Section 314(b) Information Sharing Explained: How It Works and How to Register

In financial crime compliance, sometimes you spot activity that looks like laundering or fraud. The problem is, the full picture sits inside another institution's systems, and there's no clean way to compare notes without worrying about a privacy lawsuit. Section 314(b) exists to solve exactly that problem.

Section 314(b) is a provision of the USA PATRIOT Act. It passed in 2001. The provision lets financial institutions share information with one another about activity they suspect may involve money laundering or terrorist financing. The heart of the approach is a safe harbor. As long as an institution follows the rules, it's protected from liability for sharing information. This approach removes the legal fear that used to keep compliance teams quiet.

The program is administered by FinCEN, the Financial Crimes Enforcement Network, a bureau of the U.S. Treasury. Participation is voluntary, but FinCEN strongly encourages financial institutions to join. The reason is that bad actors move across multiple institutions to evade detection. When institutions can talk to each other, those gaps close.

There's a timely reason this matters right now. On June 12, 2026, FinCEN released an updated 314(b) fact sheet that broadened the scope of information sharing to explicitly include suspected fraud offenses. It also confirmed that institutions can share in real time, as activity is occurring. That guidance replaced the older December 2020 version and reflects a wider Treasury push to fight fraud and scams.

This guide covers what 314(b) actually allows, how the sharing works day to day, and the exact steps to register through FinCEN's portal.

The following topics are going to be covered in this article;

  • What Is Section 314(b)?
  • Section 314(a) vs Section 314(b): What's the Difference?
  • What Can Be Shared Under 314(b)? The June 2026 Update
  • Who Can Participate and How to Register
  • The Safe Harbor: Legal Protection for Information Sharing
  • Practical Use Cases: How 314(b) Sharing Works in Investigations
  • Common Challenges and How to Overcome Them

Mceclip2 11

1. What Is Section 314(b)?

Section 314(b) of the USA PATRIOT Act is a voluntary program that lets US financial institutions share information with one another to identify and report activity that may involve money laundering, terrorist financing, fraud, or other specified unlawful activities. Institutions that register and follow the rules receive a legal safe harbor that protects them from liability for sharing that information.

That safe harbor is the whole point. Before 314(b), a bank that wanted to warn a peer about a suspicious customer faced real exposure under privacy laws. The safe harbor removes that risk, as long as the institution shares for a permitted purpose and keeps the information secure. It covers liability under both federal and state law.

It helps to separate 314(b) from its sibling, Section 314(a), since people mix them up constantly. Both come from Section 314 of the PATRIOT Act, but they run in opposite directions:

  • 314(a) is mandatory and points to the government. FinCEN, acting for law enforcement, sends institutions a list of suspects, and the institution must search its records and report any matches back to FinCEN. These requests go out roughly once every two weeks.
  • 314(b) is voluntary and points to other institutions. Firms share information directly with each other, on their own initiative, to spot activity that no single institution could see alone.

The quick mental model: 314(a) is law enforcement asking the industry a question; 314(b) is the industry comparing notes among itself.

Five things define how 314(b) works:

  • Voluntary: Participation is optional. No institution has to register. It's a tool, not an obligation.
  • Institution to institution: Sharing runs between institutions, or through an association of them, and can include a group of participating institutions. It doesn't run between an institution and the government.
  • Protected: The safe harbor shields registered participants from liability for sharing in good faith under the program.
  • Registered: Only institutions registered with FinCEN can share, and each side must take reasonable steps to verify the other is a registrant before exchanging anything.
  • Updated: On June 12, 2026, FinCEN issued a new fact sheet that broadened the practical scope of sharing. It confirmed that fraud information is covered and that institutions can share in real time.

That last point is why 314(b) is drawing fresh attention. The core statute hasn't changed since 2001, but FinCEN's 2026 guidance removed two long-standing points of uncertainty, making clear the safe harbor reaches further than many compliance teams had assumed, especially for fast-moving fraud and scam activity.

2. Section 314(a) vs Section 314(b): What's the Difference?

The two provisions sit side by side in Section 314 of the PATRIOT Act. This can make them get confused, but they solve different problems and run in opposite directions. The simplest way to hold them apart is; 314(a) is the government reaching into the industry, and 314(b) is the industry reaching across to itself. Under 314(a), FinCEN takes requests from law enforcement, packages named subjects into a confidential list, and pushes it to institutions. The institution has to search its records and report any matches back to FinCEN. It's a one-way pull of information toward investigators, and responding is not optional.

