# Identity Theft Red Flags Rules

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2013-08830

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** April 19, 2013
- **Citation:** 78 FR 23638

## Text

COMMODITY FUTURES TRADING COMMISSION
17 CFR Part 162
RIN 3038-AD14
SECURITIES AND EXCHANGE COMMISSION
17 CFR Part 248
[Release Nos. 34-69359, IA-3582, IC-30456; File No. S7-02-12]
RIN 3235-AL26
Identity Theft Red Flags Rules

AGENCY:

Commodity Futures Trading Commission and Securities and Exchange Commission.

ACTION:

Joint final rules and guidelines.

SUMMARY:

The Commodity Futures Trading Commission (“CFTC”) and the Securities and Exchange Commission (“SEC”) (together, the “Commissions”) are jointly issuing final rules and guidelines to require certain regulated entities to establish programs to address risks of identity theft. These rules and guidelines implement provisions of the Dodd-Frank Wall Street Reform and Consumer Protection Act, which amended the Fair Credit Reporting Act and directed the Commissions to adopt rules requiring entities that are subject to the Commissions' respective enforcement authorities to address identity theft. First, the rules require financial institutions and creditors to develop and implement a written identity theft prevention program designed to detect, prevent, and mitigate identity theft in connection with certain existing accounts or the opening of new accounts. The rules include guidelines to assist entities in the formulation and maintenance of programs that would satisfy the requirements of the rules. Second, the rules establish special requirements for any credit and debit card issuers that are subject to the Commissions' respective enforcement authorities, to assess the validity of notifications of changes of address under certain circumstances.

DATES:

Effective date:
May 20, 2013;
Compliance date:
November 20, 2013.

FOR FURTHER INFORMATION CONTACT:

CFTC: Sue McDonough, Counsel, at Commodity Futures Trading Commission, Office of the General Counsel, Three Lafayette Centre, 1155 21st Street NW., Washington, DC 20581, telephone number (202) 418-5132, facsimile number (202) 418-5524, email
smcdonough@cftc.gov;
SEC: with regard to investment companies and investment advisers, contact Andrea Ottomanelli Magovern, Senior Counsel, Amanda Wagner, Senior Counsel, Thoreau Bartmann, Branch Chief, or Hunter Jones, Assistant Director, Office of Regulatory Policy, Division of Investment Management, (202) 551-6792, or with regard to brokers, dealers, or transfer agents, contact Brice Prince, Special Counsel, Joseph Furey, Assistant Chief Counsel, or David Blass, Chief Counsel, Office of Chief Counsel, Division of Trading and Markets, (202) 551-5550, Securities and Exchange Commission, 100 F Street NE., Washington, DC 20549-8549.

SUPPLEMENTARY INFORMATION:

The Commissions are adopting new rules and guidelines on identity theft red flags for entities subject to their respective enforcement authorities. The CFTC is adding new subpart C (“Identity Theft Red Flags”) to part 162 of the CFTC's regulations [17 CFR part 162] and the SEC is adding new subpart C (“Regulation S-ID: Identity Theft Red Flags”) to part 248 of the SEC's regulations [17 CFR part 248], under the Fair Credit Reporting Act [15 U.S.C. 1681-1681x], the Commodity Exchange Act [7 U.S.C. 1-27f], the Securities Exchange Act of 1934 [15 U.S.C. 78a-78pp], the Investment Company Act of 1940 [15 U.S.C. 80a], and the Investment Advisers Act of 1940 [15 U.S.C. 80b].

Table of Contents

I. Background

II. Explanation of the Final Rules and Guidelines

A. Final Identity Theft Red Flags Rules

1. Which Financial Institutions and Creditors Are Required to Have a Program

2. The Objectives of the Program

3. The Elements of the Program

4. Administration of the Program

B. Final Guidelines

1. Section I of the Guidelines—Identity Theft Prevention Program

2. Section II of the Guidelines—Identifying Relevant Red Flags

3. Section III of the Guidelines—Detecting Red Flags

4. Section IV of the Guidelines—Preventing and Mitigating Identity Theft

5. Section V of the Guidelines—Updating the Identity Theft Prevention Program

6. Section VI of the Guidelines—Methods for Administering the Identity Theft Prevention Program

7. Section VII of the Guidelines—Other Applicable Legal Requirements

8. Supplement A to the Guidelines

C. Final Card Issuer Rules

III. Related Matters

A. Cost-Benefit Considerations (CFTC) and Economic Analysis (SEC)

B. Analysis of Effects on Efficiency, Competition, and Capital Formation

C. Paperwork Reduction Act

D. Regulatory Flexibility Act

IV. Statutory Authority and Text of Amendments

I. Background

The growth and expansion of information technology and electronic communication have made it increasingly easy to collect, maintain, and transfer personal information about individuals.
1

Advancements in technology also have led to increasing threats to the integrity and privacy of personal information.
2

During recent decades, the federal government has taken steps to help protect individuals, and to help individuals protect themselves, from the risks of theft, loss, and abuse of their personal information.
3

1

See, e.g.,
U.S. Government Accountability Office, Information Security: Federal Guidance Needed to Address Control Issues with Implementing Cloud Computing (May 2010),
available at http://www.gao.gov/new.items/d10513.pdf
(discussing information security implications of cloud computing); Department of Commerce, Internet Policy Task Force, Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework, at Section I (2010),
available at http://www.ntia.doc.gov/reports/2010/iptf_privacy_greenpaper_­12162010.pdf
(reviewing recent technological changes that necessitate a new approach to commercial data protection).
See also
Fred H. Cate, Privacy in the Information Age, at 13-16 (1997) (discussing the privacy and data security issues that arose during early increases in the use of digital data).

2
A recent survey found that in 2012, over 5% of Americans were victims of identity fraud.
See
Javelin Strategy & Research, 2013 Identity Fraud Report: Data Breaches Becoming a Treasure Trove for Fraudsters (Feb. 2013),
available at https://www.javelinstrategy.com/uploads/web_brochure/1303.R_2013IdentityFraudBrochure.pdf; see also
Comment Letter of Tyler Krulla (“Tyler Krulla Comment Letter”) (Apr. 27, 2012) (“In today's technology driven world it is easier than ever for anyone to acquire and exploit someone's identity and cause severe financial problems.”).

3

See, e.g.,
Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy (Feb. 2012),
available at http://www.whitehouse.gov/sites/default/files/privacy-final.pdf
(a White House proposal to establish a consumer privacy bill of rights); The President's Identity Theft Task Force Report (Sept. 2008),
available at http://www.ftc.gov/os/2008/10/081021taskforcereport.pdf;
Securities and Exchange Commission, Online Brokerage Accounts: What you can do to Safeguard Your Money and Your Personal Information,
available at http://www.sec.gov/investor/pubs/onlinebrokerage.htm.

The Fair Credit Reporting Act of 1970 (“FCRA”),
4

as amended in 2003,
5

required several federal agencies to issue joint rules and guidelines regarding the detection, prevention, and mitigation of identity theft for entities that are subject to their respective enforcement authorities (also known as

the “identity theft red flags rules”).
6

Those agencies were the Office of the Comptroller of the Currency (“OCC”), the Board of Governors of the Federal Reserve System (“Federal Reserve Board”), the Federal Deposit Insurance Corporation (“FDIC”), the Office of Thrift Supervision (“OTS”), the National Credit Union Administration (“NCUA”), and the Federal Trade Commission (“FTC”) (together, the “Agencies”).
7

In 2007, the Agencies issued joint final identity theft red flags rules.
8

At the time the Agencies adopted their rules, the FCRA did not require or authorize the CFTC and SEC to issue identity theft red flags rules. Instead, the Agencies' rules applied to entities that registered with the CFTC and SEC, such as futures commission merchants, broker-dealers, investment companies, and investment advisers.
9

4
Pub. L. 91-508, 84 Stat. 1114 (1970),
codified at
15 U.S.C. 1681-1681x.

5

See
Fair and Accurate Credit Transactions Act of 2003, Pub. L. 108-159, 117 Stat. 1952 (2003) (“FACT Act”).

6

See
FCRA sections 615(e)(1)(A)-(B), 15 U.S.C. 1681m(e)(1)(A)-(B). Section 615(e)(1)(A) of the FCRA requires the Agencies to jointly “establish and maintain guidelines for use by each financial institution and each creditor regarding identity theft with respect to account holders at, or customers of, such entities, and update such guidelines as often as necessary.” Section 615(e)(1)(B) requires the Agencies to jointly “prescribe regulations requiring each financial institution and each creditor to establish reasonable policies and procedures for implementing the guidelines established pursuant to [section 615(e)(1)(A)], to identify possible risks to account holders or customers or to the safety and soundness of the institution or customers.”

7
The FCRA also required the Agencies to prescribe joint rules applicable to issuers of credit and debit cards, to require that such issuers assess the validity of notifications of changes of address under certain circumstances (the “card issuer rules”).
See
FCRA section 615(e)(1)(C), 15 U.S.C. 1681m(e)(1)(C).

8

See
Identity Theft Red Flags and Address Discrepancies under the Fair and Accurate Credit Transactions Act of 2003, 72 FR 63718 (Nov. 9, 2007) (“2007 Adopting Release”). The rules included card issuer rules.
See supra
note 7. The OCC, Federal Reserve Board, FDIC, OTS, and NCUA began enforcing their identity theft red flags rules on November 1, 2008. The FTC began enforcing its identity theft red flags rules on January 1, 2011.

9

See
2007 Adopting Release,
supra
note 8.

In 2010, the Dodd-Frank Wall Street Reform and Consumer Protection Act (“Dodd-Frank Act”)
10

amended the FCRA to add the CFTC and SEC to the list of federal agencies that must jointly adopt and individually enforce identity theft red flags rules.
11

Thus, the Dodd-Frank Act provides for the transfer of rulemaking responsibility and enforcement authority to the CFTC and SEC with respect to the entities subject to each agency's enforcement authority. In February 2012, the Commissions jointly proposed for public notice and comment identity theft red flags rules and guidelines and card issuer rules.
12

10
Pub. L. 111-203, 124 Stat. 1376 (2010). The text of the Dodd-Frank Act is available at
http://www.cftc.gov/LawRegulation/OTCDERIVATIVES/index.htm.

11

See
FCRA section 615(e)(1), 15 U.S.C. 1681m(e)(1). In addition, section 1088(a)(10)(A) of the Dodd-Frank Act added the Commissions to the list of federal administrative agencies responsible for enforcement of rules pursuant to section 621(b) of the FCRA.
See infra
note 24. Section 1100H of the Dodd-Frank Act provides that the Commissions' new enforcement authority (as well as other changes in various agencies' authority under other provisions) becomes effective as of the “designated transfer date” to be established by the Secretary of the Treasury, as described in section 1062 of that Act. On September 20, 2010, the Secretary of the Treasury designated July 21, 2011 as the transfer date.
See
Designated Transfer Date, 75 FR 57252 (Sept. 20, 2010).

12
The Commissions' joint proposed rules and guidelines were published in the
Federal Register
on March 6, 2012.
See
Identity Theft Red Flags Rules, 77 FR 13450 (Mar. 6, 2012) (“Proposing Release”). For ease of reference, unless the context indicates otherwise, our general use of the terms “identity theft red flags rules” or “rules” in this release will refer to both the identity theft red flags rules and guidelines. In addition, unless the context indicates otherwise, the general use of these terms in this preamble and Section III of this release will refer to both the identity theft red flags rules and guidelines, and the card issuer rules (which are discussed in further detail later in this release).

The CFTC and SEC received a total of 27 comment letters on the proposal.
13

Most commenters generally supported the proposal, and many stated that the rules would benefit individuals.
14

Commenters expressed concern about the prevalence of identity theft and supported our efforts to reduce it.
15

Commenters also supported the Commissions' proposal to adopt rules that would be substantially similar to the rules the Agencies adopted in 2007.
16

Some commenters raised questions about the scope of the proposal and the meaning of certain definitions.
17

One commenter stated that benefits to consumers would outweigh the costs of the rules,
18

while another took issue with the estimated costs of complying with the rules.
19

13
Comments on the proposal, including comments referenced in this release, are available on the SEC's Web site at
http://www.sec.gov/comments/s7-02-12/s70212.shtml
and the CFTC's Web site at
http://comments.cftc.gov/PublicComments/CommentList.aspx?id=1171.

