9.3 Red Flags Rule, Dodd-Frank, and the CFPB
Key Takeaways
- The Red Flags Rule (FACTA § 114; 16 C.F.R. Part 681) requires financial institutions and covered creditors that offer or maintain covered accounts to have a written Identity Theft Prevention Program that identifies, detects, and responds to red flags and is updated periodically.
- The Red Flag Program Clarification Act of 2010 narrowed "creditor": advancing funds for expenses incidental to the creditor's own services (the classic professional courtesy account) is not enough.
- Dodd-Frank (2010) created the Consumer Financial Protection Bureau and transferred most Gramm-Leach-Bliley Act Privacy Rule and most Fair Credit Reporting Act rulemaking to it; the Federal Trade Commission retained Red Flags, the Disposal Rule, and the Safeguards Rule.
- Consumer Financial Protection Bureau UDAAP adds **abusive** to unfair and deceptive (12 U.S.C. §§ 5531, 5536). Federal Trade Commission Act Section 5 is UDAP — unfair or deceptive only. The extra A is the exam trap.
- A red flag is a pattern, practice, or specific activity that indicates the possible existence of identity theft — not a Gramm-Leach-Bliley Act privacy notice and not a Fair Credit Reporting Act permissible-purpose certification.
9.3 Red Flags Rule, Dodd-Frank, and the CFPB
FACTA told the agencies to write identity-theft guidelines. The result is the Red Flags Rule, which the FTC codified at 16 C.F.R. Part 681 ("Detection, Prevention, and Mitigation of Identity Theft"). Dodd-Frank later created the CFPB and moved large pieces of financial-privacy rulemaking. CIPP/US tests those two stories together because candidates mix Red Flags with the Safeguards Rule and mix UDAP with UDAAP.
Who must have a Red Flags program
The Rule applies to financial institutions and creditors that offer or maintain one or more covered accounts. A business must implement a written Identity Theft Prevention Program (ITPP) only if it is in one of those categories and it has covered accounts.
- Financial institution here is the FCRA/Red Flags sense: a bank, savings association, credit union, or any other person that holds a transaction account belonging to a consumer. That is narrower than the GLBA "significantly engaged in financial activities" definition. A tax preparer can be a GLBA financial institution for Safeguards purposes and still not be a Red Flags financial institution unless it also holds transaction accounts or is a covered creditor.
- Creditor, after the Red Flag Program Clarification Act of 2010, 15 U.S.C. § 1681m(e)(4), is not everyone who ever bills later. It is a creditor that regularly and in the ordinary course of business obtains or uses consumer reports in connection with a credit transaction, furnishes information to CRAs in connection with a credit transaction, or advances funds to or on behalf of a person based on an obligation to repay. Congress expressly excluded a creditor that advances funds for expenses incidental to a service the creditor itself provides — the lawyer, physician, or hospital that lets a client pay after the visit. The 2010 Act was a reaction to an earlier, broader reading that swept in many professional firms.
- A covered account is (i) an account offered or maintained primarily for personal, family, or household purposes that involves or is designed to permit multiple payments or transactions (credit card, mortgage, auto loan, checking, savings, and, in the Rule's examples, certain telecom or utility accounts), or (ii) any other account for which there is a reasonably foreseeable risk of identity theft. The institution must periodically redetermine whether it offers covered accounts.
A red flag is a pattern, practice, or specific activity that indicates the possible existence of identity theft. Examples from the interagency guidelines include a fraud alert on a consumer report, an address discrepancy, documents that look altered, a Social Security number that the Social Security Administration lists as unissued, and a new-account request shortly after an address change.
The four program elements
16 C.F.R. § 681.1(d)(2) is the outline you should be able to recite:
- Identify relevant red flags for the covered accounts the institution offers and incorporate them into the program.
- Detect those red flags in day-to-day operations (for example, verify identity at account opening and authenticate existing customers).
- Respond appropriately to prevent and mitigate identity theft (contact the customer, change passwords, refuse the transaction, notify law enforcement, determine that no response is warranted).
- Update the program periodically to reflect changes in risks, methods, accounts, and business arrangements.
The program must be appropriate to the size and complexity of the business and the nature of its covered accounts. The board of directors or a designated board committee (or, if there is no board, senior management) must approve the initial program. Staff must be trained. Service providers that handle covered accounts must be required, by contract, to have reasonable identity-theft procedures. Do not confuse this board-approval story with the Safeguards Rule's Qualified Individual and annual written report. Red Flags is an identity-theft program. Safeguards is an information-security program. A company can need both.