Under 314(b), there's no government request at all. A registered institution decides on its own to share information with a peer, usually because it has spotted something suspicious and wants to know whether the other side sees the same pattern. Nobody is compelled to do anything.

Here's the side-by-side comparison table:

Dimension

Section 314(a)

Section 314(b)

Nature

Mandatory

Voluntary

Direction

FinCEN / law enforcement → FIs (requests)

FI ↔ FI (direct sharing, including group sharing)

Purpose

Law enforcement investigating specific subjects

FIs collaborating to identify suspicious activity

Initiator

FinCEN (on behalf of law enforcement)

Any registered FI

Response required

Yes, generally within 14 days

No (voluntary participation)

Legal protection

Confidentiality(obligation) of the request

Safe harbor from liability for sharing

Registration

Automatic (all BSA-covered FIs receive requests)

Must register with FinCEN through the FI Portal

Scope

Specific subjects named in the request

Broader: any suspected ML / TF / fraud activity

SAR disclosure

Cannot share SAR information

Cannot share SAR information (same restriction)

Table 1: Section 314(a) vs. Section 314(b) Comparison

A few of these differences matter more than the rest in day-to-day compliance work. The response obligation is the big one. A 314(a) request carries a deadline, generally 14 days to search for and report matches. 314(b) carries no deadline, because there's nothing you're required to answer. You share when it helps you. Registration is the other practical split. Every BSA-covered institution is already wired into the 314(a) system and will receive requests. 314(b) is opt-in. You don't get the safe harbor until you register through FinCEN's FI Portal and confirm your counterpart is registered too. One thing they share is not letting you disclose a SAR or reveal that one exists. That restriction holds across both provisions, with no exceptions.

The takeaway is that these are complementary, not competing. 314(a) is the government asking you to check your records against known targets. 314(b) is you asking a peer whether they see the same suspicious activity that you do. One feeds law enforcement's active investigations; the other helps institutions build a fuller picture before they ever file a report. Used together, they close gaps that either one alone would leave open.

Mceclip0 23

3. What Can Be Shared Under 314(b)? The June 2026 Update

The June 12, 2026 fact sheet is the reason this section exists. It didn't change the underlying law, and FinCEN was clear that the guidance does not represent a change in existing rules or laws. What it did was settle several questions that had kept compliance teams cautious for years, and the practical effect is a noticeably wider lane for sharing.

Before the update, most institutions read 314(b) narrowly. You could share information tied to identifying or reporting possible money laundering or terrorist financing and little beyond that. The 2026 guidance opened it up in three concrete ways:

  • Fraud is now squarely in scope. FinCEN spelled out that fraud offenses are specified unlawful activities (SUAs) for money laundering offenses and therefore subject to the information-sharing safe harbor. That covers mail fraud, wire fraud, bank fraud, securities fraud, and fraud connected to unauthorized access of a protected computer, among others, under 18 U.S.C. Crucially, institutions do not need to identify specific proceeds of fraud being laundered to trigger the protection. A reasonable suspicion of fraud is enough on its own. Morrison Foerster flagged this as a "notable departure" from FinCEN's September 5, 2025, guidance on cross-border information sharing, which appeared to strictly limit sharing to money laundering and terrorist financing threats.
  • You don't need a nexus to the receiving institution. A registered financial institution may share information with another registered institution even if the sharing entity has no reason to believe the information relates to any specific customer, account, or transaction of the receiving institution. In plain terms, Bank A can tell Bank B, "We're seeing a money mule ring using accounts that match these patterns," without knowing whether Bank B actually holds any of those accounts. That matters for spotting networks no single institution can see as a whole.
  • The receiving institution can use it broadly. The information isn't just for chasing one named person. A receiving institution can use it to strengthen its overall AML program, feed the intelligence into its transaction monitoring system, or meet its broader BSA obligations. The goal is better detection across the board, not a single lookup.

The fact sheet also confirmed there's no restriction on the types of information or the method of sharing, with SARs as the one exception. Institutions can share transaction data, video footage, IP addresses and geolocations, device IDs, account decisions, and monitoring alerts, and they can do it in writing, verbally, or electronically, in real time as activity is happening. FinCEN even listed sample fraud indicators worth sharing. These are newly added payees followed by large transfers, multiple accounts with the same or similar identifying information, and login activity from geographically distant locations.

