Full language-screen report
Fictional sample · no paymentIdentity theft prevention program · United States only
11 in-scope checks · 0 unresolved · 2 out of scope
Strong matches earn full credit; partial matches earn half credit. Unresolved and out-of-scope checks are excluded. This is a wording score, not a compliance grade.
Important: This report identifies potential policy and documentation gaps. It does not verify that controls are operating effectively and is not legal advice, certification, or a compliance determination.
FTC Red Flags Rule readiness
Version 0.1.0-draft.1 · DRAFT · 13 checks
- 16 CFR 681.1(c)No matching language · critical
The organization periodically identifies covered accounts using a documented risk assessment that considers account-opening methods, access methods, and identity-theft experience.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 64.0%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Perform and approve a periodic covered-account risk assessment.
- 16 CFR 681.1(d)(1)No matching language · critical
A written, implemented, risk-scaled program detects, prevents, and mitigates identity theft for new and existing covered accounts.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 0.0%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Create and implement a written Identity Theft Prevention Program scaled to the organization.
- 16 CFR 681.1(d)(2)(ii)No matching language · high
The program defines how incorporated Red Flags are detected.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 77.7%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Define operational detection methods for every incorporated Red Flag.
- 16 CFR 681.1(d)(2)(iii)No matching language · high
The program defines risk-appropriate responses to detected Red Flags.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 74.3%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Create risk-scaled response and escalation playbooks.
- 16 CFR 681.1(d)(2)(iv)No matching language · high
The program has a periodic and event-driven update process.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 21.6%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Establish periodic and event-driven program review with retained approvals.
- 16 CFR 681.1(e)(1)No matching language · high
The initial written program has approval from the required governing body.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 32.7%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Obtain and retain formal initial program approval.
- 16 CFR 681.1(e)(2)No matching language · high
Required senior governance participates throughout the program lifecycle.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 17.7%).
Suggested fix: Assign senior governance and define its recurring duties.
- 16 CFR 681.1(e)(3)No matching language · high
Personnel receive role-appropriate training needed to operate the program.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 56.8%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Implement role-based training and retain completion evidence.
- 16 CFR 681.1(e)(4)No matching language · high
The organization oversees service providers that perform activities connected to covered accounts.
Federal Trade Commission · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 39.7%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Add identity-theft controls to service-provider governance.
- 16 CFR 681.1(d)(2)(i)Partial matching language · high
The program identifies account-specific Red Flags and incorporates them into operating procedures.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (39.1% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“4. Response procedure When a red flag appears, the employee pauses account opening or the requested change and escalates the case to the Finance and Insurance Manager.”
Suggested fix: Document account-specific Red Flags and their sources.
- 16 CFR 681.1(f)Partial matching language · high
Program design documents consideration of Appendix A and identifies which guidelines are appropriate.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (42.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“CRA alert Fraud or active-duty alert on credit report Application intake Partial CRA alert Notice of address discrepancy Application intake Partial Documents Identification appears altered or forged Application intake Partial Documents Photo inconsistent with applicant Application intake Partial Identifying info SSN matches another applicant Verification service No Identifying info Phone number is invalid or a pager or answering service Verification service No Account activity Change of address followed by request for added authorized users Servicing No Account activity Mail repeatedly returned despite active payments Servicing Partial Notice Customer reports an unfamiliar account Complaints Partial Notice Law enforcement inquiry Management No Appendix B - Intake checklist (current version) • Compare government ID to application name, address, and date of birth.”
Suggested fix: Perform and retain an Appendix A applicability crosswalk.
- 16 CFR 681.2(c)Not in scope based on answers · critical
Card-issuer procedures block additional or replacement card issuance until the address change is validated using a permitted method.
Federal Trade Commission · official source
The organization-provided applicability facts place this requirement outside the rule's stated scope. Human review of those facts is required.
- 16 CFR 681.2(e)Not in scope based on answers · high
Required address-validation notice is understandable, prominent, and separate from regular correspondence.
Federal Trade Commission · official source
The organization-provided applicability facts place this requirement outside the rule's stated scope. Human review of those facts is required.
Limitations
- Preview built on DRAFT rule packs that have not completed independent legal review.
- Produced by a deterministic keyword screen, not by AI and not by a human reviewer; it can miss evidence phrased differently and can match text that does not satisfy the requirement.
- Readiness screening only; not legal advice, an audit, or a certification of compliance.
- Items marked applicability unresolved depend on facts that have not been collected or confirmed yet.
Legal Notice & Disclaimer
This report is provided for informational and readiness-assessment purposes only. It is intended to help identify potential gaps, inconsistencies, or areas for improvement within policies, procedures, SOPs, manuals, and related documentation.
AuditReady does not provide legal advice, regulatory certification, audit opinions, or assurances that an organization is compliant with any law, regulation, standard, or contractual obligation. The presence or absence of a finding in this report does not establish compliance, non-compliance, operational effectiveness, or the adequacy of an organization’s actual practices.
AuditReady is not responsible for the implementation, operation, enforcement, interpretation, or failure to implement any policy, procedure, control, process, or recommendation. Responsibility for business operations, legal compliance, regulatory obligations, internal controls, and organizational decisions remains solely with the organization and its authorized personnel.
AuditReady and its operators disclaim liability, to the fullest extent permitted by applicable law, for any loss, damage, penalty, regulatory action, business interruption, claim, or other consequence arising from reliance on this report, the organization’s operations, or any action or inaction taken in response to the report.
Organizations should consult qualified legal, compliance, security, financial, or other professional advisers where appropriate before making decisions based on this report.