Designing an Identity Theft Prevention Program
|
|
|
- Charla Lyons
- 10 years ago
- Views:
Transcription
1 The Federal Trade Commission has indicated that mortgage brokers are covered by the Red Flags Rule and must design identity theft prevention programs to comply with the law. The FTC has published a How-To Guide for Businesses on Red Flags compliance, titled Fighting Identity Theft with the Red Flags Rule. To get started on designing your Identity Theft Prevention Program, read it here: Fighting Identity Theft with the Red Flags Rule To download a pdf of the article click here The Red Flags Rule requires brokers to implement a written Identity Theft Prevention Program. This guide helps you write your own Identity Theft Prevention Program your Program is the central document your business needs for compliance with the Red Flags Rule law. Included are suggestions to follow and an example policy and procedures template which, when amended, can become the core of a program specific to your mortgage brokerage. Designing your Identity Theft Prevention Program requires a four-step process: 1. Identify the Red Flags that are relevant to your business 2. Determine how you will Detect these Red Flags 3. Establish how your program will Respond to Red Flags and help Prevent/Mitigate identity theft 4. Decide how you will Implement and Evaluate your Program (sign-off, training, update) Through these four steps, the decisions you make about identity theft and your business will become the fundamentals of your Program. Here s the Key! Compliance also requires that your Identity Theft Prevention Program be written down. Our Written ID Theft Program template provides you fill in the blanks to develop a written program that addresses all the key requirements of the Red Flags Rule. Only you can identify the risks and Red Flags relevant to your business and describe your procedures to detect, prevent, and mitigate identity theft this guide will give you a framework to get started and a process to follow in using the template to create your own written Identity Theft Prevention Program. Step 1: Identify the Red Flags that are relevant to your business Red Flags are suspicious patterns or practices, or specific activities that indicate the possibility of identity theft;
2 they are warning signs that a possible identity problem is present. The Red Flags Rule legislation points out four categories of common Red Flags, and lists 26 specific examples (detailed in Supplement A to the Red Flags Rule), several of which likely apply to your business as a mortgage broker: Category Alerts, Notifications and Warnings from a Credit Reporting Company Suspicious Documents Suspicious Personal Identifying Information Unusual Use of, or Suspicious Activity Related to, the Covered Account Specific Example (as written in Red Flags Rule legislation) A fraud or active duty alert is included with a consumer report A consumer reporting agency provides a notice of address discrepancy, as defined in (b) of FACTA Documents provided for identification appear to have been altered or forged An application appears to have been altered or forged, or gives the appearance of having been destroyed and reassembled. Personal identifying information provided by the customer is not consistent with other personal identifying information provided by the customer. For example, there is a lack for correlation between the SSN range and date of birth. Personal identifying information provided is associated with known fraudulent activity as indicated by internal or third-party sources used by the financial institution or creditor. For example: - The address on an application is fictitious, a mail drop, or prison; or - The phone number is invalid, or is associated with a pager or answering service The financial institution or creditor is notified by a customer, a victim of identity theft, a law enforcement authority, or any other person that it has opened a fraudulent account for a person engaged in identity theft Note: This is only a partial list of the 26 specific examples of Red Flags listed in Supplement A to the Red Flags Rule to view all 26, reference the original text here: Click to view FACTA 26 Suggested Red Flags (pdf)
3 As a mortgage broker, you need to consider all stages of your involvement with a borrower s identity information: from taking the initial loan application and collecting documentation, to closing and storing the borrower s loan file. If you have a system that supports any kind of online loan tracking for your borrowers, you should also consider how your clients/employees access that information and what Red Flags might warn you that the wrong person was attempting to gain access. For instance, many companies consider a series of failed attempts to login to a password-protected website a Red Flag indicating someone may be trying to break into an account. In the Program Template section of this guide, you can fill in the Identity Theft Red Flags you identify when you think through your relationship and work with your borrowers. To get you started, some widely applicable Red Flags have already been listed for you. As an Informative Research customer receiving the Red Flags Risk Platform, you can identify 9 of the 26 FACTA Suggested Alerts (and 8 of the specific sub-examples [i.e. 4 a. and 4 b., 10 a. and 10 b., etc.]) from credit report data and bureau fraud alerts the Red Flags detected by the Platform are very likely applicable to your business as a mortgage broker. Step 2: Determine how you will detect Red Flags Once you ve identified the Red Flags that might surface in your business, your next step is to make sure that you and/or your staff will notice when one of them pops up. Because most of your