What you still cannot share are SARs. This is the most common misunderstanding, so it's worth stating plainly. 314(b) does not override SAR confidentiality. You cannot share the existence of a SAR, the fact that you filed one, or its contents, even with a trusted 314(b) partner. What you can share is the underlying activity that led you to file. "We observed this suspicious pattern involving this customer" is fine. "We filed a SAR on this customer" is not. Institutions weighing a joint SAR may discuss it among themselves, but the wall around the SAR itself stays up.

4. Who Can Participate and How to Register

Eligibility comes down to one test. Is your institution subject to an anti-money laundering program requirement under FinCEN's regulations? If yes, you and any association of institutions like yours can take part. FinCEN's current list of eligible categories:

  • Banks (under the BSA, the definition also covers credit unions, savings associations, and trust companies).
  • Money services businesses, including money transmitters and, where covered, crypto exchanges.
  • Brokers or dealers in securities
  • Mutual funds
  • Insurance companies with BSA obligations
  • Casinos and card clubs
  • Futures commission merchants and introducing brokers in commodities
  • Dealers in precious metals, stones, or jewels
  • Operators of credit card systems
  • Loan or finance companies
  • Housing government-sponsored enterprises
  • Associations made up of the institutions mentioned above.

One thing that trips people up: Registered investment advisers are not eligible yet. FinCEN finalized an AML rule for advisers in 2024, but the effective date has been pushed to January 1, 2028. Until then, advisers aren't subject to an AML program requirement, so plan for 2028, not now.

How to register

The process runs through FinCEN's Financial Institution (FI) Portal, which replaced the older SISS system in May 2024.

  1. Request FI Portal access. Go to FinCEN's Financial Institutions resource page and select "FI Access Request." This step needs FinCEN approval before you can move on, so build in some lead time.
  2. Submit your 314(b) registration. Once access is approved, log in at fiportal.fincen.gov, open the 314(b) tile, and submit. Registrations are processed automatically, and you can generate an acknowledgment letter for your records.
  3. Designate a point of contact. You need at least one, and you can list more than one. Keep it current, since a stale contact means missed sharing requests.
  4. Verify before you share. Before exchanging anything, confirm your counterpart is also a registrant. The FI Portal has a searchable directory of participants for exactly this purpose.
  5. Renew every year. Registration is effective for one year and must be renewed annually. A lapsed registration means you lose the safe harbor until you renew, so put it on a tickler.

Cost and reality check

Registration is free. The friction is operational, not financial: Written policies, confidentiality safeguards, and the annual renewal.

Participation is lighter than you'd expect. Roughly 7,200 institutions are registered as of mid-2026.

Mceclip3 10

The safe harbor is what makes 314(b) usable. Without it, the program would sit unused, because no compliance officer would volunteer their institution for a lawsuit. With it, sharing becomes a protected act rather than a legal gamble.

Here is the protection explained in simple terms. When an institution shares information under 314(b), it's shielded from liability for the act of sharing, and that shield is broad. It reaches claims under federal law, state law, and even private contracts.

So a bank that flags a suspicious customer to a peer generally can't be sued for:

  • Breaching that customer's privacy
  • Violating a confidentiality clause in an account agreement
  • Defaming someone whose activity turned out to be innocent

The suspicion doesn't have to pan out. As long as the institution shared the information in good faith for a permitted purpose, the protection holds.

The legal basis sits in Section 314(b) of the USA PATRIOT Act, carried out through FinCEN's regulation at 31 C.F.R. § 1010.540, with the safe harbor itself in subsection (b)(5).

What do you have to do to earn it?

The protection isn't automatic. You qualify only if you meet every condition:

  • Register with FinCEN as a 314(b) participant.
  • Share only with other registered participants, and take reasonable steps to verify the other side is registered before you exchange anything.
  • Share for a permitted purpose: Identifying or reporting activity that may involve money laundering, terrorist financing, fraud, or another specified unlawful activity.
  • Ensure that the information is subject to appropriate security and confidentiality measures.
  • Use what you receive only for legitimate purposes: Your AML/CFT activities, deciding whether to open or continue an account relationship, or meeting BSA requirements.

If you miss any one of these requirements, the shared information will no longer be protected by the safe harbor.

Where does the protection stop?