14

See, e.g.,
Comment Letter of MarketCounsel (Apr. 25, 2012) (“MarketCounsel Comment Letter”) (“MarketCounsel supports the Commission's attempt to help protect individuals from the risk of theft, loss, and abuse of their personal information through the Proposed Rule.”); Comment Letter of Erik Speicher (“Erik Speicher Comment Letter”) (Mar. 17, 2012) (“Identity theft is a major concern of all citizens. The effects and burdens associated with having ones [sic] identity stolen necessitate these proposed regulations. The affirmative duty placed on the covered entities will better protect all of us from the possibility of having our identity stolen.”); Comment Letter of Lauren L. (Mar. 12, 2012) (“Lauren L. Comment Letter”) (“[R]equirements to implement an identity theft prevention plan and to verify change of personal information [have] the [potential] to protect people.”).

15

See, e.g.,
Tyler Krulla Comment Letter; Lauren L. Comment Letter (“I agree with the proposed changes. With the market shifting to an IT based world, identity theft is increasing. Therefore, more stringent rules and regulations should be in place to protect those that may be affected.”).

16

See, e.g.,
Comment Letter of the Investment Company Institute (May 1, 2012) (“ICI Comment Letter”).

17

See, e.g.,
Comment Letter of the Investment Adviser Association (May 7, 2012) (“IAA Comment Letter”) (requesting that the SEC and CFTC clarify the definitions of “financial institution” and “creditor” and exclude investment advisers from the categories of entities specifically mentioned in the scope section of the rule); Comment Letter of the Options Clearing Corporation (May 3, 2012) (“OCC Comment Letter”) (requesting that the SEC and CFTC clarify the definition of “creditor” and expressly exclude clearing organizations from the scope section of the rule); Comment Letter of the Financial Services Roundtable and the Securities Industry and Financial Markets Association (May 2, 2012) (“FSR/SIFMA Comment Letter”) (requesting that the SEC specifically exclude certain categories of entities from the definitions of “financial institution” and “covered account,” and that the SEC and CFTC specifically define the types of accounts that would qualify as covered accounts).

18

See
Erik Speicher Comment Letter.

19

See
FSR/SIFMA Comment Letter. We discuss estimated costs and benefits in the Section III of this release.

Today, the CFTC and SEC are adopting the identity theft red flags rules. The final rules are substantially similar to the rules the Commissions proposed,
20

and to the rules the Agencies adopted in 2007.
21

The final rules apply to “financial institutions” and “creditors” subject to the Commissions' respective enforcement authorities, and as discussed further below, do not exclude any entities registered with the Commissions from their scope. The Commissions recognize that entities subject to their respective enforcement authorities, whose activities fall within the scope of the rules, should already be in compliance with the Agencies' joint rules. The rules we are adopting today do not contain requirements that were not already in the Agencies' rules, nor do they expand the scope of those rules to include new categories of entities that the Agencies' rules did not already cover. The rules and this adopting release do contain examples and minor language changes designed to help guide entities within the SEC's enforcement authority in complying with the rules, which may lead some entities that had not previously complied with the Agencies' rules to determine that they fall within the scope of the rules we are adopting today.

20

See infra
Section II.A.1.ii (discussing a revision to proposed definition of “creditor”);
see also
§ 248.201(b)(2)(i) (SEC) (revising the term “non U.S. based financial institution or creditor,” which was included in the proposed definition of “board of directors,” to “foreign financial institution or creditor,” for clarity and consistency with the CFTC's and Agencies' respective identity theft red flags rules).

21

See
2007 Adopting Release.

II. Explanation of the Final Rules and Guidelines

A. Final Identity Theft Red Flags Rules

Sections 615(e)(1)(A) and (B) of the FCRA, as amended by the Dodd-Frank Act, require that the Commissions jointly establish and maintain guidelines for “financial institutions” and “creditors” regarding identity theft, and adopt rules requiring such institutions and creditors to establish reasonable policies and procedures for the implementation of those guidelines.
22

Under the final rules, a financial institution or creditor that offers or maintains “covered accounts” must establish an identity theft red flags program designed to detect, prevent, and mitigate identity theft. To that end, the final rules discussed below specify: (1) Which financial institutions and creditors must develop and implement a written identity theft prevention program (“Program”); (2) the objectives of the Program; (3) the elements that the Program must contain; and (4) the steps financial institutions and creditors need to take to administer the Program.

22
15 U.S.C. 1681m(e)(1)(A) and (B). Key terms such as “financial institution” and “creditor” are defined in the rules and discussed later in this Section.

1. Which Financial Institutions and Creditors Are Required To Have a Program

The “scope” subsections of the rules generally set forth the types of entities that are subject to the Commissions' identity theft red flags rules.
23

Under these subsections, the rules apply to entities over which Congress recently granted the Commissions enforcement authority under the FCRA.
24

The Commissions' scope provisions are similar to those contained in the rules adopted by the Agencies, which limit the rules' scope to entities that are within the Agencies' respective enforcement authorities.
25

23
§ 162.30(a) (CFTC); § 248.201(a) (SEC).

24
Section 1088(a)(10)(A) of the Dodd-Frank Act amended section 621(b) of the FCRA to add the Commissions to the list of federal agencies responsible for enforcement of the FCRA. As amended, section 621(b) of the FCRA specifically provides that enforcement of the requirements imposed under the FCRA “shall be enforced under * * * the Commodity Exchange Act, with respect to a person subject to the jurisdiction of the [CFTC]; [and under] the Federal securities laws, and any other laws that are subject to the jurisdiction of the [SEC], with respect to a person that is subject to the jurisdiction of the [SEC] * * *” 15 U.S.C. 1681s(b)(1)(F)-(G).
See also
15 U.S.C. 1681a(f) (defining “consumer reporting agency”).

25

See, e.g.,
12 CFR 334.90(a) (stating that the FDIC's red flags rule “applies to a financial institution or creditor that is an insured state nonmember bank, insured state licensed branch of a foreign bank, or a subsidiary of such entities (except brokers, dealers, persons providing insurance, investment companies, and investment advisers)”); 12 CFR 717.90(a) (stating that the NCUA's red flags rule “applies to a financial institution or creditor that is a federal credit union”).

As noted above, the CFTC's “scope” subsection “applies to financial institutions and creditors that are subject to” the CFTC's enforcement authority under the FCRA.
26

The CFTC's proposed definitions of “financial institution” and “creditor” describe the entities to which its identity theft red flags rules and guidelines apply. In the Proposing Release, the CFTC defined “financial institution” as having the same meaning as in section 603(t) of the FCRA.
27

In addition, the CFTC's proposed definition of “financial institution” also specified that the term includes any futures commission merchant (“FCM”), retail foreign exchange dealer (“RFED”), commodity trading advisor (“CTA”), commodity pool operator (“CPO”), introducing broker (“IB”), swap dealer (“SD”), or major swap participant (“MSP”) that directly or indirectly holds a transaction account belonging to a consumer.
28

Similarly, in the CFTC's proposed definition of “creditor,” the CFTC applies the definition of “creditor” from 15 U.S.C. 1681m(e)(4) to any FCM, RFED, CTA, CPO, IB, SD, or MSP that “regularly extends, renews, or continues credit; regularly arranges for the extension, renewal, or continuation of credit; or in acting as an assignee of an original creditor, participates in the decision to extend, renew, or continue credit.”
29

The CFTC has determined that the final identity theft red flags rules apply to these entities because of the increased likelihood that these entities open or maintain covered accounts, or pose a reasonably foreseeable risk to customers, or to the safety and soundness of the financial institution or creditor, from identity theft. This approach is consistent with the general scope of part 162 of the CFTC's regulations.
30

26
§ 162.30(a);
see also supra
note 24.

27

See
15 U.S.C. 1681a(t) (defining “financial institution” to include certain banks and credit unions, and “any other person that, directly or indirectly, holds a transaction account (as defined in Section 19(b) of the Federal Reserve Act) belonging to a consumer”). Section 19(b) of the Federal Reserve Act defines a transaction account as “a deposit or account on which the depositor or account holder is permitted to make withdrawals by negotiable or transferable instrument, payment orders or withdrawal, telephone transfers, or other similar items for the purpose of making payments or transfers to third parties or others.” 12 U.S.C. 461(b)(1)(C).)

28
§ 162.30(b)(7).

29
§ 162.30(b)(5).

30
§ 162.1(b) (specifying that “[t]his part applies to certain consumer information held by * * * futures commission merchants, retail foreign exchange dealers, commodity trading advisors, commodity pool operators, introducing brokers, major swap participants and swap dealers.”)

One commenter suggested that the CFTC follow the SEC's approach and simply cross-reference the FCRA definition of “financial institution” and the FCRA definition of “creditor” as amended by the Red Flag Program Clarification Act of 2010 (“Clarification Act”)
31

rather than including named entities in the definition.
32

The commenter argued that cross-referencing the FCRA definitions, as amended by the Clarification Act, rather than including specific types of entities that are subject to the CFTC's enforcement authority in the definitions of “financial institution” and “creditor,” would be more consistent with the SEC's and the Agencies' regulations and would allow the agencies to easily adapt to any changes to the FCRA over time.
33

31
In December 2010, President Obama signed into law the Red Flag Program Clarification Act of 2010, which amended the definition of “creditor” in the FCRA for purposes of identity theft red flags rules. Red Flag Program Clarification Act of 2010, Public Law 111-319 (2010) (inserting new section 4 at the end of section 615(e) of the FCRA),
codified at
15 U.S.C. 1681m(e)(4).

32
IAA Comment Letter.

33
The commenter also noted that the CFTC's proposed definition of “creditor” would include certain entities such as CPOs and CTAs—entities that do not extend credit.

After considering these concerns, the CFTC has concluded that if it were to follow the SEC's approach and simply cross-reference the FCRA definitions of “financial institution” and “creditor,” the general scope provisions of 17 CFR part 162 would still apply and specify that part 162 applies to FCMs, RFEDs, CTAs, CPOs, IBs, MSPs, and SDs. As a practical matter, a cross-reference to the FCRA definitions of “financial institution” and “creditor” would not change the result because under the general scope provisions of part 162, the CFTC's identity theft red flags rules would still apply to the same list of entities. As a result, the CFTC believes that it should retain the same definition of “financial institution” and “creditor” contained in the Proposing Release.

The SEC's “scope” subsection provides that the final rules apply to a financial institution or creditor, as defined by the FCRA, that is:

• A broker, dealer or any other person that is registered or required to be registered under the Securities Exchange Act of 1934 (“Exchange Act”);

• An investment company that is registered or required to be registered under the Investment Company Act of 1940 (“Investment Company Act”), that has elected to be regulated as a business

development company (“BDC”) under that Act, or that operates as an employees' securities company (“ESC”) under that Act; or

• An investment adviser that is registered or required to be registered under the Investment Advisers Act of 1940 (“Investment Advisers Act”).
34

34
§ 248.201(a).

The types of entities listed by name in the scope section are the registered entities regulated by the SEC that are most likely to be financial institutions or creditors,
i.e.,
brokers or dealers (“broker-dealers”), investment companies, and investment advisers.
35

The scope section also includes any other entities that are registered or are required to register under the Exchange Act.
36

Some types of entities required to register under the Exchange Act, such as nationally recognized statistical rating organizations (“NRSROs”), self-regulatory organizations (“SROs”), municipal advisors, and municipal securities dealers, are not listed by name in the scope section because they may be less likely to qualify as financial institutions or creditors under the FCRA.
37

Nevertheless, if any entity of a type not listed qualifies as a financial institution or creditor, it is covered by the SEC's rules. The scope section does not include entities that are not themselves registered or required to register with the SEC (with the exception of certain non-registered investment companies that nonetheless are regulated by the SEC
38

), even if they register securities under the Securities Act of 1933 or the Exchange Act, or report information under the federal securities laws.
39

35
The SEC's final rules define the scope of the identity theft red flags rules, section 248.201(a), differently than Regulation S-AM, the affiliate marketing rule the SEC adopted under the FCRA, defines its scope.
See
17 CFR 248.101(b) (providing that Regulation S-AM applies to any brokers or dealers (other than notice-registered brokers or dealers), any investment companies, and any investment advisers or transfer agents registered with the SEC). Section 214(b) of the FACT Act, pursuant to which the SEC adopted Regulation S-AM, did not specify the types of entities that would be subject to the SEC's rules, and did not state that the affiliate marketing rules should apply to all persons subject to the SEC's enforcement authority. By contrast, the Dodd-Frank Act specifies that the SEC's identity theft red flags rules should apply to a “person that is subject to the jurisdiction” of the SEC.
See
Dodd-Frank Act sections 1088(a)(8), (10). Therefore, the SEC's identity theft red flags rules apply to BDCs, ESCs, and “any * * * person that is registered or required to be registered under the Securities Exchange Act of 1934,” as well as to those entities within the scope of Regulation S-AM.

