SEC and CFTC Adopt Rules on Red Flags and Identity Theft
Time 2 Minute Read

On April 10, 2013, the Securities and Exchange Commission (“SEC”) and the Commodity Futures Trading Commission (“CFTC”) jointly adopted rules that require broker-dealers, mutual funds, investment advisers and certain other regulated entities to adopt programs designed to detect “red flags” and prevent identity theft. These rules implement provisions of the Dodd-Frank Wall Street Reform and Consumer Protection Act, that amended the Fair Credit Reporting Act (“FCRA”) to direct the SEC and the CFTC to adopt rules requiring regulated entities to address risks of identity theft. The 2003 amendments to the FCRA required other regulatory authorities to issue identity theft red flags rules, but did not authorize or require the SEC or the CFTC to issue their own rules.

The final rules require “financial institutions” and “creditors” (as defined in the FCRA) to develop and implement written identity theft prevention programs “designed to detect, prevent, and mitigate identity theft in connection with certain existing accounts or the opening of new accounts.” The rules set forth four elements that the regulated entities must incorporate into their identity theft prevention programs. These elements include adopting policies and procedures to (1) identify relevant red flags, (2) detect the red flags, (3) respond appropriately to red flags that have been detected, and (4) periodically update the program to reflect changes in identity theft risks to customers and to the regulated entity. The rules also establish specific requirements for covered credit or debit card issuers to assess the validity of notifications of changes of address under certain circumstances.

The final rules will become effective 30 days after publication in the Federal Register, with compliance required by six months after the effective date.

You May Also Be Interested In

Time 2 Minute Read

In mid-January 2026, key Senate committees published discussion drafts of market structure legislation for comprehensive federal regulation of digital assets. The Senate Banking Committee’s version of the bill is called the “Digital Asset Market Clarity Act.”  The Senate Agriculture Committee’s version of the bill is called the “Digital Commodity Intermediaries Act.”

Time 2 Minute Read

On November 20, 2025, the U.S. Securities and Exchange Commission issued a brief announcement that it filed a joint stipulation with defendants SolarWinds Corporation and its Chief Information Security Officer to dismiss, with prejudice, the SEC’s ongoing civil enforcement action against them.

Time 5 Minute Read

On September 29, 2025, staff in the SEC’s Division of Investment Management issued no-action relief for certain crypto asset custodians. Specifically, the relief will, under certain circumstances, allow SEC-registered investment advisers (Registered Advisers), registered investment companies and business development companies (collectively, Regulated Funds) to treat a state-chartered trust company as a “bank” (for custody purposes) with respect to crypto assets and related cash or cash equivalents, without fear of enforcement under the SEC’s custody rules.

Time 3 Minute Read

On July 30, 2025, the President’s Working Group on Digital Assets released its report entitled “Strengthening American Leadership in Digital Financial Technology.” The report champions American innovation in crypto, and “endorses the notion that digital assets and blockchain technologies can revolutionize not just America’s financial system, but systems of ownership and governance economy-wide.”

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page