Feature Compliance Strategy
FinCEN Extended 314(b) to Fraud: The Safe Harbor Most Financial Institutions Are Still Ignoring
On June 12, 2026, FinCEN updated its Section 314(b) Fact Sheet to explicitly cover fraud — including pig butchering, romance scams, and mule account activity. Institutions can now share transaction records, device data, IP addresses, and video footage in real time with other registered participants. Here's what changed, what you can and can't share, and why most compliance teams are leaving this tool unused.
Table of Contents
Here’s a fraud network scenario that plays out hundreds of times a year: a pig butchering victim sends a series of wire transfers to what they believe is a crypto investment account. Your institution processes the outgoing wires. Another institution receives the inbound funds and converts them to crypto through what appears to be a legitimate customer account. A third institution sees unusual incoming wires from multiple first-time senders.
Each institution has a piece of the picture. None of them knows the others have it. The network disperses the funds across four more accounts before compliance at any one institution completes a SAR. The money is gone before the intelligence reaches law enforcement.
That’s the problem Section 314(b) was built to solve — and until June 12, 2026, it was mostly being used as an AML-only tool while fraud schemes adapted to exploit the gap.
On June 12, 2026, FinCEN released an updated Section 314(b) Fact Sheet that explicitly extends the safe harbor to fraud. The guidance isn’t a new program — 314(b) has existed since 2001. But the clarification matters because it removes the legal uncertainty that has kept compliance teams from using 314(b) as a fraud-fighting tool, and it adds operational guidance on real-time sharing that changes what the program can actually accomplish.
TL;DR
- FinCEN’s June 12, 2026 Section 314(b) Fact Sheet explicitly extends the voluntary information-sharing safe harbor to fraud — including pig butchering, romance scams, and mule account activity
- Registered institutions can now share transaction records, IP addresses, video surveillance, device data, and adverse media in real time — verbally or electronically
- You cannot share a SAR or reveal one exists; you can share all the underlying facts it’s based on
- FDIC and OCC both issued guidance encouraging institutions to register that haven’t already done so
- Most compliance teams have treated 314(b) as an AML program — the June 2026 update turns it into a fraud intelligence network for institutions willing to use it
What Section 314(b) Actually Is
Section 314(b) of the USA PATRIOT Act, codified at 31 CFR 1010.540, creates a voluntary information-sharing mechanism between financial institutions to jointly identify and report money laundering and terrorist financing activity.
The core mechanism is simple: registered financial institutions can share information about individuals, entities, and transactions suspected of involving illicit activity — and the sharing is protected by a federal safe harbor from liability under state and federal privacy laws, including GLBA Regulation P.
Before the June 2026 update, the statute and FinCEN’s guidance technically covered “money laundering and terrorist financing” without explicitly addressing fraud. The legal question was whether fraud-derived proceeds fell within the program’s scope. In practice, many compliance teams treated 314(b) as an AML tool and reached for Section 314(a) — the mandatory information-sharing channel with law enforcement — or state fraud coalitions for fraud-specific intelligence sharing.
The June 2026 update closes that ambiguity. FinCEN’s Fact Sheet states plainly that the safe harbor extends to “suspected fraud” and gives specific examples: pig butchering scams, romance scams, and mule account activity. The guidance notes that a financial institution “need only suspect that activity may involve a fraud-related Specified Unlawful Activity” to share under the safe harbor — a lower bar than many compliance teams had assumed.
What Changed — and What Didn’t
The June 2026 guidance introduces meaningful operational changes alongside the fraud extension. Understanding both matters.