The scope of the SEC's final rules also differs from that of Regulation S-P, 17 CFR part 248, subpart A, the privacy rule the SEC adopted in 2000 pursuant to the Gramm-Leach-Bliley Act. Public Law 106-102 (1999). Regulation S-P was adopted under Title V of that Act, which, unlike the FCRA, limited the SEC's regulatory authority to: (i) Brokers and dealers; (ii) investment companies; and (iii) investment advisers registered under the Investment Advisers Act.
See
15 U.S.C. 6805(a)(3)-(5).

36
The Dodd-Frank Act defines a “person regulated by the [SEC],” for other purposes of the Act, as certain entities that are registered or required to be registered with the SEC, and certain employees, agents, and contractors of those entities.
See
Dodd-Frank Act section 1002(21).

37
The SEC believes that municipal advisors and municipal securities dealers may be less likely to qualify as financial institutions because they may be less likely to maintain transaction accounts for consumers. A commenter agreed with us that municipal advisors and municipal securities dealers may be less likely to qualify as financial institutions.
See
FSR/SIFMA Comment Letter. For further discussion, see
infra
notes 43-47 and accompanying text.

38
As noted above, the scope of the final rules covers BDCs and ESCs, which typically do not register as investment companies with the SEC but are regulated by the SEC. BDCs file with the SEC notices of reliance on the BDC provisions of the Investment Company Act and the SEC's rules thereunder.
See
Form N-54A (“Notification of Election to be Subject to Sections 55 through 65 of the Investment Company Act of 1940 Filed Pursuant to Section 54(a) of the Act”) [17 CFR 274.53]. ESCs operate pursuant to individual exemptive orders issued by the SEC that govern the companies' operations.
See
Investment Company Act section 6(b) [15 U.S.C. 80a-6(b)].

39

See, e.g.,
Exemptions for Advisers to Venture Capital Funds, Private Fund Advisers With Less Than $150 Million in Assets Under Management, and Foreign Private Advisers, Investment Advisers Act Release No. 3222 (June 22, 2011) [76 FR 39646 (July 6, 2011)] (adopting rules related to investment advisers exempt from registration with the SEC, including “exempt reporting advisers”).

The SEC received four comment letters arguing that it should specifically exclude certain entities from the scope of the rules.
40

These commenters recommended that the scope section exclude registered investment advisers,
41

clearing organizations,
42

SROs, municipal securities dealers, municipal advisors, or NRSROs.
43

The commenters argued that these entities are unlikely to be financial institutions or creditors and that, without a specific exclusion, the scope of the rules is unclear and the rules would require these entities to periodically review their operations to ensure compliance with rules that are not relevant to their businesses.
44

Another commenter recommended that the rules not list any of the types of entities subject to the rules, because such a list could confuse entities that are on the list but do not qualify as financial institutions or creditors.
45

40

See
IAA Comment Letter; Comment Letter of the National Society of Compliance Professionals, Inc. (May 4, 2012) (“NSCP Comment Letter”); OCC Comment Letter; FSR/SIFMA Comment Letter.

41

See, e.g.,
IAA Comment Letter (“[W]e believe a cleaner approach would be to eliminate investment advisers from the entities specifically mentioned in the scope section.”); NSCP Comment Letter (“We would urge the Commission to specifically exclude investment advisers from the scope of the rule since it is our view that any adviser that is a financial institution would already be covered by FCRA.”). For further discussion,
see infra
notes 55-60 and 73-76 and accompanying text.

42

See
OCC Comment Letter (“[W]e encourage the Commissions to expressly exclude clearing organizations from the scope of the Proposed Rules because, as explained below, clearing organizations like OCC should not be considered `creditors' for these purposes.”). For further discussion,
see infra
note 75.

43

See
FSR/SIFMA Comment Letter (“Specifically, we ask that the SEC exclude * * * those entities that are unlikely to be deemed financial institutions or creditors under the FCRA, such as NRSROs, SROs, municipal advisors, municipal securities dealers, and registered investment advisers.”).

44

See, e.g.,
NSCP Comment Letter.

45

See
MarketCounsel Comment Letter.

We appreciate these concerns, and seek to minimize potential unnecessary burdens on regulated entities. As we acknowledge above, the entities that are not listed in the rule's scope section may be less likely to qualify as financial institutions or creditors under the FCRA,
e.g.,
because they do not hold transaction accounts for consumers.
46

The Dodd-Frank Act required the SEC to adopt identity theft red flags rules with respect to persons that are “subject to the jurisdiction of the Securities and Exchange Commission.”
47

Expressly excluding from certain requirements of the rules any entities that are registered with the SEC, are subject to the SEC's enforcement authority, and are covered by the scope of the rules likely would not effectively implement the purposes of the Dodd-Frank Act and the FCRA, which are described in this release. In addition, we continue to believe that specifically listing in the scope section the entities that are likely to be subject to the rules—if they qualify as financial institutions or creditors—will provide useful guidance to those entities in determining their status under the rules. Therefore, we are adopting the scope section of the rules as proposed.

46

See supra
note 37 and accompanying text. For further discussion of the extent to which investment advisers, which are specifically listed in the rules' scope section, may qualify as financial institutions or creditors,
see infra
notes 55-60 and 73-76 and accompanying text.

47
15 U.S.C. 1681s(b)(1)(G).

i. Definition of Financial Institution

As discussed above, the Commissions' final red flags rules apply to “financial institutions” and “creditors.” As in the proposed rules, the Commissions are defining the term “financial institution” in the final rules by reference to the definition of the term in section 603(t) of the FCRA.
48

That section defines a

financial institution to include certain banks and credit unions, and “any other person that, directly or indirectly, holds a transaction account (as defined in section 19(b) of the Federal Reserve Act) belonging to a consumer.”
49

Section 19(b) of the Federal Reserve Act defines “transaction account” to include an “account on which the * * * account holder is permitted to make withdrawals by negotiable or transferable instrument, payment orders of withdrawal, telephone transfers, or other similar items for the purpose of making payments or transfers to third persons or others.”
50

Section 603(c) of the FCRA defines “consumer” as an individual;
51

thus, to qualify as a financial institution, an entity must hold a transaction account belonging to an individual. The following are illustrative examples of an SEC-regulated entity that could fall within the meaning of the term “financial institution” because it holds transaction accounts belonging to individuals: (i) A broker-dealer that offers custodial accounts; (ii) a registered investment company that enables investors to make wire transfers to other parties or that offers check-writing privileges; and (iii) an investment adviser that directly or indirectly holds transaction accounts and that is permitted to direct payments or transfers out of those accounts to third parties.
52

48
15 U.S.C. 1681a(t).
See
§ 162.30(b)(7) (CFTC); § 248.201(b)(7) (SEC). The Agencies also defined “financial institution,” in their identity theft red flags rules, by reference to the FCRA.
See, e.g.,
16 CFR 681.1(b)(7) (FTC) (“Financial institution has the same meaning as in 15 U.S.C. 1681a(t).”).

49
15 U.S.C. 1681a(t). In full, the FCRA defines “financial institution” to mean “a State or National bank, a State or Federal savings and loan association, a mutual savings bank, a State or Federal credit union, or any other person that, directly or indirectly, holds a transaction account [as defined in section 19(b) of the Federal Reserve Act] belonging to a consumer.”
Id.

50
12 U.S.C. 461(b)(1)(C). Section 19(b) further states that a transaction account “includes demand deposits, negotiable order of withdrawal accounts, savings deposits subject to automatic transfers, and share draft accounts.”
Id.

51
15 U.S.C. 1681a(c).

52
The CFTC's definition specifies that financial institution “includes any futures commission merchant, retail foreign exchange dealer, commodity trading advisor, commodity pool operator, introducing broker, swap dealer, or major swap participant that directly or indirectly holds a transaction account belonging to a consumer.”
See
§ 162.30(b)(7).

A few commenters raised concerns about the SEC's statements in the Proposing Release regarding the possibility that some investment advisers could be financial institutions under certain circumstances. These commenters argued that investment advisers generally do not “hold” transaction accounts, thus meaning that they would
not
be financial institutions under the definition.
53

One commenter requested that we state that investment advisers who are authorized to withdraw assets from investors' accounts to pay bills, or otherwise direct payments to third parties, on behalf of investors do not “indirectly” hold such accounts and therefore are not financial institutions.
54

53

See, e.g.,
IAA Comment Letter (“Investment advisers are not banks or credit unions and do not hold transaction accounts, such as custodial accounts or accounts with check-writing privileges. Instead, any cash or securities managed by investment advisers must be held in custody with financial institutions that are qualified custodians (broker-dealers or banks, primarily).”).

54

See
MarketCounsel Comment Letter (“MarketCounsel requests additional clarification in the Proposed Rule to make it clear that an investment adviser will not be deemed to indirectly hold a transaction account simply because it has control over, or access to, the transaction account.”).

The SEC has concluded otherwise. As described below, some investment advisers do hold transaction accounts, both directly and indirectly, and thus may qualify as financial institutions under the rules as we are adopting them. As discussed further in Section III of this release, SEC staff anticipates that the following examples of circumstances in which certain entities, particularly investment advisers, may qualify as financial institutions may lead some of these entities that had not previously complied with the Agencies' rules to now determine that they should comply with Regulation S-ID.
55

55
SEC staff understands, based on comment letters and communications with industry representatives, that a number of investment advisers may not currently have identity theft red flags Programs.
See
MarketCounsel Comment Letter; IAA Comment Letter. SEC staff also expects, based on Investment Adviser Registration Depository (IARD) data, that certain private fund advisers could potentially meet the definition of “financial institution” or “creditor.”
See infra
note 190.

Investment advisers who have the ability to direct transfers or payments from accounts belonging to individuals to third parties upon the individuals' instructions, or who act as agents on behalf of the individuals, are susceptible to the same types of risks of fraud as other financial institutions, and individuals who hold transaction accounts with these investment advisers bear the same types of risks of identity theft and loss of assets as consumers holding accounts with other financial institutions. If such an adviser does not have a program in place to verify investors' identities and detect identity theft red flags, another individual may deceive the adviser by posing as an investor. The red flags program of a bank or other qualified custodian
56

that maintains physical custody of an investor's assets would not adequately protect individuals holding transaction accounts with such advisers, because the adviser could give an order to withdraw assets, but at the direction of an impostor.
57

Investors who entrust their assets to registered investment advisers that directly or indirectly hold transaction accounts should receive the protections against identity theft provided by these rules.

56

See
17 CFR 275.206(4)-2(d)(6) (setting forth the entities that fall within the definition of “qualified custodian”).

57

See, e.g.,
Byron Acohido,
Cybercrooks fool financial advisers to steal from clients,
USA Today, Aug. 26, 2012,
available at

http://usatoday30.usatoday.com/money/perfi/basics/story/2012-08-26/wire-transfer-fraud/57335540/1
(last visited March 4, 2013) (“In a new twist, cyber-robbers are using ginned-up email messages in attempts to con financial advisers into wiring cash out of their clients' online investment accounts. If the adviser falls for it, a wire transfer gets legitimately executed, and cash flows into a bank account controlled by the thieves—leaving the victim in a dispute with the financial adviser over getting made whole.”).

For instance, even if an investor's assets are physically held with a qualified custodian, an adviser that has authority, by power of attorney or otherwise, to withdraw money from the investor's account and direct payments to third parties according to the investor's instructions would hold a transaction account. However, an adviser that has authority to withdraw money from an investor's account solely to deduct its own advisory fees would not hold a transaction account, because the adviser would not be making the payments to third parties.
58

58

See supra
note 50 and accompanying text.

