Draft · internal validation

FTC Identity Theft Red Flags Rule

16 CFR Part 681 · Federal Trade Commission

Checks a covered-account determination and written identity theft prevention program against 16 CFR Part 681.

This pack is a draft.Every requirement traces to official text, but it has not had independent compliance or legal review. You can get a quote and aggregate policy pre-scan today; cited reports open after review.
Requirements13atomic checksCRITICAL3severityHIGH10severityWith official link13/13eCFR section URLRule effectiveJan 1, 2008current textPack version0.1.0-draft.1authored Sep 26, 2026

Requirements

Showing 8 of 13 · official summaries
16 CFR 681.1(c)

The organization periodically identifies covered accounts using a documented risk assessment that considers account-opening methods, access methods, and identity-theft experience.

CRITICALeCFR
16 CFR 681.1(d)(1)

A written, implemented, risk-scaled program detects, prevents, and mitigates identity theft for new and existing covered accounts.

CRITICALeCFR
16 CFR 681.1(d)(2)(i)

The program identifies account-specific Red Flags and incorporates them into operating procedures.

HIGHeCFR
All 13 requirements are versioned in the draft pack. Full evidence and remediation guidance remain inside the product.