identity theft risk as a mortgage broker probably pertains to the application process, pay special attention to how you will make sure you and your staff are trained in recognizing Red Flags when they occur. Everyone in your office will need to learn to think a little bit like a detective: on the lookout for suspicious documents, credit report alerts, concerns voiced by borrowers, etc. In the Program Template section of this guide, fill in the measures you will take to ensure that your business recognizes Red Flags when they occur. Some common approaches have been pre-entered for you to keep, remove or edit as applicable to your business practices. Because you re using IR s Red Flags Risk Platform, detection of alerts based on the borrower s credit and fraud alert data is easy for you to document the Platform automatically lists fraud alerts that fire on the borrower s identify information, and each fraud alert includes information on which specific Red Flags from the list of FACTA 26 Suggested Alerts apply for that alert. Step 3: Establish how your program will respond to Red Flags and help prevent/mitigate ID theft This is the heart of your Identity Theft Prevention Program. If a Red Flag is detected and suggests something suspicious might be going on, what will you do about it to protect the consumer? The Red Flags Rule requires you to respond appropriately to any Red Flag. What is appropriate depends on the level of risk involved. An appropriate response to a credit report alert might simply be to take an extra step in loan processing to further verify your borrower s identity, or to call the consumer at the telephone number as directed in the alert. But if you receive 20 alerts in one day telling you that 20 of your borrowers provided Social Security
4 numbers belonging to deceased persons, that might make you suspect that criminals are trying to use your business in a larger fraud scheme in which case, the appropriate response would be to notify law enforcement. Most of the time, though, a Red Flag will probably be just a warning or trigger to look a little closer at your borrower and his or her application, just to be sure that nothing is wrong. More often than not, following your procedures to mitigate and prevent identity theft will simply result in your loan going forward with better documentation. If the steps you take really do reveal a fraud, such as an applicant using someone else s identity, catching that fraud before you submit the loan for funding will make a big difference for both you and for your lending partners. Because most brokers are involved in the process of opening an account but not in servicing it over time, most of your responses to Red Flags will probably be focused on ensuring that Red Flags are resolved during the application process such that you are confident no identity theft is involved, or stopping the loan process if suspicions remain. The Red Flags Risk Platform you receive with each IR credit report will provide you and your staff with suggested actions to assist you in resolving any credit data alerts that are triggered, offering a high level of confidence that your responses to these specific Red Flags will be appropriate in the specialized context of your business as a mortgage broker. In the Program Template, you can add all of the procedures your business will take to respond to Red Flags when they arise. Your descriptions should be fairly specific, unless they cross-reference written procedures you have already created separately for your employees. Step 4: Decide how you will implement and assess your Program (sign-off, training, update) In order to be effective, your Identity Theft Prevention Program must be familiar to everyone working in your company. Although many of the procedures you ll be using to detect and prevent identity theft may already be common practice in your office, you ll need to be confident your staff understands all the procedures and the contexts in which they should be applied. Risks change over time, so your Identity Theft Prevention Program needs to change too. The Red Flags Rule sets out specific steps you need to take to ensure that your Program is officially adopted by your company and then formally updated as necessary to keep pace with changes in your company, your business procedures, and the risk environment. Your written Program should describe both how you will train your employees about Red Flags and how you will keep your Program current. See the Program Template for ideas on how to approach this. If you use third party service providers to assist you in handling your covered accounts (most likely your borrowers
5 loan applications), your written Program must also describe how you will ensure that those service providers are conscious of the risks of identity theft and the measures they take to detect Red Flags and prevent identity theft. When you finish designing your Program, take the written document to your Board of Directors for approval, or to a senior officer of your company if there is no Board. In the Program Template, there is a space for you to document the Board s approval. You should plan on reviewing your Program after a certain amount of time has passed, or after a fraud is detected, a new Red Flag is foreseen, or a major change to the way your borrower s identity information is handled. The Red Flags Rule is specific in calling for Programs to be periodically updated as risks and fraudsters change with your business. See the Program Updates section of the Program Template. Written ID Theft Prevention Program Template Click to access the Program template in Microsoft Word format: Contact Informative Research at , for more information on our products and services.
