TL;DR: FinCEN 314(b) information sharing lets financial institutions share information with each other about suspected money laundering or terrorist activity under a statutory safe harbor. On June 12, 2026 FinCEN replaced its December 2020 fact sheet, permitting real-time sharing, confirming that fraud is squarely in scope, and removing the requirement that shared information relate to any specific customer of the receiving institution. Participation still sits at roughly 6,100 institutions out of a BSA filer population above 324,000.
What 314(b) Actually Permits

Section 314(b) of the USA PATRIOT Act, implemented at 31 CFR 1010.540, allows a financial institution to share information with another financial institution for the purpose of identifying and, where appropriate, reporting on activities that may involve money laundering or terrorist activity. Institutions that meet the conditions receive protection from liability for the sharing itself and for failing to notify the person identified in it.
The safe harbor is conditional, not automatic. Four things have to be true: the institution has filed notice of intent to share with FinCEN, it has verified that the counterparty has also filed notice, the sharing is for a permissible purpose, and it maintains adequate procedures to protect the confidentiality of the information.
The permissible purposes are a closed list — identifying and reporting on money laundering or terrorist activity, deciding whether to establish or maintain an account or engage in a transaction, and assisting with compliance with any Chapter X requirement. Using information obtained through 314(b) for credit decisions, marketing, or litigation falls outside the safe harbor entirely.
Eligibility covers institutions subject to an AML program requirement under FinCEN regulations, plus associations of such institutions. That includes banks and credit unions, money services businesses, broker-dealers, mutual funds, casinos, insurance companies, futures commission merchants, dealers in precious metals, credit card system operators, loan and finance companies, and housing GSEs. A crypto firm qualifies if it is a registered money services business with an AML program obligation.
What Changed in June 2026