Registered investment advisers to private funds also may directly or indirectly hold transaction accounts.
59

If an individual invests money in a private fund, and the adviser to the fund has the authority, pursuant to an arrangement with the private fund or the individual, to direct such individual's investment proceeds (
e.g.,
redemptions, distributions, dividends, interest, or other proceeds related to the individual's account) to third parties, then that adviser would indirectly hold a transaction account. For example, a private fund adviser would hold a transaction account if it has the authority to direct an investor's redemption proceeds to other persons upon instructions received from the investor.
60

59
A “private fund” is “an issuer that would be an investment company, as defined in section 3 of the Investment Company Act, but for section 3(c)(1) or 3(c)(7) of that Act.” 15 U.S.C. 80b-2(a)(29).

60
On the other hand, an investment adviser may not hold a transaction account if the adviser has a narrowly-drafted power of attorney with an investor under which the adviser has no authority to redirect the investor's investment proceeds to third parties or others upon instructions from the investor.

ii. Definition of Creditor

The Commissions' final definitions of “creditor” refer to the definition of

“creditor” in the FCRA as amended by the Clarification Act.
61

The FCRA now defines “creditor,” for purposes of the red flags rules, as a creditor as defined in the Equal Credit Opportunity Act
62

(“ECOA”) (
i.e.,
a person that regularly extends, renews or continues credit,
63

or makes those arrangements) that “regularly and in the course of business * * * advances funds to or on behalf of a person, based on an obligation of the person to repay the funds or repayable from specific property pledged by or on behalf of the person.”
64

The FCRA excludes from this definition a creditor that “advances funds on behalf of a person for expenses incidental to a service provided by the creditor to that person * * *”
65

61

See
§ 162.30(b)(5) (CFTC); § 248.201(b)(5) (SEC);
see also supra
note 31.

62
Section 702(e) of the ECOA defines “creditor” to mean “any person who regularly extends, renews, or continues credit; any person who regularly arranges for the extension, renewal, or continuation of credit; or any assignee of an original creditor who participates in the decision to extend, renew, or continue credit.” 15 U.S.C. 1691a(e).

63
The Commissions are defining “credit” by reference to its definition in the FCRA.
See
§ 162.30(b)(4) (CFTC); § 248.201(b)(4) (SEC). That definition refers to the definition of credit in the ECOA, which means “the right granted by a creditor to a debtor to defer payment of debt or to incur debts and defer its payment or to purchase property or services and defer payment therefor.” The Agencies defined “credit” in the same manner in their identity theft red flags rules.
See, e.g.,
16 CFR 681.1(b)(4) (FTC) (defining “credit” as having the same meaning as in 15 U.S.C. 1681a(r)(5), which defines “credit” as having the same meaning as in section 702 of the ECOA).

64
15 U.S.C. 1681m(e)(4)(A)(iii). The FCRA defines a “creditor” also to include a creditor (as defined in the ECOA) that “regularly and in the ordinary course of business (i) obtains or uses consumer reports, directly or indirectly, in connection with a credit transaction; (ii) furnishes information to consumer reporting agencies * * * in connection with a credit transaction * * *” 15 U.S.C. 1681m(e)(4)(A)(i)-(ii).

65
FCRA section 615(e)(4)(B), 15 U.S.C. 1681m(e)(4)(B). The Clarification Act does not define the extent to which the advancement of funds for expenses would be considered “incidental” to services rendered by the creditor. The legislative history indicates that the Clarification Act was intended to ensure that lawyers, doctors, and other small businesses that may advance funds to pay for services such as expert witnesses, or that may bill in arrears for services provided, should not be considered creditors under the red flags rules.
See
156 Cong. Rec. S8288-9 (daily ed. Nov. 30, 2010) (statements of Senators Thune and Dodd).

The CFTC's definition of “creditor” includes certain entities (such as FCMs and CTAs) that regularly extend, renew or continue credit or make those credit arrangements.
66

The proposed definition applies the definition of “creditor” from 15 U.S.C. 1681m(e)(4) to “any futures commission merchant, retail foreign exchange dealer, commodity trading advisor, commodity pool operator, introducing broker, swap dealer, or major swap participant that regularly extends, renews, or continues credit; regularly arranges for the extension, renewal, or continuation of credit; or in acting as an assignee of an original creditor, participates in the decision to extend, renew, or continue credit.”
67

One commenter stated that the proposed definition was overly broad and unclear because it did not appear to include derivative clearing organizations (“DCOs”) such as the Options Clearing Corporation, while the SEC's definition could be read to include DCOs, and recommended that DCOs be explicitly excluded from the definition.
68

The commenter further requested that the Commissions specifically exclude DCOs from the scope of the Proposed Rules.

66

See
§ 162.30(b)(5).

67

See
§ 162.30(b)(7).

68
OCC Comment Letter.

As the commenter noted, the CFTC's definition of “creditor” excludes DCOs because DCOs are not included on the list of entities that may qualify as creditors under the rule. Under the proposed CFTC rules, a “creditor” includes any FCM, RFED, CTA, CPO, IB, SD, or MSP that regularly extends, renews, or continues credit or makes credit arrangements. Unlike DCOs, the listed entities which are included in the CFTC definition of “creditor” engage in retail customer business and maintain retail customer accounts. These entities are included as potential creditors in the definition because they are the CFTC registrants most likely to collect personal consumer data. Moreover, this list of potential creditors is consistent with the general scope provisions of the part 162 rules, which also apply to FCMs, RFEDs, CTAs, CPOs, IBs, SDs, or MSPs.
69

Accordingly, the CFTC declines to provide a specific exclusion for DCOs from the scope of the rule.

69

See
§ 162.1(b).

As proposed, the SEC's definition of “creditor” referred to the definition of “creditor” under FCRA, and stated that it “includes lenders such as brokers or dealers offering margin accounts, securities lending services, and short selling services.”
70

The SEC proposed to name these entities in the definition because they are likely to qualify as “creditors,” since the funds advanced in these accounts do not appear to be for “expenses incidental to a service provided.” One commenter, the Options Clearing Corporation, argued that the proposed definition's reference to securities lending services could be read to mean that an intermediary in securities lending transactions is a “creditor” under the SEC's rules, even if the entity does not meet FCRA's definition of “creditor.”
71

The SEC intended the proposed definition of “creditor” to be limited to the FCRA definition, and to include relevant examples of activities that could qualify an entity as a creditor. In order to clarify this definition and avoid an inadvertently broad meaning of the term “creditor,” we are revising the definition to rely on FCRA's statutory definition of the term and omit the references to specific types of lending, such as margin accounts, securities lending services, and short selling services.
72

70

See
proposed § 248.201(b)(5).

71
OCC Comment Letter.

72

See
§ 248.201(b)(5).

Some commenters stated that most investment advisers would probably not qualify as creditors under the definition.
73

One commenter believed that the proposal might have implied that investment advisers were subject to a different standard than other entities under the definition of “creditor,” and requested that we clarify that investment advisers may, like all other entities, take advantage of the exception in the definition to advance funds on behalf of a person for expenses incidental to a service provided by the creditor to that person.
74

Our final rules do not treat investment advisers differently than any other entity under the definition of “creditor.”
75

An investment adviser could potentially qualify as a creditor if it “advances funds” to an investor that are not for expenses incidental to services provided by that adviser. For example, a private

fund adviser that regularly and in the ordinary course of business lends money, short-term or otherwise, to permit investors to make an investment in the fund, pending the receipt or clearance of an investor's check or wire transfer, could qualify as a creditor.
76

73

See, e.g.,
MarketCounsel Comment Letter; NSCP Comment Letter (“We agree with the proposal that investment advisers are not creditors for purposes of the proposal because advisers generally do not bill in arrears. We are not aware of any situation where an investment adviser would advance funds and we would note that such advisers would likely run afoul of state rules that prohibit an adviser from loaning funds or borrowing funds from a client.”).

74
MarketCounsel Comment Letter.

75
The definition of “creditor” in FCRA also authorizes the Agencies and the Commissions to include other entities in the definition of “creditor” if the Commissions determine that those entities offer or maintain accounts that are subject to a reasonably foreseeable risk of identity theft. 15 U.S.C. 1681m(e)(4)(C). One commenter urged the Commissions not to exercise this authority, and particularly not to include clearing organizations as creditors under the definition.
See
OCC Comment Letter (“We believe there is no reasonable basis for concluding that the securities loan clearing services offered by OCC as described above would pose a reasonably foreseeable risk of identity theft or that such services should cause OCC to be considered a `creditor.'”). The Commissions did not propose to specifically include clearing organizations in the definition of “creditor” under this authority, and the final rules do not include any additional types of entities in the definition of “creditor” that are not already included in the statutory definition.

76
However, a private fund adviser would not qualify as a creditor solely because its private funds regularly borrow money from third-party credit facilities pending receipt of investor contributions, as the definition of “creditor” does not include “indirect” creditors.

iii. Definition of Covered Account and Other Terms

Under the final rules, a financial institution or creditor must establish a red flags Program if it offers or maintains “covered accounts.” As in the proposed rules, the Commissions are defining the term “covered account” in the final rules as: (i) An account that a financial institution or creditor offers or maintains, primarily for personal, family, or household purposes, that involves or is designed to permit multiple payments or transactions; and (ii) any other account that the financial institution or creditor offers or maintains for which there is a reasonably foreseeable risk to customers
77

or to the safety and soundness of the financial institution or creditor from identity theft, including financial, operational, compliance, reputation, or litigation risks.
78

The CFTC's definition includes a margin account as an example of a covered account.
79

The SEC's definition includes, as examples of a covered account, a brokerage account with a broker-dealer or an account maintained by a mutual fund (or its agent) that permits wire transfers or other payments to third parties.
80

77
To be a financial institution, an entity must hold a transaction account with at least one “consumer” (defined as an “individual” in 15 U.S.C. 1681a(c)). However, once an entity is a financial institution, it must periodically determine whether it offers or maintains “covered accounts” to or on behalf of its customers, which may be individuals or business entities. Sections 162.30(b)(6) (CFTC) and 248.201(b)(6) (SEC) define “customer” to mean a person that has a covered account with a financial institution or creditor. The Commissions are including this definition for two reasons. First, this definition is the same as the definition of “customer” in the Agencies' final rules. Second, because the definition uses the term “person,” it covers various types of business entities (
e.g.,
small businesses) that could be victims of identity theft. 15 U.S.C. 1681a(b). Although the definition of “customer” is broad, not every account held by or offered to a customer will be considered a covered account, as the identification of covered accounts under the identity theft red flags rules is based on a risk-based determination.
See infra
notes 95-100 and accompanying text.

78
§ 162.30(b)(3) (CFTC) and § 248.201(b)(3) (SEC). The Agencies' 2007 Adopting Release (which included an identical definition of the term “account”) noted that “the definition of `account' still applies to fiduciary, agency, custodial, brokerage and investment advisory activities.” 2007 Adopting Release
supra
note 8, at 63721.

79

See
§ 162.30(b)(3)(i).

80

See
§ 248.201(b)(3)(i).

The Commissions are defining an “account” as a “continuing relationship established by a person with a financial institution or creditor to obtain a product or service for personal, family, household or business purposes.”
81

The CFTC's definition specifically includes an extension of credit, such as the purchase of property or services involving a deferred payment.
82

The SEC's definition includes, as examples of accounts, “a brokerage account, a mutual fund account (
i.e.,
an account with an open-end investment company), and an investment advisory account.”
83

81
§ 162.30(b)(1) (CFTC) and § 248.201(b)(1) (SEC). Two commenters requested further guidance on the meaning of “continuing relationship” in the proposed definition of the term “account.” Comment Letter of Nathaniel Washburn (April 12, 2012); Comment Letter of Chris Barnard (“Chris Barnard Comment Letter”) (Mar. 29, 2012). The SEC and the CFTC's definition of “account” is the same as that adopted by the Agencies. The Agencies' 2007 Adopting Release provides further guidance on the meaning of continuing relationship, noting that it is designed to exclude single, non-continuing transactions by non-customers. 2007 Adopting Release
supra
note 8, at 63721.

82
§ 162.30(b)(1).

83
§ 248.201(b)(1).