What’s new:
| Area | Previous Guidance | June 2026 Update |
|---|---|---|
| Fraud coverage | Ambiguous — technically AML-focused | Explicit: fraud is covered, including pig butchering, romance scams, mule accounts |
| Real-time sharing | Permitted but not emphasized | Explicitly encouraged; “including in real time” language added throughout |
| Shareable data types | Transaction records, account information | Expanded to: video surveillance footage, IP addresses, device data, cyber-related data, adverse media |
| Sharing format | Not specified clearly | Can be verbal, written, or electronic |
| Recipient-transaction link | Required in prior interpretations | Not required: information need not relate to a transaction of the receiving institution |
What didn’t change:
- Registration is still required and still voluntary — institutions must register with FinCEN to participate
- The SAR wall remains: you cannot share a SAR or reveal that one has been filed
- The safe harbor does not extend to information shared in bad faith or outside program requirements
- Participating institutions are still bound by their own data handling and security obligations for 314(b) information received
The SAR Wall — and What It Doesn’t Protect
This distinction trips up compliance teams more than any other part of the program.
You cannot share a Suspicious Activity Report. You cannot tell another institution that you have filed a SAR. This is a hard statutory rule under 31 U.S.C. § 5318(g)(2), and it applies even in 314(b) sharing.
But the underlying facts that went into the SAR? Those are not protected.
If your transaction monitoring identified that account 7890 sent seventeen wires to seven different receiving institutions in forty-eight hours, each just below $10,000, and your blockchain analytics team traced the destination addresses to a known pig butchering network — you can share all of that. The transaction dates, amounts, routing, account characteristics, device fingerprints, IP addresses used during session activity, and the network attribution. You can share it in real time, electronically, with any institution registered in the 314(b) program.
You just can’t say “we also filed a SAR.”
The practical result is that the SAR wall, while real, protects less than it might appear. The analytical intelligence your team develops in the course of suspicious activity review — the substance of what makes the activity suspicious — is shareable. The formal designation of that conclusion is not.
The Fraud Types This Is Actually Built For
FinCEN’s June 2026 Fact Sheet names three fraud types because they’re exactly the scenarios where information fragmentation lets criminals move faster than compliance can respond.
Pig butchering / investment fraud: Victims are groomed over weeks or months before being convinced to send funds to fraudulent crypto investment platforms. The outgoing wires look like ordinary customer transfers at the originating institution. The receiving accounts — often mule accounts — look like ordinary customer activity. Only by sharing intelligence across institutions do the patterns emerge. By the time any one institution identifies the scheme, the funds have moved across four or five institutions to a crypto off-ramp.
Romance scams: Structurally similar to pig butchering, but often using established relationship patterns as the social engineering vector. The FBI’s 2024 Internet Crime Report documented $2.9 billion in romance scam losses — predominantly elderly victims, predominantly wire and crypto transfers. The victim’s financial institution sees a customer sending a series of wires to someone they’ve never met; real-time intelligence from the receiving institution about the destination account’s activity profile could trigger intervention before the transfer completes.
Mule account activity: Money mule networks use recruited or unknowing individuals to receive and forward criminal proceeds. Spotting a mule account requires seeing patterns across institutions — a series of small inbound wires from multiple sources, followed by immediate outbound transfers, is classic mule activity that’s nearly invisible from a single institution’s transaction view. Sharing in real time about suspicious high-velocity activity in receiving accounts lets originating institutions catch transfers before they clear.
The common thread: these schemes exploit the fact that each institution sees only its slice of the transaction chain, and traditional SAR filings reach law enforcement after the money moves. Real-time 314(b) sharing intercepts the transfer.
How to Actually Use It
If your institution isn’t registered in the 314(b) program, registration is the first step and it costs nothing. Both the OCC (Bulletin 2026-30) and FDIC (FIL-2026) have issued guidance explicitly encouraging institutions to register.
Once registered, here’s what an operational 314(b) fraud workflow looks like:
Step 1: Trigger identification. Your transaction monitoring or fraud detection system identifies activity that may involve fraud — unusual outgoing wire patterns, rapid fund forwarding, mule account indicators. This does not require a full SAR determination; suspicion is sufficient.
