3.4.6 SEC/FTC Red Flags Rule
As we know, the FACT Act directed the FTC to develop an identity theft rule for certain financial institutions. The Dodd-Frank Act in 2010 directed the securities industry to develop its own rules on identity theft. As a result, the SEC and CFTC launched a joint identity theft red flags rule, known as Regulation S-ID. Regulation S-ID requires member firms that offer covered accounts to develop and implement a written identity theft prevention program to guide the opening and execution of those accounts. The program must create procedures to identify red flags and incorporate them into the firm’s daily activities. Entities must respond “appropriately” when red flags are detected to prevent identity theft. The board of directors or a designated senior level employee must approve the program, administer it, and train staff to implement it. The firm must update the program “periodically” to reflect changes in customer and institutional identity theft risks. Staff should report to the board of directors or its designated employee at least annually on compliance.
The program must include relevant red flags from the four categories listed below. The rule also provides illustrative examples of red flags for these categories, such as the following.
Alerts Received from Consumer Reporting Agencies or Service Providers |
|
Presentation of Suspicious Documents or Persona |