University Policy: Identity Theft Prevention Policy
University Policy: Identity Theft Prevention Policy Policy Category: Ethics, Integrity and Legal Compliance Policies Subject: Detection, prevention and mitigation of identity theft Office Responsible for
Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation
Guidelines to FTC Red Flag Rule(reformatted) Appendix A to Part 681 Interagency Guidelines on Identity Theft Detection, Prevention, and Mitigation Section 681.2 of this part requires each financial institution
Identity Theft Policy Created: June 10, 2009 Author: Financial Services and Information Technology Services Version: 1.0
Identity Theft Policy Created: June 10, 2009 Author: Financial Services and Information Technology Services Version: 1.0 Scope: The risk to Loyola University Chicago and its faculty, staff and students
Spotting ID Theft Red Flags A Guide for FACTA Compliance. An IDology, Inc. Whitepaper
Spotting ID Theft Red Flags A Guide for FACTA Compliance An IDology, Inc. Whitepaper With a November 1 st deadline looming for financial companies and creditors to comply with Sections 114 and 315 of the
University of St. Thomas. Identity Theft Prevention Program. (Red Flags Regulation Response)
University of St. Thomas Identity Theft Prevention Program (Red Flags Regulation Response) Revised: January 10, 2013 Program Adoption and Administration The University of St. Thomas ( University ) established
identity TheFT PREVENTION Programs and Response
IDENTITY THEFT PREVENTION PROGRAM This program is launched in response to the Federal Trade Commission Red Flag Rules and Address Discrepancy Rules in conjunction with the Fair and Accurate Credit Transaction
Questions and Answers About the Identity Theft Red Flag Requirements
Questions and Answers About the Identity Theft Red Flag Requirements 1. Who is covered by the new Identity Theft Regulations? The Identity Theft Regulations consist of three different sets of requirements,
Red Flags Identity Theft Training Program. Fall 2015
Red Flags Identity Theft Training Program Fall 2015 Background In 2003, U.S. Congress enacted the Fair and Accurate Credit Transactions Act of 2003 (FACTA). FACTA requires creditors to adopt policies and
Detecting, Preventing, and Mitigating Identity Theft
THE RED FLAGS RULE Detecting, Preventing, and Mitigating Identity Theft Training for Ball State University s Identity Theft Protection Program What is the Red Flag Rule? Congress passed the Fair and Accurate
University Identity Theft and Detection Program (NEW) All Campuses and All Service Providers Subject to the Red Flags Rule
NUMBER: BUSF 4.12 SECTION: SUBJECT: Finance and Planning University Identity Theft and Detection Program (NEW) DATE: March 3, 2011 Policy for: Procedure for: Authorized by: Issued by: All Campuses and
Meeting Identity Theft Red Flags Regulations with IBM Fraud, Risk & Compliance Solutions
Leveraging Risk & Compliance for Strategic Advantage IBM Information Management software Meeting Identity Theft Red Flags Regulations with IBM Fraud, Risk & Compliance Solutions XXX Astute financial services
RADLEY ACURA RED FLAG IDENTITY THEFT PROTECTION PROGRAM and ADDRESS DISCREPANCY PROGRAM
RADLEY ACURA RED FLAG IDENTITY THEFT PROTECTION PROGRAM and ADDRESS DISCREPANCY PROGRAM SUMMARY OF OUR PROGRAM AND PROCESSES This dealership is committed to protecting its customers and itself from identity
NEVADA SYSTEM OF HIGHER EDUCATION PROCEDURES AND GUIDELINES MANUAL CHAPTER 13 IDENTITY THEFT PREVENTION PROGRAM (RED FLAG RULES)
