Under the Red Flags Rule, a covered account is one of two things: a consumer account that a financial institution or creditor maintains primarily for personal, family, or household purposes and that allows multiple payments or transactions, or any other account where identity theft poses a reasonably foreseeable risk to the customer or to the institution. If your business offers or maintains either kind, the rule requires a written identity theft prevention program.
The definition comes from regulations issued under the Fair Credit Reporting Act, and it sweeps in far more businesses than the word “account” suggests.1eCFR. 16 CFR 681.1 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft
The Two Categories That Make an Account “Covered”
An account only needs to fit one category to count.
The first category is automatic. It captures any account a financial institution or creditor maintains primarily for personal, family, or household purposes that involves or permits multiple payments or transactions. The regulation names credit card accounts, mortgage loans, automobile loans, margin accounts, cell phone accounts, utility accounts, checking accounts, and savings accounts as examples.1eCFR. 16 CFR 681.1 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft If you offer one of these to consumers, it’s a covered account by default. No further analysis needed.
The second category is a catch-all. It reaches any other account, consumer or business, where there is a reasonably foreseeable risk of identity theft to the customer or to the safety and soundness of the institution. That risk includes financial, operational, compliance, reputational, and litigation exposure.1eCFR. 16 CFR 681.1 – Duties Regarding the Detection, Prevention, and Mitigation of Identity Theft
The catch-all is where businesses get surprised. Medical payment plans, gym memberships billed monthly, insurance policies, and small-business credit lines can all fall in if someone could plausibly open or hijack one using stolen identity information.
How to Tell Whether the Catch-All Applies
The first category asks a simple question about what the account is. The second requires a risk assessment. To decide whether a particular account type poses a reasonably foreseeable risk, look at how accounts are opened, how they’re accessed afterward, and whether similar accounts elsewhere have been targets of identity theft.
That assessment is not a one-time exercise. Any time you introduce a new product or service, or change how customers open or access an existing one, you should revisit whether it creates a covered account. A product that started as a low-risk offering can shift categories once online enrollment or remote access is added.
Concretely: an account opened in person with government ID and used only for face-to-face transactions carries a different risk profile than one opened online with a form and used through a self-service portal. Two accounts that look identical on paper can land on opposite sides of the covered-account line depending on how customers interact with them.
Whose Accounts Count: Financial Institutions and Creditors
An account only becomes a “covered account” if the entity holding it is a financial institution or a creditor under the rule. Both terms are broader than they sound.
A financial institution includes every bank, savings association, and credit union, whether or not it holds consumer transaction accounts, plus any other person or entity that directly or indirectly holds a transaction account belonging to a consumer.2Office of the Comptroller of the Currency. Ten of the Most Common Questions About the Final CIP Rule (Identity Theft Red Flags and Address Discrepancies)
The creditor definition reaches further. Under the Fair Credit Reporting Act, a creditor is any entity that regularly extends, renews, or continues credit, or arranges for someone else to do so. In practice, that sweeps in businesses that routinely let customers pay later for goods or services, including utility companies, auto dealers, and telecom providers.3Federal Trade Commission. Red Flags Rule
What matters is not your industry but whether you offer or maintain a covered account. A dentist who bills patients on a payment plan can be operating as a creditor for Red Flags purposes, even though the office looks nothing like a bank. Whether that dentist still qualifies after 2010 is the next question.
What the 2010 Clarification Act Took Out of the Definition
The original creditor definition was broad enough to catch attorneys who billed clients after providing services, doctors who invoiced patients, and similar professionals. Congress narrowed it through the Red Flag Program Clarification Act of 2010.
Under the amended definition, a creditor subject to the Red Flags Rule is one that regularly and in the ordinary course of business does at least one of the following: obtains or uses consumer reports in connection with a credit transaction, furnishes information to consumer reporting agencies in connection with a credit transaction, or advances funds to a person based on an obligation to repay.4Federal Register. Identity Theft Red Flags and Address Discrepancies Under the Fair and Accurate Credit Transactions Act of 2003, as Amended by the Red Flag Program Clarification Act of 2010
The Clarification Act also excludes creditors who advance funds only for expenses incidental to a service they provide. A law firm that fronts court filing fees, or a doctor who bills after a procedure, no longer qualifies as a creditor solely because of those arrangements. The phrase “regularly and in the ordinary course of business” also excludes isolated transactions.4Federal Register. Identity Theft Red Flags and Address Discrepancies Under the Fair and Accurate Credit Transactions Act of 2003, as Amended by the Red Flag Program Clarification Act of 2010
If you’re not sure whether your business still qualifies as a creditor after these changes, the three-part test above is the place to start. Businesses that only bill for their own services after the fact, without pulling credit reports or reporting to credit bureaus, generally sit outside the rule.
Common Examples of Covered Accounts
Working from the regulation and its examples, the accounts most clearly covered include:
- Consumer checking and savings accounts at banks and credit unions.
- Credit card accounts issued to individuals.
- Mortgage loans and home equity lines held by consumers.
- Automobile loans made to individual buyers.
- Margin accounts held with a broker.
- Residential utility accounts, including electricity, gas, and water service billed after use.
- Consumer cell phone accounts with recurring billing.
Beyond that automatic list, business accounts and other product types can also be covered if a risk assessment shows a reasonably foreseeable identity theft risk. A small-business credit line accessed through the same portal as consumer accounts, for instance, may end up on the list even though the account holder is a company rather than an individual.
What Follows Once You Have a Covered Account
The reason the definition matters is that it turns on a compliance obligation. Every financial institution or creditor that offers or maintains a covered account must develop and implement a written Identity Theft Prevention Program tailored to its size, complexity, and the nature of its operations. The program must identify relevant red flags, detect them in day-to-day operations, respond appropriately when one appears, and be updated periodically to keep pace with new fraud methods.5Federal Trade Commission. Fighting Identity Theft with the Red Flags Rule: A How-To Guide for Business
The board of directors or an appropriate committee must approve the initial program; if you don’t have a board, senior management signs off. Staff whose jobs put them near account openings, transactions, or customer authentication need training on how to spot and handle red flags. And if you outsource any activity involving covered accounts to a service provider, you remain responsible for identity theft prevention in that area and must take steps to ensure the provider follows reasonable procedures.6eCFR. Part 681 Identity Theft Rules
A small utility with a few thousand residential accounts can run a much simpler program than a national bank. The rule expects proportionality, not uniformity. What it does not accept is skipping the exercise once you’ve confirmed that even one of your account types is covered.