The June 12, 2026 fact sheet expands upon and replaces the December 2020 version. Any policy or training material still written against the 2020 document is now out of date in three specific ways.
Sharing can happen in real time, as activity is occurring. The 2020 guidance never prohibited this, but it also never blessed it, and the ambiguity was enough to keep most institutions in a request-and-wait email workflow.
Fraud is explicitly covered. The new fact sheet devotes a dedicated question to it and confirms that fraud offenses are specified unlawful activities for money laundering purposes, listing mail fraud, wire fraud, bank fraud, health care fraud, securities fraud, and fraud connected to unauthorized computer access. Critically, the institution need not have identified specific proceeds of fraud being laundered. For anyone working fraud and AML convergence, this removes a long-standing objection.
And the sharing no longer has to touch the receiving institution's book. An institution may share information "even if the entity sharing the information has no reason to believe the information relates to any specific customer, account, or transaction of the financial institution receiving the information." The receiving institution may feed it directly into its transaction monitoring system.
That third change is the one with architectural consequences. It converts 314(b) from a case-by-case inquiry mechanism into a channel for typology and indicator distribution — shared red flags, device identifiers, wallet addresses, and behavioral patterns that a receiving institution can operationalize as detection logic rather than as a single lookup.
The Misconceptions That Keep Institutions Out
Most of the reasons compliance teams give for not participating are not accurate, and FinCEN has addressed each of them directly.
Two things are genuinely constrained, and both are frequently overstated in the other direction. You cannot share a SAR or reveal its existence — 314(b) does not relax SAR confidentiality, though the underlying transaction and customer information is fair game, and institutions filing a joint SAR may discuss it freely among themselves. And sharing with a foreign affiliate reaches the safe harbor only if that institution is itself required under Chapter X to maintain an AML program. Otherwise the sharing may still be permissible for the enumerated purposes, but without safe harbor protection, and the Right to Financial Privacy Act, GLBA, state law, and foreign law all still apply.
314(a) Is a Different Program
These get conflated constantly, and the operational difference matters.
The absence of any response obligation under 314(b) is the program's central design weakness, and it is the source of most practitioner frustration with it.
Enrollment and the Renewal Trap
Enrollment runs through the Financial Industry Portal. Request access by selecting the FI Access Request option on FinCEN's financial institutions resource page, then log in, open the 314(b) tile, and submit the registration. Registrations are processed automatically, and participants can generate an acknowledgment letter for their records. At least one point of contact is required, more can be designated, and other employees may participate under the institution's own policies.
Then there is a discrepancy worth flagging to whoever owns this at your institution. 31 CFR 1010.540(b)(2) states that each notice "shall be effective for the one year period beginning on the date of the notice," and that an institution must submit a new notice to continue sharing. The June 2026 fact sheet's participation section contains no discussion of renewal, expiry, or annual cadence at all.
The regulation is the binding authority, so the operational answer is unchanged: renew annually or lose the safe harbor. But an institution reading only the new fact sheet could let its registration lapse without realizing it — and a lapsed registration means the verification condition fails for every exchange afterward.
This may already be happening. FinCEN reported over 6,100 registered participants in fiscal year 2024, down from 7,790 the prior year. Some of that drop likely reflects the migration to the FI Portal and lapsed renewals rather than deliberate withdrawal, but FinCEN has not explained it.
Why Adoption Stays Low
Roughly 6,100 registered institutions against a FinCEN filer population above 324,000 puts participation under 2 percent of BSA filers. Even measured against eligible institutions, one widely cited practitioner analysis put the rate around 12 percent, ranging from about 2 percent of money services businesses to over 40 percent of banks, credit unions, and broker-dealers.
In fiscal year 2024, 48,223 SARs referenced 314(b) in the narrative, filed by 1,693 institutions — against 4.7 million SARs in total, or roughly one percent.
Four reasons account for most of the gap. Most U.S. financial institutions are small and already stretched by mandatory obligations, so a voluntary program loses the resourcing argument. Unanswered requests train institutions to stop asking, which is a self-reinforcing failure. The process is manual, which caps volume at whatever an analyst can do by email.
And there is a regulatory asymmetry that nobody advertises: examiners have historically been reluctant to criticize an institution for not participating in a voluntary program, but can criticize a participating institution for any failure in how it participates. That calculus has started to shift. The FDIC issued FIL-34-2026 in July 2026 affirmatively encouraging supervised banks to participate as a means to share information, mitigate losses, and increase suspicious activity detection. A prudential regulator putting that in writing changes what non-participation looks like on exam.
What a Good Request Contains
There is no FinCEN form and no FinCEN routing. Working from what the regulation requires and what the 2026 guidance permits, a defensible request identifies the requesting institution and confirms its current registration, provides enough subject identifiers to avoid false matches, states that the request is made under 314(b) for a permissible purpose, describes the suspected activity type without asserting or implying that a SAR exists, specifies what is being sought, and gives a response deadline tied to the requester's own filing clock.
The shareable set under the current guidance is considerably wider than most policies contemplate: transaction data, video surveillance footage, IP addresses and geolocation, device identifiers, account opening and closure decisions along with the analysis behind them, transaction monitoring alerts, and named behavioral indicators such as newly added payees followed by large transfers, multiple accounts sharing identifiers, and logins from geographically distant locations.
On recordkeeping, the regulation imposes no explicit 314(b) requirement but does require adequate confidentiality procedures — and it deems that requirement satisfied if the institution applies the procedures it already maintains under GLBA Section 501 for customer nonpublic personal information. Most institutions can inherit that control rather than build it. What you do need to be able to evidence on exam is a current registration, the pre-sharing verification for each counterparty, the permissible purpose, and the use limitation.
FinCEN also encourages noting 314(b) reliance in the SAR narrative, which is both how it measures the program and why the 48,223 figure almost certainly understates real usage. Institutions working on SAR narrative quality should be building that reference into their template.
Where Sphinx Fits
The 2026 guidance removed the legal ambiguity that was the stated reason for not participating, and simultaneously authorized exactly the kind of continuous, alert-level, machine-speed sharing that a manual email workflow cannot deliver. The constraint has moved from whether an institution is allowed to do this to whether it can operationally do it at volume.
That is squarely an operations problem. Verifying counterparty registration before each exchange, assembling a request with the right identifiers, chasing non-responsive counterparties, and documenting the permissible purpose and use limitation for examination are all retrieval and record-keeping tasks that scale badly with headcount. Sphinx's agents run inside the systems where that evidence already lives and document the reasoning behind each step, which is what an examiner asks for when the question is whether the safe harbor conditions were actually met.
Deciding whether a suspicion is worth raising with a counterparty, and what to do with what comes back, stays with the compliance team. That has not changed and should not.
Frequently Asked Questions
Do we have to file a SAR before using 314(b)?
No. Nothing in 31 CFR 1010.540 conditions sharing on a prior SAR filing, and receiving a 314(b) request does not obligate the recipient to file one. Information obtained through 314(b) can be used to decide whether a filing is warranted at all — including reaching the conclusion that it is not.
Can 314(b) be used for fraud, or only money laundering?
Fraud is covered. FinCEN's June 2026 fact sheet addresses this directly, confirming that fraud offenses are specified unlawful activities for money laundering purposes, including mail fraud, wire fraud, bank fraud, health care fraud, securities fraud, and fraud involving unauthorized computer access. The institution does not need to have identified specific proceeds of fraud being laundered.
How often does 314(b) registration need to be renewed?
Annually. 31 CFR 1010.540(b)(2) states that each notice is effective for the one-year period beginning on the date of the notice, and a new notice must be submitted to continue sharing. Worth noting: the June 2026 fact sheet does not mention renewal at all, so an institution relying solely on that document could let its registration lapse — which would void the safe harbor for every subsequent exchange.
Can we share with a foreign affiliate under 314(b)?
Only if that institution is itself required under 31 CFR Chapter X to maintain an AML program. Otherwise, information may still be shared with a foreign affiliate for the permissible purposes, but the exchange does not receive safe harbor protection. The Right to Financial Privacy Act, GLBA, state privacy law, and applicable foreign law all continue to apply, and FinCEN has explicitly placed those outside the scope of its guidance rather than resolving them.
What is the difference between 314(a) and 314(b)?
314(a) is a government-to-institution request under 31 CFR 1010.520. Participation is mandatory when a request is received, the institution must search records and report matches within 14 days, and it cannot disclose that FinCEN made the request. 314(b) is voluntary institution-to-institution sharing under 31 CFR 1010.540, triggered by the institution's own suspicion, with no obligation on the recipient to respond at all.

.png)