Step 2: Determine whether 314(b) sharing would add intelligence. The relevant question is: would another institution’s knowledge about the destination account, the counterparties, or related accounts help you assess or stop the activity? For most fraud schemes involving multiple financial institutions, the answer is yes.
Step 3: Identify receiving institutions. Check whether destination financial institutions are registered 314(b) participants. FinCEN maintains the participant database.
Step 4: Share — in real time if the situation warrants it. The June 2026 guidance is explicit that real-time verbal or electronic sharing is permitted. For an active transfer, a phone call to the receiving institution’s BSA team about a wire that just left your institution is a legitimate use of 314(b).
Step 5: Document the sharing and the response. Keep records of what you shared, when, with whom, and what (if any) information you received in return. This creates the audit trail for your BSA/AML program and supports any subsequent SAR filing.
What 314(b) Participation Looks Like in an Examiner Review
The OCC and FDIC have both issued guidance encouraging 314(b) participation — which means examiners are aware of whether your institution is registered and whether the program is being used.
The examiner question isn’t just “are you registered?” It’s “show me your 314(b) activity log.” An institution registered since 2015 with zero 314(b) sharing events signals that the program exists on paper but isn’t integrated into actual fraud response or AML operations.
Registration plus zero use is not the goal. The goal is registration plus an operational workflow that routes appropriate fraud intelligence through the 314(b) channel — documented, trained, and tested in your BSA/AML program.
For your AML/fraud program’s key risk indicators, 314(b) participation metrics are worth tracking: how many sharing events per quarter, what information types, how many inbound requests processed, and whether real-time sharing has been operationalized for high-velocity fraud scenarios. The KRI Library’s BSA/AML-specific indicators include transaction monitoring alert rates and SAR filing volumes — 314(b) usage rounds out the fraud response picture.
So What?
The June 2026 update to Section 314(b) doesn’t create new legal powers — it removes an ambiguity that had kept compliance teams from using existing powers for fraud. The practical change is significant: financial institutions now have an unambiguous, liability-protected channel to share fraud intelligence in real time, with any other registered institution, across every format including video and device data.
The fraud schemes that FinCEN explicitly calls out — pig butchering, romance scams, mule accounts — are also the schemes your fraud team is losing to right now. They move faster than SAR filings reach law enforcement. Real-time 314(b) sharing is the mechanism that can match the speed.
If your institution isn’t registered, registration takes a form submission. If your institution is registered but 314(b) is treated as an AML-only checkbox, the June 2026 guidance is your reason to rebuild that workflow. If your institution already has an active 314(b) program, the fraud extension and real-time guidance expand the scope of what you can share — which means updating your sharing procedures, training, and documentation to reflect what’s now explicitly permitted.
The tool is there. The question is whether your compliance program is set up to use it.
Internal Resources
- BSA/AML Independent Testing Program: Building a Program That Passes the FFIEC Exam
- SAR Template: Narrative Writing, Filing Triggers, and Common Mistakes
- What the OCC’s CFSB Consent Order Says About BSA/AML Risk in Fintech Payment Partnerships
External Sources
- FinCEN Section 314(b) Fact Sheet, June 12, 2026 — FinCEN
- FinCEN Issues Guidance to Help Financial Institutions Eliminate Fraud Through Information Sharing — U.S. Treasury
- FinCEN Expands Section 314(b) Information-Sharing Guidance to Incorporate Fraud — Morrison Foerster (June 2026)
- FinCEN Updates § 314(b) Fact Sheet, Clarifying Scope of Information Sharing Safe Harbor — Troutman Pepper (June 2026)
- OCC Notification: FinCEN Guidance on Voluntary Information Sharing, Bulletin 2026-30 — OCC
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did FinCEN's June 2026 update to Section 314(b) actually change?
What types of fraud does the updated 314(b) guidance cover?
What information can a financial institution share under 314(b)?
What can't you share under 314(b)?
How do you register to participate in the 314(b) program?
Is there liability protection for information shared under 314(b)?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026