The safe harbor is wide but not unlimited. It does not cover:

  • SAR content. You still cannot share a SAR or reveal that one exists. That's governed by a separate rule, the SAR confidentiality provision at 31 U.S.C. § 5318(g), which 314(b) does not override.
  • Sharing with unregistered institutions. No registration on the other end means no protection, full stop.
  • Off-purpose use. Using shared information for anything outside the permitted purpose for which it was shared breaks the safe harbor. These can be marketing or credit decisions unrelated to AML, etc.
  • Bad faith or reckless sharing. The protection assumes a reasonable basis for suspicion and good-faith conduct. It isn't a license to spread damaging information carelessly.

The practical takeaway is that the safe harbor rewards discipline. Register, verify your counterparts, document your purpose, lock down the data, and stay within the permitted uses. Neglecting any of these steps jeopardizes the very foundation of safe sharing.

Mceclip1 19

6. Practical Use Cases: How 314(b) Sharing Works in Investigations

The value of 314(b) shows up when a single institution can only see part of a crime. Criminals count on that fragmentation. These four scenarios show how sharing turns partial views into a full one:

Money mule networks: Bank A spots an account that takes in rapid deposits from several sources and pushes the money straight back out, a classic mule pattern. It asks its 314(b) partners whether they see similar flows tied to the same originating accounts. Bank B answers that three of its accounts are feeding Bank A's suspected mule while also receiving from a fourth institution. Now both banks see a network, not a single account. They file SARs that hand law enforcement the whole structure. Neither could have mapped that alone, because each held only one node of it.

Fraud rings: An insurer notices a cluster of suspicious claims. It asks partner banks whether the claimants' accounts are receiving payouts from multiple insurance companies. The banks confirm the same accounts are collecting from several insurers at once. That cross-industry view exposes an organized ring that no single insurer's claims data would reveal, since each insurer sees only its own payouts.

Pig butchering and investment scams: Bank A watches an elderly customer send escalating transfers to an account at crypto exchange B and suspects a romance-investment scam, but it loses sight of the money once it leaves. Using 314(b), Bank A contacts Exchange B about the receiving account. Exchange B confirms the funds are converted to crypto and swept to an external wallet within hours. Both file SARs, and the speed matters because the money often disappears within a day. Bank A had the victim; Exchange B had the destination. Only by working together did Bank A and Exchange B fully understand the scam.

Business email compromise: A company's bank flags a last-minute change to the payment details for a major vendor. It contacts the vendor's bank under 314(b) to ask whether the vendor actually changed its banking information. The vendor’s bank confirms nothing changed from their side. The new instruction was fraudulent, and the payment is blocked before it goes out. Here, 314(b) worked in real time to stop a loss, not just to report one. The paying bank couldn't verify the change alone, because the truth lived at the vendor's bank.

The thread through all four is the same. Each institution starts with an origin, a destination, one victim, and one leg of a transfer. The crime only becomes visible when the pieces sit side by side, and 314(b) is the legal channel that lets that happen without either institution risking a lawsuit. The June 2026 guidance made these cases easier still, confirming that fraud and scam information is covered and that institutions can compare notes in real time.

7. Common Challenges and How to Overcome Them

For all its value, 314(b) is underused, and it's worth being honest about why. The obstacles are real, but each has a practical answer.

Low participation: Only about 7,200 institutions are registered, roughly 12% of those eligible, and the gaps are lopsided. Banks, credit unions, and broker-dealers sign up at rates above 40%, while money services businesses sit near 2%. Institutions stay out because they don't see the benefit, they still fear liability despite the safe harbor, or they have no internal process for handling information a peer sends them. The fixes are straightforward. The safe harbor genuinely removes the liability worry when you follow the rules; the benefit is better detection that examiners increasingly expect, and the intake process can run on the AML case management tools you already own.

Selective sharing: Even among participants, sharing is uneven. Larger banks tend to trade information freely with each other but hesitate with smaller institutions or non-bank firms, especially on fraud. That instinct is now outdated. The June 2026 fact sheet put fraud squarely inside the safe harbor, and FinCEN encourages broad participation regardless of an institution's size or type. Money services businesses, which sit closest to much of the fraud and mule activity, are exactly the partners the network needs.