In the Proposing Release, the Commissions noted that “entities that adopt red flags Programs would focus their attention on `covered accounts' for indicia of possible identity theft.”
84

In response to this statement, one commenter recommended revising the definition of “covered account” such that entities adopting red flags Programs would focus particularly on protecting various types of information provided by customers, rather than focusing on particular categories of accounts.
85

The Commissions have decided not to revise the definition of “covered account” as suggested by this commenter, because the Commissions believe that by focusing the rules on the types of accounts that might pose a reasonably foreseeable risk of identity theft, financial institutions and creditors are best able to protect the information that customers provide in the course of holding these accounts. Moreover, the current definition and scope of the term “covered account” are similar to the provisions of the other Agencies' identity theft red flags rules.
86

As discussed below, the Commissions believe that the final rules' terms should be defined as the Agencies defined them in their respective final rules, where appropriate, to foster consistent regulations.
87

84
77 FR 13450, 13454.

85

See
Comment Letter of Kenneth Orgoglioso (May 7, 2012).

86

See, e.g.,
16 CFR 681.1(b)(3).

87

See infra
note 93 and accompanying text.

Two commenters argued that insurance company separate accounts are unlikely to be covered accounts because they are not established for personal, family, or household purposes and do not pose a reasonably foreseeable risk of identity theft.
88

They contended that insurance company separate accounts are investment vehicles underlying variable life and annuity insurance products, and generally individual customers do not have a direct relationship with these accounts. One of the commenters requested that the definition of “covered account” specifically exclude insurance company separate accounts.
89

The commenter noted that because third parties and customers do not have direct access to insurance company separate accounts, there is little risk of identity theft in these accounts.
90

88
Comment Letter of the American Council of Life Insurers (May 7, 2012); FSR/SIFMA Comment Letter.

89
FSR/SIFMA Comment Letter.

90

See id.
(“Further, third parties, including customers, do not have direct access to Separate Accounts, which means that the types of identity theft risks anticipated by the proposed Red Flags Rules are essentially nonexistent.”).

The final rules require all financial institutions and creditors to assess whether they offer or maintain covered accounts. Although, as discussed above, some commenters suggested that insurance company separate accounts may not qualify as covered accounts under the definition, the final rule does not exclude insurance company separate accounts from the definition of “covered account” because it would be impracticable to provide an exhaustive list of account types that are not covered accounts. Similarly, one commenter requested that the SEC list all of the types of accounts that would be “covered accounts” under the rules.
91

The rules provide examples of covered accounts, but we cannot anticipate all of the types of accounts that could be covered accounts. Any list that attempts to encompass all types of covered accounts would likely be under-inclusive and would not take into account future business practices.
92

The

definition of “covered account” is deliberately designed to be flexible to allow the financial institution or creditor to determine which accounts pose a reasonably foreseeable risk of identity theft and protect them accordingly. Therefore, we are adopting the definitions of “account” and “covered account” as they were proposed.

91

Id.

92
For example, an institution that holds only business accounts may decide later to offer accounts for personal, family, or household purposes that permit multiple payments. The rule's requirement that a financial institution or creditor periodically determine whether it holds covered accounts is designed to require that these entities re-evaluate whether they in fact hold any covered accounts.
See infra
notes 95 and 96 and accompanying text.

The identity theft red flags rules also define several other terms as the Agencies defined them in their final rules, where appropriate, to foster consistent regulations.
93

In addition, terms that the SEC's rules do not define have the same meaning they have in FCRA.
94

93

See
§ 162.30(b)(4) (CFTC) and § 248.201(b)(4) (SEC) (definition of “credit”); § 162.30(b)(6) (CFTC) and § 248.201(b)(6) (SEC) (definition of “customer”); § 162.30(b)(7) (CFTC) and § 248.201(b)(7) (SEC) (definition of “financial institution”); § 162.30(b)(10) (CFTC) and § 248.201(b)(10) (SEC) (definition of “red flag”); § 162.30(b)(11) (CFTC) and § 248.201(b)(11) (SEC) (definition of “service provider”).

The Agencies defined “identity theft” in their identity theft red flags rules by referring to a definition previously adopted by the FTC.
See, e.g.,
12 CFR 334.90(b)(8) (FDIC). The FTC defined “identity theft” as “a fraud committed or attempted using the identifying information of another person without authority.”
See
16 CFR 603.2(a). The FTC also has defined “identifying information,” a term used in its definition of “identity theft.”
See
16 CFR 603.2(b). The Commissions are defining the terms “identifying information” and “identity theft” by including the same definitions of the terms as they appear in 16 CFR 603.2.
See
§ 162.30(b)(8) and (9) (CFTC); § 248.201(b)(8) and (9) (SEC). One commenter suggested that we add the following highlighted language to the definition of “identity theft” so that it would read a “fraud, deception, or other crime committed or attempted using the identifying information of another person without authority.” Chris Barnard Comment Letter. Changing the definition of “identity theft” so that it differs from the definition used by the Agencies could lead to higher compliance costs, reduce comparability of the Agencies' rules in contravention of the statutory mandate, and pose difficulties for entities within the enforcement authority of multiple agencies. Accordingly, we are adopting the definition of “identity theft” as it was proposed.

94

See
§ 248.201(b)(12)(vi) (SEC).

iv. Determination of Whether a Covered Account Is Offered or Maintained

As under the proposed rules, under the final rules, each financial institution or creditor must periodically determine whether it offers or maintains covered accounts.
95

As a part of this periodic determination, a financial institution or creditor must conduct a risk assessment that takes into consideration: (1) The methods it provides to open its accounts; (2) the methods it provides to access its accounts; and (3) its previous experiences with identity theft.
96

A financial institution or creditor should consider whether, for example, a reasonably foreseeable risk of identity theft may exist in connection with accounts it offers or maintains that may be opened or accessed remotely or through methods that do not require face-to-face contact, such as through email or the Internet, or by telephone. In addition, if financial institutions or creditors offer or maintain accounts that have been the target of identity theft, they should factor those experiences into their determination. The Commissions anticipate that entities will be able to demonstrate that they have complied with applicable requirements, including their recurring determinations regarding covered accounts.
97

95
§ 162.30(c) (CFTC) and § 248.201(c) (SEC).

96
§ 162.30(c) (CFTC) and § 248.201(c) (SEC).

97

See, e.g.,
Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies at I.1,
available at http://www.ftc.gov/os/2009/06/090611redflagsfaq.pdf
(noting in joint interpretive guidance provided by the Agencies' staff that, while the Agencies' 2007 identity theft rules do not contain specific record retention requirements, financial institutions and creditors must be able to demonstrate that they have complied with the rules' requirements).

The Commissions acknowledge that some financial institutions or creditors regulated by the Commissions do not offer or maintain accounts for personal, family, or household purposes,
98

and engage predominantly in transactions with businesses, where the risk of identity theft is minimal. In these instances, the financial institution or creditor may determine after a preliminary risk assessment that the accounts it offers or maintains do not pose a reasonably foreseeable risk to customers or to its own safety and soundness from identity theft, and therefore it does not need to develop and implement a Program because it does not offer or maintain any “covered accounts.”
99

Alternatively, the financial institution or creditor may determine that only a limited range of its accounts present a reasonably foreseeable risk to customers, and therefore may decide to develop and implement a Program that applies only to those accounts or types of accounts.
100

As proposed, under the final rules, a financial institution or creditor that initially determines that it does not need to have a Program is required to periodically reassess whether it must develop and implement a Program in light of changes in the accounts that it offers or maintains and the various other factors set forth in sections 162.30(c) (CFTC) and 248.201(c) (SEC).

98

See
§ 162.30(b)(3)(i) (CFTC) and § 248.201(b)(3)(i) (SEC).

99

See
§ 162.30(b)(3)(ii) (CFTC) and § 248.201(b)(3)(ii) (SEC). For example, an FCM that is otherwise subject to the identity theft red flags rules and that handles accounts only for large, institutional investors might make a risk-based determination that because it is subject to a low risk of identity theft, it does not need to develop and implement a Program. Similarly, a money market fund that is otherwise subject to the identity theft red flags rules but that permits investments only by other institutions and separately verifies and authenticates transaction requests might make such a risk-based determination that it need not develop a Program.

100
Even a Program limited in scale, however, needs to comply with all of the provisions of the rules.
See, e.g.,
§ 162.30(d)-(f) (CFTC) and § 248.201(d)-(f) (SEC) (program requirements).

2. The Objectives of the Program

The final rules provide that each financial institution or creditor that offers or maintains one or more covered accounts must develop and implement a written Program designed to detect, prevent, and mitigate identity theft in connection with the opening of a covered account or any existing covered account.
101

These provisions also require that each Program be appropriate to the size and complexity of the financial institution or creditor and the nature and scope of its activities. Thus, the final rules are designed to be scalable, by permitting Programs that take into account the operations of smaller institutions. We received no comment on the proposed objectives of the Program and are adopting them as proposed.

101

See
§ 162.30(d)(1) (CFTC) and § 248.201(d)(1) (SEC).

3. The Elements of the Program

The final rules set out the four elements that financial institutions and creditors must include in their Programs.
102

These elements are being adopted as proposed and are identical to the elements required under the Agencies' final identity theft red flags rules.
103

102

See
§ 162.30(d)(2) (CFTC) and § 248.201(d)(2) (SEC).

103

See
2007 Adopting Release,
supra
note 8, at 63726-63730.

First, the final rules require a financial institution or creditor to develop a Program that includes reasonable policies and procedures to identify relevant red flags
104

for the covered accounts that the financial institution or creditor offers or maintains, and incorporate those red flags into the Program.
105

Rather than

singling out specific red flags as mandatory or requiring specific policies and procedures to identify possible red flags, this first element provides financial institutions and creditors with flexibility in determining which red flags are relevant to their businesses and the covered accounts they manage over time. The list of factors that a financial institution or creditor should consider (as well as examples) are included in Section II of the guidelines, which appear at the end of the final rules.
106

Given the changing nature of identity theft, the Commissions believe that this element allows financial institutions or creditors to respond and adapt to new forms of identity theft and the attendant risks as they arise.

104
§ 162.30(b)(10) (CFTC) and § 248.201(b)(10) (SEC) define “red flag” to mean a pattern, practice, or specific activity that indicates the possible existence of identity theft.

105

See
§ 162.30(d)(2)(i) (CFTC) § 248.201(d)(2)(i) (SEC). The board of directors, appropriate committee thereof, or designated senior management employee may determine that a Program designed by a parent, subsidiary, or affiliated entity is also appropriate for use by the financial institution or creditor. In making such a

determination, the board (or committee or designated employee) must conduct an independent review to ensure that the Program is suitable and complies with the requirements of the red flags rules.
See
2007 Adopting Release,
supra
note 8, at 63730.

106

See
Section II.B.2 below.

Second, the final rules require financial institutions and creditors to have reasonable policies and procedures to detect the red flags that the Program incorporates.
107

This element does not provide a specific method of detection. Instead, section III of the guidelines provides examples of various means to detect red flags.
108

107

See
§ 162.30(d)(2)(ii) (CFTC) and § 248.201(d)(2)(ii) (SEC).

108

See
Section II.B.3 below.

Third, the final rules require financial institutions and creditors to have reasonable policies and procedures to respond appropriately to any red flags that they detect.
109

This element incorporates the requirement that a financial institution or creditor assess whether the red flags that are detected evidence a risk of identity theft and, if so, determine how to respond appropriately based on the degree of risk. Section IV of the guidelines sets out a list of aggravating factors and examples that a financial institution or creditor should consider in determining the appropriate response.
110

109

See
§ 162.30(d)(2)(iii) (CFTC) and § 248.201(d)(2)(iii) (SEC).

110

See
Section II.B.4 below.

Finally, the rules require financial institutions and creditors to have reasonable policies and procedures to periodically update the Program (including the red flags determined to be relevant), to reflect changes in risks to customers and to the safety and soundness of the financial institution or creditor from identity theft.
111

As discussed above, financial institutions and creditors are required to determine which red flags are relevant to their businesses and the covered accounts they offer or maintain. The Commissions are requiring a periodic update, rather than immediate or continuous updates, to be parallel with the identity theft red flags rules of the Agencies and to avoid unnecessary regulatory burdens. Section V of the guidelines provides a set of factors that should cause a financial institution or creditor to update its Program.
112

We received no comment on the proposed elements of Programs and are adopting them as proposed.

