The SEC and CFTC recently issued rules and guidelines requiring the entities they regulate to adopt rules to address the risks of identity theft, that is, “fraud committed or attempted using the identifying information of another person without authority.” The final rules require “financial institutions” and “creditors” that offer and maintain “covered accounts” to develop and implement a written identity theft prevention program, including reasonable policies and procedures designed to identify, detect, prevent, and mitigate identity theft. The rules contain guidelines to assist in the design and maintenance of programs that would satisfy the requirements of the rules.
While these rules close the loop left open by similar rules under the Fair Credit Reporting Act, as a practical matter, entities registered with the CFTC and the SEC, such as futures commission merchants, broker-dealers, investment companies, and investment advisers, already were covered by the FCRA. The new rules pull within their purview recent registrants with the SEC, private fund and hedge fund advisers to the financial institutions that must ensure that they have appropriate identity theft red-flag programs.
There are several notable takeaways from this development:
- The two agencies refused to expressly exempt from the scope of the rules any registered entities that qualify as “financial institutions” and “creditors.”
- Instead of requiring specific policies and procedures for identifying red-flags, the SEC and CFTC provided regulated entities flexibility in determining which red flags are most relevant to their businesses and in responding and adapting to new emerging forms of identity theft.
- The duty of financial institutions and creditors to have reasonable policies and procedures to update their identity theft programs to reflect changing risks from identity theft is ongoing.