NEVADA SYSTEM OF HIGHER EDUCATION PROCEDURES AND GUIDELINES MANUAL CHAPTER 13 IDENTITY THEFT PREVENTION PROGRAM (RED FLAG RULES) Section 1. NSHE... 2 Section 2. UNR... 4 Section 3. WNC... 9 Chapter 13,
Administrative Procedure 5800 Prevention of Identity Theft in Student Financial Transactions
Reference: Fair and Accurate Credit Transactions Act, ( Pub. L. 108-159) The purpose of the Identity Theft Prevention Program (ITPP) is to control reasonably foreseeable risks to students from identity
DSU Identity Theft Prevention Policy No. DSU 802.7.001
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 IDENTITY THEFT PREVENTION DSU Policy No. 802.7.001 SOURCE: Fair and Accurate
Red Flag Rules and Aging Services: What You Need to Know
Red Flag Rules and Aging Services: What You Need to Know Late in 2007, six federal agencies, including the Federal Trade Commission ( FTC ), jointly issued final rules and accompanying guidelines to implement
Facts About FACTA Red Flag Identity Theft Prevention Program
FACTA Red Flag Identity Theft Prevention Program FACTA Red Flag Policy Program, page 1 of 6 Contents Overview 3 Definition of Terms 3 Covered Accounts..3 List of Red Flags 3 Suspicious Documents...4 Suspicious
DMACC IDENTITY THEFT- RED FLAGS PROCEDURES
DMACC IDENTITY THEFT- RED FLAGS PROCEDURES This document contains identity theft red flag procedures for Des Moines Area Community College. Section Topic Page 1.0 2.0 3.0 4.0 5.0 6.0 7.0 8.0 XX PURPOSE
Identity Theft Prevention Program
Identity Theft Prevention Program DATE: 10/22/2015 VERSION 2015-1.0 Abstract Purpose of this document is to establish an Identity Theft Prevention Program designed to detect, prevent and mitigate identity
I. Purpose. Definition. a. Identity Theft - a fraud committed or attempted using the identifying information of another person without authority.
Procedure 3.6: Rule (Identity Theft Prevention) Volume 3: Office of Business & Finance Managing Office: Office of Business & Finance Effective Date: December 2, 2014 I. Purpose In 2007, the Federal Trade
POLICY NO. 449 IDENTITY THEFT PREVENTION POLICY
POLICY NO. 449 IDENTITY THEFT PREVENTION POLICY I. POLICY SUMMARY It shall be the policy of Polk County Rural Public Power District (PCRPPD) to take all reasonable steps to identify, detect, and prevent
Ouachita Baptist University. Identity Theft Policy and Program
Ouachita Baptist University Identity Theft Policy and Program Under the Federal Trade Commission s Red Flags Rule, Ouachita Baptist University is required to establish an Identity Theft Prevention Program
RESOLUTION NO. 2009-1
RESOLUTION NO. 2009-1 A RESOLUTION OF THE MAYOR AND COUNCI8L OF THE CITY OF ST. ANTHONY, IDAHO, ADOPTING AN IDENTY THEFT PREVENTION PROGRAM WHEREAS, Section 114 of the Fair and Accurate Transaction Act
Red Flag Identity Theft Financial Policy 1.10
Issued: 05/16/2014 Revised: Policy and College ( Seminary ) developed this Identity Theft Prevention Program ("Program") pursuant to the Federal Trade Commission's ( FTC ) Red Flags Rule, which implements
CITY OF MARQUETTE, MICHIGAN CITY COMMISSION POLICY
CITY OF MARQUETTE, MICHIGAN CITY COMMISSION POLICY Policy Number: 2008-02 Date Adopted: October 27, 2008 Department: Administrative SUBJECT: IDENTITY THEFT PREVENTION PROGRAM I. OBJECTIVE: A. To protect
Red Flag Rules Information and Training
Red Flag Rules Information and Training What are Red Flag Rules? The Red Flag Rules: - Are enforced by the Federal Trade Commission (FTC), the federal bank regulatory agencies, and the National Credit
Wake Forest University. Identity Theft Prevention Program. Effective May 1, 2009
Wake Forest University Identity Theft Prevention Program Effective May 1, 2009 I. GENERAL It is the policy of Wake Forest University ( University ) to comply with the Federal Trade Commission's ( FTC )