111

See
§ 162.30(d)(2)(iv) (CFTC) and § 248.201(d)(2)(iv) (SEC).

112

See
Section II.B.5 below.

4. Administration of the Program

The final rules provide direction to financial institutions and creditors regarding the administration of Programs as a means of enhancing the effectiveness of those Programs.
113

First, the final rules require that a financial institution or creditor obtain approval of the initial written Program from either its board of directors, an appropriate committee of the board of directors, or if the entity does not have a board, from a designated senior management employee.
114

This requirement highlights the responsibility of the board of directors in approving a Program. One commenter asked us to clarify that an entity that already has an existing Program in place, in compliance with the other Agencies' rules, need not have the board reapprove the Program to comply with this requirement.
115

We agree that if a financial institution or creditor already has a Program in place, the board is not required to reapprove the existing Program in response to this requirement, provided the Program otherwise meets the requirements of the final rules.

113

See
§ 162.30(e) (CFTC) and § 248.201(e) (SEC).

114

See
§ 162.30(e)(1) (CFTC) and § 248.201(e)(1) (SEC),
see also
§ 162.30(b)(2) (CFTC) and § 248.201(b)(2) (SEC).

115
ICI Comment Letter.

Second, the final rules provide that financial institutions and creditors must involve the board of directors, an appropriate committee thereof, or a designated senior management employee in the oversight, development, implementation, and administration of the Program.
116

The designated senior management employee who is responsible for the oversight of a broker-dealer's, investment company's or investment adviser's Program may be the entity's chief compliance officer.
117

Third, the final rules provide that financial institutions and creditors must train staff, as necessary, to effectively implement their Programs.
118

116

See
§ 162.30(e)(2) (CFTC) and § 248.201(e)(2) (SEC). Section VI of the guidelines elaborates on this provision.

117

See, e.g.,
rule 38a-1(a)(4) under the Investment Company Act (addressing the chief compliance officer position), 17 CFR 270.38a-1(a)(4); rule 206(4)-7(c) under the Investment Advisers Act, 17 CFR 275.206(4)-7 (same).

118

See
§ 162.30(e)(3) (CFTC) and § 248.201(e)(3) (SEC).

Finally, the rules provide that financial institutions and creditors must exercise appropriate and effective oversight of service provider arrangements.
119

The Commissions believe that it is important that the rules address service provider arrangements so that financial institutions and creditors remain legally responsible for compliance with the rules, irrespective of whether such financial institutions and creditors outsource their identity theft red flags detection, prevention, and mitigation operations to a service provider.
120

The final rules do not prescribe a specific manner in which appropriate and effective oversight of service provider arrangements must occur. Instead, the requirement provides flexibility to financial institutions and creditors in maintaining their service provider arrangements, while making clear that such institutions and creditors are still required to fulfill their legal compliance obligations.
121

We received no comments on the substance of this aspect of the proposal
122

and are adopting the requirements related to the administration of Programs as proposed.

119

See
§ 162.30(e)(4) (CFTC) and § 248.201(e)(4) (SEC). § 162.30(b)(11) (CFTC) and § 248.201(b)(11) (SEC) define the term “service provider” to mean a person that provides a service directly to the financial institution or creditor.

120
For example, a financial institution or creditor that uses a service provider to open accounts on its behalf, could reserve for itself the responsibility to verify the identity of a person opening a new account, may direct the service provider to do so, or may use another service provider to verify identity. Ultimately, however, the financial institution or creditor remains responsible for ensuring that the activity is conducted in compliance with a Program that meets the requirements of the identity theft red flags rules.

121
These legal compliance obligations include, but are not limited to, the maintenance of records in connection with any service provider arrangements.
See
17 CFR 240.17a-4(b)(7) (requiring that each broker-dealer maintain a record of all written agreements entered into by the broker-dealer relating to its business as such); 17 CFR 275.204-2(a)(10) (requiring that each investment adviser maintain a record of all written agreements entered into by the investment adviser with any client or otherwise relating to the business of the investment adviser as such).

122

But see infra
note 143 and accompanying text (discussing a comment received on the costs associated with this aspect of the proposal).

B. Final Guidelines

As amended by the Dodd-Frank Act, section 615(e)(1)(A) of the FCRA provides that the Commissions must jointly “establish and maintain guidelines for use by each financial institution and each creditor regarding identity theft with respect to account holders at, or customers of, such entities, and update such guidelines as often as necessary.”
123

Accordingly, the Commissions are jointly adopting guidelines in an appendix to the final identity theft red flags rules that are intended to assist financial institutions and creditors in the formulation and maintenance of a Program that satisfies the requirements of the rules. These guidelines are substantially similar to the guidelines adopted by the Agencies.

123
15 U.S.C. 1681m(e)(1)(A).

The final rules require each financial institution or creditor that is required to implement a Program to consider the guidelines and include in its Program those guidelines that are appropriate.
124

The Program needs to contain reasonable policies and procedures to fulfill the requirements of the final rules, even if a financial institution or creditor determines that one or more guidelines are not appropriate for its circumstances. We received no comment on the guidelines, and the Commissions are adopting them as proposed.

124

See
§ 162.30(f) (CFTC) and § 248.201(f) (SEC).

1. Section I of the Guidelines—Identity Theft Prevention Program

Section I of the guidelines makes clear that a financial institution or creditor may incorporate into its Program, as appropriate, its existing policies, procedures, and other arrangements that control reasonably foreseeable risks to customers or to the safety and soundness of the financial institution or creditor from identity theft. An example of such existing policies, procedures, and other arrangements may include other policies, procedures, and arrangements that the financial institution or creditor has developed to prevent fraud or otherwise ensure compliance with applicable laws and regulations.

2. Section II of the Guidelines—Identifying Relevant Red Flags

Section II(a) of the guidelines sets out several risk factors that a financial institution or creditor must consider in identifying relevant red flags for covered accounts, as appropriate. These risk factors are: (i) The types of covered accounts a financial institution or creditor offers or maintains; (ii) the methods it provides to open or access its covered accounts; and (iii) its previous experiences with identity theft. Thus, for example, red flags relevant to one type of covered account may differ from those relevant to another type of covered account. Under the guidelines, a financial institution or creditor also should consider identifying as relevant those red flags that directly relate to its previous experiences with identity theft.

Section II(b) of the guidelines sets out examples of sources from which financial institutions and creditors should derive relevant red flags. As discussed in the Proposing Release, this section of the guidelines does not require financial institutions and creditors to incorporate relevant red flags strictly from these sources. Instead, financial institutions and creditors must consider them when developing a Program.

Section II(c) of the guidelines identifies five categories of red flags that financial institutions and creditors must consider including in their Programs, as appropriate:

• Alerts, notifications, or other warnings received from consumer reporting agencies or service providers, such as fraud detection services;

• Presentation of suspicious documents, such as documents that appear to have been altered or forged;

• Presentation of suspicious personal identifying information, such as a suspicious address change;

• Unusual use of, or other suspicious activity related to, a covered account; and

• Notice from customers, victims of identity theft, law enforcement authorities, or other persons regarding possible identity theft in connection with covered accounts held by the financial institution or creditor.

Supplement A to the guidelines includes a non-comprehensive list of examples of red flags from each of these categories.

3. Section III of the Guidelines—Detecting Red Flags

Section III of the guidelines provides examples of policies and procedures that a financial institution or creditor must consider including in its Program's policies and procedures for the purpose of detecting red flags. As discussed in the Proposing Release, entities that are currently subject to the Agencies' identity theft red flags rules,
125

the federal customer identification program (“CIP”) rules
126

or other Bank Secrecy Act rules,
127

the Federal Financial Institutions Examination Council's guidance on authentication,
128

or the Interagency Guidelines Establishing Information Security Standards
129

may already be engaged in detecting red flags. These entities may wish to integrate the policies and procedures already developed for purposes of complying with these rules and standards into their Programs. However, such policies and procedures may need to be supplemented.
130

125

See
2007 Adopting Release,
supra
note 8.

126

See, e.g.,
31 CFR 1023.220 (broker-dealers), 1024.220 (mutual funds), and 1026.220 (futures commission merchants and introducing brokers). The CIP regulations implement section 326 of the USA PATRIOT Act, codified at 31 U.S.C. 5318(l).

127

See, e.g.,
31 CFR 103.130 (anti-money laundering programs for mutual funds).

128

See
“Authentication in an Internet Banking Environment,”
available at http://www.ffiec.gov/pdf/authentication_guidance.pdf
.

129

See
12 CFR part 30, app. B (national banks); 12 CFR part 208, app. D-2 and part 225, app. F (state member banks and bank holding companies); 12 CFR part 364, app. B (state non-member banks); 12 CFR part 570, app. B (savings associations); 12 CFR part 748, app. A (credit unions).

130
For example, the CIP rules were written to implement section 326 (31 U.S.C. 5318(
l
)) of the USA PATRIOT Act (Pub. L. 107-56 (2001)), and certain types of “accounts,” “customers,” and products are exempted or treated specially in the CIP rules because they pose a lower risk of money laundering or terrorist financing. Such special treatment may not be appropriate to accomplish the broader objective of detecting, preventing, and mitigating identity theft.

4. Section IV of the Guidelines—Preventing and Mitigating Identity Theft

Section IV of the guidelines states that a Program's policies and procedures should provide for appropriate responses to the red flags that a financial institution or creditor has detected, that are commensurate with the degree of risk posed by each red flag. In determining an appropriate response, under the guidelines, a financial institution or creditor is required to consider aggravating factors that may heighten the risk of identity theft. Section IV of the guidelines also provides several examples of appropriate responses. These examples are identical to those included in the Agencies' final guidelines. Financial institutions and creditors also may consider adopting measures to prevent and mitigate identity theft that are not listed in the guidelines.

5. Section V of the Guidelines—Updating the Identity Theft Prevention Program

Section V of the guidelines includes a list of factors on which a financial institution or creditor could base the periodic updates to its Program. These factors are: (i) The experiences of the financial institution or creditor with identity theft; (ii) changes in methods of

identity theft; (iii) changes in methods to detect, prevent, and mitigate identity theft; (iv) changes in the types of accounts that the financial institution or creditor offers or maintains; and (v) changes in the business arrangements of the financial institution or creditor, including mergers, acquisitions, alliances, joint ventures, and service provider arrangements.

6. Section VI of the Guidelines—Methods for Administering the Identity Theft Prevention Program

Section VI of the guidelines provides additional guidance for financial institutions and creditors to consider in administering their Programs. These guideline provisions are substantially identical to those prescribed by the Agencies in their final guidelines.

i. Oversight of Identity Theft Prevention Program

Section VI(a) of the guidelines states that oversight by the board of directors, an appropriate committee of the board, or a designated senior management employee should include: (i) Assigning specific responsibility for the Program's implementation; (ii) reviewing reports prepared by staff regarding compliance by the financial institution or creditor with the final rules; and (iii) approving material changes to the Program as necessary to address changing identity theft risks.

ii. Reporting to the Board of Directors

Section VI(b) of the guidelines states that staff of the financial institution or creditor responsible for development, implementation, and administration of its Program should report to the board of directors, an appropriate committee of the board, or a designated senior management employee, at least annually, on compliance by the financial institution or creditor with the final rules. In addition, section VI(b) of the guidelines provides that the report should address material matters related to the Program and evaluate issues such as recommendations for material changes to the Program.
131

131
The other issues referenced in the guideline are: (i) The effectiveness of the policies and procedures of the financial institution or creditor in addressing the risk of identity theft in connection with the opening of covered accounts and with respect to existing covered accounts; (ii) service provider arrangements; and (iii) significant incidents involving identity theft and management's response.

iii. Oversight of Service Provider Arrangements

Section VI(c) of the guidelines provides that whenever a financial institution or creditor engages a service provider to perform an activity in connection with one or more covered accounts, the financial institution or creditor should take steps to ensure that the activity of the service provider is conducted in accordance with reasonable policies and procedures designed to detect, prevent, and mitigate the risk of identity theft. As discussed in the Proposing Release, the Commissions believe that these guidelines make clear that a service provider that provides services to multiple financial institutions and creditors may do so in accordance with its own program to prevent identity theft, as long as the service provider's program meets the requirements of the identity theft red flags rules.

