SEC proposes identity theft “red flags” rules to protect investors

BY KEN TYSIAC

Broker-dealers, mutual funds and other SEC-regulated entities would be required to create programs to detect and respond appropriately to identity theft red flags under an SEC rules proposal announced Tuesday and issued for public comment.

The proposed rules are designed to protect investors from identity theft and are similar to rules adopted in 2007 by the Federal Trade Commission (FTC) and other federal financial regulatory agencies. CPAs and others received a permanent exemption from the FTC’s rule with the enactment of the Red Flag Program Clarification Act of 2010, which limited the scope of the FTC’s rule by narrowing the definition of who can be considered a “creditor.”

According to the SEC’s proposal, SEC-regulated entities would be required to adopt a written policy for detection and response to identity theft. The proposed rule would include guidelines and examples of red flags to help firms comply.

The SEC issued the proposal jointly with the Commodity Futures Trading Commission (CFTC). Authority over certain parts of the Fair Credit Reporting Act was transferred from the FTC to the SEC and CFTC, for entities they regulate, by the Dodd-Frank Wall Street Reform and Consumer Protection Act, P.L. 111-203.

Comments can be submitted on the SEC’s website. The proposal will be published in the Federal Register with a 60-day comment period.

Ken Tysiac ( ktysiac@aicpa.org ) is a JofA senior editor.

More from the JofA:

 Find us on Facebook  |   Follow us on Twitter  |   View JofA videos

SPONSORED REPORT

Questions to ask before committing to the cloud

Cloud computing has its pros and cons. In this report, we answer common questions CPAs may have as they consider transitioning partially or fully to the cloud.

QUIZ

News quiz: IRS reopens an online service, but criticism endures

The IRS brings back the Get Transcript Online service, but the agency faces criticism for its handling of the aftermath of the event that led to the shutdown of the service. See how much you know about other recent news with this quiz.

CHECKLIST

Auditing risks in culture

Cultural flaws can seriously damage an organization. Here’s how internal auditors can reduce risks by embedding culture audits into existing audit programs.