IDENTITY THEFT DETECTION POLICY
IDENTITY THEFT DETECTION POLICY Approved By: President s Cabinet Date of Last Revision: May 5, 2009 Responsible Office/Department: Business and Finance Policy Statement Grand Valley State University (GVSU)
UNIVERSITY OF MASSACHUSETTS IDENTITY THEFT PREVENTION PROGRAM
Doc. T08-109 Passed by the BoT 12/11/08 UNIVERSITY OF MASSACHUSETTS IDENTITY THEFT PREVENTION PROGRAM The Board recognizes that some activities of the University are subject to the provisions of the Fair
Lake Havasu City. Identity Theft Prevention Program
Lake Havasu City Identity Theft Prevention Program Effective beginning May 1, 2009 I. PROGRAM ADOPTION Lake Havasu City (City) developed this Identity Theft Prevention Program (Program) pursuant to the
PROVISIONS IDENTITY THEFT RED FLAG FAQS
R E D F L A G PROVISIONS 2 0 0 9 IDENTITY THEFT RED FLAG FAQS Provided to you by P r e p a r e d b y Eduard Goodman, J.D.,LL.M. Chief Privacy Officer I d e n t i t y T h e f t 9 11, L L C FREQUENTLY ASKED
Fighting Identity Theft with the Red Flags Rule: A How-To Guide for Business
Federal Trade Commission BCP Business Center business.ftc.gov Fighting Identity Theft with the Red Flags Rule: A How-To Guide for Business An estimated nine million Americans have their identities stolen
MCPHS IDENTITY THEFT POLICY
SECTION 1: BACKGROUND MCPHS IDENTITY THEFT POLICY The risk to the College, its employees and students from data loss and identity theft is of significant concern to the College and can be reduced only
City of Hercules Hercules Municipal Utility Identity Theft Prevention Program
City of Hercules Hercules Municipal Utility Identity Theft Prevention Program Purpose The purpose of the program is to establish an Identity Theft Prevention Program designed to detect, prevent and mitigate
RED FLAGS RULE. Identifying, Detecting, & Mitigating Possible Identity Theft
RED FLAGS RULE Identifying, Detecting, & Mitigating Possible Identity Theft What is the Red Flag Rule? The Federal Trade Commission (FTC), along with federal bank regulators and the National Credit Union
FACTA Identity Theft Red Flags Program. www.chs.acfei.com
1 FACTA Identity Theft Red Flags Program Module 1 Fair and Accurate Credit Transactions Act Overview Identity thieves use individual s personal identifiable information to open new accounts and misuse
21.01.04.Z1.01 Guideline: Identity Theft Prevention Program
Texas A&M Health Science Center Guidelines 21.01.04.Z1.01 Guideline: Identity Theft Prevention Program Approved October 7, 2009 Reviewed February 26, 2015 Supplements System Regulation 21.01.04 Reason
Village of Brockport Identity Theft Prevention Program Effective December 1, 2009 Confirmed 7/21/14
Village of Brockport Identity Theft Prevention Program Effective December 1, 2009 Confirmed 7/21/14 I. PROGRAM ADOPTION The Village of Brockport ( Village ) developed this Identity Theft Prevention Program
Florida International University. Identity Theft Prevention Program. Effective beginning August 1, 2009
Florida International University Identity Theft Prevention Program Effective beginning August 1, 2009 I. PROGRAM ADOPTION Florida International University developed this Identity Theft Prevention Program
EXHIBIT A Identity Theft Protection Program. Definitions. For purposes of the Policy, the following definitions apply (1);
EXHIBIT A Identity Theft Protection Program Definitions. For purposes of the Policy, the following definitions apply (1); A. City means: the City of Troy, Montana B. Covered Account means: An account that
