21.3 Identity Theft Program Scope, Governance and Detection

Key Takeaways

  • A written identity-theft program is required when the covered-account analysis triggers the rules.

  • The program must identify, detect and respond to relevant red flags.

  • Board approval and oversight do not replace operational detection and response controls.

Last updated: October 2026

1. Scope and Definition of Covered Accounts

The Red Flags Rule applies to financial institutions (state and national banks, savings associations, and credit unions) and creditors that offer or maintain 'covered accounts'.

The Red Flag Program Clarification Act of 2010

The Clarification Act narrows the creditor branch of coverage. Beyond meeting the ECOA creditor definition, the entity ordinarily must regularly use consumer reports, furnish information to consumer reporting agencies in connection with credit, or advance repayable funds to or on behalf of people. The advance-of-funds prong has a specific exception for funds incidental to a service. Merely billing after a service is not automatically sufficient. Banks also have separate coverage as financial institutions; the covered-account analysis determines whether a written program is required.

A small-business deposit account can be a covered account under the foreseeable-risk prong even though it is not a consumer account. Consider remote opening, payment privileges, access credentials and prior fraud. Record the reasons for inclusion or exclusion, and reconsider them when account features or threats change. An initial assessment that found no covered accounts is not permanent immunity from the program requirement.

Definition of 'Covered Account' (the applicable prudential bank identity theft rule(b)(3))

The regulations establish a two-prong definition of a covered account:

  1. Consumer Accounts Permitting Multiple Transactions: An account that a financial institution or creditor offers or maintains, primarily for personal, family, or household purposes, that involves or is designed to permit multiple payments or transactions. This includes checking accounts, savings accounts, credit card accounts, residential mortgage loans, automobile loans, margin accounts, and home equity lines of credit.
  2. Other Accounts with Foreseeable Identity Theft Risk: Any other account (including commercial or small business accounts) that the financial institution or creditor offers or maintains for which there is a reasonably foreseeable risk to customers or to the safety and soundness of the institution from identity theft.

Operational Mandate: Financial institutions must conduct periodic risk assessments of all deposit and loan product lines to identify covered accounts, evaluating the methods provided to open accounts, access mechanisms, and historical experiences with identity theft.


2. The Four Core Elements of an Identity Theft Prevention Program

Under the applicable bank regulator’s identity theft rule and guidelines (for example, 12 CFR 334.90 and Appendix J for FDIC-supervised banks) Section II, every institution's written Program must incorporate four essential operational elements tailored to the size and complexity of the institution and the nature and scope of its activities:

Element 1: Identify Relevant Red Flags

A Red Flag is defined as a pattern, practice, or specific activity that indicates the possible existence of identity theft. Supplement A to Appendix J enumerates five categories of Red Flags that institutions must consider:

  1. Alerts, Notifications, or Warnings from a CRA:
    • A fraud alert or active duty alert on a consumer report;
    • A Notice of Credit Freeze from a CRA;
    • A Notice of Address Discrepancy;
    • An unusual surge in the volume of credit inquiries or recent opening of multiple accounts.
  2. Suspicious Documents:
    • Identification documents showing signs of tampering, alteration, or forgery;
    • Photograph or physical description on identification inconsistent with the applicant's appearance;
    • Inconsistencies within the document itself (e.g., issue date postdating expiration date).
  3. Suspicious Personal Identifying Information (PII):
    • Identifying information provided that is inconsistent with external sources (e.g., address does not match credit report records);
    • Social Security Number reported as deceased on the Social Security Administration's Death Master File;
    • SSN invalid (e.g., unissued range) or duplicate SSN currently used by another customer;
    • Address provided is fictitious, a mail drop, a commercial PO Box, or associated with known fraud;
    • Telephone number provided is disconnected, invalid, or associated with a pre-paid burner phone.
  4. Unusual Use of, or Suspicious Activity Related to, a Covered Account:
    • An account used in a manner inconsistent with established historical patterns (e.g., sudden cash advances or rapid depletion of balances);
    • An account that has been inactive for an extended period suddenly experiencing large withdrawals;
    • Notification that the customer is not receiving periodic statements;
    • A request for a replacement debit/credit card immediately following a change of address request.
  5. Notice of Identity Theft:
    • Notice received directly from a customer, a victim of identity theft, or law enforcement indicating an account was opened or compromised through fraudulent means.

Element 2: Detect Red Flags

The Program must establish procedures to detect identified Red Flags in daily operations:

  • New Accounts: Authenticating consumer identity using documentary and non-documentary Customer Identification Program (CIP) procedures under the Bank Secrecy Act; validating address history against independent databases.
  • Existing Accounts: Monitoring ongoing transaction activity for velocity anomalies; verifying identity before executing wire transfers, resetting online banking passwords, or altering account profiles.
Test Your Knowledge

Under the FACTA Red Flags Rule (the applicable bank regulator’s identity theft rule and guidelines (for example, 12 CFR 334.90 and Appendix J for FDIC-supervised banks)), what specific governance action is required for a financial institution's initial written Identity Theft Prevention Program?

A

The program must be submitted to the CFPB for formal certification prior to implementation.

B

The program must be published annually in the local newspaper of record within the bank's assessment area.

C

The program must be approved by the chief information security officer without requiring Board involvement.

D

The initial written program must be approved by the Board of Directors or an appropriate designated committee of the Board.

Sections you finish are checked off in the contents.