dealer has expanded internationally, and now your foreign parent company needs insight into your AML compliance program. However, you can't simply email them your Suspicious Activity Reports (SARs) without breaching Bank Secrecy Act confidentiality requirements. Here's how to create a compliant SAR-sharing framework that aligns with FinCEN guidance and your operational needs.
The Problem: Balancing Compliance Oversight and Confidentiality
Your parent company has legitimate oversight duties, needing to ensure you're identifying and reporting suspicious activity. But the Bank Secrecy Act prohibits disclosing a SAR except to law enforcement, regulatory agencies, or FinCEN.
The Financial Crimes Enforcement Network allows securities broker-dealers and commodity brokers to share SARs with parent entities, both domestic and foreign, under strict conditions. You're still barred from notifying anyone involved in the suspicious activity that you've filed a report. If your parent company is outside the U.S., you face additional risks under foreign law.
The stakes are high: If your parent company mishandles a SAR, you're liable. Without proper controls, you're operating outside regulatory guidance.
Preparing for Implementation
Documentation:
- Corporate structure chart showing all parent entities
- List of parents needing SAR access
- Legal opinion on disclosure obligations in each jurisdiction
Technical Infrastructure:
- Secure file transfer system with access logging
- Document classification system for SAR-related files
- Audit trail capability for all SAR disclosures
Stakeholder Alignment:
- Sign-off from your Chief Compliance Officer
- Legal review of your FinCEN guidance interpretation
- Agreement from parent company compliance leadership on confidentiality obligations
Regulatory Foundation:
- Written AML program addressing SAR procedures
- Documented and tested SAR filing process
- Understanding of which parent companies fall under "corporate group" definition
You don't need new software, but you do need a way to track access.
Step-by-Step Implementation
Step 1: Draft the Confidentiality Agreement
Your confidentiality agreement must ensure the parent company protects SAR confidentiality with compliance controls. Include:
- Prohibition on further disclosure of the SAR
- Prohibition on disclosing the fact a SAR was filed
- Permission to disclose underlying information that doesn't reveal a SAR exists
- Acknowledgment that the recipient may not notify anyone involved in the suspicious activity
- Requirement to apply access controls limiting SAR visibility to compliance personnel
- Obligation to maintain audit logs of SAR access
- Immediate notification if the parent receives a legal demand for SAR disclosure
For foreign parent companies, add a clause addressing foreign law disclosure requests. The parent may need to resist such requests or notify you immediately.
Step 2: Establish Technical Controls
Create a separate channel for SAR sharing:
- Set up a secure folder or portal accessible only to designated compliance officers
- Implement MFA for all access
- Configure automatic logging to capture user identity, timestamp, and document accessed
- Apply watermarking or document tracking to SAR files
- Restrict download and print capabilities if possible
Don't rely on email, even if encrypted. You need persistent access controls and an audit trail.
Step 3: Define What You'll Share
Decide your approach to sharing SARs:
- Conservative: Share only underlying facts without the actual SAR filing
- Moderate: Share redacted versions of internal SAR documentation, marked as "not the filed SAR"
- Permissive: Share complete SAR filings under strict confidentiality agreement
Document your decision and rationale. If you choose a permissive approach, ensure your confidentiality agreement addresses SAR document protection.
Step 4: Implement the Sharing Process
Create a standard operating procedure:
- File SAR with FinCEN following your normal process
- Compliance officer determines if parent company notification is required
- Officer uploads SAR or underlying information to secure portal
- Automated notification sent to designated parent company recipients
- Access logged automatically
- Quarterly review of access logs to verify authorized access
Your procedure should specify turnaround time. If the parent company needs near-real-time visibility, define "without delay" as 24-48 hours after filing.
Step 5: Train Both Sides
Your team needs to understand:
- What triggers parent company notification
- How to use the secure sharing system
- What information can be discussed verbally versus what must remain in writing
Parent company recipients need training on:
- Confidentiality obligations under the agreement
- Prohibition on notifying subjects of SARs
- Handling disclosure requests from local regulators
- Escalation path for legal demands
Don't assume compliance teams automatically understand U.S. SAR confidentiality rules.
Validation: Ensuring It Works
Test Technical Controls:
- Attempt unauthorized access to SAR repository (should fail)
- Verify audit logs capture all required fields
- Confirm watermarking or tracking on downloaded documents
- Test MFA enforcement
Review a Sample Transaction:
- File a test SAR (or use a recent real filing)
- Walk through your sharing procedure
- Verify parent company received notification
- Check access logs for authorized access
- Confirm no unauthorized disclosure
Audit the Confidentiality Agreement:
- Have outside counsel review against current FinCEN guidance
- For foreign parents, verify the agreement addresses jurisdiction-specific risks
- Confirm appropriate signature authority
Quarterly Spot Checks:
- Pull access logs to verify authorized access
- Interview parent company users to confirm understanding of confidentiality obligations
- Review any disclosure requests or legal demands
If unauthorized access occurs, treat it as a breach and determine if FinCEN notification is required.
Maintenance and Ongoing Tasks
Monthly:
- Review access logs for anomalies
- Verify all users still require access (remove departed employees)
- Check technical controls remain functional
Quarterly:
- Update corporate structure chart if ownership changes
- Reassess which parent entities require SAR access
- Review and update confidentiality agreements if regulatory guidance changes
Annually:
- Refresh training for your team and parent company recipients
- Audit compliance with confidentiality agreement terms
- Evaluate whether your sharing approach remains appropriate
When Regulatory Guidance Changes:
- Monitor FinCEN, SEC, and CFTC releases for updates to SAR sharing policy
- Assess impact on confidentiality agreements
- Update procedures and retrain as needed
The regulatory landscape around SAR sharing is evolving, especially as cross-border financial structures grow more complex. Your framework must protect confidentiality today while adapting to future FinCEN guidance on affiliate sharing or foreign parent disclosure obligations.



