← All posts
How-to Guides

What can you tell a customer after filing a SAR? A wording guide for UK and EU firms

August 31, 2026 · 9 min read

In late 2023, a senior partner at a small London law firm was convicted of tipping off. Investigators had made covert enquiries about a client who had bought an GBP 8 million property. The solicitor called the client the same day. Over the following five months he met the client to discuss it, including a flight to the client’s home in Malta. He was sentenced to nine months, suspended, with 100 hours of unpaid work and GBP 5,000 towards prosecution costs. He appealed. The Court of Appeal refused him permission.

That case is unusual because it went to trial. What should concern a compliance function sits elsewhere in the appeal ruling, in a single line: seemingly routine communications with customers or clients can create criminal liability. In most regulated firms, tipping-off exposure accumulates somewhere far more ordinary than a flight to Malta. It accumulates in a support agent, on a Tuesday, trying to give a helpful answer about a delayed payment.

What the prohibition actually covers

Three points about the legal test are routinely misunderstood inside firms, and each one widens the exposure considerably.

You do not have to mention a report. Under section 333A of the Proceeds of Crime Act 2002, the offence in the regulated sector covers disclosing that a report has been made, and separately disclosing that a money laundering investigation is being considered or carried out. In the EU, Article 39 of Directive (EU) 2015/849 prohibits obliged entities, their directors and their employees from disclosing to the customer or to third parties that information has been transmitted, or that an analysis is being or may be carried out.

Prejudice does not have to happen. Prosecutors do not need to show that an investigation was actually damaged. The statutory test is whether the disclosure is likely to prejudice it. The Court of Appeal took the view that telling the subject of a covert investigation that enquiries are being made is inherently likely to prejudice it, through the plain risk of evidence being destroyed or the subject taking evasive steps.

Intent is irrelevant. There is no requirement to show that the person meant to help a criminal. The revelation is the offence. This is the single most important point for anyone designing controls, because it means the typical profile of the person who commits the offence is a conscientious employee answering a question as helpfully as they can.

One more change is worth putting in the diary now. From 10 July 2027, Regulation (EU) 2024/1624 replaces the directive with a single directly applicable rulebook, and Article 73 restates the prohibition in wider terms. It covers disclosing the fact that transactions or activities are being or have been assessed, under Article 69. The categories of person bound are unchanged. What is new is the covered fact: the directive attaches the prohibition to the transmission of a report and to an analysis being carried out, and the Regulation adds the assessment itself, which happens before any report exists. The prohibition currently bites at the point of reporting. Under the Regulation it bites at the point of assessment, which is earlier and far more often in view of customer-facing staff.

The four moments where the sentence gets written

In practice, almost all of the exposure sits in four routine interactions. Each one puts an employee under pressure to explain something they are not permitted to explain.

  1. The delay question. A payment or withdrawal is held. The customer asks why. The employee wants to sound competent and specific.
  2. The exit conversation. The relationship is being ended. The customer asks for a reason, often repeatedly, and often in writing.
  3. The document request. The firm asks for source of funds or source of wealth evidence. The customer asks what prompted it.
  4. The escalation reply. A complaint has been raised, and the employee explains internally where the matter now sits.

A wording table for the four moments

The table below is editorial analysis of the statutory test applied to ordinary phrasing. It is not a legal opinion and it is not software output. Firms should calibrate it with their MLRO and their own legal advice.

