Regulation S-ID requirements obligate SEC-registered broker-dealers, investment companies, and investment advisers that offer “covered accounts” to build and maintain a written Identity Theft Prevention Program. The program has to identify relevant red flags, detect them, respond appropriately, and get updated as risks change, all under board or senior-management oversight. The rule sits at 17 CFR Part 248, Subpart C, and traces back to the Fair and Accurate Credit Transactions Act of 2003, with rulemaking authority moved to the SEC by the Dodd-Frank Act in 2010.1Securities and Exchange Commission. Identity Theft Red Flags Rules Firms that skip the work pay for it: in 2022 the SEC fined JPMorgan $1.2 million, UBS $925,000, and TradeStation $425,000 for program deficiencies.2Securities and Exchange Commission. SEC Charges JPMorgan, UBS, and TradeStation for Deficiencies
Which Firms Are In Scope
Regulation S-ID reaches SEC-regulated entities that meet the Fair Credit Reporting Act’s definitions of “financial institution” or “creditor.” Three categories of registrants fall within the rule:3eCFR. 17 CFR 248.201 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft
- Broker-dealers registered or required to register under the Securities Exchange Act of 1934, particularly firms offering margin or custodial accounts.
- Registered investment companies, business development companies, and employees’ securities companies under the Investment Company Act of 1940, especially those that allow wire transfers or check-writing privileges.
- Investment advisers registered or required to register under the Investment Advisers Act of 1940, particularly those that can direct transfers or payments from individual accounts to third parties.
The FCRA labels trip firms up. A brokerage that lets customers defer payment for services, or an adviser that can direct third-party payments on a client’s behalf, can qualify as a creditor even though it looks nothing like a traditional lender. SEC examiners found firms that never even asked whether they met those definitions, which itself constituted a violation.4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
Which Accounts Are Covered
The program obligation only kicks in for “covered accounts,” which fall into two categories:3eCFR. 17 CFR 248.201 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft
- Accounts maintained primarily for personal, family, or household purposes that involve or permit multiple payments or transactions. A retail brokerage account, or a mutual fund account that permits wire transfers, sits squarely here.
- Any other account where there is a reasonably foreseeable risk to customers or to the firm from identity theft, including financial, operational, compliance, reputation, or litigation risks. This category can pull in business and institutional accounts when the risk profile warrants.
You cannot decide this once and shelve it. The rule requires periodic reassessment that considers the methods available to open accounts, the methods available to access them, and the firm’s own history with identity theft.3eCFR. 17 CFR 248.201 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft Examiners have cited firms that failed to reassess after launching online customer portals, adding new account types, or completing mergers.4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
The Four Program Elements
If any of your accounts are covered, you need a written Identity Theft Prevention Program tailored to your size, complexity, and the nature of your activities. It must contain four elements.3eCFR. 17 CFR 248.201 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft
Identify Relevant Red Flags
The program has to pinpoint which red flags actually apply to your covered accounts and put them in written policies. This is where the most common failures happen. Firms copy the illustrative examples out of the regulation’s appendix without asking whether those flags fit their business, listing physical-appearance red flags for an entirely online operation, for instance, or including consumer-report alerts when the firm never pulls consumer reports.4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
Detect Red Flags
You need procedures that actually catch the flags you have identified, both when new accounts are opened and during ongoing account activity. Opening detection means verifying the identity of the person opening the account. Ongoing detection means monitoring transactions, authenticating customers, and verifying change-of-address requests.5Legal Information Institute. 17 CFR Appendix A to Subpart C of Part 248 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation Existing anti-money-laundering procedures do not satisfy this. The SEC has rejected that argument on the ground that AML procedures are built to catch different things.4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
Respond Appropriately
When a red flag surfaces, the response has to be proportionate to the risk. The interagency guidelines list options ranging from increased monitoring, contacting the customer, changing credentials, reopening the account under a new number, declining to open the account, closing it, or notifying law enforcement, up to determining that no response is warranted under the circumstances.5Legal Information Institute. 17 CFR Appendix A to Subpart C of Part 248 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation A firm that applies the same response to every flag, or has no documented response protocol, is not meeting the standard. Your program should say who makes those calls.
Update Periodically
Identity theft techniques change, and a program written years ago will miss threats that exist now. The rule requires periodic updates reflecting changes in risks to customers and to the firm. Triggers include new types of identity theft, changes in account access methods such as adding a mobile app, new business lines, mergers or acquisitions, and lessons learned from actual incidents.5Legal Information Institute. 17 CFR Appendix A to Subpart C of Part 248 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation The SEC has cited firms that added online portals without revisiting their programs.4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
Red Flag Categories to Draw From
The interagency guidelines identify five broad categories a program should consider, along with dozens of illustrative examples:5Legal Information Institute. 17 CFR Appendix A to Subpart C of Part 248 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation
- Consumer reporting agency alerts, including fraud alerts, credit freeze notices, address discrepancy notices, or activity inconsistent with the customer’s history.
