22.1 Red Flag Responses, Program Updates and Address Validation

Key Takeaways

  • Identity-theft responses should address the actual risk rather than automatically close every account.

  • Program updates consider changing threats, products and experience.

  • Address-change validation and consumer-report address discrepancies are separate requirements.

Last updated: October 2026

Element 3: Respond Appropriately

When a Red Flag is detected, the institution must execute an operational response commensurate with the degree of risk:

  • Monitoring the covered account for evidence of ongoing fraud;
  • Contacting the customer via pre-established, validated contact channels to verify transactions;
  • Changing passwords, PINs, security questions, or online access credentials;
  • Reopening the account with a new account number or closing the compromised account;
  • Refusing to open a new account;
  • Freezing the account to halt transactions and prevent fund dissipation;
  • Filing a Suspicious Activity Report (SAR) with FinCEN; or
  • Determining that no operational response is warranted after investigating circumstances.

Element 4: Update Program Periodically

The Program must be updated periodically as risks change to reflect changes in risks to customers and the safety and soundness of the institution. Updates must evaluate changes in identity theft methods, new account opening channels (e.g., mobile deposit capture, fintech integrations), changes in business structure, and historical fraud losses.


3. Governance, Oversight, and Administration

Examiners place substantial emphasis on the governance structure supporting the Red Flags Program (Appendix J Section VI).

Board of Directors Approval

  • Initial Approval: The initial written Identity Theft Prevention Program must be formally approved by either the institution's Board of Directors or an appropriate designated committee of the Board (e.g., Risk Committee or Audit Committee).
  • Program Administration: The Board or committee may delegate ongoing oversight, operational implementation, and maintenance of the Program to designated senior management personnel.

Annual Reporting to the Board

The interagency identity-theft guidelines provide that staff administering the program should report at least annually to the board, an appropriate committee or a designated senior-management employee. Distinguish the rule’s required program oversight from this recommended reporting framework. The report addresses:

  1. The overall effectiveness of the policies and procedures in addressing identity theft risks;
  2. Significant incidents involving identity theft and management's operational response;
  3. Oversight of third-party service providers performing account activities; and
  4. Recommendations for material changes to the Program.

Staff Training and Third-Party Oversight

  • Employee Training: Relevant staff in frontline branch banking, loan underwriting, customer service, back-office operations, and IT must receive role-based training on detecting and escalating Red Flags.
  • Third-Party Service Provider Oversight: When a bank contracts with third parties to perform activities on covered accounts (e.g., digital onboarding platforms, loan service bureaus, call center operators), the bank must ensure the service provider conducts its activities in accordance with reasonable policies and procedures to detect, prevent, and mitigate identity theft.

4. Duties Regarding Address Discrepancies (§ 605(h), 12 CFR § 1022.82)

Under FCRA § 605(h) and CFPB Regulation V (12 CFR § 1022.82), nationwide CRAs must issue a Notice of Address Discrepancy to report users whenever the address provided by the user in an inquiry differs substantially from the address in the CRA's consumer file.

Bank Duties Upon Receiving a Notice of Address Discrepancy

  1. Form a Reasonable Belief: The bank must maintain reasonable written policies and procedures to enable it to form a reasonable belief that the consumer report relates to the applicant about whom it requested the report. Methods include:
    • Comparing information in the consumer report with information provided on the application;
    • Verifying the address with the consumer using documentary evidence (utility bill, government ID);
    • Cross-referencing third-party identity verification databases.
  2. Duty to Furnish Confirmed Address to CRA: The bank must furnish the consumer's confirmed address to the CRA if:
    • The bank forms a reasonable belief that the consumer report relates to the consumer;
    • The bank establishes a continuing relationship with the consumer (e.g., opens a loan or deposit account); and
    • The bank regularly and in the ordinary course of business furnishes information to that CRA.
    • Timing: The confirmed address must be furnished as part of the information the bank regularly furnishes for the reporting period in which the relationship is established.

5. Special Rules: Card Reissuance & Disposal Rules

Special Card Reissuance Rules (the bank regulator’s card-issuer address-validation rule (for example, 12 CFR 334.91))

To prevent account takeover, when a debit or credit card issuer receives a request for an additional or replacement card within 30 calendar days after receiving notification of a change of address for the account:

  • The issuer shall not issue the card until it assesses the validity of the address change.
  • The issuer must either: (1) notify the cardholder at the former address; or (2) assess validity through other pre-agreed verification procedures.

The Disposal Rule (§ 628, the applicable prudential bank identity theft rule)

Any person that possesses or maintains consumer report information or data derived from consumer reports for a business purpose must take reasonable measures to protect against unauthorized access in connection with its disposal:

  • Paper Records: Burning, pulverizing, or shredding physical papers so consumer information cannot be read or reconstructed.
  • Electronic Media: Erasing, degaussing, or physically destroying electronic media (hard drives, magnetic tapes, SSDs) so that electronic data cannot be recovered.
  • Third-Party Vendors: Conducting due diligence on third-party document shredding and asset disposition vendors.
Test Your Knowledge

A national bank receives a credit report from a nationwide consumer reporting agency in connection with an auto loan application. The credit report contains a Notice of Address Discrepancy under 12 CFR § 1022.82. Which of the following procedures must the bank execute to comply with federal address discrepancy rules?

A

File a Suspicious Activity Report (SAR) with FinCEN within 30 calendar days of receiving the report.

B

Deny the application immediately under FCRA § 615(a) citing an invalid applicant address.

C

Form a reasonable belief that the credit report relates to the applicant, and furnish a confirmed address to the CRA if a continuing relationship is established and the bank regularly reports to the CRA.

D

Issue a credit score exception notice to the CRA within 5 business days of loan funding.

Test Your Knowledge

A credit card issuer receives a customer request for a replacement credit card 12 calendar days after receiving a notice of change of address for the same account. Under the bank regulator’s card-issuer address-validation rule (for example, 12 CFR 334.91), what restriction applies to the card issuer?

A

The issuer must notify the primary regulatory agency within 24 hours of receiving the replacement card request.

B

The issuer must permanently close the credit card account and require a brand-new application.

C

The issuer may issue the card immediately provided it increases the customer's APR to cover fraud risk.

D

The issuer cannot issue the replacement card until it assesses the validity of the address change by notifying the cardholder at the former address or through other validated procedures.

Sections you finish are checked off in the contents.