Key Insights
- FinCEN’s updated Section 314(b) guidance clarifies that participating financial institutions may share information about suspected fraud when the activity may involve possible money laundering or terrorist activity, including fraud that may constitute a specified unlawful activity.
- Real-time Section 314(b) information sharing can give institutions a better chance to identify related activity and limit additional losses.
- The value of Section 314(b) depends on preparation: confirmed participation, connected fraud and BSA/AML teams, and designated rapid-response contacts.
In nature, camouflage can be a matter of survival. Predators use it to approach prey without being detected, while prey use it to avoid being seen — and eaten. Payments fraudsters are using a digital version of that strategy, deploying AI-generated deepfakes and manipulated identity documents to make deceptive transactions and account activity look legitimate.
In a late-2025 survey of more than 400 financial institution risk professionals, Federal Reserve Financial Services found that faster payments had the largest increase in attempted fraud and losses among payment categories compared with the prior year. As fraudsters become more convincing and payments are moving faster, institutions cannot always rely on their own singular view. Recognizing the disguise and sharing what has been uncovered could be helpful to other financial institutions in their efforts to protect their customers.
Now financial institutions (FIs) may voluntarily share certain information about suspected fraud under the USA PATRIOT Act’s Section 314(b) safe harbor, provided they meet the program’s conditions.
In a late-2025 survey of more than 400 financial institution risk professionals, Federal Reserve Financial Services found that faster payments had the largest increase in attempted fraud and losses among payment categories compared with the prior year. As fraudsters become more convincing and payments are moving faster, institutions cannot always rely on their own singular view. Recognizing the disguise and sharing what has been uncovered could be helpful to other financial institutions in their efforts to protect their customers.
Now financial institutions (FIs) may voluntarily share certain information about suspected fraud under the USA PATRIOT Act’s Section 314(b) safe harbor, provided they meet the program’s conditions.
FinCEN Updated Guidance on PATRIOT Act
The US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) in June issued updated guidance to clarify how financial institutions can share information with each other about suspected fraud under section 314(b) of the USA PATRIOT Act.
FinCEN’s updated guidance clarifies that a financial institution may share information about activity involving suspected fraud, money laundering, terrorist financing, or other specified unlawful activities, and that it may share that information with another registered Section 314(b) participant to identify illicit financial activity.
Examples of information FIs may share, when the Section 314(b) conditions are met, include video surveillance footage, cyber-related data, such as IP addresses, and fraud indicators like newly added payees followed by large transfers, multiple accounts with the same or similar identifying information, and login activity from geographically distant places.
“One of the main clarifications is that FinCEN says an institution need not identify specific fraud proceeds being laundered before using the Section 314(b) safe harbor,” says Matt Wallace, PCBB’s chief information officer. “A reasonable suspicion of a covered fraud offense can support information sharing, provided the other 314(b) requirements are met. That will be new information for many banks that have read 314(b) narrowly.”
“FedNow and RTP funds can move in seconds. A 314(b) call three days later may be too late to stop the initial payment, though it can still help institutions identify connected activity and limit additional losses,” Wallace says. “A call within the hour can give the receiving institution a better chance to assess the activity, evaluate available response options under applicable law and payment-network rules, and identify related accounts or transactions before additional loss occurs.”
What CFIs Should Consider with Updated FinCEN Guidance
FinCEN’s updated Section 314(b) guidance gives community financial institutions (CFIs) a clearer path to share fraud-related information with registered Section 314(b) participants, but the value of that authority will depend on preparation before a suspected event occurs. From an operational-risk perspective, effective Section 314(b) information sharing requires more than identifying suspicious activity and contacting a participating institution. CFIs should establish documented governance that defines who may share information, what may be shared, how the exchange will occur, and how decisions and resulting actions will be recorded.
CFI executive leadership and managers will want to consider the following steps to make real-time information sharing more practical, controlled, and useful.
- Confirm participation before sharing. Verify that your institution’s Section 314(b) participation is current, and establish a documented process for confirming that another institution is a current Section 314(b) participant before an information exchange.
- Define the permitted purpose. Document the circumstances in which Section 314(b) sharing is appropriate, including the suspected fraud or other illicit activity at issue and the authorized purpose of the exchange.
- Connect fraud, BSA/AML and control functions. Fraud personnel may be the first to detect suspicious activity, while BSA/AML personnel often manage the formal Section 314(b) process. Include legal, privacy, information-security and operations teams in procedure design, particularly when a correspondent network, fraud consortium, platform provider or other third party is involved.
- Set clear approvals and escalation paths. Identify decision rights, required approvals and escalation procedures for potential Section 314(b) outreach — including events that require urgent action outside normal business hours.
- Designate rapid-response contacts. Maintain current contacts at participating peer institutions and establish after-hours communication and response protocols for faster-payment events.
- Use approved, secure communication channels. Establish repeatable, secure methods for transmitting and receiving information while protecting customer data, investigative details and other sensitive information.
- Train staff on applicable fraud indicators. Use the examples in FinCEN’s guidance — including IP addresses, device and login information, video surveillance and fraud patterns — to help staff recognize when outreach to another participating institution may be appropriate.
- Retain evidence of the exchange and response. Keep a record of information sent or received, the recipients, the suspected activity involved, related investigative or account actions, and any resulting suspicious activity report decisioning. Do not share a SAR or information that would reveal whether one has been filed.
“From a risk perspective, this is an opportunity to share information faster and more effectively — not a reason to share customer information without controls,” says Radhika Lipton, PCBB’s chief risk and compliance officer. “Institutions still need appropriate safeguards, documented processes, and a clear understanding of what information is relevant to the suspected activity.”
FinCEN’s clarification gives CFIs another tool for responding to fraud that is increasingly sophisticated, fast-moving, and difficult for any one institution to see in full. By establishing the right participation, escalation and information-sharing processes before an incident occurs, institutions can help turn timely intelligence into a stronger line of defense for their customers and the broader payments system.