Scenario. A community bank's new-account clerk opens a checking account for a walk-in whose photo identification looks altered and whose consumer report carries an active fraud alert. Detecting those red flags is not optional color. The ITPP must tell the clerk what to do next — additional identity verification, refusal to open, escalation — and the bank must be able to show the program was approved, trained, and updated.
SEC- and CFTC-regulated entities follow parallel identity-theft rules (Regulation S-ID, 17 C.F.R. Part 248, Subpart C, and CFTC 17 C.F.R. Part 162, Subpart C) that Dodd-Frank directed those commissions to adopt. The substance matches Part 681.
Dodd-Frank and the CFPB — who got which book
The Dodd-Frank Wall Street Reform and Consumer Protection Act, Pub. L. 111-203 (21 July 2010), created the CFPB in Title X (the Bureau opened in 2011). For CIPP/US, the transfer table is the point:
| Authority | After Dodd-Frank |
|---|---|
| GLBA Privacy Rule (notice, opt-out, NPI sharing) | Mostly CFPB — Regulation P, 12 C.F.R. Part 1016. FTC keeps a residual book for entities such as certain motor-vehicle dealers. |
| Most of the FCRA | CFPB rulemaking and a large enforcement share — Regulation V, 12 C.F.R. Part 1022. CFPB also examines very large depository institutions (generally more than $10 billion in assets) and certain nonbanks. |
| Red Flags (15 U.S.C. § 1681m(e)) | FTC (and the prudential regulators / SEC / CFTC for their own populations). Not transferred. |
| Disposal Rule (15 U.S.C. § 1681w) | FTC retained. |
| GLBA Safeguards Rule for FTC-jurisdiction institutions | FTC — 16 C.F.R. Part 314. Bank agencies keep their own interagency guidelines. |
| UDAAP | CFPB, 12 U.S.C. §§ 5531 and 5536. |
The CFPB is an independent bureau. It writes rules, supervises large banks and designated nonbanks, and brings civil enforcement. It does not displace state attorneys general, the FTC's remaining books, or the banking agencies' safety-and-soundness examinations. A CIPP/US item that asks "which agency writes the Privacy Rule today?" wants the CFPB. An item that asks "which agency writes Red Flags or the Disposal Rule?" wants the FTC.
UDAP versus UDAAP — the extra A
FTC Act § 5, 15 U.S.C. § 45, prohibits unfair or deceptive acts or practices — UDAP. The deception and unfairness tests from Domain I still apply: a material representation likely to mislead a reasonable consumer; or substantial injury that is not reasonably avoidable and not outweighed by countervailing benefits (15 U.S.C. § 45(n)).
The Consumer Financial Protection Act inside Dodd-Frank prohibits unfair, deceptive, or abusive acts or practices by covered persons and service providers in connection with consumer financial products or services — UDAAP. Unfair and deceptive are essentially the same tests. Abusive is the added prong, 12 U.S.C. § 5531(d). An act or practice is abusive if it:
- materially interferes with the ability of a consumer to understand a term or condition of a consumer financial product or service; or
- takes unreasonable advantage of (A) a lack of understanding of the material risks, costs, or conditions, (B) the inability of the consumer to protect his or her interests in selecting or using the product, or (C) the reasonable reliance of the consumer on a covered person to act in the consumer's interests.
Abusive does not require the FTC § 5 unfairness balancing test. It is its own standard. The exam's one-letter trap is reliable: FTC = UDAP; CFPB = UDAAP. Do not put "abusive" in an FTC § 5 answer. Do not drop "abusive" from a CFPB consumer-financial-product answer.
Scenario. A fintech overdraft product is marketed as "always free protection" while a dense fee schedule deducts $35 on any negative balance. The CFPB can plead deception (the headline contradicts the fee), unfairness (substantial, unavoidable injury), and abusiveness (material interference with understanding, or taking unreasonable advantage of a lack of understanding). The FTC, on a nonbank product still inside § 5, would plead UDAP only.
Exam traps
- Red Flags is not the Safeguards Rule. One is identity theft on covered accounts; the other is security of customer information.
- A doctor who bills after a visit is generally not a Red Flags creditor after the 2010 Clarification Act.
- Dodd-Frank did not move Red Flags, Disposal, or FTC Safeguards to the CFPB.
- Memorize the extra A.
A community bank offers consumer checking accounts and credit cards. Which statement correctly describes its Red Flags Rule duty?
After the Dodd-Frank Act, which assignment of rulemaking authority is accurate?
A CIPP/US item asks which extra theory the Consumer Financial Protection Bureau can use that Section 5 of the Federal Trade Commission Act does not name. What is the correct contrast?