ARTICLE
6 December 2016

US Financial Crimes Enforcement Network Issues Advisory And Frequently Asked Questions On Reporting Cyber-Events In Suspicious Activity Reports

SS
Shearman & Sterling LLP

Contributor

Our success is built on our clients’ success. We have a long and distinguished history of supporting our clients wherever they do business, from major financial centers to emerging and growth markets. We represent many of the world’s leading corporations and major financial institutions, as well as emerging growth companies, governments and state-owned enterprises, often working on ground-breaking, precedent-setting matters. With a deep understanding of our clients' businesses and the industries they operate in, our work is driven by their need for outstanding legal and commercial advice.
On October 25, 2016, FinCEN issued an Advisory and related Frequently Asked Questions (FAQs) regarding the reporting of cyber-events, cyber-enabled crime and cyber-related information through SARs.
United States Finance and Banking
To print this article, all you need is to be registered or login on Mondaq.com.

On October 25, 2016, FinCEN issued an Advisory and related Frequently Asked Questions (FAQs) regarding the reporting of cyber-events, cyber-enabled crime and cyber-related information through Suspicious Activity Reports (SARs).

According to FinCEN, while suspicious transactions may not always involve a cyber-event, relevant cyber-related information should still be included in SARs when available (e.g., Internet Protocol (IP) addresses and accompanying timestamps associated with fraudulent wire transfers being reported). Similarly, the FinCEN guidance provides that when suspicious transactions do involve cyber-events, a financial institution should include in SARs all relevant and available information regarding the suspicious transactions and the cyber-event - including the type, magnitude and methodology of the cyber-event as well as signatures and facts on a network or system that indicate a cyber-event. The advisory also encourages collaboration between in- house BSA/AML and cybersecurity units and sharing information with other financial institutions to the extent permitted under Section 314(b) of the USA PATRIOT Act.

Among other things, the FAQs explain the circumstances in which an SAR must be filed in connection with an unsuccessful cyber-event and provide for the submission of a single, cumulative SAR to report multiple cyber-events that are similar in nature and share common identifiers or are believed to be related, connected or part of a larger scheme.

The advisory and FAQs are available at: https://www.fincen.gov/sites/default/files/advisory/2016-10-25/Cyber%20Threats%20Advisory%20-%20FINAL%20508_2.pdf

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More