FinCEN Clarifies What You Cannot Tell a Customer (09/03/2026)

September 3, 2026
FinCEN Clarifies What You Cannot Tell a Customer (09/03/2026)
Key Intel / TL;DR
  • Five federal agencies issued joint clarification on what a bank may and may not say to a customer about a suspicious activity report.
  • The NBA found the Los Angeles Clippers arranged sham endorsement deals to route additional money to a star player in violation of league rules.
  • Managed Care of North America agreed to a multi-million dollar settlement resolving class action litigation over its 2023 breach.
  • New Jersey extended its ban on intentionally added PFAS to apparel and diaper products, signed August 27.
  • Broadcast licensees have until September 24 to pay FY 2026 regulatory fees before a 25% late penalty applies.

Today’s items split between obligations with a date attached and what happens when a control existed on paper and nobody enforced it. The Clippers report in particular is worth reading even if you have no interest in basketball, because the mechanism it describes is one any privately held company can run without anybody noticing for years.

Top 5 Critical Compliance Alerts

1. Five Agencies Clarify What a Bank Can Say About a SAR

On September 2, the Office of the Comptroller of the Currency, the Federal Reserve, the Federal Deposit Insurance Corporation, the Financial Crimes Enforcement Network, and the National Credit Union Administration jointly clarified the confidentiality rules governing what an institution may tell a customer about a suspicious activity report (SAR). Front line staff routinely field the question of why an account was frozen or closed, and the line between a lawful answer and unlawful disclosure has been drawn from folklore in a lot of branches. Written guidance turns a training problem into a documentable one. JD Supra has the analysis.

Operator Note: Pull the actual script your tellers and service reps use for account closure questions, because that script is your compliance position whether or not anybody in the compliance function has read it.

2. The NBA Finds the Clippers Ran Sham Endorsement Deals

The National Basketball Association found that the Los Angeles Clippers and owner Steve Ballmer arranged sham endorsement deals to route additional money to one of the team’s star players in violation of league rules. The published account describes governance failures rather than a single bad transaction, which is the shape this always takes when a control environment has been quietly optional for a long time. Sham vendor contracts are not a sports problem and they show up in any organization where one person can approve a payment and describe what it was for. Radical Compliance covers the findings, and Corporate Compliance Insights walks the governance failures.

Operator Note: The control here is separation between whoever selects a vendor and whoever confirms the service was delivered, and it costs nothing except the discomfort of telling an executive no.

3. MCNA Settles 2023 Breach Litigation for Millions

Managed Care of North America (MCNA) agreed to a multi-million dollar settlement resolving class action litigation stemming from its 2023 cybersecurity incident. The gap between the incident and the settlement is roughly three years, which is the number worth carrying into your own risk modeling, because the legal exposure from a breach stays open long after the technical response has closed. Set your reserves against that three year window and not against the cost of the technical response. HIPAA Journal has the settlement detail.

4. New Jersey Extends Its PFAS Ban to Apparel and Diapers

Governor Mikie Sherrill signed legislation on August 27 broadening New Jersey’s restrictions on intentionally added per- and polyfluoroalkyl substances (PFAS) to cover apparel and diaper products, continuing a nationwide trend. Product compliance obligations of this kind land on procurement and supplier documentation long before they land on legal, since proving a substance was not intentionally added means having a supplier attestation you did not previously collect. Start with the supplier list, because that is where the evidence has to come from. JD Supra has the scope.

5. Broadcast Regulatory Fees Are Due September 24

Radio and television licensees must pay their annual FY 2026 regulatory fees to the Federal Communications Commission by September 24, and payments received after that date carry a 25% late penalty. A quarter of the fee is an expensive calendar failure, and it is the kind that happens when the person who used to own the filing has left. Confirm who owns this filing before anybody goes looking for the amount due. JD Supra has the requirements.

Additional Compliance Alerts

Regulatory Updates

  • EDGAR Next annual confirmations are coming due: Filers moved onto the Securities and Exchange Commission (SEC) EDGAR Next platform now face an annual confirmation obligation to keep account access current, which is a small task that locks you out of filing if it slips. JD Supra
  • The SEC Investor Advisory Committee meets September 10 on AI in public markets: The public meeting at SEC headquarters will address artificial intelligence technologies in the public markets and the Commission’s response. SEC

Policy and Governance Updates

  • When failing to disclose misappropriation becomes securities fraud: An analysis of the charges against two Pacific Private Money Group executives works through the point at which an ordinary investment scheme gone bad turns into a disclosure violation. Compliance Building

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)