FTC Publishes Identity Theft Program Template for Low-Risk Entities
Time 3 Minute Read
Categories: FCRA, Identity Theft

On May 13, 2009, the Federal Trade Commission ("FTC") published a compliance template designed to assist financial institutions and creditors "at low risk for identity theft " in developing the Identity Theft Prevention Program required by the FTC’s Identity Theft Red Flags and Address Discrepancies Rule (the "Rule").  The template is entitled "A Do-It-Yourself Prevention Program for Businesses and Organizations at Low Risk for Identity Theft."

While the Rule does not explicitly contemplate a category of entities that are "at low risk for identity theft," the imposition of less onerous requirements on lower-risk entities is consistent with the Rule'’s risk-based approach to combating identity theft.  To take advantage of the template, an entity first must assess whether it is at low risk for identity theft.  The FTC suggests that low risk may be shown by factors such as knowing customers personally, providing services at customers'’ homes, not having experienced fraud based on identity theft in the past and being in a line of business in which it is uncommon to experience fraud due to identity theft.  These factors are not exhaustive, however, as the template requires entities to also consider their unique circumstances in determining their identity theft risk level.  The assessment and the resulting conclusion must be documented in the template.

The FTC template then guides low-risk entities through the requirements of the Rule by asking them to identify red flags they may experience in their business if a consumer tries to obtain a product or service via identity theft.  The template assists low-risk entities in selecting methods to detect and respond to red flags and administering their Identity Theft Prevention Programs, including implementing updates and managing service providers.  Unlike the Rule, the template requires low-risk entities to document only the final, streamlined Identity Theft Prevention Program (which may be done by simply printing the completed template) and, as compared to the Rule, appears to place less emphasis on the process by which the program is developed.  The template'’s program administration requirements are also less onerous than those contemplated by the Rule.

Notably, the template does not address the issue of whether an entity is subject to the Rule; rather, it assists only in implementation of an Identify Theft Prevention Program once the entity has determined that it is subject to the Rule and is a low-risk entity. In other words, the template does not assist entities in the determination of whether they are financial institutions or creditors, nor does it assist entities in determining whether they have "covered accounts" that necessitate implementation of an Identity Theft Prevention Program, although these issues have been the subject of much debate and confusion among business interests.  In order to make these determinations, businesses may look to the Rule and the FTC’s Red Flags Guide for guidance.

 

You May Also Be Interested In

Time 3 Minute Read

The Federal Trade Commission has issued a new Policy Statement encouraging the adoption of robust age‑verification technologies by pledging not to bring enforcement actions under the COPPA Rule against operators of general‑ or mixed‑audience sites that collect, use or disclose personal information solely to determine users’ ages, so long as long as they follow strict safeguards.

Time 1 Minute Read

On February 6, 2026, the Federal Trade Commission announced its second report to Congress on its efforts to combat ransomware and other cyber attacks.

Time 2 Minute Read

On January 28, 2026, the U.S. Federal Trade Commission held a workshop entitled “Protecting American Children: A Workshop to Explore Age Verification Technologies.”

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page