Moment Creates exposure Lower risk Why the difference matters
Delay “It is with our financial crime team.” / “We are waiting on compliance to release it.” “The payment is going through a standard internal review. I do not have a completion time I can commit to yet.” Naming the function identifies the nature of the review. The customer does not need to hear the word report to draw the inference.
Exit “We cannot continue the relationship following a review of your account activity.” “We have decided to end the relationship. We do not provide reasons for commercial decisions of this kind.” Linking the exit to a review of activity supplies the causal link. A generic formula, applied to every exit, does not.
Documents “We need this because your transaction was flagged.” “We are required to keep customer records current and periodically request supporting documentation.” The second framing is true, routine, and consistent with what the firm asks other customers. The first attributes the request to a specific trigger.
Escalation “I have escalated this to our MLRO.” / “Once something has been reported we cannot discuss it.” “Your complaint has been escalated internally. I will update you when I have information I can share.” The second example in the exposure column is a direct disclosure. The first is an indirect one, and the case law is clear that allowing the customer to infer is enough.

The consistency trap

There is a second-order problem that wording guidance alone does not solve. If a firm gives clear, specific reasons to every exiting customer except the ones subject to a report, then the refusal itself becomes the signal. The absence of an explanation carries information. This is why the safer formulations above are written as standing policy language rather than as something an employee reaches for only in sensitive cases. A phrase that is only used when there is something to hide eventually announces that there is something to hide.

The full wording pack. The table above covers one formulation per moment. We have written the complete version as a ten-page pack: four moments, twenty-two wording pairs each with the reasoning behind it, a page of the constructions that disclose by inference, and a printable desk card an agent can hold during a call. It is free and it goes to your inbox as a PDF. Get the SAR-safe wording pack.

Why training and scripts leave a gap

Every published guide on this subject arrives at the same three recommendations: train staff annually, write a policy, and give customer-facing teams pre-approved scripts. All three are necessary. None of them operate at the moment the risk is created.

Annual training is a point-in-time event. The sentence is written eleven months later, by an agent with a queue, in a free-text box, under pressure to be helpful. Scripts cover the scenarios someone anticipated, and the difficult messages are the ones that fall between scenarios: the customer who has asked three times, the escalation that has become personal, the second-line colleague summarising the position in an internal thread that is later disclosed. We have written before about why compliance training fades between the classroom and the keyboard.

The other standard control is review after the fact. Archiving and supervision platforms will surface the message, and they should. The limitation is structural: by the time a supervisory alert fires, the sentence has been read by the person it was least safe to send it to. The disclosure is complete. What remains is remediation and, on the Court of Appeal’s reasoning, the prejudice is already likely. This is the same pattern we set out in why post-send review keeps failing, and it appears in a different regulatory dress in the words that trigger a securities problem.

Where a pre-send check fits

The gap between the policy and the keyboard is narrow and specific, and it can be closed by moving the check to the moment of writing. A pre-send check reads the draft while the employee is composing it, in Outlook or Gmail, and raises the risk before the message is sent rather than after. It is a front-end shield for accidental human risk, the careless line a well-intentioned person does not notice, and it sits in front of archiving and supervision rather than replacing them. Fewer messages reach the supervisory queue because fewer are sent.

The second benefit matters more to the MLRO than to the agent. Each check produces a timestamped record that the control operated on a specific message at a specific moment. Policy documents and training registers show that a control exists. Evidence that it ran on the message in question is a different category of proof, and it is the category a supervisor or an auditor asks for. That is the audit trail side of the same control, and it is why we treat tipping-off wording as a control design problem rather than a training problem.

The takeaway

Write the four formulations above into standing customer communication policy, not into a sensitive-cases annex, and use them for every customer in that situation. Consistency is the control. The wording only protects the firm if the customer subject to a report receives exactly the same sentence as everyone else, and the only reliable way to achieve that is to check the sentence at the point it is written.

If you want the standing policy language ready to take to your MLRO, the SAR-safe wording pack sets out all four moments in full, with the reasoning for each line so you can apply it to wording we did not anticipate. It is free and it arrives as a PDF.

For the wider picture, our Benchmark Report 2025 takes verbatim communication from cases that were actually lost and shows what a pre-send check would have caught.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← The Cost of One Sentence: What a Dozen Real Cases Reveal About Communication Risk ISO 27002 A.5.14: what an auditor actually accepts as evidence →