Section VI(c) of the guidelines also includes, as an example of how a financial institution or creditor may comply with this provision, that a financial institution or creditor could require the service provider by contract to have policies and procedures to detect relevant red flags that may arise in the performance of the service provider's activities, and either report the red flags to the financial institution or creditor, or to take appropriate steps to prevent or mitigate identity theft. In those circumstances, the Commissions expect that the contractual arrangements would include the provision of sufficient documentation by the service provider to the financial institution or creditor to enable it to assess compliance with the identity theft red flags rules.

7. Section VII of the Guidelines—Other Applicable Legal Requirements

Section VII of the guidelines identifies other applicable legal requirements from the FCRA and USA PATRIOT Act that financial institutions and creditors should keep in mind when developing, implementing, and administering their Programs.

8. Supplement A to the Guidelines

Supplement A to the guidelines provides illustrative examples of red flags that financial institutions and creditors are required to consider incorporating into their Programs, as appropriate. These examples are substantially similar to the examples identified in the Agencies' final guidelines. The examples are organized under the five categories of red flags that are set forth in section II(c) of the guidelines.

The Commissions recognize that some of the examples of red flags may be more reliable indicators of identity theft, while others are more reliable when detected in combination with other red flags. The Commissions intend that Supplement A to the guidelines be flexible and allow a financial institution or creditor to tailor the red flags it chooses for its Program to its own operations. Although the final rules do not require a financial institution or creditor to justify to the Commissions failure to include in its Program a specific red flag from the list of examples, a financial institution or creditor has to account for the overall effectiveness of its Program, and ensure that the Program is appropriate to the entity's size and complexity, and to the nature and scope of its activities.

C. Final Card Issuer Rules

Section 615(e)(1)(C) of the FCRA provides that the CFTC and SEC must “prescribe regulations applicable to card issuers to ensure that, if a card issuer receives notification of a change of address for an existing account, and within a short period of time (during at least the first 30 days after such notification is received) receives a request for an additional or replacement card for the same account, the card issuer may not issue the additional or replacement card, unless the card issuer applies certain address validation procedures.”
132

Accordingly, the Commissions are adopting rules that set out the duties of card issuers regarding changes of address.
133

These rules are similar to the final card issuer rules adopted by the Agencies.
134

The rules apply only to a person that issues a debit or credit card (“card issuer”) and that is subject to the enforcement authority of either Commission.
135

The Commissions did not receive any comments on the card issuer rules, and are adopting them as proposed.

132
15 U.S.C. 1681m(e)(1)(C).

133

See
§ 162.32 (CFTC) and § 248.202 (SEC).

134

See, e.g.,
16 CFR 681.3 (FTC).

135

See supra
Section II.A.1.

As discussed in the Proposing Release, the CFTC is not aware of any entities subject to its enforcement authority that issue debit or credit cards and, as a matter of practice, believes that it is highly unlikely that CFTC-regulated entities would issue debit or credit cards. As also discussed in the Proposing Release, the SEC understands that a number of entities within its enforcement authority issue cards in partnership with affiliated or unaffiliated banks and financial institutions, but that these cards are generally issued by the partner bank, and not by the SEC-regulated entity. The SEC therefore expects that no entities within its enforcement authority will be subject to the card issuer rules.

III. Related Matters

A. Cost-Benefit Considerations (CFTC) and Economic Analysis (SEC)

CFTC

Section 15(a) of the CEA
136

requires the CFTC to consider the costs and benefits of its actions before promulgating a regulation under the CEA or issuing certain orders. Section 15(a) further specifies that the costs and benefits shall be evaluated in light of the following five broad areas of market and public concern: (1) Protection of market participants and the public; (2) efficiency, competitiveness, and financial integrity of futures markets; (3) price discovery; (4) sound risk management practices; and (5) other public interest considerations. The CFTC considers the costs and benefits resulting from its discretionary determinations with respect to the section 15(a) considerations.
137

In the paragraphs that follow, the CFTC summarizes the proposal and comments to the same before considering the costs and benefits of the final rule in light of the 15(a) considerations.

136
7 U.S.C. 19(a).

137

Id.

Cost-Benefit Considerations of Identity Theft Red Flags Rules

Background and Proposal.
As discussed above, section 1088 of the Dodd-Frank Act transferred authority over certain parts of FCRA from the Agencies to the CFTC and the SEC for entities they regulate. On February 28, 2012, the CFTC, together with the SEC, issued proposed rules to help protect investors from identity theft by ensuring that FCMs, IBs, CPOs, and other CFTC-regulated entities create programs to detect and respond appropriately to red flags.
138

The proposed rules, which were substantially similar to rules adopted in 2007 by the FTC and other federal financial regulatory agencies, would require CFTC-regulated entities to adopt written identity theft programs that include reasonable policies and procedures to: (1) Identify relevant red flags; (2) detect the occurrence of red flags; (3) respond appropriately to the detected red flags; and (4) periodically update their programs. The proposed rules also included guidelines and examples of red flags to help regulated entities administer their programs.

138
77 FR 13450 (Mar. 6, 2012).

In its proposed consideration of costs and benefits pursuant to CEA section 15(a), the CFTC stated that section 162.30 should not result in any significant new costs or benefits because it generally reflects a statutory transfer of enforcement authority from the FTC to the CFTC. The CFTC requested comment on all aspects of its proposed consideration of costs and benefits.

Comments.
The CFTC received two comments on its consideration of the costs and benefits of the joint proposal. These two commenters were divided on the reasonableness of the Commissions' estimated costs of compliance. In a letter focused on the SEC's proposed regulations (which are, of course, substantially similar to the CFTC's proposed regulations), one commenter stated that because Regulation S-ID “is substantially similar to” the existing FTC rules and guidelines, broker-dealers should not bear “any new costs in coming into compliance with proposed Regulation S-ID.”
139

This commenter further stated that “broker-dealers should already have in place a program that complies with the FTC rule. While firms will need to update some of their procedures to reflect the SEC's new responsibility for the oversight of the application of this rule, many of the changes would be cosmetic and grammatical in nature.”
140

In marked contrast, another comment letter, submitted on behalf of the Financial Services Roundtable (“FSR”) and the Securities Industry and Financial Markets Association (“SIFMA”), stated that the “consensus of our members is that the estimated compliance costs for the proposed Rules are extremely low and unrealistic.”
141

139

See
NSCP Comment Letter.

140

Id.

141

See
FSR/SIFMA Comment Letter.

The FSR/SIFMA Comment Letter also stated that the FSR and SIFMA members estimated that the initial compliance burden to implement the rules would average 2,000 hours for each line of business conducted by a “large, complex financial institution,” noting that the estimate would vary based on the number of “covered accounts” for each line of business. In addition, this comment letter also stated that continuing compliance monitoring for such an institution would average 400 hours annually. They did not provide any data or information from which the CFTC could replicate its estimates.

The FSR/SIFMA Comment Letter also stated that “financial institutions with an existing Red Flags program would experience an incremental burden due to reassessing the scope of the `covered accounts' and reevaluating whether a business activity would be defined as a `financial institution' or as a `creditor' for purposes of the Agencies' Rules.”
142

The letter did not attribute a time estimate to this “incremental burden.”

142

Id.

Finally, the FSR/SIFMA Comment Letter contended that the Commissions' “estimated compliance costs further fail to consider the cost to third-party service providers, many of which may be required to implement an identity theft program even though they are not financial institutions or creditors.”
143

143

Id.

CFTC Response to Comments Regarding Costs and Benefits.
In considering the costs and benefits of the final rules, the CFTC assumes that each CFTC-regulated entity covered by the final rules is already in existence and acting in compliance with the law, including the FTC's identity theft rules.
144

Under this assumption, the CFTC believes, as one of the commenters did,
145

that entities will incur few if any new costs in complying with the CFTC's regulations because they are largely unchanged in terms of scope and substance from the FTC's rules. The CFTC believes that the costs of compliance for such entities may actually decrease as a result of the additional guidance provided in this rulemaking. Without such guidance from the CFTC, entities might incur the costs of seeking advice from third parties. With respect to the comment that CFTC-regulated entities will experience an “incremental burden” in reassessing covered accounts and determining whether their activities fall within the scope of the rules,
146

the CFTC notes that the FTC's identity theft rules also include the requirement to periodically reassess covered accounts, and thus costs associated with this requirement are not new costs.

144
As discussed above, the final rules implement a shift in oversight of identity theft red flags rules for CFTC-regulated entities from the FTC to the CFTC. The rules do not contain new requirements, nor do they substantially expand the scope of the FTC's rules. Most entities should already be in compliance with the FTC's existing rules, which the FTC began enforcing on January 1, 2011.

145

See
NSCP Comment Letter.

146

See supra
note 142 and accompanying text.

With regard to the estimate in the FSR/SIFMA Comment Letter that a “large, complex financial institution” will incur 2,000 hours of “initial compliance burden,”
147

the CFTC is unaware of any such institution that is not already acting in compliance with the FCRA and the FTC's rules. But even if such a large, complex financial institution exists and is not already in compliance with FCRA and the FTC's rules, the “initial burden” that such an entity would incur is largely attributable to the FCRA, as amended by the Dodd-Frank Act. As discussed above,

Congress mandated that the CFTC promulgate rules to bring its regulated entities into compliance with FCRA, and the CFTC has elected to do so in a manner that imposes minimal incremental cost on CFTC-regulated entities. In response to the comments concerning the costs to “third-party service providers,” the CFTC stresses these costs have already been taken into account, as CFTC-regulated entities that have outsourced identity theft detection, prevention, and mitigation operations to affiliates or third-party service providers have effectively shifted a burden that the CFTC-regulated entities otherwise would have carried themselves.

147

See
FSR/SIFMA Comment Letter.

One commenter also stated that since it maintains no covered accounts and has no plans to, it should be specifically excluded from the scope of the rules to avoid any potential that it would be subject to the requirements of the final rules. According to this commenter, to include it within the scope of the final rules would require it needlessly to incur compliance costs associated with periodically reassessing whether they maintain any covered accounts and documenting the same.
148

148

See
OCC Comment Letter.

The majority of the per-entity costs associated with the final rules would be incurred by those financial institutions and creditors that maintain covered accounts.
149

Additionally, even if financial institutions and creditors do not currently maintain, or intend to maintain, covered accounts, such entities must nevertheless periodically assess whether they maintain covered accounts, as certain accounts may be deemed to be “covered accounts” if reasonably foreseeable identity theft risks are associated with these accounts.
150

Moreover, the CFTC reiterates that the final rules do not contain any new requirements or significantly expand the scope of the pre-existing FTC rules. Therefore, no financial institutions or creditors, regardless of whether they maintain covered accounts, should incur any additional costs other than the costs already being incurred under the previous regulatory framework.

149

See infra
notes 151 and 152.

150

See supra
notes 95-100 and accompanying text.

Consideration of Costs and Benefits in Light of CEA Section 15(a).
As discussed above, the Dodd-Frank Act shifted enforcement authority over CFTC-regulated entities that are subject to section 615(e) of the FCRA from the FTC to the CFTC. Section 615(e) of the FCRA, as amended by the Dodd-Frank Act, requires that the CFTC, jointly with the Agencies and the SEC, adopt identity theft red flags rules. To carry out this requirement, the CFTC is adopting section 162.30, which is substantially similar to the identity theft red flags rules adopted by the Agencies in 2007.

Section 162.30 will shift oversight of identity theft rules of CFTC-regulated entities from the FTC to the CFTC. These entities should already be in compliance with the FTC's existing identity theft red flags rules, which the FTC began enforcing on January 1, 2011. Because section 162.30 is substantially similar to those existing rules, these entities should not bear any significant costs in coming into compliance with section 162.30. The new regulation does not contain new requirements, nor does it expand the scope of the rules significantly. The new regulation does contain examples and minor language changes designed to help guide entities within the CFTC's enforcement authority in complying with the rules, which the CFTC expects will mitigate costs of compliance. Moreover, section 162.30 would not impose any significant new costs on new entities since any newly-formed entities would already be covered under the FTC's existing rules.