- Suspicious documents, such as identification that appears altered or forged, photos that don’t match the person, or applications that look reassembled after being destroyed.
- Suspicious personal identifying information, including a Social Security number that doesn’t match the person’s date of birth range, an address associated with known fraud, or information that conflicts with what the firm already has on file.
- Unusual account activity, such as a sudden change in transaction patterns, a large withdrawal right after a contact information change, or an account reopened after being closed for abuse.
- External notices, including customer reports of unauthorized transactions, law enforcement contacts about suspected identity thieves, or complaints about mail not reaching the customer’s listed address.
These are examples, not a mandatory list. The identification step exists so each firm evaluates which flags fit its own business. An online-only brokerage doesn’t need flags for forged physical documents but does need flags for suspicious IP addresses and device fingerprints.
Governance, Training, and Vendor Oversight
Regulation S-ID pushes accountability up. The board of directors, an appropriate board committee, or, for firms without a board, a designated senior management employee must oversee the program. That includes approving the initial program, reviewing staff compliance reports, and approving material changes.5Legal Information Institute. 17 CFR Appendix A to Subpart C of Part 248 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation
Day-to-day management should sit with a specific person who owns implementation; the role can’t float unassigned. Staff who interact with customers or handle compliance need recurring training on the red flags relevant to their roles, not a one-time onboarding module. Examiners have cited firms where too little information reached the board for meaningful oversight.4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
When you outsource functions like data processing or customer onboarding, you remain responsible for making sure the vendor operates in accordance with your identity theft program. Contracts should require the service provider to detect and report red flags, and you should monitor whether that actually happens.5Legal Information Institute. 17 CFR Appendix A to Subpart C of Part 248 – Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation
Extra Duties for Card Issuers
Section 248.202 adds a separate obligation for any SEC-regulated entity that issues debit or credit cards. When a card issuer receives a change-of-address notification and then, within 30 days, receives a request for an additional or replacement card on the same account, it cannot simply mail the new card to the updated address. It must first validate the address change, either by notifying the cardholder at the former address or through another previously agreed communication channel and giving the cardholder a way to report an incorrect change, or by validating the change through the procedures in its identity theft prevention program.6eCFR. 17 CFR 248.202 – Duties of Card Issuers Regarding Changes of Address The rule interrupts a classic identity theft sequence: change the victim’s address, then request a replacement card that gets mailed somewhere the thief controls.
Where Firms Actually Fail
The SEC’s December 2022 risk alert is the clearest public view of how firms miss the mark. The recurring patterns are worth using as a self-check:4Securities and Exchange Commission. Observations From Broker-Dealer and Investment Adviser Compliance Examinations Related to Prevention of Identity Theft Under Regulation S-ID
- Never assessing whether accounts qualified as covered, and so never building a program at all.
- Copy-paste programs that restated the regulation without any firm-specific process, sometimes with fill-in-the-blank templates left blank.
- Red flags that don’t fit the business, like physical-appearance flags at an online-only firm.
- Treating AML procedures as a substitute for identity-theft-specific detection.
- No program update after launching online portals, adding account types, or completing mergers.
- Inadequate reporting to the board, leaving decision-makers unable to oversee the program.
The 2022 enforcement actions against JPMorgan, UBS, and TradeStation each involved censure and civil penalties for violating Section 248.201, with fines from $425,000 to $1.2 million.2Securities and Exchange Commission. SEC Charges JPMorgan, UBS, and TradeStation for Deficiencies The remediation burden under a cease-and-desist order tends to outweigh the dollar penalty.
How S-ID Differs From S-P
Both regulations live in 17 CFR Part 248, but they do different jobs. Regulation S-P, in Subpart A, governs privacy of consumer financial information, controlling when firms can share nonpublic personal information, requiring privacy notices, and mandating safeguards for customer data including record disposal. Regulation S-ID, in Subpart C, is about detecting and preventing identity theft through a proactive program of red flag identification and response.7eCFR. 17 CFR Part 248 – Regulations S-P, S-AM, and S-ID S-P protects the customer’s data from being improperly disclosed; S-ID protects the customer from someone using stolen data to impersonate them. A data-security program under S-P does not automatically satisfy S-ID.