Quick Answer
Regulation S-ID requires a firm that offers or maintains covered accounts to establish a written Identity Theft Prevention Program. The program identifies, detects, and responds to relevant red flags, which are patterns, practices, or activities indicating possible identity theft. The firm updates the program periodically as risks change.
Does the Firm Offer or Maintain a Covered Account?
Regulation S-ID is the identity-theft red flags framework. A red flag is a pattern, practice, or specific activity that indicates possible identity theft.
A covered account includes:
- A personal, family, or household account designed to permit multiple payments or transactions.
- Another account presenting a reasonably foreseeable identity-theft risk to customers or to the firm's safety and soundness.
A firm that offers or maintains a covered account establishes a written Identity Theft Prevention Program.
What Must the Identity Theft Prevention Program Do?
The program must include reasonable policies and procedures for four elements:
| Required program element | What it does |
|---|---|
| Identify | Finds relevant identity-theft red flags and incorporates them into the program |
| Detect | Detects red flags incorporated into the program |
| Respond | Responds appropriately to detected red flags to prevent and mitigate identity theft |
| Periodically update | Updates the program, including its relevant red flags, as identity-theft risks change |
Exam Tip: Gotchas
- Regulation S-ID covers possible identity theft involving covered accounts. It is not the general privacy-and-safeguarding framework.
- Regulation S-P and Regulation S-ID address different duties. Regulation S-P concerns privacy and safeguarding of customer information. Regulation S-ID concerns detecting, preventing, and mitigating identity theft.
Think of it this way: Regulation S-P controls the privacy of the information. Regulation S-ID uses warning signals to help a firm spot and address possible misuse of an identity.
What Should You Check on Exam Day?
- Determine whether the account fits either covered-account category.
- Check for policies and procedures that identify relevant red flags and incorporate them into the program.
- Confirm that the program detects incorporated red flags, responds appropriately to detected red flags, and receives periodic updates as risks change.
- Keep identity-theft red flags separate from Regulation S-P privacy and incident-response duties.