In the analysis for the Paperwork Reduction Act of 1995 (“PRA”) below, the staff identified certain initial and ongoing hour burdens and associated time costs related to compliance with section 162.30. However, these costs are not new costs, but are current costs associated with compliance with the Agencies' existing rules. CFTC-regulated entities will incur these hours and costs regardless of whether the CFTC adopts section 162.30. These hours and costs would be transferred from the Agencies' PRA allotment to the CFTC. No new costs should result from the adoption of section 162.30.

These existing costs related to section 162.30 would include, for newly-formed CFTC-regulated entities, the one-time cost for financial institutions and creditors to conduct initial assessments of covered accounts, create a Program, obtain board approval of the Program, and train staff.
151

The existing costs would also include the ongoing cost to periodically review and update the Program, report periodically on the Program, and conduct periodic assessments of covered accounts.
152

151
CFTC staff estimates that the one-time burden of compliance would include 2 hours to conduct initial assessments of covered accounts, 25 hours to develop and obtain board approval of a Program, and 4 hours to train staff. CFTC staff estimates that, of the 31 hours incurred, 12 hours would be spent by internal counsel at an hourly rate of $354, 17 hours would be spent by administrative assistants at an hourly rate of $66, and 2 hours would be spent by the board of directors as a whole, at an hourly rate of $4000, for a total cost of $13,370 per entity for entities that need to come into compliance with proposed subpart C to Part 162. This estimate is based on the following calculations: $354 × 12 hours = $4,248; $66 × 17 = $1,122; $4,000 × 2 = $8,000; $4,248 + $1,122 + $8,000 = $13,370.

As discussed in the PRA analysis, CFTC staff estimates that there are 702 CFTC-regulated entities that newly form each year and that would fall within the definitions of “financial institution” or “creditor.” Of these 702 entities, 54 entities would maintain covered accounts.
See infra
note 168 and text following note 168. CFTC staff estimates that 2 hours of internal counsel's time would be spent conducting an initial assessment to determine whether they have covered accounts and whether they are subject to the proposed rule (or 702 entities). The cost associated with this determination is $497,016 based on the following calculation: $354 × 2 = $708; $708 × 702 = $497,016. CFTC staff estimates that 54 entities would bear the remaining specified costs for a total cost of $683,748 (54 × $12,662 = $683,748).
See
SIFMA's Office Salaries in the Securities Industry 2011.

Staff also estimates that in response to Dodd-Frank, there will be approximately 125 newly registered SDs and MSPs. Staff believes that each of these SDs and MSPs will be a financial institution or creditor with covered accounts. The additional cost of these SDs and MSPs is $1,671,250 (125 × $13,370 = $1,671,250).

152
CFTC staff estimates that the ongoing burden of compliance would include 2 hours to conduct periodic assessments of covered accounts, 2 hours to periodically review and update the Program, and 4 hours to prepare and present an annual report to the board, for a total of 8 hours. CFTC staff estimates that, of the 8 hours incurred, 7 hours would be spent by internal counsel at an hourly rate of $354 and 1 hour would be spent by the board of directors as a whole, at an hourly rate of $4,000, for a total hourly cost of $6,500. This estimate is based on the following calculations rounded to two significant digits: $354 × 7 hours = $2,478; $4,000 × 1 hour = $4,000; $2,478 + $4,000 = $6,478 ≉ $6,500.

As discussed in the PRA analysis, CFTC staff estimates that 2,946 existing CFTC-regulated entities would be financial institutions or creditors, of which 260 maintain covered accounts. CFTC staff estimates that 2 hours of internal counsel's time would be spent conducting periodic assessments of covered accounts and that all financial institutions or creditors subject to the proposed rule (or 2,946 entities) would bear this cost for a total cost of $2,100,000 based on the following calculations rounded to two significant digits: $354 × 2 = $708; $708 × 2,946 = $2,085,768 ≉ $2,100,000. CFTC staff estimates that 260 entities would bear the remaining specified ongoing costs for a total cost of $1,500,000 (260 × $5,770 = $1,500,200 ≉ $1,500,000).

The benefits related to adoption of section 162.30, which already exist in connection with the Agencies' identity theft red flags rules, would include a reduction in the risk of identity theft for investors (consumers) and cardholders, and a reduction in the risk of losses due to fraud for financial institutions and creditors. It is not practicable for the CFTC to estimate with precision the dollar value associated with the benefits that will inure to the public from the adoption of section 162.30, as the quantity or value of identity theft

deterred or prevented is not knowable. The CFTC, however, recognizes that the cost of any given instance of identity theft may be substantial to the individual involved. Joint adoption of identity theft red flags rules in a form that is substantially similar to the Agencies' identity theft red flags rules might also benefit financial institutions and creditors because entities regulated by multiple federal agencies could comply with a single set of standards, which would reduce potential compliance costs. As is true of the Agencies' identity theft red flags rules, the CFTC has designed section 162.30 to provide financial institutions and creditors significant flexibility in developing and maintaining a Program that is tailored to the size and complexity of their business and the nature of their operations, as well as in satisfying the address verification procedures.

Accordingly, as previously discussed, section 162.30 should not result in any significant new costs or benefits, because it generally reflects a statutory transfer of enforcement authority from the FTC to the CFTC, does not include any significant new requirements, and does not include new entities that were not previously covered by the Agencies' rules.

Section 15(a) Analysis.
As stated above, the CFTC is required to consider costs and benefits of proposed CFTC action in light of (1) protection of market participants and the public; (2) efficiency, competitiveness, and financial integrity of futures markets; (3) price discovery; (4) sound risk management practices; and (5) other public interest considerations. These rules protect market participants and the public by detecting, preventing, and mitigating identity theft, an illegal act that may be costly to them in both time and money.
153

Because, however, these rules create no new requirements — rather, as explained above, the CFTC is adopting rules that reflect requirements already in place — the impact of the rules on the protection of market participants and the public will remain the same. The Commission is not aware of any effect of these rules on the efficiency, competitiveness, and financial integrity of futures markets, price discovery, sound risk management practices, or other public interest considerations. Customers of CFTC registrants will continue to benefit from these rules in the same way they have benefited from the rules as they were administered by the Agencies.

153
According to the Javelin 2011 Identity Fraud Survey Report, consumer costs (the average out‐of‐pocket dollar amount victims pay) increased in 2010.
See Javelin 2011 Identity Fraud Survey Report
(2011). The report attributed this increase to new account fraud, which showed longer periods of misuse and detection and therefore more dollar losses associated with it than any other type of fraud. Notwithstanding the increase in cost, the report stated that the number of identity theft victims has decreased in recent years.
Id.

Cost-Benefit Considerations of Card Issuer Rules

With respect to specific types of identity theft, section 615(e) of the FCRA identified the scenario involving credit and debit card issuers as being a possible indicator of identity theft. Accordingly, the card issuer rules in section 162.32 set out the duties of card issuers regarding changes of address. The card issuer rules will apply only to a person that issues a debit or credit card and that is subject to the CFTC's enforcement authority. The card issuer rules require a card issuer to comply with certain address validation procedures in the event that such issuer receives a notification of a change of address for an existing account from a cardholder, and within a short period of time (during at least the first 30 days after such notification is received) receives a request for an additional or replacement card for the same account. The card issuer may not issue the additional or replacement card unless it complies with those procedures. The procedures include: (1) Notifying the cardholder of the request in writing or electronically either at the cardholder's former address, or by any other means of communication that the card issuer and the cardholder have previously agreed to use; or (2) assessing the validity of the change of address in accordance with established policies and procedures.

Section 162.32 will shift oversight of card issuer rules of CFTC-regulated entities from the FTC to the CFTC. These entities should already be in compliance with the FTC's existing card issuer rules, which the FTC began enforcing on January 1, 2011. Because section 162.32 is substantially similar to those existing card issuer rules, these entities should not bear any new costs in coming into compliance. The new regulation does not contain new requirements, nor does it expand the scope of the rules to include new entities that were not already previously covered by the Agencies' card issuer rules.

The existing costs related to section 162.32 would include the cost for card issuers to establish policies and procedures that assess the validity of a change of address notification submitted shortly before a request for an additional card and, before issuing an additional or replacement card, either notify the cardholder at the previous address or through another previously agreed-upon form of communication, or alternatively assess the validity of the address change through existing policies and procedures. As discussed in the PRA analysis, CFTC staff does not expect that any CFTC-regulated entities would be subject to the requirements of section 162.32.

The benefits related to adoption of section 162.32, which already exist in connection with the Agencies' card issuer rules, would include a reduction in the risk of identity theft for cardholders, and a reduction in the risk of losses due to fraud for card issuers. However, it is not practicable for the CFTC to estimate with precision the dollar value associated with the benefits that will inure to the public from these card issuer rules. As is true of the Agencies' card issuer rules, the CFTC has designed section 162.32 to provide card issuers significant flexibility in developing and maintaining a Program that is tailored to the size and complexity of their business and the nature of their operations.

Accordingly, as previously discussed, the card issuer rules should not result in any significant new costs or benefits, because they generally reflect a statutory transfer of enforcement authority from the FTC to the CFTC, do not include any significant new requirements, and do not include new entities that were not previously covered by the Agencies' rules.

Section 15(a) Analysis.
As stated above, the CFTC is required to consider costs and benefits of proposed CFTC action in light of (1) Protection of market participants and the public; (2) efficiency, competitiveness, and financial integrity of futures markets; (3) price discovery; (4) sound risk management practices; and (5) other public interest considerations. These rules protect market participants and the public by preventing identity theft, an illegal act that may be costly to them in both time and money.
154

Because, however, these rules create no new requirements—rather, as explained above, the CFTC is adopting rules that reflect requirements already in place—their cost and benefits have no incremental impact on the five section 15(a) factors. Customers of CFTC registrants will continue to benefit from these rules in the same way they have benefited from the rules as they were administered by the Agencies.

154

See id.

SEC

The SEC is sensitive to the costs and benefits imposed by its rules. As discussed above, the Dodd-Frank Act shifted enforcement authority over SEC-regulated entities that are subject to section 615(e) of the FCRA from the Agencies to the SEC. Section 615(e) of the FCRA, as amended by the Dodd-Frank Act, requires that the SEC, jointly with the Agencies and the CFTC, adopt identity theft red flags rules and guidelines. To carry out this requirement, the SEC is adopting Regulation S-ID, which is substantially similar to the identity theft red flags rules and guidelines adopted by the Agencies in 2007, and whose scope covers the same categories of SEC-regulated entities that were covered under the Agencies' red flags rules.

Regulation S-ID requires a financial institution or creditor that is subject to the SEC's enforcement authority and that offers or maintains covered accounts to develop, implement, and administer a written identity theft prevention Program. A financial institution or creditor must design its Program to detect, prevent, and mitigate identity theft in connection with the opening of a covered account or any existing covered account. A financial institution or creditor also must appropriately tailor its Program to its size and complexity, and to the nature and scope of its activities. In addition, a financial institution or creditor must take certain steps to comply with the requirements of the identity theft red flags rules, including training staff, providing annual reports to the board of directors, an appropriate committee thereof, or a designated senior management employee, and, if applicable, oversight of service providers.

Section 615(e)(1)(C) of the FCRA singles out change of address notifications sent to credit and debit card issuers as a possible indicator of identity theft, and requires the SEC to prescribe regulations concerning such notifications. Accordingly, the card issuer rules in this release set out the duties of card issuers regarding changes of address. The card issuer rules apply only to SEC-regulated entities that issue credit or debit cards.
155

The card issuer rules require a card issuer to comply with certain address validation procedures in the event that such issuer receives a notification of a change of address for an existing account, and within a short period of time (during at least the first 30 days after it receives such notification) receives a request for an additional or replacement card for the same account. The card issuer may not issue the additional or replacement card unless it complies with those procedures. The procedures include: (1) Notifying the cardholder of the request either at the cardholder's former address, or by any other means of communication that the card issuer and the cardholder have previously agreed to use; or (2) assessing the validity of the change of address in accordance with established policies and procedures.

155

See
§ 248.202(a) (defining scope of the SEC's rules).

The baseline we use to analyze the economic effects of Regulation S-ID is the identity theft red flags regulatory scheme administered by the Agencies. Regulation S

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2013-08830. Public record. Not legal advice.
