If your business is a financial institution or a creditor that maintains covered accounts, the FTC’s Red Flags Rule requires you to have a written identity theft prevention program that identifies warning signs of identity theft, tells your staff how to spot and respond to them, and is approved and overseen by your board or a senior manager. The rule sits at 16 CFR § 681.1 and came out of the Fair and Accurate Credit Transactions Act. It is not a policy statement you draft once and file away; the document has to be specific enough for an employee to follow, and it has to be updated as your accounts and fraud risks change.
Does the Rule Apply to Your Business
Two questions decide whether you need a program at all: are you a financial institution or a creditor, and do you maintain covered accounts.
Financial institutions are banks, credit unions, and savings associations. Creditors, under 15 U.S.C. § 1681m(e)(4), are entities that regularly and in the ordinary course of business use consumer reports in connection with a credit transaction, furnish information to consumer reporting agencies, or advance funds based on an obligation to repay.1Office of the Law Revision Counsel. 15 USC 1681m – Requirements on Users of Consumer Reports That definition reaches well beyond traditional lenders. Auto dealers that finance purchases, mortgage brokers, utility companies that bill after service, and cell phone carriers extending monthly credit generally qualify. If you let customers pay over time and either check credit or report to a bureau, assume you are covered until you confirm otherwise.
One narrow carve-out: the Red Flag Program Clarification Act of 2010 excluded businesses that advance funds on a customer’s behalf only for expenses incidental to a service they already provide, which is why most doctors and lawyers who bill after rendering services fall outside the rule.2GovInfo. Red Flag Program Clarification Act of 2010
What Counts as a Covered Account
A covered account comes in two forms. The first is any account maintained primarily for personal, family, or household purposes that involves or is designed to permit multiple payments or transactions. Credit cards, mortgages, auto loans, cell phone accounts, utility accounts, checking, and savings all fit.3eCFR. 16 CFR 681.1 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft
The second is broader and catches accounts the first category misses: any account where there is a reasonably foreseeable risk of identity theft to the customer or to the organization’s own safety and soundness, whether the risk is financial, operational, reputational, or litigation-related.3eCFR. 16 CFR 681.1 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft So a checklist match is not enough. You have to look at every account type you offer and ask whether it could realistically be exploited using stolen identity information.
The Four Things Your Written Program Must Do
The regulation requires a written document covering four areas: identifying red flags relevant to your business, detecting them in day-to-day operations, responding when they appear, and keeping the program current.4eCFR. 16 CFR Part 681 – Identity Theft Rules Generic language will not carry the weight. The document has to give a front-line employee enough operational detail to act.
Red Flags to Build Into the Program
Appendix A to Part 681 organizes red flags into five categories. Your program should draw from each category that fits your business rather than copying the appendix wholesale.5eCFR. Appendix A to Part 681 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation
- Alerts from consumer reporting agencies or fraud detection services, such as a fraud alert or credit freeze on a consumer report, a notice of address discrepancy, or a pattern of activity flagged by a detection service.
- Suspicious documents: identification that looks altered or forged, a photo ID where the photo does not match the person, or an application that appears falsified.
- Suspicious personal identifying information, including an address that does not match the credit report, a Social Security number associated with someone else, or information the applicant provides that conflicts with what you already have on file.
- Unusual account activity, such as a dormant account that suddenly shows transactions, a sharp departure from a customer’s spending pattern, or mail returned as undeliverable on an otherwise active account.
- External notices, including a customer’s report that they did not open a particular account, a law enforcement notification about identity theft involving your accounts, or a complaint from a victim whose information was used at your organization.
Once you have identified the red flags, describe how staff will actually spot them. For new accounts, that typically means verifying name, address, and identification number, and for in-person interactions, checking a current government-issued ID.6Federal Trade Commission. Fighting Identity Theft with the Red Flags Rule – A How-To Guide for Business For existing accounts, detection should include confirming the identity of anyone requesting changes, monitoring transaction patterns, and verifying change-of-address requests before redirecting sensitive correspondence. A company that opens accounts entirely online faces different verification challenges than a brick-and-mortar lender; the written program should say how yours actually works.
How Employees Should Respond
The program has to tell employees what to do when a red flag appears, and the response has to be proportionate to the risk. The interagency guidelines list options that range from monitoring to shutting the account down:
- Monitor the account more closely for further signs of fraud.
- Contact the customer directly to verify recent activity.
- Change passwords, security codes, or other access credentials.
- Reopen the account under a new number.
- Decline to open a new account.
- Close an existing account.
- Notify law enforcement.
Financial institutions subject to Suspicious Activity Report requirements may also need to file a SAR with FinCEN when the facts warrant it.4eCFR. 16 CFR Part 681 – Identity Theft Rules A minor address inconsistency might call for a verification phone call; a forged ID paired with a fraud alert on the credit report calls for declining the transaction and contacting authorities.
Board Approval, Training, and Service Providers
The initial written program must be approved by the organization’s board of directors or an appropriate committee of the board. After that, the board, a committee, or a designated senior manager has to stay involved in overseeing, developing, and implementing the program.3eCFR. 16 CFR 681.1 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft Handing the whole thing to a compliance officer without any board-level engagement will not satisfy the rule. Smaller organizations trip on this often.
Whoever runs the program should report at least annually to the board or the designated senior manager. That report should cover how effective the program has been, how service providers are performing, any significant identity theft incidents and the response, and recommendations for changes.6Federal Trade Commission. Fighting Identity Theft with the Red Flags Rule – A How-To Guide for Business
Staff need training “as necessary” to implement the program.6Federal Trade Commission. Fighting Identity Theft with the Red Flags Rule – A How-To Guide for Business The FTC uses that flexible phrase deliberately. An employee who opens accounts all day needs thorough instruction on identity verification; a back-office worker with no customer contact may need only a general overview. Train people when they are hired into relevant roles, refresh as tactics change, and document each session so you have an audit trail.
When you hire a third party to handle work tied to covered accounts, you stay responsible for making sure their activities line up with reasonable identity theft policies. The usual approach is contract language requiring the provider to maintain its own red flag procedures and either report detected red flags back to you or take appropriate preventive steps directly.4eCFR. 16 CFR Part 681 – Identity Theft Rules Outsourcing the function does not outsource the obligation.
Keeping the Program Current
The rule requires periodic updates. Events that should trigger a fresh review include changes in the account types you offer, shifts in how customers interact with you (moving to online account opening, for example), mergers or acquisitions, new service provider relationships, and emerging fraud methods you learn about through industry channels or your own experience.6Federal Trade Commission. Fighting Identity Theft with the Red Flags Rule – A How-To Guide for Business The annual report to the board is a natural checkpoint. When it flags gaps or new risks, revise the program and document the reasoning behind each change.
What Noncompliance Costs
The FTC enforces the rule against creditors under its jurisdiction; federal banking regulators enforce it against the financial institutions they supervise. Civil penalties are adjusted annually for inflation. As of the January 2025 adjustment, the maximum civil penalty for a knowing violation of the Fair Credit Reporting Act is $4,983 per violation, and the maximum penalty for a knowing violation of an FTC rule on unfair or deceptive practices is $53,088 per violation.7Federal Register. Adjustments to Civil Penalty Amounts Those figures are per violation, so systemic failures across many accounts can produce substantial aggregate exposure. The FTC can also seek injunctive relief that forces the organization to build a compliant program and submit to monitoring.