SAR confusion: Plenty of BSA officers avoid 314(b) because they're unsure where the SAR disclosure line falls. The rule is simpler than it feels. You can share the underlying facts, but you cannot share the SAR or its existence. "We observed these suspicious transfers to this entity" is fine. " We filed a SAR on this entity" is not. Train your team on that one distinction, and most of the hesitation goes away.

No guaranteed response: Because the program is voluntary, a request may go unanswered, and no institution is obligated to reply. The workaround is relationships. BSA officers who know their counterparts receive answers faster, and industry groups like ACAMS chapters and ABA regional meetings are where those contacts form. A named person who trusts you beats a cold query every time.

Cross-border limits: The 314(b) safe harbor typically doesn't apply to sharing with non-US institutions, unless the foreign institution itself is subject to a FinCEN AML program requirement. FinCEN partially closed this gap in September 2025 with guidance FIN-2025-G001, which clarified that the BSA doesn't prohibit sharing the underlying facts, transactions, and documents behind a SAR with foreign counterparts. One important caveat is that the guidance covers sharing outside the safe harbor. It doesn't expand 314(b) itself, so cross-border sharing carries less legal protection than a domestic exchange and deserves closer legal review.

The pattern across all five is the same. The barriers are mostly about knowledge, habit, and process, not law. The framework already supports far more sharing than the industry currently does.

Mceclip4 7

Sources

[1] Financial Crimes Enforcement Network. Section 314(b) Fact Sheet. 2026.

[2] eCFR, U.S. Code of Federal Regulations. 31 CFR 1010.540: Voluntary Information Sharing Among Financial Institutions. 2026.

[3] Financial Crimes Enforcement Network. FinCEN Issues Final Rule to Postpone Effective Date of Investment Adviser Rule to 2028. 2025.

[4] Financial Crimes Enforcement Network. FIN-2025-G001: Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality. 2025.

[5] Morrison Foerster. FinCEN Expands Section 314(b) Information-Sharing Guidance to Incorporate Fraud. 2026.



FAQ's Blog Post

Registered investment advisers are not yet eligible, because eligibility depends on being subject to a FinCEN AML program requirement. FinCEN finalized an AML rule for advisers in 2024, but the effective date now sits at January 1, 2028. Plan for then rather than now.

The Section 314(b) safe harbor shields registered institutions from liability for the act of sharing, reaching claims under federal law, state law, and private contracts. The suspicion does not have to turn out to be correct. Protection holds as long as sharing was in good faith for a permitted purpose.

The Section 314(b) safe harbor generally does not extend to non-US institutions, unless the foreign institution is itself subject to a FinCEN AML program requirement. Cross-border sharing may be permissible under other authorities, but it carries less protection and warrants legal review before you rely on it.

Section 314(b) registration is effective for one year and must be renewed annually. A lapsed registration means the safe harbor no longer covers what you share, which makes it a recurring audit finding. Putting the renewal date on a tickler is the simplest fix.

Section 314(b) registration runs through FinCEN's Financial Institution (FI) Portal. Request portal access and wait for FinCEN approval, then log in, open the 314(b) tile, and submit. Designate at least one point of contact, and verify a counterpart is registered before sharing anything. Registration is free.

Eligibility turns on one test: Is your institution subject to an AML program requirement under FinCEN's regulations? That covers banks, credit unions, money services businesses, broker-dealers, mutual funds, casinos, insurance companies with BSA obligations, and several other categories, plus associations made up of them.

Section 314(b) covers fraud. FinCEN's June 2026 fact sheet confirmed that fraud offenses are specified unlawful activities for money laundering purposes, so suspected fraud sits inside the safe harbor. An institution does not need to identify specific fraud proceeds being laundered; suspicion of fraud alone is enough.

Section 314(b) does not override SAR confidentiality. You cannot share a SAR, its contents, or the fact that one exists, even with a trusted 314(b) partner. What you can share is the underlying activity that led to the filing. That distinction is the most common point of confusion.

Section 314(a) is mandatory and points to the government: FinCEN sends institutions a list of law enforcement subjects, and they must search records and report matches. Section 314(b) is voluntary and points sideways: Institutions share information directly with each other, on their own initiative.

Section 314(b) is a voluntary program under the USA PATRIOT Act that lets registered US financial institutions share information with one another about activity they suspect involves money laundering, terrorist financing, or fraud. Institutions that follow the rules receive a safe harbor protecting them from liability for sharing.

Judi Tero

Judi Tero

Senior Content Writer

View full profile →